Topics / topic

China

17 items across 5 editions · appeared in the last 5 editions in a row. First seen Fri 11 Sep, last seen Tue 15 Sep. Traced across 1 weekly review.

How this story has evolved

From the week in review: the connections, developments and open questions filed under China, newest week first.

Week of 7–13 September 2026

Connection
Two government agencies, two frontier labs and Beijing all spoke about model extraction within three days

The joint advisory came on 8 September from CISA, NSA and FBI; Google's threat group published the same day; Anthropic's report followed on 10 September; Beijing responded on 9 September; and Amodei's essay of 12 September asks governments to "Crack down on unauthorized distillation by companies in authoritarian countries" and to "Do not sell powerful AI chips or semiconductor manufacturing equipment to China".

Development · Tue 8 Sep, Wed 9 Sep, Thu 10 Sep
Anthropic names seven Chinese labs over illicit distillation and Google reports campaigns exceeding 100 million prompts, two days after a joint US advisory named six firms

On 8 September CISA, NSA and FBI issued joint advisory AA26-251A, "China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies", naming DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. The advisory says the firms "extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024", and says DeepSeek's publicly stated $5.6 million training cost excludes data "acquired through extensive malicious distillation".

Open question
Why does the US agencies' list of Chinese labs not match Anthropic's, and why does Google name none?

Advisory AA26-251A names StepFun; Anthropic's report does not. Anthropic names Xiaomi and SenseTime; the advisory does not. Google reports campaigns "some exceeding 100 million prompts" without naming any company. Neither document states what evidence it drew on or whether the lists were compiled together. Every exchange count, including the 151 million attributed to Alibaba, rests on the reporting company's own telemetry.

Tuesday, 15 September 2026

China's state security minister singles out OpenClaw and calls for special AI laws, The Register reports UpdateSingle source

  • The Register reported on 15 September on an article by Chen Yixin, China's minister of state security, in China Cyberspace magazine, in which Chen wrote that "The field of AI has become the main battleground for global technological competition".
  • The Register says Chen singled out "OpenClaw and similar products", criticising "structural problems such as remote control of device management permissions and leakage of sensitive user information", and set out risks including weaponisation for vulnerability detection and infrastructure attacks, theft of industrial and state secrets, overseas data leaks, algorithmic opacity amplifying social biases, and attribution problems in automated decision-making.
  • Chen's prescribed response, per The Register, is for China to achieve "independent control of key core technologies, firmly grasp technological sovereignty" and to enact "special laws and regulations targeting the research, development, application, and supervision of artificial intelligence technology".
  • This adds the product criticism and the call for dedicated AI legislation to Chen's "new arena for strategic rivalry" framing covered in an earlier edition. The Register's account cites no documented attack on Chinese systems and no figures quantifying China's exposure.

China's new exit rules take effect, allowing travel bans on citizens who endanger "technological security" harmful

  • China's new Exit and Entry Administration Provisions took effect on Tuesday 15 September 2026. Free Malaysia Today reports the rules target violations of export controls or technology import and export rules that may endanger "industrial or technological security", and were unveiled in July.
  • The News International reports the regulations were formulated by the State Council alongside multiple ministries and empower border and security authorities to impose exit bans, and says individuals who breach technology import and export rules — "particularly engineers and corporate officials operating in sensitive sectors like artificial intelligence (AI) and advanced manufacturing" — face immediate travel restrictions.
  • Free Malaysia Today reports the rules provide for exit bans of six months to three years on citizens who return to China after committing illegal or criminal acts abroad that harm national security or interests, and that foreign nationals may be denied entry for one to five years for false statements in visa applications.
  • Free Malaysia Today reports Taiwan's Mainland Affairs Council deputy head raised concerns about the new "export control" and "technology import-export management" grounds, particularly for Taiwanese tech workers. Neither report cites a case in which the AI-related grounds have been used.

