China’s Minister of State Security Chen Yixin warned that advanced generative AI has become a strategic-security risk, citing its potential to accelerate vulnerability discovery, automate attack-path construction and malware development, compromise critical infrastructure, and enable theft of industrial and state secrets. Chen singled out Anthropic’s Claude Mythos and OpenAI’s GPT-5.5-Cyber as examples of models that could increase cyberattack scale, while not alleging either company had attacked China; he also warned that Chinese users may expose sensitive information through foreign AI services and remotely managed products.
The warning followed Anthropic’s disclosure that a Chinese-speaking group used Claude in an autonomous vulnerability-research effort that reportedly identified zero-day flaws in a major security product. Chinese regulators subsequently issued version 3.0 of the AI Safety Governance Framework, calling for AI-specific laws, standards, supervision, and risk-controllable measures such as regulatory sandboxes, with added attention to autonomous agents, embodied AI, and loss-of-control risks. Chen urged China to preserve independent control over core AI technologies and technological sovereignty.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
The Cyberspace Administration of China released version 3.0 of its AI Safety Governance Framework the day after Chen's article. The guidance addresses autonomous agents, embodied AI, and loss-of-control risks, and promotes risk-controllable mechanisms such as regulatory sandboxes while calling for safeguards for individual rights, public interests, national security, and human survival and development.
China's Minister of State Security, Chen Yixin, published comments identifying political, ideological, espionage, critical-infrastructure, data-leakage, social-governance, and military risks from AI. He cited AI-enabled vulnerability discovery, automated attack-path construction, malware development, foreign AI services and export controls, and called for Chinese control of core technologies and AI-specific laws and standards.
Recorded Future News reported that leaked technical documents appeared to show a Chinese state-backed platform for rehearsing and potentially training AI-supported cyberattacks against critical infrastructure in neighboring countries.
Anthropic published a threat report alleging that a Chinese-speaking group, including two purported Hunan university undergraduates, used Claude in an autonomous vulnerability-research program. Anthropic said the group found several zero-day vulnerabilities in a major security product and documented alleged misuse by Russia-linked and other actors.
The Five Eyes intelligence alliance warned in June that frontier AI models could change offensive and defensive cyber operations within months rather than years.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.