What should the United States seek in an AI agreement with China, and how could either side verify it? Glenn Parham moderates a conversation with Kevin Wolf, Ryan Fedasiuk, and Karson Elmgren about model capabilities, export controls, open-weight AI, and practical channels for reducing risk.
The conversation
- Moderator: Glenn Parham, Head of Public Sector, Vals AI
- Kevin Wolf, partner, Akin Gump; former Assistant Secretary of Commerce for Export Administration
- Ryan Fedasiuk, fellow, American Enterprise Institute
- Karson Elmgren, senior researcher, Institute for AI Policy and Strategy
Edited transcript
This transcript has been edited for clarity and readability. Repetitions, false starts, and microphone chatter have been removed. Timestamps refer to the original session. Glenn Parham's opening presentation is included before the panel discussion. Bracketed notes identify unclear wording in the source transcript. Policy references and other remarks reflect the discussion on September 23, 2026.
Opening presentation: capabilities, policy, and this week's talks
Glenn Parham (00:00): I'm the head of public sector at Vals AI. Thank you all for being here. There's so much activity around AI, especially in the context of the United States and China. We'll get into a panel in a few moments, but first I want to give an overview of the U.S.-China relationship and where current capabilities sit from our perspective at Vals.
It's helpful to look at the negotiations and the relationship through three lenses. First, capability: What is the capability gap? How well do models from U.S. AI labs perform versus those from Chinese AI labs?
Second, government action: What are our respective governments doing about AI? What regulatory actions are they taking, and how are they coalescing around this activity?
Third, events this week: Secretary Bessent and China's vice premier met in New York earlier this week to discuss AI coordination and this idea of an incident channel. What does that actually mean? We'll get into that in the presentation and the panel.
Let's start with capability. Where do Chinese models excel? In our analysis of cybersecurity and other benchmarks at Vals AI, much of which is on the poster boards in the back, we've found Chinese models are very good at certain cybersecurity tasks. They're nearing the frontier of U.S. models, which has been fascinating and, to some, alarming.
We have a benchmark called CyberBench. It asks: How well can AI agents find and fix real software vulnerabilities? Think of a codebase on GitHub. You deploy an agent powered by a U.S. model, a Chinese model, or another model. How well can it identify vulnerabilities, and how well can it patch them?
When it comes to finding vulnerabilities, U.S. models are still clearly ahead in most cases. The story is different when you look at fixing and patching vulnerabilities. GPT-5.6 and Kimi K3 come out equally in our CyberBench evaluations. They've achieved parity.
These are two models and results we've selected. There are many models we evaluate. This demonstrates the broader narrative: Chinese models aren't catching up across the board, but at least on some cybersecurity tasks, they're catching up to U.S. capabilities.
Now let's discuss the governments' different approaches to regulating AI. Broadly speaking, China regulates public AI deployment centrally. The United States relies more on private markets, while regulation remains a patchwork and the federal approach is largely unsettled.
China started regulating AI several years ago, in 2023, through the Cyberspace Administration of China, or CAC. It regulates public-facing generative AI services. These services are required to uphold “core socialist values.” China has specific laws pertaining to generative AI services.
Over the past couple of years, rules have mostly focused on identifying deepfakes and controlling content, ensuring outputs from models and chatbots abide by China's laws and regulations.
What's fascinating is that despite this regulatory body heavily regulating the industry, China has put out many models and services. At the end of 2024, there were about 300 approved generative AI services. By August 2026, that had grown to more than 1,100. On social media, it seems like another Chinese AI model comes out every other day.
The narrative right now is that any regulation gets in the way of the AI industry's pace and speed. In China, the story is a little different.
China's approach has also focused on open-source and open-weight AI. President Xi met with countries at a BRICS summit recently and advocated coordinating on open-source AI and diffusing Chinese models. They're being deliberate. His quote on the slide is that we should “develop AI for the positive and for good” and “work faster to evolve a consensus-based global AI governance framework.”
