China's spy chief names Claude Mythos and GPT-5.5-Cyber as AI threats
Beijing's security apparatus put American frontier models on the threat list Sunday, while MIT showed what agent societies actually build when nobody tells them what to do.
Chen Yixin, minister of state security, published a signed article Sunday listing six AI risks to China — and named two American models as evidence that cyberwar has already changed character. In the piece "Comprehensively Fortifying the AI Security Barrier to Promote Healthy and Orderly Development of AI", carried by the magazine China Cyberspace on Sunday, Chen said the arrival of Anthropic's Claude Mythos and OpenAI's GPT-5.5-Cyber marks a shift into "industrialised vulnerability discovery, fully automated offence and defence, and AI against AI", lowering both the technical bar and the cost of attacking China's critical information infrastructure. Lianhe Zaobao and Caixin both reported the essay. The other risks on his list: deepfakes, AI-generated text and image dumps, and bot armies used for cheap mass-produced political rumours against the Party (his first and most explicitly political item), large-scale data leakage from domestic users feeding sensitive material into overseas AI products, Western monopoly on models and compute expressed as entity lists and closed ecosystems, structural strain on social governance, and the transformation of military operations — where he cited the US-Israel-Iran conflict as proof AI has moved from a supporting role to a key one.
Read it as doctrine, not complaint. The ministry that runs China's counter-espionage law enforcement put two US product lines inside the country's official threat taxonomy in a signed essay — a heavier signal than a state-media editorial, with consequences for any Chinese firm weighing those models and for the export-control argument in Washington. It lands the same week Xi used the BRICS podium to sell open weights to the developing world in Xi offers BRICS a China-led open-source AI community, and it mirrors what US agencies said about Claude's misuse in Houthi-linked cell used Claude to write missile guidance software — both governments are now writing policy around the same models' offensive capability.
MIT dropped hundreds of identical language-model agents into one shared, persistent world and they built technology that survived after the agents were removed. In SwarmWorld (arXiv:2608.26081, by Subhadeep Pal, Fiona Y. Wang and Markus Buehler of MIT's LAMM group and Schwarzman College of Computing), agents propose material recipes and write small executable controllers, but a deterministic simulator decides what is legal and what works — so an artifact's value is measured by physics, not by another model's description of it. Specialization emerged with no roles assigned: in the 800-tick, 200-agent run, a constructor/operator behavioural state grew from zero to 24% of agent-windows while the "cultural coordinator" state shrank from 81% to 56%. Most first-time reuse of another agent's technology travelled through the environment itself — a standing artifact the next agent walks past — rather than through messages — about 95% of first-time reuse, on the paper's own diffusion counts — and Buehler put it more bluntly on X: "The agents mostly learned technology by walking past it."
The honest limit is the part most coverage will skip: there is no universal swarm advantage. Shared worlds won on breadth and durability of the technology portfolio, but isolated parallel search kept the strongest single artifact, and adding explicit communication never overtook the stigmergy-only ablation on validated invention count. Engine and dataset are released openly, funded by a DOE SciDAC programme — useful for anyone building agent swarms, because it says the collaboration payoff is endpoint-specific, not free.
Lyft says it will spread its robotaxi supply across more partners next year. Writing in TechCrunch Mobility, Kirsten Korosec reports that Lyft entered 2026 built around two relationships — Waymo in Nashville, where riders can hail a Waymo through either app, and Baidu in London, where commercial service has not started — and that its autonomous lead, Joe Bird, promised "more diversification" next year while calling London a "fascinating market". The company sold its own self-driving unit to Toyota's Woven Planet for $550 million in 2021, so this is an aggregator strategy, not a technology bet: Lyft says it will prioritise markets where it can run human drivers and robotaxis on one network from day one, and where regulators have already opened the door.
What to watch: whether Chen's six-risk list turns into procurement rules or a formal security-review regime for foreign models, and whether any agent-swarm lab can beat the isolated-search baseline on a single-objective task.
China's security minister just named your favourite coding model as an offensive-capability milestone. Does that change how you'd weigh a US lab's cyber-tuned release? Tell us in the comments.
Sources: Lianhe Zaobao · Caixin · SwarmWorld (arXiv:2608.26081) · Markus Buehler on X · AI Socratic · TechCrunch Mobility