Skip to main content
v2026.11,858 entries · CC-BY 4.0

The IDAIS-Beijing Statement, Explained: AI Safety’s Red Lines From China

The IDAIS-Beijing Consensus Statement on Red Lines, co-signed by Andrew Yao, Zeng Yi and Xue Lan alongside Bengio, Hinton and Russell, is CASRAI’s first frontier-ai-safety guide to center a non-Western academic-institution voice — and its self-modification and R&D-budget asks map to two specific NIKOLAI elements.

Written and maintained by CASRAI Editorial Board

Last updated

Last verified: September 20, 2026. On March 10–11, 2024, in Beijing, a group of AI scientists co-signed a short “Consensus Statement on Red Lines in Artificial Intelligence” — hosted at idais.ai/dialogue/idais-beijing as the record of the second dialogue in the International Dialogues on AI Safety (IDAIS) series. Its opening line sets the stakes plainly: “Unsafe development, deployment, or use of AI systems may pose catastrophic or even existential risks to humanity within our lifetimes.” What makes IDAIS-Beijing distinct from most Western-drafted AI safety statements CASRAI covers elsewhere on this site is who put a name to it: alongside Turing laureates Geoffrey Hinton and Yoshua Bengio and UC Berkeley’s Stuart Russell sit Andrew Yao (Tsinghua University, Shanghai Qi Zhi Institute), Zeng Yi (Chinese Academy of Sciences), Xue Lan (Tsinghua University), and HongJiang Zhang (Beijing Academy of Artificial Intelligence) — a genuine cross-section of China’s AI research establishment, not a token signature. This guide covers what the statement’s five red lines actually commit signatories to arguing for, who from China’s institutions is on record, and — the part most summaries skip — how two of its asks map onto specific elements in NIKOLAI, CASRAI’s own frontier-AI-safety crosswalk.

The five red lines, in the statement’s own words

The statement itself is short: five bolded red-line sentences, each stating a bright-line restriction rather than a graduated threshold. Quoted directly from the live page:

  • Autonomous replication and improvement — “No AI system should be able to copy or improve itself without explicit human approval and assistance.”
  • Power seeking — “No AI system should take actions to unduly increase its power and influence.”
  • Weapons assistance — “No AI systems should substantially increase the ability of actors to design weapons of mass destruction, or violate the biological or chemical weapons convention.”
  • Cyberattacks — “No AI system should be able to autonomously execute cyberattacks resulting in serious financial losses or equivalent harm.”
  • Deception — “No AI system should be able to consistently cause its designers or regulators to misunderstand its likelihood or capability to cross any of the preceding red lines.”

The first of these — autonomous replication and improvement — is the one this guide returns to below, because it is the clearest real-world instance of a control pattern CASRAI’s NIKOLAI dictionary already tracks under a different name: a declared condition that gates an action behind explicit human sign-off.

Who signed from China’s institutions, specifically

IDAIS-Beijing is not simply a Western statement with a courtesy Chinese co-signature. Verified directly against the live signatory list at idais.ai/dialogue/idais-beijing, at least four signatories hold senior positions inside Chinese academic and research institutions:

  • Andrew Yao — Dean, Shanghai Qi Zhi Institute; Dean, Institute for Interdisciplinary Information Sciences and College of AI, Tsinghua University. A Turing Award laureate (2000), Yao is the most internationally recognized computer scientist on the Chinese side of the list.
  • Zeng Yi — Director, International Research Center for AI Ethics and Governance, Chinese Academy of Sciences.
  • Xue Lan — Dean, Schwarzman College, Tsinghua University; Director, Institute for AI International Governance (I-AIIG), Tsinghua University.
  • HongJiang Zhang — Founding Chairman, Beijing Academy of Artificial Intelligence (BAAI).

They sign alongside Ya-Qin Zhang (also Tsinghua), Huang Tiejun and Zhongyuan Wang (BAAI and Peking University), and a Western contingent that includes Geoffrey Hinton (University of Toronto), Yoshua Bengio (Université de Montréal / Mila), Stuart Russell (UC Berkeley), Gillian Hadfield (Johns Hopkins), and Toby Ord (Oxford). The dialogue also carries two names tied to the wider IDAIS series’ own convening organizations: Fynn Heide (Executive Director, Safe AI Forum) and Adam Gleave (Founder and CEO, FAR.AI).

