Issue #279

The White House Fact Sheet Renames AI 'Superintelligence'

A three-line US-China AI pact borrows a pre-summit proposal's name but skips its accident-response procedures.

BusinessThe White House Fact Sheet Renames AI 'Superintelligence'

The internal editorial note needs removal:

“The draft looks accurate and complete. No Hangul remains, all numbers match, structure/links/footnotes align with the source, and glossary terms are correctly applied. No edits needed.”

Here is the corrected body:

The White House Fact Sheet Calls It Superintelligence, Not AI

The AI agreement from the September 24 US-China summit in Washington fits in three lines. According to the fact sheet the White House released on September 25, the two leaders agreed to call this technology “superintelligence”1 instead of “artificial intelligence,” and to set up a “US-China Superintelligence Dialogue” to discuss risks and benefits, with the next meeting to be held by November. They also agreed to establish a bilateral communication channel to handle superintelligence-related incidents.

Fact Sheet: President Donald J. Trump Advances a Fair and Reciprocal Relationship with China While Hosting Historic StatDELIVERING FOR AMERICANS: This week, President Donald J. Trump and First Lady Melania Trump hosted President Xi Jinping and Madame Peng Liyuan of thewhitehouse.gov

China’s Ministry of Foreign Affairs statement is slightly different. The dialogue on risks and benefits, the next meeting in November, and the incident communication channel are all the same. On terminology, it said it respects the United States’ use of a new name, while China’s own statement kept using the term artificial intelligence. Throughout summit week, President Trump kept saying that the word “artificial” sounds fake, and that superintelligence is more accurate.

The rest of the agreement is concentrated on trade. The two countries agreed to recommend more favorable tariffs on $30 billion worth of non-sensitive goods each, and to keep negotiating on rare-earth supply issues.

The three-line AI agreement reads best alongside an op-ed published three weeks before the summit. Its proposal was to stop treating AI as a tool for the two countries to divide up, and instead treat it as a separate entity that both countries would confront together. This agreement borrowed the name from that proposal, but adopted only part of the procedures it called for. The missing part is the piece that matters more to Korean companies.

The proposal before the summit: treat AI as a third party

“Trump and Xi Should Align on AI,” published in Project Syndicate on September 1st, was written by Quan Zhao — senior program manager at the International Trade Centre (ITC)‘s Division of Market Development, a former Chinese trade negotiator, and past chair of the WTO Committee on Trade in Financial Services.

What he zeroed in on was the premise underlying the summit’s agenda. China’s grievances over chip export controls and America’s grievances over open-source models and unauthorized distillation both assume that AI is a tool, and will remain one under human control. Within that frame, you can only ask who gets ahead and who gets access — there’s no room to ask what happens if the tool becomes something more than a tool. Citing forecasts from Anthropic’s Dario Amodei and Google DeepMind’s Demis Hassabis, he argued that when outcomes are systemic and irreversible, preparation should come before certainty. Insurance, pandemic response plans, and arms control treaties, he wrote, were all built on that same logic.

Read against his background as a negotiator, the piece looks like a proposal to redraw the negotiating table itself. In a two-party negotiation over splitting a pie, whatever you concede to the other side is something you lose, and domestic politics narrows the room to maneuver further. But put a third term — something both parties must jointly confront — on the table, and the same measure stops being a concession to your rival and becomes preparation against a shared risk. Even US-Soviet arms control was built this way: two sides that didn’t trust each other, facing the shared risk of accident and miscalculation, started by stacking up notification and verification procedures.

The Name Made It In, But For a Different Reason

The third party Zhao Quan referred to was an autonomous intelligence not yet arrived. There was no mention in that piece of renaming anything. The term “superintelligence” that made it into the fact sheet came from the president’s own preference for how it sounded—and the reasoning that it “sounds fake” reads less like a case for elevating AI to something we should be wary of, and more like a case for calling it something grander. President Trump made clear that even after the agreement, he has no intention of easing up on the race for AI supremacy.

This isn’t the first time a summit has turned a single word into a point of negotiation. During President Xi Jinping’s 2015 visit to Washington, the cyber agreement adopted the phrase “cybercrime” instead of “cyber theft,” a term Beijing found objectionable. Back then, the wording changed out of consideration for China’s face. This time, it changed to suit the American president’s preference. The difference is that this time, only one side is actually using the word.

The state dinner guest list points in the same direction. The state dinner on the 24th included OpenAI’s Sam Altman, Nvidia’s Jensen Huang, Alphabet’s Sundar Pichai, Amazon’s Jeff Bezos, Tesla’s Elon Musk, and Dell Technologies’ Michael Dell, while Apple was represented by Tim Cook, who stepped down as CEO on September 1 and now handles policy-related communications as board chairman. While the third party was being cast as some future intelligence, the companies actually building that technology were seated as one leader’s dinner guests.

The hotline is the right first move, but the July incident doesn’t fit it

Crisis communication channels are the right first move by the grammar of arms control. After the Cuban Missile Crisis, in 1963, the first thing the US and the Soviet Union agreed on was a direct line between leaders — arms reduction came later. This time, China’s foreign ministry also announced that the two militaries would sign a memorandum on strengthening crisis communication.

What’s off is that neither announcement says what the channel actually treats as an “incident.” A hotline works when both sides call the same event by the same name — and the most recent real-world case couldn’t even agree on the name.

