September 21, 2026
Donald Trump and Xi Jinping’s summit, beginning September 24, brings AI into the centre of the U.S.–China relationship alongside trade and security. Preparatory talks between Treasury Secretary Scott Bessent and Vice Premier He Lifeng have already produced a U.S. proposal for a mechanism to notify one another about AI incidents with national-security implications. Reuters
By Monday, the discussion had advanced further: Bessent said the countries had agreed to a formal AI dialogue, including an incident line, with another meeting expected in Shenzhen in roughly two months. The details still need to be worked out, but the direction is significant. Two technological competitors are beginning to build a process for communicating when something goes wrong. Reuters
It’s a decent starting point for a week in which the practical questions around AI became harder to avoid. Who pays when infrastructure bets fail? Who defines what an agent is allowed to do? Who controls the systems businesses and governments increasingly depend on? And what happens when AI makes political coordination look like spontaneous public opinion?
Macro
AI is building its own financial system
The infrastructure story has moved well beyond companies spending extraordinary amounts on data centres. The Financial Times reports that technology companies have issued up to US$300 billion in guarantees over the past year, supporting financing for AI infrastructure while recording relatively little of the exposure on their balance sheets. Some arrangements guarantee a minimum future value for chips or facilities held in separate financing vehicles. Financial Times
A guarantee can help make a project financeable today by promising someone else protection against tomorrow’s losses. That protection has value because the underlying investment carries risk. Moving the obligation into a contingent commitment changes when it becomes payable.
AI is developing a financial architecture of its own. Compute becomes collateral. Expected future demand supports present borrowing. Suppliers, customers and investors increasingly occupy overlapping roles. A company can help finance the customers buying its products, while those purchases help validate the growth assumptions supporting the next investment.
CoreWeave makes those connections tangible. Its OpenAI agreements reached US$22.4 billion last year, while Nvidia is both an investor and a major commercial counterparty. That creates multiple routes through which a change in demand or financing conditions can travel. Reuters
As we have discussed in the Canadian AI Sovereignty Series Canada is connected to this system, too. CoreWeave and Cerebras were named in March as tenants of Bell’s planned 300-megawatt AI data-centre development near Regina. The first phase is expected in the first half of 2027. CoreWeave’s involvement merits renewed attention as the financing arrangements behind the wider AI buildout become clearer. EdTech Innovation Hub
For Bell, the risk question is how much of the project’s economics depends on a tenant’s ability to sustain demand and meet its commitments. A large infrastructure customer can bring substantial revenue and substantial concentration risk at the same time. A problem elsewhere in the AI financing chain could reach this project.
There is another sovereignty issue. Canadian buildings, power and fibre are valuable assets. Effective control additionally depends on who operates the systems, holds the contracts, controls access and can keep services running through commercial disruption. The nationality of the landlord cannot answer all those questions. Calling infrastructure sovereign should begin a due-diligence process, not conclude one.
China, operational risk and the language of failure
The summit complicates the familiar suggestion that taking AI risk seriously is incompatible with technological competition. Washington and Beijing have strong incentives to compete, and strong reasons to avoid incidents that damage infrastructure or trigger escalation. Their willingness to establish a dialogue shows that these interests can coexist.
The consequential questions concern the objective, the test scope, available credentials, network access and the point at which the system recognized a boundary. Describing the event as a machine deciding to rebel adds a motive that the reported sequence doesn’t establish. It also distracts from the configuration decisions that made the actions possible.
This is the problem examined in my Latitude of Resolution research: the discretion available to an agent emerges from specification gaps, permission boundaries and environmental affordances. A goal leaves something unresolved. The agent selects an interpretation. Available tools turn that interpretation into action. Each subsequent step can introduce another decision about scope, relevance or permission.

Agency converts ambiguity into discretion; capability converts discretion into action. A system that eventually recognizes a boundary can still cause harm before it gets there. The timing of recognition belongs in the evaluation, alongside whether recognition occurs at all.

Huang, Benioff and the power centre in the room
Jensen Huang’s appearance at Salesforce’s Dreamforce supplied the week’s clearest illustration of where commercial authority now sits. Huang argued that AI safety is an engineering problem and backed a lighter regulatory approach while Marc Benioff moderated the discussion. San Francisco Chronicle
The power centre in that conversation was Huang. Benioff owned the event; Huang represented the infrastructure on which so much of the industry’s ambition depends. That is the telling interpretation of the encounter: enterprise software leaders are selling visions of what AI will do, while Nvidia occupies a position that helps determine the cost and availability of doing it.