The United States has been interesting in its regulation of AI, or lack thereof. At the federal level, a summer executive order lets labs voluntarily provide models to the government up to 30 days before release. That's voluntary, not mandated or binding.
The Trump administration's posture has been to lean on the private sector, let it self-regulate, and not pursue a government-directed slowdown. I showed Xi's statement emphasizing worldwide coordination on open-source AI and safety. President Trump made his own statement last week: “The only control or guardrails that AI needs is a strong and smart president. Whoever wins AI wins.” You can see the divergence and some overlap in philosophies.
Across the states, as you heard on the previous panel, there's been legislative activity, especially on child safety. California created a voluntary independent verification organization framework. We'll say IVO a lot today. Illinois followed suit.
At the federal level, Congress is considering the FRONTIER Act, which we'll discuss in the panel after this one. The Senate is considering its own legislation. Whether regulations are signed into law by year-end, given the midterms and the chaos, is unknown.
We've also seen the U.S. government use export controls and Entity List designations involving AI labs. Restrictions on Nvidia GPUs being sold into China have evolved, or devolved, over time. The NSA and FBI recently called out Chinese AI labs for engaging in what's known as AI distillation. From a national-security perspective, they've been proactive in trying to protect American intellectual property.
As the United States and China discuss and negotiate, independent evaluation is emerging as a point of convergence and cooperation. An IVO is broadly defined as an independent third party with protected access to a lab's safety plans, models, systems, personnel, and incident data.
We've seen states sign this into law, and it's being considered federally. There are different philosophies about whether compliance should be mandatory or voluntary. The jury is still out, but it's fascinating.
CAISI, the Center for AI Standards and Innovation, is supposed to be the main U.S. agency tasked with running AI evaluations, whether for child safety or cybersecurity threats. Even that is up in the air. Its budget is only $10 million. If you've worked in government, you know that's small relative to the mission. It'll be interesting to see whether CAISI becomes the main AI regulatory agency going forward or whether that sits elsewhere in government.
This week, competition and communication have moved in parallel. The NSA and FBI issued a statement alleging large-scale AI distillation by Chinese labs. Yet we're also trying to work with the Chinese government and these labs on AI safety. It's a fine line to walk.
Our Treasury secretary and China's vice premier met in New York to discuss a notification channel for AI incidents with national-security implications. Basically, if something goes south, they want to make it easier for AI researchers and specialists in China and the United States to have conversations, because right now it's siloed.
President Trump and President Xi are scheduled to meet tomorrow in Washington, and AI will be on the agenda. We'll discuss incident-reporting mechanisms and how the two countries can share and communicate when things go wrong.
From our perspective, AI evaluations are important. They're a constructive vehicle everyone can agree on to assess and measure risks, whether in child safety, cybersecurity, or other domains. That's where we see the best way to collaborate.
Let's invite our panelists up: Ryan, Kevin, and Karson. We couldn't have better experts at the intersection of the United States, China, and export controls.
Ryan Fedasiuk is a fellow at the American Enterprise Institute focused on U.S.-China relations, technology, and national power, and an adjunct professor at Georgetown. He formerly handled China technology and bilateral affairs at the State Department and researched Chinese military AI at Georgetown's Center for Security and Emerging Technology.
Kevin Wolf is a partner at Akin Gump. He served as Assistant Secretary for Export Administration at the U.S. Department of Commerce's Bureau of Industry and Security, overseeing export controls, from 2010 to 2017.
Karson Elmgren is a senior researcher at the Institute for AI Policy and Strategy, focused on China. He previously worked at RAND and Georgetown's Center for Security and Emerging Technology and recently co-authored a proposal for a U.S.-China AI risk and incident dialogue. I think that work inspired a lot of this past week's discussions.
The capability gap and what export controls do
Glenn Parham (16:36): Ryan, how do you view the capability gap between the United States and China today? Are we on a trajectory where it narrows or widens?
Ryan Fedasiuk (16:45): Thanks for the invitation. Most of you follow the constant model releases in the United States, whether it's [model names unclear in source transcript]. U.S. models are in the lead on many benchmarks shown on the screen. I think that's likely to remain the case for two reasons.
