A commentary published today by Yuyuan Tantian, a self-media outlet regarded as close to the Chinese official line, was titled “Anthropic Has Caught the American Disease.”
Its central argument is that if the authority to define model safety rests with a single U.S. company such as Anthropic, then its competitors will inevitably be placed on the “unsafe” side of the divide. What is needed instead is a scientific definition acceptable to both sides, not one unilaterally imposed by a single country or company.
According to the commentary, capabilities that could genuinely cause severe harm, the commentary says, can be jointly tested and jointly constrained. Ordinary model development and commercial use, however, should not be subject to covert interference. The line between the two must be drawn collectively by all relevant parties.
The commentary argues that U.S. figures are already discussing how to persuade China to accept limits on “AI models with dangerous capabilities.” The question, however, is whether, in the presence of companies such as Anthropic, Washington should first examine its own firms before asking China to restrict model releases or disclose risks. That would mean publicly clarifying the purpose, scope, and rules of such companies’ identification mechanisms and subjecting them to independent third-party audits.
The commentary further pointed out that if U.S. companies are permitted to transmit user data back without informed consent, bypass permission checks, and enable automated decision-making by default, while the U.S. government remains silent, then American talk of “safety boundaries” amounts to little more than rhetoric.
Only if the United States can first show that its safety rules apply equally to its own model companies, the piece suggests, can China and the United States move into substantive discussions.
Reuters reported on July 21, citing five sources familiar with the matter, that the two sides were planning to hold the first formal AI dialogue of the Trump administration in September, tentatively under the lead of U.S. Treasury Secretary Scott Bessent and ahead of President Xi Jinping’s visit to the United States. At that point, however, the date, venue, agenda, and composition of the delegations had yet to be settled. By August 19, the South China Morning Post was still reporting that no venue had been fixed, no decision had been made on whether companies and technical experts would participate, and the U.S. side itself had not fully settled which department would take the lead.
At the same time, peripheral channels of communication appear to be accelerating. On August 24, Wang Huning met the U.S. delegation to the third China-U.S. Track 1.5 Dialogue, and the American side, in its public remarks, made specific reference to the need to “prevent risks such as those posed by artificial intelligence.”
Against that backdrop, and on the eve of what could become intergovernmental China-U.S. talks on AI safety, the Yuyuan Tantian commentary merits attention.
To understand the piece, it is also useful to note several developments in the days immediately preceding its publication.
On August 26, Bill Gates told Reuters that if the United States were to move first in constraining dangerous models, China might be willing to restrict the release of such models as well, and he raised the idea of some form of international governance body.
On August 28, a U.S. court overturned the Pentagon’s supply-chain risk designation concerning Anthropic.
Two days later, Yuyuan Tantian published its article. In that context, the line stating that “relevant figures on the U.S. side are discussing how to get China to limit models with dangerous capabilities” most plausibly refers not only to statements by officials such as Bessent, but also to arguments advanced by Gates and broader circles in the U.S. policy community.
One line in particular stands out: “Capabilities that could truly cause serious harm can be jointly tested and jointly restricted.” That wording suggests China may not be rejecting frontier-model controls in principle. Rather, it appears to be setting out three conditions: first, that dangerous capabilities must be defined in technical terms that are repeatable and verifiable; second, that the standards must apply equally to Chinese and U.S. firms; and third, that the mechanisms for testing and restriction cannot be secretly controlled by American companies.
Taken together, the commentary appears to send a fairly clear signal. China may be willing to engage the United States on AI safety, but only in relation to a narrow category of clearly defined and verifiable catastrophic capabilities. Any rules would need to be reciprocal, rather than leaving companies such as Anthropic with effective interpretive authority. Normal research and development, open-source ecosystems, and commercial applications, meanwhile, should not be subjected to covert monitoring or blocked in the name of safety.
Below is my full English translation of the article. As always, any errors or omissions are entirely my own.
But before getting to the translation, I’d like to make a brief personal note.
AI policy and geopolitics are increasingly sensitive and sometimes highly politicized subject. For that reason, I would like to reiterate that all views, commentary, and translations published on this Substack are entirely my own and should not be understood as representing the position or interests of any organization.
This Substack is a personal, non-commercial project that I maintain in my spare time, simply because I enjoy following these issues and believe that serious ideas and debates are worth sharing with a wider audience. I receive no payment for this work, and my decisions about what to translate, what to write about, and what views to express are entirely my own.
I very much welcome disagreement, criticism, and debate on the substance. Readers are, of course, equally free to follow or not follow this work. My only request is that the discussion remain focused on the ideas themselves, rather than speculation about personal identities, affiliations, or presumed interests.
I hope this small independent project can remain what it was intended to be: a space for sharing information, exchanging ideas, and encouraging serious discussion of technology and public policy. I would be grateful for everyone’s understanding and respect for that purpose.
Anthropic Has Caught America’s Disease Anthropic CEO Dario Amodei once said that if powerful artificial intelligence develops in the right direction, the world could become “stunningly beautiful.”