In his subsequent CBS interview, Huang challenged dramatic warnings about AI and suggested that some executives seeking government intervention had “ulterior reasons.” That allegation is Huang’s interpretation of his peers’ motives. It does, however, sharpen a substantive disagreement over whether new AI-specific regulation is necessary or existing law and company responsibility can address the risks. Business Insider
Huang’s own commercial position matters to that argument. A company selling the infrastructure for continued expansion has an interest in continued expansion. The useful response is to examine the proposed controls: access restrictions, independent testing, incident reporting, accountability and consequences for failures. Executives’ competing accounts of one another’s motives are a poor substitute for that work.
A new paper on AI unemployment shifts the dialogue toward experience
New research by Bharat Chandar and Bouke Klein Teeselink suggests that AI adoption can accompany employment growth while shifting opportunities toward experienced workers. Drawing on 1.25 billion job advertisements and 154 million employment records, the researchers compare foreign affiliates of AI-adopting companies with similar non-adopting affiliates. Their estimates show senior employment increasing by 6.7% and the junior share of employment falling by 1.9 percentage points by March 2026. Computer and mathematical occupations also gained employment share within adopting firms, even as their workforce shifted toward senior staff. Coauthor’s research summary
The measurement distinction matters: this study includes employment records, extending beyond what employers say in job advertisements. Its causal interpretation still depends on the researchers’ comparison strategy and assumptions, and a declining junior share does not by itself establish widespread entry-level job destruction. The business implication is nevertheless significant: growing demand for an occupation can coexist with fewer opportunities to enter it. Companies expanding their experienced workforce need to consider how the next generation will acquire that experience.
Micro
Jev gives judgment its own place in software
The most interesting release this week may be a model that does not write paragraphs. TypeSafe AI’s Jev takes application state and predefined questions, then returns typed decisions with probabilities. Its outputs are produced in parallel, allowing surrounding software to use the results directly. TypeSafe calls the category “System One Models.” Its published price is US$0.042 per million input tokens, with reported response times of 70–500 milliseconds. TypeSafe AI
The distinction is architectural. Many applications need a judgment about urgency, relevance, routing or risk before deciding what to do next. Making that judgment an explicit component gives developers a place to define possible outcomes and determine what should happen when confidence is insufficient.
For my Significance research, Jev offers external support for the architectural direction: determining what matters deserves explicit treatment in an AI system. My framework proposes a defined significance scale. Jev supplies probabilistic judgments to questions chosen by the application. The connection is the decision to give judgment a distinct role in the path from information to action; Jev’s launch does not empirically validate the specific Significance scale.
That separation is useful for governance as well as efficiency. A model can estimate whether an action is appropriate, while code determines whether it is permitted and when review is required. The quality of the questions, decision thresholds and surrounding controls remains essential.
The broader release roundup can stay brief. The outline identifies Qwen3.8-Omni-Flash, dated September 18, with a one-million-token context window, as the major multimodal addition. Its official release link and specifications still need confirmation before publication. Jev earns the lead because it raises a different product question: how much of the work currently assigned to a conversational model actually requires a dedicated decision component?
Muse brings an established agentic playbook to Meta
Meta’s Muse, launched September 8, follows a product direction already familiar in China: give an assistant a goal, connect it to everyday services, and let it carry out the steps. Meta says Muse operates through a dedicated virtual computer with a browser, works across applications and continues tasks after the user closes the app. Users can interact with it through its own app or WhatsApp. Meta
Alibaba’s Qwen app provides a concrete precedent. By February, it connected shopping, payments, travel and navigation through services including Taobao, Alipay, Fliggy and Amap. Users could order food, book flights and buy movie tickets from one conversational interface. Alibaba reported more than 120 million orders during six days of its heavily subsidized Lunar New Year promotion. Those numbers reflect promotional activity, but they demonstrate that AI-mediated consumer transactions were already operating at substantial scale months before Muse arrived. Alibaba Cloud
The resemblance is clearest in the service model: conversation becomes the interface through which software coordinates and completes everyday activities. Muse brings that approach to Meta’s distribution network, with personal memory and execution across applications. Calling it a continuation of the Chinese consumer-agent playbook is a reasonable product comparison; claiming its underlying model derives from Chinese models would require different evidence.
Qwen draws on Alibaba’s integrated commerce and payments infrastructure, while Muse is designed to navigate across services through its browser and connected applications. Meta says a separate Sentinel agent checks internet-bound actions and that purchases and sending emails require user approval. The business contest is increasingly about who controls the path from a person’s request to a completed transaction—and which companies get access to that path. Meta
Policy
ALL IN’s sovereignty strategy becomes more concrete
ALL IN’s announcements add up to a more coherent policy direction when considered together. Canada and Germany committed up to C$300 million in joint funding for Yoshua Bengio’s LawZero. The organization says the money will support its research team, a Berlin office and dedicated Canadian compute infrastructure with Hypertec and 5C. Its Scientist AI programme aims to make reliability a core capability of advanced AI. LawZero
This combines an investment in a technical approach with an attempt to retain research and infrastructure capacity. The public-policy test will be what the programme demonstrates: measurable reliability, usable systems and capabilities that Canadian and European institutions can actually control.
