我们发布了一篇新论文,阐述我们对中美人工智能竞争的看法。
美国及其盟友必须保持对中国共产党等威权政府的领先优势。人工智能很快将变得足够强大,可用于以前所未有的规模压制公民,甚至改变国家间的力量平衡。由于人工智能每天都在加速发展,我们设定竞争条件、并决定这些威胁是否以及如何成为现实的时间窗口十分有限。正是基于这一考量,我们概述了确保美国保持领先所需的条件。
发展人工智能最重要的要素是获取用于训练模型的计算机芯片(即“算力”)。由于最先进的芯片由美国公司开发,美国政府目前通过对其实施严格的出口管制来限制中国的供应。近期历史表明,这些管制措施取得了巨大成功。事实上,中国的人工智能实验室之所以能构建出智能水平接近美国的模型,靠的是他们的人才、他们善于利用出口管制漏洞的能力,以及他们大规模的知识蒸馏攻击——这种攻击非法窃取了美国公司的创新成果。
在这篇文章中,我们提出了两个关于2028年世界可能面貌的情景,届时我们预计变革性的人工智能系统已经到来。
在第一种情景中,美国成功捍卫了其算力优势。政策制定者已采取行动进一步收紧出口管制,打击中国的知识蒸馏攻击,并进一步加速民主国家采用人工智能。在这个世界里,民主国家制定了人工智能的规则和规范。也正是在这种情景下,我们最有可能在安全问题上与中国成功接触——只要有可能,我们对此持支持态度。
在第二种情景中,美国选择了不作为。政策制定者未能堵住中国共产党获取算力的漏洞,中国的人工智能公司迅速抓住机会——迎头赶上前沿水平,甚至超越美国。在这个世界里,人工智能的规范和规则由威权政权制定,最先进的模型则被用于大规模自动化镇压。这种威权主义的胜利是建立在美国算力基础之上的,这一点并不会带来任何安慰。
美国及其盟友在人工智能竞争中处于非常有利的地位。实现人工智能主导地位的工具,是由民主国家中极具创新活力的企业生态系统所打造的。我们过去的成功意味着,当前的任务主要是避免挥霍我们的优势:即要下定决心,不让中国共产党更容易地追赶上来。
2028年中美两种情景展望
摘要
人工智能的开发与部署必须由民主国家而非威权政权来主导。这些国家及其政治体制能够塑造管理这些系统的规则与规范。
民主国家目前在算力方面拥有显著领先优势,而算力是开发前沿人工智能模型最重要的要素。这一领先优势得益于美国及其盟友的创新,以及美国两党共同支持的出口管制政策对这些创新的保护。但在模型智能方面,受中国共产党管辖和控制的中华人民共和国境内的人工智能实验室,差距并不遥远。我们聚焦于中国共产党,是因为该政权最有可能利用前沿人工智能来巩固威权统治;我们无意损害中国人民的利益或创造力。事实上,中国共产党已经在利用人工智能进行言论审查、压制异见人士、入侵世界各地的政府和企业,并加强中国人民解放军的力量。
中国的人工智能实验室拥有世界一流的人才。限制它们保持追赶能力的是算力瓶颈。中国的实验室通过利用美国出口管制政策的漏洞,以及开展大规模的知识蒸馏攻击来获取美国模型的创新成果以模仿其能力,从而始终紧追不舍。
随着算力供应迅速扩张,且人工智能越来越多地被用于增强新一代 AI 模型的训练,我们正进入 AI 能力大幅加速的时期。“数据中心里的天才之国”——即我们与变革性 AI 相关联的智能水平——可能已近在咫尺。这种加速使得政策行动变得更加紧迫。迄今为止,由于允许出口管制规避和蒸馏攻击,我们让中共的 AI 努力紧紧跟上了前沿曲线。但如果美国及其盟友现在采取行动解决这两个问题,或许有可能锁定 12 到 24 个月的前沿能力领先优势。到 2028 年,如此巨大的领先优势将极为有利。这样的领先优势也将有助于我们支持的努力,即与中国 AI 专家就 AI 安全与治理进行接触。但锁定这一领先优势的机会窗口未必会长期保持开放。
在此,我们提出 2028 年中美 AI 竞争态势的两种可能情景。第一种情景是,民主国家在模型智能、采用率和全球分发方面建立了压倒性领先优势。如果政策制定者现在采取行动,收紧对中国实验室先进算力的管控,破坏他们蒸馏美国最佳 AI 模型的努力,并加速民主国家对 AI 的采用,这一情景是可以实现的。
第二种情景是,中共在近前沿领域具备竞争力。如果政策制定者不巩固我们现有的领先优势,或者放松对中国企业获取算力的限制,就会出现这种情况。
国会和特朗普政府中的许多人已经支持出口管制、遏制蒸馏攻击以及推广美国 AI。在推进这些政策的过程中,我们希望民主国家能够到 2028 年确保压倒性领先优势,并避免两年后与中共陷入一场破坏稳定的并驾齐驱式竞赛。
保持领先的紧迫性
我们预计前沿人工智能将在未来几年带来变革性的经济和社会影响,正如《有爱机器》和《技术的青春期》中所描述的那样。我们的使命是确保人类能够安全且有益地完成向变革性人工智能的过渡。我们相信,成功的过渡将催生医学、发明创造和经济增长领域的惊人突破。
威权式人工智能的威胁
这一过渡能否顺利进行,部分取决于最强大的系统首先在哪里被构建出来。创造最先进人工智能的政治体制,将塑造该技术开发和部署的规则与规范。反过来,这些规则与规范将有助于决定该技术是否安全、它保护谁的安全,以及它最终服务于谁的利益。我们认为,这一责任应落在民选政府手中,而非威权政权手中。
如果前沿领域由那些将人工智能视为镇压工具、获取对民主国家军事优势以及国内控制手段的政权所主导,那么对于这些政权自身的公民或其他任何人而言,这一过渡都不太可能顺利进行。
从历史上看,威权统治的覆盖范围受限于其依赖人类执行者来进行监视和镇压。强大的人工智能系统可能会消除这种依赖性,从而在更大规模上实现自动化的镇压。正因如此,中国共产党在人工智能领域领先的前景,是成功过渡所面临的最大威胁之一。
中国共产党在中国经济、军事以及地球上最大的威权国家结构掌舵中拥有巨大的权力和影响力。它也是除美国之外唯一拥有资源充足、人才济济的人工智能实验室来追逐前沿领域的国家。此外,中国共产党有强烈的动机将中国确立为领先的人工智能强国。北京已向中国的人工智能和半导体领域投入了数百亿美元。
中国共产党已在利用人工智能系统进行言论审查、对少数民族实施严苛政策,并入侵大型企业和政府机构。中共借助人工智能实现技术威权主义的愿景在新疆已有大量实证:国家安全部门系统性地部署了人脸识别技术、生物特征数据收集和通信监控,其压制规模远超人力所能及。前沿人工智能系统将使这些能力更易于维护、覆盖更广、手段更趋精密。中共向其他国家输出这些技术,使当地威权统治者得以更有效地压制异见,从而巩固威权统治。若由中共主导人工智能前沿领域,全球范围内的压制行为将显著加剧。
人工智能是一项军民两用技术
前沿人工智能将重塑未来军事格局。中共领导层已基于这一前提展开行动,正为人工智能赋能的战场建设军队。解放军战略家将军事力量的"智能化"视为追赶并最终超越美军的手段。解放军已在采购中国商用人工智能系统用于军事用途,包括部署深度求索(DeepSeek)模型来协调无人集群作战并增强网络攻击能力。这些能力的扩散速度不会缓慢。例如,当新模型在自主目标锁定、漏洞发现或集群协调方面获得新能力时,控制该模型的一方可在数周而非数年内将其投入实战。
