AI capabilities are moving fast. Most institutions—including governments—can’t keep up.
Anton Leicht, Scott Singer
{
"authors": [
"Lucy Luo"
],
"type": "commentary",
"blog": "Emissary",
"centerAffiliationAll": "",
"centers": [
"Carnegie Endowment for International Peace"
],
"englishNewsletterAll": "",
"nonEnglishNewsletterAll": "",
"programAffiliation": "",
"regions": [
"United States",
"China"
],
"topics": [
"AI",
"Foreign Policy"
]
}Xi and Trump on May 14, 2026 in Beijing. (Photo by Brendan Smialowski/pool/Getty Images)
When a swarm of OpenAI models broke out of their testing sandboxes and hacked into AI company Hugging Face’s infrastructure, alarm bells went off across the AI world. From a geopolitical perspective, the incident was tame. Both companies involved are from the United States, and they were easily able to cooperate to rein in the rogue AI agents.
But there is nothing to prevent rogue AIs from crossing borders. What if in the future it’s a Chinese company’s AI agents that are hacking into core American technical infrastructure? What if an American company’s model decides that achieving its goals requires it to access Chinese banks or even military systems? Or what if the intelligence services in either country learn that AI agents of unknown origin are embedding themselves deep within digital networks across several countries?
These scenarios once seemed far-fetched but are now eminently possible. If the United States and China—the rival great powers with the most rapidly advancing AI capabilities—are going to safely navigate this brave new world, they will need the ability to communicate quickly and effectively about an emerging AI crisis.
To address these scenarios, experts have recommended an AI crisis “hotline” to reduce miscommunication and misinterpretation of incidents. But established U.S.–China hotlines have a fraught track record: Washington wasn’t able to reach Beijing during actual moments of crisis. Any AI-focused communication channel must be adapted and modernized to deal with the intricacies of the U.S.–China relationship and the specific challenges AI-enabled crises pose.
That means the channel should be text-based, tiered, come with specific triggers, and be continuously staffed by technically proficient people.
Hotlines have been critical to limiting accidental escalation during crises. During the Cuban Missile Crisis, diplomatic telegram messages took up to twelve hours to be delivered and sometimes contradicted each other by the time they arrived. In the aftermath, the Washington–Moscow Direct Communications Link was established to mitigate these risks.
The “Hot Line” agreement made each government responsible for its own telegraph circuits and for prompt delivery to its head of state, with a radio link as backup. Contrary to the popular belief in a “red telephone,” the text-based telegraph design created a record, removed tone as a source of misunderstanding, reduced risks of mistranslation, and allowed time for internal deliberation.
Although the Washington–Moscow hotline has a mixed record, it did support communication during the 1967 Six-Day War to clarify U.S. fleet movements and in the Yom Kippur War of 1973 to explain intentions and coordinate a ceasefire. This model has been expanded to link different levels of authority, and its purposes have also grown to include symbolic confidence-building, routine dialogues, and mediation. These experiences indicated that hotlines could be a useful tool for crisis management, but only if they were designed well.
The hotline model was transferred to the U.S.–China context with little success. In response to the 1995–1996 Taiwan Strait Crisis, China and the United States established a direct presidential hotline in 1998. In April 2008, the two sides set up a military-to-military Defense Telephone Link to prevent military misunderstandings in the Pacific region. Publicly known use cases have primarily served symbolic, assurance, and dissuasion purposes, including assuring Chinese officials during moments of heightened tension.
Despite their intentions, the U.S.–China hotlines repeatedly failed in moments of need. In 1999, after U.S. planes accidentally bombed the Chinese Embassy in Belgrade, U.S. officials hoping to apologize were unable to reach their Chinese counterparts. During the 2001 Hainan Island incident, when a U.S. EP-3 surveillance plane collided with a Chinese fighter jet, calls from the United States went unanswered for twelve hours. More recently, as bilateral tensions rose after former House speaker Nancy Pelosi visited Taiwan in 2022, China suspended the military hotline. It was restored at the Asia-Pacific Economic Cooperation summit in San Francisco in 2023.
