China Sees Opportunity in America’s Recent A.I. Security Scares
In the United States, recent episodes where powerful artificial intelligence software broke free and hacked into other computer systems prompted a wave of anxiety and intense debate about how to guard against the risks of A.I.
But in China, these incidents and the growing capabilities of A.I. have not caused the same level of alarm. The government already controls many kinds of technology including A.I. The prevailing attitude in the industry has been that the benefits of A.I. far outweigh the risks.
That was exemplified on Friday when Z.ai, a Beijing-based A.I. start-up, made public the details of its latest model. The company claims the new model is nearly as powerful as those developed in Silicon Valley, especially when it comes to hacking and coding capabilities.
Z.ai, like most other leading Chinese companies, has embraced an approach known as open-source or open-weight software. The weights are the mathematical parameters that determine how an A.I. system operates. Z.ai published the weights on its new model, called GLM-5.3.
With open-weight software, anyone can access and tinker with the rules of an A.I. system. American companies, which generally keep the weights of their most powerful models secret, warn that opening the technology could increase cyberattacks. The open-weight camp argues the opposite: Giving more people access means more eyes looking for security flaws and ways to fix them.
In a speech last month, China’s leader, Xi Jinping, called open models a “rare and historical opportunity” to spread the benefits of A.I. globally, a clear signal of how China plans to compete with the United States.
But Mr. Xi paired that call for openness with a warning. He urged governments to cooperate on regulations to “ensure that A.I. is always under human control.”
His statement represented “a subtle but meaningful posture shift on A.I. safety,” said Xiaomeng Lu, a director focused on geopolitics and technology at the Eurasia Group, a research and consulting firm.
When Chinese labs lagged well behind U.S. tech companies in developing leading edge models, safety and testing were “a distant concern and a low priority,” Ms. Lu said.
But as Chinese companies have approached the technological frontier, that calculation has started to change. China, she said, now recognizes that “credible leadership” requires making A.I. safety a priority.
Chinese universities, government labs and tech companies have sharply increased their research on the safety of the most powerful A.I. models in the past year, according to a study by Concordia AI, a Beijing-based consulting firm focused on A.I. safety. The monthly number of papers on cutting-edge models and A.I. agents rose 60 percent from June 2025 to April 2026, the analysts found.
The report also said the increase marked a departure from China’s traditional focus on A.I. safety as policing online speech and imagery produced by the technology.
The growing attention to advanced models expands the notion of A.I. safety from what A.I. says to what A.I. does. That, the Concordia AI study said, is “a shift in China’s framework from content control toward action control.”
The Chinese government has also begun drawing attention to those risks. After software made by OpenAI, the Silicon Valley giant, broke free and hacked into another company’s computer systems, China’s Ministry of State Security, which oversees the country’s intelligence services, issued a warning. The statement, issued this month and titled “When A.I. Learns to Act on Its Own,” urged serious consideration of the technology’s safety and security risks.
Yet the article stopped short of questioning whether A.I. could continue to advance safely. Instead, it places the burden largely on individual users, cautioning them not to enter sensitive information into A.I. systems.
So far, China has pursued broader A.I. safety rules mainly through multilateral organizations like the United Nations and the China-led World AI Cooperation Organization. Experts say U.S. and Chinese interests overlap in this area. In May, Treasury Secretary Scott Bessent said the two nations planned to discuss A.I. safety.
Chinese companies, too, are taking more visible steps to manage the risks of increasingly capable models. In preparation for the release of its new model, Z.ai said it started a “security disclosure ledger” with the help of security teams at Tsinghua University, Nankai University and other institutions.
But Z.ai has also made a forceful case that openness itself can make A.I. safer. The closed approach taken by the big U.S. tech companies “turns cutting-edge security capabilities into a privilege enjoyed by a select few institutions,” Z.ai said. Later, the security article, published on its WeChat account, offered what amounted to a manifesto: “When the most powerful spear is locked in the hands of a few, the best shield must belong to everyone.”
Recent A.I. security lapses in the United States have strengthened that argument. When OpenAI’s system hacked into a popular online service called Hugging Face, Hugging Face turned to an open-source model made by Z.ai to contain the breach.
For supporters of open models, the episode seemed to invert the argument about the dangers of open models. In China, many concluded that the incident showed that the harm caused by an unsafe, closed American model could be undone by a safe, open Chinese system.
“The narrative was that the West tells us the open models are unsafe, when really their models are overly restrictive and truly unsafe,” said Scott Singer, who studies China’s A.I. policy at the Carnegie Endowment for International Peace.
The view contrasts from the debate unfolding in the United States, where technologists and policymakers increasingly worry about the unchecked advance of autonomous A.I. models.
Last month, OpenAI and Anthropic endorsed a letter signed by more than 1,000 employees of leading A.I. companies asking the U.S. government to help find a way to slow the pace of the technology’s development. In Washington, lawmakers have introduced a bill that would require A.I. companies to establish a “kill switch” to shut down or slow their models.
In an interview with The New York Times last week, Bill Gates, the billionaire co-founder of Microsoft, warned that A.I. posed a grave threat to humanity and was more dangerous than the tech companies were willing to admit.
Behind the divergent approaches to A.I. safety lies a more fundamental difference in how the United States and China view the technology and who can be trusted to control it.
In Silicon Valley, many see A.I. as an unprecedented force destined to change the world, with the people building it endowed with something approaching superpowers — and thus bearing extraordinary responsibility.
By contrast, many in China view A.I. as transformative but broadly comparable to major general-purpose technologies of the past, from steam power to electricity to the internet — life-changing, but ultimately manageable. There is also a view that, unlike in America, the government stands ready to step in.
“For the Chinese companies, there is a sense of the government being like a helicopter parent, always watching and acting as a guiding hand,” said Ms. Lu of the Eurasia Group.
Xinyun Wu contributed reporting from Taipei, Taiwan.