As Washington and Beijing Race on AI, Who Will Build the Guardrails?

If history is any guide, the guardrails for frontier AI will have to be built before the superpowers are ready to embrace them.

September 15, 2026
Rheault, Philippe - AI Guardrails v3
Is there a way for Washington and Beijing to work in tandem to establish guardrails for the most dangerous capabilities of frontier AI? (IMAGO/APA Images/REUTERS)

The United States and China are advancing the frontier of artificial intelligence (AI) at breakneck speed, racing to build systems whose consequences neither country is able to manage alone. Each new generation of models arrives before governments have fully understood the implications of the last, while policy makers and regulators struggle to keep pace. Given this backdrop, is there a way for Washington and Beijing, despite their rivalry, to work in tandem to establish guardrails for the most dangerous capabilities of frontier AI? And is there anything Canada, working with other middle powers, can usefully do?

Some commentators have recently reached for a nuclear analogy, with Washington viewing frontier AI as something akin to a nuclear weapon: a decisive strategic capability to be nurtured and protected through export controls and technological denial. Beijing, by contrast, purports to treat AI more like civilian nuclear power: a general-purpose technology whose models, benefits and applications should be diffused widely in pursuit of economic and geopolitical influence.

China has now made its positioning explicit. Speaking at the World Artificial Intelligence Conference in Shanghai in July 2026, President Xi Jinping called for open-source development, collaboration and sharing — positioning China as a provider of AI technologies, training and institutional support to the Global South. And he warned against stretching national security claims to restrict AI development, a thinly veiled reference to the American approach. This message was then amplified by the subsequent release of Moonshot AI’s Kimi K3, a powerful and comparatively inexpensive open-weight model that has left Washington debating whether Chinese open-weight systems can feasibly be walled off at all.

But beyond the rhetoric, the contrast should not be overstated: Washington is also keen to see American AI systems and standards adopted abroad, while Chinese policy pairs appeals for openness with demands that AI remain secure, controllable and under human direction.

Perhaps the more useful analogy lies less in nuclear technology itself than in the political challenge it posed: how strategic rivals began constructing institutions of restraint amid deep distrust. Within a decade of the Cuban Missile Crisis in 1962, Washington and Moscow had installed a direct hotline and concluded a string of treaties limiting nuclear testing, proliferation and missile defences, all while arming themselves and engaging in proxy wars. None of this was predicated on amity; rather, both sides came to accept that rivalry did not preclude building limited institutions of communication, verification and restraint around dangers neither could contain alone.

If Washington and Moscow could construct such an architecture amid profound ideological hostility, then perhaps Washington and Beijing could explore a comparable dialogue on AI safety. However, because the technology at play today is so different, the analogy strains in three places when applied to AI: verification, deterrence logic and diffusion.

Where the Analogy Strains

First is verification. Warheads, missile silos and enrichment facilities are large physical objects that can be viewed from space and accounted for by inspectors on the ground. Model weights, on the other hand, are files — reproducible and transferable in ways far more difficult to observe or track.

The most promising response here could be compute oversight. Training frontier systems still requires advanced chips, enormous data centres, substantial electricity and sophisticated cloud infrastructure. Any initial verification regime could focus less on counting models than on identifying and reporting the largest training runs. Monitoring compute will not reveal everything that matters, but it offers a real — if possibly temporary — opening before algorithms become more efficient and large-scale training becomes easier to distribute or conceal.

The second limitation is that the logic of mutual assured destruction (MAD), which underpinned much of Cold War strategic stability, does not apply to all catastrophic AI scenarios. MAD stabilized the nuclear standoff because the threat was symmetric and retaliatory. By contrast, model-assisted biological attacks, cascading autonomous cyber operations and the loss of control over increasingly capable agentic systems may have neither a clear return address nor an assured retaliatory mechanism.

Some nuclear logic does carry over, however: strategic stability measures retain their applicability in preventing algorithms from acquiring authority over nuclear-use decisions and in ensuring meaningful human control. For scenarios lacking MAD’s retaliatory symmetry, biosecurity and non-proliferation may offer more instructive templates. Writ large, proposing workable solutions will mean looking beyond established Cold War logic to find ways to mitigate risk.

The third and final challenge is that of diffusion. Nuclear non-proliferation efforts bore fruit, in part, because building a bomb required a massive and comparatively detectable state program. AI capabilities diffuse through private firms, cloud platforms, mid-sized states and open-weight model releases. Furthermore, in China’s case, openness and diffusion are elements of its competitive strategy.

