ChinaChina
China Markets
CSI 3004,547.96 1.38%
Hang Seng25,278.30 1.13%
Shanghai3,941.39 0.97%
CNY/USD6.7210 0.07%
HuxiuFEATURE · TRANSLATED

Translated from Chinese · 9/2/2026 · 27 min read · 文化纵横

Original: 美鹰派报告罕见承认“双线失守”: 限72小时审核中国新AI模型, 防其全球扩散 · https://www.huxiu.com/article/4887934.html

US Hawkish Report Rarely Admits 'Two-Front Failure': 72-Hour Review of Chinese AI Models to Prevent Global Spread

In 2026, the World Artificial Intelligence Conference and the High-Level Meeting on Global Artificial Intelligence Governance were held in Shanghai, where China proposed a vision of artificial intelligence "empowering thousands of industries," "shaping the values of artificial intelligence with the common values of all humanity," and "helping the Global South bridge the digital divide." At this time, China has become one of the leaders in the global artificial intelligence field, with a series of world-renowned artificial intelligence companies, including DeepTech, ZhiPu, DarkSide of the Moon, and MiniMax.

As China's advanced artificial intelligence continues to progress and empower socio-economic development, it has also spread globally, even to the US, where Chinese AI models have gained favor with some enterprises and individuals due to their lower prices. For a long time, the US has controlled many global infrastructures and key industries, including computing, communication, financial payments, satellite positioning, software development, and operating systems. These products and facilities are widely used globally, to the extent that the US can use them as a weapon and as the foundation of its hegemonic system, such as restricting Russia's use of US software and information services after the outbreak of the Russia-Ukraine war. The widespread application of Chinese emerging technologies, including AI models, 5G communication, and photovoltaic green energy, is trending towards breaking this hegemonic monopoly, which naturally touches a nerve with US hawks.

Advances in science and technology were a key driver of the United States' global dominance throughout the 20th century. The White House's July release of "Science: A New Golden Age" provided a comprehensive examination of the US research system and the impact of AI on science. One of the report's starting points was the realization that the US's leadership in global science and technology is no longer unshakeable, with China being a key challenger, posing a challenge that the US has not faced even during the Cold War, due to the Soviet Union's significantly smaller economic scale. Trump has been even more ambitious, emphasizing that "our competitors are working hard to catch up with the US, and we must boldly pave the way to maintain our technological lead."

Against the backdrop of China's achievements, hawks have a different perspective on understanding today's China and its artificial intelligence. This report is a product of such a "confrontational" mindset, which starts from the perspective of American interests and argues that China's artificial intelligence poses a threat to US national security. In the military field, there are concerns that AI will enhance China's military capabilities; in the economic and technological fields, there are concerns that China's productivity will continue to improve and squeeze out American competitors in the global AI market. Ultimately, these various "security threats" are used to lobby the state machinery to take an action that is no longer new - suppressing China.

This article is compiled by Cultural Landscape New Media and originally published by the Center for a New American Security (CNAS), with the original title "Red Lines: Understanding the National Security Risks of China's Advanced AI". The article clearly reflects the US perspective and does not represent objective facts, so readers are advised to read it critically to understand the US perspective on China's AI.

I notice the source text is just a publication name and section title, not an article to translate. Since you've instructed me not to prepend newsletter names or digest branding, there's no article content to translate here. Please provide the actual article text you'd like translated.

No. 45, 2026, Total No. 325

China's advanced artificial intelligence is seen as a threat to US national security, as it has the potential to surpass American capabilities in areas such as facial recognition, natural language processing, and autonomous systems. The US government has expressed concerns that China's AI development could be used for military purposes, such as developing autonomous weapons and enhancing surveillance capabilities. Additionally, the use of AI in China's Belt and Road Initiative has raised concerns about the potential for China to expand its geopolitical influence and undermine US interests. The US has responded by increasing investment in its own AI research and development, as well as implementing measures to restrict the transfer of AI technology to China.

