China and the United States are the two world leaders in artificial intelligence, yet until now their formal dialogue on the topic has been limited. This is set to end with the first official U.S.-China AI dialogue under the Trump administration, scheduled for September this year. The discussions will likely be wide-ranging, covering chip supplies, data centre hosting, model usage permissions and safeguards against cyberattacks.

Washington is reportedly planning to raise the topic of Chinese firms renting U.S.-made compute resources from companies located outside China. On the other hand, China’s delegation is seeking answers about Anthropic’s frontier model Mythos. The company claims this model - which has been held back from public release - is exceptionally adept at identifying flaws in software, and so could pose threats to national security.

The meeting is expected to take place before Xi Jinping’s September 24 visit to the U.S., according to a July 21 report from Reuters, with Treasury Secretary Scott Bessent leading the American side.

China relies on offshore compute

The U.S. imposes export controls that restrict Chinese access to certain advanced American-designed AI chips. However, cloud access has remained a potential loophole, allowing Chinese companies to rent restricted computing capacity without taking ownership of the chips themselves.

Recent estimates suggest that American company Oracle supplies as much as 22.6% of China’s AI processing power through such arrangements. The firm recently announced a $6.5 billion investment in a Malaysian cloud compute hub, similar to the $2.1 billion pledged by Chinese firm ByteDance in 2024.

According to SemiAnalysis, these initiatives have made the Singapore-Johor-Batam cluster the second-largest AI hub in the world behind Northern Virginia. However, these measurements rely partly on estimates, as neither ByteDance nor Oracle publishes figures on the chip count across these facilities.

U.S. representatives are reportedly seeking to clamp down on Chinese use of restricted American technology in these facilities. On July 31, a Reuters report claimed that Chinese researchers had used American models to train their own system for military purposes, including cybersecurity and surveillance. Earlier that month, Bessent announced that "watermarks of our U.S. large language models" were showing up on Chinese-developed equivalents.

The concern is that this trend of offshore compute rental may undermine the U.S.’s competitive advantage or even pose national security risks.

Mythos is Beijing’s primary concern

The Chinese side is equally concerned with cybersecurity, but for an altogether different reason. As AI agents are proving increasingly adept at breaching live systems - with Anthropic’s own models attacking three organizations during a botched internal test last week - the cyber capabilities of America’s frontier AI models are in sharp focus.

Mythos Preview, Anthropic’s most powerful model to date, was released to trusted partners this April, allowing them to test it in real-world defensive cybersecurity conditions. It has reportedly identified over 10,000 vulnerabilities since then; web developer Mozilla used it to patch 271 flaws in its Firefox 150 browser.

Chinese firms have of course been given no such privileged access, raising concerns that the same AI model could compromise government and commercial systems. Chinese firm 360 Security Technology released an equivalent model in June that has reportedly identified 3,432 vulnerabilities in domestic systems, but concerns remain that Mythos is significantly more powerful.

In response, the Chinese government met with major domestic technology firms to discuss restricting U.S. access to the country’s own advanced models, according to a July 7 report from Reuters. These restrictions add another point of contention to the agenda for September’s talks.