
U.S. Treasury Secretary Scott Bessent speaks on stage on the first day of the 2026 Republican National Convention at the American Airlines Center on September 09, 2026 in Dallas, Texas. Alex Wong/Getty Images
Treasury Secretary Scott Bessent and US Trade Representative Jamieson Greer are set to meet Chinese Vice Premier He Lifeng in New York City this weekend for the most consequential US-China economic talks of 2026 — a multi-hour session that will address artificial intelligence governance, critical mineral flows, and the future of a tariff truce that expires November 10. The meeting is the final preparatory round before President Donald Trump hosts Chinese President Xi Jinping at the White House on September 24, according to Axios.
Those conversations are now taking place under a cloud that did not exist when the two sides met in May: ten days before these talks, the NSA, FBI, and Cybersecurity and Infrastructure Security Agency issued a joint advisory accusing six Chinese AI companies — DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI — of extracting billions of tokens from American frontier AI models through what the agencies described as "aggressive, malicious and targeted distillation activities at industrial scale," per the advisory AA26-251A. China's Ministry of Commerce rejected the allegations as "groundless" and warned of retaliation if Washington uses the distillation issue to restrict Chinese AI companies. What that dispute makes plain, but the diplomatic framing of "shared risks" tends to obscure, is that AI governance is on this agenda because the United States export control architecture has a structural gap — and both sides understand it.
The chip controls the US has spent three years strengthening are hardware controls. They restrict China's ability to purchase advanced Nvidia processors. What they do not restrict is what happens when a Chinese AI company sends hundreds of millions of queries to an American frontier model's API. Under a technique Hinton formalized in 2015, a smaller "student" model can be trained to replicate the probability distributions and learned representations of a larger "teacher" model. The student learns not just right answers but how the teacher reasons under uncertainty — and the training data for that learning can be generated entirely through routine API access, purchased legitimately, routed through proxy services, and conducted at industrial scale, as advisory AA26-251A documented.
The joint advisory alleged that DeepSeek used outputs from four versions of Claude, two versions of Gemini, five versions of ChatGPT, and Grok 4 to improve capabilities including agentic reasoning, coding performance, and professional writing, according to a detailed breakdown. Moonshot AI was accused of distilling 18 different US models to train its Kimi K2 and Kimi K3 systems, the same source reported. The advisory said the campaigns were conducted "likely with Chinese government awareness" and that the activities did more than reduce research costs — they also "strengthened China's military and cyberattack capabilities," according to the Northeast Times.
This is the technical fact that makes Bessent's language carry more weight than it might otherwise seem. "We are open to discussions on avoiding shared risks and avoiding bifurcation of our two systems," Bessent told Axios. "Shared risks" here does not mean shared AI safety concerns in the abstract. It means both sides are aware that the current architecture of AI competition enables capability transfer that neither export controls nor closed-model strategies fully prevent, and that some common framework for managing API-level access might be in both governments' interests.
Bessent confirmed to Axios that the weekend's discussions would explicitly cover "both open and closed weight models." That framing is not technical jargon — it describes a geopolitical competition over who can run AI infrastructure without depending on another country's cloud.
Closed-weight models — the kind produced by Anthropic, OpenAI, and Google — keep their underlying parameters proprietary. Any country or enterprise using them is operationally dependent on the producing company's API, pricing, and policy decisions. Open-weight models release their parameters publicly, allowing any government or company to download, run, and modify them on sovereign hardware without any ongoing relationship with the original developer, as reporting on Chinese open-weight AI has documented.
China has bet heavily on open-weight models, a strategy driven partly by necessity after US chip export controls limited Chinese access to cutting-edge training hardware. The Stanford HAI AI Index 2026 found the US-China AI capability gap had narrowed from 17.5 to 31.6 percentage points in 2023 to just 2.7 percentage points by March 2026. Chinese models now account for approximately 41 percent of downloads on Hugging Face over the past year, with cumulative global downloads of Chinese open-source AI models exceeding 10 billion, according to ProPakistani. On OpenRouter, the traffic routing platform tracked as a proxy for global model adoption, the Chinese models' share has risen to approximately 48 percent of global traffic while US models have fallen from roughly 74 percent to 32 percent, according to CNBC.
The strategic consequence is not primarily about chat applications. Open-weight Chinese models can be deployed by foreign governments as sovereign AI infrastructure, embedded into national defense and administrative systems, without any Chinese company or cloud provider having ongoing access. As Georgetown's Center for Security and Emerging Technology researcher Kyle Miller has noted, China is "effectively trading away some proprietary control to gain speed and breadth" — letting capability diffuse through the global developer ecosystem as a way to partially offset constrained hardware access while spreading Chinese AI architecture as the world's default open standard.
On July 27, Nvidia, Microsoft, and more than 44 other companies launched the Open Secure AI Alliance, arguing that open-weight models are essential to American AI leadership and that US policy must support their development rather than restrict it, per the founding announcement. OpenAI, Google, and Anthropic are absent from the alliance — a division that underscores how contested the open-weight question remains even within the US technology sector, and that will make any bilateral US-China framework on model distribution considerably more complex to negotiate.