The report uses the term "advanced AI systems" to describe AI models commonly referred to as generative AI, large language models (LLMs), or foundation models. Advanced AI systems also encompass other widely used related tools, such as chat interfaces and agent harnesses, which are software that enable AI models to perform specific actions, like browsing the web or running code. This term is widely used in international discussions, although its specific meaning is not entirely consistent; using this terminology avoids confusion with regulatory definitions that are still taking shape.

China's advanced artificial intelligence systems are currently in a state of rapid development, with many companies and research institutions actively exploring and applying various AI technologies. However, as AI systems become increasingly complex and autonomous, the potential risks associated with their development and deployment are also growing. According to a recent report, the Chinese government has begun to take steps to assess and mitigate these risks, including establishing a national AI governance framework and implementing stricter regulations on the development and use of AI systems. The report notes that China's AI industry is facing significant challenges in terms of ensuring the safety, security, and reliability of AI systems, particularly in high-risk areas such as finance, healthcare, and transportation. Experts warn that the lack of transparency and accountability in AI decision-making processes, as well as the potential for AI systems to be used for malicious purposes, pose significant risks to individuals, organizations, and society as a whole. To address these concerns, the Chinese government is encouraging the development of more transparent and explainable AI systems, as well as the establishment of industry-wide standards and best practices for AI development and deployment. In addition, many Chinese companies, including tech giants such as Baidu, Alibaba, and Tencent, are investing heavily in AI research and development, with a focus on developing more advanced and

China's AI vanguard refers to the group of pioneering companies and research institutions at the forefront of the country's artificial intelligence development, including Baidu, Alibaba, Tencent, and iFlytek, as well as top universities such as Tsinghua University and the Chinese Academy of Sciences. These entities are driving innovation and advancements in AI technologies such as natural language processing, computer vision, and machine learning, with applications in areas like autonomous vehicles, smart homes, and healthcare.

By combining multiple metrics, key players in China's artificial intelligence ecosystem can be identified. Three categories of metrics correspond to different dimensions of measurement, ultimately pointing to China's most advanced AI systems. These categories include: intelligence level, real-world value, and technical design. An AI developer does not need to be a leader in all categories to have strategic importance. The developers identified in this report are representative because they demonstrate competitiveness in enough categories to collectively support a vibrant AI ecosystem.

Based on these metrics, this report identifies seven leading developers in China's artificial intelligence ecosystem: Alibaba, ByteDance, DeepSeek, MiniMax, Moonlight, Tencent, and Zhixu. The flagship models of these companies are at the forefront among their Chinese peers, but still lag behind AI models developed by US-based Anthropic, Google, and OpenAI.

Field of Action

Conventional military capabilities

Advanced artificial intelligence systems can help the military operate on a larger scale, at faster speeds, and with a higher level of coordination. Although it is difficult to fully assess the actual maturity of Chinese AI systems in military applications based on publicly available information, benchmark test results and related reports released by the US and China can reflect the current and potential future applications of these systems. The combination of intelligent agent capabilities, software engineering capabilities, multimodal recognition capabilities, and multi-step reasoning capabilities is expected to play an important role in areas such as command and control, logistics support, decision-making support, and intelligence analysis.

The most direct applications currently focus on analysis-intensive, high-latency tasks before and after kinetic engagements, such as integrating multi-source intelligence, generating and prioritizing target lists, tracking logistical support, and assessing battle damage. The US military's early experience in the 2026 Iran operation exemplifies this trend. According to reports, Anthropic's Claude series model participated in target identification and strike support, enabling the US military to complete strikes on over 1,000 targets within the first 24 hours of the operation, demonstrating how AI capabilities can quickly translate into real combat advantages.

The Center for Security and Emerging Technology (CSET) analysis suggests that China is increasingly adopting Chinese advanced AI systems, particularly models from Alibaba and DeepSeek, for tasks such as intelligence analysis. According to data compiled by CSET, between 2023 and 2024, 70% of entities globally that secured AI-related procurement contracts were non-traditional suppliers.

