CYBER DELTA FORCESearch

China spy chief points at US AI models in cyber threat warning

China's spy chief identified Anthropic’s Claude Mythos and OpenAI’s GPT-5.5-Cyber as signs of what he called a “disruptive upgrade” in cyber capabilities, increasing the speed and potential weaponization of vulnerability discovery and malware development.

CDF News DeskThe Record15 Sept 2026, 6:24 pm
Image courtesy of The Record. Original report
CDF REPORT

China's spy chief identified Anthropic’s Claude Mythos and OpenAI’s GPT-5.5-Cyber as signs of what he called a “disruptive upgrade” in cyber capabilities, increasing the speed and potential weaponization of vulnerability discovery and malware development. artificial intelligence models as cybersecurity risks to China’s critical infrastructure, though he did not accuse either of being used in attacks on the country. Chen Yixin, head of the Ministry of State Security, made the comments in the journal of the Cyberspace Administration of China. The ministry oversees China’s intelligence and secret police apparatus and reports to the Communist Party’s top political-legal body.

“Some countries and organizations possess the capability to rapidly and in large quantities discover vulnerabilities, automatically connect attack paths, and complete complex hacking tasks, drastically lowering the technical barriers and costs of launching cyberattacks and posing serious risks to China's critical information infrastructure.” Western governments have raised similar concerns about AI’s effect on cyber operations. Chen’s warning came days after Anthropic published a threat report describing a Chinese-speaking group that used Claude to conduct what the company called an “autonomous vulnerability research program.” Anthropic said the group, which included two operators it identified as undergraduates at a university in Hunan, found several zero-day flaws in a major security product. Chen also criticized foreign export controls and “closed-source ecosystems.” Chinese labs have become major proponents of open-weight models, a strategy analysts view in part as an effort to spread Chinese technology and influence technical standards abroad.

China already requires public-facing AI services to undergo government security reviews and register before launch.

China already requires public-facing AI services to undergo government security reviews and register before launch.

What changed

A day after Chen’s article, the Cyberspace Administration of China released a new version of its AI governance framework at the opening of National Cybersecurity Week in Jinan.

Who is affected

“Some countries and organizations possess the capability to rapidly and in large quantities discover vulnerabilities, automatically connect attack paths, and complete complex hacking tasks, drastically lowering the technical barriers and costs of launching cyberattacks and posing serious risks to China's critical information infrastructure.” Western governments have raised similar concerns about AI’s effect on cyber operations.

Chen’s warning came days after Anthropic published a threat report describing a Chinese-speaking group that used Claude to conduct what the company called an “autonomous vulnerability research program.” Anthropic said the group, which included two operators it identified as undergraduates at a university in Hunan, found several zero-day flaws in a major security product.

Chen also criticized foreign export controls and “closed-source ecosystems.” Chinese labs have become major proponents of open-weight models, a strategy analysts view in part as an effort to spread Chinese technology and influence technical standards abroad.

What defenders should do now

China already requires public-facing AI services to undergo government security reviews and register before launch.

What to watch next

Watch for revised fixed-version guidance and confirmation that mitigations are holding in affected environments.

What remains unknown

The available reporting does not establish whether the issue is being actively exploited in the wild.

MORE IN AI SECURITY

More cybersecurity reporting

OpenAI Investigates Report Linking AI Agents to RubyGems AttackSecurityWeek · 15 Sept 2026, 6:12 pmManhattan DA takes down 12 AI deepfake porn sitesThe Record · 15 Sept 2026, 6:12 pmHuman Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight SecondsThe Hacker News · 15 Sept 2026, 5:22 pmMicrosoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety ConstraintsSecurityWeek · 15 Sept 2026, 3:10 pm