China’s state security minister names two US AI models as a cyber threat

Claude Mythos by Anthropic Credit: Primakov via Shutterstock China’s minister of state security has named two American AI models as a threat to Chinese infrastructure. Chen Yixin made the claim in a signed article published on Sunday. It ran in China Cyberspace, the journal of the Cyberspace Administration of China. The two models are named in the text, in Chinese and in English.

The passage, in the full Chinese text, names Claude Mythos and GPT-5.5-Cyber. In translation, it says the two models mark a point at which AI is markedly raising the efficiency and the weaponisation of two things. One is vulnerability discovery. The other is malware development.

That, Chen writes, brings serious risk to China’s critical information infrastructure. The Chinese text glosses the two names as “myth” and “cyber”. What the article is The piece runs under Chen’s name and his two titles, party secretary and minister of the Ministry of State Security. Its title translates as building a comprehensive AI security barrier and promoting the healthy and orderly development of AI.

China Cyberspace published it through its WeChat account on 13 September. Taiwan’s United Daily News reported the model names from the Chinese text. Cheryl Teh wrote it up for Business Insider on Monday. Chen sets out six risks, in this order.

A systemic effect on the political security environment. A disruptive upgrade of the cyber offence and defence picture. A large-scale amplification of leak and espionage risk. A technological imbalance caused by AI monopoly.

A structural shock to social governance. And a fundamental change in the form of military conflict. Regime security comes first. Chen writes that hostile forces and bad actors abuse generative tools to manufacture political rumours cheaply and at volume.

He lists synthetic audio and video, AI-generated images and text, and what he calls intelligent online armies. Those tools spread harmful information and wage cognitive warfare, he writes, which threatens political, institutional and ideological security. The third risk is about data. Chen writes that both Chinese users of AI services and foreign intelligence agencies could come away with national data, trade secrets or citizens’ personal information.

The cyber section is the new part The second risk is where the model names appear. Chen describes cyber offence and defence entering a new stage. He characterises it with three phrases. Industrialised vulnerabilities.

Fully automated attack and defence. AI against AI. He writes that AI has sharply lowered both the technical threshold and the cost of mounting a cyberattack. The article gives no example of an attack on a Chinese target.

It attributes no incident to either model. It does not say whether Chinese systems have been hit at all. The two models appear as a marker of capability, not as the instrument of a named event. Anthropic released Mythos as its strongest model.

It has said it will hand what the model finds to defenders, while withholding the model itself. OpenAI sells GPT-5.5-Cyber as a security-specific model. Both companies market the same capability Chen describes, as a defensive one. The evidence on what these models actually do The capability claim is partly measurable.

TNW reported in July, using VulnCheck’s data, that AI is finding roughly twice as many software flaws as before. Almost none of those flaws were then exploited in the wild. Discovery and use are running at very different rates. Other governments are handling the same two model families as material to be tested rather than denounced.

The European Commission said last week that its cybersecurity agency is now testing Mythos 5 and GPT-6 Astra. Chen’s article asks for a national prevention and control system instead. Beijing said a version of this in private first The anxiety is not new, but the venue is. TNW reported in August that China champions open AI in public while worrying privately about one closed American model.

Chen’s article moves that position into an official journal, under a minister’s name, with the models identified. It also lands two days after Beijing’s answer to Dario Amodei. The commerce ministry called his export-control essay proof of American technological hegemony. Global Times ran a commentary describing a Cold War script.

That exchange was about chips and containment. Chen’s article is about the models themselves and what they can do. The weekend carried a third strand. Amodei, Sam Altman and Elon Musk each backed calls to slow frontier AI development, Business Insider reported.

Chen does not mention any of them. His article argues for controls that Beijing would write and enforce itself. What Chen asks for The remedies are domestic and international. At home, Chen calls for faster construction of a security risk prevention and control system, and for high-efficiency governance.

He restates the principle of party management of the internet and party management of data. Abroad, he asks for a fair and open international system of AI rules, and says powers must resist hegemonism, technical barriers and exclusive blocs. He writes that AI should be developed with the wellbeing of all humanity as its guiding principle. Xi Jinping used compatible language the same day.

At the BRICS summit in New Delhi he called for a people-centred approach and a consensus-based global governance framework, in remarks TNW covered alongside his pitch on open-source AI. Chen supplies the security case beneath that diplomacy. What is not established Three things in the article rest on assertion. The first is that the two named models have raised malware and vulnerability capability against China specifically, which Chen states without an example.

The second is the scale of any resulting exposure, which he does not quantify. The third is the direction of travel. Chen frames the problem as foreign capability reaching Chinese systems. He does not address Chinese models in the same terms, and the article names no Chinese system as a source of similar risk.

Leave a Reply

Your email address will not be published. Required fields are marked *