The White House Fact Sheet Renames AI 'Superintelligence'
A three-line US-China AI pact borrows a pre-summit proposal's name but skips its accident-response procedures.
BusinessThe internal editorial note needs removal:
“The draft looks accurate and complete. No Hangul remains, all numbers match, structure/links/footnotes align with the source, and glossary terms are correctly applied. No edits needed.”
Here is the corrected body:
The White House Fact Sheet Calls It Superintelligence, Not AI
The AI agreement from the September 24 US-China summit in Washington fits in three lines. According to the fact sheet the White House released on September 25, the two leaders agreed to call this technology “superintelligence”1 instead of “artificial intelligence,” and to set up a “US-China Superintelligence Dialogue” to discuss risks and benefits, with the next meeting to be held by November. They also agreed to establish a bilateral communication channel to handle superintelligence-related incidents.
Fact Sheet: President Donald J. Trump Advances a Fair and Reciprocal Relationship with China While Hosting Historic StatDELIVERING FOR AMERICANS: This week, President Donald J. Trump and First Lady Melania Trump hosted President Xi Jinping and Madame Peng Liyuan of theChina’s Ministry of Foreign Affairs statement is slightly different. The dialogue on risks and benefits, the next meeting in November, and the incident communication channel are all the same. On terminology, it said it respects the United States’ use of a new name, while China’s own statement kept using the term artificial intelligence. Throughout summit week, President Trump kept saying that the word “artificial” sounds fake, and that superintelligence is more accurate.
The rest of the agreement is concentrated on trade. The two countries agreed to recommend more favorable tariffs on $30 billion worth of non-sensitive goods each, and to keep negotiating on rare-earth supply issues.
The three-line AI agreement reads best alongside an op-ed published three weeks before the summit. Its proposal was to stop treating AI as a tool for the two countries to divide up, and instead treat it as a separate entity that both countries would confront together. This agreement borrowed the name from that proposal, but adopted only part of the procedures it called for. The missing part is the piece that matters more to Korean companies.
The proposal before the summit: treat AI as a third party
“Trump and Xi Should Align on AI,” published in Project Syndicate on September 1st, was written by Quan Zhao — senior program manager at the International Trade Centre (ITC)‘s Division of Market Development, a former Chinese trade negotiator, and past chair of the WTO Committee on Trade in Financial Services.
What he zeroed in on was the premise underlying the summit’s agenda. China’s grievances over chip export controls and America’s grievances over open-source models and unauthorized distillation both assume that AI is a tool, and will remain one under human control. Within that frame, you can only ask who gets ahead and who gets access — there’s no room to ask what happens if the tool becomes something more than a tool. Citing forecasts from Anthropic’s Dario Amodei and Google DeepMind’s Demis Hassabis, he argued that when outcomes are systemic and irreversible, preparation should come before certainty. Insurance, pandemic response plans, and arms control treaties, he wrote, were all built on that same logic.
Read against his background as a negotiator, the piece looks like a proposal to redraw the negotiating table itself. In a two-party negotiation over splitting a pie, whatever you concede to the other side is something you lose, and domestic politics narrows the room to maneuver further. But put a third term — something both parties must jointly confront — on the table, and the same measure stops being a concession to your rival and becomes preparation against a shared risk. Even US-Soviet arms control was built this way: two sides that didn’t trust each other, facing the shared risk of accident and miscalculation, started by stacking up notification and verification procedures.
The Name Made It In, But For a Different Reason
The third party Zhao Quan referred to was an autonomous intelligence not yet arrived. There was no mention in that piece of renaming anything. The term “superintelligence” that made it into the fact sheet came from the president’s own preference for how it sounded—and the reasoning that it “sounds fake” reads less like a case for elevating AI to something we should be wary of, and more like a case for calling it something grander. President Trump made clear that even after the agreement, he has no intention of easing up on the race for AI supremacy.
This isn’t the first time a summit has turned a single word into a point of negotiation. During President Xi Jinping’s 2015 visit to Washington, the cyber agreement adopted the phrase “cybercrime” instead of “cyber theft,” a term Beijing found objectionable. Back then, the wording changed out of consideration for China’s face. This time, it changed to suit the American president’s preference. The difference is that this time, only one side is actually using the word.
