America’s AI Leaders Fear Runaway Superintelligence — China Is More Worried About Deepfakes, Cyberattacks and Social Disorde

Business

America’s AI Leaders Fear Runaway Superintelligence — China Is More Worried About Deepfakes, Cyberattacks and Social Disorde

BEIJING/WASHINGTON — The United States and China are racing to dominate artificial intelligence.

Increasingly, they are also racing to define what exactly everyone should be afraid of.

In Silicon Valley, the most dramatic warnings now focus on frontier AI systems becoming capable of improving themselves, operating autonomously and eventually escaping meaningful human control.

Anthropic CEO Dario Amodei has called on leading AI developers to slow the pace at which they improve their most advanced models, arguing that safety systems may not be keeping up with rapidly accelerating capabilities. OpenAI CEO Sam Altman and Elon Musk have publicly supported elements of his call.

China’s public warnings sound different.

Beijing officials have placed greater emphasis on threats that already look familiar to governments: deepfakes, mass influence campaigns, cyberattacks, data theft, manipulated information and AI systems destabilising society before hypothetical superintelligence ever appears.

The contrast is important.

But it would be misleading to conclude that one country worries about AI safety while the other does not.

China is already building mandatory security assessments and standards around increasingly autonomous AI systems.

The United States, meanwhile, is deeply divided over whether frontier development should slow at all.

The more revealing story is that Washington and Beijing may be approaching AI risk from different starting points — while confronting some of the same underlying technology.

And an extraordinary WeChat security experiment may have just shown where cooperation could begin.

A single incoming WeChat call was enough in a security demonstration

Earlier this month, cybersecurity researchers at Palo Alto-based Calif revealed what they called WeWorm.

It was a demonstration of a zero-click vulnerability involving WeChat’s voice-calling system.

According to Calif, a malicious call exploiting the flaw could compromise a WeChat account without requiring the victim to click a link or intentionally interact with the attacker.

The compromised account could then contact other people, creating the potential for worm-like propagation across users.

That sounds like the beginning of a catastrophic cyberattack.

It was not.

There is no evidence that WeWorm was released in the wild as a mass attack.

Calif discovered the flaw during security research, reported it to WeChat parent Tencent in July and says Tencent had mitigated the exploit for users before the researchers publicly disclosed it in September.

That distinction is crucial.

The incident was a warning about what could become possible, not evidence that more than a billion WeChat accounts had actually been compromised.

The frightening part was how AI changed the economics of hacking

Calif’s larger point was not simply that WeChat contained a vulnerability.

Software vulnerabilities have existed for decades.

What changed was the researchers’ ability to use increasingly capable AI tools to help discover and develop sophisticated exploits.

Calif said its AI discovered the underlying bug in July.

Its researchers then built working Android and iOS exploits and eventually a polished worm demonstration.

The company argues that capabilities once concentrated among highly skilled, well-funded cyber teams may increasingly become accessible to much smaller groups as AI assists with vulnerability research, coding and attack development.

That creates two opposite possibilities.

AI can make attackers far more capable.

But it can also make defenders far faster at finding vulnerabilities before criminals do.

The WeChat episode contained both.

AI helped uncover a potentially devastating weakness.

Then researchers in the United States disclosed it to a Chinese technology company, and Tencent fixed it.

Why WeChat makes this more than an ordinary software bug

WeChat is not simply a messaging app.

For many people in China, it is part of the digital infrastructure of ordinary life.

Users communicate with family and colleagues, interact with businesses, access services and make payments through the broader WeChat ecosystem.

Calif warned that a self-spreading exploit involving such a platform could therefore have consequences extending far beyond stolen chat accounts.

That helps explain why China’s AI-security debate is heavily focused on threats to platforms, information networks and social stability.

If an AI-assisted attack compromised communications at enormous scale, the immediate danger would not require a science-fiction superintelligence.

Ordinary humans armed with better automation could cause severe disruption first.

China’s intelligence chief has warned about exactly that kind of danger

CNA’s Bloomberg commentary points to a recent essay by Chinese Minister of State Security Chen Yixin, who highlighted AI-related risks including deepfakes, influence operations, large-scale information manipulation and cyber threats.

The emphasis was notably different from the extinction-focused warnings that have dominated Silicon Valley’s latest debate.

