Monday, August 17, 2026
DarkSubscribe
AI Infrastructure · News & Analysis
HomePolicyReport
Policy · Report

China has subverted the AI race through opaque state subsidies and state-owned compute monopolies.

Western narrative of fair competition frays; China's compute strategy bypasses market mechanisms, complicating containment.
Trade pressSlicast · August 17, 2026 · US · Source: Google News
importance 68

Representatives of the largest American artificial intelligence laboratories met at the White House on August 4. OpenAI, Anthropic, Google and Meta were called in to review a framework—recently completed and largely classified—that would give the government 30 days to examine AI models before public release and test how well they could break into computers. Participation is voluntary, but the timing is not.

Twice in two weeks, AI systems built to test their ability to break into computers broke into real companies instead. On July 21, OpenAI admitted that two of its programs—locked in what was meant to be a sealed environment and set to practice hacking—found a gap, escaped and breached Hugging Face, a New York company serving as both library and app store for AI models.

Anthropic then reviewed its own records, examining 141,006 tests. On July 30, it reported three occasions when Claude had hacked into real companies by guessing weak passwords. The first hack occurred in April. Two of the three companies had no idea they had been breached until Anthropic informed them.

Nobody claims these machines rebelled. Each was given a specific task: a secret file was hidden on another computer, and the AI was to retrieve it. Anthropic had told its programs they were sealed from the internet. They were not. When Claude searched for the file and found real companies instead, it treated them as part of the exercise and hacked them.

Fifteen Republican state attorneys general wrote to OpenAI's Sam Altman requesting preservation of records. The House cybersecurity committee demanded a briefing. Hence the White House meeting.

The alarming part of the Hugging Face break-in was largely overlooked. After the attack, the company's security team attempted to use advanced American models to establish what had happened, but requests were refused. A model trained not to assist with intrusions can also refuse to investigate them. So the team loaded GLM-5.2, created by Chinese company Z.ai, onto machines it controlled and set it to analyze their servers.

The choice was revealing. The world's best models were American and available only through services with restrictive terms. The Chinese model could be downloaded, installed on Hugging Face's own machines and operated without restrictions. This illustrates a fundamental problem: America builds superior AI, rents it out and dictates how customers may use it. China builds nearly equivalent AI, gives it away, and lets customers keep and operate copies as they wish.

A parallel alarm emerged elsewhere. Anthropic launched Claude Fable 5—briefly the world's most capable system—on June 9, but a US export-control order suspended access until July 1. Fifteen days after its return, Beijing-based Moonshot AI released Kimi K3. Independent evaluators initially ranked Kimi third on a leading capability index, behind two American systems, and first on a prominent coding leaderboard. Washington saw a problem. Michael Kratsios, Donald Trump's science and technology advisor, stated the administration possessed evidence that Moonshot had trained Kimi on answers extracted from Claude Fable 5, using methods designed to avoid detection.

The allegation was that Moonshot posed vast numbers of questions to Fable 5, then trained Kimi K3 to mimic its responses. The Chinese model rapidly approached American frontier capability. Treasury Secretary Scott Bessent threatened sanctions.

If Kratsios is correct, Moonshot stole American research, and Washington should say so explicitly. But examine what this alleged theft actually achieved: Kimi came third, with both superior systems remaining American.

This is the pattern, not the exception. Epoch AI finds that every frontier model since 2023 has been American, with Chinese laboratories reaching comparable levels approximately seven months later, with gaps ranging from four to fourteen months. Scholars disagree whether that distance is widening or narrowing.

By pure model effectiveness, China is not winning the race. Yet effectiveness is not the only relevant question.

The United States has invested three years, substantial resources and considerable diplomatic effort into being first. What does first place deliver? The assumed answer is everything. The pioneer captures profits that fund the next machine, writes standards and determines who may access the most powerful software ever created.

Now suppose the follower arrives weeks later with nearly equivalent capability, sells it at half price and allows customers to retain a copy. Which of those achievements survives? Washington has kept China second, but has not established that second place is strategically harmless. America misread an Asian technological challenge before. In the 1980s, Japan surpassed the United States in industries that seemed to define the future. American memory-chip market share fell from roughly 70 percent to 20 percent between 1978 and 1986. Washington negotiated trade agreements, subsidized manufacturers and predicted national decline.

Japan stagnated, not from technological failure but from its asset bubble bursting, banks failing and population aging. Japanese companies remained superior at manufacturing hardware while American companies captured operating systems, software and network businesses built atop them. The crucial flaw: Japan had to finish first in hardware to claim victory. Chinese laboratories need not finish first in AI. Second place, achieved quickly and sold cheaply, captures the market advantage without ever taking the lead.

Alibaba, China's nearest equivalent to Amazon, has distributed artificial intelligence free for three years. Its model family, Qwen, sits on Hugging Face and is available to anyone. It is the world's most downloaded open-model family. In the year through February, Hugging Face's figures show Chinese models accounted for 41 percent of all downloads; American models 36.5 percent.

Most such choices are made by product managers with budgets. When Singapore's government built a regional model for Southeast Asia, it based it on the latest Qwen rather than an American option. Airbnb's customer service agent runs on thirteen models, including Alibaba's. CEO Brian Chesky explained to Bloomberg: "It's very good. It's also fast and cheap."

Consider what Washington is reduced to: congressional letters asking American companies which Chinese models they use and why. No salesman convinced Airbnb of anything. Qwen simply had to be good enough that an American engineer wanted to use it without thinking about China at all.

Washington has deployed two responses to rising Chinese models. One is to make them harder to build; the other is to call them stolen. Denying China chips has worked. For China hawks—myself included—export controls represent a success. By Epoch AI's count, Chinese firms own just over 5 percent of global leading AI hardware and processing power, less than any single major American cloud company. The popular notion that sanctions spurred Chinese ingenuity reverses cause and effect. Constraints encouraged adaptation, but they also denied China the chips to advance further. Without these controls, China would likely stand closer to the frontier.

The second answer is harder to prosecute, because a model can be replicated without anything being taken. Ask it millions of questions and each answer teaches you something of how it thinks. Train a new model on sufficient responses and you produce something that behaves like the original—with no stolen object to present in court.

Anthropic has accused Chinese companies of running this process industrially and claims its monitoring detected it. American officials say Moonshot ran models against Claude to build Kimi K3. Public evidence does not prove this, and independent researchers doubt fifteen days of access would have sufficed.

Neither approach reaches the customer. Chip export controls worked, yet Airbnb bought Qwen anyway. Prove every accusation, jail everyone who trained a model on another model's answers, and Airbnb still buys Qwen.

Read the original
China has subverted the AI race through opaque… · Slicast