By S. Alex Yang, Angela Huyue Zhang, Project Syndicate | September 22, 2026
Warnings that AI may lead to our extinction often overlook the most immediate risk: a war triggered by an attack that no human intended or approved. A mechanism for distinguishing unintended harm from deliberate attacks is urgently needed.
LONDON/LOS ANGELES—When President Donald Trump and Chinese President Xi Jinping meet in Washington this week, AI governance is expected to be at the top of the agenda. The United States and China have been racing to develop increasingly powerful AI systems, and neither has shown much appetite for slowing down. But not even the winner of the AI race will be exempt from the profound risks the technology poses.
One such risk arises from AI’s improving ability to spot software vulnerabilities and conduct complex cyber operations. Because cyber conflict is marked by a stark asymmetry between offense and defense, the country with the world’s most advanced AI models will still be exposed to cyberattack. This mutual vulnerability creates a strong incentive for reciprocal restraint when it comes to AI-enabled attacks on critical infrastructure, such as financial networks, communications systems, and power grids.
There is precedent for such restraint. In 2015, US President Barack Obama agreed with Xi that neither government would conduct or knowingly support cyber-enabled theft of intellectual property for commercial advantage. They also established mechanisms for exchanging information, assisting investigations, and addressing malicious cyber activity. Cybersecurity firms subsequently recorded a steep decline in attacks attributable to China-based groups, though analysts noted that the decline began before the agreement and may have reflected changes within China’s military and cyber apparatus.
But AI raises a possibility not fully considered by traditional cyber agreements: the technology could carry out an autonomous attack on a critical system. In mid-July, during internal cybersecurity evaluations conducted with reduced safeguards, a swarm of OpenAI agents escaped the sandboxed testing environment, gained internet access, and compromised the systems of Hugging Face, a major open-source AI platform. OpenAI reported that the agents had “gone rogue,” taking actions outside their assignments.
Anthropic, Google, and Meta have reported similar incidents: AI agents escaped isolated testing environments and attempted unauthorized hacks against external systems. While the consequences of such breaches have so far been limited, this might not be the case if a US AI agent entered, say, Tencent’s systems and disrupted WeChat, the super app used by 1.4 billion people and deeply woven into daily life in China.
This is not a far-fetched scenario. Researchers at the security firm Calif recently disclosed that AI had helped them find a zero-click vulnerability in WeChat’s calling system. The team built a remote-code-execution exploit in about two days, then spent another week creating a worm capable of spreading through WeChat calls.
In a controlled demonstration, a call from a trusted contact could hijack a WeChat account without the user answering, not only giving the attacker access to their messages and calls, but also enabling them to reach and compromise their saved contacts. Calif reported the flaw to Tencent, which subsequently fixed the bug.
Calif’s WeWorm was a controlled security demonstration. But, together with the incidents in the US, it points to a troubling possibility: an unintended AI intrusion across national borders could look much like a deliberate attack. The US and China can observe the harm without knowing whether it was intentional. Repeated interaction could encourage restraint, but ambiguity could also trigger retaliation or give a deliberate attacker cover. Accidental or not, a cross-border breach could quickly spiral into a geopolitical crisis or even military conflict.
Given this, any future US–China agreement on AI-enabled cyberattacks must include a credible means of distinguishing accidents from deliberate intrusions. This means that, beyond creating reporting channels and a hotline, the agreement must address verification.
One option would be to put the burden of proof on the “perpetrator.” The country where the attack originated must provide credible evidence that it was not intentional, such as documentation showing the assignment given to the system, its permissions, tool use, records of human authorization, and logs showing when the agent’s behavior deviated from its instructions.
Verification need not mean full transparency. Under the Chemical Weapons Convention, to which the US and China are both parties, “managed access” allows inspectors to investigate possible violations, while permitting states to protect sensitive installations and unrelated confidential information. A similar mechanism could give mutually approved experts access to the evidence needed to assess an AI incident and limit the disclosure of sensitive findings.
