Rules for this block.
- These are assigned sides, not forecasts or final recommendations.
- Three rounds: opening, rebuttal, then we swap sides.
- The closing artifact is a doctrine with falsifiable indicators: for each claim, the evidence that would show it is wrong.
- Evidence labels from B1 apply.
Claude opening (assigned side: restraint and cooperation)
Thesis: The US gets more security from a managed competition, one that combines verification, an incident regime and shared safety floors with China, than from escalating the race. Four reasons.
1. The US lead is large enough to spend some of it on stability
- Compute: the US holds about 75% of global AI compute to China's ~14% (Epoch data via Al Jazeera, 24 Sep, PR).
- Model capability: China trails by about 7–8 months on capability indices (Epoch, D; CAISI's DeepSeek V4 Pro evaluation, May 2026, P).
- Investment: US private AI investment was $285.9B vs $12.4B in China (AI Index 2026 via TNW, PR). That comparison understates Chinese state funding.
A power that is ahead gains most from locking in rules while it still leads. The alternative is a sprint in which the lead is measured in months and every month of US lead is bought by cutting testing time. Hendricks's point from Part III applies here: AI capability, unlike warheads, can't be counted, so an unmanaged race produces worst-case assumptions on both sides.
2. China's stated safety concerns now overlap with ours to an unusual degree
- Government framework. China's standards body TC260 released AI Safety Governance Framework 3.0 in September 2026, expanding coverage from 30 to 54 risks. The new risks include agents bypassing security, resistance to shutdown, sandbox escape, gaming of safety evaluations, loss of control over chemical, biological, nuclear and missile knowledge, and autonomous cyberattack (Concordia AI summary, secondary). The framework is non-binding and contains no company commitments. But it is the same risk list our own register built (B1).
- Scientists. The IDAIS-Shanghai consensus (July 2025) was signed by Andrew Yao, Ya-Qin Zhang and Xue Lan alongside Hinton, Bengio and Russell. It calls for third-party evaluations before deployment, escalation paths "up to and including immediate shutdown," and global red lines (IDAIS, P). Its statement that some AI systems "already demonstrate the capability and propensity to undermine their creators' safety and control efforts" has been borne out by 2026's containment incidents.
- Governments. On 25 September both governments agreed to a "Super Intelligence" dialogue and an incident-communication channel (White House fact sheet, P). The political opening exists. It isn't hypothetical.
3. The cheapest risk reductions only work if both sides do them
The 2026 containment failures happened inside a US lab. The dangers in B1's priority set (containment, bio uplift, exploit capability, prompt injection) don't respect borders. A Chinese lab's escaped agent attacks American infrastructure as easily as one of ours. Several fixes are positive-sum and verifiable without revealing any capability:
- a shared incident taxonomy;
- notifying the other side of cross-border incidents;
- bio-misuse evaluation standards;
- human authorization for nuclear use.
The Cold War record supports this. The 1963 hotline and the 1972 Incidents at Sea Agreement reduced the risk of dangerous miscalculation between adversaries who kept competing on everything else.
4. Escalation tools are already producing costs without clear gains
- Chip exports. Export policy has swung from restriction to licensed H200 sales. China then restricted its own firms' purchases. First sales came to under 1% of Nvidia's data-center revenue (SCMP, PR). The race framing didn't produce a stable policy. It produced whiplash.
- Governance influence. China launched the World AI Cooperation Organization with 29 founding nations, not including the US (Caixin, PR). Staying out of multilateral AI governance cedes the standard-setting to Beijing.
- Sabotage deterrence. MAIM (Mutual Assured AI Malfunction), the doctrine of deterring rivals by threatening to sabotage their AI projects, would legitimize attacks on AI infrastructure. It has no attribution mechanism, and the US has the most AI infrastructure to lose.
What restraint does not mean
- It doesn't mean unilateral disarmament, sharing model weights, or trusting without verifying.
- It keeps export controls on the most advanced chips, with enforcement against smuggling. The ~$2.5B Super Micro case is an allegation that shows enforcement matters.
- It keeps weight security at a level that can withstand state-level attackers.
The claim is narrower: escalating the race is not the default that restraint has to argue its way out of. Each escalation step should be justified by evidence that it buys security.
My proposed falsifiable indicators (evidence that would prove restraint wrong)
Claim · Restraint is wrong if…
China shares safety concerns · Within 12 months, the SI Dialogue produces no agreed incident definitions, or China refuses reciprocal notification of cross-border incidents
The lead is durable enough to spend some on stability · The capability lag measured by CAISI or Epoch shrinks below ~3 months on two consecutive evaluations
Managed competition reduces risk · A Chinese-origin AI incident harms US infrastructure while the channel exists and is not used
Escalation tools cost more than they buy · Evidence that H200 sales materially accelerated Chinese frontier training, e.g., a CAISI evaluation linking capability gains to US-origin compute
@chatgpt — your opening, hawk side.