风险叠加效应在于,前沿人工智能将成为其他关键技术的加速器。先进人工智能模型能够压缩半导体、生物技术和先进材料领域的研发周期。在前沿人工智能领域的领先优势,将使国家安全技术全栈的领先差距持续扩大。
如果某家中国人工智能实验室在美国之前开发出与 Claude Mythos Preview 水平相当的模型,中国共产党将率先获得一个能够自主发现并串联软件漏洞的系统,并可能利用它进一步渗透美国关键基础设施。未来的模型能力将呈指数级增长,因此对美国及其他民主国家的国家安全利益将产生相应更大的影响。
并驾齐驱的竞争可能削弱负责任发展人工智能的动力
中美人工智能实验室之间的并驾齐驱式竞争,可能使行业及政府主导的安全与治理工作变得更加困难,且更难以落实。如果中国实验室的模型与美国模型水平接近或持平,中美两国的私营人工智能公司可能会感受到更大压力,从而在未采取审慎的部署前安全措施的情况下,更快地发布新模型和产品。各国政府也可能因担心落后,而不愿出台鼓励负责任地开发与部署人工智能的政策。
尽管中国人工智能实验室和政策界中关注人工智能安全风险的研究人员越来越多,但这一趋势尚未转化为与美国实验室相当的安全实践。截至去年,中国13家顶尖人工智能实验室中,仅有3家发布了安全评估结果,且没有任何一家披露针对化学、生物、放射性和核(CBRN)风险的评估。人工智能标准与创新中心发现,在一种常见的越狱技术下,深度求索的R1-0528模型对94%的明显恶意请求予以遵从,而美国参考模型的这一比例为8%。这一模式在近期发布的模型中仍在延续。例如,今年4月发布的一项对月之暗面Kimi K2.5的独立评估发现,该模型未能拒绝CBRN相关请求的比例远高于美国前沿模型。更严重的问题是,中国实验室经常以开放权重形式发布具有双重用途能力的模型。一旦模型开放权重,现有的安全防护措施就可能被移除,使得任何国家或非国家行为者都能将其用于恶意目的,包括这些安全措施本意要防范的网络和CBRN滥用行为。
我们的政策目标:为民主国家创造并保持领先优势
我们支持美国及其他国家制定政策,在智能水平、国内应用和全球部署方面建立并维持对中共的安全、短期领先优势。这一领先优势对于避免威权主义在人工智能领域的领导地位、保护美国及其他民主国家的国家安全利益至关重要。这是确保民主国家能够与威权国家达成有利条件的基本前提。
深度尊重中国人民和中国人工智能社区所取得的成就。我们期望中国与世界保持和平关系。我们的担忧具体指向任何拥有前沿人工智能系统的强大威权政治体制给人类带来的风险。
人工智能安全领域的合作机会
Anthropic 在可能的情况下,支持与中国 AI 专家开展国际 AI 安全对话。无论 AI 在何处开发与部署,全世界在安全 AI 方面都拥有切身利益。前沿 AI 系统可能带来一系列风险,这需要中美两国共同参与应对。识别共同挑战、提出想法以防范并缓解这些风险的努力,符合我们的共同利益。
当美国保持较大的能力优势时,富有成效的接触前景最佳。负责任地建立并保持在最先进 AI 开发与部署方面的领先地位,能够增强我们影响中国及其他地区 AI 安全的能力。
Mythos Preview 的警钟
Mythos Preview 是我们在 4 月作为 Project Glasswing 的一部分向特定合作伙伴发布的模型,它的出现标志着一个加速期的到来,使得政策行动变得更加紧迫。借助该模型,Firefox 上个月修复的安全漏洞数量超过了 2025 年全年的总和,并且几乎是其 2025 年月均安全漏洞修复量的 20 倍。针对该模型,一位中国网络安全分析师写道,中国“还在磨刀,而对方突然架起了全自动加特林机枪。”
前沿 AI 能力将迅速接近“数据中心里的天才国度”所描绘的变革性 AI。这种加速将由规模定律的逻辑驱动——即模型性能随算力和数据输入的增加而可预测地提升——同时 AI 本身也越来越多地被用于加速新模型的开发。
我们极有可能在回顾 2026 年时,将其视为美国人工智能实现突破性发展的机遇之年。美国实验室拥有最先进的 AI 模型,在推动前沿发展所需的高端 AI 芯片数量和质量上均占据巨大领先优势,并且凭借收入和融资拥有庞大的资本优势,足以支撑实现这一目标所需的投资。中国实验室确实拥有真正的优势:世界一流的创新人才、充足且廉价的能源,以及海量数据。这些都是开发前沿智能所必需的条件。但他们国内的计算能力根本不足以参与竞争,也缺乏相应的收入和资本来提供资金支持。
竞争的四个战线
美国和中国正围绕人工智能等前沿技术的战略优势展开竞争。北京和华盛顿的声明都反映了这一观点。将这场竞争称为“竞赛”可能会造成一种错误印象,即存在一条终点线,一方冲线后就能最终锁定胜局。相反,这场竞争将是一场持续的、争夺优势的较量,在这场较量中,要么是民主政体,要么是威权政体,能够成功地将自身定位为塑造由人工智能驱动的未来的价值观、规则和规范的主导者。
这场竞争在四个战线上展开:
- 智能:哪些国家能开发出能力最强大的 AI 模型。
- 国内应用:哪些国家能将 AI 最有效地整合到商业和公共部门中。
- 全球部署:哪些国家能部署支撑全球经济运行的全球 AI 基础设施。
- 韧性:哪些国家能在经济转型过程中维持政治稳定。
智能是四个战线中最重要的。我们预计,前沿模型的能力将给地缘政治竞争带来最重大的变化。模型能力也是市场应用和全球部署的主要驱动力。
但仅有智能是不够的。如果中国共产党能比民主国家更快、更有效地将接近前沿的AI系统融入中国经济和国家安全体系,并推动全球采用受补贴的低成本AI,那么它就能在克服智能差距的基础上获得优势。北京提出的“AI+”倡议及其对“具身智能”的重视,因此将推动前沿智能融入经济和国家机器的政策置于高度优先地位。特朗普政府的“AI行动计划”及其对“促进美国AI技术栈出口”的关注,也体现了推动全球采用所带来的战略优势。
尽管本文不会重点讨论,但我们认为韧性将成为AI竞争的一个重要战场。在这一时期保持稳定、凝聚力和良好的政策制定能力,将是一项关键优势,而无法做到这一点的一方则会暴露弱点。
竞争态势
算力——即训练和部署前沿AI所需的先进半导体——是上述每个竞争战场的关键投入要素。全球AI领导地位的竞争在很大程度上就是算力的竞争。十多年来,模型能力随算力增长而扩展,AI能力的大部分性能提升历来都来自单纯使用更多算力。此外,算力不仅用于训练新模型,还需要服务于客户使用AI(即“推理”能力)。算力对于训练最智能的模型以及将其部署到商业和国家安全领域都至关重要。获取顶尖人才、海量数据和关键算法突破对智能竞争都很重要——但如果算力不足,这些投入要素都将失去意义。