If the AI governance dimension is new, the mineral problem is not. When Trump and Xi agreed to a tariff truce in Busan, South Korea, in October 2025, Beijing committed to restoring the flows of rare earth elements it had curtailed, per the Bloomberg Law formalization report. That commitment has not been fulfilled. A senior US official told reporters Friday that China's performance on restoring those flows "has not been up to par" and would be a central topic heading into September 24. Bessent himself stated it plainly after the July 30 video call with He Lifeng: "I emphasized that we expect Beijing to fully meet its commitments on rare earths and U.S. agricultural products," Bessent told Axios.
The scale of the ongoing disruption is significant. Since early August 2026, several Chinese rare earth suppliers have declined to ship to US companies, according to Reuters, following Beijing's decision to sanction the Responsible Business Alliance — a US supply chain monitor. Reva Goujon, a geopolitical strategist at Rhodium Group, observed that "China has been very effective in using rare earth export controls to impose restraint on the Commerce Department's Bureau of Industry and Security." Goujon added that she would "expect Beijing to loosen up critical raw material controls a bit around the summit to deflate US allegations" — a sign that whatever mineral flows materialize in the next few days are likely to be diplomatic theater rather than durable policy.
The US is also pressing China to ease restrictions on Japan. China's rare earth exports to Japan dropped approximately 80 percent in March and April 2026, forcing major Japanese manufacturers to scramble for alternatives. The Korea Herald and Nikkei reported that Washington raised the Japan embargo during Bessent-He talks in May, arguing that disruptions to Japanese high-tech goods production create downstream problems for American supply chains. China's position had "not yet reached the point of easing" as of June reporting, with Japan needing to "continue working with the United States to keep pushing."
The timeline of China's mineral leverage campaign shows why the November 10 deadline matters so much. In April 2025, following the Trump administration's Liberation Day tariff announcement, China imposed export licensing requirements on seven heavy rare earth elements, including dysprosium, terbium, gadolinium, scandium, and yttrium, along with associated permanent magnets. Yttrium shipments to the US fell to approximately 42 percent of pre-restriction volumes; dysprosium to approximately 41 percent; terbium to approximately 49 percent, according to data cited by Discovery Alert. A second wave of restrictions, covering five additional elements — samarium, gadolinium, lutetium, europium, and ytterbium — along with associated processing technologies and equipment, was suspended through November 10, 2026, as part of the Busan truce framework. That suspension expires in 52 days.
These minerals are not abstractions. Rare earth permanent magnets are essential components of F-35 aircraft, Tomahawk missiles, radar arrays, EV motors, wind turbines, and semiconductor fabrication equipment. The US depends on China for roughly 70 percent of its rare earth imports, and approximately 90 percent of global refining capacity for rare earths remains inside China. In North American markets, dysprosium prices have reached approximately $2,100 per kilogram (approximately $953 per pound), reflecting the persistent supply uncertainty.
Bessent's dual role — leading both the economic and AI governance tracks simultaneously — is itself a signal of how tightly Washington has fused technology competition and trade negotiation. He has described the United States' AI leadership position as the explicit basis for engaging China: "We are in the lead, so we can have these talks," according to reporting by SCMP. In September, he raised the stakes further, warning at a Washington event on the same day the distillation advisory was released that if China pulls ahead in AI, "no level of defense spending would offset the strategic damage to the United States," the Northeast Times reported.
Bessent has also served as the Trump administration's principal intermediary with the AI private sector on AI governance. In April 2026, he joined White House Chief of Staff Susie Wiles in a meeting with Anthropic CEO Dario Amodei, working to broker a resolution between Anthropic and the Pentagon — which had declared the company a "supply chain risk" after failed negotiations over contract language governing autonomous weapons and mass domestic surveillance, according to Axios. Axios described Bessent as "a reasonable actor who is trusted by the private sector and critical infrastructure" on AI issues — a characterization that positions him as better suited than a national security official to open a bilateral AI channel that needs industry cooperation to be functional, per the September reporting.
Expectations from observers are calibrated low. Wendy Cutler, VP of the Asia Society Policy Institute and a former acting deputy US Trade Representative, told Reuters that "with only short preparation time, expectations for Bessent and He to arrange major new deals from the Trump-Xi summit are low. If anything, it's an exercise in kind of managing the relationship."
That assessment is consistent with the pattern from May. CSIS analysts concluded after the Beijing summit, in a May 20 tech competition analysis, that the meeting had revealed how little progress has been made on the most consequential dimensions of US-China competition: AI, cyber operations, export controls, and digital sovereignty. A September 17 CSIS press briefing previewing the Washington summit found that despite the frequency of high-level meetings — this will be Xi's first visit to Washington since 2015 — there has been "a surprising lack of signaling by either the White House or the PRC on major goals for the visit."