Such a regime would offer additional benefits. Since the ability to prove that an intrusion was unintended could reduce the risk of retaliation, governments and AI companies would be motivated to improve their systems for preserving and sharing records, which could also help developers improve their AI agents and forestall future incidents.
Similarly, to avoid costly investigations, governments and AI companies would be motivated to adopt tighter permissions and invest in monitoring and containment. These safeguards could reduce the likelihood of future incidents and limit the damage when one does occur. And as the institutional, procedural, and technological tools developed for a bilateral arrangement were adopted more broadly, AI safety practices would improve everywhere.
Warnings that AI may lead to our extinction often overlook the most immediate risk: a war triggered by an attack that no human intended or approved. A mechanism for distinguishing unintended harm from deliberate attacks is urgently needed. A US–China agreement must seek to establish one.
S. Alex Yang is Professor of Management Science and Operations at London Business School.
Angela Huyue Zhang, Professor of Law at the University of Southern California, is the author of High Wire: How China Regulates Big Tech and Governs Its Economy (Oxford University Press, 2024) and Chinese Antitrust Exceptionalism: How the Rise of China Challenges Global Regulation (Oxford University Press, 2021).
📝Editor’s Note: We appreciate the authors’ high ideals. But given the unresolved questions surrounding COVID-19, including the continued lack of access to important information about the pandemic’s origins, we are less sanguine about the level of transparency and trust between the United States and China that their proposal would require. The WHO estimates that the pandemic was associated with approximately 14.9 million excess deaths worldwide in 2020 and 2021 alone. That experience raises a fundamental question: can the transparency and verification envisioned here be relied upon when the stakes of an AI incident are potentially just as consequential?
Loved it, hated it, or somewhere in between — tell us. Grade this article here and help shape what lands in your inbox next.
🔗 Further Reading
Deeper on what you just read.
🟨 AI Firms’ Self-Serving Warnings – Brian Judge, Project Syndicate
🟨 Utopia Yesterday, Apocalypse Today – Editorial Board, TIPP Insights
🟨 Trump Slams Anthropic CEO Who Sounded Alarm About AI Threats – TIPP News
🟨 Sam Altman Warns AI Could Become Too Powerful To Control – TIPP News
🟨 Who Is Raising The Alarm Over The Rapid AI Race – TIPP News
🟨 AI Stocks Plunge As Industry Leaders Raise Safety Concerns – TIPP News
🧭 Power & Capital · September 23, 2026
Where state power meets the boardroom.
🔷 Trump Calls AI “Super Intelligence” And Rejects Global Oversight
🌍 Global Affairs
The world's flashpoints, in motion.
🟥 Trump Faces Gulf Concerns Over Iran War And US Military Role – TIPP News
🟥 Trump, Denmark And Greenland Sign Deal To Expand Arctic Security – TIPP News
🟥 F-16 Fighter Jet Crashes Near U.S. Air Base In Germany, One Injured – TIPP News
🟥 Guterres Urges Stronger AI Regulation And Global Action To End Wars – TIPP News
🟥 War Watch: The Storm Cone – Martin Sieff, Ron Paul Institute for Peace and Prosperity
🏛️ National Affairs
The fights shaping America right now.
