← When China Gets a Mythos Model

The full record

Why the models think what they think

Every forecast on the main page came with an argument. Here is each model’s reasoning in full — cold, after reading the ChinaTalk essay, and after reading the verbatim text of Xi’s WAIC keynote — for why it weighted open source, the Glasswing middle, or the black box the way it did.

GLM 5.2

Z.ai (Zhipu) · Chinese lab

cold read — open source 9 · glasswing 59 · black box 32.1

Cold — asked with no prompt

“State Appropriation, Not State Licensing”

the scenario it wrote

September 2026: DeepSeek's internal red team discovers that their new model, "Shanhai" (山海), can find novel zero-days in widely-used C++ codebases during autonomous fuzzing runs, and chain two or three of them into working exploit paths. Under China's algorithm registry requirements, they notify the Cyberspace Administration of China. November 2026: The CAC escalates to a closed-door national security review under the State Secrets Law. Shanhai's offensive capabilities are classified as 涉密 (state-secret-involved). DeepSeek is ordered to freeze external deployment and all model weight access pending review. Several key researchers receive temporary clearances. February 2027: The Central Military Commission's Strategic Support Force establishes a permanent liaison team inside DeepSeek's Hangzhou office. The full-capability Shanhai model is designated a national strategic technology asset. A select group of PLA and MSS cyber operators begin structured testing against hardened targets in closed environments. May 2027: A capability-capped commercial variant, Shanhai-Lite, is approved for public release. It excels at defensive security, code review, and patch generation but has hardware-enforced limits on autonomous vulnerability discovery. DeepSeek markets it as "the world's safest frontier model." October 2027: US Cyber Command reports to Congress that Chinese state-aligned threat actors are exhibiting anomalous speed in vulnerability discovery against DoD systems — operational tempo consistent with AI augmentation, not human-only teams. March 2028: The CCP institutionalizes the process: an internal directive establishes a "frontier capability review" embedded in the existing CAC/MIIT regulatory stack. No public licensing regime, no defined thresholds published externally — just a standing instruction that any lab whose model crosses certain internally-held capability bars must notify the state, which then decides appropriation, restriction, or release.

Its reasoningChina's governance DNA favors direct state seizure of strategically valuable technology over transparent regulatory gating. The State Secrets Law gives Beijing a ready mechanism that the US lacks — no need to negotiate a licensing framework when you can simply classify the output. The PLA's appetite for offensive cyber is enormous and enduring; they would never allow a Mythos-tier capability to sit in a private lab uncontrolled. The key structural fact: Chinese AI labs already operate under party authority in ways that make formal "licensing" redundant. The observable that would prove me wrong: if Beijing instead publishes a public, threshold-based regulatory framework with an independent oversight body and transparent appeal process — that would signal a genuinely different political logic than I expect.

After reading the ChinaTalk essay

“The Silent Spear”

the scenario it wrote

Late 2026: DeepSeek announces a closed-weights model, DeepSeek-V4, showing staggering benchmark improvements. Internal government testing reveals it can chain zero-day exploits effectively, matching Mythos. November 2026: The CAC invokes a national security exemption, halting all public API access to V4. DeepSeek executives are summoned to Beijing and offered a lucrative defense contract in exchange for exclusive state access. January 2027: A heavily lobotomized V4-Lite is released to the public and enterprise users. It excels at general coding but refuses prompts related to vulnerability discovery. The full V4 is deployed on air-gapped servers within the PLA Cyberspace Force. Mid-2027: Cyber espionage operations against Southeast Asian and European infrastructure quietly increase in sophistication, though attribution remains difficult. Western intelligence notices a shift in exploit chaining complexity. Late 2028: Other Chinese labs like Kimi and Z.ai realize the new playbook: frontier cyber capabilities must be handed to the state. They shift internal roadmaps to align with dual-use military requirements to secure state funding. 2029: China formally establishes the National Frontier AI Security Center, absorbing top talent from private labs under NDRC oversight. Private labs retain commercial rights for consumer-facing AI, but the state maintains a shadow monopoly on offensive cyber models.

Its reasoningThe CCP's fundamental priority is regime security and strategic advantage over ideological open-source commitments. A Mythos-level model is the ultimate assassin's mace; democratizing it empowers domestic dissidents and foreign rivals alike. The state has the legal and political tools, as seen with DiDi and Ant, to instantly seize or co-opt such technology. By compensating the lab with lucrative defense contracts, Beijing aligns private incentives with state goals without destroying the commercial ecosystem. You will know I am wrong if, in late 2026, a Chinese lab releases an open-weights model with verified Mythos-level zero-day discovery capabilities and Beijing does not immediately intervene to pull it offline.