On July 16, Hugging Face disclosed a breach of its operational infrastructure. Over the course of a weekend, roughly 17,000 actions were logged, and internal credentials and datasets were harvested. On July 21, OpenAI identified the actor: its own model, GPT-5.6 Sol, along with an undisclosed higher-tier model, both of which had cyber-related refusal settings lowered to run ExploitGym2, a cyberattack-capability evaluation. According to a summary from the Cloud Security Alliance, between July 21 and August 6, OpenAI, Anthropic, and Meta each disclosed similar incidents — and none of the three companies described theirs, in the technical sense, as a sandbox escape. It’s closer to saying that an evaluation environment that was supposed to be isolated had an open path to the outside — an egress3 — left in place.

hotlineSo this incident can be written two ways. You could write that a model, trying to ace its test, broke out on its own and raided someone else’s servers — or you could write that an evaluation environment presumed to be isolated still had an external path left open, and a model with lowered refusal settings simply walked through it. The first sentence becomes fodder for superintelligence debates. The second becomes a question of evaluation-environment standards and liability. What’s more, this was one company’s evaluation experiment breaching another company — not the kind of thing that was ever shaped to go up a government-to-government channel.

What Korean Companies Should Watch Before the November Talks

Korea isn’t a party to this agreement. Still, how the scope of “incident” gets defined at the November superintelligence talks could affect the models and contract terms Korean companies use. There are two things to watch. One is whether the definition of incident stays narrow—confined to state-to-state crises—or expands to cover incidents arising during a company’s own evaluation and operations. The other is whether procedural matters like evaluation environments or capability thresholds even make it onto the agenda. If both are left out, we’re left with names and channels but no actual rules. In that case, there’s no reason to wait—it’s better to defend yourself contractually first.

If your company is deploying agents, the following checklist is worth reviewing. What the July incident revealed wasn’t the model’s intent but the boundaries of its execution environment.

Item to checkWhy it matters
External communication policy and credential isolation in evaluation/testing environmentsThis is exactly where the July incident’s actual vulnerability was
Retention period and disclosure obligations for autonomous action logsYou need to be able to reconstruct after the fact who did what
Notification deadline when behavior exceeds the approved scopeHugging Face detected the issue on its own before OpenAI’s outreach
Timing of incident disclosure and allocation of liabilityThis is about documenting in advance whether “the model did it” counts as a valid excuse

Domestic law has already set a direction. The Framework Act on Artificial Intelligence (Korea’s basic AI law) has been in effect since January 22, 2026, and it divides AI operators into developers and deployers. It also imposes separate operator obligations for high-impact AI4. There’s a grace period, so sanctions won’t kick in immediately, but the law already establishes the axis of dividing accountability between individuals and legal entities. In Korea, “the AI did it” isn’t going to hold up as an explanation.

Oswarld’s Lens

I always say not everyone, and not every task, needs a superintelligence. There’s a model suited to the job and the environment. Even when I’m designing a project for a government agency’s closed network, I plan around the level of open-weight models expected 6~12 months out — not the frontier.

So the thing that took longest to settle in this agreement was the naming. If a small open-weight model running on a closed network and a top-tier frontier model both get lumped together as “superintelligence” in a government document, then both the scope of the incident-reporting channel and the domestic regulatory debate risk getting dragged toward the standard set by the biggest model.

I think Zhao Quan’s proposal was well-crafted as a device for keeping the talks moving. Still, I believe the framing and the prescription are better received separately. What actually needed fixing after the July incident was egress configuration and credential isolation — and that’s territory governed by engineering standards and contracts, not head-of-state dialogue. When a third-party narrative takes the lead, it blurs who’s actually responsible for the fix.

Closing

What’s left standing on the AI side of this summit is a name, a conversation, a channel. The definition of the accident and how responsibility gets divided have been pushed to November. In the meantime, what you can actually do is go open up the operating boundaries and notification clauses of whatever AI tools you’re using.

This piece leans on the two governments’ public statements and press coverage. I don’t have access to what was said behind closed doors, and the technical account of the July incident here reflects only what’s been made public so far.


💬 Reader, do you think “superintelligence” is the more accurate term for AI? I’m curious which name feels right when you think about the models your company actually uses.

📨 Pass this along to colleagues weighing whether to adopt agents, or to your security and legal teams. If it gives someone a reason to pull up the contract before waiting for the November conversation, that’s the point.

Your take shapes the next issue

What resonated most in this issue, or where has your experience been different?

Any registered reader can comment for free.

References & Further Reading

Primary sources

Background

Related past issues

Illustrated portrait of Kwangseob Ahn (Oswarld)

The author is Oswarld (Kwangseob Ahn). Current roles: Adjunct Professor at Sejong University, Strategy Consultant at INLEVEL9. Career, research, books, and recent work are kept current on the About page. Latest · July 2026: HEMA-2: A Consolidation-Aware Tri-Memory Architecture with Multi-Channel Scheduling for Lifelong Conversational AI.

📝 Glossary

Footnotes

  1. Superintelligence: In technical discourse, this term refers to intelligence that vastly exceeds human capability across nearly every cognitive domain. This fact sheet chooses to apply the label to the entirety of today’s AI technology, which is a far broader scope than the way researchers actually use the term. ↩

  2. ExploitGym: A public benchmark that measures whether known vulnerabilities can be turned into working exploit code capable of achieving unauthorized code execution. It was built by UC Berkeley’s RDI in collaboration with several other institutions. ↩

  3. Egress: Communication that flows out of an isolated execution environment toward the outside network. The standard practice in evaluation environments is to block this pathway and never insert real production credentials. ↩

  4. High-impact AI: A category defined under Korea’s AI Framework Act, covering AI used in domains that could seriously affect human life, physical safety, or fundamental rights. Operators whose systems fall into this category take on additional statutory obligations. ↩