First, U.S. labs are swimming in compute relative to Chinese counterparts. They have high token budgets to play with. Second, they're magnets for the world's top AI talent, and that's unlikely to change. Even a researcher in China may want to end up at OpenAI, Anthropic, or Google.
There are other competitions where I worry about U.S. positioning: adoption of AI for national power and international diffusion among local and independent developers. It's hard to compete with free. And there's making our society resilient to AI's disruptive effects, where I don't think either the United States or China is positioned very well.
Glenn Parham (18:12): Kevin, in your role as assistant secretary of commerce, you oversaw BIS. Could you give an overview of what it does and how it fits into this conversation about export controls and chips?
Kevin Wolf (18:43): Thanks for being here, and apologies for my pre-Covid photo. I let myself go after Covid. I'm the oldest one in the room. The old photo is misleading.
Export controls are rules governing three verbs, export, re-export, and transfer, of four things, commodities, software, technology, and services, to specific end users, end uses, and destinations to accomplish national-security and foreign-policy objectives. That sentence defines thousands of pages of regulations and their policy objective.
The question is: What's the national-security objective? It evolves with every generation and administration. Since the end of the Cold War, the traditional focus has been nonproliferation.
Identify military items and weapons of mass destruction and regulate them with the United States and its allies. Identify parts, components, software, and technology with a relationship to developing or producing conventional military items or weapons of mass destruction, including missiles, chemical and biological weapons, and nuclear weapons. Regulate those through multilateral agreement to increase effectiveness.
That governed my time in government, as well as the Bush and Clinton administrations. The first Trump administration gets credit for shifting the focus beyond that classical objective. It recognized that issues with China, and later Russia, couldn't be limited to traditional nonproliferation.
The Biden administration expanded the definition of national security with respect to anxiety about AI in China. In addition to those classical objectives, it said China's indigenous capability to develop or produce four things was an inherent national-security threat, regardless of source or commerciality: compute for AI, such as Nvidia GPUs; semiconductor production equipment to make those chips; support for developing or producing advanced-node integrated circuits, including logic, NAND, and DRAM; and support for supercomputers.
There was a policy objective, clarified and expanded in January 2025, that advanced frontier AI was a threat to humanity, national security, and democracy, and therefore needed to be aggressively regulated. That included not only the inputs but, in January 2025, frontier models themselves, basically derived from U.S. content.
Beginning in October 2022, the Biden administration expanded national security to encompass all the inputs into AI. A January 2025 rule imposed controls globally on every GPU on the planet, to anybody, anywhere, for any reason, through extraterritorial jurisdiction because it's derived from U.S. technology or produced with U.S. equipment.
Lawyers were going to love this because every transaction on the planet required advice from me or my colleagues. In May of last year, the Trump administration said it wouldn't enforce those rules, except with respect to China and the Middle East. [A sentence about subsequent amendments is unclear in the source transcript.]
Historically, BIS works with allies to regulate inputs into weapons of mass destruction. It's a nonproliferation tool. The Biden administration expanded that to AI inputs as such, applied unilaterally, with no other ally agreeing with us, and extraterritorially, meaning our rules apply overseas.
The Trump administration said it wouldn't enforce that, but it hasn't told us what comes next. It's been a year and a half. I'll get into where things stand when you ask other questions.
Glenn Parham (23:05): There's a lot of public discussion about export controls. I'm looking forward to the mechanics, including how a company gets on the Entity List.
Karson, you've done work on a U.S.-China AI risk and incident dialogue. Could you lay out the report you recently published? We've seen discussion of this, especially this week with Secretary Bessent and the vice premier.
Building an AI risk and incident dialogue
Karson Elmgren (23:47): There's a lot going on. It's difficult to keep up with AI policy without checking your phone every five minutes.
