In 1957, Washington went all-in on the development and production of intercontinental nuclear missiles for fear that Moscow was pulling ahead in the arms race. Using estimates of what Soviet factories could produce, the U.S. Air Force projected that the Soviet Union was on track to possess 500 intercontinental missiles by 1960—hundreds more than the United States planned to deploy.
Decades later, Washington’s approach to the race in artificial intelligence rests on a similar logic: If U.S. labs do not double down, China will pull ahead and be the first to reach the holy grail of artificial general intelligence—that is, cognitive abilities that match or go beyond human abilities. Maybe. In the 1950s, the U.S. count of Soviet missiles ended up being wrong. This time, Washington could be measuring the wrong thing altogether with its focus on technological benchmarks. Beijing instead measures the success of its AI rollout in terms of adoption and diffusion across its economy and beyond. This has a key safety implication: Beijing’s version of the AI rollout has no off switch.
In 1957, Washington went all-in on the development and production of intercontinental nuclear missiles for fear that Moscow was pulling ahead in the arms race. Using estimates of what Soviet factories could produce, the U.S. Air Force projected that the Soviet Union was on track to possess 500 intercontinental missiles by 1960—hundreds more than the United States planned to deploy.
Decades later, Washington’s approach to the race in artificial intelligence rests on a similar logic: If U.S. labs do not double down, China will pull ahead and be the first to reach the holy grail of artificial general intelligence—that is, cognitive abilities that match or go beyond human abilities. Maybe. In the 1950s, the U.S. count of Soviet missiles ended up being wrong. This time, Washington could be measuring the wrong thing altogether with its focus on technological benchmarks. Beijing instead measures the success of its AI rollout in terms of adoption and diffusion across its economy and beyond. This has a key safety implication: Beijing’s version of the AI rollout has no off switch.
Today, China lags behind in frontier AI but not by much. Since 2023, all frontier models have been American, but the best Chinese models, such as Kimi K3, Qwen 3.8 Max, and GLM-5.3, are just a few months behind the leading U.S. ones, according to Epoch AI. For U.S. labs, that is fuel to advance faster. The idea that the United States is still ahead rests on a single premise—that the decisive battleground for AI is the frontier. China, however, may well be running another race.
Whereas the U.S. AI ecosystem fixates on top-notch models, Beijing likes to see AI a bit like the internet: a technology to embed in the economy and means to an end. In August 2025, China released its “AI Plus” action plan, borrowing its name from the 2015 “Internet Plus” plan. This blueprint makes for an enlightening read. While Washington focuses on the supply side—chips, data centers, and frontier models—Beijing treats AI as a tool to achieve broader long-term objectives, such as boosting manufacturing productivity, tackling a dire demographic outlook, supporting innovation, and fostering the diffusion of Chinese technology standards abroad. The plan targets a “penetration rate”—whatever that means—of 70 percent for AI agents and smart devices by 2027 and 90 percent by 2030.
At home, China’s AI plan rests on three pillars. The first is collecting industrial data. In 2020, Beijing formally designated data as a factor of production in a bid to make the most of the data points that Chinese factories, logistics networks, and smart cities generate. China’s bet is simple: Crunching all of this data with AI at scale—using small-scale, specialized models that operate far from the frontier—will boost production, further cementing China’s standing as the world’s top manufacturing power. Work on this front is already underway. In March, for example, a U.S. congressional commission reported that a firm in Guangdong was using data from intelligent cameras to feed into an AI model that improved quality inspection, saving the company more than $140,000 per year.
The second pillar involves developing industrial applications for AI. U.S. consultancy IDC estimates that nearly half of China’s industrial firms had deployed specialized models or agents by mid-2025. That data is from more than a year ago—an eternity in the AI world—suggesting that the share of Chinese firms using AI is likely to be even higher now. Looking ahead, Beijing has even bigger goals. In January, China announced that it was aiming for 1,000 industrial AI agents, 500 application scenarios, and 1,000 showcase firms by 2027. Again, the focus is on applying AI widely and quickly, rather than top-notch benchmarks.
