AI researchers from the US and China used a Beijing Academy of Artificial Intelligence conference in Zhongguancun last week to argue that the two countries' frontier AI rivalry has become dangerous enough to require active cooperation on safety. The week-long event drew Whitfield Diffie, co-inventor of public-key cryptography, and Andrew Barto, who shared the Turing Award with Rich Sutton for reinforcement learning, alongside Chinese academics and industry researchers. The throughline across sessions: agentic models capable of writing and executing their own code are arriving faster than either government's safety apparatus.
The conference landed against a hardening US export-control posture. Washington has tightened restrictions on chips and chipmaking equipment headed to China for years, and most recently the US government ordered Anthropic to prevent foreign nationals from accessing its most powerful models, Mythos and Fable 5, on national security grounds. Anthropic responded by revoking access for everyone — a blunt compliance move that underscored how quickly frontier model access is being walled off by jurisdiction. One company of particular concern in that review was a South Korean telecom with alleged ties to China.
Stephen Casper, a computer scientist at MIT who spoke at the conference via video, told Wired afterward that the math on international cooperation has shifted. He pointed to research showing the benefits of cross-border collaboration on AI dangers outweigh the national security risks of working with a rival, and likened the moment to US–Soviet nuclear coordination during the Cold War — adversaries forced to share information on catastrophic risk while still racing each other on capability.
“AI is a global technology with global benefits, global harms, and a consistent tendency for new capabilities to eventually proliferate.”— Stephen Casper, Computer scientist at MIT
Key facts
- 01The Beijing Academy of Artificial Intelligence conference in Zhongguancun drew Whitfield Diffie and Turing Award winner Andrew Barto alongside Chinese AI researchers.
- 02The US government recently ordered Anthropic to block foreign nationals from accessing Mythos and Fable 5; Anthropic responded by revoking access for everyone.
- 03Z.ai's GLM 5.2 ships with frontier agentic and coding capabilities, narrowing the gap with closed US frontier models.
- 04360 Security Technologies said this week it built an AI model with hacking capabilities on par with Anthropic's Mythos.
- 05Chinese open-weight leaders now include Moonshot's Kimi, Alibaba's Qwen, and Z.ai's GLM; the US counter is Nvidia's Nemotron.
One day-long session at the conference walked through the cybersecurity surface that more capable models open up: new classes of vulnerabilities in AI-generated code, attack patterns enabled by agentic tool use, and automated social-engineering pipelines. These are not theoretical. Each is already showing up in red-team reports from both Chinese and US labs, and the techniques translate cleanly across language and jurisdiction.
Lin Yun, a professor at Shanghai Jiao Tong University who works on AI and computer security, told Wired he expects attackers to hold the advantage in the near term, with defenders catching up over time as new countermeasures — including AI-driven ones — mature. Yun said competition between governments complicates cooperation but should not preclude it.
The harder question is open weights. Chinese labs now lead the open-weight frontier with Moonshot's Kimi, Alibaba's Qwen, and Z.ai's GLM, all of which have found significant adoption among US developers. The US open-weight response has come primarily from Nvidia's Nemotron family. The latest from Z.ai, GLM 5.2, ships with frontier agentic and coding capabilities according to expert analysis cited at the conference — meaning the next generation of open-weight releases may match the proprietary Fable and Mythos tier.
That ceiling is where the cybersecurity argument bites hardest. This week, 360 Security Technologies, a Chinese cybersecurity firm, said it had built an AI model with hacking capabilities on par with Mythos. A widely available open-weight model with comparable offensive capability, stripped of guardrails by a downstream fine-tune, is a different category of risk from a rate-limited API. Yun said the industry will need new mechanisms to verify that open models are current, free of backdoors, and have cleared safety evaluations before release.
There are early signs the calculus is already changing inside China. A source at one of China's leading AI companies, who was not authorized to speak publicly, told Wired that security concerns are one reason some advanced Chinese models are no longer being released as open source. That mirrors the closed-weight default at OpenAI and Anthropic and suggests the open-weight gap between the US and China may narrow from both directions — Chinese labs pulling back on releases, US labs leaning further in via Nemotron and similar efforts.
Skeptics of formal US–China AI cooperation have a straightforward case: shared safety standards risk leaking capability information, and a regime that conditions market access on alignment with Beijing's preferences is a non-starter in Washington. Casper's counter, echoed by Yun, is that the cooperation does not have to look like a treaty. It can start with shared threat taxonomies, common evaluation suites for agentic risk, and coordinated disclosure of vulnerabilities discovered in widely deployed open-weight models. None of that requires either side to hand over training data or weights.
The strategic read for the AI market is that the export-control era and the safety-cooperation era are about to run in parallel rather than in sequence. Frontier labs in both countries will keep racing on capability while their researchers quietly compare notes on what goes wrong. For Anthropic, OpenAI, and the Chinese open-weight leaders, the practical consequence is that compliance, jurisdiction filtering, and pre-release red-teaming are now product features — not back-office work. The labs that ship a credible answer to 'who can use this and how do we know it's safe' will set the terms of the next round of access fights.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