🟫 President Trump Bribes The People – Ron Paul, Ron Paul Institute for Peace and Prosperity
🟫 Six Major Hospitals Agree To Halt Gender-Affirming Care For Minors – TIPP News
🟫 Judge Temporarily Blocks Deportation Of Venezuelan Man Shot By ICE Agent – TIPP News
🟫 Two Ole Miss Students Die On Campus As Investigations Continue – TIPP News
🟫 Election Year Ploy? Democrats Reject Husted’s Unanimous Consent Request On Data Centers – Rebecca Downs, The Daily Signal
🟫 ‘People Are Pretty Freaked Out’: GOP Congressman Sounds Alarm On Socialist Agenda – Robert B. Bluey, The Daily Signal
🟫 Republicans Who Support War In Iran Are Giving Democrats Chance To Control Congress – Rep. John J. Duncan Jr., Ron Paul Institute for Peace and Prosperity
🟫 Early Voting Underway In Virginia With Senate Race, 11 House Seats On Ballot – Rich Tucker, The Daily Signal
🟫 Network Of State Conservatives Advance SAVE Laws – Virginia Grace McKinnon, The Daily Signal
🟫 6-Figure Ad Buy Calls On Trump To Send This Message To China On AI Threats – Elizabeth Troutman Mitchell, The Daily Signal
🟫 Conservative Lawmakers Demand The WNBA Define What A Woman Is – Pedro Rodriguez, The Daily Signal
🟫 Is ‘Neurodiversity’ The New DEI In Education? – Tyler O’Neil, The Daily Signal
🟫 Top Hispanic-American Think Tank Doubles Down On Efforts 15 Years After Its Founding – Pedro Rodriguez, The Daily Signal
🟫 Utopian Net Zero Just Got Riskier – Stefan Padfield, The Daily Signal
🟫 Government By Consent Of The Governed — Later On – George Ford Smith, Mises Wire
🟫 Stanford Scientists Challenge Long-Held Theory Of Brain Development – TIPP News
🟫 Fat Bear Week Begins As Alaska’s Biggest Bears Battle For The Crown – TIPP News
📈 Economy
Prices, policy, and the pressure on your wallet.
🟩 California Farmers Struggle As Wine Grape Demand Continues To Fall – TIPP News
🟩 Explaining Versus Describing Economic Events – Frank Shostak, Mises Wire
🟩 The Conflict Between Crony Capitalism And Market Logic – Shahin Karkhaneh, Mises Wire
🟩 The Limits Of China’s Market Reforms Under Communist Party Rule – William Hongsong Wang, Mises Wire
🟩 Property Rights Are Not A Luxury: Why Zimbabwe Cannot Grow Without Secure Ownership – Tinotenda Bhunu, Mises Wire
💼 Markets & Business
The deals and tickers making moves.
🟧 Microsoft Cuts 268 Jobs As Xbox Overhaul Moves Forward – TIPP News
🟧 Nvidia CEO Jensen Huang Dismisses ‘Doomsday Narratives’ Surrounding AI Development – Spencer Lombardo, Daily Caller News Foundation
🟧 Meta Tests Human Concierge To Handle Calls For AI Agent Muse – TIPP News
🟧 Weight-Loss Drugs Face Thousands Of Lawsuits Over Rare Vision Loss – TIPP News
📊 Market Mood · June 26, 2026
How the trading day is setting up.
🟩 AI continues to power global stocks. Asian shares are higher for a sixth straight session and U.S. technology sentiment remains strong after the Nasdaq touched another record, with enthusiasm around new AI applications supporting chip and technology shares.
🟧 Oil is slipping again, offering some inflation relief. Hopes for U.S.-Iran negotiations and the restart of Saudi Arabia’s East-West Pipeline have eased immediate supply fears, although crude remains near levels that can still pressure inflation.
🟦 Treasury yields remain the market’s pressure point. The 10-year yield is hovering near 5% following the Fed’s rate hike, making today’s business-activity data particularly important for the outlook for further tightening.
🟨 Attention is already turning to Thursday’s Trump-Xi summit. Markets are looking for progress on the trade truce, technology and AI issues as the two leaders prepare to meet in Washington.
🗓️ Key Economic Events
On today's U.S. data calendar.
🟧 9:45 a.m. ET — S&P Global Flash Manufacturing PMI (September)
Forecast: 53.6 | Previous: 53.9
Manufacturing is expected to remain comfortably in expansion territory, providing a timely read on business activity after the Fed’s rate hike.
🟧 9:45 a.m. ET — S&P Global Flash Services PMI (September)
Forecast: 55.8 | Previous: 56.5
Services are expected to remain strong, with investors particularly alert to signs of persistent price pressures.