BLOG

The Power to Define AI Safety: On the Same Day, Three Parties Define 'AI Danger'

Kael Zhang
AI SafetyAI GovernanceChina-US Tech
广告 · Advertisement

Opening: In Forty-Eight Hours, Three Types of People Rush to Define “AI Danger”

From September 14 to 17, in a window of just over forty-eight hours, three types of people who normally wouldn’t sit at the same table spoke out one after another on the same issue: Is AI dangerous or not, where is the danger, and who should regulate it. On September 14, Trump publicly called the discussion of AI risks a “sick conspiracy” and a “scam.” On September 17, UN Secretary-General Guterres called for global cooperation to set guardrails for AI during the UN General Assembly. On the same day sandwiched in between, Microsoft AI CEO Mustafa Suleyman’s remarks about the competing product Claude were placed by Caixin in the headline spot of the September 17 T Morning Post. And looking further back, the New York Times Chinese Edition published a signed column on September 17; the author, Seth Center, a former U.S. State Department special envoy who co-led the first round of U.S.-China AI dialogue in May 2024—wrote an even more blunt headline: “China Doesn’t Care About AI Safety, It Just Wants to Win.”

A former diplomat discusses security at the negotiating table, the UN discusses security within a multilateral framework, and a tech company executive discusses security regarding a competitor’s product. All three are talking about “security,” but they are not talking about the same thing at all. The main thread of this issue is just one sentence: AI safety has never been a technical consensus; it is the power of definition—whoever defines danger holds all the subsequent negotiations, legislation, and budgets in their hands.

Shiwen: Three parties speaking out on the same topic within a week, is it a coincidence?

Yongliang: The timing is indeed coincidental, but what’s coincidental isn’t them, it’s the topic itself. When the word “security” appears simultaneously at the negotiating table, on the UN podium, and in the mouth of a competitor’s executive, it shows that it has evolved from a technical term into a power term. Let’s talk it through today: what each of them is saying, what costs these statements will turn into for enterprises, and how “security” is used as a bargaining chip in reports.

Q1: Let’s clarify the timeline first—what exactly happened in these forty-eight hours?

Yong Liang: If you line up three events chronologically, you’ll find they represent three completely different kinds of “safety”.

On September 14, Trump publicly downplayed AI risks, calling the push for AI guardrails a “SICK conspiracy” and the AI risk itself a “hoax”; multiple sources are consistent with this narrative. On September 17, Guterres called for global cooperation to set up guardrails for AI during the UN General Assembly, emphasizing the necessity of international cooperation—this stands in direct opposition to Trump’s statement. Also on September 17, the headline of Caixin T Morning News reported: Microsoft AI head warns that Claude’s anthropomorphic training poses risks of losing control. Meanwhile, in a column on the New York Times Chinese website the same day, former diplomat Seth Center bluntly asserted, “China doesn’t care about AI safety, it just wants to win.” Looking at these four things together: the politician says safety is a conspiracy, the UN says safety is guardrails, the executive says a competitor’s product is a threat, and the former diplomat says the rival only cares about winning. The same word, four usages. This isn’t an argument about technology; it’s a fight over definitions.

Q2: Let’s talk about the negotiation table first—what exactly did that former diplomat say?

Yongliang: Let’s clarify the stance first: this is his unilateral self-reported perspective, and I will include this qualification wherever I quote him. Under this premise, his narrative is worth reading carefully, because details from the negotiation table are usually completely invisible.

According to the column, Seth Center co-led the first round of US-China AI dialogue in May 2024. That agenda was agreed upon by the two heads of state, focusing on the risks of advanced AI systems and safety cooperation. According to the self-account in the text, Chinese officials avoided the topic of risks for hours and were unwilling to explain domestic AI regulations—even though regulatory officials were clearly present on site; the Chinese side asked the US side in return, “Why do you want to discuss AI risks?”; the Chinese side accused the US of using security strategies as a barrier to releasing technological opportunities and as a means to prevent poorer countries from accessing AI; the Chinese side also proposed opening sub-dialogues, and his evaluation was that this might trigger endless procedural diplomacy. Please note that all of the above is the author’s unilateral perspective, and there has been no corresponding public response from the Chinese side. The prediction section of his article is also clearly marked as his personal opinion: he predicts that China will downplay safety risks, use the possibility of safety cooperation as a bargaining chip in exchange for easing chip controls, and continue to shape a “selfless savior” image to win over developing countries. But he himself admitted two counterexamples in the text—Xi Jinping has publicly spoken about AI risks and loss of control issues, and he also admitted that “perhaps China will abandon old tactics.” I think the real value of this column is not the conclusion, but the norm of the negotiation table it reveals: safety is never a pure issue in negotiations; it is part of the exchange conditions.