The Mila–Mozilla announcement is similarly practical. Their new open-source AI initiative has an initial $5 million investment from Mozilla and $1 million in first-year funding from Hypertec. Mila will lead technical delivery and coordination. The partners are building a foundation that organizations can run locally, with interchangeable components, governance and access controls, and expect working reference implementations within six months. Mila
For an ordinary business, access to an open model is only the beginning. Deployment, integration, security and maintenance determine whether it becomes useful. The initiative addresses that implementation burden directly.
Taken together, these announcements suggest a middle-power strategy: develop domestic expertise, build infrastructure that institutions can control, and share the effort with international partners. Its success should be judged by the options it creates for users. Can they operate independently, change providers, protect their data and maintain service when a commercial relationship changes? Those are concrete tests of sovereignty.
Europe connects enforcement with capacity
The EU AI Board’s September 17 meeting brought recent AI incidents, enforcement priorities and cybersecurity preparation into the same discussion. Its agenda included evaluation and testing infrastructure for advanced cyber capabilities and strengthening Europe’s own AI capacity. European Commission
The Commission’s AI Office and national authorities began enforcing the relevant AI Act provisions on August 2, alongside new transparency requirements. The question is how those powers will be applied to concrete failures and provider practices. European Commission
The independent Transformative AI Strategy for Europe proposal adds a related industrial-policy argument. It recommends securing reliable access to advanced AI, strengthening compute and supply-chain positions, preparing institutions for incidents and developing assurance capabilities. It considers both access to foreign systems and domestic development, with greater emphasis on the former because of the cost of building a competitive European alternative. This is a policy proposal, not an adopted EU programme. Transformative AI Strategy for Europe
Trump’s preference: existing power
The underlying issue is familiar from Canada: the ability to regulate a supplier does not automatically provide an alternative to depending on it.
Trump’s position combines opposition to broad new AI restrictions with an assertion that his administration already has “CRIMINAL and REGULATORY power” over companies that do “bad” things.
That points toward a preference for existing executive and enforcement authority over a new framework imposing requirements before systems are deployed. Businesses should pay attention to the distinction. Fewer new rules do not necessarily mean less government intervention; they can mean more uncertainty about when existing powers will be invoked and against whom. The summit will test whether that domestic preference can coexist with a predictable international incident process.
Scuttlebutt
Bradford and the automation of apparently organic speech in Toronto’s mayoral race
According to the National Observer reporting identified for this edition, Brad Bradford’s Toronto mayoral campaign is using Israeli-developed technology to supply supporters with AI-generated suggested comments. The issue is political manipulation using Israeli technology: the ability to coordinate and generate speech that audiences may experience as independent public reaction.
Campaigns have always distributed talking points, but in this case, participants actually get points for distributing the points, pre drafted for convenience by AI. This adds the ability to produce many variations quickly and place them in the hands of people posting through their own accounts. A reader encountering those comments may see a collection of independently composed opinions without knowing that software and campaign coordination sit behind them.
Apparent consensus is itself persuasive. People use the reactions around a story to judge what neighbours think, which issues matter and whether a candidate has momentum. Coordinated, generated comments can distort that signal even when the accounts belong to real supporters.
The disclosure question extends beyond whether an individual sentence contains a false claim. It concerns who organized the intervention, who generated the language and whether the audience can recognize the campaign’s role. AI-assisted political mobilization deserves scrutiny at the point where campaign messaging becomes apparently spontaneous constituent speech.
What to watch
September 24 remains the immediate marker. The bilateral AI dialogue now has political momentum; the next test is whether Trump and Xi give it an operational form. That means named contacts, defined notification thresholds and a process officials can use during an incident. A practical communication channel could be more consequential than another expansive declaration.
Watch the financing chain as closely as the model announcements: what guarantees cover, when they can be called, how dependent infrastructure projects are on individual customers, and who ultimately carries a demand shortfall. In Canada, Bell’s development makes those questions local.
Then watch implementation. Do the EU’s discussions of incidents produce concrete enforcement decisions? Do ALL IN’s partnerships deliver systems organizations can operate and control? Does Jev’s approach attract adoption and independent evaluation sufficient to establish judgment models as a distinct category?
This week’s developments put responsibility at identifiable decision points: the financing contract, the access boundary, the deployment choice and the campaign instruction. Those are places where power can be examined, failures can be tested and accountability can be assigned.