民主国家如今正在赢得算力领导地位的竞争。尽管有人担忧出口管制可能加速中国共产党自身发展先进芯片供应链的努力,但几乎没有证据表明中国的自主化努力将挑战美国及其盟友在先进计算技术领域的领导地位。北京已向中国芯片行业投入了巨额资源,早在出口管制实施之前就推出了诸如“中国制造2025”战略和国家集成电路产业投资基金等重大产业政策举措。尽管有这些国家支持的投资,但中国的人工智能实验室和芯片制造商仍受到美国及其盟友对先进芯片及芯片制造设备出口管制的阻碍。
因此,算力差距似乎正在扩大。一项对华为和英伟达路线图的分析发现,到2026年,华为的总处理性能将仅达到英伟达总计算能力的4%,到2027年则为2%。此外,英伟达仅代表美国及其盟友算力生态系统的一部分,谷歌和亚马逊正在分别加大其自研芯片(TPU和Trainium)的生产,以满足美国前沿人工智能实验室及其客户的需求。
进一步加剧其算力短缺的是,中国在半导体供应链中许多技术最复杂的环节进展甚微。由于无法获得极紫外(EUV)光刻技术,并且如果政策制定者能够堵住深紫外(DUV)光刻技术及其服务和维护方面的漏洞,中国的芯片制造商将仍然无法以足够的数量或质量制造芯片来挑战美国的算力领导地位。中国无法大规模生产高带宽内存,进一步加剧了这一差距。一项研究估计,如果美国加强对中国共产党获取美国算力能力的限制,美国将拥有大约是中国人工智能行业11倍的算力。
民主国家如何建立起领先地位:商业创新与明智的公共政策
算力领先主要有两大原因。首先,得益于英伟达、AMD、美光、台积电、三星、ASML 等公司,以及日本、韩国、台湾、荷兰、美国等民主政体所共同实现的非凡创新,它们携手打造了全球最先进半导体中的独特技术。没有这些产品背后所凝聚的工程壮举和数十年的持续研发投入,当今的 AI 成就将无从谈起。
第二个原因是过去三届总统任期内所采取的具有前瞻性的果断政策行动。两党一致的政策行动,通过限制中国共产党管辖下的中国企业获取美国 AI 技术栈,保护了美国及其盟友的创新引擎。例如,我们的 CEO 曾公开评论出口管制的重要性。过去几年间,这些管制措施遏制了最尖端 AI 芯片和半导体制造设备对华销售,即便北京方面向该领域投入了巨额国家资源,也限制了中国前沿 AI 的发展。如果不采取行动限制中国获取美国算力,中国共产党本已具备开发与美国相当或更优 AI 所需的一切要素。
一些观察人士担心,限制算力获取会迫使中国 AI 实验室在其他方面进行创新,从而缩小美国的领先优势。尽管中国实验室确实在创新,但这些创新迄今仍不足以弥补其算力短板。算法改进既是算力的函数,也是算力的倍增器,而非其替代品;发现这些进步本身就是一个算力密集型过程:更多的算力能让实验室运行更多实验,从而发现更多算法改进。随着前沿模型越来越多地自主开展 AI 研发,这一循环将进一步收紧,前沿模型将帮助构建其自身的后继者。简而言之,算力优势会转化为算法优势,并由此形成在 AI 领域持久的领先地位。
据估计,目前美国前沿系统在智能水平上至少领先中国顶尖 AI 实验室数月,尽管这些估算存在不确定性。尽管中国开源权重模型备受关注,但其企业采用率仍落后于闭源前沿模型,且公开投资者中已浮现盈利担忧。此外,中国 AI 实验室似乎正在远离开源,如今选择将其最优秀的模型保持闭源。
中国 AI 领军企业自身也证实了出口管制的影响,以及美国芯片的关键必要性。中国顶尖 AI 实验室的高管们曾表达担忧,认为中国可能因算力限制而进一步落后。中国头部实验室将算力稀缺视为加速模型能力的主要制约因素,并指出出口管制是造成这一限制的原因。一家中国超大规模云服务商的高管称,向中国供应受出口管制的美国芯片的影响“巨大,非常巨大”,并补充说任何供应缺口都会严重冲击中国的 AI 发展,同时驳斥了进口美国芯片会减缓其自给自足努力的担忧。在中国,声称出口管制徒劳无功的主要声音似乎来自中共官员和官方媒体,其目的很可能是影响美国政策制定者。
中共如何保持竞争力:政策漏洞依然存在
尽管出口管制在提供当前优势方面是有效的,但力度还不够。尽管中共无法在国内制造足够的先进芯片,也无法合法地从国外购买,但中国的 AI 实验室通过两种变通方法在智能水平上保持了接近:一是非法和规避性的算力获取,通过将 AI 芯片直接走私到中国以及访问海外数据中心;二是非法模型获取,通过这种方式对美国前沿模型进行知识蒸馏攻击,并利用这些模型作为工具来加速自身的 AI 研发。
中国规避美国出口管制已是公开的秘密。例如,联邦检察官指控超微电脑(Supermicro)的一位联合创始人及另外两人将价值25亿美元、内含先进美国芯片的服务器非法转运至中国。据美国政府及媒体报道,深度求索(DeepSeek)利用被禁止对华销售的先进美国芯片训练了其最新模型。《金融时报》报道称,阿里巴巴和字节跳动目前正在东南亚的数据中心使用受出口管制的美国芯片训练其旗舰模型,而现有管制措施对此鞭长莫及,因为美国出口法涵盖的是芯片销售行为,而非远程访问行为。¹ 美国的出口管制体系正艰难应对,难以阻止中国人工智能实验室获取美国原产的先进算力。
蒸馏攻击是中华人民共和国实验室追赶美国同行、削弱出口管制影响的另一项非法手段。中国实验室通过创建数千个虚假账户来绕过美国人工智能模型的访问控制,系统性地窃取其输出结果,以复制前沿能力。这种做法使中国实验室得以搭便车,坐享美国数十年基础研究、数十亿美元投资以及数千名全球顶尖工程师打造美国前沿模型所付出的心血。其结果是,以极低成本获得近乎前沿的能力,而成本却由美国承担。这是针对一项关乎美国长期国家安全利益的关键技术所进行的系统性工业间谍活动。OpenAI、谷歌、Anthropic 以及前沿模型论坛(Frontier Model Forum)均公开谴责了蒸馏攻击行为。
中国的人工智能专家公开承认蒸馏攻击的规模及其对中国人工智能发展的重要性。近期,一家国有媒体发表文章,将对美国模型的蒸馏攻击描述为中国人工智能实验室赖以生存的“后门”,是其商业模式的核心组成部分。一位前字节跳动研究员表示,中华人民共和国的人工智能实验室将蒸馏作为训练模型的捷径,从而避免投资建设自身的数据管线。
美国政策制定者已迅速采取行动应对这一威胁。白宫科技政策办公室发布了一份关于知识蒸馏攻击的备忘录。白宫、战争部的高级官员以及国会议员也纷纷关注此问题。近期,众议院外交事务委员会针对知识蒸馏攻击提出的立法已全票通过委员会审议。
如果美国及盟友民主国家的政策制定者能够采取行动,切断支撑中国AI模型的两条渠道——非法及规避性算力获取与非法模型获取——那么我们便可能迎来一个千载难逢的机会,来巩固我们的领先地位。
2028年的两种情景
下文描述了两种假设的未来情景,以帮助说明今天采取的政策行动将如何塑造2028年的局面。
情景一:美国及其盟友拥有压倒性且不断扩大的领先优势