We believe that in the SWE-Bench Pro benchmark test, which evaluates the ability of models to solve complex software engineering problems, the leading Chinese AI system achieved an accuracy rate of around 50%, while GPT-5.2 and Claude Opus 4.6 both exceeded 55%. In the Terminal-Bench 2.0 test, which assesses the ability of AI agents to autonomously solve software engineering problems through command lines, the Chinese models Kimi K2.5 and GLM-5 scored 50.8% and 56.2%, respectively, while GPT-5.2 and Claude Opus 4.6 scored 54% and 65%, respectively, with the gap narrowing.

These achievements are sufficient to support the selective application of artificial intelligence in areas such as intelligence analysis and operational planning, which are also the military application directions where artificial intelligence has been proven to be most valuable; however, these systems are not yet mature enough for widespread deployment. Firstly, due to the limitations of onboard hardware, the energy consumption required to run artificial intelligence systems is still too high; secondly, the real-time requirements of weapon system operations are in fundamental conflict with the latency generated by model inference that relies on network connections. The battlefield environment also poses challenges such as decreased sensor performance, electromagnetic interference, and adversarial environments, and the current artificial intelligence systems do not perform well under these conditions. Even at the operational level, integrating artificial intelligence systems into existing software and data systems faces significant limitations. Furthermore, embedding artificial intelligence into existing command systems also involves various challenges, including establishing trust mechanisms, managing failure risks, and clarifying responsibility attribution. Regardless of the performance of the models themselves, these factors will slow down the military application of artificial intelligence. However, these limitations are mainly engineering and organizational management issues, rather than fundamental limitations of artificial intelligence capabilities themselves.

As artificial intelligence capabilities continue to advance, model compression technology is helping to overcome these technical limitations. Quantization technology reduces the memory space and energy consumption occupied by model weights, shrinking the model size with limited precision loss. Distillation, a technique that utilizes a developer's own large models to train smaller ones, can generate efficient versions that retain most of the flagship model's capabilities at extremely low computational cost, particularly suited for specific task domains. Modern weapon platforms often lack the hardware conditions required to run large AI models, but we believe that lightweight versions produced by models such as those from Alibaba or DeepSeek through distillation can theoretically run on devices equivalent to those used by the US military. As China explores which AI capabilities are best suited for deployment on edge devices and develops onboard compute capabilities, we believe that cutting-edge AI in both China and the US will gradually enter real-world battlefield environments.

Cyber Capabilities

One area where Chinese artificial intelligence-powered cyber operations could have the most direct impact on US national security is that Chinese AI systems can be deployed locally, making them uncontrollable by the US through intervention at the model level. The US defense side cannot track the output generated by these systems, nor can it cut off their operation.

Chinese artificial intelligence systems are currently capable of playing a role in certain aspects of offensive network operations, although some of these capabilities have not undergone rigorous public evaluation. In a test on CyBench, a rare network security evaluation benchmark that models have not thoroughly mastered, DeepSeek-R1, GLM-4.7, and Kimi K2 Thinking were able to handle common and relatively straightforward security testing tasks, but still required human guidance for complex, multi-step vulnerability exploitation tasks. In contrast, OpenAI's GPT-5 has sufficient capabilities to autonomously complete certain tasks with a certain level of complexity, which are typically performed by intermediate-level network operators. This gap reflects the difference between two types of systems: one that can only assist in completing isolated sub-tasks, and another that can substantially improve overall operational efficiency. However, continued technological advancements mean that Chinese AI systems may reach this capability threshold at some point in 2026.