Common governance will therefore likely need to focus on the narrow band of frontier capabilities and high-consequence deployment settings where American and Chinese interests genuinely overlap, since sweeping controls that appear designed to preserve one side's technological advantage will surely be resisted or circumvented. Nor will resistance come only from Beijing: current calls to preserve access to Chinese open-weight models, on which many smaller US firms now depend, have extended from nearly 200 American start-up founders to industry leaders such as Nvidia’s Jensen Huang and Meta’s Mark Zuckerberg.

The transferable Cold War lesson may therefore not be MAD itself, but the possibility of an architecture of strategic stability: restraint, communication and crisis management among rivals that cannot compel each other to disarm.

Addressing these three limitations would still leave another challenge: forging common ground on frontier risk. Washington and Beijing do not yet share a common assessment of the severity and imminence of catastrophic scenarios, or of whether proposed safeguards are neutral precautions or instruments of strategic advantage.

Focused diplomacy and sustained exchange will therefore be essential: not to persuade either side that frontier risks exist, but to translate areas of conceptual overlap into shared definitions, reciprocal commitments and workable governance mechanisms. First steps need not be sweeping: effective hotlines between relevant authorities, notification channels for serious AI incidents, explicit red lines around nuclear command and control, and recurring technical exchanges on evaluations and military applications would be a good start.

Washington and Beijing have already taken a small step in this direction: in November 2024, both leaders affirmed the need to maintain human control over decisions to use nuclear weapons and called for prudence in developing AI for military purposes. The commitment was modest, general and unverified, but it did establish precedent.

More ambitious measures could then ensue: common reporting thresholds for the largest training runs, shared testing methodologies and, eventually, carefully designed forms of reciprocal or third-party visibility. The important thing will be to build these channels before a major crisis, rather than waiting for its aftermath to supply the requisite political will.

The Middle-Power Role

Where does this leave Canada and other middle powers? Not at the centre of things, to be sure. The core strategic accommodations, if they come, need to be reached between Washington and Beijing, and it would be counterproductive to pretend otherwise.

But middle powers do have agency and interests at stake, and they will absorb many of the economic, security and political consequences of frontier systems developed elsewhere. What cards, if any, do they have?

The historical record offers instructive parallels. Irish initiatives at the United Nations helped launch the process that produced the Nuclear Non-Proliferation Treaty; Canada helped build the International Atomic Energy Agency’s safeguards system; and Norway later partnered with the United Kingdom on warhead-dismantlement verification. Such unglamorous institutional work helped shape the regime and the rules by which great powers ultimately played.

If mutual verification capability is a missing load-bearing wall, someone must develop the verification science: compute-monitoring techniques, evaluation benchmarks, audit protocols and reporting standards. Canada has strong foundations on which to build in this space, including world-class AI research clusters in Edmonton, Montreal and Toronto; the Canadian Artificial Intelligence Safety Institute; the Canadian-chaired International AI Safety Report; and experience in technical safeguards and international standard-setting.

If the deeper obstacle is the absence of a shared threat model, middle powers can act as conveners. They can host Track 1.5 and Track 2 dialogues in which American and Chinese scientists, officials and policy specialists compare assessments of capabilities, incidents and possible red lines without the encounter itself being treated as a political concession. In a low-trust environment, credible third countries are scarce strategic infrastructure.

And if AI capability diffuses in ways no bilateral agreement can contain, the governance of AI adoption will need to be shaped by a broader international system. Standards for procurement, model evaluation, incident reporting and high-risk deployment will be determined not only by the two leading AI powers but also by the governments and institutions that decide what systems are allowed to operate in their markets.

Middle powers should therefore work to turn the emerging network of national AI safety institutes into an interconnected web for joint testing, shared methodologies and interoperable standards. A recent joint US-UK government evaluation of Kimi K3 offers an early glimpse of such a network. Much of this requires no advance buy-in from Washington or Beijing; it can begin now, iterating the norms and technical foundations on which eventual great-power agreements might rest.

Here in Canada, at a moment when Ottawa is seeking to expand and diversify its international partnerships and enhance its middle-power standing, marshalling its AI research, diplomatic and policy capabilities in support of frontier safety would be both good international citizenship and sound national strategy.

One key and demonstrable lesson of the Cold War record is that institutions of restraint are not generally built after strategic rivalry has disappeared. They are built concurrently, often when competition is at its most strained. If Washington and Beijing are ever to develop meaningful guardrails for frontier AI, much of the technical, diplomatic and institutional groundwork will have to be laid before either side is politically ready to embrace it. That is where middle powers can make their greatest contribution.

The opinions expressed in this article/multimedia are those of the author(s) and do not necessarily reflect the views of CIGI or its Board of Directors.

About the Author

Philippe Rheault is director of The China Institute at the University of Alberta. A former Canadian diplomat with five postings across Greater China, including two as consul general, he writes on how middle powers can navigate US-China strategic competition.