Mounting evidence presages a change in China’s AI strategy.
Ever since Premier Li Qiang proposed China’s “AI Plus” initiative in 2024, Beijing has generally treated AI as a normal technology and sought to diffuse its access. Chinese AI labs’ success with consumer applications, personal agents, and business automation all serve the political leadership’s ambition to unlock “high-quality” economic growth. But at the same time China’s AI systems are growing more popular, they are also growing more powerful. Summer 2026 saw multiple model releases capable of aiding terrorism and sophisticated cyberattacks.
The threats brought by more powerful AI are colliding with Chinese leadership’s mandate to balance “development” and “security.” This tension is likely to push Chinese labs to restrict access to their largest, most disruptive future models—even as they aim to remain dominant in open-source, local deployments.
Recent open-source AI releases have crossed an important threshold of disruptive capability. On September 29, Anthropic reported that Z.ai’s GLM-5.3 approached the capability of its Mythos model at certain tasks related to cyber exploitation. Like Anthropic had done with Mythos, Z.ai at first delayed the release of GLM-5.3 to provide time to shore up cyber defenses.
But since August 28, the model has been out in the wild—its weights are freely downloadable on HuggingFace—with built-in safeguards that can be easily bypassed with creative prompting or removed altogether through a process coined “abliteration.” Some commentators have speculated this model may have been the one used to develop “WeWorm,” a critical exploit, first reported in September, capable of reaching the 800 million users of China’s most popular messaging app.
China’s security services are paying attention. In September, Minister of State Security Chen Yixin penned a rare public warning that AI was lowering the cost and technical barriers to cyberattacks, threatening critical infrastructure. He called for stronger security reviews, supervision, and tighter punishment of AI-enabled crimes.
TC260, the technical advisory body that advises the Cyberspace Administration of China, released a new AI Safety Governance Framework in mid-September that specified several problems with open models in particular: Their safeguards can be stripped out—and if they are later discovered to be generating content that is politically sensitive, they cannot be retroactively fixed or patched.
Chinese AI labs are confronting these risks too. Moonshot told the BBC it was reviewing evidence that researchers had bypassed Kimi’s safeguards to obtain instructions on how to develop biological weapons or carry out assassinations. As with Z.ai’s release of GLM-5.3, it has become a common practice for Chinese labs to delay the public release of a model’s weights until they can collect enough data on user interaction through an established API.
Beijing has ample reason to keep promoting widely available AI. Xi Jinping personally endorsed China’s open-source leadership at the World AI Conference in July. TC260’s governance framework is notably “nonbinding” and explicitly endorses an open-source AI ecosystem. But these priorities can coexist with restrictions on more dangerous capabilities—and we are likely to see these restrictions manifest soon. The likely outcome is a bifurcation in Chinese strategy: continued diffusion at the low end of the AI value chain, with Chinese labs increasingly withholding systems that Beijing regards as threats to social stability or state control.
Any restrictions on China’s AI frontier are likely to amount to a “soft” closure—and much is uncertain about what this might look like in practice. Some labs are already attaching more restrictive terms to their open-weight releases. Z.ai had replaced GLM-5.2’s permissive MIT license with a custom GLM-5.3 license, with a security review required for qualifying hosts earning more than $10 billion in annual revenue. Moonshot’s Kimi K3 license likewise requires a separate commercial agreement for hosting businesses making more than $20 million.
Enforcing more stringent licenses is a creative way of shifting liability for AI misuse onto model hosts rather than developers—TC260 already recommends that model hosts implement identity verification and deny high-risk operations for ordinary users. But a major AI incident could prompt China’s political and technical leadership to put an outright end to open-weight releases at the high end. As with frontier American models, access to cutting-edge Chinese AI could shift to restricted APIs with customer verification requirements, activity monitoring, and explicit authorization for sensitive tasks. Or some other arrangement might reserve select AI capabilities for approved enterprises or government institutions.
The timing and exact arrangements of China’s closing AI frontier remain uncertain. But Beijing’s growing emphasis on misuse and control makes it increasingly unlikely that Chinese labs will keep freely democratizing access to ever-more-disruptive capabilities. What will matter most to the Chinese Communist Party is whether AI access can be monitored—and denied or withdrawn from those who might threaten its rule.
The Party can want AI everywhere without wanting everyone to possess its most powerful capabilities.