← All posts / Policy

Naming the Enemy's Models: China's Spy Chief Declares AI a 'New Arena for Strategic Rivalry'

China's State Security Minister Chen Yixin names Claude Mythos and GPT-5.5-Cyber as cyber-threats in a party journal — the first time Western frontier models appear by brand in Beijing's national-security discourse.

Naming the Enemy's Models: China's Spy Chief Declares AI a 'New Arena for Strategic Rivalry'

For years, Beijing’s warnings about foreign artificial intelligence stayed comfortably abstract: Western models were “unsafe,” “untrustworthy,” or guilty of unspecified “ideological risks.” That era ended on Sunday. In an article for China Cyberspace, the journal run by the Cyberspace Administration of China, State Security Minister Chen Yixin — the country’s top intelligence official — declared that AI has become “a new arena for strategic rivalry among major powers,” and then did something previous Chinese security commentary had not: he named names. Anthropic’s Claude Mythos and OpenAI’s GPT-5.5-Cyber appear by brand as next-generation US-led systems that “significantly lower the technical threshold and costs” of executing cyberattacks.

It is a short sentence with a long shadow. When a state security minister puts specific foreign commercial products into a national-security threat framing, he is not writing an op-ed — he is laying groundwork.

What the article actually says

Chen’s piece, published on the journal’s social media account on September 13 and picked up by SCMP on September 14, organizes Beijing’s anxieties into a familiar-but-hardening structure:

  • Ideological and regime security come first. Chen warns that AI could have a “systemic impact on ideological security,” including being “leveraged by hostile forces” to generate rumors and mass-produce harmful information. The deepfake scenario — hostile actors manufacturing destabilizing narratives inside China — is risk number one, echoed in summaries of the article describing how “hostile forces and people with ulterior motives” can use deepfakes and AI-generated text.
  • Critical infrastructure is risk number two. Advances marked by “next-generation US-led models such as Anthropic’s Claude Mythos and OpenAI’s GPT-5.5-Cyber,” Chen argues, raise the efficiency of discovering system vulnerabilities and developing malware — lowering the technical threshold and costs of executing cyberattacks against critical information infrastructure.
  • State data, business secrets, and personal privacy round out the stake list in SCMP’s summary, alongside the standard call for “robust risk prevention frameworks” and stronger safeguards.

Notably absent: any Chinese domestic model named as a safer counterweight. The article carries the imprint of the internet watchdog rather than an operational directive — framing, not enforcement. At least not yet.

Why naming brands is the real news

The specific models Chen cites matter less than the act of citing them. Beijing has spent two years building the legal scaffolding for treating foreign AI as a governed risk object — generative AI licensing rules, a national AI safety governance framework, security assessments for algorithms — but its public threats discourse rarely descended to product names. Now it has.

There is precedent for where this leads. In July, China’s National Vulnerability Database classified Anthropic’s Claude Code as a major security risk, and Chinese regulators have warned against the model as a back-door. Around the same time, US intelligence accused six Chinese firms of stripping billions of tokens from US frontier models. The two sides are now openly warning against each other’s AI — a mutual designation spiral that looks increasingly like the export-control lists it mirrors. As AI Weekly’s analysis put it: does China now begin publishing named-model threat assessments the way US export-control lists work, and which lab gets named next?

For Anthropic and OpenAI, being written into a rival power’s official security lexicon converts their products from exports into strategic objects. That has second-order effects: it hardens the case inside China for a parallel, Beijing-led AI rules system; it gives CAC regulators a citation for future restrictions on foreign model access; and it feeds the very “decoupling” narrative both governments claim to want to manage.

The governance counter-move

Chen’s article pairs the threat framing with a pitch. He called for “a fair and open international AI rules system,” warning against AI becoming an “exclusive game” of a few powers — language that tracks almost word-for-word with Beijing’s running critique of US export controls.

The timing is not accidental. Over the weekend at the BRICS summit in India, President Xi Jinping proposed an AI-powered initiative to drive new industrialization and deepen supply-chain cooperation across the bloc, pitching what amounts to a BRICS AI cooperation community. Chen’s journal article lands days later, converting the summit’s cooperative vision into a security brief: the same technology Beijing wants to industrialize the Global South with is, when wielded by “hostile forces,” a direct threat to China’s “political security, institutional security and ideological security.”

This is Beijing’s standard two-handed play — offer to write the world’s AI rules while securitizing the AI it doesn’t control. What’s new is that the security hand now points at named American products.

What to watch

Three signals will tell us whether Chen’s article was rhetorical positioning or the prelude to policy:

  1. A follow-on CAC rule or advisory naming foreign LLMs. The article carries the watchdog’s journal imprint; a concrete rule citing Claude or GPT by name would move the language from framing to enforcement — the step AI Weekly flags as the one to watch.
  2. Access restrictions inside China. Multinationals operating in China that rely on foreign frontier APIs should anticipate scrutiny of model training practices, data flows, and vendor relationships — the compliance squeeze cryptobriefing’s analysis anticipates for anyone in China’s AI ecosystem.
  3. US response in kind. Washington has already named Chinese models in advisories. Each side’s naming legitimizes the other’s next round.

For the AI industry, the deeper signal is that the “AI race” is no longer a metaphor confined to benchmarks and compute. When intelligence ministries on both sides of the Pacific start maintaining lists of each other’s models, frontier AI has fully entered the national-security state machine — with everything that implies for market access, research collaboration, and the already-fraying idea of a single global AI ecosystem.

The models were named on Sunday. The rules that cite them may not be far behind.