The U.S.-China relationship is competitive, but that doesn't mean we can't cooperate on mutual interests. People sometimes ask how we can have export controls and also want to talk to China. It's not strange. During the Cold War, the United States and Soviet Union competed but also cooperated on things including nuclear nonproliferation.
The current administration clearly realizes we're in a competitive situation, but can put a floor on competition or build structures for stability.
My understanding is that Secretary Bessent has submitted a proposal to President Trump for a potential communication channel between the United States and China. Trump will make a decision before the summit, so I guess today.
The currently envisioned form seems to be a channel between Secretary Bessent and Vice Premier He Lifeng. Topics would include cybersecurity risks, national-security threats, rogue AI, and possibly other things. Those are reasonable topics to expect.
Our team's recent report is a more ambitious version of what's being discussed. It involves a high-level connection between senior, empowered principals, plus working groups on different topics involving relevant stakeholders across the AI ecosystem.
I'm excited there's traction on the idea. A dialogue can be a platform from which other things are built. Having Bessent and He speak regularly, share views about developing risks, and discuss recent incidents could provide a platform for later bringing together U.S. CAISI and a Chinese equivalent to discuss evaluation standards in detail. It could also support a Track 1.5 group involving industry.
Glenn Parham (27:16): Ideally, you'd have the entire ecosystems in both countries coordinating on incidents. Right now, our understanding is that this relationship would just be between our secretary and China's vice premier. Who else should be brought in? Should OpenAI or Anthropic literally talk to DeepSeek? What should it ideally look like?
Karson Elmgren (27:54): Some kinds of private-sector engagement make sense. That could include frontier labs as model developers. Compute providers, hyperscalers, and neoclouds are relevant stakeholders and governance loci.
There are capable open-weight models. Anyone can take one, run it on a cloud, and do wonderful and not-so-wonderful things. There are also potential targets of harm. The financial sector is an important node. It's not totally coincidental that Secretary Bessent is leading here.
At least the frontier labs and other particularly relevant stakeholders, such as compute providers, should be involved.
Open-weight models and the distinction between misuse and loss of control
Glenn Parham (29:04): Ryan, why has China leaned so much into open-source models, more than the United States from my perspective? Is there a strategy behind it?
Ryan Fedasiuk (29:31): I'll pick up on that and what Karson said about what to expect this week.
China's labs aren't making products as competitive with the U.S. frontier for enterprise customers. But they're making exceptionally token-efficient models, energy-efficient to run and often small enough to run locally. It makes sense for different labs to pursue different commercialization strategies.
ByteDance's strategy is to build AI into social-media products like TikTok and put it in front of a billion-plus monthly active users. Alibaba offers locally downloadable models for free, with permissive licenses, to get developers to rent its compute infrastructure. That's different from Moonshot or DeepSeek offering software as a service, charging for access through an API.
Those are three pathways to attracting large numbers of customers. If you can't compete on price at the high end, you can undercut the competition and attract customers at the low end of the value chain. We've seen this in other industries.
There are risks and problems with this approach. When thinking about U.S.-China coordination, it's worth distinguishing what you mean and what you want China's labs to do.
On one hand, AI could be misused by would-be bioterrorists or cybercriminals with always-available tutors helping their objectives. On the other, there are concerns in mainstream media about AI loss of control: frontier systems becoming powerful enough to replicate themselves, exfiltrate, and embed in critical infrastructure. Those are different risk scenarios.
People in both governments are worried about model misuse. There's energy behind vetting who receives capable models to make sure they use them responsibly, not for terrorism or cybercrime. I think that's the core objective of the most acute ongoing U.S.-China AI negotiation: what to do about misuse risk.
There's very little being discussed right now about loss of control or existential or catastrophic risks, and I don't expect much in the next month or two. That's my personal opinion, and I welcome other thoughts.
Karson Elmgren (32:53): I probably agree that the immediate and, in some sense, more tractable focus is misuse.
On open source, it's true that the Chinese government says it supports it, and Chinese companies release open-weight models. But it's too easy to draw a direct line and say companies are doing it because the government told them to.
