Deep Dive — A think tank just put bombs on the table in the AGI race
A Washington think tank published a paper last week arguing that the United States should think through how it would blow up Chinese data centers. Not sanction them, not out-compete them — destroy them with conventional munitions, in the event that Beijing looks close to artificial general intelligence and Washington does not.
The report is "Superpowers and AGI," published August 27 by the Center for a New American Security. Its author, Jacob Stokes, is a senior fellow and deputy director of CNAS's Indo-Pacific Security Program, a former Obama-administration national security staffer who advised Joe Biden when he was vice president. He is not a fringe figure, and that is precisely why the paper matters.
The story broke into wider circulation on Thursday, when Stokes discussed it at an online event and the South China Morning Post reported it. Within a day, Hu Xijin — the former editor-in-chief of China's state-backed Global Times — responded on social media that a US strike on Chinese data centers would bring retaliation "directly target[ing] the US mainland with missile strikes."
That exchange is the actual news, and it is worth separating from the paper that provoked it. Stokes's report is careful, conditional, and mostly about something other than bombs. The reaction to it is not. What landed this week is a threshold crossing: a mainstream national security institution has written down, in public, that AI infrastructure is a legitimate category of military target. Everything after that follows from the category, not the recommendation. (We flagged the report when it surfaced — US think tank proposes military strikes to block China's AGI — and it deserves the longer read.)
What the report actually says
Start with the framing, because the loudest coverage has flattened it. Stokes does not argue that the US should bomb anything. He "stipulates" a world where AGI is imminent or already exists — explicitly declining to make a technological judgment about whether or when it will arrive — and then works forward from that assumption to the choices policymakers would face.
The analytical core is more interesting than the escalation ladder. Stokes proposes five mechanisms through which AGI could shift the US-China balance: boosted economic growth, consolidated influence over the global information environment, new military capabilities, large-scale misalignment or loss of control, and downstream political effects. Each comes with an argued limit, which is unusual for the genre. His most useful finding cuts against the paper's own premise: acquiring AGI "would not automatically convert to geopolitical dominance." The state that has it would still have to turn capability into wealth, power and influence, and would have to do so cost-effectively relative to the alternatives. Sometimes, he writes, that conversion "could prove unworkable."

He is similarly skeptical about the other side. Reading China through four interpretive lenses, Stokes concludes that Beijing's approach is "a messy and still-developing mix of all the lenses" — AGI is "moving up the priority list" of Chinese AI policy, but it is not the North Star it has become in Silicon Valley, "at least not yet — and it might never be."
That is a genuinely moderating finding, and it sits awkwardly beside the recommendation list, which includes preparing to "reverse engineer or steal AGI technology if China gets it first" and conducting "a scenario exercise to test when and how the United States might intervene to stop China from developing AGI." Intervention, in the escalation ladder Stokes lays out, runs from diplomacy to espionage to offensive cyber to the option he calls last: "kinetic attacks, meaning destroying things with missiles and bombs." His own gloss is blunt about what that would mean — bombing "would cross a major threshold that heretofore has not been crossed in US-China relations," and "data centers can be bombed with conventional munitions."
Note the tense. Stokes is not calling for strikes; he is calling for the intelligence work that would precede a decision to strike. At the event on Thursday he said the Defense Department and the NSA should begin assessing "what intelligence they would need to justify taking such actions," working backwards from the technology to the policy "in the same way that in a past era, policymakers would learn about nuclear weapons." The nuclear analogy is doing enormous work in this paper, and it is where the argument is weakest.
Why the nuclear analogy fails
The nuclear parallel is seductive because it offers a ready-made vocabulary: deterrence, escalation ladders, arms control, mutually assured destruction. Stokes reaches for it deliberately. But the properties that made nuclear deterrence tractable are exactly the properties AGI lacks.
Warheads can be counted. Fissile material is physically hard to make and leaves detectable signatures. Delivery systems are large, expensive, and visible from orbit. That observability is what made treaties possible — you cannot verify what you cannot see, and the entire Cold War arms control architecture was built on the fact that you could, imperfectly but adequately, see.
None of that transfers. A training run is not a warhead. Capability is determined by weights that fit on a hard drive, by algorithmic techniques that can be written down in a paper, and by tacit knowledge held in the heads of a few thousand researchers. The physical plant — the data centers Stokes proposes as targets — is the most countable part of the stack and arguably the least important. Frontier labs have spent years demonstrating that the same capability can be trained on more or less compute, and that much of the advantage lives in methods that export easily. Blowing up a building destroys the most replaceable input in the system.
Stokes half-acknowledges this. He notes that AGI's emergence may be "neither discrete nor observable," which would scramble the phase model his framework depends on — you cannot calibrate intervention against a threshold you cannot detect. But the paper never reckons with what that does to the nuclear framing. If you cannot see the object of deterrence, the deterrence is theater.

