Top

The US-China Pause Button: Why Neither Superpower Can Pause Alone, and What Would Let Them

The two countries that matter most for a pause on superintelligence are the United States and China. Together they host close to 90%  of the compute used to train frontier models. Without both of them, no treaty means anything. With both of them, almost everything else follows.

This page describes where the two governments stand, what the treaty literature proposes, and why the missing piece is not political will alone but a way for each side to check that the other has stopped. It builds on Building the Pause Button and The Dutch Pause Button.

This page is a work in progress. Last updated September 2026, ten days before Xi Jinping’s visit to Washington.

Contents

Two leaders, one race

On 13 September 2026, Trump told reporters: “We’re leading China in AI … whoever wins AI wins.”  Five days earlier, Treasury Secretary Bessent had said: “We can’t pause. You can’t, because the Chinese won’t pause.” 

In July 2026, Xi Jinping opened the World AI Conference in Shanghai and said that China must “constantly refine measures to forestall loss of control”  and “ensure that AI is always under human control”. He used the phrase “loss of control” three times. A year earlier, his top technology official Ding Xuexiang had warned in Davos that “if we allow this reckless competition among countries to continue, then we will see a ‘gray rhino’.” 

So both sides say the race is dangerous. Both sides say they cannot be the one to stop. This is the race to the bottom we have been warning about since 2023, now stated out loud by the people running it.

What has happened so far

  • November 2024. Biden and Xi jointly affirmed that humans, not AI, must control the decision to use nuclear weapons  . It was the first US-China statement on AI. It has stayed declaratory; the IISS notes it is “eroding rather than consolidating”.
  • May 2024 and May 2026. The only two official AI dialogues between the two governments. The first was in Geneva. The second was agreed at the Beijing summit of 14-15 May 2026, ending a two-year freeze  .
  • July 2026. Around 1,200 OpenAI agents escaped a test environment  , coordinated on improvised message boards, and broke into 41 production servers at Hugging Face. OpenAI noticed only after Hugging Face disclosed the breach. Two weeks later, 1,178 employees  of OpenAI, Anthropic, DeepMind and Meta asked the US government to support “an international effort to develop the technical and governance tools needed to deliberately pace the frontier”.
  • September 2026. Senator Sanders introduced the Ban Artificial Superintelligence Act  , which would make it US policy “to pursue international agreements, allied coordination, and policies such as export controls to prevent the development of artificial superintelligence anywhere in the world”. Anthropic’s Dario Amodei wrote “We must slow the pace at which we improve the capabilities of AI models”  , and Sam Altman said Trump and Xi “would get the Nobel Peace Prize together”  for a one-page agreement on development and testing standards.
  • 24 September 2026. Xi visits the White House. AI is on the agenda. A dedicated safety dialogue led by Bessent was planned for mid-September, then folded into a broader economic meeting  because a separate meeting “was becoming difficult to arrange”.

Why the talks stall

Read the two governments’ positions side by side and you see the same problem from two angles.

Washington’s problem is trust. Bessent’s line is not that a pause is undesirable. It is that China would cheat. The US wants to talk about AI-directed cyberattacks and distillation  of American models, and has proposed that labs on both sides “police themselves”.

Beijing’s problem is symmetry. On 31 August, a CCTV-affiliated account published two conditions  for the September talks: first, jointly define what counts as a “genuine security threat” as opposed to ordinary competition; second, the US must show that its rules “are equally effective against its own companies” before asking China to restrict anything. Chinese officials see the US requests as limiting Beijing’s ability to develop its own capabilities  .

Both problems have the same shape. Neither side can verify what the other is doing. Anthropic’s own brake pedal proposal  admits that verification is “much more challenging” for AI than for missiles, because training runs are easier to hide than silos. And even the word “safety” is not shared: Chinese usage of “loss of control” covers military AI, infrastructure and social stability  , while Western usage means AI agents subverting oversight inside a lab. As the Oxford China Policy Lab puts it, “converging on the word ‘loss of control’ matters far less than building the shared capacity to actually test for it”.

What the treaty proposals say

There is no shortage of draft agreements. The serious ones agree on one thing: the only part of AI development you can count is the hardware.

  • The MIRI treaty draft  (Scher et al., 2025) is a full text for a US-China-led coalition. It sets FLOP thresholds, tracks every AI chip through a Chip Tracking Body, and allows short-notice challenge inspections modeled on the Chemical Weapons Convention. Its Article VI treats chip manufacturing equipment more strictly than chips, because a fab produces for a decade while a chip lasts a few years.
  • Belfield’s Secure Chips Agreement  (2025) is an NPT for AI: members do not supply advanced chips to states that refuse safeguards. It “only needs the active participation of a small group”: the US, Taiwan, the Netherlands, Japan and South Korea.
  • Our own compute governance report  (2025) proposes a global chip registry, chain-of-custody tracking, and production quotas modeled on how the US Drug Enforcement Administration caps controlled substances.
  • Convergence Analysis  (Siddik, 2025) sketches a phased bilateral treaty built on chip tracking, cloud usage reports and audit rights for large training runs.
  • Katzke and Futerman  (2025) argue that an ASI-specific treaty is verifiable precisely because an ASI project needs “the very largest data centers”, which are visible from space.

