
Image: METAL
Summary
- China's Minister of State Security Chen Yixin published a signed article on the WeChat account of the magazine China Cyberspace on September 13, laying out AI risk under six headings: political security, cyber offense and defense, information leakage, monopoly, social governance, and forms of warfare.
- The top-ranked risk isn't models slipping out of control — it's public-opinion and cognitive warfare waged with deepfakes and intelligent bot armies. In the cyber section, Claude Mythos and GPT-5.5-Cyber are named specifically as threats to critical information infrastructure.
- A day later, foreign ministry spokesperson Guo Jiakun responded that spreading threat narratives only obstructs global AI governance — an answer given in response to a question about US AI companies calling Chinese AI a threat.
China's Minister of State Security Chen Yixin published a signed article on September 13 dividing AI risk into six categories. Titled Comprehensively Building an AI Safety Barrier to Advance the Healthy and Orderly Development of Artificial Intelligence, it ran not on the Ministry of State Security's own channel but on the official WeChat account of the magazine China Cyberspace, which is run by the Cyberspace Administration of China. It's rare for the head of an intelligence agency to lay out this detailed a view of how AI is seen.
The article's tone is captured in one sentence. Chen Yixin, secretary of the Ministry of State Security's Party committee and minister, wrote, "We must recognize the opportunity and seize the initiative, but at the same time clearly see the risks and hold the line." It's a declaration meant to give opportunity and control equal weight, yet the list that follows devotes all six items to risk. The discussion of opportunity gets pushed into the countermeasures section instead.
The first risk is the political security environment. He argues that various hostile forces and actors with impure intentions are abusing deepfake audio and video, AI-generated text and images, and intelligent bot armies to mass-produce political rumors cheaply, spread harmful information, and stir up antagonistic sentiment. The result, in his view, is public-opinion warfare and cognitive warfare aimed at China, which he diagnoses as "a direct threat to political security, institutional security, and ideological security." The fact that the number-one item on this risk list isn't a model slipping out of control, but people using models to manipulate public opinion, says something about the character of this document right away.
The second is the balance between offense and defense. The article names Claude Mythos and GPT-5.5-Cyber, recent releases from US tech companies, specifically, saying these models are sharply raising the efficiency and weaponization level of vulnerability discovery and malware development. It states that cyber offense and defense has entered a new stage: the industrialization of vulnerabilities, full automation of attack and defense, and AI-versus-AI confrontation. It's close to a situation where lockpicking has left the craftsman's hands and gone onto a factory line. METAL has reported on Anthropic's release of Mythos 5.1 and on OpenAI's Astra receiving a critical cyber rating.
The third is information leakage at greater scale. The article argues that foreign intelligence agencies are using intelligent web crawlers, data mining, and profiling analysis to scrape up large volumes of core national data, trade secrets, and citizens' personal information. It also notes that some domestic users process sensitive information through overseas AI products, letting data flow out of the country. It further points to a structural problem in Longxia, an open-source agent tool that became popular in the first half of 2026, where device management permissions could be remotely manipulated and users' sensitive information leaked.
The fourth is monopoly. The argument is that some countries use the pretext of protecting national security to leverage the advantages they've built up in basic theory, model architecture, and core computing power, blocking other countries from acquiring advanced equipment through entity lists, technology controls, monopolized industry standards, and closed ecosystems. The result, in this view, is the fragmentation of the global AI industrial and supply chain. According to reports, this section echoes remarks President Xi Jinping made in July opposing the broad expansion of the concept of national security.
The fifth and sixth items are about society and the battlefield. The fifth holds that algorithmic black boxes and data contamination amplify existing social biases and that automated decision-making makes it harder to assign accountability, with the diagnosis that legal norms, ethical principles, and governance mechanisms keep trailing behind the technology. The sixth is the changing form of warfare. Citing the conflict entangling the United States, Israel, and Iran as an example, the article states that AI has moved from a supporting role to a core role in intelligence fusion, decision support, target identification, real-combat support, and cognitive shaping.
The original article reviewed by METAL contains figures alongside the risks. As of June 2026, China's AI products had more than 500 million users, with average daily token usage exceeding 140 trillion. Seven countermeasures follow: comprehensive Party leadership, an inter-agency cooperation system, risk detection and early-warning platforms, self-reliance in core technologies such as chips and development frameworks, dedicated AI legislation on top of enforcing the Cybersecurity Law and Counter-Espionage Law, public outreach through the April 15 National Security Education Day and National Cybersecurity Publicity Week, and international cooperation.
A day later, a different ministry of the same country struck a different tone. At the regular briefing on the afternoon of September 14, foreign ministry spokesperson Guo Jiakun was asked about US AI companies calling China's AI development a threat to the United States, and answered that "spreading all kinds of threat narratives and engaging in confrontation and malicious competition only obstructs the process of global AI governance and serves neither side's interests." He added that because AI development concerns the common welfare of all humanity, all countries should jointly advance openness, inclusiveness, universal benefit, and good faith.
Placed side by side, the two statements look like they pull in different directions, but they're aimed at different targets. Chen's article is a document tallying threats coming in; Guo's response is pushing back against threat narratives coming from outside. In the same week, China both wrote up risk at maximum volume and warned against threat narratives — but the two statements do overlap in one place: seizing technological sovereignty and getting into rule-making first. METAL has reported on Xi Jinping's proposal for a BRICS AI open-source community at the BRICS summit; these two statements correspond to the inward-facing and outward-facing sides of that same proposal.
The timing is also worth reading closely. According to reports, President Xi Jinping is set to meet US President Donald Trump in Washington this month, with AI governance and safety reportedly on the agenda. In the US the same weekend, Anthropic and OpenAI leadership called for slowing development, and METAL has reported on the Trump camp's rejection of that call. Chen Yixin's article doesn't respond to that debate in a single line — there's no mention of existential risk, nor of the proposal to slow development.
That silence says something about the nature of this document. At the top of the AI risk list drawn up by China's top intelligence agency is not a model slipping out of human control, but people using models to shake public opinion and institutions. The only item that overlaps with the risk list circulating in the West the same week is cyberattacks. That means the two countries will sit down at the Washington table holding different risk lists — and the difference between those lists is the first thing that shows where any AI governance agreement is likely to get stuck.





Comments