The deeper problem is the premise. Stokes stipulates AGI rather than arguing for it, and the stipulation launders an enormous assumption. This is the same week OpenAI declared "we are now in the AGI era" at the GPT-6 Astra launch — a claim we argued is flippant but not solely OpenAI's fault, because the field has never defined the term it keeps using (The Take — Calling Astra AGI is flippant. The field's silence is worse). A security analyst building a war-fighting scenario on top of an undefined marketing word is not building on bedrock. If AGI is whatever a company declares it to be on launch day, then "China is about to achieve AGI" is not an intelligence assessment; it is a press release with missiles attached.
The skeptics' case, which is strong
The sharpest criticism came from William Hartung of the Project on Government Oversight, who called the idea "the height of recklessness," warning it risks "a shooting war between two nuclear-armed powers." That is the core of it, but three further objections deserve more than a line.
Chinese data centers are not military installations. They host civilian traffic, hospital records, banking systems, and a great deal of computing that has nothing to do with frontier training. A strike framed as counter-proliferation would, in practice, be an attack on civilian infrastructure with an unusually large blast radius — and one where the attacker's own claim about what the facility was doing is the only evidence anyone outside the targeting cell would see. The legal exposure is considerable; the precedent is worse. Once "it might have been training a dangerous model" is accepted as sufficient, every country with an AI industry has a casus belli against every other.
The retaliation surface is asymmetric and near. Hu Xijin's threat is the loud version of a quieter reality: China does not need to reach the continental United States to respond proportionally. Undersea cables, internet exchange points, semiconductor fabs in allied Asia, and the cloud regions of US multinationals are all closer, softer, and more deniable than a missile silo. A doctrine that treats server farms as strategic targets hands every adversary an argument for treating them the same way — and the US has far more of them, in far more countries, than China does.
It collides with domestic politics the industry is already losing. You cannot simultaneously tell American communities that data centers are critical national infrastructure and tell a security audience that they are legitimate targets. The domestic buildout is already fighting a hard political fight: three out of four Americans now oppose a data center being built near them, up from 42 percent a year ago (The Take — The data center backlash is the new NIMBY tax on AI). Militarizing the category makes every one of those fights harder. Why should a county approve a substation for a facility that a think tank has publicly designated a bombing target?
What actually changed this week
Strip away the missiles and the report still marks something real, and it is the part worth watching.
For a decade, the governing metaphor for US-China AI competition was the chip war — export controls, entity lists, restrictions on advanced semiconductors and the tools that make them. That framework was about supply: deny the inputs and the capability cannot be built. It was bureaucratic, slow, and mostly civilian in character.
Stokes's paper is an early artifact of a shift from denying inputs to threatening facilities. That is a different logic with a different escalation profile, and it did not originate with him. Eliezer Yudkowsky floated destroying "a rogue data center by airstrike" in 2023. What is new is the institutional address: CNAS is a mainstream organization with deep ties to the Democratic foreign policy establishment, and its reports get read by the people who staff national security councils.
The tell is in the recommendations that are not about bombs. "Develop a technically sophisticated way to track inputs to AGI as well as key performance thresholds for frontier AI systems" is a call for a verification regime — the thing that does not currently exist and that any future arms control would need. "Create diplomatic channels with allies and China focused on AI" is an admission that the competitive frame alone is unstable. Read those two together with the escalation ladder and the paper's real structure comes into focus: it is an argument that the US has no doctrine, no measurement capability, and no channel for a problem it may soon have to manage, and that improvising at that point would be worse than thinking now.
That argument survives even if you reject every word about kinetic options. There is no hotline, no inspection regime, no agreed definition of what would count as crossing the line, and no taboo against attacking AI infrastructure. There is not even agreement on the thing being raced toward — our own reporting this week on benchmark claims being quietly rewritten after publication is a reminder of how far the field is from measuring itself, let alone from a shared international standard.
What to watch
Three dates and one process. US and China officials are expected to discuss AI safety risks in talks planned for mid-September, with Treasury Secretary Scott Bessent leading the American side. Trump and Xi are set to meet in Washington on September 24 with AI governance confirmed on the agenda. Those are the two near-term venues where any of this could get walked back, formalized, or quietly shelved.
The process to watch is whether anyone in government actually commissions the scenario exercise Stokes recommends. If the answer is yes, the interesting question becomes who runs it and whether the results are classified — a secret war game about destroying data centers is the worst of both worlds, producing no public deterrent and no public debate. If the answer is no, the paper joins a long shelf of speculative strategy documents, and the threshold stays uncrossed.
The third thing is smaller and more diagnostic: whether any US official is asked about this on the record and refuses to rule it out. A non-denial from a sitting administration official would move this from think tank to doctrine faster than any report could.
Should a national security establishment be planning for strikes on another country's AI infrastructure — and does saying so make anyone safer? Tell us in the comments.
Sources: CNAS — Superpowers and AGI (Jacob Stokes) · South China Morning Post — US urged to consider military strikes to stop China achieving AGI first · Futurism — Former Obama official floats bombing China's data centers · BizTech Weekly — U.S. National Security Expert Advocates Military Strikes on Chinese AI Data Centers · AI Midday — The Take: Calling Astra AGI is flippant. The field's silence is worse · AI Midday — The Take: The data center backlash is the new NIMBY tax on AI