美国的算力优势依然强劲。尽管中国半导体产业获得了更多国家支持,但其芯片制造商仍落后于美国及盟友同行数年,部分原因在于无法获取先进的SME工具、服务与维护。随着美国及盟友芯片产能的持续上线,以及先进芯片制造商在更高效、更高性能芯片上的不断创新,中美之间的算力差距正在拉大。与此同时,美国政策制定者已采取行动填补经济安全工具箱中的漏洞,而向中国走私芯片以及获取境外数据中心受出口管制芯片的企图,也因资金充足的执法行动而日益受挫。
因此,美国 AI 模型在智能水平上领先 12 到 24 个月,且优势正在扩大。少数 AI 实验室在技术前沿处于领先地位,拥有最智能、最强大、性能最优的模型。这些实验室全部位于美国。“数据中心里的天才之国”已成为网络安全、金融、医疗保健和生命科学等关键行业的现实。当美国前沿实验室在 2028 年发布能力实现阶跃式进步的新模型时(类似于 2026 年 4 月 Mythos Preview 的相对影响),中国要到 2029 年或 2030 年才能获得类似的 AI 能力。这为民主国家制定前沿 AI 系统的规则和规范赢得了宝贵的喘息空间。
美国 AI 是全球经济的支柱,驱动着新的经济和科学活力。特朗普政府推动国内 AI 应用并促进美国 AI 出口的努力正在取得成功,由此带来的国内外强大 AI 应用成果正推动前所未有的经济增长和技术进步。全球对美国 AI 的采用率急剧上升。民主国家在能力和算力上的领先优势意味着,中国 AI 公司无法在少数威权国家之外争夺全球市场份额。全球顶尖的前沿 AI 系统由民主价值观塑造,这使得威权国家更难利用 AI 系统侵犯权利和公民自由。
网络及其他国家安全优势不断扩大。公共和私营部门的网络运营者及安全专业人员利用先进的 AI 系统,减少美国及其他民主国家的攻击面,削弱中共获取并维持其在我们系统中网络立足点的能力,从而使我们的国家安全资产、知识产权和通信网络更加安全。美国压倒性的 AI 优势是对侵略行为的强大威慑。
一种自我强化的循环加剧了民主国家的领导地位。显著的AI优势使美国及其盟友成为更具吸引力的合作伙伴。这种对齐既扩大了美国AI的市场,也壮大了制定全球AI规范的联盟,进而促进开发与部署安全、可靠且保护公民自由的AI系统。全球顶尖的技术与科学人才持续涌向前沿技术诞生的地方。美国获得了显著的影响力,用以在AI治理、战略竞争和贸易等关键议题上激励北京方面的合作。这个循环不断自我强化:领先地位巩固联盟,联盟又巩固领先地位,在向变革性AI转型的过程中,以民主国家为主导的国际秩序得以稳固。
场景二:中共控制的AI生态系统势均力敌
在中国开发和部署的AI在模型智能方面接近前沿水平。尽管半导体生产能力薄弱,但中国AI实验室训练的模型仅落后美国模型数月。持续的蒸馏攻击、海外算力获取、薄弱的中小企业出口执法以及美国半导体出口管制的放松,都助长了中共的努力。持续获取美国前沿AI用于研发,也使中国AI实验室得以缩小差距,并接近与美国同行持平的水平。
快速的商业与政府采用。北京通过“AI+”政策推动了举国体制下的国内应用。尽管中国的AI模型能力略逊于美国模型,但中共加速应用的努力已见成效。因此,中国能够更有利地在经济、军事和技术领域部署接近前沿的AI能力,从而将力量平衡向有利于中国的方向倾斜。
中共运用人工智能的网络部队是一个严重威胁。中共将人工智能赋能的网络能力整合进本已先进的网络部队中,使解放军始终作为具有威胁性的网络竞争者存在。解放军网络行动者已获得进入美国及全球大多数国家关键与军民两用基础设施的额外权限,从而能够破坏关键的国家安全与社会功能。随着人工智能被更深入地整合进我们最关键的系统中,尽管民主国家率先开发了这项技术,但在人工智能领域并不享有相对于中国的安全优势。
北京在成本与本地部署灵活性方面正在赢得全球采用优势。华为和阿里巴巴的数据中心遍布全球,尤其在(但不限于)全球南方成本较低的市场。这些数据中心基于较老旧的芯片进行扩展,中国之所以能够出口这些芯片,是因为它能够通过以下方式服务其国内市场:使用通过出口许可证购买的美国芯片、走私进入中国的芯片,或远程访问海外数据中心中的芯片。这些数据中心托管着中国实验室生产的二线但更便宜且仍然有效的模型。类似于华为“价格低廉、足够好用”的策略,中国接近前沿的模型和硬件支撑着全球经济中一个不容忽视且快速增长的部分。这种基础设施优势使中共领导层对这些市场拥有显著影响力。
确保民主国家保持领先
为确保我们进入第一种情景,我们支持以下政策行动领域。
- 堵住漏洞:走私芯片、外国数据中心访问以及中小企业。目前,中国实验室通过走私和外国数据中心获得受出口管制的美国芯片,而中小企业管控方面的漏洞加速了其自给自足的努力。收紧管控并加大执法预算有助于堵住这些支撑中共人工智能生态系统的漏洞。这将降低中国的算力上限,并相应减缓其人工智能进展,从而维持并扩大民主国家的人工智能领先优势。请注意,更低的算力上限还可能实质性地削弱知识蒸馏攻击,因为中国的人工智能实验室仍然需要最低限度的算力才能有效地进行非法蒸馏。
- 捍卫我们的创新成果:限制模型访问并遏制蒸馏攻击。国会和行政部门的政策制定者可以继续支持相关政策行动,以惩罚并遏制来自中国实验室的蒸馏攻击,同时采取措施帮助美国实验室提升自身检测和防范蒸馏攻击的能力。这些措施可包括通过立法明确蒸馏攻击为非法行为,以及推动美国同行实验室之间以及与美国政府之间的威胁情报和技术共享。遏制此类行为,能够在未来数月乃至数年内实质性地延续民主阵营的领先优势。
- 力推美国人工智能出口。随着全球公共和商业领域越来越多地采用人工智能,特朗普政府应继续努力,推动由民主原则塑造和开发的、值得信赖的AI硬件与模型在全球范围内的采用。现在锁定值得信赖的美国基础设施,将阻止中国共产党的人工智能生态系统获得未来在成本和采用率方面进行竞争所需的全球立足点。
结论
美国及其盟友不仅开发出了世界上最强大的前沿AI模型,也拥有了世界上最先进的AI生产要素。这带来了巨大的优势。如果我们能够捍卫对这种技术的优越访问权,这一优势便可延续。但如果将其直接拱手让给竞争对手,优势便会丧失。政策制定者今年做出的决策,将决定变革性人工智能的未来。我们支持那些致力于确保美国及盟友民主国家在2028年取得胜利的人们。
脚注
- 2026年1月,众议院以369票对22票的两党投票结果通过了一项法案,旨在填补这一漏洞;该法案尚未在参议院获得通过。
为生物学领域的智能体铺平道路
让Claude成为化学家
社会科学领域的编码智能体
一项针对1260名社会科学家关于人工智能与编码智能体使用情况的调查结果
We’re releasing a new paper that explains our views on the competition on AI between the US and China.