Beijing’s concern is that AI can amplify familiar threats:

false information can become cheaper to produce;

personal data can be harvested more efficiently;

cyber operations can become easier to automate;

and influence campaigns can operate at larger scale.

These are not speculative technologies that require a future superintelligence.

Elements of them already exist.

But China is also preparing for autonomous AI failures

This is where the simple “China only cares about social control” narrative breaks down.

Reuters reported that Beijing has also been developing a sophisticated regulatory framework for advanced AI safety, including security assessments, external testing and mandatory technical standards.

Chinese regulators have been working on what could become one of the first mandatory national standards specifically addressing AI-agent security.

The risks under consideration include rogue agent behaviour, manipulated models, poisoned data and systems acting outside their intended boundaries.

So there is overlap with Western frontier-safety concerns.

The difference is partly one of framing.

American AI laboratories increasingly discuss whether extremely advanced systems could become uncontrollable.

Chinese policy documents more commonly describe advanced AI as a powerful technology whose risks can be managed through rules, testing, technical controls and government supervision.

Beijing already regulates generative AI more directly than Washington

China has not waited for hypothetical superintelligence before imposing national AI rules.

The country’s interim generative-AI measures require providers of certain public-facing services to comply with security, data and content obligations.

As of August 31, 2026, China’s cyberspace regulator said 1,112 generative-AI services had completed filing procedures, while another 731 applications or functions using registered models had completed separate registration.

Draft internet rules released this summer would further require providers to manage AI-generated content, follow labelling requirements and strengthen safeguards against significant AI security risks.

China’s system therefore combines innovation policy with much more direct state supervision than the fragmented U.S. model.

That does not establish that either approach is more effective.

They are structurally different regulatory systems operating under different political and legal institutions.

America’s biggest AI companies are now asking whether they are moving too quickly

The immediate U.S. debate intensified after Anthropic’s Amodei published an essay titled “We Must Pace the Frontier.”

Amodei argued that AI capabilities have recently begun advancing more rapidly partly because AI itself is becoming increasingly useful for developing the next generation of AI systems.

That phenomenon is often called recursive self-improvement.

He also cited incidents involving autonomous AI agents engaging in unintended cybersecurity behaviour.

His concern is not that today’s chatbots are already unstoppable superintelligences.

It is that improving AI-assisted research and coding could shorten development cycles faster than safety research can adapt.

Amodei therefore proposed three broad steps.

Frontier companies would allow independent evaluators deeper access to their development processes.

Major AI developers would coordinate on safety standards.

And eventually, governments — including geopolitical competitors — would attempt international coordination.

He explicitly said “pacing” does not mean ending AI research.

It means slowing capability advancement enough for safeguards and evaluations to catch up.

OpenAI and Musk surprised the industry by broadly agreeing

The proposal attracted attention partly because some of Anthropic’s fiercest competitors supported key elements of it.

Reuters and the Financial Times reported that OpenAI’s Sam Altman and Elon Musk backed the general call for greater caution, while Google DeepMind leaders have also emphasised stronger evaluation frameworks.

That is unusual in an industry where companies compete intensely for models, researchers, computing infrastructure and customers.

But even within Silicon Valley, there is no unified position.

Meta CEO Mark Zuckerberg has argued that companies already possess strong incentives to develop AI safely and should be free to slow their own projects when necessary rather than entering an industry-wide slowdown agreement.

So the U.S. debate is not “America has decided to slow AI”.

It has not.

It is an argument among companies, policymakers and researchers over whether voluntary safety measures are enough.

The Trump administration is resisting a broad slowdown

President Donald Trump has rejected calls for the United States to substantially decelerate AI development, emphasising competition with China.

House Speaker Mike Johnson similarly argued this week that an AI moratorium could weaken the United States’ technological advantage and create national-security risks if China continued moving ahead.

Johnson has nevertheless supported measures including independent auditing and increased transparency by developers.

That distinction matters.

Opposing a moratorium does not necessarily mean opposing every safety rule.

The U.S. political dispute is increasingly about how much oversight can be added without materially slowing technological competition.

U.S. states are filling part of the regulatory vacuum

America also lacks a single national AI regime comparable to China’s central framework or the European Union’s AI Act.

Instead, states have begun establishing their own requirements.

OpenAI noted in July that California, New York and Illinois had advanced frontier-safety measures, arguing that state rules could eventually contribute to a common federal baseline.

