Chen Yixin, China's minister of state security, has publicly identified two American artificial intelligence models as posing a threat to Chinese infrastructure. Writing in an official journal, Chen named Claude Mythos and GPT-5.5-Cyber as examples of AI systems that have substantially increased the efficiency of malware creation and vulnerability discovery. His article, published in China Cyberspace on 13 September, outlines six distinct AI-related security risks but provides no documented instances of attacks using these models against Chinese targets.
The piece appeared under Chen's byline in the publication of the Cyberspace Administration of China, identifying him by his roles as party secretary and minister of the Ministry of State Security. Taiwan's United Daily News first reported the specific model names from the Chinese-language text, with the coverage subsequently picked up by international outlets. The article's title translates to a call for building a comprehensive AI security barrier and promoting healthy AI development.
Six categories of risk
Chen's analysis identifies six separate threat vectors. These range from systemic effects on the political security environment to fundamental changes in military conflict. The enumeration begins with regime security concerns, where Chen describes how hostile actors exploit generative AI tools to produce political disinformation at scale, including synthetic media and what he terms intelligent online armies that conduct cognitive warfare.
- Systemic effect on the political security environment
- Disruptive upgrade of the cyber offence and defence picture
- Large-scale amplification of leak and espionage risk
- Technological imbalance caused by AI monopoly
- Structural shock to social governance
- Fundamental change in the form of military conflict
The cyber threat framing
The second risk category is where Chen introduces the two named models. He characterizes the cyber landscape as entering a new phase, which he describes through three concepts: industrialised vulnerabilities, fully automated attack and defence, and AI against AI. According to Chen's analysis, artificial intelligence has dramatically reduced both the technical barriers and financial costs required to execute cyberattacks.
Notably, the article contains no specific examples of attacks on Chinese systems, nor does it attribute any particular incident to either model. The two systems function in Chen's text as markers of emerging capability rather than as documented instruments of actual harm.
What the models actually do
Anthropic released Claude Mythos as its most advanced model to date, with the company stating it will share findings with defenders while restricting direct access to the model itself. OpenAI markets GPT-5.5-Cyber specifically as a security-focused tool. Both vendors present the capabilities Chen describes as defensive in nature.
Data on actual vulnerability discovery shows measurable increases in AI capability. Research from July indicated that AI systems are identifying roughly twice as many software vulnerabilities compared to previous periods. However, the gap between discovery and exploitation remains substantial, with almost none of these newly identified flaws being actively exploited in real-world attacks.
Other governments are treating these model families as subjects for technical evaluation rather than public denunciation. The European Commission announced last week that its cybersecurity agency is conducting tests on Claude Mythos 5 and GPT-6 Astra. Chen's article, by contrast, calls for a national prevention and control system under Beijing's authority.
A shift from private to public
This public statement represents an escalation in tone. Earlier reporting revealed that China has maintained a dual posture: publicly championing open AI development while privately expressing concerns about closed American models. Chen's article moves this anxiety into an official publication under a senior minister's name, with specific models identified by name.
The timing connects to broader tensions. Two days before Chen's article, Beijing's commerce ministry responded to remarks by Dario Amodei regarding export controls, characterizing his position as evidence of American technological dominance. The Global Times published commentary framing the exchange as part of a Cold War narrative. That dispute centered on semiconductors and containment; Chen's piece shifts focus to the AI models themselves and their capabilities.
The same weekend also saw Amodei, Sam Altman, and Elon Musk each endorse calls for slowing frontier AI development. Chen's article makes no reference to these figures. Instead, it advocates for controls that Beijing would design and implement independently.
Proposed solutions
Chen proposes remedies operating at both domestic and international levels. Within China, he calls for accelerated construction of a security risk prevention and control system alongside high-efficiency governance. He reaffirms the principle of party management of the internet and party management of data.
On the international stage, Chen advocates for a fair and open system of global AI governance. He urges powers to reject hegemonism, technical barriers, and exclusive blocs, arguing that AI development should be guided by the wellbeing of all humanity.
Xi Jinping employed similar language the same day at the BRICS summit in New Delhi, calling for a people-centred approach and consensus-based global governance. Chen's security-focused analysis provides the underlying rationale for that diplomatic positioning.
What remains unsubstantiated
Three central claims in Chen's article rest on assertion rather than documented evidence. First, he states that the two named models have raised malware and vulnerability capability specifically against China, yet provides no concrete example. Second, he does not quantify the scale of any resulting exposure or harm. Third, he frames the problem as foreign capability targeting Chinese systems while declining to address Chinese AI models in equivalent terms or to identify any Chinese system as a comparable source of risk.
Source: The Next Web