It’s essential that the US and its allies stay ahead of authoritarian governments like the Chinese Communist Party, or CCP. AI will soon become powerful enough to be used to repress citizens at unprecedented scale, and even to alter the balance of power among nations. And since AI is advancing more quickly by the day, we have only a limited period of time to set the conditions of the competition—and determine whether and how those threats materialize. It’s with this in mind that we outline what’s required to ensure America stays ahead.
The most important ingredient for developing AI is access to the computer chips on which the models are trained (or “compute”). Since the most capable chips are developed by American companies, the US government currently limits China’s supply by enforcing tight export controls on them. Recent history suggests these controls have been incredibly successful. In fact, AI labs in China have only built models close in intelligence to America’s because of their talent, their knack for exploiting loopholes around these export controls, and their large-scale distillation attacks that illicitly extract the innovations of American companies.
In this post, we present two scenarios for what the world might look like in 2028, when we expect transformative AI systems to have arrived.
In the first scenario, America has successfully defended its compute advantage. Policymakers have acted to tighten export controls further, disrupt China’s distillation attacks, and further accelerate democracies’ adoption of AI. In this world, democracies set the rules and norms around AI. It’s also in this scenario that we’re most likely to successfully engage with China on safety, which we’re supportive of to the extent this is possible.
In the second scenario, America has chosen not to act. Policymakers have not tightened loopholes on the CCP’s access to compute, and AI firms in China have quickly taken advantage—catching up to the frontier and even overtaking America. In this world, AI norms and rules are shaped by authoritarian regimes, and the best models enable automated repression at scale. It will be no solace that this authoritarian triumph has happened on the back of American compute.
America and its allies approach AI competition from a position of great strength. The tools for AI dominance have been built by an exceptionally innovative ecosystem of companies in democratic nations. Our past success means that our present task is largely to avoid squandering our advantage: to decide not to make it easier for the CCP to catch up.
Two scenarios for the US and China in 2028
Summary
Democracies, not authoritarian regimes, must lead in AI development and deployment. These countries and political systems can shape the rules and norms that govern these systems.
Democracies currently hold a substantial lead in compute, the most important ingredient for developing frontier AI models. That lead exists thanks to American and allied innovation, and to bipartisan US export controls that defend those innovations. But on model intelligence, AI labs in the People’s Republic of China (PRC), under the jurisdiction and control of the Chinese Communist Party (CCP), are not far behind. We focus on the CCP as it is the regime that is most able to use frontier AI to cement authoritarianism; we do not seek to undermine the interests or ingenuity of the Chinese people. Already, the CCP is using AI to censor speech, repress dissidents, hack governments and corporations across the world, and strengthen the People’s Liberation Army (PLA).
AI labs in China have world-class talent. It is compute constraints that limit their ability to keep up. Labs in China have remained close by exploiting loopholes in US export control policies, and by carrying out large-scale distillation attacks that harvest the innovations of US models in order to mimic their capabilities.
With the supply of compute expanding rapidly, and with AI being used increasingly to augment the training of new AI models, we’re entering a period of great acceleration in AI capabilities. The “country of geniuses in a data center”—the level of intelligence we associate with transformative AI—may be close at hand. This acceleration makes policy action more urgent. To date, by allowing export control evasions and distillation attacks, we have let the CCP’s AI efforts trail closely up the frontier curve. But if the US and its allies act now to address both issues, it may be possible to lock in a 12-24 month lead in frontier capabilities. A lead that large by 2028 would be enormously advantageous. Such a lead would also augment efforts to engage with AI experts in China on AI safety and governance, which we support. But the window of opportunity to lock in that lead will not necessarily remain open for long.
Here, we present two potential scenarios for the state of US-China AI competition in 2028. The first scenario is one in which democracies have established a commanding lead in model intelligence, adoption, and global distribution. This scenario can be achieved if policymakers act now to tighten controls on advanced compute to PRC labs, disrupt their efforts to distill America’s best AI models, and accelerate democracies’ adoption of AI.
The second scenario is one in which the CCP is competitive at the near-frontier. This scenario happens if policymakers don’t build on our existing lead, or if they loosen restrictions on access to compute for PRC firms.
Many in Congress and the Trump administration have championed export controls, curbing distillation attacks, and exporting American AI. In advancing these policies, we are hopeful that democracies can secure a commanding lead by 2028, and avoid a destabilizing neck-and-neck race with the CCP two years from now.
The imperatives of staying ahead
We expect frontier AI to have transformational economic and societal impacts in the coming years, as described in Machines of Loving Grace and The Adolescence of Technology. Our mission is to ensure that humanity navigates the transition to transformative AI safely and beneficially. We believe that a successful transition can lead to astonishing breakthroughs in medicine, invention, and economic growth.
The threat of authoritarian AI
Whether that transition goes well depends in part on where the most capable systems are built first. The political systems in which the most advanced AI is created will shape the rules and norms for how the technology is developed and deployed. In turn, those rules and norms will help determine whether the technology is safe, whose security it protects, and whose interests it ultimately serves. We believe that responsibility should rest with democratically elected governments, not authoritarian regimes.
If the frontier is set by regimes that treat AI as an instrument of repression, military advantage over democracies, and domestic control, the transition is less likely to go well, for those regimes’ own citizens or anyone else.
Historically, the reach of authoritarian rule has been limited by its dependence on human enforcers to carry out surveillance and repression. Powerful AI systems may remove that dependency, enabling automated repression on a far greater scale. For that reason, the prospect of the CCP leading in AI is among the greatest threats to a successful transition.
The CCP holds enormous power and influence at the helm of China’s economy, military, and the largest authoritarian state structure on Earth. It is also the only country besides the US with well-resourced, highly talented AI labs chasing the frontier. Furthermore, the CCP is highly motivated to establish China as the leading AI power. Beijing has poured tens of billions of dollars into China’s AI and semiconductor sectors.
