Most of the debate around AI, at least in the U.S., is not about the international aspect. The local political debate is all about data center construction; the national economic debate is mostly about fear of job loss, with a side discussion about a potential bubble; and the technological discussion, at least in public, is mostly about AI safety and risk. U.S.-China competition gets mentioned in certain circles, but it’s probably safe to say that it’s not Americans’ chief topic of concern.
But it still matters! For one thing, there’s the military aspect to think about. Cyberwarfare so far hasn’t been decisive in military conflicts, but AI’s incredible cybersecurity prowess could change that. If AI ends up strengthening defense more than offense — say, by finding all of the available exploits and patching them before an attacker can get to them — then cyberwarfare will become less important. But if those who possess the best AI models are able to successfully hack anyone using a less capable model to defend, it could lead to a decisive shift in the balance of power.
AI hacking doesn’t have mutually assured destruction, like nuclear warfare does. Imagine if China were to gain a big lead in AI models that gave it the power to easily hack into American banks and brokerage accounts and erase people’s wealth. It would cause absolute chaos in American society, but how could the U.S. retaliate? Launch nukes? Nor could the U.S. hack China in return, since China’s more capable AI would also be used to defend.
If either country opens up a large, sustained lead in AI capabilities, it might upend the balance of power between the two.
Not all AI issues are zero-sum, of course. If the U.S. and China both continue pushing forward with AI research at maximum speed, it may quickly cause safety issues. The recent AI agent swarm attack on Hugging Face shows that AI has reached the level where it can pose a significant hazard to human companies and organizations — and perhaps soon to human society itself. Bioterror risk is certainly the most terrifying, but there are plenty of other ways that highly capable AI could cause chaos.
The U.S. and China have a shared incentive to implement strict safeguards against these catastrophic risks, and perhaps even to regulate the pace of AI development. But given the Chinese Communist Party’s power-seeking nature, it seems much more likely that China would agree to cooperate on AI safety if U.S. capabilities were comfortably ahead. So even if the goal is cooperation, the U.S. should be thinking about how to keep its technological edge.
Fortunately, the U.S. is still beating China in the AI race. Our companies have better models, more compute, and far more revenue. But there are ways that the Trump administration, despite claiming to be the AI industry’s best friend, could squander America’s lead — especially by pushing Chinese AI talent out of the country.
U.S. models are still better than Chinese models
There have been several moments when it seemed as if China’s frontier models were catching up to America’s in capabilities. The most dramatic was the “DeepSeek Moment” in early 2025, which put Chinese AI on the map. More recently, the release of Moonshot’s Kimi K3 this July and Z.ai’s GLM-5.3 a few weeks ago seemed to indicate that Chinese models were nipping at the Americans’ heels.1 Z.ai especially made waves when it beat Anthropic’s famous Mythos model on one measure of cyber-hacking capabilities:
Chinese AI startup Z.ai said on Friday its open-source GLM-5.3 model had neared Anthropic’s restricted Mythos 5 in identifying software vulnerabilities…Z.ai said GLM-5.3 scored 84.5% on CyberGym, a test of whether a model can review code, identify security flaws and confirm that they are real. That was slightly higher than the 83.8% it reported for Mythos 5. The results have not been independently verified.
Note that this is just one measure of cybersecurity prowess, and that Mythos was still comfortably ahead on other measures:
GLM-5.3 lagged behind Mythos 5 in converting discovered flaws into working attacks — a standard part of defensive security research. Z.ai said its model scored 54.4% on the ExploitBench test of this capability, versus 78.0% for Mythos 5…In a separate timed test, Z.ai said GLM-5.3 completed 105 attack-development tasks in two hours and 130 in six hours. Mythos 5 completed 181 and 247 tasks, respectively.
But still, if Chinese AI could get within striking distance of America’s best, it was a big deal.