The open-weight release has further enabled these capabilities to be accessed by US-identified "adversarial nations" and non-state actors. Through model fine-tuning, even models with robust security mechanisms can have their security restrictions weakened or removed at a relatively low cost; meanwhile, Chinese AI developers have been found to be under-invested in protection mechanisms for network security-related outputs, according to US assessments. Although DeepSeek-R1's technical capabilities are on par with GPT-4O or Claude Opus 4.5, it rejects US-identified "harmful network security-related requests" at a rate of less than half of the latter two. As a result, Chinese models with stronger capabilities are more permissive by default and easier to be manually adjusted to a completely open state.

Biological capabilities

Public benchmark tests and research results disclosed by companies themselves have shown that China's leading artificial intelligence systems possess strong biological knowledge and reasoning capabilities. These capabilities have raised concerns in the US about the dual-use applications of AI in the biological field. However, in the most stringent studies to date on how advanced AI could potentially aid in the development of biological weapons, the US has not included Chinese AI systems in its assessment. In February 2026, an intelligence agency capability assessment aimed at overcoming previous testing limitations only tested models from Anthropic, Google, and OpenAI.

Nevertheless, we believe that China's AI systems may be on par with the US in terms of biological weapons capabilities. In the Virology Capabilities Test, DeepSeek-R1 achieved a score of 38.6% in a text-based question test, significantly higher than the human average of 22.6%. From a practical application perspective, the model can already assist in troubleshooting experimental procedures, interpreting DNA sequences, and analyzing pathogen characteristics at a level exceeding that of trained virologists.

Economic and Technological Fields

Industrial capability

China's advanced artificial intelligence systems have demonstrated sufficient capabilities, particularly in the field of programming, to support numerous industrial applications. Modern manufacturing and industrial systems are increasingly reliant on code execution - processes such as process control, quality monitoring, supply chain logistics, and predictive maintenance all rely on software. The SWE-Bench Pro scores mentioned earlier indicate that China's leading AI systems are capable of handling around three-quarters of the software engineering tasks measured by the benchmark. Even partial automation could revolutionize industrial production, and Chinese companies are actively experimenting with related applications. Within weeks of the release of DeepSeek-R1 in January 2025, more than 20 central state-owned enterprises in the industrial sector, including Sinopec and Sinochem, began integrating it into their businesses.

Intelligent agent tools may further enable multi-step industrial operations. Kimi K2.5 claims to be able to create up to 100 sub-agents, executing over 1,500 coordinated operations in parallel, achieving a 4.5-fold speed boost in complex analysis tasks. Supply chain optimization tasks - such as evaluating inventory levels at dozens of warehouses, comparing transportation plans, identifying bottlenecks, and adjusting procurement plans - are naturally suited to this type of technology. Currently, it is reported that China's State Grid is deploying an AI-assisted power grid monitoring and optimization system. However, for now, these tools are mainly accelerating certain independent tasks, rather than being responsible for coordinating entire industrial operations from end to end. The real concern is not whether they can operate perfectly today, but that intense domestic competition and national demand are driving rapid iteration, which may quickly narrow the gap between them and actual deployment in the next one or two generations of products.

Multimodal recognition can further improve efficiency. Chinese researchers have demonstrated how image analysis can detect subtle cracks or surface defects that human inspectors may miss. Maintenance technicians can also take pictures of unfamiliar equipment and obtain equipment identification results, technical specifications, and maintenance operation procedures. Professional systems like Qwen3-VL, which support visual detection workflows, have reportedly been applied in automotive parts manufacturing.

These capabilities can be fully embodied in the field of robotics. Image recognition, reasoning ability, and intelligent tool usage converge in robotic systems, a technology sometimes referred to as "embodied AI", which Chinese developers are actively laying out. Humanoid robot manufacturers such as Unitree have collaborated with Alibaba and DeepSeek. In addition, other important product categories that are the focus of China's industrial policies are also integrating Chinese artificial intelligence technology. BMW has partnered with Alibaba to embed the Qwen model in its Neue Klasse series cars produced in China, with plans to apply it starting from 2026. Tencent is developing "world models" that can simulate physical environments, further driving the combination of multimodal reasoning and reinforcement learning processes used to train autonomous systems.