To the extent the government's position is causal, it's a permissive cause. If it said not to release open weights, most companies probably wouldn't. But generally, this has been a commercially driven strategy the government has been okay with so far.
My understanding is there's an active debate in China about open weights, how to manage them, and their risks. The current status quo of companies putting models onto the internet won't necessarily remain forever.
Entity List designations and enforcement
Glenn Parham (34:25): Let's look at the U.S. government's reaction to allegations of AI distillation. A couple of weeks ago, the NSA, FBI, and CISA alleged that several Chinese AI labs were using American models to improve models abroad.
Over the past year, the U.S. government put Zhipu on the Entity List. I'm not asking about that one designation specifically, but as the government considers adding more AI labs, could you walk us through the mechanics? Is the intelligence community talking to State and Commerce? What's the sequence behind the scenes?
Kevin Wolf (35:49): Remember, export controls cover items, hardware, software, and technology of concern; activities, such as uses supporting weapons of mass destruction; and end users. End-user controls can prohibit exports of hardware, software, or technology to a company.
The Entity List began in 1997 under Clinton to make it easier to identify entities outside the United States involved in developing and producing missiles, chemical or biological weapons, or nuclear weapons. After 9/11, the Bush administration expanded it to terrorism. As assistant secretary, I expanded it as an enforcement tool against those supporting Russia's invasion of Ukraine.
The first Trump administration dramatically expanded it for other reasons, listing hundreds of names, including those involved in the South China Sea and other matters not traditionally linked to export controls.
The Biden administration went further on AI. Beginning in October 2022, but more in October 2023 and December 2024, it added Chinese entities in the AI ecosystem, such as Biren, which designs GPUs for AI.
It's not like a sanction prohibiting economic transactions. It prohibits U.S.-origin hardware, software, and technology from going to that project. No other country has this Entity List concept or jurisdiction. Generally, it doesn't apply to foreign-made items, and other countries don't recognize the concept.
To accomplish a national-security objective, the government can decide it doesn't want U.S.-origin technology going to a list of about 2,000 companies, roughly 1,400 of them in China.
At the beginning of 2025, the Trump administration cleaned up lists left over from Biden. But for almost a year and a half, it has taken virtually no Entity List actions or imposed new controls against companies, particularly in China.
The generally accepted reason is that doing so would irritate efforts to reach a broader trade deal. Anything that would irritate Xi has been on hold. There have been virtually no new regulations or Entity List actions against China for almost any reason.
Last fall, a rule expanded the Entity List to automatically apply to affiliates and subsidiaries of listed entities. China responded by cutting off rare-earth metals to the United States and U.S. companies. Within a month, export controls became a transactional tool for the first time in history, and the rule was withdrawn, or technically suspended for a year until November 10. That will likely be extended.
My point is that under the current administration, the process is dead. There's no interagency process or activity.
Since the late 1990s, the process had involved Commerce, State, Defense, and Energy through the End-User Review Committee. They reviewed intelligence and other assessments daily and made recommendations weekly about entities to cut off from U.S. technology to accomplish one of those objectives.
Three agencies voting yes put an entity on; four voting yes took one off. They met at Commerce and made recommendations to the assistant secretary, who amended the Export Administration Regulations to impose the restriction. That process has basically been dead since the beginning of 2025.
Glenn Parham (40:01): You mentioned enforcement during your tenure. Enforcing controls on hardware, like GPUs, makes sense to me. How difficult is it for software or model weights?
Kevin Wolf (40:24): If software is U.S.-origin, whether it's for an electric toothbrush or something else, it's caught by the prohibition whenever a listed entity is a party to the transaction.
Anything intangible is harder to enforce. You rely on fear of prosecution to motivate companies to build internal compliance systems. Competitors are active about reporting one another, so there's a strong incentive to comply even if the government wouldn't find out directly. Many recent enforcement cases, and cases during Biden, were based on violations of these entity rules.
Their effectiveness is limited for most items because, by definition, they apply only to U.S.-origin items. Once listed, a company generally switches to buying foreign-made items.