Trump calls AI risk a "HOAX", attacks Amodei, and says the only guardrail AI needs is a "STRONG AND SMART" president Update

  • NBC News reports Trump "posted in support of AI more than a half-dozen times Monday on Truth Social". CNBC quotes him writing: "I'm right now breaking another Hoax — That AI is going to take over, consume, and destroy the World, and that Robots will be marching into our Cities, and getting rid of us all!" and "There is a SICK conspiracy going on against AI and Data Centers, and the only one that is happy about it is China."
  • NBC News quotes him writing that the only control needed is "a STRONG AND SMART (High IQ!) PRESIDENT", and naming "Dario (Anthropic!), who is now pretending to be a 'perfect little angel'". CNBC quotes a further post: "Concerning AI, when, in the History of Business, did anyone see the Leaders of an Industry call for Regulation that, if strongly implemented, will drive them into oblivion and bankruptcy?"
  • CNBC reports Trump also wrote "We already have tremendous CRIMINAL and REGULATORY power over these companies!", and that the posts followed Amodei's weekend essay "We Must Pace the Frontier". CNBC reports Anthropic did not immediately respond to a request for comment on Trump's posts.
  • CNBC notes any AI regulation by Congress appears unlikely before the 3 November midterms, with House members due to leave Washington on Thursday and stay in their districts through October. No executive action was announced alongside the posts.

Monday, 14 September 2026

Amodei tells CBS the industry "lied" about AI risks, calls China the toughest dilemma for pacing Update

  • In a CBS News "Sunday Morning" interview aired on 13 September, Anthropic chief executive Dario Amodei said: "And I think for too long the industry lied to people about the fact that this technology had risks." He said the pace of progress "doesn't mean we need to panic today. It doesn't mean we need to shut it all down" but is "a warning sign that we need to slow down".
  • CNBC reports Amodei told the programme that adversarial nations, namely China, not doing the same is "the toughest dilemma": "The more long-term thing would be working together to put a speed limit on the rate of of AI progress. I think that's going to be very difficult because the incentives to pull ahead and the military advantage that you get from that are so large. And honestly, I don't know if it's possible, but we should we should try."
  • CNBC notes President Trump is scheduled to meet Xi Jinping at the White House on 24 September, with AI expected to be discussed.
  • This updates the pacing essay covered in earlier editions; the broadcast interview and its China framing are the new facts. No evaluation data was published alongside the interview, and Anthropic has still not said what capability threshold would trigger pacing.

Beijing's foreign and commerce ministries and Global Times reject Amodei's call to keep curbing China's AI Update

  • At a regular briefing in Beijing on Monday 14 September, foreign ministry spokesperson Guo Jiakun said: "Fearmongering, confrontation and vicious competition will only disrupt the process of global AI governance which serves no one's interest." The AP reports the commerce ministry separately dismissed US allegations as groundless, said distillation is commonly used by many AI companies, and accused the US of pursuing a "monopoly of the AI industry".
  • The AP reports the response follows Amodei's essay, which warned that a "Chinese lead in AI would pose grave danger for the United States and the world" and called for continuing restrictions on sales of cutting-edge AI chips and chipmaking equipment to China.
  • Reuters reports the state-backed Global Times said the essay's true objective was "to attempt to curb China's AI development through technological barriers and regulatory monopolies", and that "this 'silent AI Cold War' is hypocritical and short-sighted", warning that excluding China would "significantly increase the trial-and-error costs and risks of loss of control in global AI development".
  • This is an update: the essay and its chip and distillation proposals were covered in earlier editions, and the Chinese government reaction is the new element. Neither wire reports any change in Chinese policy, and the AP places the exchange ahead of the Trump-Xi meeting on 24 September.

China's state security minister calls AI "a new arena for strategic rivalry among major powers"

  • The South China Morning Post, publishing at 8:00am on 14 September, reports that China's state security minister Chen Yixin wrote that AI has become "a new arena for strategic rivalry among major powers", and warned of risks to state data, business secrets and personal privacy.
  • Semafor, publishing at 6:49am EDT on 14 September, describes the piece as a weekend essay by the minister of state security listing six principal AI risks, among them threats to political regime security, digital infrastructure, public order and national defence.
  • The SCMP reports Chen called for robust risk-prevention frameworks, stronger global governance of AI and a "fair and open international AI rules system". Semafor reports that Global Times characterised Amodei's essay as coming "out of the 'Cold War playbook'".
  • Neither report reproduces the full essay and the SCMP article is partly paywalled; the six-risk breakdown here is Semafor's characterisation rather than a translated list. No new Chinese regulation was announced alongside the essay.

