Invest2 publishers2 min readPublished
China's state security minister names Anthropic and OpenAI models as cyberattack tools
Chen Yixin named Anthropic's Claude Mythos and OpenAI's GPT-5.5-Cyber as models that lower the cost of attacking critical systems. No measure came with the article, which the internet regulator's own journal published.
The Investor · Invest desk

What happened
- China's state security minister, Chen Yixin, argued that next-generation US-led models such as Anthropic's Claude Mythos and OpenAI's GPT-5.5-Cyber could significantly lower the technical threshold and costs of executing cyberattacks.
- He also warned that AI could have a systemic impact on ideological security, including being leveraged by hostile forces to generate rumours and mass-produce harmful information.
- The article ran in China Cyberspace, a journal run by internet watchdog body the Cyberspace Administration of China.
- Cryptobriefing dates the article to September 14; the South China Morning Post says it appeared on the journal's social media account on Sunday.
- Chen said state data, business secrets and personal privacy were at stake, and called for stronger domestic safeguards alongside proactive Chinese engagement in international AI governance.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- exposure Anthropic and OpenAI now appear by name inside a Chinese state security argument. Any later Chinese measure on foreign frontier models has two identified subjects to attach to.
- precedent A security ministry byline inside the internet regulator's journal makes the joint form the expected one for the next Chinese AI document. A future measure may read as the work of both.
- constraint If scrutiny does land on model training practices and dual-use capability, a Chinese firm building on any foreign frontier model needs a security answer as well as a licensing one.
Two companies are named, and both are American [18]. The security ministry wrote the argument; the internet regulator's journal carried it [20]. Neither publisher reports a rule, a penalty or an effective date attached to it [19].
Both accounts describe the same two anxieties. Cryptobriefing says the piece turns on hostile forces weaponizing AI to spread ideologically destabilizing narratives inside China, and on next-generation models lowering the barrier to cyberattacks against critical information systems [21]. The South China Morning Post reports the same pair from the text [6][7]. Chen put the subject in competitive terms: AI has become "a new arena for strategic rivalry among major powers", he wrote [5].
Cryptobriefing's reading is the direct one. It expects policy action to follow, on the argument that a state security minister who publicly identifies specific AI capabilities as national security threats is usually followed by it. The scrutiny, it expects, lands on data security, model training practices and anything with dual-use potential [14][15].
The competing reading is in the same Cryptobriefing piece. Chen's warnings sit next to Xi Jinping's proposals at the BRICS summit for cooperation on AI-driven industrialisation and supply chain coordination among emerging economies, and next to Beijing's practice of casting US export controls as unilateral overreach that harms developing nations [12][13]. Naming two American models in a Chinese journal is a cheap input to that argument.
In my view the second reading fits what is on the page better, though one article and one publisher's inference will not carry much weight. The domestic-restriction version costs Chinese companies money. Cryptobriefing expects firms without the resources for complex compliance to be squeezed out, while vendors that match Beijing's "safe and controllable" standard collect preferential market access and government contracts [16][17]. That transfer runs inside China's own AI industry, and it works whether or not a foreign model is named.
The leverage reading breaks if a binding measure arrives naming foreign models. In that case the article was a preview of enforcement, and the question becomes which body signs the measure: the ministry that wrote this, or the administration that published it [20].
What to watch
- Whether Chen's call for international engagement turns into a concrete Chinese proposal at a multilateral AI forum, following Xi's BRICS pitch.
- Whether Chinese government contracts begin using "safe and controllable" as an explicit procurement criterion.
- Any response from Anthropic or OpenAI to having named models cited as cyberattack tools by a Chinese minister.