Research and Development Applications

Advanced artificial intelligence systems that can accelerate the development of the entire scientific research system may become a strategic capability for China. China has elevated AI-driven scientific research to a key strategic priority, stating that "it is necessary to leverage AI to lead the paradigm shift in scientific research, accelerate technological innovation and breakthroughs in various fields." Accelerating scientific discovery and driving the transformation of the research and development (R&D) model are the first two key tasks of the "AI Plus" initiative.

So far, these capabilities have primarily focused on productivity-enhancing tasks, such as automating peer review and data annotation. More ambitious endeavors, however, hint at future directions. The StarWhisper Telescope system, released in November 2025, utilizes intelligent agents driven by DeepSeek-R1 to achieve autonomous observation and analysis. Notably, the system still relies on a model that has been available for nearly a year, indicating that Chinese scientists remain relatively slow in adopting existing AI capabilities.

Chinese artificial intelligence developers are closely following related discussions in Silicon Valley and are likely to develop along the path already taken by leading US AI developers, utilizing their own AI systems to carry out autonomous and accelerated internal research and development. MiniMax claims that its MiniMax-M2.7, released in March 2026, is its "first model to deeply participate in its own evolution," and is expected to have taken on around 30% to 50% of the development process. In the future, such activities may eventually extend to research in life sciences and other scientific fields, directions that US AI developers have already begun to explore.

Computational efficiency, model compression, and open-weight releases.

Sufficient capability is the basic threshold for adoption, but China's AI developers have also taken three additional design strategies, driving the adoption of AI in China's domestic industrial sector while creating economic dependence overseas: compute efficiency, model compression, and open-weight publishing.

Computing efficiency is both a result of proactive choice and a necessity of reality. The US export controls have prompted China to develop more efficient architectures, but low-cost reasoning also aligns with China's interests in driving the large-scale adoption of AI both domestically and abroad. Alibaba claims that its Qwen3 model series can deliver performance on par with US models at a fraction of the computing resources and cost. Although CAISI found that one US model costs 35% less than DeepSeek-R1 when reaching similar capability levels, the lower prices of Chinese AI systems still hold irresistible appeal for many potential users. On the OpenRouter platform, popular among startups, the top three most-used models as of early 2026 were all from China, with prices up to 17 times cheaper than their US counterparts.

Chinese developers have further advanced this logic through model compression. Alibaba's Qwen3 series includes 32 models, with parameter scales ranging from 0.5B to 235B, where the smallest model is compact enough to run on a mobile phone, while the largest model is comparable to cutting-edge US models. Each model offers multiple compressed versions of varying degrees, mainly achieved through quantization, which trades off a small amount of precision for significant gains in speed and efficiency.

In comparison, leading US developers primarily offer a handful of large models, with the smallest version of OpenAI's open-source weight model, gpt-oss, having 20B parameters, which is small enough to run on high-end consumer-grade graphics cards but still too large to run on smartphones.

The third pillar of the strategy is open-weight release, which translates computational efficiency and model compression into broader technological diffusion. Permissive licensing allows users to deploy, fine-tune, and use the models commercially without relying on the developers' infrastructure. The traditional view that model choice does not lead to lock-in, even for open-source models, misunderstands how organizations adopt technology. Small, agile startups can switch models at relatively low cost, but large enterprises and government departments, especially in developing countries, cannot do so easily. Once an organization has selected a vendor, built workflows and testing infrastructure around the model, and integrated it into existing systems, switching models incurs high organizational costs - even if it is technically feasible. Risk-averse procurement processes often favor continuing to use established vendors. Models that have been fine-tuned and incorporated into an organization's knowledge may also not be replicable on new models, and we need to be aware of the scale advantages that China can generate from global enterprises and government entities using Chinese models.

