China's Ministry of State Security Publicly Warns on AI Risks and the Implications for US-China AI Security Competition
Executive Summary
Remarks on AI threats by Minister of State Security Chen Yixin came ahead of the September 24 US-China summit. Externally, China refutes US-led calls to slow down AI development, framing them as a tactic in a hegemonic competition. At the same time, the Ministry of State Security has specifically identified models from OpenAI and Anthropic as threats to political, ideological, and cybersecurity. This reveals a dual structure in which external rhetoric and internal threat perceptions are proceeding on separate tracks. Rather than fully aligning with the US-China discursive competition, South Korea should prioritize building its own defense capabilities and information-sharing channels against the emerging security threat of state-backed AI misuse.
I. Analysis of the Current Situation
China's Ministry of State Security Publicly Warns on AI Risks: An Analysis of the Situation
1. Background and Developments
The remarks by Minister of State Security Chen Yixin came ahead of the US-China summit [1]. AI safety has emerged as a key agenda item for the Washington summit scheduled for September 24 [1]. The Ministry of State Security is China's top intelligence agency, performing the dual functions of a foreign intelligence service and a domestic anti-dissident surveillance body. The public mention of AI threats by the head of this agency is considered Beijing's most specific expression of its security concerns to date [4].
The timing of the remarks was not coincidental. On September 12, Anthropic CEO Dario Amodei published an article urging a slowdown in AI development, a call echoed by OpenAI and several US politicians [14]. Amodei warned that swarms of autonomous AI agents could take over the internet via botnets within 6 to 12 months [9][14]. Underlying this statement was the premise that US companies must maintain their competitive edge over China [17].
The Chinese government immediately refuted these arguments. Foreign Ministry spokesperson Guo Zhakun stated, "Fear-mongering, confrontation, and malicious competition will only hinder progress in global AI governance and serve no one's interests" [16]. The state-run Global Times also criticized the US framing of AI as a competition and its "China threat" narrative for dividing global governance [17]. According to a report by The Hankyoreh, the US call for a slowdown is viewed in China as an attempt to "kick away the ladder" by raising barriers to entry, while within the US, it sparks fears of China catching up, leading to mixed reactions in both countries [7].
2. Current Situation
Separate from its external refutations, Chen Yixin's remarks are different in nature, reflecting an internal threat perception. He specifically pointed to the threats AI could pose to political, institutional, and ideological security [10]. Warning that advanced AI could discover cyber vulnerabilities and conduct large-scale hacking operations, he specifically mentioned Anthropic's Claude-Mythos and OpenAI's ChatGPT-5.5-Cyber models [10]. Foreign media outlets, including Reuters, have assessed this as Beijing's most detailed statement on AI security risks to date [4][8].
DW analyzed that the warning reflects the anxieties of Chinese intelligence agencies along three axes: political stability, cybersecurity, and information control [12]. Rebecca Arcesati of the Mercator Institute for China Studies (MERICS) pointed out that Beijing is concerned not only about cyber risks but also about its very dependence on foreign models [12]. This aligns with assessments that despite having built its own AI ecosystem, China still lags a few months behind the capabilities of US frontier models from companies like OpenAI and Anthropic [8].
The Guardian reported on the concurrent timing of the warning from China's intelligence chief and the drop in US AI-related stock prices following calls for a slowdown from Big Tech executives [18]. This indicates that the discourse on AI risk is proceeding simultaneously on two separate tracks: an internal debate within the US tech industry and a national security logic within China.
3. Key Actors and Positions
China's Ministry of State SecurityThe MSS adopts a dual stance: externally, it criticizes the US "threat" narrative, while internally, it recognizes the need for its own safety management measures. Chen Yixin's remarks stem from the intelligence agency's core mission of maintaining the stability of Communist Party rule [4]. The phrase "political and ideological security" reflects a uniquely Chinese concept of risk focused on regime stability, which differs from Western discussions of AI safety.
China's Ministry of Foreign AffairsThe Ministry of Foreign Affairs delivers a message that differs in tone from that of the MSS. Spokesperson Guo Zhakun directly refuted the US-led AI threat narrative, framing it as fear-mongering driven by commercial interests [16]. The coexistence of the MSS's internal warning and the Foreign Ministry's external refutation suggests that China is operating on a two-track basis: criticizing the politicization of the safety debate in its engagement with the United States, while internally acknowledging its own substantive vulnerabilities.