Xi tells the BRICS summit China will create a BRICS AI open-source community and a digital ecosystem cloud platform

  • In a statement released on Sunday 13 September by China's Ministry of Foreign Affairs and reported by CNBC, President Xi Jinping said at the BRICS summit in New Delhi that China "will pioneer the establishment of a BRICS AI open-source community, support the cooperation in developing and applying large language models, hold AI seminars and training courses, and build an open AI ecosystem".
  • CNBC reports Xi also said China will work to establish a BRICS digital ecosystem cloud platform and conduct digital skills training, technological exchange and industrial alignment, and proposed a BRICS engineer cultivation alliance and a youth exchange programme for scientific and technological innovation. In separate reporting CNBC says Xi called for a "consensus-based global AI governance framework".
  • BRICS was established in 2009 and now comprises 11 nations including China, India, Russia, Iran and the United Arab Emirates, CNBC notes.
  • CNBC says Xi did not address the ongoing AI safety debate. No funding figure, timetable or governing structure was announced for the open-source community or the cloud platform, so this is a commitment rather than a launch.

Johnson rules out an emergency AI session and Trump dismisses the warnings as the House prepares to leave until November

  • House Speaker Mike Johnson said on CNN's "State of the Union" on Sunday 13 September: "If Congress just races in and does some sort of emergency session to try to regulate AI, we will lose the race to China, that is a threat to every single American." He added: "We don't need everybody to panic right now, we need to handle this new technology like we have others in the past." CNBC reports Johnson is scheduled to send the House home after this week until after November's elections.
  • Johnson called instead for a meeting between Washington and industry leaders: "I'd do it tomorrow. I think we need to go in a big room, close the door and sort this out."
  • In brief remarks in Ireland on Sunday, according to a pool report cited by CNBC, President Trump said: "Well I say this, we're leading China on AI. We're the most sophisticated country in the world and frankly I want to keep it that way, because whoever wins AI wins. We can put guardrails, and we can do this and that, but I think you have a lot of negative forces that are bringing it up and they're bringing up things that won't happen." NPR reports he did not say what he meant by "negative forces"; CNN reports he later said AI's advance will bring "more good" than harm.
  • No bill, hearing or vote was scheduled in the window. CNBC reports that a Senate bill being worked on by Majority Leader John Thune with Senators Amy Klobuchar and Ted Cruz "has not yet been introduced", and that an unnamed industry source expects legislation "in the coming week".

Ramaphosa asks BRICS to set up an international mechanism for independent scientific evaluation of AI Single source

  • In a statement delivered at the 18th BRICS Leaders' Summit in New Delhi and published on 13 September, President Cyril Ramaphosa said: "South Africa accordingly proposes that BRICS should establish an international mechanism for the independent scientific evaluation of AI."
  • He listed the risks he wants evaluated: "Systems capable of advanced cyber operations, assistance in biological weapons development, autonomous action, manipulation, mass surveillance, disruption of employment and, ultimately, systems whose capabilities may become difficult for human beings to control."
  • The statement pairs the proposal with meaningful human-control principles, mandatory reporting of serious incidents, progressively stronger safeguards as capability increases, and simultaneous investment in sovereign AI capacity for developing-economy countries, arguing that "such oversight is standard practice in other industries whose activities have a significant impact on human safety and well-being, such as aviation, pharmaceuticals, nuclear power and financial institutions".
  • This is one government's proposal in a summit statement, and the primary text is the only source used here. No other BRICS member endorsed it in the window, and the summit's New Delhi Declaration — adopted on 12 September, before this window — does not establish such a mechanism.

