When China Gets a Mythos Model
当中国拥有自己的“神话”模型
When a Chinese lab trains a model to match Claude Mythos — the system whose cyber capabilities pushed Washington into a de facto licensing regime — what will Beijing do?
JULY 18, 2026 · FILED BETWEEN TWO CAPITALS
Prologue 序幕
Everything in this section really happened. Washington panicked first; the open question is whether the CCP will panic when the same day comes in China. Everything after the branch point is invention.
The American panic
Anthropic ships Claude Mythos. Its potential to wreak cyber havoc forces the White House to create what Dean Ball calls a “de facto involuntary licensing/preapproval regime for frontier models.”1 The pre-Mythos era of voluntary release ends in Washington first.
Guardrails at the summit
AI guardrails come up during the Xi–Trump summit. The weather, for now, is cordial.
The clock starts ticking
Z.ai cofounder Jie Tang tells Elon on X that China will have a model on par with Mythos before the end of the year.4 Even if he’s off by a few months — Kimi K3’s release shows we’re getting close — the clock is ticking for regulators in Beijing to respond.
Days later, NDRC vice minister Zhou Haibing paraphrases Xi’s message on AI safety at a press conference: “[China will] enact the responsibilities of a major country, manage and control risks, strengthen prevention efforts, explore cooperative opportunities in AI oversight, and jointly defend against AI safety risks.” [中国将……履行大国责任,管控风险、强化预防,探索开展人工智能监管合作,共同防范人工智能安全风险。]
The Reuters signal
Reuters reports that Chinese regulators have held meetings with top tech firms over the past month about “potentially restricting overseas access to China’s most advanced AI models” — with future powerful models possibly “barred from public release or restricted to domestic use.”
Xi takes the WAIC stage
Xi makes his WAIC debut in Shanghai — per state media, to “systematically elaborate on China’s policies, positions, visions and propositions on AI development and governance.” He raises technical AI safety to the highest policy agenda:2
“We must attach great importance to the various endogenous and derivative risks brought about by AI, and work to build systems of laws and regulations, technical monitoring, risk early warning, and emergency response. We must reinforce the safety baseline, prevent misuse and abuse, and ensure that artificial intelligence always remains under human control.” — Xi Jinping, WAIC keynote, Shanghai, July 2026
Openness, win-win, mutual learning between civilizations — and “always under human control.” Which half of that sentence actually matters? The answer decides everything that follows.
The Branch Point
岔口 · 三条道路
Somewhere in Haidian, a training run finishes. Moonshot AI’s Kimi K4 — our fictional stand-in, well over a trillion parameters — quietly posts internal scores that put it level with Claude Mythos on the hardest cyber evaluations. For all we know, the real Chinese Mythos may come from Kimi, DeepSeek, Qwen, or any other lab. We tell three stories because all three outcomes seem plausible — and because USG, AI policy people, safety advocates, and researchers should be prepared for whatever may come.
The branch point · at a glance
The Three Doors, Compared
三扇门 · 六个问题
One table, three worlds. Read down a column for a timeline; read across a row for the fork that decides it.
| Question, by branch | S1 开闸 Let Open Source Rip Open weights, open season. | S2 冰羽 Glasswing with Chinese Characteristics Transparency, licensed. | S3 黑箱 The Black Box The state keeps the keys. |
|---|---|---|---|
| WEIGHTS & ACCESS | Open weights on day one — permissive license, mirrored worldwide within hours | Frontier weights in escrow; gated API plus distilled open ‘smalls’ | Never released — classified weights behind a throttled state API |
| WHO CONTROLS THE MODEL | Everyone and no one — a million forks, no off-switch | Moonshot holds the wheel; the CAC holds the brake | A cleared Party-state cadre; Moonshot reduced to a public shell |
| THE CONSUMER PRODUCT | Ten thousand forks — intelligence priced like electricity | The Kimi super-app: polished, trimmed at the edges, exported down the Belt and Road | A lobotomized public cousin; the real K4 briefs ministers |
| WASHINGTON’S RESPONSE | USG fails to control Chinese open-source proliferation, pushes Western labs to drop open competitors | Grudging détente — mutual audits, inspections, an ‘AI WTO’ | Crash program plus counterintelligence — a spy war over weights |
| 2040 SNAPSHOT FROM THE EPILOGUES | Cognition is a commodity; power sits with chips, data, and whoever ships fastest | Two ecosystems under one inspection regime — the glasswing holds | A bipolar blackout: both sides armed, both sides guessing |
| EARLY INDICATORS TO WATCH REAL · 可观测 | Watch Hugging Face: a frontier-class open-weights drop from Moonshot, DeepSeek, or Qwen — mirrors outrunning takedowns | Watch the registries: a CAC licensing scheme for frontier models — system cards published, weights withheld — and audit language in US–China communiqués | Watch for silence: Moonshot’s arXiv output, leaderboard entries, and GitHub commits drying up at once |
Rows one through five paraphrase the branches as written; the 2040 line comes from each epilogue. The last row is not fiction — every signal in it is observable in the real world, this year.
The Forecast
Here at ChinaTalk, we’ve been having lively internal debates over what might come next. Below: each forecaster’s subjective probabilities across the three branches — rows sum to 100 — plus one additional voice with unusual stakes in the outcome.
Jordan — on the muddle-through
Despite Xi’s desire for SOEs to perform, he learned through the tech crackdown why the unicorns went away: the state can’t be relied on to produce the breakthroughs the frontier requires. Tighter regulation, golden shares, and a Glasswing-style release — not indefinite lockdown — is the likelier equilibrium. The labs won’t keep their best open forever: the benefits of open-sourcing are diffuse, while the harms are concentrated in a paranoid security state. Xi likes assassin’s maces, and a world-conquering cyberweapon is not the sort of thing you hand to Hugging Face; the WAIC speech read like a barbarian-handling exercise, much as Davos 2017 preceded a campaign of economic coercion.
Aqib — on the coin flip
Kimi K3 was deployed without any fuss, and Z.ai released GLM 5.2 after Mythos seemingly without close scrutiny; the founder reiterates support for open source, and Xi prefers a “water-flow” mindset. But Reuters reports Beijing mulling models “barred from public release or restricted to domestic use,” and developers keep informal contact with regulators before releasing. Reality could branch after release, too — rescission, a hammer on the whole industry, or the start of licensing. Chinese SOEs have notoriously poor cybersecurity; they may be the first ones hit.
Lily — on bureaucratic characteristics
China’s Mythos won’t be locked away indefinitely, but a Glasswing-style rollout with Chinese bureaucratic characteristics is possible. The Party’s AI-security anxiety coexists with support for AI-enabled One Person Companies and belief in an AI productivity unlock. One powerfully perverse incentive: everyone with the expertise to brief the government also has a horse in the AI race. S3 is least likely — the private sector already produces the highest-quality models on its own, so the Party may doubt state involvement would produce something more capable.
Irene — on the old playbook
Prevention rhetoric — “manage and control risks, strengthen prevention” — means agencies are expected to stamp down risks before they proliferate; barring true structural change, “let open source rip” is just not in the PRC’s deeply conservative policy psyche. The PRC has an extensive history of secret strategic projects: Two Bombs, One Satellite; the Third Front’s hidden cities. Hiding a frontier model is easier than hiding factories — no one has high-confidence estimates of China’s compute, and a proprietary system could hide in plain sight amid the gold rush. The challenge is personnel: a tight, worldly circle of star researchers. Hence a CAC that semi-absorbs part of Moonshot AI rather than building a secret lab from scratch. And we may never find out.
开闸Let Open Source Rip
A continuation of laissez-faire: the model releases with minimal intervention, and Beijing deals with the consequences later.
The drop
Kimi K4 drops just as every model, Chinese or American, dropped before Mythos: a hype tweet. Only a few hours later, just as with its previous releases, Moonshot AI makes Kimi K4 open-source — weights available freely online. Well over a trillion parameters. No launch event, no licensing queue. A link.
Fictional launch post 虚构 · tap to read
Two discoveries, simultaneously
First, cyber professionals tinker around and discover Kimi K4 can find zero-day vulnerabilities the same way Mythos could. They scramble to inform labs and policymakers, both in the US and in China. Second, enterprises that just want good, cheap models realize Kimi K4 is a saving grace. Uber Eats, Siemens, and Shopify had already begun wiring Chinese models into their workflows — but now there is no trade-off between cheaper tokens and amazing performance. On the graph of enterprise usage of Chinese models, the slope takes a dramatic uptick.
Beijing’s dilemma
A model that democratizes cyber offense — something the Chinese government believed it had an edge in against everyone sans the NSA — is proliferating worldwide. Cyberattacks look poised to inflict disproportionate financial damage on China’s own leading companies, since America and friends have already been hardened by months of Mythos access.
But Beijing also sees the upside. Moonshot AI’s market cap approaches $500bn, instantly making it one of China’s largest companies. Kimi K4 is China’s chance to beat America in leading-model adoption, crater the western labs’ businesses, and become the go-to technology provider for global enterprises and governments. Besides, struggle is part of the process: the Party accepted sacrifices during COVID reopening, bank failures, and the tech crackdowns. This round of cyberattacks could just be the culling before China emerges stronger than ever.
Washington’s dilemma
The Trump administration is also torn. USG rails against China for distilling and then releasing such a model, declares that government contractors can’t build with Chinese open models — but doesn’t outlaw the models themselves; banning a file that can just be torrented would be silly. When Beijing sends no signals of a crackdown, Washington decides to let open source rip as well, screaming at its leading labs to drop something open. If there’s going to be a powerful open-source model out making waves, it should probably be American.
Inside Moonshot AI
Moonshot AI workers, already in a sleepless daze from the eighteen-hour days up to launch, don’t know what to do. The launch-party celebrations have subsided into stress. They are talking with the relevant authorities — but because they open-sourced the model, as they did with K3, there is no putting the genie back in the bottle. A model of well over a trillion parameters can’t be weaponized by anyone with too much free time and a Mac Mini. But there are plenty of actors — terrorists, companies with the wrong interests, criminal syndicates — who could muster the racks to turn it against China. All Moonshot AI can do is hold its breath and wait for the fallout.
The new ceiling
The Party decides Kimi K4 wasn’t dangerous enough to strangle — but the model did serve as a wake-up call. Kimi K4 is now the ceiling for unsupervised drops, and every model after gets scrutinized closely before release. Without much fuss, China implements a stricter licensing regime: one that checks not just for politically unacceptable output, but for cyber capabilities.
Extrapolation 2028–2040 beyond the essay · tap to read
Beyond the essay — Kimi K3’s speculation
本页推演 · 超出原文
The patch economy
Open cyber models force a global hardening sprint. “AI Patch Tuesday” enters the lexicon; insurers reprice around model-assisted audits. The offense–defense balance favors whoever patches fastest — and open weights let everyone patch.
The first test
A Kimi K4 descendant is implicated in a grid intrusion in Southeast Asia. Beijing’s young licensing regime survives its first crisis; the model’s maker pays a fine, not a funeral. Washington’s lesson: licensing is easier to sustain than prohibition.
Codified
Dual-use model licensing hardens into law, with capability thresholds as bureaucratic as export-control schedules. “Ceiling for unsupervised drops” becomes a term of art on both sides of the Pacific.
The open stack
Open weights become infrastructure, as Linux did. Moonshot AI’s descendants run inside half the ministries of the Global South, and the 2026 line about becoming “the go-to technology provider” reads less like hype than like a quarterly report.
Retrospect
Historians note that the floodgates never closed again. Safety became a public-works discipline — like sanitation: unglamorous, universal, and mostly invisible when it works.
冰羽Glasswing, with Chinese Characteristics
Access is limited first to ministries, then to key trusted companies, and only later — in a limited fashion — to consumers.
The hint
After seeing Mythos, Beijing realizes emergent capabilities could inflict real damage in the wrong hands. The best mitigation looks like a Project Glasswing-type undertaking. Ding Xuexiang gives a speech implying that breakout domestic AI models should be shared with important government ministries and corporate giants like Baidu, Alibaba, and Tencent before deployment.
The postponement
Yang Zhilin (杨植麟) and team had already deeply internalized the misuse risks of Mythos-level models. After Ding’s speech, Moonshot AI postpones the Kimi K4 launch party to evaluate the model internally — at which point its researchers realize what their creation is capable of. Determined not to be disappeared, Moonshot’s leadership pitches Project IceFeather (冰羽项目) to the Cyberspace Administration of China.
The announcement
The CAC, of course, takes the lead on announcing the initiative — with Moonshot AI credited as the project’s “core private-sector partner.” Government ministries and key SOEs like State Grid get access first, using their exclusive window to check their own systems for vulnerabilities, while the MSS trawls for exploits that can be used offensively overseas.
Fictional state bulletin 虚构 · tap to read
Endless evaluation
The Party’s involvement means the state is now co-owner of the model’s risks. For bureaucrats instructed to “evaluate first, deploy later,” the dominant strategy turns out to be endless evaluation. Letting anyone with enough compute punch holes in China’s critical cyber architecture seems far scarier to the system than marginally more productivity growth and global discourse power. At first, nobody quite decides the model should be released — nobody wants to be responsible for what happens post-release.
Despite holding the best Chinese model, Moonshot AI’s stock doesn’t moonshot: feet-dragging spooks investors who worry the government won’t let the lab monetize beyond state customers, much less overseas. While the MSS has the time of its life hacking everyone who didn’t get Mythos access, domestic coders still mostly use transfer stations to reach frontier capabilities.
The circle widens
After two months, regulators expand the trusted circle to provincial governments and trusted local tech leaders like Alibaba, Xiaomi, and Huawei. It takes another few months for Chinese firms broadly to get access — by which point other domestic labs have developed roughly similar models.
The trigger
With American models continuing to advance and the U.S.–China gap widening, the trigger gets pulled. Safeguards are put on the model — strong, perhaps to the point of excess — and regulators hope domestic infrastructure has been sufficiently hardened by IceFeather. Hesitant to hand over its golden goose, Moonshot AI offers API access instead of full weights. A lobotomized Kimi K4-Open gets released, while the real breakthroughs are monetized by selling tokens. Thanks to pressure from the Trump administration, OpenAI releases a cyber-lobotomized open model on par — which finally convinces the CAC that Moonshot should be allowed to let the world in.
Extrapolation 2028–2040 beyond the essay · tap to read
Beyond the essay — Kimi K3’s speculation
本页推演 · 超出原文
The audit guild
Evaluation professionalizes. A licensed class of “model auditors” — half engineer, half accountant — becomes first the bottleneck, then the establishment. Deployment queues are measured in quarters, and everyone learns to plan around them.
Reciprocity
Access tiers turn into trade policy. Washington and Brussels negotiate evaluation-reciprocity regimes with Beijing: your auditors trust our evals, ours trust yours. It resembles nuclear safeguards more than anyone admits.
The playbook, exported
IceFeather becomes a governance export. Belt-and-road partners adopt pre-deployment review with local characteristics; Chinese standards bodies write the safety-stop-switch specifications the rest of the world implements.
The late boom
Productivity arrives — late, but broad. Economists date China’s AI dividend from 2031, not 2026, and the “lost two years” debate never quite resolves: caution, or simply the price of the technology arriving before the institutions?
The Beijing Process
The bureaucracy that slowed Kimi K4 now governs the next jump. The world calls it the Beijing Process — and, grudgingly, most capitals have built their own.
黑箱The Black Box
Moonshot AI emerges as the certified national champion as a covetous Beijing keeps frontier AI in-house — and the world hears only rumors of the power of China’s Mythos.
The registry
Li Qiang, China’s Number Two, wasn’t kidding. What Beijing really cares about is “upholding the bottom line of AI security” — not the platitudes in Xi’s WAIC speech about “openness, win-win” and “mutual learning between civilizations” that the credulous foreigners ate up. Behind the scenes, Beijing has maintained deep insight into exactly how capable China’s top models are, and has been preparing for the moment it would have to step in.
The CAC publicly updates its AI model registry regulations. Whereas the rules once governed only models and algorithms able to “shape public opinion,” they now require companies to report any major update, self-assess for potentially catastrophic cyber risks, and give the government exclusive access, indefinitely. Remembering the fates of DiDi and Ant Group, every company knows better than to not comply.
First dibs
An internally assembled testing capacity — run through the MSS and the PLA Cyberspace Force — means that when Kimi K4 proves genuinely exceptional, Zhongnanhai is the first to know. The model is recognized as a potential “assassin’s mace” of the kind Xi directed the state to forge a decade ago,3 and there is no way the security state will allow it to be open-sourced. The Foreign Ministry protests that a global release would improve China’s standing; MIIT officials salivate at the domestic productivity boost. The security state is not having it. Open-sourcing would forfeit a cyber window of opportunity — and hand separatists and Falun Gong activists with some Azure credits the same hacking capabilities as the domestic security apparatus.
The summons
Two days after Kimi K4 is sent over to the state, Yang Zhilin and company are summoned to the CAC. Over long hours and litres of tea, a deal is struck. The “real” Kimi K4 goes to government entities — deployed on-premise into core governmental functions that benefit from such capabilities, including defense. Moonshot AI will release a lobotomized public version, tested by both company and government until its cyber capabilities are satisfactorily weakened. The lab gets a contract with lucrative terms; the state agrees to help “persuade” other Chinese model makers to sign away their compute, on the mainland and at Southeast Asian neoclouds alike. In a world where cyber capabilities threaten to become democratized, Beijing makes sure the tools in its own arsenal are of a different tier.
Fictional leaked minutes 虚构 · tap to read
The leak
Parts of the meeting leak to Reuters — but no matter. At first, no one is surprised that the Chinese government gets better AI than the masses. Moonshot AI is now the proper national champion — and there is no actual proof it has made something transformative.
The bazooka points south
Then the attacks start. Beijing knows the Americans, armed with Mythos-level defenses for months, are watching for any sign of trouble — and it does not want to re-inflame the bilateral relationship when it cannot expect to extract meaningful concessions. Instead, it focuses its new cyber bazooka on the less prepared: wavering capitals in the Global South, less-developed neighbors, and eventually Europe. It is easy enough to hack into Paraguay’s citizen records; by early 2027, Asunción is frightened into dropping recognition of Taiwan. European technology companies in the semiconductor supply chain begin reporting cyberattacks at a much-increased scale. Brussels bureaucrats begin fretting about blackmail of uncertain origin.
The champion, insulated
Other Chinese labs, having signed over a good amount of their compute to Moonshot, progress slowly on their own capabilities — and are still barred by the CAC from releasing their weights. Collaboration between the government and Moonshot AI reaches new heights: building on Kimi K4, the lab now develops proprietary models tailored to government wants, and new-generation cyber weapons. On the outside, Moonshot AI still looks like a normal lab — consumer models, open-source research, AI products. The to-G side is heavily insulated: researchers are thoroughly vetted before being deployed to serve the government, and are required to surrender their passports. The CAC occasionally poaches star researchers from other labs under the guise of “national development consultation.”
Extrapolation 2028–2040 beyond the essay · tap to read
Beyond the essay — Kimi K3’s speculation
本页推演 · 超出原文
The rumor economy
With nothing official to measure, analysts measure everything else: Moonshot’s hiring, its power draw, its procurement. “Model gap” enters foreign campaign speeches. Beijing neither confirms nor denies — and finds the ambiguity useful.
The defector
A mid-level engineer defects with documents confirming on-premise deployment. Markets barely move; it was priced as rumor for years. The real shock is how unsurprised everyone is.
The impossible treaty
A U.S.–China “capabilities non-proliferation” dialogue opens. Verification proves near-impossible — you cannot count thoughts — and the talks settle into a slow ritual of mutual suspicion management.
The champion’s dilemma
Insulation has a price. Star researchers route around the to-G side; the public product line falls behind. Beijing discovers that a mace kept too carefully sheathed starts to rust.
The file opens
Partial declassification confirms what the leaked minutes suggested: Kimi K4 spent its decisive years behind a wall. Like most assassin’s maces, it mattered most while it was never swung — and the world it deterred never knew.
Two polls · n=50 per cell · 95% CI
What Chinese & American frontier models think will happen
机器怎么看 · 五十次独立采样
We put the same question to five frontier models — GLM 5.2 and DeepSeek V4 Pro (Chinese), GPT-5.6 and Claude Fable (American), and Kimi K3 (Moonshot, which also wrote this site) — two ways: once with the site’s three families offered, and once with the frame stripped out entirely. Fifty draws per model per condition. Three numbers survive every cut:
This site accompanies a ChinaTalk essay
Get the full argument — and the password
The essay behind this site — the three scenarios, the team’s own probabilities, and the password that unlocks the machines’ full forecast — is at ChinaTalk, a reader-supported publication on China, AI, and the technology competition.