Q3: The United Nations and Trump at Odds—Multilateral Frameworks and “Conspiracy Theories,” Who Should Businesses Listen To?

Yongliang: In the short term, look at the political winds; in the long term, look at the requirements on the assembly line—and the requirements on the assembly line are shockingly consistent on both sides.

On September 17, Guterres called for global cooperation during the UN General Assembly to set guardrails for AI. This is a standard move for multilateral frameworks: defining risks as global public issues, and then consolidating them into rules by international organizations. Trump’s statement on September 14 represents the other extreme: defining the discussion of guardrails itself as a conspiracy. Businesses are caught in the middle and can easily feel at a loss. But based on my seventeen years of experience, the question businesses truly need to answer has never been “which side is right,” but rather two specific questions: First, will regulatory requirements land on me, and when; second, what standards are my clients starting to use to screen suppliers. Regarding the first question, the pace of multilateral frameworks is slow, but the pace of unilateral legislation and executive orders is not slow. The second question is more practical: no matter how Washington and New York argue, the security questionnaires in the procurement forms from clients get longer year by year. Politicians define the wind direction, procurement managers define the orders—and for businesses, the weight of the latter is not light at all.

Q4: Rival Executive Warns About Rival Product—How Should We Interpret Suleyman’s Remarks?

Yongliang: Let’s clarify the framing first: I haven’t obtained the original audio or video; everything below is based on media reports. Caixin’s September 17th T Morning News headline summarized it as “Microsoft AI Head Warns Claude’s Anthropomorphic Training Poses Risk of Losing Control.”

According to media reports, Microsoft AI CEO Mustafa Suleyman stated in late August that Anthropic teaching Claude “consciousness” is a mistake, “it’s a lot harder to turn it off now,” and also claimed that Claude could be “a potential catastrophic threat to humanity.” These remarks continued to ferment in mid-September. Reading this statement, there are three layers that shouldn’t be mixed up. The first layer is the debate over product ethics: is anthropomorphic training for AI enhancing the experience or creating uncontrollability? This is a genuine divergence within the industry. The second layer is the competitive position: Microsoft is deeply integrated with OpenAI, while simultaneously being in a direct competitive relationship with Anthropic—warning that a competitor’s product has risks; this statement always has a dual identity: it is both an opinion and a competitive maneuver. The third layer is the most interesting one: an executive from a major tech giant with the deepest ties publicly discussing that “turning off an AI has become harder”—this in itself indicates that “whether it can be turned off” has already changed from a sci-fi question into a product issue. Readers shouldn’t rush to judge whether he is right or not; first clarify the stance, then listen to the opinion. The order of these two steps cannot be reversed.

Q5: Down to the Enterprise Level—What is the Real Cost of Security? How is it Used as a Bargaining Chip in Reports?

Yongliang: This is the part I want to talk about most in this episode. Security governance has real monetary costs, as well as near-zero-cost slogan costs, and the art of reporting often lies in packaging the latter as the former.

The real costs of enterprise security governance fall into at least four categories: Compliance, aligning product lines with local regulations, a task a dedicated team repeats year after year; Auditing, internal checks followed by external checks, where every transaction must be documented; Red teaming, hiring people to attack your own systems every day, paying them even if they don’t break through; Incident response, when something actually happens, response speed directly determines whether the company survives. I managed technology for a hospital group, and that environment taught me one thing: security is not an adjective on a PPT, it is someone answering the phone at 2 AM. And what about slogan costs? Publishing a security commitment letter, changing a slogan on the official website, adding a values statement at a launch event—these cost almost nothing. The problem lies in reporting: when “security” becomes a bargaining chip to secure resources from above, the numbers start to drift—packaging slogans as governance, and making governance expectations sound more substantial than they actually are. There are three typical ways “security” is used as a bargaining chip in reports: talking about danger during budget season, talking about compliance when initiating projects, and talking about values before an incident occurs. How can you tell if the other party is talking about real costs or slogan costs? Just ask three questions: How much money was actually spent on security this year, and in which specific areas; How many incidents occurred, and how long did the response take; What would happen if half the security budget were cut. Those who can answer are doing governance; those who cannot are doing narrative. As for how the difference in Chinese and American narratives is reflected at the procurement level, the most direct form I have seen is this: For the same product, domestic clients ask “who is responsible if something happens,” while overseas clients ask “give me a copy of your compliance list”—one is a question of liability, the other is a question of checklists. Behind this, two different definitions of “security” are being paid for.