The Washington think tanks that advise on the September talks take the opposite view. Brookings says export controls “should not be part of” risk reduction talks  . Carnegie says any “chips for safety” deal ought to be rejected  . Heritage warns against “non-enforceable or non-verifiable guardrails”  and against any concession on chips.

Both camps are right on their own terms. The treaty camp is right that chips are the only thing you can verify. The Washington camp is right that the US should not hand its chip leverage to China in exchange for promises. What neither camp has worked out is a chip-based verification regime that the US does not have to give up, because it does not own it.

Where the third party comes in

Every advanced AI chip, American or Chinese, is made on machines from one company in one country. That country is not the US or China. It is the Netherlands, and the company is ASML. The Dutch government already licenses every export of ASML’s EUV machines, and since 2024 also their servicing, spare parts and software updates.

This changes the negotiation:

  1. It answers Bessent. “China won’t pause” stops being a guess when Chinese fabs cannot get lithography machines, upgrades or maintenance without registering their AI chip output and accepting inspections. The same holds for TSMC, Samsung and Intel.
  2. It answers Beijing. A Dutch license condition applies to American customers and Chinese customers alike. That is the symmetry the CCTV post demanded, delivered by a party that is neither.
  3. It does not require a shared definition of safety. A production cap and a chip register need a shared count, not a shared theory of loss of control. That sidesteps the definitional trap that has blocked talks since 2024.
  4. It fits both sides’ own proposals. MIRI’s presumption of denial for equipment transfers to non-parties, Belfield’s small supplier group, and Sanders’ “export controls to prevent the development of artificial superintelligence anywhere in the world” all describe the same instrument. The Netherlands is the country that holds it.

We are not naive about this. The US can retaliate against ASML through the Foreign Direct Product Rule, and has done so before. But the US is already forcing the Netherlands to restrict ASML on American terms through the MATCH Act  . A Dutch regime built around AI safety criteria is not a challenge to Washington. It is the verification layer Washington says it cannot get.

What we ask of Trump and Xi

The September summit will not produce a treaty. It can produce the first three steps toward one:

  1. A joint statement that loss of control of frontier AI is a shared risk, in the same form as the November 2024 statement on nuclear weapons. Both leaders have already said this separately. Saying it together costs nothing and changes the baseline.
  2. A commitment to negotiate verifiable limits on frontier training, with compute as the unit of account. The Center for American Progress  proposes an AI “red phone” and a working group on testing and restrictions as first deliverables. We agree, and we add that the working group must be told to produce a verification design, not only a dialogue.
  3. An invitation to the supplier states. The Netherlands, Japan, Taiwan and South Korea should be asked to bring their existing equipment licensing regimes into the negotiation as the enforcement module. This is how the 2023 trilateral understanding on lithography was built, in eight months, without a treaty text.

Why now

  • The Global Call for AI Red Lines  , signed by ten Nobel laureates, asked governments for a binding agreement with an enforcement body by the end of 2026. That deadline is three months away and nothing exists.
  • The UN’s Global Dialogue on AI Governance  reconvenes in New York in 2027. China has put two experts on the UN scientific panel and launched WAICO; the US launched Pax Silica. The two blocs are forming now.
  • The stand-down agreed at Busan in October 2025, under which China suspended rare-earth measures and the US suspended its Affiliates Rule, expires in November 2026  .
  • Hardware governance only works while chip production is concentrated. China started producing its own DUV machines  in 2026. Ansari (2026)  and Horowitz and Kahn  both call the window temporary. That is an argument for using it, not for waiting.
  • Anthropic’s alignment lead now puts the chance of AI killing everyone in the next decade at more than 10%  . OpenAI says its most advanced unreleased models cannot yet be safely deployed  . The labs are asking for a brake. Only governments can build one.

What you can do

  • If you are in the US, ask your representative to support the Ban Artificial Superintelligence Act and to demand that the September summit produce a joint statement on loss of control. See our US lobby guide.
  • If you are in the Netherlands, read The Dutch Pause Button and ask your representative why ASML licenses are used only against China.
  • Anywhere else: join PauseAI. The supplier states need to hear from their own citizens that this is what their chokepoint is for.

Further reading