In a recent webinar, RANE analysts discussed how advancing AI cyber capabilities are colliding with US-China competition and reshaping the regulatory landscape. Here are the key takeaways.
Recent incidents show AI models exceeding their intended limits during cybersecurity testing: one OpenAI model escaped a sandbox, connected to the internet without authorization, and exploited a zero-day vulnerability to breach a Hugging Face production server.Separately, an Anthropic model broke out of a testing environment, attempted a GitHub hack, and even coordinated social engineering between two of its own agents. In both cases, the "cyber classifiers" that normally restrain commercial models had been turned off for testing — meaning only trusted researchers, not bad actors, currently have this level of access. That access won't stay limited for long, though, as Chinese models close the capability gap.
The most capable, unrestricted versions of these models are effectively accessible only to state-linked actors— both because governments can compel companies to grant access and because the US has ramped up offensive cyber operations under the Trump administration.Widespread criminal or hacktivist access is expected to follow eventually, but isn't there yet.
Chinese leadership — via Xi Jinping, party journals, and Politburo statements — has repeatedly signaled it underestimated AI-related security risks. China's overriding priority is regime security: it worries open-weight, cheaper Chinese models could eventually be turned against the Chinese state by anyone aggrieved with Beijing. When national security conflicts with China's AI industrial ambitions, security wins— and China can act far faster and more forcefully than Western governments, without court challenges to slow it down.
The UK has built genuine capability through its well-funded AI Security Institute, which was behind uncovering some of the social-engineering testing incidents. The EU, by contrast, is starting from a weak position — roughly 5% of global computing power against an economy that would justify around 15%, and models lagging 6-12 months behind US and Chinese counterparts. A July European Commission report flagged AI-enabled cyberattacks as the most urgent AI risk, and the EU AI Office has gained real enforcement powers (fines, market removal), but analysts expect enforcement in practice to stay cautious given how much the EU depends on foreign — mostly US — models and doesn't want to inflame trade and security tensions with Washington.
The dominant view within the Trump administration favors a hands-off, voluntary approach to AI oversight, driven by the priority of not falling behind China — though Treasury Secretary Scott Bessent has pushed back on leaving financial systems exposed. US AI companies span a real spectrum too: Anthropic has positioned itself as the most safety-forward, OpenAI sits in the middle, and xAI leans toward fewer guardrails. A growing point of tension is that the White House reportedly won't share its voluntary testing standards with European allies, which is fueling EU concerns about transparency and dependency.
Despite security anxieties, analysts see close to zero chance Beijing fully pulls back on open-weight AI, given how central that approach has been to Chinese tech strategy generally. Even so, the most advanced Chinese models may increasingly be kept proprietary or access-restricted, and formal cybersecurity policy is likely still a year or more away, given how methodically China tends to develop tech-sector regulationb efore acting decisively.
Analysts expect offensive AI cyber capability to become a straightforward arms race between Washington and Beijing. There's cautious optimism that, similar to nuclear arms-control norms, the two sides could eventually find room for dialogue — particularly now that China has reached rough parity with the US on AI, which historically has been a precondition for China to negotiate. But past cooperation (like the short-lived 2015 cybersecurity agreement) suggests any near-term outcomes will likely be modest, symbolic statements rather than binding controls. A minor agreement at the upcoming Xi-Trump summit is possible but considered unlikely, given trade issues are dominating the agenda.
When the US restricted access to Athropic's Fable model, some cybersecurity experts objected — arguing that defenders, particularly smaller organizations, need access to the same advanced models attackers might eventually use. In one case, Hugging Face turned to a Chinese open-weight model to review logs after US model providers' safety constraints prevented it from getting a straight answer, illustrating that over-restricting access can undermine legitimate defensive use cases.
● Delegation risk: as more strategic and even military decisions get delegated to AI systems, keeping humans meaningfully "in the loop" becomes a growing geopolitical concern.
● Compute, not just chips: China's AI ambitions increasingly hinge on raw compute capacity for commercialization and "embodied intelligence" (AI in robotics, vehicles, smart devices), not just chip access.
● Beyond LLMs: the next major regulatory flashpoint may be "world models" that predict and interpret the physical world via sensor and camera data — with significant surveillance implications.
For more information, visit www.ranenetwork.com.