A near war over a report an AI invented
Special forces were preparing to board a Chinese ship on the strength of a report a chatbot fabricated. The answer under negotiation between Washington and Beijing is a mechanism to warn before acting: a telephone rather than a rule about where AI may sit.
Special forces stood ready, with aircraft support, to board a Chinese ship in the Middle East. What sustained the operation was an intelligence report stating that the cargo included components for a nuclear weapons programme. The later review showed something else: the analyst had fed the initial data into a chatbot, and the chatbot invented the cargo.
CNN revealed the case on 18 September. The episode dates from the spring of 2026, in the middle of the United States’ war against Iran, and stayed out of public view for months. A source described the intelligence to the network as “entirely false” and said it “almost started a war”. CNN could not establish what the ship’s real cargo was.
What the report said, and what it was
The technical detail is what matters. The tool mixed open-source data with secret signals intelligence and, in that mix, misidentified the contents. The analyst then used the same kind of tool to format the result to the dissemination standard — the format that circulates inside the machine and becomes the basis for an operational decision.
The chain has three links, and none of them was audited before the operation became real preparation. The first is data intake: open and secret information in the same pipe, with no separation of trust. The second is inference: a system that produces a categorical statement out of heterogeneous material, without indicating how much it is guessing. The third is packaging: the formatting to the official standard, which gives the text the appearance of verified work precisely because it obeys the form.
Inventing the cargo was the mistake. Signing the form was what nearly turned the invention into an operation.
It is the first documented case in which a language-model hallucination crossed an entire nuclear state’s intelligence chain and came to the edge of an operation against a ship of another nuclear power, in an active theatre of war. The difference between this episode and dozens of similar ones is that the review came in time.
The table in New York
Four days after publication, US Treasury Secretary Scott Bessent and Chinese Vice-Premier He Lifeng spent about eight hours in meetings at JPMorgan’s headquarters in New York, according to Reuters, CNBC and AFP. With them was US Trade Representative Jamieson Greer. The meeting prepares what comes next: a gathering between Trump and Xi Jinping at the White House on Thursday, 24 September.
The agenda is a portrait of how the two economies became inseparable and hostile at the same time. A tariff truce that expires on 10 November, safeguards for the development of artificial intelligence, chip export controls, rare-earth magnets and critical minerals, Chinese purchases of American farm goods and American pressure on Iran, whose war has entered its seventh month. CNA recorded the most interesting item: Washington proposed a bilateral incident-notification mechanism, including security threats. Bessent called the talks “very successful” and the parties agreed to meet again.
Guardrails, to what end
The word the press adopted is guardrails. It is worth reading what it covers in practice. What is on the table is the pace at which the technology develops and access to chips — the industrial contest, in other words: who builds faster and with what input. What the ship incident exposed was something else: the use of the technology inside the state’s decision cycle, where an error has no market to correct it and where there is no second attempt after the shot.
Neither delegation arrived in New York with a proposal about where AI may or may not be plugged in. They arrived with proposals about who manufactures what.
There is an uncomfortable symmetry in the calendar. The incident-notification mechanism the Americans proposed is, under another name, the same instrument that existed during the Cold War for the telephone between Washington and Moscow: a line to warn before acting, rather than a rule about what may be done. It is useful, it is cheap, and it does not solve the problem the ship episode revealed.
And there is the regional backdrop. The ship was in the Middle East, and Iran is today the point where the two powers negotiate by proxy: China buys much of Iran’s oil and sustains Tehran diplomatically, while the United States runs a war that has lasted seven months. An American boarding of a Chinese ship in that theatre would rank as the kind of accident nobody plans and neither side can undo, with nothing bureaucratic about it.
What remains
What nearly happened in the spring was an error corrected by human review, and that is what makes the case worth teaching: what failed was a process that trusted the format. The notification mechanism now under negotiation addresses the next scare, not the source of the scare.
On Thursday, Trump and Xi Jinping meet with the usual agenda, trade, technology and minerals. The report a chatbot invented is not on the list — and it should be, because it was what nearly put American special forces aboard a Chinese ship, and neither delegation has, so far, a rule that prevents a repeat.