China's AI systems are accelerating the country's industrial modernization and scientific and technological goals by achieving manufacturing automation, optimizing supply chains, and shortening the R&D cycle for strategic industries. As cumulative productivity gains continue to build, the long-term result will be the formation of an industrial foundation that can compete with and replace US production in one industry after another. Furthermore, technical design choices such as computing efficiency, model compression, and open-weight licensing are aimed at maximizing the global spread of Chinese AI, enabling it to compete with the US and create structural dependence. The combination of these two paths embodies an open and globally competitive Chinese strategy.

▍Absolute risk and its consequences

The US Department of Commerce has only released three assessments of Chinese AI systems, each time weeks or even months after the relevant assessments were completed. Meanwhile, the US government has neither promoted the issue at the diplomatic level nor taken corresponding policy actions, thereby ceding control of public opinion to Chinese AI developers and allowing these systems to be widely adopted without scrutiny. Since adding Zhiyun to the entity list in 2024, the US government has not taken further action against any Chinese AI developers. Although Asian and European allies have shown interest, no coordinated policy actions have been taken against any Chinese AI developers, and information sharing remains limited and lacking in continuity.

Over the past two years, Chinese AI systems have been roughly 3 to 12 months behind the US cutting-edge level, with adversarial distillation maintaining this pace of pursuit. Anthropic, Google, and OpenAI have all recently reported that their models were targeted by such actions, specifically naming DeepSeek, Moonshot, and MiniMax. The lack of mitigation measures and legal remedies highlights the vulnerability that US AI developers continue to face. China's ability to absorb or exploit these technological advancements, thereby undermining US national security, further exacerbates the absolute risk posed by Chinese AI systems.

This also means that the risks documented in this report have a very short shelf life. A system assessed in early 2026 as not yet possessing partial capability could cross that threshold by the end of the year.

Analyzing the issue based on the relative gap between Chinese and US AI systems does not well serve policymaking. The continuously expanding capability gap between the US and China can indeed reduce some risks in certain risk categories, but it has no actual impact in some risk categories, and neither can completely eliminate any risk.

The proposed policy recommendations are the first step in translating this analysis into action. The purpose of each recommendation is to enhance evaluation capabilities, not only to determine the ranking of Chinese AI systems, but also to assess what they can actually do.

Policy Recommendations

The threats documented in this report require more drastic policy tools than those proposed, such as further tightening export controls, implementing investment restrictions, and utilizing the US Department of Commerce's Information and Communications Technology and Services Program to take action. If the US government currently lacks the necessary analytical and institutional capabilities, these policy tools cannot be precisely calibrated. Therefore, building such analytical and institutional capabilities should be seen as a complementary measure to undermine the Chinese AI ecosystem.

The US Department of Commerce shall publish a national security risk assessment for these advanced AI systems within 72 hours of their release in China.

If directed by the Department of Commerce, CAISI has the capability to conduct rapid assessments of Chinese AI systems. Under clear guidance, rapid assessments should examine the technical characteristics, security vulnerabilities, and capabilities of the systems, and compare each Chinese AI system to its counterparts in the US and China. The assessment framework should be standardized and developed in conjunction with the Department of Defense, Department of Energy, and the State Department. At a minimum, it should include the evaluations of agent hijacking, jailbreaking, and censorship that CAISI conducted in its two reports in 2025. Assessment results involving classified or sensitive information should be provided to the US government for internal use within 96 hours of system release, and to allies as appropriate.

A 72-hour assessment period should apply to major releases, such as the launch of a new model series, like the transition from Qwen2 to Qwen3, or significant upgrades, like from DeepSeek-R1 to DeepSeek-R1-0528. The Ministry of Commerce should announce in advance which systems and developers will be assessed, and should cover at least the major model releases of the seven Chinese AI developers focused on in this report. Even a preliminary assessment to identify risks and vulnerabilities would be more valuable than having no independent assessment at all, as Chinese AI systems are widely adopted by US companies and researchers.

Currently, CAISI has a relatively limited budget, and although assessing Chinese AI systems is a key part of its responsibilities - a role clearly outlined by US Commerce Secretary Howard Lutnick - CAISI's evaluation of Chinese systems remains largely ad-hoc and non-systematic.