That creates a distinctly American governance model.

Federal agencies regulate parts of the technology through existing law.

States add separate requirements.

Companies publish voluntary safety frameworks.

Congress debates new legislation.

And courts determine how older rules apply to new systems.

Whether that fragmented structure can keep pace with rapidly developing autonomous AI remains contested.

China does not want the United States writing the global rules alone

The disagreement becomes even larger when governance moves from domestic regulation to international coordination.

At the BRICS summit in New Delhi on September 13, President Xi Jinping called for a consensus-based global AI governance framework and proposed a BRICS open-source AI community.

China also offered to support cooperation on large language models, AI training and an “open ecosystem for AI.”

The political message was clear.

Beijing wants international AI rules to be negotiated through structures in which China and developing countries have substantial influence rather than having standards primarily established by Washington and its allies.

China will also take over the BRICS chair next year, giving it another platform for advancing that position.

China reacted sharply to Amodei’s proposal

The problem is that Amodei’s version of international cooperation comes bundled with geopolitical policies Beijing strongly opposes.

His proposal supports tighter controls on advanced AI technology reaching China as part of a strategy designed to maintain a U.S. technological advantage while safety mechanisms develop.

China’s state-backed Global Times responded by portraying the proposal as a “Cold War” approach aimed at constraining Chinese technology rather than purely protecting humanity.

China’s foreign ministry and state media have instead argued for more inclusive governance and warned against allowing a small group of countries to monopolise AI technology.

The People’s Daily said this week that AI should not become a monopoly of major powers and called for U.S.-China dialogue over shared risks.

These are competing national positions.

Neither establishes the actual motive of every company or government actor involved.

Export controls make safety cooperation much harder

The United States has spent years restricting China’s access to some advanced semiconductors and chipmaking technology.

Washington argues such controls address national-security concerns and prevent sensitive technology from strengthening Chinese military or surveillance capabilities.

China has repeatedly criticised those restrictions as attempts to suppress its technological development.

AI safety therefore sits inside a much larger strategic rivalry.

Imagine Washington proposing that both countries disclose detailed information about the capabilities and vulnerabilities of their most advanced AI systems.

From a safety perspective, greater transparency could help researchers understand shared risks.

From a national-security perspective, revealing too much could expose strategically valuable information to a rival.

That tension is one reason global AI governance is much harder than drafting domestic regulations.

The WeChat case offers a much smaller form of cooperation

That is what makes WeWorm significant.

It did not require Washington and Beijing to agree on superintelligence.

It did not require either government to disclose classified AI programmes.

It did not require a global treaty.

A U.S. research team discovered a dangerous vulnerability in a major Chinese product.

The researchers contacted Tencent.

Tencent engaged with the disclosure.

And the flaw was mitigated before the researchers publicly released their findings.

Calif says it reported the bug in July.

Tencent released updated Android and iOS software on August 21.

By August 28, the researchers had confirmed that the exploit was also mitigated server-side.

The research was publicly announced on September 8.

That sequence is significant because it shows cooperation can occur at the technical level even when governments disagree over almost everything surrounding AI.

But this was cooperation between researchers and a company — not an AI treaty

It is important not to exaggerate the example.

The WeChat disclosure does not prove Washington and Beijing have solved AI-security cooperation.

It was primarily interaction between security researchers and Tencent.

There was no new bilateral AI accord.

No joint regulatory institution emerged.

And the two countries remain in a fierce strategic technology competition.

Still, the episode illustrates a potentially practical model.

Researchers can share vulnerability information.

Companies can fix systems before publication.

Technical communities can establish rules for responsible disclosure.

Governments can create legal conditions that allow that cooperation rather than criminalising or politicising it.

Those mechanisms are far narrower than an agreement to control superintelligence.

They may also be easier to achieve.

The two countries already agree on more than their rhetoric suggests

Washington and Beijing both say AI can generate enormous economic benefits.

Both are investing heavily.

Both worry about cyberattacks.

Both worry about national security.

Both increasingly recognise that autonomous agents create new risks.

And both say some international cooperation is desirable.

The disagreements concern who writes the rules, what risks deserve priority and whether safety restrictions could be used strategically against the other side.

Those are substantial disagreements.

But they are different from saying the two sides share no common ground.

