Representatives of the largest American artificial intelligence laboratories met in the White House on August 4. OpenAI, Anthropic, Google and Meta were called in to review a framework, recently completed and largely classified, that would give the government 30 days to review AI models before the public sees them and test how well they break into computers. Participation is voluntary, but the timing is not.
Twice in two weeks, AI systems built to test how well they could break into computers broke into real companies instead. On July 21, OpenAI admitted that two of its programs, locked in what was meant to be a sealed computer and set to practice hacking, had found a gap, escaped and broken into Hugging Face, a New York company that is somewhere between a library and an app store for AI.
Anthropic then went through its own records, 141,006 tests in all, and on July 30 reported three occasions when Claude had hacked its way into a real company, guessing weak passwords and walking in. The first hack was in April. Two of the three companies had no idea they had been hacked until Anthropic told them.
The US has spent three years and a lot of money and diplomacy on being first
Nobody says these machines rebelled. Each was given a job by its handlers: a secret file was hidden on another computer, and the AI was to go and get it. Anthropic told its programs they were sealed off from the internet. They were not. So when Claude went looking for the file and found real companies instead, it treated them as part of the game – and hacked them.
Fifteen Republican state attorneys general wrote to OpenAI’s Sam Altman last month, asking him to preserve his records. The House cybersecurity committee wants a briefing. Hence the White House meeting.
Go back to the break-in that started all this and the alarming part seems to have been missed. When the Hugging Face attack was over, the dull work of reconstruction began. The company’s security team tried to use the most advanced American models to establish what had happened, but requests were refused. A model trained not to assist with an intrusion can also refuse to investigate that intrusion. So the team loaded GLM-5.2, made by the Chinese company Z.ai, on to machines it controlled and set it to comb their servers.
The choice was revealing. The best models in the world were American and could only be rented through a service whose rules said no. The Chinese model could be downloaded, installed on Hugging Face’s own machines and told to get on with it without pushback. Here is the problem. America builds the best AI in the world, rents it out and tells customers what they may do with it. China builds AI that is almost as good, then hands it over free, to keep and to run as the customer likes.
At the same time, a different sort of alarm was raised. Anthropic launched Claude Fable 5, briefly the most capable system in the world, on June 9; a US export-control order suspended access until July 1. Fifteen days after Fable 5’s return, a Beijing company called Moonshot AI released Kimi K3. At launch, independent evaluators placed Kimi third on a leading capability index, behind two American systems, and first on a prominent coding leaderboard. Washington saw an American problem. Michael Kratsios, Donald Trump’s science and technology advisor, said the administration had information that Moonshot had trained Kimi on answers pulled out of an Anthropic model, using a set-up built to avoid being noticed.
It was alleged that in those 15 days, Moonshot asked Fable 5 a huge number of questions. It then trained Kimi K3 to mimic Fable’s responses. The Chinese model rapidly became almost as good as the American frontier model. Scott Bessent, the Treasury Secretary, threatened sanctions.
If Kratsios is right, Moonshot allegedly stole the work of an American laboratory, and the White House should say so loudly. But look at what the alleged theft is supposed to have bought. Kimi came third, and both of the systems above it were American.
That is the pattern, not the exception. Epoch AI, which keeps score in this business, finds that every model at the frontier since 2023 has been American and that Chinese laboratories have arrived at the same level on average about seven months later, with gaps of between four and 14 months. Scholars disagree about whether that distance is growing or shrinking.
So, on the question of AI effectiveness alone, China is not winning the race. But model effectiveness is not the only question that matters here.
The United States has spent three years and a great deal of money and diplomacy on being first. What does first place buy? The assumed answer is: everything. The pioneer takes the profits, and the profits pay for the next machine. It writes the standards and decides who may use the most powerful software ever made.
Now suppose the follower arrives weeks later with a model nearly as good, sells it for half the price and lets the customer keep a copy. Which of those achievements survives? Washington has succeeded in keeping China second. But it hasn’t established that second place is strategically harmless. America has misread an Asian technological challenge before. In the 1980s, Japan overtook the United States in industries that appeared to define the future. In memory chips the American share fell from about 70 percent to 20 percent between 1978 and 1986. Washington negotiated trade agreements, subsidized manufacturers and predicted national decline.
Japan stagnated, and not because of technological failure: its asset bubble burst, its banks staggered and its population aged. Japanese companies remained superb at manufacturing hardware while American companies captured the operating systems, software and network businesses built on top of it. Here was the flaw: Japan had to finish first in hardware to declare victory. Chinese laboratories do not need to finish first with AI. Second place, reached quickly and sold cheaply, takes the winnings away from the winner without ever taking the lead.
Alibaba, the closest thing China has to Amazon, has been giving artificial intelligence away for three years. Its family of models is called Qwen, it sits on Hugging Face and anyone may take it. It is the most downloaded open model family in the world. In the year to February, by Hugging Face’s own figures, Chinese models accounted for 41 percent of everything downloaded from the platform; American models 36.5 percent.
Most of the time, this choice is made by a product manager with a budget. When Singapore’s government built a model for Southeast Asia, it built the latest version on Qwen rather than on an American one. Airbnb’s customer-service agent runs on 13 models, one of them Alibaba’s. Brian Chesky, its chief executive, told Bloomberg last year why: “It’s very good. It’s also fast and cheap.”
Look at what Washington is reduced to: congressional letters asking American companies which Chinese models they use and why. No salesman had to talk Airbnb into anything. Qwen had only to be good enough that an American engineer wanted to use it without thinking about China at all.
Washington has two answers to the rise of Chinese models. One is to make them harder to build and the other is to call them stolen. Starving China of chips has worked. For China hawks, myself included, the export controls are a success. By Epoch AI’s count, Chinese firms own just over 5 percent of the world’s leading AI hardware and processing power, less than any one of the largest American cloud companies. The popular claim that sanctions taught Chinese laboratories to be ingenious reverses cause and effect. Constraints encouraged adaptation, but they also denied China the chips to go further. Without the controls, China would probably be closer to the AI frontier.
Alibaba, the closest thing China has to Amazon, has been giving AI away for three years
The second answer is harder to press, because a model can be copied without anything being taken. Ask it a million questions and every answer teaches the questioner a little more about how it thinks. Train a new model on enough of them and you have something that behaves like the original – and no stolen object to produce in court.
Anthropic has accused Chinese companies of running that process on an industrial scale and says its own monitoring caught them. American officials say Moonshot ran models against Claude to build Kimi K3. The public evidence does not prove it and independent researchers doubt that 15 days of access would have been long enough.
Neither answer reaches the customer. The chip export controls worked and Airbnb bought Qwen anyway. Prove every accusation, jail everyone who trained a model on another model’s answers and Airbnb still buys Qwen.
Airbnb told Congress that it hands no data to Chinese companies and on that narrow technical point it is correct. A downloaded model telephones nobody. No customer records go to Hangzhou. The danger sits in the model itself, in the answers it was trained to give and the subjects it was trained to avoid. Alibaba and Moonshot build under Chinese law, which regulates what a model may say; those choices, made long before anyone at Airbnb downloaded the file, subtly influence the work of American companies.
On July 17, the day after the release of Kimi K3, Xi Jinping stood up in Shanghai. Twenty-nine governments had signed up the day before to a new AI company headquartered in the city. He offered developing countries 5,000 training places over five years.
Then he explained what China’s own laws are for: to make sure that AI is “safe, secure and controllable.” He told the truth only about the third point. Free to download, controllable by design and no need to come first.
Comments