The final pillar is embodied AI—physical robots controlled by AI models. On this front, the latest annual report of the International Federation of Robotics is sobering. Last year, Chinese firms installed 354,000 industrial robots, more than all other countries combined. According to data from MERICS, China also produced 12,800 humanoid robots last year, about 90 percent of the worldwide total. It is not far-fetched to imagine that many of these robots could soon take orders from AI models that learn from their own factories’ data.
Abroad, China’s AI strategy relies on developers adopting Chinese models because they are cheap and good enough for many use cases. Crucially, Chinese AI models are often “open-weight,” meaning that their core parameters are available for anyone to download, fine-tune, and run on their own server. U.S. firms such as Meta and Nvidia release open-weight models, too, but Chinese ones are proving much more popular. According to OpenRouter, seven of the nine most popular AI models in mid-September were Chinese. This popularity fuels a self-reinforcing cycle. When firms download China’s AI models to build on them, they absorb Chinese technical assumptions and help make them industry standards. This further fuels the diffusion of Chinese AI tools.
This fast and wide diffusion has critical implications for the AI safety debate. The U.S. conversation about AI safety focuses on creating a kill switch if things go wrong. Closed U.S. models come with such a panic button because they run on their makers’ servers. In June, for example, Anthropic suspended global access to frontier models Mythos 5 and Fable 5 in order to comply with the U.S. government’s sudden imposition of export controls. In July, U.S. Reps. Ted Lieu and Nathaniel Moran introduced the AI Kill Switch Act in the House, and in September, Sen. John Kennedy’s AI Emergency Button Act reached the Senate floor before stalling. Both would require developers to design ways to shut down AI models. The proposals also highlight growing concern about recursive self-improvement, or AI’s ability to self-improve and autonomously create new, more powerful models.
The catch is that these safety debates are irrelevant in the Chinese AI ecosystem. No developer can recall every single copy of an open-weight model that runs in thousands of Chinese factories or on servers across the globe. In August, Chinese AI lab Zhipu held off on publishing the weights of GLM-5.3 for two weeks because of concerns about the model’s cybercapabilities. The company knew that there would be nothing left to recall once the weights were out. Since the weights were finally released later that month, developers have downloaded GLM-5.3 more than 1.4 million times on the Hugging Face platform.
Developers have put these downloads to good use: In just over a month, they released some 80 variants of GLM-5.3. Most such versions tweak the model so it runs faster or on less powerful servers. Others are more intriguing; just a few days after Zhipu released GLM-5.3’s weights, a developer posted a version—billed as a security-research tool—that removes the model’s safety guardrails. Even flagship U.S. firms are not shying away from getting their hands on Chinese models and rejiggering them. U.S. chipmaker Nvidia published a compressed version of GLM-5.3 that optimizes disk space and memory use.
The issue goes deeper: Nobody can see what users do with open weights once a user stores them on their own computer. The AI safety incidents that are making the news, such as the recent hack of Australia’s Medicare statistics portal by OpenAI agents, are public largely because they involved closed models that record interactions. In November 2025, Anthropic announced that it had reason to believe that a Chinese state-sponsored group had used Claude Code against roughly 30 global targets. (Some experts questioned Anthropic’s account, noting that sophisticated attackers would never use a closed-source model from a U.S. firm that logs all messages instead of using an open-weight model that evades such detection.)
In 1961, the U.S. panic over Soviet intercontinental missiles came to an end after Washington finally found a way to actually count them, thanks to the new Corona spy satellites. At 25 at most, the count of Soviet intercontinental missiles was no higher than the United States’. The problem today is that no satellite can track China’s AI successes if they hinge on widespread diffusion into factories and onto foreign servers, regardless of where the models stand compared with the technological frontier. China’s AI advances could well be as invisible as they are hard to stop. Washington may have to rethink what the global AI race really looks like.


