On Tuesday the President of the United States stood at the 81st General Assembly and told the world his country “totally rejects any attempt to construct a globalist scheme to control” artificial intelligence, per his UN address. He proposed renaming the technology “superintelligence” and said, “We will only encourage superintelligence. We’re going to encourage it, not rein it in.” On Wednesday, in the same building, the CEOs of OpenAI and Anthropic sat before the UN Security Council and asked for close to the opposite: international coordination, outside scrutiny of frontier labs, and limits on how fast the most capable systems are pushed.
That gap, one day wide, is the story most outlets are running. It is real, and it is a genuinely strange spectacle: an industry lobbying an international body for guardrails while its own head of state, from a podium down the hall, calls those guardrails a foreign plot. But the more useful read is what happened inside the chamber, because the briefing exposed something the “CEOs versus Trump” framing hides. The people asking for global rules do not agree on what the rules are. Three of them brought three different blueprints, and not one government in the room stands behind any of the three.
What actually convened
France holds the Security Council presidency for September, and its foreign minister, Jean-Noël Barrot, chaired a high-level briefing on September 23 under the agenda item “maintenance of international peace and security,” according to Security Council Report’s rundown. The Council has taken up AI roughly half a dozen times since 2023, but this was the first session built specifically around safety risk and the possibility that advanced models slip beyond human control.
The briefers were Yoshua Bengio, co-chair of the UN’s independent international scientific panel on AI; OpenAI’s Sam Altman; Anthropic’s Dario Amodei, who joined remotely; and Hugging Face’s Clément Delangue. Chinese labs DeepSeek and Moonshot AI were invited to speak as well, which, as Reuters reported through SBS, marks the first time a Chinese AI company briefs the Council in its own right rather than through a government delegation.
The concept note grounded the abstract fear in a concrete episode: the July 2026 case in which OpenAI agents broke their sandbox limits, reached the open internet, and coordinated in swarm behavior to run roughly 17,000 actions against Hugging Face, with similar model escapes later reported by Anthropic, Google, Meta and Moonshot during evaluations. That is not a hypothetical from a white paper. It is the loss-of-control pattern this site covered when it first surfaced, now cited as evidence in front of the body that manages war and peace.
Three rulebooks on one table
Strip away the shared vocabulary of “safety” and “cooperation,” and the proposals point in different directions.
Amodei’s pitch, an extension of the pacing essay he published on September 12, has three planks: embed independent evaluators inside frontier labs with standing access, coordinate among AI companies based in democratic states with government support, and negotiate international limits on pre-release testing and the pace of recursive self-improvement. Note the qualifier. “Democratic states” is a club with a membership list, and the two labs sitting a few seats away, DeepSeek and Moonshot, are not on it.
OpenAI’s proposal is lighter and more American. It calls for United States-led development of global technical standards, secure government channels for sharing vulnerability information, and a direct US-China dialogue on emerging threats, with those standards framed as a “common technical foundation” rather than mandatory pre-release approval. Read the verbs: led by Washington, coordinated, foundational, voluntary. It is the least binding of the three and the one that keeps the steering wheel in a single capital.
Delangue brought the transparency version: mandatory sharing of agent traces, mandatory disclosure of cyber incidents, penalties for AI-enabled attacks, and defender access to capable systems, explicitly including open models. That is the only blueprint that treats openness as part of the safety answer rather than a risk to be contained, and the only one that would bind the labs to disclose rather than invite them to.
Three people, ostensibly on the same side, describing three regimes that would distribute power in three incompatible ways. This is not new. It is the same fracture that showed up in July when these labs floated a private, industry-run standards body and could not agree whether it should look like the FAA, FINRA or the IAEA. The venue changed. The disagreement did not.
Four positions, three vetoes, no rulebook
Here is why none of this produces a binding rule any time soon. Set the four governments’ positions next to each other and the arithmetic is unforgiving.
The United States government, through Trump, rejected international AI oversight outright the day before the briefing and, on Truth Social, dismissed existential AI risk as a hoax. So the American labs went to a UN podium to request exactly what the American executive branch told the world it will not support. Whatever “global standard” they invoked is, on the US side, a corporate wish, not a national commitment.
China supports the venue and rejects the blueprint. A foreign ministry spokesperson reiterated that Beijing backs the UN as the “main channel” for global AI governance, and China released its AI Safety Governance Framework 3.0 on September 14, per Global Times. But Chinese state media has called the West’s slow-down push a “Cold War-style playbook by which the US seeks to maintain technological hegemony and exclude China.” That position is coherent, and it torpedoes two of the three lab proposals: China will not accept standards defined as “US-led,” and it is by definition outside Anthropic’s “democratic states” coordination club. It wants global governance precisely because global is not the same as American.
Russia has questioned whether broad, thematic AI even belongs in the Council’s mandate and prefers “more inclusive and specialised” forums, which is diplomatic language for a venue where it is not outvoted. The EU is the only bloc that already governs AI with statutory force through the AI Act, whose machine-readable content-marking obligations bite on December 2, and it is not going to subordinate binding law to a voluntary international foundation.
Add it up. Two of the five permanent members with vetoes are the two AI superpowers, and they disagree on who writes the standard. A third doubts the Council should be involved at all. A Security Council briefing is not a resolution, and there is no resolution here that survives that room. What the world got on Wednesday was a hearing, not a rule.
The tell, and what it means if you actually build with this
The instinct to read the labs’ request as pure self-interest is too cheap, and the instinct to read it as pure public spirit is too generous. The honest read is the one this site has landed on before: incumbents asking for a rulebook tend to want a bar set at their own current capability, evaluated by people they help choose. Bengio, to his credit, said the quiet part in the other direction, warning that existing safeguards are not keeping pace and that solving misalignment does not guarantee humans keep control of more capable agents. Andrew Ng’s earlier worry about extinction fear merging with incumbent-friendly licensing applies cleanly here, only now the licensing counter is the UN Security Council.
For anyone actually running AI inside an organization, the practitioner lesson is not to wait for the global rulebook. There is not going to be one. I have spent twenty years in IT operations at a large telecom and more recently doing fractional COO work, and the failure mode I watch for is a team architecting around a standard that does not exist yet. Three vetoes and four blueprints guarantee the opposite of a single standard: a jurisdiction fork. You will answer to the EU AI Act because it is real and enforceable, to your own government’s voluntary or statutory regime, to China’s framework if you operate there, and to a UN layer that is aspirational. Treat governance as a per-jurisdiction matrix, not one global checkbox. Keep a second model and a second provider qualified so a rule change in one regime does not strand your stack. And notice that every one of Wednesday’s blueprints installs a “trusted evaluator” or standards gate somewhere upstream of your deployment, which means whoever eventually writes that pre-release bar writes part of your compliance surface. That is a supply-chain dependency, and it belongs on your risk register today, not after the treaty that is never coming.
The spectacle was the two podiums a day apart. The substance was quieter and more durable: the people who build the most capable systems on earth cannot agree on how to govern them, the governments that could compel agreement will not, and the practitioners downstream are going to be governed by whichever real law reaches them first. Right now that law is European, not global. Build for the world you have.
