Security1 publisher3 min readPublished
China's intelligence chief names Claude Mythos and GPT-5.5-Cyber in a state cyber-risk article
Chen Yixin, who runs the Ministry of State Security, cited the two frontier models in the Cyberspace Administration's journal as evidence of a disruptive upgrade in offensive cyber capability, without alleging either was used against China.
The Watch · Security desk

What happened
- Chen Yixin, head of China's Ministry of State Security, named Anthropic's Claude Mythos and OpenAI's GPT-5.5-Cyber as cybersecurity risks to China's critical infrastructure.
- He cited the two models' capabilities but did not allege that either had been used in an attack on China. The article names no victim, incident or date.
- Vulnerability reports have reached record levels since the Five Eyes warned in June about frontier models, without a proportionate rise in observed cyberattacks.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- contradiction Chen presents frontier model capability as an inbound risk to China. Anthropic's report has a Chinese-speaking group, including two people it identified as Hunan undergraduates, using Claude to find zero-days in a security product.
- constraint The article moves no patch queue and no detection rule, so a security team can read it as a policy signal.
- precedent Once the MSS has named two foreign products in print, Chinese regulators have a domestic citation to reach for in the security reviews that public-facing AI services must already pass.
- exposure Anthropic and OpenAI now sit inside a Chinese state security argument that also attacks export controls and closed-source ecosystems. Their market access is now tied to the trade dispute.
Chen was specific about how the attacks work. He wrote that "Cybersecurity is entering a new phase characterized by vulnerability industrialization, fully automated attack and defense, and AI versus AI" [6]. The capability he attributed to unnamed countries and organizations is the ability "to rapidly and in large quantities discover vulnerabilities, automatically connect attack paths, and complete complex hacking tasks, drastically lowering the technical barriers and costs of launching cyberattacks" [7]. Claude Mythos and GPT-5.5-Cyber appear as the evidence for that claim, described as signs of a "disruptive upgrade" in the speed and potential weaponization of vulnerability discovery and malware development [5].
Chen led with something else. He listed six risks, and the first was that the technology was "directly threatening our political security, institutional security, and ideological security" [3][4][1]. He wrote that hostile forces "abuse generative artificial intelligence technologies... to fabricate political rumors, spread harmful information, and incite confrontational sentiments at low cost and in large quantities" [8]. Espionage, data leaks, US export controls, alleged monopolistic practices, algorithmic decision-making in "social governance" and military applications filled out the rest [9].
The sequencing matters. Chen's article came days after Anthropic published a threat report on a Chinese-speaking group that used Claude for what the company called an "autonomous vulnerability research program" [10]. Anthropic said the group included two operators it identified as undergraduates at a university in Hunan, and that it found several zero-day flaws in a major security product [11]. Earlier this year Recorded Future News reported on leaked technical documents. They appeared to show a Chinese state-backed training platform used to rehearse cyberattacks against critical infrastructure in neighboring countries, and potentially to train AI to support them [12]. Chen was silent on AI in China's own offensive operations, which Beijing routinely denies conducting despite Western attributions [13].
Western agencies described the same capability first. The Five Eyes alliance warned in June that frontier AI models could reshape offensive and defensive cyber operations within months rather than years [14]. Vulnerability reports have since reached record levels, without a proportionate uptick in observed cyberattacks [15].
A day after Chen's article, the Cyberspace Administration of China released a new version of its AI governance framework at the opening of National Cybersecurity Week in Jinan. It focuses on autonomous agents and embodied AI, and names "loss of control" as a core risk [16]. The framework is guidance, not law [17]. China already requires public-facing AI services to pass a government security review and register before launch [18].
The article contains no CVE, indicator or named victim for a defender to action [21]. Its use is as a citation. The head of the MSS has authored a risk write-up that names two foreign products. In a country that already gates AI services on state review, that is the kind of document a later licensing or access decision leans on [1][18]. Chen also criticized foreign export controls and "closed-source ecosystems", a position aligned with Chinese labs that have become major proponents of open-weight models [19]. He described AI as an "international public good" and called for its use so the Global South could close the "intelligence gap" [20].
What to watch
- Any Chinese state attribution that places a named US model inside an actual attack on Chinese infrastructure.
- Whether the CAC's autonomous-agent guidance is folded into the existing pre-launch security review and registration requirement.
- Whether other Chinese ministries repeat the two model names in later regulatory or procurement documents.