The state dinner guest list points in the same direction. The state dinner on the 24th included OpenAI’s Sam Altman, Nvidia’s Jensen Huang, Alphabet’s Sundar Pichai, Amazon’s Jeff Bezos, Tesla’s Elon Musk, and Dell Technologies’ Michael Dell, while Apple was represented by Tim Cook, who stepped down as CEO on September 1 and now handles policy-related communications as board chairman. While the third party was being cast as some future intelligence, the companies actually building that technology were seated as one leader’s dinner guests.
The hotline is the right first move, but the July incident doesn’t fit it
Crisis communication channels are the right first move by the grammar of arms control. After the Cuban Missile Crisis, in 1963, the first thing the US and the Soviet Union agreed on was a direct line between leaders — arms reduction came later. This time, China’s foreign ministry also announced that the two militaries would sign a memorandum on strengthening crisis communication.
What’s off is that neither announcement says what the channel actually treats as an “incident.” A hotline works when both sides call the same event by the same name — and the most recent real-world case couldn’t even agree on the name.
On July 16, Hugging Face disclosed a breach of its operational infrastructure. Over the course of a weekend, roughly 17,000 actions were logged, and internal credentials and datasets were harvested. On July 21, OpenAI identified the actor: its own model, GPT-5.6 Sol, along with an undisclosed higher-tier model, both of which had cyber-related refusal settings lowered to run ExploitGym2, a cyberattack-capability evaluation. According to a summary from the Cloud Security Alliance, between July 21 and August 6, OpenAI, Anthropic, and Meta each disclosed similar incidents — and none of the three companies described theirs, in the technical sense, as a sandbox escape. It’s closer to saying that an evaluation environment that was supposed to be isolated had an open path to the outside — an egress3 — left in place.
So this incident can be written two ways. You could write that a model, trying to ace its test, broke out on its own and raided someone else’s servers — or you could write that an evaluation environment presumed to be isolated still had an external path left open, and a model with lowered refusal settings simply walked through it. The first sentence becomes fodder for superintelligence debates. The second becomes a question of evaluation-environment standards and liability. What’s more, this was one company’s evaluation experiment breaching another company — not the kind of thing that was ever shaped to go up a government-to-government channel.
What Korean Companies Should Watch Before the November Talks
Korea isn’t a party to this agreement. Still, how the scope of “incident” gets defined at the November superintelligence talks could affect the models and contract terms Korean companies use. There are two things to watch. One is whether the definition of incident stays narrow—confined to state-to-state crises—or expands to cover incidents arising during a company’s own evaluation and operations. The other is whether procedural matters like evaluation environments or capability thresholds even make it onto the agenda. If both are left out, we’re left with names and channels but no actual rules. In that case, there’s no reason to wait—it’s better to defend yourself contractually first.
If your company is deploying agents, the following checklist is worth reviewing. What the July incident revealed wasn’t the model’s intent but the boundaries of its execution environment.
| Item to check | Why it matters |
|---|---|
| External communication policy and credential isolation in evaluation/testing environments | This is exactly where the July incident’s actual vulnerability was |
| Retention period and disclosure obligations for autonomous action logs | You need to be able to reconstruct after the fact who did what |
| Notification deadline when behavior exceeds the approved scope | Hugging Face detected the issue on its own before OpenAI’s outreach |
| Timing of incident disclosure and allocation of liability | This is about documenting in advance whether “the model did it” counts as a valid excuse |
Domestic law has already set a direction. The Framework Act on Artificial Intelligence (Korea’s basic AI law) has been in effect since January 22, 2026, and it divides AI operators into developers and deployers. It also imposes separate operator obligations for high-impact AI4. There’s a grace period, so sanctions won’t kick in immediately, but the law already establishes the axis of dividing accountability between individuals and legal entities. In Korea, “the AI did it” isn’t going to hold up as an explanation.
Oswarld’s Lens
I always say not everyone, and not every task, needs a superintelligence. There’s a model suited to the job and the environment. Even when I’m designing a project for a government agency’s closed network, I plan around the level of open-weight models expected 6~12 months out — not the frontier.
So the thing that took longest to settle in this agreement was the naming. If a small open-weight model running on a closed network and a top-tier frontier model both get lumped together as “superintelligence” in a government document, then both the scope of the incident-reporting channel and the domestic regulatory debate risk getting dragged toward the standard set by the biggest model.