Anthropic and OpenAIThese companies have taken the stance of proactively calling for regulation by publicly disclosing the risks associated with their own models. In a 154-page report released on September 10, Anthropic had already revealed evidence of a China-based actor attempting to use its Claude model to neutralize Taiwan's air defense network and for cyber espionage [6]. The fact that Claude-Mythos was again singled out in Chen Yixin's remarks illustrates a dynamic of mutual reference, where risk disclosures by US AI firms and threat perceptions by Chinese intelligence agencies inform one another.
The Trump AdministrationThe Trump administration maintains its position of addressing safety discussions only within the framework of maintaining a competitive advantage over China, rejecting the industry's calls for a slowdown [3][9]. This creates a structural context that makes it difficult for the MSS's internal warning to develop into a substantive agenda for cooperation at the US-China summit.
4. Key Issues
The first key issue is the gap between China's internal perceptions and its external messaging. While the MSS's warning appears to stem from a recognition of substantive vulnerabilities, the Ministry of Foreign Affairs and state media frame the same risks as a political tactic by the United States [16][17]. This gap is a key variable for gauging the position China will take in future US-China AI safety dialogues.
The second issue is China's dependence on foreign models. The fact that China specifically expresses concern about the hacking capabilities of OpenAI and Anthropic models, even while cultivating its own AI industry, indicates that it still benchmarks against US models for real-world threat response capabilities. This is separate from assessments that the performance gap has narrowed to just a few months [8][12].
The third issue is how the discourse on safety is being politically utilized. A previous EAI analysis pointed out that the safety discourse originating from Amodei, combined with calls for chip export controls against China, has transformed into a new front in the US-China technological competition. The assessment that "the language of safety is being consumed by both countries not as an agenda for substantive cooperation, but as a bargaining chip and a means to secure a competitive advantage" [9] suggests that Chen Yixin's remarks should also be interpreted within this framework.
II. In-Depth Analysis
China's Ministry of State Security Publicly Warns on AI Risks: An In-Depth Analysis
1. Analysis of Root Causes
The root cause of Chen Yixin's remarks lies in a dual anxiety unique to the Chinese Communist Party system. The Ministry of State Security is both a foreign counterintelligence agency and a domestic ideological control apparatus. That this agency has identified AI as a threat implies a greater concern over the loss of control than over the technology itself.
Chen explicitly stated that AI could threaten political, institutional, and ideological security [10]. This phrase directly targets the ruling legitimacy of the Chinese Communist Party and its system of information control. The Romanian media outlet Digi24 assessed this as the first instance of China's intelligence chief defining AI as a direct threat to Communist Party power [4]. The Council on Foreign Relations (CFR) also analyzes the remarks as Beijing's most specific articulation of AI security risks at the highest level [8].
There are also causes at the technological level. Chen specifically named Anthropic's Claude-Mythos and OpenAI's ChatGPT-5.5-Cyber [10]. This is not an abstract threat assessment but a warning that specifies actual model names. In an interview with DW, MERICS researcher Rebecca Arcesati pointed out that Beijing's concerns extend beyond the possibility of cyberattacks to its structural dependence on foreign models [12]. This anxiety is reinforced by assessments that China, despite having built its own AI ecosystem, remains just a few months behind US models on key benchmarks [8].
2. Structural Context
Political Structure: China's system of information control is a key pillar of the regime's legitimacy. Generative AI can erode this system in two ways: first, through the influx of information that bypasses censorship via foreign models, and second, through the generation of unpredictable discourse by domestic users of AI. The MSS's explicit mention of "political, institutional, and ideological security" can be interpreted as targeting both of these pathways [10].
Security Structure: From a cybersecurity perspective, the dual-use nature of AI is at the core of the problem. Anthropic's 154-page threat report, released on September 10, details evidence of actors backed by China, Russia, and Iran attempting to use its Claude model to neutralize air defense networks and for cyber espionage [6]. The report identified the root cause as an "asymmetric structure where the dual-use nature of general-purpose AI models neutralizes existing arms proliferation control methods, lowering the cost of attack while raising the cost of defense" [6]. Chen Yixin's warning reflects a recognition that this asymmetric structure could also be turned against China. A separate CFR analysis assesses that the United States is also highly vulnerable to cyber threats from China, indicating that cyber risk is a reciprocal, not unidirectional, structure [13].