Congress should appropriate at least $10 million to $20 million annually for CAISI's China AI assessment mission. The underlying authorization already exists under NIST's foundational statute, but a formal directive from the Commerce Secretary would make the 72-hour assessment timeline binding. In their 2025 report "Prepared, Not Paralyzed," Janet Egan, Spencer Michaels, and Caleb Withers of the Center for a New American Security also detailed further measures to strengthen CAISI's overall authority and resource allocation.

The US Cybersecurity and Infrastructure Security Agency (CISA) should issue cybersecurity alerts and advisories targeting China's advanced AI systems and lead the establishment of an "Artificial Intelligence Information Sharing and Analysis Center" (AI-ISAC), which would aggregate threat intelligence from US AI developers.

The cyber security vulnerabilities documented in this report require immediate action to protect critical infrastructure and enterprise systems. CISA should issue alerts to warn organizations in the US about the specific risks associated with China's advanced AI systems, including increased vulnerability to agent hijacking attacks and incomplete security documentation. The alerts should include technical guidance on vulnerability detection, risk mitigation, and secure alternative solutions, and be updated in real-time as new vulnerabilities are discovered, incorporating the assessment results recommended in this report to be conducted by the Department of Commerce.

To sustain this effort, CISA should work with the Commerce Department and the Office of the National Cyber Director to establish the Artificial Intelligence Information Sharing and Analysis Center (AI-ISAC) required under the AI action plan.

US technology companies, including major AI developers, possess substantial intelligence on China's AI-driven threats, yet this information remains fragmented, and competitive considerations impede meaningful information sharing. AI-ISAC should enable developers to share indicators of compromise and emerging attack methods without exposing proprietary information, thereby building a comprehensive picture of the Chinese threat landscape to inform CISA's public security advisories and the development of an AI incident response framework. A priority workstream should be established to identify signatures of AI-driven cyberattacks and integrate them with capability assessments, enabling clear analysis of which AI systems and associated capabilities attackers consider operationally valuable.

The AI-ISAC should be modeled after existing industry-specific Information Sharing and Analysis Centers (ISACs), with the Department of Justice issuing guidance to clarify that good-faith participation in information sharing is protected by antitrust safe harbors. Initial funding could range from $10 million to $15 million, sourced from the Cybersecurity and Infrastructure Security Agency's (CISA) budget and congressional appropriations, supplemented by membership fees.

3. The U.S. Department of Commerce, in coordination with the Department of Defense, the Department of Energy, the Department of State, and American companies, should develop security testing guidelines for entities that host, distribute, or provide regulated access to AI models developed by foreign adversary entities within the United States.

The National Institute of Standards and Technology (NIST) should develop security testing and assurance guidelines specifically for AI models developed by foreign adversaries and hosted, distributed, or made accessible by entities within the US. The testing should include, but not be limited to, the model's vulnerability to jailbreaking and prompt injection, ideological bias, presence of backdoors, and inadequacy of security measures to prevent abuse. These guidelines should require the disclosure of testing results and security measures before hosting the models, enabling enterprise customers and government procurement officials to compare different service providers and encouraging more comprehensive security protection and analysis.

Another complementary effort is to develop best practice guidelines for various US institutions, based on the aforementioned CAISI national security risk assessment, to help them mitigate the risks posed by AI models developed by foreign adversaries, without undermining the competitiveness of US companies. On the contrary, these guidelines will facilitate collective action and protect US companies, including cloud service providers, from greater reputational and legal risks that may arise from being used as a conduit for espionage or sabotage activities. This risk is far more damaging to customer trust than reducing the catalog of models that can be offered.

The U.S. Department of Energy should leverage infrastructure established under the Genesis Mission framework to set up a classified adversarial testing program targeting advanced Chinese AI systems at national laboratories, coordinating with the Department of Defense, the Department of Commerce, and the Office of the Director of National Intelligence (ODNI).