A handful of 72 entities, prominently Huawei, are subject to an extraterritorial Entity List Foreign Direct Product Rule. For those entities, foreign-made items produced with U.S. technology or equipment are also covered. For most of the 2,000 entities, the rules apply only to U.S.-origin items. As I said, the process for adding names has basically been dead.
For AI model weights, the Biden administration imposed global controls on frontier models, with 10 to the 26 as the threshold. The Trump administration said it wouldn't enforce those controls. There are now no controls on model weights of any sort, regardless of capability or whether they became functional through U.S. technology.
Making communication channels work
Glenn Parham (42:21): It'll be fascinating to see what happens after Trump and Xi's negotiations tomorrow. Secretary Bessent and the vice premier have agreed to another round of discussions in China in a couple of months. We'll track whether Entity List restrictions or export controls are added or removed.
Karson, you've mentioned Track 1.5 and Track 2 diplomacy. Could you define those official and unofficial channels? Where have these discussions worked in other technology fields, and what can we learn for AI?
Karson Elmgren (43:16): Track 2 diplomacy is a term for essentially nonofficial diplomacy. Track 1 is government-to-government. Track 2 could be think-tank staff, academics, or industry talking to one another. Track 1.5 is the middle ground, where government and nongovernment people are in the room.
Track 1 goes back to the dawn of time. Track 2 also has a long history, including during the Cold War. There's been a small but substantial amount of Track 2 AI diplomacy between the United States and China, and more broadly the West and China. It's useful given the difficulty of Track 1.
Track 1 is more where the rubber hits the road, but it's sensitive, fraught, and dependent on political circumstances. Track 2 allows coordination, signaling, and back-channel communication when Track 1 isn't happening.
For official communication channels, unfortunately, lessons in the U.S.-China relationship have been more negative than positive. Existing channels have had some utility, but they face challenges.
Lower-level officials staffing Chinese communication channels generally don't have authority to speak off the cuff about an incident. They need to send talking points up the chain, get approval, and wait for an authorized response before having a conversation.
An AI channel could be more effective if it were asynchronous rather than synchronous. Not a telephone, but a fax or an email inbox, allowing the Chinese side to respond on a cadence that fits its system.
What could either side actually verify?
Glenn Parham (46:07): That makes sense. People may be cynical that even if we reached an agreement, we could enforce China's side of the bargain. What are your thoughts on enforceability, but also verification?
Ryan Fedasiuk (46:34): I'll give a somewhat pessimistic take. First, this is an amazing panel. We've covered a lot. In our past lives, Karson and I benefited from Kevin Wolf's export-control expertise when debating how GPU controls could be implemented. You can see why that was instrumental.
Just as in 2022, ahead of the U.S. decision to control the export of a household commodity, a GPU, we're now faced with an uncertain question about verifying an agreement.
Before asking how verification could work, we should take a step back and ask: What do we want from China? I haven't heard a compelling answer. There's a lot of hysterics in the media and calls for talks, coordination, or cooperation.
That's why Karson's recent IAPS report is useful as a maximalist instrument. What could a comprehensive, verifiable agreement to share sensitive information, or even proscribe certain capability development, look like in practice?
I don't share that degree of optimism. I'll tell you what I think we should ask for. I'd love China's AI labs to coordinate with Chinese authorities to audit models before public release, in some of the ways Vals has discussed today. How much capability uplift will DeepSeek's next release give would-be bioterrorists and cybercriminals?
Currently, it's easy to jailbreak Chinese models. They fail basic tests around the limited nominal guardrails labs design for security. In my view, China's AI governance has primarily focused on regime security and political censorship. I'd love the government and labs to take AI security seriously in a way similar to the U.S. government.
People in the United States have opinions about the wisdom of AI regulation. Like it or not, the Trump administration has enacted a de facto licensing regime of sorts: a voluntary process for frontier labs to submit models for government review within a 30-day period, enacted through a June executive order.
