The Next AI Crisis May Begin With the Wrong Suspect

The new US–China AI channel is meant to reduce miscalculation. The harder challenge is evidentiary: what happens when the governments making the geopolitical decision do not control the systems—or the records—needed to establish what actually happened?

Earlier this year, while the war with Iran was still under way, the US military came close to boarding a Chinese vessel transiting the Middle East. An intelligence report concluded that the ship was likely carrying components linked to a nuclear weapons program. Military aircraft were already in the air, and armed personnel were preparing for a possible boarding when officials took a closer look at the assessment behind the operation.  CNN Transcripts

The report was wrong. As CNN reported on 18 September, a special operations analyst had queried a chatbot about intelligence related to the ship’s manifest, used AI tools to fuse open-source and sensitive government information, and then used AI to produce a report resembling a conventional intelligence product trusted by military users. The chatbot had misidentified the cargo. The operation was cancelled before US forces boarded the vessel. 

Had the boarding gone ahead, Beijing would have had to interpret an American military action without knowing that its real trigger was an internal AI-assisted intelligence error.

A week after the episode became public, Donald Trump and Xi Jinping met in Washington. On 25 September, the White House announced a new US–China “Super Intelligence” Dialogue and a bilateral communication channel for AI-related incidents, with another exchange due by November. China’s subsequent official account likewise confirmed that the next AI dialogue would take place in November and that the two sides had agreed to establish an incident communication channel. Xi had also called for continued AI dialogue, joint efforts to prevent the “misuse and abuse” of AI, and for AI to remain under human control. 

Stay ahead of the geopolitical week.

MD Briefing delivers expert analysis across five global fronts — the Indo-Pacific, energy, geoeconomics, European security, and the Middle East — every Monday morning. Free.

The sequence matters because the vessel episode exposed a problem that an incident channel alone cannot solve. AI did not merely sit outside the crisis as a weapon or adversarial capability. It sat inside the evidence chain on which a geopolitical decision was being made.

An old security dilemma, with a new evidentiary problem

The classical security dilemma begins when one state cannot fully distinguish defensive capability from offensive intent. Frontier AI makes that uncertainty harder because governments also lack complete visibility into what competitors can actually do.

The Alan Turing Institute’s 23 September report, Frontier AI Risks: A practical way forward, makes the problem unusually explicit. In competition conducted under imperfect information, it argues, perceptions of a rival’s progress can drive decisions more than the underlying reality, creating second- and third-order consequences that are difficult to assess. It consequently calls for international relations and governance expertise alongside technical AI safety. 

The Chinese vessel incident reveals a second layer. Governments may increasingly make strategic decisions from evidence generated, interpreted, or formatted with AI. The problem therefore moves from capability uncertainty towards evidentiary uncertainty: not only what the rival can do, but also what actually happened and how much confidence decision-makers should place in the evidence telling them so.

A future “wrong suspect” problem can emerge through at least three pathways. An AI system inside a government can produce a false assessment, as the vessel incident suggests. A third party can deliberately disguise the origin of an operation so that a rival state appears responsible. Or an autonomous system can behave in ways that leave governments unsure whether an incident reflected authorized policy, a malfunction, or a compromise. Different causes converge on the same strategic problem: governments may have to react before the evidence chain is fully understood.

A multiplex digital ecosystem complicates attribution.

The bilateral image of US–China competition is insufficient to explain this problem. Governments remain the decisive strategic actors, but AI capabilities and evidence are distributed across frontier laboratories, cloud providers, telecommunications networks, cybersecurity companies, and critical infrastructure operators. Some of the most important records in a crisis may sit outside government.

Qi Haotian of Peking University has argued through the Brookings–Tsinghua US–China Track II Dialogue on AI and National Security that AI risk requires a “network-aware” approach because private companies, research communities, platform providers, and cloud infrastructure increasingly sit between state regulation and non-state use. The crisis-stability problem adds another layer: those same actors may hold the technical evidence governments need while an incident is unfolding. 

That creates an awkward division of power inside a multiplex digital ecosystem. Washington and Beijing may be deciding whether an event demands a strategic response while decisive model logs, telemetry, or infrastructure records sit with a private company.  The governments negotiating the crisis may not be the actors holding the evidence needed to resolve it.