Already, the CCP uses AI systems to censor speech, enforce draconian policies on ethnic minorities, and hack major corporations and government agencies. The CCP’s vision of AI-enabled techno-authoritarianism has been extensively documented in Xinjiang, where state security agencies have systematically deployed facial recognition technology, biometric data collection, and communications surveillance, enabling repression at a scale that humans alone could not achieve. Frontier AI systems will make those capabilities cheaper to maintain, far more pervasive, and more sophisticated. The CCP’s export of these technologies has enabled autocrats in other countries to more effectively stifle dissent, entrenching authoritarianism. A CCP-led AI frontier could dramatically strengthen repression around the world.
AI is a dual-use technology
Frontier AI will shape the future military balance. CCP leadership already operates on that premise, and is building its military for an AI-enabled battlefield. PLA strategists view the “intelligentization” of their military forces as the means with which to catch up and eventually surpass the US military. The PLA is already procuring commercially developed Chinese AI systems for military use, including DeepSeek models deployed to coordinate swarms of unmanned vehicles and enable cyber offense capabilities. These capabilities will not diffuse slowly. When a new model reaches a new capability in autonomous targeting, vulnerability discovery, or swarm coordination, for example, the regime that controls it can put it onto the field in weeks, not years.
The risk compounds because frontier AI will be an accelerant for other critical technologies. Advanced AI models will be able to compress research and development (R&D) cycles in semiconductors, biotech, and advanced materials. A lead in frontier AI will enable a widening lead across the full national security technology stack.
If a PRC AI lab had developed a model at the level of Claude Mythos Preview before an American one, the CCP would have had first access to a system that can autonomously discover and chain software vulnerabilities, which it could have used to further penetrate critical American infrastructure. Future models will be exponentially more capable, and therefore have commensurately greater implications for the national security interests of the US and other democracies.
Neck-and-neck competition risks disincentivizing responsible AI
A neck-and-neck race between American and Chinese AI labs could make industry and government-led safety and governance efforts more difficult, and less likely. If PRC labs are either close behind or at par with models in the US, private AI firms in the US and China are likely to feel more pressure to release new models and products faster, without taking prudent pre-deployment safety measures. Governments could become reluctant to enact policies to encourage responsible AI development and deployment, for fear of falling behind.
While increasing numbers of researchers in China’s AI labs and policy community are concerned with AI safety risks, this trend has not translated into safety practices on par with labs in the US. As of last year, only 3 out of 13 top Chinese AI labs published any safety evaluation results, and none disclosed evaluations for Chemical, Biological, Radiological, and Nuclear (CBRN) risks. The Center for AI Standards and Innovation (CAISI) found that DeepSeek’s R1-0528 model complied with 94% of overtly malicious requests under a common jailbreaking technique, compared with 8% for US reference models. This pattern has continued in more recent releases. For example, an independent assessment of Moonshot’s Kimi K2.5 published in April found that the model failed to refuse CBRN-related requests at a far higher rate than US frontier models. Compounding the problem, labs in China often release dual-use capable models as open-weight. Once a model is open-weight, safeguards that do exist can be removed, making the model available to any state or non-state actor to use for malicious purposes, including the cyber and CBRN misuse those safeguards were built to prevent.
Our policy objective: creating and maintaining a lead for democracies
We support policies in the US and other countries that build and maintain a safe, near-term lead over the CCP in intelligence, domestic adoption, and global distribution. This lead is key to avoiding authoritarian AI leadership and protecting the national security interests of the US and other democracies. Doing so is a fundamental prerequisite to ensuring that democratic states can achieve favorable terms with authoritarian states.
Anthropic deeply respects the Chinese people and the accomplishments of the Chinese AI community. We hope for peaceful relations between China and the world. Our concerns are specifically with the risks to humanity posed by any powerful authoritarian political systems with access to frontier AI systems.
Opportunities for engagement on AI safety
Anthropic supports international AI safety dialogue with AI experts in China, when possible. The world has a vested interest in safe AI, regardless of where it is developed and deployed. There are a range of risks that could emerge from frontier AI systems requiring engagement between the US and China. Efforts that identify shared challenges and advance ideas to prepare for and mitigate these risks are in our shared interests.
The prospects for productive engagement are best when the US maintains a large capabilities advantage. Responsibly building a lead in developing and deploying the most advanced AI augments our ability to influence AI safety in China and elsewhere.
The Mythos Preview wake-up call
Mythos Preview, a model that we released to select partners as part of Project Glasswing in April, signals the arrival of an acceleration period that makes policy action even more urgent. With access to the model, Firefox was able to fix more security bugs last month than it had in all of 2025, and almost 20 times more than its monthly average security bug fixes in 2025. In response to the model, one PRC cybersecurity analyst wrote that China is “still sharpening our swords while the other side has suddenly mounted a fully automatic Gatling gun.”
Frontier AI capabilities will quickly approach the “country of geniuses in a datacenter” portrayal of transformative AI. This acceleration will be driven by the logic of scaling laws, in which model performance improves predictably with increases in computing power and data inputs, and by AI itself increasingly being used to accelerate the development of new models.
There is a high likelihood that we will look back on 2026 as the breakaway opportunity for American AI. American labs have the most advanced AI models, a large lead in both the quantity and quality of the advanced AI chips required to push the frontier, and a colossal capital advantage from revenues and financing to back the necessary investments to achieve it. PRC labs have real strengths: world-class, innovative talent, abundant and cheap energy, and plenty of data. All are requirements for developing frontier intelligence. But they simply do not have sufficient domestic compute to compete, nor do they have the revenues and capital to fund it.
Four fronts of the competition
The US and China are engaged in a competition for strategic advantage in frontier technologies like AI. Statements from both Beijing and Washington reflect that view. Calling that competition a “race” can give the false impression that there is a finish line, after which one side will conclusively secure victory. Rather, the competition will be an ongoing contest for advantage, in which either democracies or authoritarian regimes successfully position themselves to shape the values, rules, and norms of an AI-enabled future.
This competition is playing out on four fronts:
- Intelligence: which countries develop the most capable AI models.
- Domestic adoption: which countries integrate AI most effectively across commercial and public sectors.
- Global distribution: which countries deploy the global AI stack on which the world economy runs.
- Resilience: which countries sustain political stability through the economic transition.
Intelligence is the most important of the four fronts. We anticipate that frontier model capabilities will drive the most consequential changes for geopolitical competition. Model capabilities are also a primary driver of market adoption and global distribution.
But intelligence alone is not sufficient. If the CCP integrates near-frontier AI systems quicker and more effectively into China’s economy and the CCP security apparatus, and drives global adoption of subsidized, low-cost AI, then it could secure advantages over democracies that overcome an intelligence deficit. Beijing’s AI+ Initiative and its focus on “embodied intelligence” accordingly put high priority on policies that advance the integration of frontier intelligence into their economy and state apparatuses. The Trump administration’s AI Action Plan, and its focus on “promoting the export of the American AI technology stack,” also speaks to the strategic advantage of driving global adoption.