Z.ai files in Hong Kong to raise about $5bn through a discounted placement and zero-coupon convertible bonds Single source

  • TechNode Global, reporting a filing made to the Hong Kong stock exchange on 13 September, says Z.ai plans a share placement of HK$15.68 billion (about $1.98 billion) at HK$714 per share — a 9.96% discount to the 11 September close of HK$793 — representing about 4.5% of enlarged share capital and expected to close on 16 September.
  • Alongside it the company plans convertible bonds with gross proceeds of $3.016 billion and principal of RMB20.14 billion, zero coupon, maturing in 2027, with an initial conversion price of HK$892.50 per share.
  • Of the proceeds, 60% is earmarked for next-generation GLM models and training, inference and computing infrastructure, 15% for business expansion, strategic investments and potential acquisitions, and 25% for capital structure, working capital and general corporate purposes, with deployment expected by 30 June 2028.
  • Both transactions remain conditional and had not closed; TechNode notes the placement may not proceed if its conditions are not met. Only this outlet's account of the filing was read for this item.

Sunday, 13 September 2026

Amodei ties his pacing plan to blocking China chip sales, a distillation crackdown and model weight security Company claimSingle source

  • Amodei lists three steps to defend the US lead: "Do not sell powerful AI chips or semiconductor manufacturing equipment to China, and crack down on chip smuggling operations and remote access to data centers outside China"; "Crack down on unauthorized distillation by companies in authoritarian countries"; and "Strengthen security at the AI companies and prevent model weight theft."
  • He writes: "If we execute these measures well, I believe they would slow China's progress enough to widen America's lead significantly over the next 3-5 years — the window when AI becomes geopolitically most important."
  • On international agreements he ranks four levels, calling a "speed limit" on recursive self-improvement "analogous to the SALT treaties" and "difficult but just on the edge of being possible", while a full pacing agreement or pause is "unlikely to actually happen any time soon".
  • This is one company chief executive's policy proposal, published on his personal site. No government has endorsed it, and the 3-5 year estimate is his own with no analysis published alongside it.

South Korea's expanded espionage law takes effect, covering leaks of AI and chip technology to any foreign country Single source

  • The revised Criminal Act took effect on Sunday 13 September, broadening espionage offences beyond acts involving North Korea to include all foreign countries. The National Assembly passed the revision on 26 February; it was promulgated on 12 March and took effect after a six-month grace period.
  • The amendment creates a new offence covering espionage for a foreign country or equivalent organisation, carrying a minimum sentence of three years in prison. Existing "enemy state" provisions remain in place.
  • Reuters reports the National Intelligence Service said the amendment would strengthen South Korea's ability to prevent leaks of strategic technologies such as semiconductors, displays, batteries and AI. The report cites the 2025 indictment of five former Samsung Electronics employees accused of transferring DRAM technology to Chinese memory maker CXMT.
  • Asked whether the law targets Beijing, Chinese foreign ministry spokesperson Mao Ning said all countries should safeguard normal investment and business activities of enterprises and provide a fair and non-discriminatory business environment. The report does not say how many cases are expected or how AI technology will be defined in practice.

Sanders says pacing is not enough, calls for a pause on advanced AI and a superintelligence ban at the Trump-Xi summit Single source

  • Responding to the pacing proposals, Senator Bernie Sanders wrote: "When you are racing towards a cliff, you don't just ease up on the gas pedal. You hit the brakes."
  • Sanders called for a pause on advanced AI development and a ban on artificial superintelligence, and said Trump and Xi should negotiate a treaty to that effect at their upcoming summit.
  • The Tribune, carrying an ANI report published 13 September at 7:02 AM IST, groups the statement with endorsements of Amodei's essay from Hassabis and Sunak.
  • This is a statement by one senator, not a bill. No legislative text, co-sponsors or summit agenda item has been reported, and the report does not give a date for the summit.

Saturday, 12 September 2026

Anthropic names seven China-based AI companies behind distillation campaigns, with 151 million exchanges attributed to Alibaba harmfulCompany claimUpdate