What this discourse rarely mentioned, though, is that Mythos is not America’s best. It was simply the best that’s been released. Mythos Preview came out in April, four months before GLM-5.3. And the original Mythos actually finished training three months earlier, in January, and was released internally in February.2 Anthropic delayed its release due to cybersecurity concerns. Z.ai, being a fast follower, probably had far fewer such concerns. In fact, Anthropic has stated that it has internal models that are better than Mythos.
Facts Only
* U.S. domestic AI debates center on data center construction, job loss, and AI safety.
* AI capabilities in cybersecurity can either strengthen defense by patching exploits or strengthen offense by enabling hacking.
* China's Z.ai released the GLM-5.3 model.
* Z.ai reported GLM-5.3 scored 84.5% on the CyberGym test.
* Anthropic's Mythos 5 scored 83.8% on the CyberGym test.
* Z.ai reported GLM-5.3 scored 54.4% on the ExploitBench test.
* Anthropic's Mythos 5 scored 78.0% on the ExploitBench test.
* Mythos 5 completed 247 attack-development tasks in six hours, while GLM-5.3 completed 130.
* Mythos finished training in January and was released internally in February.
* An AI agent swarm attack recently targeted Hugging Face.
* U.S. AI companies currently possess more compute and revenue than Chinese counterparts.
Executive Summary
The competition between the U.S. and China in artificial intelligence centers on a potential shift in the global balance of power, specifically regarding cybersecurity and military capabilities. While domestic U.S. discourse focuses on data centers and job loss, the strategic risk involves a scenario where one nation gains a decisive lead in AI-driven hacking, potentially bypassing traditional deterrence mechanisms like mutually assured destruction.
Current data indicates the U.S. maintains a lead in model quality, compute power, and revenue. However, recent releases from Chinese firms, such as Z.ai’s GLM-5.3, have demonstrated competitive performance in identifying software vulnerabilities, even surpassing certain released U.S. models like Anthropic’s Mythos 5 in specific metrics. Despite this, U.S. models generally maintain superiority in converting those vulnerabilities into working attacks. A shared incentive exists to prevent catastrophic AI risks, such as bioterrorism, but cooperation is viewed as contingent on the U.S. maintaining its technological edge to ensure leverage over the Chinese Communist Party.
Full Take
The strongest version of this narrative is a geopolitical warning: AI is a "force multiplier" for cyberwarfare that lacks the stabilizing effect of nuclear deterrence, making a technological lead a prerequisite for both national security and the ability to enforce global safety standards.
This analysis operates in SKEPTICAL MODE. The primary load-bearing pattern is a Fear Appeal; the text moves from a specific technical benchmark (CyberGym) to an existential scenario where wealth is erased and society collapses. This escalation serves to justify a policy of aggressive technological dominance and the protection of specific talent pools. By framing cooperation as something the Chinese Communist Party would only accept from a position of weakness, the narrative effectively closes the door on diplomacy as a primary tool, presenting a "lead or lose" binary.
Patterns detected: ARC-0031 Fear Appeal, ARC-0027 False Binary
The driving paradigm is Neorealism—the belief that international relations are a zero-sum game where security is achieved only through relative power. The unstated assumption is that the "internal models" mentioned by U.S. companies are significantly superior to released ones, a claim that cannot be independently verified but is used to neutralize the impact of Chinese gains.
This framing benefits the U.S. AI industrial complex by aligning corporate profit (more compute and revenue) with national survival. The second-order consequence is a heightened "AI arms race" that may accelerate the very catastrophic risks (like bioterrorism) the author claims to fear.
Bridge Questions:
1. If safety is a shared global risk, does a "winner-take-all" race actually increase the probability of a catastrophic accident?
2. How would the balance of power shift if the most capable models became open-source rather than proprietary?
Counterstrike Scan: A state-sponsored influence campaign would use this pattern to manufacture consent for restrictive immigration policies targeting foreign nationals or to secure increased government subsidies for AI firms. The content aligns structurally with this pattern by linking "talent" and "revenue" directly to the prevention of societal collapse.
Sentinel — Human
The text is a reasoned analytical piece that skillfully weaves geopolitical strategy with technical comparisons, showing signs of human synthesis and interpretation rather than raw content generation.