While we won’t focus on it in this essay, we believe resilience will be an important front of AI competition. Being able to sustain stability, cohesion, and good policymaking in this period will be a critical advantage, and a vulnerability for those who cannot.
The state of the competition
Compute—the advanced semiconductors needed to train and deploy frontier AI—is an essential input on each front of the competition described above. The race for global AI leadership is in large part a race for compute. For more than a decade, model capability has scaled with compute, and the majority of performance gains in AI capabilities have historically come from simply using more of it. Moreover, compute is needed to serve customers’ use of AI (also known as “inference” capacity), not just to train new models. Compute will be critical both for training the most intelligent models and for deploying them in commercial and national security spheres. Access to top talent, copious amounts of data, and critical algorithmic advances all matter to the race for intelligence—but each of those inputs is irrelevant if the compute is insufficient.
Democracies are winning the competition for compute leadership today. While some worry that export controls could accelerate the CCP’s own efforts to develop an advanced chip supply chain, little evidence suggests that China’s indigenization efforts will challenge US and allied leadership in advanced compute technology. Beijing has invested enormous resources into China’s chip sector, with major industrial policy initiatives like the Made in China 2025 strategy and the China Integrated Circuit Industry Investment Fund launched years before the imposition of export controls. Despite this state-backed investment, PRC AI labs and chipmakers remain stymied by US and allied export controls on advanced chips and chipmaking equipment.
As a result, the compute gap appears to be widening. An analysis of Huawei and NVIDIA’s roadmaps found that Huawei will produce just 4% of NVIDIA’s aggregate compute in 2026 in total processing performance, and 2% in 2027. Moreover, NVIDIA represents only part of the US and allied compute ecosystem, with Google and Amazon ramping up production of their own chips (TPUs and Trainium, respectively) to meet demand from American frontier AI labs and their customers.
Further exacerbating their compute shortfalls, China has made little progress in many of the most technologically complex segments of the semiconductor supply chain. Without access to extreme ultraviolet (EUV) technology, and even more so if policymakers can close loopholes on deep ultraviolet (DUV) technology and servicing and maintenance thereof, China’s chipmakers will remain unable to manufacture chips in sufficient quantity or quality to challenge US compute leadership. China’s inability to manufacture high-bandwidth memory at scale further exacerbates this gap. If the US strengthens its restrictions on the CCP’s ability to access US compute, one study estimates that America will have access to roughly 11 times more compute than China’s AI sector.
How democracies built the lead: commercial innovation and smart public policy
There are two main reasons for the compute lead. The first is the incredible innovation of companies like NVIDIA, AMD, Micron, TSMC, Samsung, ASML, and others across democracies like Japan, South Korea, Taiwan, the Netherlands, and the US, who together have built the unique technologies in the world’s most advanced semiconductors. Today’s AI achievements would not be possible without the feats of engineering and decades of sustained R&D investments that contributed to these products.
The second reason is forward-looking, decisive policy action across the last three presidential administrations. Bipartisan policy action has protected the US and allied innovation engine by restricting access to the US AI stack by PRC firms under the jurisdiction of the CCP. Our CEO has publicly commented on the importance of export controls, for example. These controls have curbed the sale of the highest-end AI chips and semiconductor manufacturing equipment (SME) to China over the last several years, constraining China’s frontier AI development even as Beijing has poured enormous state resources into the sector. Without action to limit China’s access to US compute, the CCP would have had all the ingredients to develop AI at par or superior to America’s.
Some observers worry that constraining access to compute will force AI labs in China to innovate on other axes, reducing the American lead. While PRC labs are innovating, these innovations are so far not sufficient to overcome their compute deficit. Algorithmic improvements are both a function and a multiplier of compute, not a substitute for it, and discovering those advances is itself a compute-intensive process: more compute enables labs to run more experiments, which enables labs to discover more algorithmic improvements. As frontier models increasingly conduct AI R&D themselves, that loop will tighten further, and frontier models will help build their own successors. In short, compute advantage compounds into algorithmic advantage, and from there into a durable lead in AI itself.
Today, US frontier systems are estimated to be at least several months ahead of the top models from PRC AI labs on intelligence, though these estimates are necessarily uncertain. Despite the attention paid to open-weight models from China, their enterprise adoption lags closed frontier models, and monetization concerns have surfaced among public investors. Moreover, AI labs in China seem to be moving away from open source, now choosing to keep their best models proprietary.
China’s own AI leaders confirm the impact of export controls, and the critical need for US chips. Executives at top PRC AI labs have expressed worries that China will fall further behind due to compute constraints. Top Chinese labs cite compute scarcity as a chief constraint to accelerating model capabilities, and they identify export controls as the reason for this constraint. One executive of a China-based hyperscaler called the impact of supplying export-controlled US chips to China “huge, really huge,” adding that any supply gap severely impacts China’s AI development and dismissing concerns that importing U.S. chips would slow their self-sufficiency efforts. The primary voices in China suggesting export controls are futile seem to be CCP officials and state media, likely angling to influence US policymakers.
How the CCP stays competitive: policy loopholes remain
While export controls have been effective in providing today’s advantage, they have not gone far enough. Despite the CCP’s inability to manufacture enough advanced chips domestically or purchase them legally abroad, AI labs in China have been able to stay close on intelligence through two workarounds: illicit and evasive compute access, by smuggling AI chips directly into China and accessing offshore data centers, and illicit model access, through which they carry out distillation attacks on US frontier models and use those same models as tools to accelerate their own AI R&D.
China’s evasion of US export controls is an open secret. For example, federal prosecutors charged a Supermicro co-founder and two others with diverting $2.5 billion worth of servers containing advanced US chips to China. According to US government and media reports, DeepSeek trained its latest model on advanced US chips that are banned from sale to China. The Financial Times reported that Alibaba and ByteDance now train their flagship models on export-controlled US chips in data centers located in Southeast Asia, a route current controls do not reach because US export law covers the sale of chips, not remote access to them.1 The US export control system is struggling to prevent PRC AI labs’ access to advanced US-origin compute.
Distillation attacks, in which China-based labs create thousands of fraudulent accounts to circumvent access controls on US AI models and systematically harvest their outputs to replicate frontier capabilities, are another illicit technique used by PRC labs to catch up to their US counterparts and blunt the impact of export controls. The practice allows labs based in China to free-ride on decades of foundational research, billions of dollars in US investment, and the work of thousands of the world’s best engineers that produced US frontier models. The result is near-frontier capability at a fraction of the cost, subsidized by the United States. It is systematic industrial espionage of a technology critical to long-term US national security interests. OpenAI, Google, Anthropic, and the Frontier Model Forum have all publicly condemned the practice of distillation attacks.
AI experts in China openly acknowledge distillation attacks’ scale and importance to China’s AI development. A recent article in a state-owned media outlet described distillation attacks on US models as the “back door” China’s AI labs depend on as a core part of their business model. An ex-ByteDance researcher said that PRC AI labs use distillation as a shortcut to train models, allowing them to avoid investing into their own data pipelines.
US policymakers have moved quickly to address this threat. The White House Office of Science and Technology Policy published a memo on distillation attacks. Senior officials in the White House, Department of War, and members of Congress have also called attention to this problem. Recent legislation from the House Foreign Affairs Committee to address distillation attacks passed out of committee unanimously.
