cd /news/ai-policy/china-spy-chief-points-at-us-ai-mode… · home topics ai-policy article
[ARTICLE · art-130490] src=therecord.media ↗ pub= topic=ai-policy verified=true sentiment=↓ negative

China spy chief points at US AI models in cyber threat warning

Chen Yixin, head of China's Ministry of State Security, named Anthropic's Claude Mythos and OpenAI's GPT-5.5-Cyber as cybersecurity risks to China's critical infrastructure in an article published in the Cyberspace Administration of China's journal, citing what he called a "disruptive upgrade" in cyber capabilities. Chen listed six major AI risks and said cybersecurity is entering a phase of "vulnerability industrialization, fully automated attack and defense, and AI versus AI," though he did not allege either model had been used against China. The warning came days after Anthropic published a threat report describing a Chinese-speaking group that used Claude for an "autonomous vulnerability research program," and a day before the Cyberspace Administration of China released a new AI governance framework at National Cybersecurity Week in Jinan focused on autonomous agents and embodied AI.

by read3 min views1 publishedSep 15, 2026
China spy chief points at US AI models in cyber threat warning
Image: source

The Chinese Communist Party’s top intelligence official named two U.S. artificial intelligence models as cybersecurity risks to China’s critical infrastructure, though he did not accuse either of being used in attacks on the country.

Chen Yixin, head of the Ministry of State Security, made the comments in the journal of the Cyberspace Administration of China. The ministry oversees China’s intelligence and secret police apparatus and reports to the Communist Party’s top political-legal body.

Chen listed six major AI risks. His first warning was that the technology was “directly threatening our political security, institutional security, and ideological security.”

“Various hostile forces and individuals with ulterior motives abuse generative artificial intelligence technologies… to fabricate political rumors, spread harmful information, and incite confrontational sentiments at low cost and in large quantities,” he wrote.

Chen identified Anthropic’s Claude Mythos and OpenAI’s GPT-5.5-Cyber as signs of what he called a “disruptive upgrade” in cyber capabilities, increasing the speed and potential weaponization of vulnerability discovery and malware development.

He cited the models’ capabilities but did not allege that either had been used against China.

“Cybersecurity is entering a new phase characterized by vulnerability industrialization, fully automated attack and defense, and AI versus AI,” Chen wrote.

“Some countries and organizations possess the capability to rapidly and in large quantities discover vulnerabilities, automatically connect attack paths, and complete complex hacking tasks, drastically lowering the technical barriers and costs of launching cyberattacks and posing serious risks to China's critical information infrastructure.”

Western governments have raised similar concerns about AI’s effect on cyber operations. The Five Eyes intelligence alliance warned in June that frontier AI models could reshape offensive and defensive cyber operations within months rather than years. While there is evidence of vulnerability reports reaching record levels since then, a proportionate uptick in cyberattacks has not yet been observed.

Chen also cited espionage and data leaks as significant concerns for the Chinese Communist Party, alongside U.S. technology controls and alleged monopolistic practices, algorithmic decision-making in “social governance,” and AI’s impact on military operations.

He did not address the use of AI in China’s own offensive cyber operations. Beijing routinely denies conducting such operations despite attributions by Western researchers in both the public and private sectors.

Chen’s warning came days after Anthropic published a threat report describing a Chinese-speaking group that used Claude to conduct what the company called an “autonomous vulnerability research program.”

Anthropic said the group, which included two operators it identified as undergraduates at a university in Hunan, found several zero-day flaws in a major security product. The report also documented misuse by Russia-linked and other actors.

Leaked technical documents reported earlier this year by Recorded Future News appeared to show a Chinese state-backed training platform used to rehearse — and potentially train AI to support — cyberattacks against critical infrastructure in neighboring countries.

A day after Chen’s article, the Cyberspace Administration of China released a new version of its AI governance framework at the opening of National Cybersecurity Week in Jinan. The framework focuses on autonomous agents and embodied AI and identifies “loss of control” as a core risk.

The framework is guidance, not law. China already requires public-facing AI services to undergo government security reviews and register before launch.

Chen also criticized foreign export controls and “closed-source ecosystems.” Chinese labs have become major proponents of open-weight models, a strategy analysts view in part as an effort to spread Chinese technology and influence technical standards abroad.

Chen described AI as an “international public good” and called for its use so the Global South could close the “intelligence gap,” casting China as an open alternative to what Beijing describes as Western technological monopoly.

Alexander Martin

is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79

── more in #ai-policy 4 stories · sorted by recency
── more on @chen yixin 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/china-spy-chief-poin…] indexed:0 read:3min 2026-09-15 ·