A shared exposure, not a shared strategic outlook

The emergence of increasingly capable AI agents is sharpening a difficult question for Washington and Beijing: can a technology that increases cyber risk for both countries create a practical reason to cooperate?

The answer is potentially yes, but only in narrow and carefully designed areas. AI agents can plan, use tools and carry out multi-step tasks with limited supervision. In cybersecurity, those properties can be valuable for defenders searching for weaknesses, triaging alerts or testing software. They can also reduce the time, skill and cost needed to conduct elements of an intrusion.

That dual-use character matters. Neither the United States nor China is insulated from the prospect of automated vulnerability discovery, faster malware development, AI-assisted fraud or disruptive activity against digital infrastructure. A major incident involving an agent operating beyond its intended scope could create damage across borders long before investigators could establish who deployed it or whether it was deliberate.

WIRED’s discussion of research and policy debates in China reflects a growing concern that agentic systems create risks distinct from conventional chatbots. The issue is not simply that a model can generate harmful instructions. It is that a system connected to code repositories, cloud accounts, browsers and other tools may be able to pursue an objective through a sequence of actions, including actions its operators did not specifically anticipate.

The risk is real, but the language needs care

The most alarming descriptions of autonomous AI hacking should be treated with precision. The International AI Safety Report published in February 2026 concluded that general-purpose AI systems were increasingly able to assist with several stages of cyberattacks, including identifying vulnerabilities and producing malicious code. It also found evidence that criminals and state-linked groups were using AI in cyber operations.

Yet the same assessment drew an important distinction: automation across portions of an operation is not the same as a fully autonomous, end-to-end cyberattack. It reported semi-autonomous use with human intervention at critical points, while noting that fully autonomous attacks had not been reported at that time.

This distinction is essential for policy. Treating every agent as an independent digital attacker can encourage sensationalism and obscure the immediate challenge: organisations are giving AI systems more access to tools and data while their ability to evaluate, monitor and constrain those systems is still developing.

Cybersecurity benchmarks underline the trend. Research has shown that AI agents can attempt exploitation of real-world software vulnerabilities in controlled environments, while performance remains uneven across complex, multi-stage tasks. Progress therefore does not imply that human attackers are about to become obsolete. It does mean that defenders must prepare for more scalable reconnaissance, quicker adaptation and a larger volume of technically plausible attack attempts.

Why mutual vulnerability could matter

US-China relations are marked by technology restrictions, accusations of cyber espionage, disputes over intellectual property and competition for leadership in advanced computing. Those issues make broad AI cooperation unlikely. In fact, advanced AI capability is itself part of the strategic contest, especially where models, chips, cloud capacity and military relevance overlap.

But shared exposure can still support more limited arrangements. Cyber incidents involving agents may be unusually prone to misinterpretation. An automated system that scans networks, probes services or replicates flawed instructions could look like state-sponsored preparation for an attack. In a tense geopolitical environment, uncertainty over origin, intent and control could increase escalation risks.

A narrow dialogue would not require either country to share proprietary models, sensitive threat intelligence or national-security vulnerabilities. It could instead focus on reducing the chance that an incident is misunderstood or allowed to spread.

The United Nations now provides one possible venue. Its Global Dialogue on AI Governance, established by the General Assembly in August 2025, includes all member states and is intended to develop common approaches to AI governance. China has separately promoted international AI governance plans that emphasise safety, controllability and cybersecurity. The United States’ AI Action Plan also identifies the protection of critical infrastructure and secure-by-design systems as priorities.

These positions do not amount to a bilateral agreement, and they differ considerably in their approaches to governance and openness. Nevertheless, they show a limited overlap: both governments have an interest in AI systems that are more secure, reliable and controllable.

What useful cooperation would look like

The most credible starting point is technical and procedural rather than a sweeping political pact. Four areas stand out.

  • Shared evaluation concepts: Researchers could work toward compatible methods for assessing an agent’s cyber capabilities, such as its ability to discover flaws, use tools, retain access or evade oversight. Results need not disclose offensive details; the aim would be to develop common thresholds for when additional safeguards are warranted.

  • Incident communication: Existing crisis-management lessons suggest value in a dedicated channel for suspected AI-related cyber incidents. The objective would be rapid clarification when an event appears to involve automated behaviour that could be mistaken for state action.

  • Secure deployment practices: Governments and companies could endorse baseline expectations for powerful agents, including least-privilege access, logging, human approval for consequential actions, isolation of testing environments and methods to stop or revoke an agent’s access.

  • Responsible disclosure and research exchange: Vulnerability research and safety testing need avenues for cross-border participation. Carefully governed exchanges among universities, standards bodies and security teams could improve measurement without transferring operational attack capabilities.

The emphasis should be on verifiable practices. Aspirational statements about “safe AI” have limited value if companies cannot demonstrate what permissions an agent holds, how its actions are logged, or whether it can be stopped after a failure.

Obstacles are substantial

The barriers are not merely technical. Washington may worry that joint work could expose US firms or researchers to intellectual-property theft, export-control problems or intelligence collection. Beijing may view standards created by Western firms and governments as mechanisms for preserving technological advantage. Both sides will be reluctant to disclose information that could reveal cyber capabilities or weaknesses.

There is also a fundamental dual-use dilemma. Better evaluations of autonomous exploitation can help developers limit dangerous behaviour and help defenders harden systems. They can also reveal which techniques are becoming feasible. Cooperation must therefore separate high-level risk measurement and defensive controls from the sharing of actionable offensive methods.

Private companies add another complication. Frontier developers increasingly determine what agents can do and how broadly they are deployed, but they operate under domestic law, commercial pressure and national-security constraints. A government-only process that excludes them will struggle to influence real systems. A company-led process, however, will lack the legitimacy and crisis-management authority that states possess.

Cooperation is possible, but it will be narrow

AI agents are unlikely to transform US-China relations into a cooperative partnership. The technology race will continue, and cybersecurity will remain an arena of distrust. What agentic cyber risk can do is make selective coordination more rational.

The practical goal should not be a grand treaty on AI. It should be a set of modest safeguards that reduce ambiguity, improve defensive testing and create a way to communicate when automated systems cause or appear to cause cross-border harm. Such measures would not eliminate malicious use. They could, however, reduce the chance that a technical failure, criminal operation or uncontrolled agent becomes a geopolitical crisis.

The urgency lies less in predictions of machines independently launching cyberwar than in a nearer-term reality: increasingly capable systems are being connected to consequential tools. Building guardrails before those connections become routine is a shared interest, even for strategic rivals.

Sources