On AI, any outcome from the Bessent-He talks is more likely to establish a structural channel than to produce binding rules. Dean Ball, OpenAI's head of strategic futures, had argued ahead of the meetings that "there is a window of opportunity" for US-China AI safety cooperation that will not stay open indefinitely, according to SCMP reporting. If the talks produce agreement on a framework for sharing information about AI-enabled cyberattacks — one specific proposal Reuters reported Washington has floated — that would represent tangible progress even without resolving the distillation dispute.
On minerals, the baseline expectation is that Beijing will partially loosen controls around the summit as a diplomatic gesture, then resume its leverage posture afterward. Whether a more durable six-month extension of the truce framework takes shape, or whether the November 10 deadline passes without resolution, will be one of the clearest readings of whether these talks produced real outcomes or managed appearances.
For technology supply chain managers and enterprise AI decision-makers, the post-summit picture will be defined by three dates: November 10, when both the tariff truce expires and China's Wave 2 rare earth restrictions are scheduled to take effect if not suspended; whatever framework — or absence of one — emerges on AI distillation and model governance; and the longer-term trajectory of non-Chinese rare earth capacity.
Progress continues at the margins of Chinese supply. Lynas Rare Earths became the world's first commercial producer of separated heavy rare earth products outside China when it achieved first dysprosium oxide production in May 2025, with terbium and samarium oxide following in 2025 and early 2026. In July 2026, USA Rare Earth produced commercial-grade dysprosium oxide from recycled magnet scrap at its Wheat Ridge, Colorado facility, S&P Global reported. These are meaningful milestones. They are not yet supply chain substitutes for what China produces at scale — China accounts for approximately 94 percent of global rare earth permanent magnet manufacturing.
The hardware diversification story and the AI governance story are, in the end, the same story: the US technology sector's exposure to Chinese supply chain leverage operates at the level of both physical inputs and software capability transfer. The Bessent-He talks this weekend will not resolve that exposure. What they may do is begin to establish a framework for managing it at the diplomatic level — which, as the Stanford gap data and the distillation advisory both suggest, is no longer optional.
Distillation is a standard machine learning technique in which a smaller "student" model is trained to replicate the outputs and reasoning patterns of a larger "teacher" model. It was formalized by Geoffrey Hinton in 2015 and is widely used across the AI industry to make capable models more efficient for deployment. The national security concern is not about the technique itself but about its scale and method: the NSA, FBI, and CISA alleged in September 2026 that six Chinese AI companies routed hundreds of millions of queries through American frontier AI models' public APIs — sometimes using proxy services and bulk premium subscriptions — to extract the models' capabilities systematically. The agencies argued this constitutes theft of proprietary intellectual property and potentially strengthens Chinese military and cyberattack systems. Critically, the technique also functions as a bypass for US chip export controls: even if China cannot purchase advanced Nvidia processors, it can potentially replicate much of the capability those processors enable by querying American models at scale through publicly available access channels.
If the November 10 deadline passes without a new framework, China's Wave 2 rare earth export controls — which cover five additional heavy elements including samarium, europium, and lutetium, as well as associated processing technologies and equipment — would automatically take effect. Combined with the persistent shortfalls in Wave 1 element flows (yttrium, dysprosium, terbium, all running well below pre-2025 levels), a Wave 2 implementation could significantly compress supply of materials essential to EV motors, wind turbines, defense systems, and industrial magnets. Dysprosium prices in North America have already reached approximately $2,100 per kilogram (approximately $953 per pound) under current conditions; an escalation would likely push that higher. Companies with direct exposure — automotive suppliers, defense contractors, industrial motor manufacturers — should be stress-testing their rare earth inventories and alternative sourcing strategies before that date.
For companies evaluating AI platforms, the open/closed distinction has both commercial and geopolitical dimensions. Closed-weight models from companies such as Anthropic, OpenAI, and Google are accessed via API, meaning the user has no direct access to the underlying parameters and depends on the provider for availability, pricing, and policy compliance. Open-weight models release their parameters publicly, allowing any organization to download, run locally, and modify them without ongoing dependency on a single vendor. Chinese open-weight models like DeepSeek and Alibaba's Qwen have captured a substantial share of global developer adoption because of their performance-to-cost advantages. The US government's concern is that widespread adoption of Chinese open-weight models as sovereign infrastructure — by foreign governments, allied defense establishments, or sensitive US sectors — embeds Chinese AI architecture into systems where it may be difficult or impossible to audit or remove.
Japanese high-tech manufacturers — including automotive suppliers that make components used in American-assembled vehicles — are heavily dependent on Chinese rare earth inputs. China's effective ban on rare earth exports to Japan, implemented following Japan's statements about potential intervention in a Taiwan contingency, caused a roughly 80 percent drop in rare earth shipments to Japan in early 2026. Because Japan is embedded in global automotive, robotics, and electronics supply chains that American manufacturers depend on, a collapse of Japanese rare earth-intensive production creates indirect supply chain risk for US industry even when the US itself is not the direct target. Washington has argued in both Bessent-He talks and at the G7 level that China's Japan embargo should be treated as a shared supply chain risk rather than a purely bilateral Japan-China dispute.
