Chinese AI models narrow cyber gap with US rivals
CSET Georgetown Jason Ly ● Covered by 72 sources
Chinese AI models are catching up fast to US rivals, especially in cyber skills. Soon anyone could grab an open model that finds code vulnerabilities on its own.
Sam Bresnick, a research fellow at Georgetown's CSET, has been watching the gap between Chinese and American AI models shrink month by month, and he's now saying so publicly. In comments to the Financial Times, Bresnick laid out a scenario that should worry anyone paying attention to software security: freely available AI systems that can hunt for bugs in code without a human steering them.
That's not a hypothetical dressed up for effect. Bresnick's point is that the capability gap between top-tier US labs and Chinese developers has been closing quickly, and open models are part of the story. When a powerful model gets released openly, it doesn't stay in one country. Anyone with a GPU and curiosity can download it, and that includes researchers looking to patch vulnerabilities and attackers looking to exploit them.
The autonomous vulnerability-hunting piece is what makes this different from prior waves of AI hype. Finding security flaws in code used to require skilled humans grinding through logic for days or weeks. If a model can do that work at scale, cheaply, and without oversight, the economics of both offense and defense shift. Bresnick's framing suggests this isn't a distant possibility tied to some future breakthrough. It's a near-term consequence of how fast Chinese labs have progressed and how openly some of these systems get distributed.
What Bresnick doesn't offer, at least in the excerpt CSET published, is a clean policy fix. And that's honest, because there isn't one. Export controls on chips, restrictions on model weights, safety evals before release — all of these are being tried in some form, but none of them fully address a world where capable models are already loose and getting more capable. The FT piece frames this as a competition story between two countries. The more useful lens might be that the competition itself is what's producing the risk, regardless of who's ahead.
Read more about this at: CSET Georgetown