A proposed international alert needs operational evidence
The United States has proposed a notification mechanism with China for artificial-intelligence incidents reaching national-security significance.
US Treasury Secretary Scott Bessent described the proposal after talks with Chinese Vice-Premier He Lifeng in New York on 20 September 2026. He said the aim was greater transparency between the two largest AI powers and that the countries had agreed to continue their AI dialogue.
No bilateral mechanism has yet been agreed. China's public response to the specific proposal remains unclear, and no common definition of a reportable incident, threshold, evidence standard or disclosure process has been published.
The proposal is nevertheless important. It recognises that serious AI incidents may cross borders, affect critical infrastructure or create risks that neither country can manage through complete opacity.
It also raises an operational question: what evidence must exist before a government can issue a credible incident notification?
Notification begins inside the affected system
An international channel operates after an organisation has identified something reportable.
A conventional activity log may contain fragments of the required history. It may not connect them into a reliable account.
Without that connection, an incident notification risks becoming a narrative assembled after the event rather than evidence preserved during it.
- Which system produced or requested the relevant action?
- Which model, agent and service version were involved?
- What information informed the action?
- What authority was available?
- Did a control allow, alter, escalate or stop the proposal?
- What instruction reached the executing system?
- What did the system report as the resulting effect?
A common threshold needs comparable evidence
The phrase "national-security-level incident" does not yet have a published bilateral definition.
The two countries may classify systems, harms and security interests differently. They may also have legitimate restrictions on the information they can disclose.
A workable mechanism would therefore need more than agreement to communicate. It would require some shared understanding of what makes an incident reportable, when the reporting obligation begins, which facts must be preserved, how uncertainty and disputed attribution are represented, how corrections are linked to earlier reports and how recipients verify integrity without demanding unrestricted access to sensitive systems.
This does not require the two countries to share models, source code or complete operational records. It does require evidence capable of supporting bounded claims.
Evidence of authority and evidence of effect are different
Suppose an autonomous system proposes a consequential change affecting critical infrastructure.
A record showing that the change was authorised does not prove that it became effective. Telemetry showing that the system changed does not prove that the change was authorised.
A credible incident account may need to connect the governed evaluation of the proposed action with trusted evidence from the executing system describing the resulting effect.
That distinction matters when investigators need to determine whether the failure concerned intelligence, authority, enforcement, execution or reporting.
Transparency does not mean unlimited disclosure
National-security reporting inevitably involves information that cannot be exchanged openly.
The objective should therefore be sufficient evidence for a defined claim—not wholesale disclosure of sensitive architecture.
A notification might establish that a particular action class was attempted, the action exceeded its available authority, a control returned a specified intervention, the executor nevertheless reported an inconsistent effect and the preserved records have not been silently substituted.
It need not reveal every underlying prompt, policy rule, dataset, credential or security control.
PF Systems' bounded relevance
PF Systems' relevant proposition is organisational rather than diplomatic.
PF Memory provides governed context. PF Kernel evaluates the proposed action. PF Core preserves linked evidence of that evaluation. ClientBridge connects downstream systems without inheriting Kernel authority, while PF Trace can display the resulting evidence.
Trusted executor evidence remains necessary to establish what became effective.
PF Systems does not determine international attribution, guarantee system safety or establish compliance with any future reporting regime.
A suitable discovery exercise would use synthetic incidents to test whether an organisation could reconstruct a bounded, attributable account without disclosing unnecessary sensitive information.
The proposed US–China mechanism remains at an early political stage. A future formal agreement or specification could materially change the reporting requirements and would need fresh assessment.
The practical lesson is already clear: international AI transparency can only be as credible as the operational evidence organisations preserve before notification becomes necessary.
Sources
Public sources supporting the factual statements in this perspective. Reported statements and company or vendor-reported results are identified in the article.