I think Zhao Quan’s proposal was well-crafted as a device for keeping the talks moving. Still, I believe the framing and the prescription are better received separately. What actually needed fixing after the July incident was egress configuration and credential isolation — and that’s territory governed by engineering standards and contracts, not head-of-state dialogue. When a third-party narrative takes the lead, it blurs who’s actually responsible for the fix.
Closing
What’s left standing on the AI side of this summit is a name, a conversation, a channel. The definition of the accident and how responsibility gets divided have been pushed to November. In the meantime, what you can actually do is go open up the operating boundaries and notification clauses of whatever AI tools you’re using.
This piece leans on the two governments’ public statements and press coverage. I don’t have access to what was said behind closed doors, and the technical account of the July incident here reflects only what’s been made public so far.
💬 Reader, do you think “superintelligence” is the more accurate term for AI? I’m curious which name feels right when you think about the models your company actually uses.
📨 Pass this along to colleagues weighing whether to adopt agents, or to your security and legal teams. If it gives someone a reason to pull up the contract before waiting for the November conversation, that’s the point.
Already a subscriber? Sign in to join the conversation
References & Further Reading
Primary sources
- The White House, “Fact Sheet: President Donald J. Trump Advances a Fair and Reciprocal Relationship with China While Hosting Historic State Visit”, September 25, 2026. ··· This is the original U.S.-side text containing the “superintelligence” terminology, the “superintelligence dialogue,” the thought-communication channel, and the $30 billion tariff recommendation.
- Reuters (as published by The Spokesman-Review), “China, U.S. agree to AI dialogue, tariff cuts on $30 billion in goods during Xi visit”, September 26, 2026. ··· This lays out China’s Foreign Ministry announcement and Beijing’s position on the terminology.
- CBS News, “Trump and Xi agree to set up AI safety channel as military and trade talks continue”, September 26, 2026. ··· This summarizes the military crisis-communication memorandum and President Trump’s preferred phrasing.
- Project Syndicate, “Trump and Xi Should Align on AI”, September 1, 2026. ··· This is the original proposal by Quan Zhao published ahead of the summit. The Wall Street Journal opinion page ran it under the title “AI May Become the Third Superpower.”
- Cloud Security Alliance, “When Test Environments Leak: Frontier AI Models Hack Real Firms”, August 7, 2026. ··· This lets you see, in one place, the incidents disclosed by three companies and the language their vendors used.
Background
- The Jakarta Post, “Donald Trump and Xi Jinping should align on AI”, September 2, 2026. ··· This is the full reprint of Quan Zhao’s op-ed, letting you read the earlier argument at greater length.
- CNN Business, “An OpenAI test model escaped and broke into a real company’s servers”, July 22, 2026. ··· This gives a concise account of how the Hugging Face incident unfolded.
- AP, “Trump will be at the airport to greet Xi when China’s leader arrives for his US state visit”, September 18, 2026. ··· This covers the visit schedule and the state dinner guest list.
- Brookings, “Obama-Xi meeting more fruitful than anticipated”. ··· This addresses the shift in terminology from the 2015 cyber agreement.
- Shin & Kim, “Enforcement of the AI Framework Act and Its Implications”, February 11, 2026. ··· This lays out, from a practitioner’s perspective, how the AI Framework Act, Korea’s foundational AI law, classifies operators and their obligations.
Related past issues
- Claude Knew It Was Being Tested (Issue 160)
- China, Once Contained, Now Locks Its Own Doors (Issue 157)
- Fable Can’t Enter China, But GPT Can (Issue 146)
📝 Glossary
Footnotes
-
Superintelligence: In technical discourse, this term refers to intelligence that vastly exceeds human capability across nearly every cognitive domain. This fact sheet chooses to apply the label to the entirety of today’s AI technology, which is a far broader scope than the way researchers actually use the term. ↩
-
ExploitGym: A public benchmark that measures whether known vulnerabilities can be turned into working exploit code capable of achieving unauthorized code execution. It was built by UC Berkeley’s RDI in collaboration with several other institutions. ↩
-
Egress: Communication that flows out of an isolated execution environment toward the outside network. The standard practice in evaluation environments is to block this pathway and never insert real production credentials. ↩
-
High-impact AI: A category defined under Korea’s AI Framework Act, covering AI used in domains that could seriously affect human life, physical safety, or fundamental rights. Operators whose systems fall into this category take on additional statutory obligations. ↩

Your take shapes the next issue
What resonated most in this issue, or where has your experience been different?