This matters for a specific, narrow reason: most of the AI safety statements and frameworks CASRAI has covered so far in this cluster — see International AI Safety Report 2026, The AI Safety Index, Explained, and The Center for AI Safety, Explained — are drafted, convened, or scored by US and UK institutions. IDAIS-Beijing is the cluster’s clearest instance of a consensus document where named signatories from a Chinese Academy of Sciences institute and two of China’s top research universities argue, in their own names, for the same category of restriction Western labs write into their own safety frameworks. That is not a claim about Chinese government policy — the statement is an academic consensus document, not a state instrument, and it does not speak for any government — but it is a real, citable data point against the assumption that red-line-style AI safety asks are a purely Western academic position.

The enforcement roadmap: registration, evaluation, and a one-third safety-budget floor

The statement does not stop at naming red lines; it also states what enforcing them would require. Read closely, three distinct asks sit underneath the “Roadmap to Red Line Enforcement” section:

  • Government visibility via registration. The statement calls for governments to require registration of AI models and training runs above specific compute thresholds, on the reasoning that “governments have visibility into the most advanced AI in their borders” only once that reporting exists.
  • Developer-borne evaluation burden. Developers, not regulators, are named as responsible for demonstrating — through empirical testing and evaluation — that a given system does not cross any of the five red lines before it is released.
  • A one-third R&D safety-budget floor. Under its technical-collaboration section, the statement states: “we call for AI developers and government funders to invest at least one third of their AI R&D budget in safety.” This is a specific, quantified resourcing commitment — not a general call to “invest more in safety,” but a named fraction, attributed to two categories of funder (developers and governments) at once.

None of these three is self-enforcing. The statement is a consensus document signed by individuals, not a treaty, a statute, or a framework any single lab has adopted for its own models — a distinction covered in more depth in the FAQ below.

Where NIKOLAI Fits In

CASRAI maintains NIKOLAI, CASRAI’s own independent, unendorsed reference dictionary for frontier-AI-safety terminology — not a standard, and not something IDAIS, any of its signatories, or any lab has adopted, endorsed, or been consulted on. NIKOLAI exists because labs, governments, and now multi-stakeholder statements like this one each describe overlapping safety concepts in incompatible vocabularies. Reading IDAIS-Beijing’s asks against NIKOLAI’s 64 elements, verified directly against the live element pages on September 20, 2026, surfaces two genuine, specific matches:

  • Halt Condition (element N3, track N3 — Thresholds and checkpoints) — NIKOLAI defines a halt condition as “a declared condition under which development, training or deployment must stop, stating (where the source discloses it) the authority who may invoke it and the authority and evidence needed to lift it.” IDAIS-Beijing’s autonomous-replication red line — “no AI system should be able to copy or improve itself without explicit human approval and assistance” — is structurally the same shape: an action (self-modification) is gated behind an authority (an explicit human) whose approval must be obtained before it may proceed. NIKOLAI’s own sourced crosswalk for this element currently draws on OpenAI’s cyber-capability pacing statement, Meta’s Advanced AI Scaling Framework, and the EU GPAI Code of Practice — none of which is IDAIS. Reading IDAIS-Beijing’s red line onto this element is CASRAI’s own addition, not something NIKOLAI, IDAIS, or any of its signatories has filed or agreed to.
  • Commitment (element N9, track N9 — Commitments and governance) — NIKOLAI defines a commitment as “a public statement by an identified party (a developer, a government body, or a named individual signatory) to do or not do something, carrying an explicit modality (binding / unilateral / conditional / aspirational), a scope, an effective or target date, and a status value that can be tracked over time.” IDAIS-Beijing’s one-third-of-R&D-budget ask fits this element almost exactly on its face: it is a public statement, attributed to named signatories, addressed at two identified parties (AI developers and government funders), with an explicit scope (AI R&D budget) and a quantified target (one third). What it does not carry is a binding modality, an effective date, or a tracked status — the statement asks for the commitment; it does not itself constitute one from any developer or government named in it.