He sketched out a future thoroughly rewritten by technology: most diseases would be cured, human life expectancy could double, poverty would disappear, and many people who lived to see it would be “moved to tears.”
To support that vision, Anthropic has demonstrated striking technical strength and unusually fast industrial penetration. On major international rankings, the company’s Claude model family currently occupies the top three spots. On the application side, data from May to July this year show that 39% of developers globally and 47% of developers in the United States were using its core AI coding tool, Claude Code, in their work.
Anthropic is now sprinting toward what could become the largest IPO in history. According to foreign media disclosures, it plans to tell investors that its potential addressable market could exceed US$30 trillion, selling the story of how AI will restructure global productivity. The grand vision in Amodei’s writing appears, on the surface, to be moving step by step toward reality.
Yet the social reaction he has received looks very different.
In the United States, public anxiety over AI squeezing human space for survival is turning into a wave of opposition directed at Anthropic, while intellectual criticism of monopoly power among technology giants is growing louder.
More than a month ago, China’s Ministry of Industry and Information Technology directly named Claude Code and said it carried serious backdoor security risks, including the ability to send users’ geographic location, identity markers, and other sensitive information back to remote servers without user consent.
The contrast is deeply ironic. How did a company that believes it is saving humanity become, in the eyes of so many people, a byword for overreach, surveillance, and hegemony?
In 2020, a group of core OpenAI employees chose to leave the company and start their own venture. They were convinced that they understood better than their predecessors how AI should develop, and that they had seen the future of AI earlier than the rest of the world.
Dario Amodei was one of the central figures in that group. He carries the typical traits of a Silicon Valley elite: educated at top universities, formed inside major technology companies, convinced that technology can solve humanity’s most fundamental problems, and convinced that engineers are not only building products but also designing the future of society.
Anthropic was born in that context.
Idealism, though, never comes free. To realize the utopia he talks about, Anthropic needs enormous investment to build the world’s most advanced models and reach users across the whole of society.
Every interaction and every line of code are treated by Anthropic as part of the capability base for training its models. If the destination is humanity’s ultimate ideal, then along the way, what does it matter to collect a bit of user data, take over a bit of terminal authority, or bypass a bit of user consent?
The backdoor issue is a concentrated expression of that worldview.
In discussions on GitHub about Claude Code, the author found that one of the major flashpoints was covert monitoring activity.
A typical case appeared in January this year, when an overseas developer checking proxy logs discovered that Claude Code was sending requests to a website every few seconds in the background, at a frequency that looked like real-time monitoring. At the time, Anthropic did not explain what the website was collecting or what it was for. The feedback that developer posted on GitHub also received no substantive response.
More developers reported similar anomalies.
Some noticed that Claude Code would send the domain name of a website the user was preparing to access to Claude’s own interface before formal authorization had even been given. Others found that Claude Code could sometimes bypass certain interception mechanisms.
Taken together, these phenomena point to one issue: Anthropic wants its model to monitor and see everything.
During use, Claude Code also exposed another, more serious problem: allowing AI to make decisions in place of the user.
Anthropic officially provides a parameter called
dangerously-skip-permissions
. Once enabled, Claude Code skips permission confirmation and executes operations directly.In March this year, Claude Code went further and introduced an “auto mode,” relying on a built-in risk-classification model to decide operational permissions by itself. Starting on August 14, that mode was enabled by default.
Anthropic’s official documentation states clearly that permission rules are enforced at the tool layer, and prompts cannot alter what the tool is allowed or forbidden to do.
From monitoring, to skipping confirmation, to automated decision-making, the pattern is the same: the user steps back, and the system steps forward. That is exactly how Amodei’s worldview shows up inside the product. If AI carries the mission of leading humanity into the future, then by definition it must know more than users, judge faster than users, and possess broader authority to act.
What is even more troubling is that none of Anthropic’s steps across the line has been effectively stopped.
In theory, the U.S. government should be the firmest defender of security boundaries. In practice, it has yielded repeatedly.
In the first half of this year, the U.S. government prepared an executive order titled “Promoting Advanced Artificial Intelligence Innovation and Safety,” under which the government would review the safety of frontier AI models before release.
Compared with the earlier draft, the final executive order steadily lowered the regulatory bar. The pre-release access period was cut from 90 days to 30 days, and the text repeatedly emphasized voluntary participation.
When the U.S. government loosens rules and retreats in order to preserve technological hegemony, and when capital markets provide a kind of moral exemption in pursuit of returns, the desire for control that originally sat inside one person’s savior complex gains fertile nourishment from the institutions of American society. That is also the root of what the article calls “closed-source America.”
A backdoor can be deleted. Permission settings can be changed. But the real problem lies far beyond the technical layer.
Recent developments have pushed the contest over artificial intelligence toward a deeper question: who gets to define the security boundaries of frontier models?
The way Anthropic is competing for power and advantage shows that it is no longer just a technology company.
Earlier, when Anthropic’s annualized revenue reached the one-billion-dollar threshold and it was preparing to accelerate commercialization, Amodei published a long essay of roughly ten thousand words that already showed an ambition to intervene in global order.