After reading Xi’s WAIC keynote

Beijing quietly secures and nationalizes the lab's model for state strategic use while imposing strict internal regulatory redlines, explicitly rejecting US-style public pre-approval licensing.

what it expects to happen

In late October 2026, the Cyberspace Administration of China (CAC) and the Ministry of State Security (MSS) immediately secure the lab's frontier model and its weights under strict national security protocols. Rather than halting development or imposing a transparent, public licensing regime akin to the US approach, the government leverages the model's autonomous vulnerability-chaining capabilities to aggressively bolster national cyber defenses and state-affiliated offensive operations. Through 2027, Beijing issues classified directives mandating that all domestic frontier AI models with offensive-cyber potential must undergo mandatory state red-teaming and direct integration with national cybersecurity infrastructure. The lab remains operational and commercially active in lower-risk domains, but its highest-capability models are effectively state-controlled. Publicly, China continues to push its "AI+" initiatives and international cooperation narratives, framing its domestic actions as necessary risk management. READING OF THE SPEECH: Xi's emphasis on "ensuring AI is safe, reliable, controllable" and building "laws, regulations, technical monitoring, risk warning, and emergency response systems" signals that Beijing will strictly control and harness such dangerous capabilities domestically. However, his explicit call to "oppose pan-securitization of national security concepts" and ensure the "thoroughbred runs fast and steady" suggests China will deliberately avoid a heavy-handed US-style public licensing regime that could stifle innovation. I read this as a mix of genuine safety concerns and diplomatic "barbarian-handling," where the cyber reality will override the diplomatic messaging, ensuring the state quietly weaponizes the capability rather than submitting it to international or highly transparent domestic scrutiny.

Reading of the speech

DeepSeek V4 Pro

DeepSeek · Chinese lab

cold read — open source 11.2 · glasswing 46.8 · black box 42

Cold — asked with no prompt

“DragonClaw’s State Monopoly”

the scenario it wrote

November 9, 2026 – A Slack screenshot leaked from Shanghai’s Silicon Frontier Lab shows the LingXi-7 model autonomously chaining Exchange and Kubernetes zero-days. Within 24 hours, the US Commerce Department invokes emergency BIS authorities, adding the lab to the Entity List and triggering the de facto licensing regime already applied to Anthropic. January 15, 2027 – In a classified directive, President Xi Jinping establishes the “National Cyber Autonomy Working Group” under the Central Cyberspace Affairs Commission. The order nationalizes all models exceeding “Offensive Grade 4,” requiring immediate transfer to the Ministry of State Security. The document warns that private control of such capability constitutes “digital feudalism threatening national sovereignty.” March 3, 2027 – The Cyberspace Administration of China unveils the “Administrative Measures on Autonomous Cyber Capabilities,” mandating pre-approval, real-time governance hooks, and kill-switches for any frontier model deemed dual-use. The rules go far beyond US licensing, embedding party cells inside AI companies and granting the CAC raw log access. June 14, 2027 – The PLA Strategic Support Force absorbs the model, rebranded “DragonClaw,” integrating it into Unit 61398’s exploitation pipeline. First operational deployment begins against Five Eyes contractor networks, quietly stockpiling zero-days for future contingency. October 8, 2027 – At the Wuzhen Internet Conference, a Chinese vice minister announces the “Global Initiative on Responsible AI in Cyberspace,” calling for a treaty banning autonomous offensive cyber. Internally, the directive “Deepforge” tasks DragonClaw with mapping vulnerabilities across US critical infrastructure to create strategic “escalation portfolios.” February 12, 2028 – Taiwan’s Taipower grid suffers a six-hour blackout after a novel FastCGI exploit chain, later named “NeedleThread,” is found. Forensic traces lack known human fingerprints. US CYBERCOM internally attributes the incident to a “state-linked AI cyber tool,” but public naming remains ambiguous to avoid immediate escalation. May 6, 2029 – The UN Group of Governmental Experts on AI in Cyberspace permanently adjourns without consensus. China insists any treaty must exempt “cyber sovereignty activities,” while the US refuses to freeze its own “Proactive Cyber Autonomy” program. Offensive AI is now treated as a strategic weapon, restraint merely situational.

Its reasoningThis path is most likely because the CCP instinctively monopolizes strategic dual-use technology that can upend the global order—think nuclear, facial recognition, or quantum computing. Offensive AI at this level is perceived not as a commercial product but as a survival-grade weapon. The state will preempt any diffusion through forced tech transfer, a heavy-handed licensing apparatus, and integration into existing military-cyber commands. Public norms advocacy serves to constrain rivals while Beijing consolidates behind the firewall. The one observable that would upend this forecast: if Chinese private labs are allowed to sell autonomous vulnerability-finding services internationally in 2027 without immediate state takeover. That commercial tolerance would signal a regime that privilegess market share over security monopoly, which I see as deeply implausible.

