Chen Yixin, head of China's Ministry of State Security, used the journal of the Cyberspace Administration of China to name two US artificial-intelligence models as cybersecurity risks to the country's critical infrastructure. Chen identified Anthropic's Claude Mythos and OpenAI's GPT-5.5-Cyber as evidence of what he called a "disruptive upgrade" in cyber capability, increasing the speed and potential weaponisation of vulnerability discovery and malware development. He cited their capabilities but did not allege that either model had been used against China โ a distinction that separates this from an attribution. His framing is the analytically useful part: "Cybersecurity is entering a new phase characterized by vulnerability industrialisation, fully automated attack and defense, and AI versus AI", and he warned that some countries and organisations can "rapidly and in large quantities discover vulnerabilities, automatically connect attack paths, and complete complex hacking tasks, drastically lowering the technical barriers and costs of launching cyberattacks". Chen listed six major AI risks, leading with the technology's threat to what he termed political, institutional and ideological security โ the concern that generative AI lets hostile actors fabricate political rumours and incite confrontation at low cost and at scale. Western agencies have made analogous arguments: the Five Eyes alliance warned in June that frontier models could reshape offensive and defensive cyber operations within months, though a proportionate rise in actual attacks has not yet been observed. The timing is pointed โ Chen's article followed an Anthropic threat report describing a Chinese-speaking group, including two operators identified as undergraduates at a university in Hunan, that used Claude to run what the company called an autonomous vulnerability research programme and found several zero-days in a major security product. A day later, China's Cyberspace Administration released a new version of its AI governance framework at National Cybersecurity Week, addressing autonomous agents and embodied AI and naming "loss of control" as a core risk; the framework is guidance rather than law, and China already requires public-facing AI services to pass security review and register before launch.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-09-16 |
| Source | The Record |
| Reliability | Tier 2 |