Given that process, wouldn't it be nice if China adopted or committed to adopting something similar? We'd at least row in a similar direction and ensure freely released models don't provide undue uplift to bad actors.
That's still a far cry for the United States. I'm not sure China will agree, for the reasons Karson and Kevin enumerated. Even if it did, it would likely ask the United States to relax technology restrictions and stop accusing Chinese labs of fraud through distillation. I'm not sure those would be useful conversations for the United States.
I don't know that verification is possible. There are ways to design a regime restricting capability development in either country, but I don't think it's likely, certainly not before year-end. That's my view.
Karson Elmgren (50:48): I agree that the right question is what we want, or what we're ultimately trying to achieve. How to verify something follows from that.
On predeployment evaluations, it would be great for China to commit to them. It might do that unilaterally; the United States doesn't necessarily need to cause it.
You could imagine an agreement at some point where we ask, “You say you're doing predeployment evaluations. Are they good? Could we run our evaluations on your models?” That's sensitive for various reasons.
There's been recent work by Google DeepMind, I think with the United Kingdom and Singapore, on privacy-preserving evaluations. Cryptographic methods can let you run evaluations or other functions on models without access to the model weights or the evaluation questions.
Technical tools might be available to verify different kinds of agreements. One challenge is that blunter methods are easier. If you wanted to pace the frontier by not running chips, it's easy to check whether a chip isn't running: If it's cold, it's not running. But literally not running the chips isn't going to happen.
There are technical methods under development, not necessarily ready yet, to verify whether a data center is running only inference, or at least 90 percent inference, rather than training.
If you wanted a temporary slowdown on training while running inference, that could be technically possible. It doesn't immediately stop the AI industry. There's a lot you can do and a lot of money you can make with inference.
There's a meme that nothing in AI is verifiable. Depending on what you're trying to achieve, technical methods could verify various properties.
Kevin Wolf (54:04): Two quick comments. On whether export controls are on the agenda, Secretary Bessent has publicly said they're not. Government friends I met on Friday said the topic isn't being discussed or raised; there are no talking points or issues.
The fact that it's even a question is fascinating. Historically, until this second Trump administration, export controls were never on that agenda. They weren't tools of transactionalism, leverage, or negotiation for another purpose. If a control accomplished a national-security or foreign-policy objective, it was imposed. Otherwise, it wasn't.
In government, under prior administrations, including the first Trump administration and Biden, we weren't included in these meetings because it wasn't a negotiable topic.
For the first time in export-control history, beginning with actions last June and the rare-earth affiliates-rule issue I mentioned, controls have become a topic of leverage and negotiation over whether to control something. That's novel.
Second, what are we trying to accomplish? That's unclear. Whether you agreed or not, Biden had a coherent view: AGI was a threat to humanity and democracy, and therefore to U.S. national security. The inputs should be regulated, particularly with respect to China, but also globally and in the Middle East: GPUs, HBM, and models above a certain threshold.
The government would decide case by case whether a use or user aligned with broader national-security objectives. Agree or disagree, it was a coherent objective articulated by Jake Sullivan in September 2022, and regulations thereafter implemented it.
We haven't heard the Trump administration's policy, philosophy, or evaluation of AI inputs. There have been individual actions, such as removing the UAE from controls and authorizing H200 licenses, but not as part of a grand strategy. That remains open, and I don't think we'll get an answer.
Ryan has written about different camps in the administration: the flood-the-zone camp, China hawks, and transactionalists. He can describe it better. There isn't a coherent worldview within the administration about broader objectives. That, plus the death of the National Security Council's interagency policy-development process, has led to uncertainty about what comes next or what objective export controls should work toward.
Closing
Glenn Parham (57:06): This has been an incredible discussion ahead of tomorrow. I'm sure Trump and Xi will have a very substantive debate about AI. That's sarcasm.
I hope these insights and perspectives have been helpful. I'm glad we've touched on evaluations as a potentially constructive vehicle for the United States and China to measure risk going forward. Thank you all for your time, and please join me in thanking our panelists.