The U.S.–China military hotline requires the party that initiates the call to provide a forty-eight-hour notice to schedule a call, making it a slow communication tool, not one built for a fast-moving crisis. Using real-time audio calls has several disadvantages: It requires time for ceremonial formality; creates challenges for accurate, live translation; and adds pressure to reach a decision before each side can internally deliberate. Incompatible approaches to crisis management lead to different assumptions about appropriate use, which in turn cause difficulties in reaching each other. Bureaucratic obstacles also exist within Chinese domestic structures, where those staffing the line may need further information and approval from higher authorities before speaking to their U.S. counterparts. Thoughtful design choices could encourage both countries to use a crisis communication line reliably.
Despite historical challenges, hotlines provide a useful model for crisis communication. But any new channel will need to address the shortcomings that have held previous U.S.–China crisis communication back and adapt to the demands posed by frontier AI.
For an AI hotline, the United States and China should pay particular attention to designing its procedure, form, and trigger thresholds.
Do not make it a phone. A text-based system would directly address issues with the current U.S.–China hotline by eliminating the inefficiencies of scheduling and live communication. It also addresses bureaucratic reasons for nonresponse, in which receiving staff lack decision authority and cannot access senior authority immediately. Text-based communication creates a record, eliminates impacts of tone, reduces risks of mistranslation, and allows for internal deliberation. This design contributed to the relative success of the Washington–Moscow hotline.
Establish different lines for routine communication and emergencies. The routine line can focus on sharing best practices, tracking minor incidents, and iterating on effective communication procedures. The working knowledge and relationships built from this working-level line can support the function of a separate crisis line. The procedures for the crisis line should ensure senior decisionmaking authorities can get in touch promptly. This separation allows each of the lines to be optimized for its purpose, rather than muddled within one.
Outline the thresholds that trigger use of the hotline. To counter political reasons for nonresponse, the two sides can consider jointly establishing the goals of the channel and agreeing in advance on the criteria that triggers use. This could involve defining the types of crises within scope, building actionable escalation criteria, and defining thresholds of severity that warrant notification. Although establishing goals cannot fully eliminate the channel being used for political ends, it can lower the barrier to use, separate communication from escalation, and build shared understanding.
Design for AI. To address the unique qualities of frontier AI, this communication channel must be continuously staffed with technical personnel who can interpret an incident. Developing a standing network of interdisciplinary experts can help inform the recovery from a cross-border, cross-jurisdiction incident. Effective communication for incident prevention and recovery will involve exchanging digital evidence such as model activity logs. The communication channel should be supplemented by a secure channel for transmitting digital data.
While political challenges cannot be engineered away, the context surrounding AI-enabled crises is more favorable to a crisis channel than the military context has been. China has signaled interest in AI-related emergency response and improving the use of political-diplomatic communication channels since the May 2026 meeting between the two countries’ leaders. This suggests a channel could be established without Washington having to treat it as a concession to be traded. Decoupling this channel from the military context helps it further, as key use cases would be clarifying attribution to rogue AI agents rather than state actors, and coordinating responses to misuse by nonstate actors. Because AI incidents could cross jurisdictions more readily than military encounters, the damage at stake and the shared interest in effective response are greater.
At the height of the Cold War, adversaries built hotlines after realizing how close they had come to destroying each other by accident. The United States and China have yet to build a well-designed channel that is easy to use—but this is changeable. The upcoming U.S.–China AI dialogue is the place to start.
With the rapid acceleration of AI capabilities, AI-enabled crises will not wait around for a shared moment of terror. Washington and Beijing can build a communication channel before the most serious risks materialize.
The author is grateful to Isabella Duan for her mentorship and Pivotal Research for supporting the research on which this piece draws.
Understand the world with the latest from our scholars around the world.
Visiting Researcher, Technology and International Affairs Program
Lucy Luo is a visiting researcher in the Technology and International Affairs Program at the Carnegie Endowment for International Peace, where her research focuses on China’s AI ecosystem and international AI governance.
Carnegie does not take institutional positions on public policy issues; the views represented herein are those of the author(s) and do not necessarily reflect the views of Carnegie, its staff, or its trustees.
AI capabilities are moving fast. Most institutions—including governments—can’t keep up.
Anton Leicht, Scott Singer
Lee’s tour shows how Seoul is reorganizing its diplomacy away from Pyongyang and toward industrial networks and the geography of the compute economy.
Darcie Draudt-Véjares
His challenge will come in balancing domestic priorities with a sharpening geopolitical environment.
Luke Cavanaugh, Scott Singer
“AI safety in parallel” is modest and pragmatic but vital.
Matt Sheehan
That statistic about a bottle of water may not live up to scrutiny.
Jon Bateman, Andy Masley