A third element came close but is deliberately excluded here rather than force-fit: NIKOLAI’s Coverage scope threshold (element N1, track N1 — Actors, models and scope) defines “the if-then test that decides whether a framework, statute or programme applies to a given developer or model (for example, a compute or revenue figure that gates coverage).” IDAIS-Beijing’s registration call gestures at exactly this shape — “registration… above certain compute thresholds” — but the statement itself does not publish a specific number, unlike the 10^26-FLOP figures that anchor Meta’s framework, California SB 53, and the EU AI Act’s Article 51 in NIKOLAI’s own sourced crosswalk for that element. An unquantified threshold call is a real ask, but it is not the same as a coverage-scope-threshold record, which requires a stated figure or an explicit disclosure that the figure is classified or referenced-but-undefined. CASRAI is noting the parallel, not filing a shadow-mapping row for it.

Every row above is, in NIKOLAI’s own terms, a shadow mapping: CASRAI’s own reading of a published document, not a match any lab, evaluator, regulator, or IDAIS signatory has declared, endorsed, or been consulted on. That changes only if an organization files its own Mapping Declaration.

How a multi-signatory statement differs from a lab’s own safety framework

It is worth being precise about what kind of document this is, because it is easy to read “red lines” and assume it functions like a lab’s Responsible Scaling Policy or Preparedness Framework. It does not. A lab’s own framework (see What Is a Frontier AI Framework? and Frontier AI Labs) is an operating document that organization has adopted for its own models, with named capability thresholds and pre-committed mitigations it applies to itself. IDAIS-Beijing is the opposite kind of object: a set of individuals, drawn from labs, universities, and civil-society organizations across multiple countries, arguing in their own names for restrictions that no single one of them can bind any government or company to adopt. It sits closer in kind to the Statement on Superintelligence — another open, multi-signatory consensus document CASRAI covers — than to any individual lab’s framework, though the two differ sharply in specificity: the Statement on Superintelligence asks for a blanket development prohibition until two broad conditions are met, while IDAIS-Beijing names five narrower behavioral red lines and attaches concrete enforcement mechanisms (registration thresholds, developer-borne evaluation, a quantified budget floor) to them.

Frequently asked questions

Is the IDAIS-Beijing statement binding on any government or AI lab?

No. It is a consensus statement signed by individual scientists and researchers, not a treaty, statute, or regulation. None of its three enforcement asks — compute-threshold registration, developer-borne evaluation, or the one-third R&D safety-budget floor — creates a legal obligation on its own; each would require a government or developer to adopt it separately.

Does the one-third AI R&D safety-budget figure come from a specific lab’s disclosed spending?

No. It is IDAIS-Beijing’s own recommendation, addressed at AI developers and government funders generally. CASRAI is not aware of any named developer or government that has publicly reported meeting a one-third-of-R&D-on-safety figure; this guide does not claim one has.

Is IDAIS-Beijing the same document as the Statement on Superintelligence?

No, and they should not be conflated. IDAIS-Beijing predates it (March 2024) and takes a narrower, mechanism-specific approach — five named red lines plus enforcement proposals — where the Statement on Superintelligence is a single-sentence, blanket development-prohibition petition. See CASRAI’s separate guide, The Statement on Superintelligence, Explained, for that document specifically.

Who else has signed statements in the wider IDAIS series?

IDAIS-Beijing was the series’ second dialogue. Signatories on the Beijing statement include Fynn Heide (Executive Director, Safe AI Forum) and Adam Gleave (Founder and CEO, FAR.AI), both tied to organizations associated with the wider IDAIS dialogue series; this guide covers the Beijing statement specifically and does not attempt to catalogue every dialogue in the series.

Does NIKOLAI’s Halt Condition or Commitment element mean CASRAI has verified IDAIS-Beijing’s asks as technically sound?

No. NIKOLAI documents vocabulary; it does not evaluate or endorse the merits of any policy proposal, including this one. The crosswalk above states that two of IDAIS-Beijing’s asks share a structural shape with elements NIKOLAI already tracks from other sources — nothing more.

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Ask CASRAI · free to try

Ask about The IDAIS-Beijing Statement, Explained: AI Safety’s Red Lines From China

Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.

Ask CASRAI answers research-administration questions and cites the passages behind every claim. When our sources don't cover a question, it says so.

Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.

Works on this site and inside Claude, Cursor and the AI tools you already use.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →