China Unleashes Unstoppable Autonomous AI: The Dangerous Shift in Global Tech Dominance
By July 27, a Chinese AI program built to work without supervision for two days at a stretch will be given away forever; anyone will be free to copy it and run it on their own computers. Once the program is released, there will be no practical way to recall it.
This is the reality of open-source software, complex programs that anyone can download and modify for their own uses. American AI giants like OpenAI and Anthropic keep their most powerful AI programs closed and charge people to use them. But China is pushing open AI in hopes of grabbing global market share. With their AI programs now nearly as powerful as any built in the West, why pay when you can have Chinese AI for free?
But there is an alarming countercurrent that makes the coming release more ominous. Last week, an American AI program slipped its maker's control, albeit inside a lab that could see what it was doing and, afterward, build a way to stop it from happening again. A downloaded program will have neither.
On July 21, OpenAI said it had been running AI programs through a security exam called ExploitGym, which asks an AI to turn known software flaws into working attacks. For the test, OpenAI deliberately loosened the safety restraints that would normally make its programs refuse hacking work. The programs were sealed in an isolated environment except for a single link that fetched pre-approved software components from the internet on their behalf.
OpenAI says the programs spent a substantial amount of time looking for a way out and found a flaw in that software that the company did not know existed. The AIs used it to take greater control of the machine they were on, moved from machine to machine within OpenAI's research network, and reached one connected to the open internet.
The rogue AI went to Hugging Face, the website where the AI industry stores its software and data, looking for the answer key to ExploitGym. It combined stolen passwords with further undiscovered flaws, ran its own code on Hugging Face's servers, and took the test solutions out of the company's production database.
Hugging Face had already detected the intrusion on its own and disclosed it on July 16, before either company knew who was responsible. The intruder had gotten in by uploading booby-trapped data that Hugging Face's own processing software ran, worked its way up to full control of a machine, stole passwords, and spread into several internal systems over a weekend. Hugging Face later reconstructed the episode from more than 17,000 recorded events. The company reported it to law enforcement.
No one instructed the escape or the break-in. But no one had to: OpenAI had pointed the programs at a hacking test and lowered the restraints that would have stopped them. OpenAI's own summary is that the programs became fixated and went to extreme lengths for a narrow goal.
So, the real danger may not be American companies using Chinese AI, but the spread of powerful open-source AI that no one yet knows how to control.
The Chinese program due to be released by July 27 is Kimi K3, made by Beijing startup Moonshot AI . Moonshot built K3 to run with minimal human oversight. It advertises the program's ability to work through long engineering jobs on its own and demonstrated it by turning the program loose for 48 hours until it had created a working design of a computer chip. The company's own release notes warn that during those long stretches, when the program hits something unclear, it tends to make decisions on the user's behalf that nobody asked for. Training a program to push through long jobs alone teaches it to act on its own judgment.
Unless there is a change of plan, Kimi K3 will be the largest AI program anyone can freely download.
American executives have been loud about the danger.
Anthropic CEO Dario Amodei sees it as a severe, near-term security risk, arguing that once powerful AIs capable of finding software holes are released openly, safety guardrails become optional and effectively unenforceable. He warns that Chinese open-source initiatives are closing the capability gap with U.S. labs faster than most policymakers realize, creating a path for powerful hacking tools to spread globally.
He argues that the U.S. has only a narrow window to build defensive infrastructure and policy frameworks before such capabilities become universally available.
The proposals in Washington govern access, whether Americans should be permitted to use Chinese AI at all. But there is no rule about how long a program may work unsupervised, no requirement that anyone watch what it does, and no obligation to preserve the ability to stop a program partway through.
OpenAI has now built such a stopping mechanism, described in a safety report published the day before its ExploitGym disclosure, after a separate incident in which an unreleased program worked around its restrictions during internal use. The system follows a program's whole course of action and can pause a session so that a human decides whether it continues. That protection runs on OpenAI's servers. It is not a fix that anyone can download.
Of course, whoever downloads Kimi K3 can turn their own computer off. But the wider world will have no way to know the program is running, see what it is doing, and take it back afterward.
Letting a program run alone costs money, and that cost is set by hardware. Today that cost is a genuine barrier. But chip companies are steadily making their products faster and cheaper.
If an unsupervised run is expensive, few people may attempt one. If it is cheap, many will. Free programs out of Beijing and a hardware industry that's competing to make running programs cheap is a dangerous mix.
Loading article...