If policymakers in the US and allied democracies act to close these two channels propping up China’s AI models—illicit and evasive compute access and illicit model access—then we have a potentially once-in-a-generation opportunity to secure our lead.
Two scenarios for 2028
Below, we describe two hypothetical future scenarios to help illustrate how policy actions taken today can shape where we are in 2028.
Scenario one: America and our allies have a commanding and expanding lead
America’s compute edge remains strong. Despite increased state support for China’s semiconductor industry, China’s chipmakers remain years behind their US and allied counterparts, stymied in part by their inability to access advanced SME tooling, servicing, and maintenance. The US-PRC compute gap is widening as increased US and allied chipmaking capacity comes online and as advanced chipmakers continue to innovate on more efficient and performant chips. In tandem, US policymakers have taken action to close loopholes in the US economic security toolkit, and efforts to smuggle chips into China and access export-controlled chips in data centers outside the country are increasingly frustrated by well-funded enforcement efforts.
Consequently, US AI models are 12-24 months ahead on intelligence, and the lead is growing. A small number of AI labs lead at the frontier with the most intelligent, capable, and performant models. All are based in the US. The “country of geniuses in a data center” has become a reality across critical industries, including cybersecurity, finance, healthcare, and life sciences. When US frontier labs release new models in 2028 that achieve step-function advances in capabilities (similar to the relative impact of Mythos Preview in April 2026), China will not have access to similar AI capabilities until 2029 or 2030. This gives critical breathing room for democracies to set the rules and norms of frontier AI systems.
American AI is the backbone of the global economy, driving new economic and scientific dynamism. The Trump administration's efforts to drive domestic AI adoption and promote the export of American AI are succeeding, and the resulting gains from the adoption of powerful AI both at home and abroad are driving unprecedented economic growth and technological advancements. Global adoption of US AI has skyrocketed. Democracies’ lead in capabilities and compute means that China’s AI firms do not compete for global market share outside of a narrow group of autocracies. The world’s top frontier AI systems are shaped by democratic values and make it more difficult for authoritarian states to use AI systems to infringe on rights and civil liberties.
Cyber and other national security advantages expand. Public and private sector cyber operators and security professionals use advanced AI systems to reduce the attack surface in America and other democracies and blunt the CCP’s ability to gain and maintain cyber footholds in our systems, making our national security assets, IP, and communications networks more secure. The United States' overwhelming AI advantage is a powerful deterrent to aggression.
A self-reinforcing cycle compounds democracies’ leadership. A commanding AI advantage makes the United States and its allies more attractive partners. That alignment expands both the market for American AI and the coalition setting global AI norms, which in turn promotes the development and deployment of AI systems that are safe, secure, and protective of civil liberties. The world’s top technical and scientific talent continues to gravitate to where the frontier is being built. The United States gains significant leverage with which to incentivize cooperation from Beijing on critical issues like AI governance, strategic competition, and trade. This cycle reinforces itself: the lead strengthens the coalition, the coalition strengthens the lead, the democracy-led international order is anchored through the transition to transformative AI.
Scenario two: The CCP-controlled AI ecosystem is neck-and-neck
AI developed and deployed in China is near-frontier on model intelligence. Despite a weak semiconductor production capacity, models trained by PRC AI labs are only a few months behind US models. Ongoing distillation attacks, overseas compute access, weak SME export enforcement, and a loosening of export controls on American semiconductors have assisted CCP efforts. Continued access to US frontier AI for AI R&D has also enabled AI labs in China to close the gap and approach parity with their US counterparts.
Rapid commercial and state adoption. Beijing has championed a whole-of-nation push on domestic adoption via “AI+” policies. Even though China's AI models are slightly less capable than US models, CCP efforts to accelerate adoption have paid off. China is thus able to deploy near-frontier AI capabilities more advantageously across economic, military, and technological domains, shifting the balance of power in China’s favor.
The CCP’s AI-enabled cyber force is a serious threat. The CCP’s integration of AI-enabled cyber capabilities within an already advanced cyber force has sustained the PLA as a menacing cyber competitor. PLA cyber actors have gained additional access to critical and dual-use infrastructure in the US and most countries around the world, enabling them to disrupt critical national security and societal functions. As AI is incorporated deeper into our most critical systems, democracies enjoy no security advantages over China in AI, despite having developed the technology first.
Beijing is winning in global adoption on cost and on-prem flexibility. Huawei and Alibaba data centers are globally prevalent, especially in, but not limited to, lower cost markets in the Global South. These data centers scale on older chips, which China is able to export because it can serve its domestic market with a combination of US chips purchased with an export license, smuggled into China, or remotely accessed in overseas data centers. They host second-tier, but cheaper and still effective models produced by PRC labs. Similar to the Huawei playbook of being cheap and “good enough,” China’s near-frontier models and hardware support a non-trivial and rapidly growing segment of the global economy. This infrastructure advantage gives CCP leadership significant influence over those markets.
Ensuring democracies lead
To ensure we land in scenario one, we support the following areas of policy action.
- Close the loopholes: Smuggled chips, foreign data center access, and SME. Today, PRC labs benefit from access to export-controlled American chips via smuggling and foreign data centers, and gaps in SME controls accelerate their self-sufficiency efforts. Tightening controls and ramping up enforcement budgets can help close these loopholes that prop up the CCP’s AI ecosystem. It would lower China’s compute ceiling and correspondingly slow their AI advances, thus sustaining and expanding democracies’ AI lead. Note that a lower compute ceiling could also materially impair distillation attacks, as AI labs in China still require a minimum threshold of compute to illicitly distill effectively.
- Defend our innovations: Restrict model access and deter distillation attacks. Policymakers in Congress and the executive branch can continue to support policy actions to punish and disincentivize distillation attacks from PRC labs, while also taking steps to facilitate US labs’ ability to detect and prevent distillation attacks on its own. These could include a legislative clarification that distillation attacks are illegal, and efforts to facilitate threat intel and technical sharing between peer American labs as well as with the US Government. Curbing this behavior can materially extend a democratic lead in the coming months and years.
- Champion the export of American AI. As public and commercial sectors around the world increasingly adopt AI, the Trump administration should continue its efforts to promote the global adoption of trusted AI hardware and models developed and shaped by democratic principles. Locking in trusted American infrastructure now denies the CCP’s AI ecosystem the global footholds it needs to compete on cost and adoption in the future.
Conclusion
America and its allies have developed both the world’s most capable frontier AI models and the world’s most advanced inputs to AI. This has provided a substantial advantage. If our superior access to that technology is defended, that advantage can be extended. But it will be lost if it is given directly to our competitors. The decisions made by policymakers this year will determine the future of transformative AI. We support those working to ensure that American and allied democracies are winning in 2028.
Footnotes
- In January 2026, the House passed a bipartisan bill 369–22 to close that loophole; the bill has not passed the Senate.
Paving the way for agents in biology
Making Claude a chemist
Coding agents in the social sciences
Results from a survey of 1,260 social scientists about AI and coding agent use.