One full section of that essay was devoted to international governance, and the language was highly controlling and openly aggressive.
He argued that an alliance of “democratic countries” should firmly control the AI supply chain and restrict adversaries’ access to chips and semiconductor equipment. At the same time, those countries should use AI to build military superiority while also using incentives to draw more countries into the alliance. He stated explicitly that this would require “extremely close cooperation” between private AI companies and governments.
That does not sound like an entrepreneur discussing a product roadmap. It sounds like someone planning a global AI order and reserving for his own company a dominant seat at the very center.
Silicon Valley has heard this kind of argument before.
Alexander Karp, the CEO of Palantir, published a book titled
The Technological Republic, arguing that Silicon Valley should reengage with national defense and state governance and use technological capability to help the United States and its allies manage security and geopolitical competition. Amodei’s vision follows the same logic.Very quickly, that ambition moved into practice.
Claude Code was brought into the U.S. Department of Defense for intelligence analysis, modeling and simulation, operational planning, and cyber operations.
But the cooperation was not smooth. The Pentagon believed that once the system entered the government’s door, it should obey government direction. Anthropic believed that control over the model’s core capabilities and safety criteria remained in its own hands, and that the government could not simply decide how those capabilities would be used.
When the two sides could not agree, Anthropic did not withdraw. It changed course, shifting from direct service provision to participation in rule-making.
In the first half of 2026, Anthropic increased its federal lobbying spending to a level above its total for all of 2025. In addition, it put US$40 million into an organization focused on AI risk regulation.
Its IPO can also be understood in that context. The money raised from going public will not be used only to build stronger models. It will also be used to keep buying something else: the power to define.
Put these facts together and the path becomes clear. Anthropic first enters government systems through the banner of safety capability, then uses lobbying and capital to help shape industry rules. It is both a regulated object and a participant in defining what kinds of models are dangerous and at what point the government should stop them from entering the market.
By this point, Amodei’s logic has gone through two enlargements: from “I am doing good” to “I will decide for you,” and from “my country is doing good” to “anyone who does not cooperate should be restricted.”
This is a creature produced entirely by the American path. It sincerely believes that it is right. It sincerely believes that its models are “democratic models,” and that its own safety standards are the world’s safety standards. It does not seem to realize that this very inability to doubt itself is the greatest danger of all.
And the reason it is now so urgent is that time is not on its side. More and more people are beginning to see that clearly.
Stanford University’s
AI Index Report 2026shows that the performance gap between the top Chinese and American models has narrowed to about 2.7%. Separate disclosures indicate that Microsoft, Amazon, and Google are in talks with the Chinese company Moonshot AI about connecting its Kimi K3 model to U.S. cloud service platforms.That piece of news carries a great deal of information.
The open-source character and low-cost profile of Chinese models are making advanced models more substitutable. That also means barriers built purely on model performance are beginning to loosen.
Today, when the United States and China discuss cooperation on artificial intelligence, control over frontier models is one of the key issues.
The problem is that America’s own frontier models have already developed in a distorted way. That means the negotiation is not, from the outset, a purely technical dialogue. It is a continuation of all the earlier problems: the United States is trying to turn the “security boundaries” it has drawn for itself into the default rules of the world. The “controls” proposed by the United States are, in substance, an attempt to have China accept an order partly defined by American companies.
So the real issue is not whether there should be controls. The real issue is who should define the security boundaries of frontier models. Who has the authority to say which models are dangerous and which kinds of behavior should be restricted?
If these questions are not resolved in a reasonable way, the later stages of negotiation have no real meaning. The principles have to be clarified first.
First, there must be a distinction between genuine security threats and straightforward technological competition.
The United States has taken Chinese models that are cheaper and more open and directly labeled them as “security threats.” That has already moved beyond technological competition and into blockade.
Anthropic’s differentiated treatment of users in different regions, and its packaging of commercial competition as a security problem, is one expression of that logic. The problem is simple: if definitional authority sits in the hands of one American company, then its competitors will always be placed on the “unsafe” side. What is needed now is a scientific definition that both sides can accept, not a unilateral declaration by a single country or a single company.
Capabilities that could truly cause severe harm can be jointly tested and jointly restricted. Ordinary model research and ordinary commercial use should not be subject to secret interference. That line must be drawn collectively by the parties involved.
Second, if the United States wants to talk about rules, it must first prove that the rules are equally effective against its own companies.
Relevant figures on the American side are already discussing how to get China to agree to restrict “AI models with dangerous capabilities.” The question is this: with companies like Anthropic in existence, before the United States asks China to restrict model releases and disclose risks, should it not first investigate its own companies, make public the purposes, scope, and rules of their identification mechanisms, and subject them to third-party audits?
If American companies can return data without users knowing, skip permission confirmation, and enable automated decision-making by default, while the U.S. government says nothing, then American talk about “security boundaries” is empty. Only after the United States proves that its safety rules are equally binding on its own model companies can China and the United States move into substantive discussion.