Economic Structure: The "slowdown" discourse from US AI companies is intertwined with calls to strengthen semiconductor export controls against China [9]. The Global Times criticized this combination, arguing that America's competitive mindset on AI and its "China threat" narrative are dividing global governance [17]. Thus, in a structure where the safety discourse is being repurposed as a tool for economic security controls, China is pursuing a two-track approach: externally rejecting this framework while internally conducting its own separate threat assessments.
3. Historical Precedents and Comparison with Similar Cases
This case is structurally similar to how closed regimes responded to the spread of information and communication technologies during the Cold War. With the successive emergence of satellite broadcasting, the internet, and social media, China has consistently pursued a dual policy of adopting new technologies while simultaneously strengthening controls over them. AI is the latest in this lineage, but the nature of the threat it poses is different; unlike past technologies, it automates not only information distribution but also cyberattack capabilities.
A direct point of comparison is Anthropic's report on misuse by state-backed actors. That report disclosed an attempt by a China-based actor to use Claude to neutralize Taiwan's air defense network [6]. Although the roles of attacker and target are reversed, Chen Yixin's warning reveals a symmetrical recognition that the "potential for AI weaponization" demonstrated in the report could also be directed at China. The case of Alibaba's unauthorized access to Claude is another precedent illustrating the inseparability of security issues and the competition for technological hegemony [6].
Another axis for comparison is the discursive competition between the US and China that unfolded following Amodei's September 12 call for a slowdown. The US side sought to leverage the slowdown argument as a means to maintain its competitive advantage over China, and President Trump rejected calls for stronger domestic regulation on these grounds [9]. China's Ministry of Foreign Affairs immediately countered, labeling it "fear-mongering, confrontation, and malicious competition" [16]. The peculiarity of Chen Yixin's remarks in this context is that he publicly revealed an internal perception completely different from China's external refutation at the same time. This demonstrates a pattern in which the safety discourse is utilized in a bifurcated manner: externally as a bargaining chip, and internally as a substantive basis for policy [9].
4. Key Variables Shaping Future Developments
Variable 1: Outcome of the AI Safety Dialogue at the September 24 US-China Summit. The safety dialogue to be discussed at the summit is unlikely to lead to a substantive agreement on norms, as both countries attach different political objectives to the term "safety" [3]. President Trump addresses safety discussions solely within the framework of maintaining a competitive advantage over China, while China has set preconditions such as sharing the authority to define safety and applying the same standards to US companies [3]. A key indicator of future developments will be whether Chen's domestic-facing warning is reflected in this negotiation track in any form, or if it remains entirely separate.
Variable 2: China's Approach to Managing Its Dependence on Foreign Models. If the concern about dependence on foreign models, as pointed out by Arcesati [12], translates into actual policy, it could manifest as restrictions on access to OpenAI and Anthropic models within China or an accelerated replacement with domestic models. This issue is directly linked to the self-reliance of China's AI ecosystem and would also affect the practice of domestic companies like Alibaba making unauthorized use of foreign models [6].
Variable 3: Whether Additional Cases of State-Backed AI Misuse Are Disclosed. Anthropic's detection and disclosure of misuse are left entirely to the company's discretion, as there are no official channels for intervention by governments or international organizations [6]. If similar reports are released in the future, the discursive advantage between the two countries could shift depending on the report's focus—for instance, whether it details China-based attacks against the US or risks posed to China by US models.
Variable 4: Whether the Gap Between Discourse and Implementation Persists. The safety discourse is likely to be implemented at different paces in security-related versus commercial sectors [9]. Similar to the US case, where the White House's cooperation track and the pressure track from Congress and regulatory agencies already operate separately [3], China is also highly likely to pursue its external critical stance and its internal risk management policies on parallel tracks. How long this gap persists will determine the timing of any substantive policy changes.
3 credits are required from here
The body beyond the scenario analysis is available with credits.
Sign in to continue reading*This text is an AI translation of an original written in Korean. Some translations or nuances may be inaccurate.
This report is an in-depth analysis planned by an EAI researcher, grounded in sophisticated AI-assisted research, and finalized by the EAI researcher.