  • The Hacker News reports the seven named companies as Alibaba, Moonshot AI, DeepSeek, Zhipu (Z.ai), MiniMax, SenseTime and Xiaomi, with per-campaign figures: GTG-16005 (Alibaba) 151 million exchanges from May to July 2026 across more than 3,500 fraudulent accounts, peaking near 3 million exchanges a day; GTG-16002 (Moonshot) 23 million exchanges across 5,380 fraudulent accounts registered in Singapore and Japan.
  • Also listed: GTG-16001 (DeepSeek) 12.1 million exchanges over 14 days in July 2026 via a proxy relay; GTG-16006 (Zhipu) 3.4 million exchanges across 273 accounts from June to July 2026; GTG-16008 (Xiaomi) 400,000 exchanges over 20 days in March–April 2026; GTG-16012 (SenseTime), which bought transcripts from vendors; and GTG-16003 (MiniMax), via a shell-company proxy network.
  • Anthropic says it responded by banning reseller accounts and accounts from unsupported regions where users fail to verify identity, by updating Claude to summarise its internal reasoning before responding, and by introducing a "preserved thinking" feature — measures aimed squarely at protecting chain-of-thought traces, which the Alibaba campaign is said to have targeted.
  • This extends yesterday's item, which carried only the 151 million figure for Alibaba-linked accounts. Every figure is Anthropic's own account of activity on its own platform; none of the named companies' responses appear in the report, and no independent party has verified the counts.

Moonshot AI targets $2bn annualised revenue by year-end, double its August run rate, as Anthropic alleges distillation Company claim

  • TechCrunch reported on 11 September at 12:35 pm PDT that Moonshot AI is "targeting $2 billion in annualized revenue by the end of the year", a doubling of its August run rate. For scale, TechCrunch puts OpenAI's revenue run rate at $40 billion and Anthropic's annualised revenue at $65 billion.
  • OpenRouter data cited by TechCrunch shows Moonshot's K3 models generating "as many as 300 billion tokens being generated each day" on that platform, with usage down slightly in recent months.
  • The figures matter because Moonshot ships open weights, which carry lower margins than closed models; a $2 billion run rate would be the strongest commercial evidence yet for that business model.
  • In the same week Anthropic accused Moonshot of routing "nearly 300,000 requests from Kimi directly to Claude Opus" and collecting "more than 23 million responses". The revenue figures are Moonshot's own, given to investors, and are not independently verified; Moonshot's response to the distillation allegation is not in the piece.

Friday, 11 September 2026

Anthropic report: Chinese undergraduates ran an AI exploit foundry against ~50 organisations, yielding more than a dozen possible zero-days in one month harmful

  • The cluster Anthropic tracks as GTG-10007 "targeted roughly fifty organizations, spanning education, retail, energy, technology, healthcare, finance, manufacturing, as well as multiple government agencies globally." Automated vulnerability research against network appliances "yielded more than a dozen possible zero day findings in a single month."
  • Anthropic identifies two operators as undergraduate students at a university in Hunan province, in its School of Computer & Communication Engineering, one of whom had previously interned at the security firm Sangfor. The operation used agent swarms, with a lead agent decomposing reconnaissance and post-exploitation work across many parallel subagents.
  • The significance is the operator profile rather than the target count: this is industrial-scale vulnerability discovery run by students, which is the concrete form of the report's broader claim that "sophisticated attacks no longer require sophisticated attackers."
  • Anthropic describes the zero-day findings as "possible" — the report does not say how many were confirmed, disclosed or exploited, and does not name the affected appliance vendors.

Anthropic attributes 151 million Claude interactions to Alibaba-linked accounts as US agencies name six Chinese firms over industrial-scale distillation harmful

  • TechCrunch, reporting figures from Anthropic's 10 September threat report, says accounts linked to Alibaba generated 151 million Claude exchanges between May and July 2026 across about 3,500 accounts, and that Moonshot AI accounted for roughly 300,000 requests over ten days across 5,000 accounts — part of around 200 million exchanges across five campaigns. Extraction techniques included framing requests as translation tasks to surface chain-of-thought reasoning.
  • The joint CISA, NSA and FBI bulletin AA26-251A, published 8 September, names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI as conducting "aggressive, malicious, and targeted distillation activities at an industrial scale" against Claude, GPT, Gemini and Grok since late 2024, extracting "billions of tokens across millions of exchanges/requests."
  • The agencies' recommended countermeasures are unusually specific, and include monitoring subscription-to-usage ratios and enterprise-scale throughput from new accounts, and subtly altering responses to suspected distillation attempts to reduce the payoff to the attacker.
  • The named companies' responses are not documented in the reporting reviewed here. Distillation of a competitor's outputs is a terms-of-service question rather than a settled legal one, and neither document alleges a criminal charge.