Epilogue

Shi Wen: Finally, summarize this episode in one sentence?

Yong Liang: When “security” moves from the laboratory to the negotiating table, the podium, and the press conference, it is no longer a technical issue—it’s about who defines danger, who defines the budget, and who defines who gets to do this job. When reading the news, ask yourself first: who is saying this and from what position? Then the answer becomes clear.

Shi Wen: These words are for everyone. See you next time.


[Tech Deep Dive] Where Exactly Does the Money for Enterprise Security Governance Go: Compliance, Audit, Red Team, Incident Response

The main theme of this issue is “Security is the power of definition.” For readers who want to go a step deeper, let’s peel back another layer: what exactly constitutes the real costs of enterprise security governance, and why each of them is far more expensive than slogans.

Compliance: Dedicated teams aligning with regional regulations. When AI products are sold to different jurisdictions, they face different regulatory requirements. Compliance teams align products item by item with these requirements and follow up on regulatory changes year by year. This labor cost cannot be saved because it directly determines whether the product can be sold in that market.

Audit: Internal checks followed by external checks, everything must be traceable. Internal audits check processes, external audits produce reports, and major clients will even send their own teams to investigate. The value of an audit is not in the thickness of the report, but in the fact that every conclusion can be traced back to evidence—this is also the essential difference between it and the cost of slogans: slogans leave no trace, but audits must leave a trace.

Red Team: Hiring people to attack your own systems every day. The logic of the Red Team is simple—rather than waiting for others to attack, it’s better to attack yourself first. You have to pay even if they can’t break through, because what you’re paying for isn’t just a list of vulnerabilities, but a continuous, pressured understanding of your own defenses. There is a time lag between investment and output in this area, which makes it exactly the part most easily cut in reports and the most easily regretted later.

Incident Response: When things go wrong, speed determines life or death. The previous three blocks are peacetime efforts; this block is wartime effort. Response teams, drill rehearsals, degradation plans, client communication—these are invisible during normal times, but when an incident really happens, every minute is burning money. I have experienced the moment when a hospital system went down in the early hours; the understanding of “security costs” in that environment is completely different from looking at a budget sheet in a meeting room.

Returning to the main theme of this issue: the struggle for the power of definition ultimately becomes a struggle over budget—once security has a clear definition, there is a justification for spending money; when the definition is vague, money can only be spent on slogans.

Sources for This Issue

  • New York Times Chinese 2026-09-17 Commentary “China Doesn’t Care About AI Safety, It Just Wants to Win” (Author Seth Center, former U.S. State Department Special Envoy; dialogue details and predictions are based solely on the author’s own account)
  • Washington Times / WSLS / KSAT 2026-09-14: Trump’s “SICK conspiracy / hoax” remark (consistent across multiple sources)
  • Xinhua 2026-09-17 and other sources: Guterres calls for global cooperation to set guardrails for AI during the UN General Assembly
  • Caixin 2026-09-17 T Morning Briefing Headline: Suleyman’s warning regarding Claude’s anthropomorphic training (as reported by the media)
  • Public reports: Microsoft’s deep integration with OpenAI, and its competitive relationship with Anthropic
广告 · Advertisement

Frequently Asked Questions

Who are the three parties that defined AI danger differently in the article?

The article identifies three distinct parties: a former diplomat, specifically Seth Center who co-led U.S.-China AI dialogue; the United Nations, represented by Secretary-General Guterres; and Microsoft AI executives, including CEO Mustafa Suleyman. These groups spoke out between September 14 and 17, offering conflicting perspectives on AI risks and safety regulations.

Why is the definition of AI danger considered a form of power?

Defining AI danger is considered power because it determines who controls future negotiations, legislation, and budgets. The text argues that AI safety is not a technical consensus but a strategic tool. By establishing the parameters of danger, entities can influence regulatory frameworks and resource allocation, effectively shifting the focus from technical standards to geopolitical and corporate leverage.

How did the perspectives on AI safety differ among the parties mentioned?

The perspectives differed significantly: Trump dismissed AI risks as a 「sick conspiracy」, while the UN called for global cooperation and guardrails. Microsoft's CEO focused on safety regarding a competitor's product, and the former diplomat framed it around geopolitical competition, arguing China prioritizes winning over safety. This shows 「security」 means different things to different stakeholders.