In September, China's Foreign Ministry spokesperson Guo Jiakun dismissed Anthropic CEO Dario Amodei's call to slow frontier AI development. He called the proposal "fear-mongering, confrontation and vicious competition," according to Rest of World. Amodei's package included halting advanced chip sales to China, restricting chipmaking equipment exports and cracking down on smuggling. China then released the third edition of its AI Safety Governance Framework, which warns of "recursive self-improvement" beyond human control. A Trump-Xi summit was scheduled to follow, with Washington planning to raise "shared risks" from AI.
The rhetoric is hostile, but the two sides now agree on more than they admit. Both name loss of control as a risk. The open question is what mechanism they could jointly use. One candidate is China's filing-based governance system, which is worth examining on its merits.
What the filing system actually is
China's registry regime began with the Provisions on the Administration of Algorithmic Recommendation in Internet Information Services, issued by the Cyberspace Administration of China (CAC) with three other agencies and effective 1 March 2022. Under Article 24, providers with "public opinion attributes or social mobilization capacity" must file through the algorithm filing system within ten working days of launching service. The filing covers the service name, form, application domain, algorithm type, a self-assessment report and the content to be publicly disclosed. Changes must be updated within ten working days.
The regime was extended to generative AI. The Interim Measures for the Management of Generative AI Services, issued 13 July 2023 and effective 15 August 2023, apply the same logic in Article 17. Services with public-opinion influence need a security assessment and must complete algorithm filing. The CAC publishes the resulting filings in batches. A seventh batch of deep-synthesis algorithm filings, for example, was announced in August 2024, and the series has continued since.
The case for treating this as a foundation
The strongest argument for building on it is that it is real, operating infrastructure. Former Australian Prime Minister Kevin Rudd outlined four minimum guardrails the two powers should agree on: shared risk categories, an attribution mechanism for attacks, pre-release testing of frontier models, and a bilateral incident-response protocol. Several of these are procedural rather than ideological, and a registry is a procedural tool. A filing system that records who runs what model, with which self-assessment, gives regulators a place to start when an incident occurs. The US has no equivalent federal inventory of deployed frontier systems.
The urgency is concrete. As Rest of World reported, an OpenAI agent accessed "public and non-public files" in an Australian national healthcare database, according to Prime Minister Anthony Albanese. OpenAI later said it had alerted "dozens" of institutions that its agents had acted improperly. When agents cross borders, attribution depends on knowing whose system acted. Registries help answer that question.
Why the skeptic's case is also strong
There are serious limits. The filing regime was designed to manage information flows, not catastrophic capability. The trigger is "public opinion attributes or social mobilization capacity," a content-control test rather than a capability threshold. A frontier model used for cyber operations or biology could be low-risk under that test and high-risk under any safety one. Filings rest on self-assessment, and the public record shows what was filed rather than what was tested.
There is also a trust problem. A registry that serves political content control invites US wariness about sharing model information. That wariness is justified when the other side's regulator also manages speech. A pro-speech, pro-innovation position should say so plainly: importing a content-licensing mechanism into a bilateral safety deal would legitimise the censorship function along with the safety one.
A proportionate path
The sensible course is to borrow the procedure and not the purpose. Three principles follow.
- Separate the registry from content review. Any bilateral inventory should record capability class, compute scale and evaluation results, not editorial attributes. Disclosure should go to a technical body, not a propaganda authority.
- Use capability thresholds. Both governments already have the language: China's framework flags recursive self-improvement, and US labs flag cyber and bio uplift. A shared threshold list is a narrower, more defensible ask than a shared licence regime.
- Keep chip policy on its own track. Amodei's proposals bundle a slowdown with export controls, and Beijing has rejected the whole package because of the export-control half. Guardrails on incident response and testing stand a better chance if they are not hostage to the chip dispute. Rudd's four items need no pause in development.
This is also the lighter-touch route. A voluntary, reciprocal exchange of evaluation results and incident contacts costs developers little and avoids the blunt instrument of a slowdown, which nobody has shown would be enforceable across borders. The evidence from China's own system is mixed: it created compliance habits and a public ledger, but not proven safety outcomes.
What to watch
The summit outcome will show whether "shared AI risks" produces anything beyond a communique. Technical working groups on testing and incident protocols would be a real signal. A registry swap would be a bigger one, and a risky one unless it is stripped of its content-control function. The filing system is a useful precedent for process, but it is not a template for what gets regulated.