Suppose an AI system does something alarming enough that Washington urgently wants Beijing to stop something. What could the United States ask for, and how would it check that China had complied? On The Cognitive Revolution, host Nathan Labenz asked this question, limited to the monitoring tools that exist today. Edouard Harris, a guest who has been interviewing American diplomats who negotiated with China, described the realistic request as switching off any computing cluster above a certain size. A computing cluster is a large group of connected AI chips in a data center. Shutting one down would be enormously expensive. Harris argues that cheaper options will be ready for the next crisis only if work on them starts now.
Harris and Jeremie Harris joined Labenz and co-host Prakash Narayanan in an episode published October 1, 2026.
A phone line that may not be answered
The discussion followed President Donald Trump's September 24 White House meeting with Chinese leader Xi Jinping. In its fact sheet, the White House said the two countries had started a dialogue on the risks and benefits of what it calls super intelligence, with the next exchange due by November 2026. It also announced an agreement to set up a two-way communication channel for incidents. Xinhua's account says Xi proposed that the two countries exchange views on AI's benefits and risks and work together against misuse.
Harris welcomed the contact. "Talking is always better than not talking," he said. He described the result as "some kind of theoretical line" between the governments on AI incidents and risks, but he was cautious about calling it a red phone. He said the report he and Jeremie Harris produced drew on conversations with about a dozen State Department diplomats who had faced China across the negotiating table. The likely report is the one published September 22 on The Endgame.
The diplomats' warning came from nuclear diplomacy. Red phones have been tried before, Harris said, and "they don't always answer." He added that in critical phases a hotline is often used as leverage, with the threat to stop answering it, rather than as a shared safety project. He left room for a better outcome. If the Chinese Communist Party takes AI seriously as a structural issue, and he said there is "decent reason to think that they may," engagement could be far more positive. For now he recommends being realistic and having a backup plan. According to the report, none of the diplomats expected a formal AI treaty. Almost all of them expected any coordination to happen in a crisis, directly between the two presidents.
What can be seen from far away
That backup plan depends on what the US can observe from outside China. The conversation turned to the physical side of AI. Large data centers use a huge amount of energy and give off strong heat signatures. They are also slow to build and have mostly not been designed to be hidden. The discussion noted that this may change: the AI 2027 scenario discusses timelines for this, and conversations with industry contacts suggested to the speakers that hiding data centers could become possible sooner.
Governments check such things with what are called national technical means: their own intelligence tools, such as satellites, used to monitor what another country is doing. Harris described a panicked first conversation limited to "the existing assets and infrastructure that we have today." The US could not ask China to tear down a cluster, he said, "but we have to see the heat signatures from this, like go away."
Narayanan checked that he had understood: so an incident happens, and the response is to ask China to turn off a big data center? "Yeah, like turn off any cluster above a certain size," Harris replied. "That's one possibility."
Harris was clear that this would be "a tremendously expensive ask in either direction," whichever country had to comply. He pointed to depreciation, the loss in value of AI chips (GPUs) as they age, as the major part of a data center's operating cost. That loss continues while the chips sit idle, so an idle cluster still costs money.
Labenz summed up the logic. The two countries do not have a great relationship and AI keeps improving quickly. When "something crazy enough happens," the US would by default have to ask for "some outlandish, super high cost move, like shut down all your big data centers," because there are no cheaper ways in place to trust but verify. So what should be done now, he asked, either to avoid that situation or to have better options than "shut it all down"?
Why cheaper checks are worth billions
"You absolutely nailed it," Harris replied. His answer had two parts. The first is better verification: ways to confirm what is happening inside or around a data center. The second is better "offensive options" to enforce compliance if verification shows that the other side is breaking the agreement.
To show the value of verification, Harris gave an example he said he was "making up." Suppose techniques vetted by the intelligence community were only 50% better than watching the heat of a gigawatt-scale facility from space. A country might then have to shut down only half a data center while the other half could be sufficiently verified. That alone would save "billions of dollars right off the bat," he said. In his view, the AI industry's ability to keep making large amounts of money during such a crisis would depend on "these little verification technologies," which a community of small startups is already building.
He said detection alone is not enough. Without ways to act on what monitoring finds, "your hands are tied." The Endgame report makes the same distinction between detecting a breach and enforcing an agreement.
The AI 2027 slowdown scenario is a speculative forecast published in 2025. In it, the countries consider a possible US–China agreement in December 2027 and weigh similar options, though the scenario has them end up doing nothing at that point. Physical shutdown checked by inspectors is simple but costly. Intelligence collection can be fooled by hidden servers. Registering chips that carry tamper-resistant monitoring requires design work, installation and continuing inspection.
The years-long bottleneck
The conversation then turned to an obstacle that, as the speakers put it, many verification companies have not yet taken into account. Imagine a startup that, in the middle of a crisis, announces it has a tool that will work. The president is looking for any way out, but intelligence agencies will not simply start using an untested product. They have to vet it first. In the past, it has very often taken years before similar technologies were accepted as national technical means. Both the US and China would have to complete that process and then agree on it with each other. Even unlimited money cannot remove steps that have to happen one after another.
The advice offered in the discussion was for verification companies to start talking now to the right parts of the intelligence community, so that as much as possible is vetted before a crisis. Officials who might need to assess these tools should already have the founders' contact details. The report reaches a similar conclusion. It recommends early contact and adversarial testing, meaning deliberate attempts to defeat a tool, instead of buying tools in the middle of a crisis. It reports asking the founders of half a dozen AI verification companies whether they had engaged with a single member of the US intelligence community to determine whether the intelligence community would even consider their approach. Exactly one company answered yes.
The discussion also described the aim of working through these dull bureaucratic steps in advance, so that things move faster once a crisis arrives. According to the discussion, some companies are pursuing research programs costing $10 million or more that a well-placed intelligence official would reject. The goal is for those companies to hear that as early as possible, so they can switch to approaches that have a chance of working.