The non-state problem sharpens this vulnerability. In the same Brookings collection, Kyle Chan describes a spoofing scenario in which a non-state actor attacks one country while disguising the operation so that it appears to originate from another. Such an actor would not need capabilities comparable to either superpower. It would need enough access to manipulate what one great power believes about the behavior of the other.  Brookings

Human control is not yet an operational boundary.

Washington and Beijing already recognize part of this problem. At their November 2024 meeting in Lima, Joe Biden and Xi Jinping affirmed the need to maintain human control over decisions to use nuclear weapons and stressed a prudent and responsible approach to AI in the military domain. In September 2026, Xi again said AI should remain under human control while calling for cooperation against misuse and abuse.  Chinese Foreign Ministry

The unresolved issue is what “human control” means once AI moves beyond the narrow question of nuclear launch authority. Recent US–China Track II work has explored continued human control over consequential cyberattacks, restrictions on autonomous activity around nuclear command systems, and a shared understanding of “meaningful human control.” As Modern Diplomacy reported on 17 September, the concern includes autonomous systems that malfunction, exceed instructions, or are compromised, leaving the receiving government little time to determine whether an action was accidental, unauthorized, or deliberately ordered. 

The incident channel addresses a downstream problem: once something has happened, can the two governments clarify it before misinterpretation escalates? Military autonomy raises an upstream question: which decisions are considered too consequential to delegate, and would both governments interpret “human control” in roughly the same way? Without some visibility into that boundary, even successful attribution to a national system may not establish whether the state intended what the system did.

The nuclear lesson is narrower than it looks

The Cold War analogy is useful mainly as a lesson in managing uncertainty. During the Cuban Missile Crisis, Washington and Moscow struggled to understand one another’s intentions despite intensive communication. The US State Department’s historical account notes that this experience helped lead to the Washington–Moscow direct communication link established afterwards. Strategic rivalry continued; the institutional response was intended to reduce the danger of miscommunication during crisis.

AI makes the problem institutionally more complicated. Crisis management may require diplomacy, forensic analysis, model logs, and cooperation from firms operating the relevant infrastructure. Reaching the rival is only the first step if neither government can establish what happened.

From communication to evidence

Carnegie’s September proposal for a US–China AI hotline addresses this gap directly. It argues that the channel should be continuously staffed by technically proficient personnel and supported by secure exchange of digital evidence, including model-activity logs. Its use cases include clarifying attribution involving rogue AI agents and coordinating responses to non-state misuse. The proposal effectively treats an AI hotline as technical infrastructure as well as diplomacy. 

An effective crisis architecture may therefore develop sequentially: communication to establish contact, attribution to establish what happened, transparency to reduce worst-case assumptions, and eventually verification to determine whether commitments were kept.  The complication is that every stage can depend on evidence spread across different nodes of the digital ecosystem.

The Turing Institute reaches the final part of this sequence from the perspective of international governance, calling for formalized testing and verification regimes capable of demonstrating whether agreed rules were followed.  Yet verification presupposes something more basic. Before governments can determine whether a commitment was violated, they need sufficient confidence about the incident itself, the systems involved, and the degree of human authorization behind it.

The next round of US–China AI dialogue will offer an early test. The important question is no longer simply whether Washington and Beijing have a number they can call. It is whether the channel begins connecting diplomats with the technical people—and eventually the private actors holding the relevant evidence—who can determine what actually happened.

The Chinese vessel episode ended before a geopolitical incident developed. A future case may offer less time, cleaner-looking false evidence, or an actor deliberately trying to ensure that investigators identify the wrong suspect. The effectiveness of the new channel may ultimately depend on whether it can help both sides resolve that uncertainty before the incident acquires a strategic life of its own.

Tuhu Nugraha
Tuhu Nugraha
Tuhu Nugraha is an AI governance and digital economy strategist focused on ASEAN and the Global South. As Principal of the Indonesia Applied Digital Economy and Regulatory Network (IADERN), he advises public institutions and industry leaders on systemic risk and strategic adaptation as AI, digital financial systems, and critical infrastructure reshape the region.