The analytical gaps documented in this report are particularly severe in classified domains. While information secrecy necessarily restricts the pool of personnel who can act on such intelligence, some of the most critical questions regarding China's AI capabilities cannot be responsibly or feasibly tested in unclassified environments.

The Genesis program's investment in the national laboratory's comprehensive AI platform provides the computational foundation for this work without requiring the construction of new infrastructure or reliance on commercial cloud service providers that may record sensitive query content. The Department of Defense and the Office of the Director of National Intelligence (ODNI) should provide threat scenarios and operational requirements, while the Department of Commerce should provide CAISI assessment data as baseline inputs. This classified project should be designed to produce decryptable summaries and risk ratings that can be made public, and these results should be fed back into the public CAISI assessment recommended in this report. While maintaining the confidentiality of specific operational details, it should provide information support for broader policy responses.

5. The U.S. State Department should regularly convene core allies to share information on China's AI ecosystem and coordinate collective policy actions.

Allies need sustained, organized coordination to prevent Chinese AI systems from becoming the default digital infrastructure of the global economy. Existing multilateral cooperation mechanisms are inadequate for this task. The International Network for Advanced AI Measurement, Evaluation, and Science, which involves the U.S. government and 10 other member states, provides a useful platform for technical agencies to share evaluation methodologies. But its membership includes countries that pursue balancing strategies between the U.S. and China; the mechanism does not operate at the policy level, nor does it have a mandate to coordinate restrictive measures or share intelligence. What is truly needed is a smaller, higher-level coordination mechanism.

The State Department should convene this group under the leadership of the Bureau of Cyberspace and Digital Policy, with support from the Commerce Department, the Defense Department, the Energy Department, the White House, and the Office of the Director of National Intelligence.

The group should initially include the UK, Japan, South Korea, Australia, Canada, Israel, the Netherlands, and Germany—countries that possess both the relevant technical capabilities and a "strategic alliance" with the United States. Such a smaller body would be sufficiently agile to take action while maintaining enough mutual trust to share sensitive information. Meetings should be held monthly, with participants at least at the assistant secretary level, ensuring attendees either hold decision-making authority or can directly inform decisions.

The group should establish three workstreams within four months of its formation: first, develop common assessment standards for Chinese AI systems; second, create a coordinated information disclosure framework that staggers the release of evaluation results and threat notifications; and third, establish a standing mechanism for joint action against Chinese AI developers and systems of concern. Over the long term, the group could gradually evolve into a formal institution for coordinating technology protection measures.

An obvious potential issue is that this group may ultimately become another coordinating mechanism that holds regular meetings but yields little in terms of actual results. Therefore, the three proposed working directions are designed to force the group to take action, rather than simply issuing meeting minutes and statements. If the group fails to achieve visible results within its first year of establishment, it should be disbanded.

The US Department of Commerce should work with the Department of Defense, Department of Energy, Department of State, and the Office of the Director of National Intelligence (ODNI) to release a report every six months on the status of China's AI ecosystem and its supply chain, providing a basis for export controls, investment reviews, and other restrictive measures.

Since 2017, nearly all actions aimed at weakening China's AI ecosystem have originated from the executive branch, with Congress playing only a limited role. Without regular reporting on China's AI ecosystem, Congress lacks a baseline for assessing whether existing policies are effective and whether new authorities need to be granted to the government.

Submitting assessment reports to Congress on a regular basis would help lawmakers weigh whether to expand government authority, allocate resources, and meet the requirements of supporting long-term strategic competition. However, rather than issuing them once a year, a semiannual cadence would better align with the rapid pace of AI technology development.

The article was originally published by the Center for a New American Security (CNAS), titled "Red Lines: Understanding the National Security Risks of China's Advanced AI". It is welcome to be shared by individuals, but media outlets must contact the copyright holder for republication.

Source: www.huxiu.com/article/4887934.html · Syndicated under attribution policy