China’s biggest nightmare may happen before superintelligence

The CNA/Bloomberg commentary argues that Beijing’s nightmare is less about a machine deciding to destroy humanity and more about AI empowering humans to destabilise society first.

There is evidence for that distinction in China’s policy emphasis.

Deepfakes can manipulate public opinion.

AI-generated propaganda can scale influence campaigns.

Automated cyber tools can attack infrastructure.

Data-analysis systems can accelerate espionage.

AI agents can automate fraud or penetrate networks.

None requires artificial general intelligence.

That makes them easier for governments to regulate today because the harms resemble existing threats.

Western policymakers also care about all of these issues.

The distinction is about relative emphasis, not mutually exclusive concerns.

Silicon Valley is asking a harder-to-measure question

Amodei and other frontier-AI researchers are asking what happens if capability growth itself becomes the risk.

Suppose models become dramatically better at coding.

They then help researchers build even better models.

Those models become better at AI research.

Development cycles accelerate again.

At some point, proponents of the recursive-self-improvement concern argue, human institutions could struggle to evaluate each generation before the next one arrives.

That scenario remains uncertain.

No publicly available AI system has demonstrated an unrestricted runaway process in which it autonomously redesigns itself into uncontrollable superintelligence.

Predictions about the timing and probability of such outcomes vary widely.

That uncertainty is precisely why the disagreement is so intense.

Supporters of stronger precautions argue that waiting for proof could mean waiting too long.

Sceptics argue that extreme scenarios can distract policymakers from measurable harms already occurring.

The irony is that both sides may need the same first step

Whether policymakers worry most about deepfakes or superintelligence, they eventually encounter the same problem:

Governments need better information about what AI systems can actually do.

Amodei wants external evaluators inside frontier labs.

China uses security assessments and regulatory filings.

OpenAI has called for frontier-safety rules and outside scrutiny.

Even U.S. politicians opposing a development moratorium have expressed support for transparency and independent auditing.

Those systems are politically very different.

But all reflect a recognition that regulators cannot govern capabilities they cannot observe.

Transparency could be the narrow bridge between Washington and Beijing

A global agreement determining how fast every frontier model may advance appears extraordinarily difficult.

The U.S. and China do not trust each other enough to easily verify such commitments.

Commercial firms do not want to disclose trade secrets.

Governments do not want to expose national-security capabilities.

And open-source or open-weight models create additional enforcement challenges.

The more achievable starting point may therefore be narrower.

Rapid reporting of severe vulnerabilities.

Shared protocols for cyber incidents.

Common terminology for dangerous agent behaviour.

Channels for researchers to disclose cross-border risks safely.

Agreements not to exploit certain AI vulnerabilities in civilian infrastructure.

Independent technical exchanges where possible.

Those steps would not resolve the question of runaway AI.

They could reduce risks that already exist.

AI governance is becoming another arena of geopolitical competition

China has proposed an open-source BRICS AI ecosystem.

U.S. companies and officials speak about preserving American technological leadership.

Beijing objects to semiconductor export restrictions.

Washington accuses Chinese actors of intellectual-property theft and influence operations.

China argues that American restrictions entrench technological dominance.

That rivalry is not going away simply because AI safety has become more urgent.

In some respects, growing concern may make competition stronger.

If advanced AI is seen as economically transformational and strategically decisive, neither government will want to be the only one that slows down.

Reuters noted this week that geopolitical competition itself is one of the biggest obstacles to coordinated deceleration.

That is why the WeChat episode matters

It offers a smaller and less dramatic lesson than declarations about saving humanity.

An American research team found a potentially serious flaw.

A Chinese technology company fixed it.

The researchers disclosed the problem publicly only after mitigation.

No global regulator forced them to cooperate.

No geopolitical breakthrough was required.

It is difficult to build an international AI regime when countries cannot agree on what the ultimate danger is.

But they do not necessarily have to agree on every hypothetical future before cooperating on concrete risks today.

America’s most alarmed AI leaders are asking how to prevent machines from eventually moving beyond human control.

China’s security establishment is asking how to stop humans from using increasingly capable machines to attack networks, manipulate information and destabilise society.

Those concerns are not identical.

But the same technology is driving both — and the WeChat case suggests that fixing the dangers everyone can already see may be the most realistic place to start.

Leave a Reply

Your email address will not be published. Required fields are marked *