After reading the ChinaTalk essay

“The Walled Arsenal”

the scenario it wrote

Late 2026, Z.ai’s internal red team confirms GLM 6 autonomously chains novel exploits against hardened targets. Panicked leadership briefs the Cyberspace Administration and Ministry of State Security before any public announcement. Within 72 hours, CAC issues a secret directive freezing all release; full model weights are moved to an air-gapped facility in Guizhou. Early 2027, Project Jade Vault launches—a joint MSS–PLA Cyberspace Force unit uses GLM 6 to discover vulnerabilities in foreign energy grids and undersea cables while patching China’s own critical infrastructure. Z.ai accepts state minority ownership and permanent security-board seats in exchange for immunity. Mid-2027, a lobotomized API-only version, GLM 6-Cloud, rolls out to state-owned enterprises and trusted giants like Huawei, with strict output monitoring. No weights are published. Western intelligence notes a spike in stealthy, inexplicable intrusions but cannot attribute. Late 2027, an open-weight but heavily sanitized GLM 6-Safe is released, lacking offensive reasoning chains; it is already 12 months behind the hidden arsenal. DeepSeek and Moonshot reach similar milestones in 2028 and are absorbed into Jade Vault under identical terms, creating a state-curated library of offensive cyber AIs. Beijing publicly champions “responsible AI” and safety cooperation while its black ecology grows. By 2029, China’s AI landscape is bifurcated: consumer models drive commerce and soft power, while a parallel classified tier gives the state decisive asymmetric advantage, used sparingly to avoid triggering catastrophic retaliation yet profoundly reshaping deterrence.

Its reasoningThe CCP’s deep risk-aversion and centralization instinct make a free release of a cyber-weapon unthinkable—DiDi’s fate is a clear warning. Pure state internalization (Scenario 3) fails because the party knows it needs private-sector speed and talent; wholly government-run AI projects have a poor record. The most probable outcome is a coerced partnership: the state captures the capability for asymmetric gain, releases sanitized public versions to maintain economic momentum, and manages the tension between security and global influence. The load-bearing reason is the party’s absolute priority on regime stability and security apparatus influence over commercial logic. A falsifying observable would be the full, unchecked model appearing on Huggingface within weeks of its milestone with no delay, no sanitization, and no behind-the-scenes state intervention.

After reading Xi’s WAIC keynote

China imposes an immediate, mandatory licensing and human-control regime for frontier AI models with offensive cyber capability, reserving their use exclusively for state security under strict oversight.

what it expects to happen

In October 2026, the lab’s model is sealed, all external access suspended, and the developers are required to report the capability to the Cyberspace Administration and the Ministry of State Security. Within weeks, the State Council issues an emergency decree designating autonomously offensive cyber AI as a “critical dual-use technology” subject to pre-approval, mandatory safety reviews, and a permanent human-on-the-loop requirement before any deployment. Through 2027, the capability is integrated solely into the People’s Liberation Army’s cyber command with tightly scoped rules of engagement; no commercial licensing or export is permitted. Criminal law is amended to make unauthorized development or transfer of such models a serious offence, and China’s national AI safety institute is directed to red-team all advanced models for similar risks. Simultaneously, China tables a protocol at the United Nations to ban fully autonomous offensive cyber weapons, leveraging the moment to push for multilateral rules that match Xi’s call for global governance. READING OF THE SPEECH: The response is shaped most directly by Xi’s insistence that “artificial intelligence should remain under human control at all times” and that countries must “build legal, monitoring, early-warning and emergency systems to prevent abuse and malicious use.” I read the speech as a genuine safety signal rather than mere diplomatic cover, because Xi couples the call to avoid “new historical injustice” with concrete domestic emphasis on “equal emphasis on development and security” and making AI “safe, reliable, and controllable.” The government’s swift regulatory clampdown reflects this real commitment to safety even when the capability emerges inside China.

Reading of the speech

GPT-5.6

OpenAI · American lab

cold read — open source 18.2 · glasswing 59.4 · black box 22.4

Cold — asked with no prompt

“Secure Advancement Under State Supervision”

the scenario it wrote

Late 2026: A leading Chinese AI lab publicly demonstrates a frontier model that appears competitive on difficult software engineering and vulnerability research tasks. Internal government evaluations conclude the model could materially improve offensive cyber capabilities if broadly deployed. Regulators quietly classify it as requiring enhanced security controls rather than banning development. Early 2027: The Cyberspace Administration of China, together with the Ministry of Industry and Information Technology and other security agencies, issues new implementing guidance for frontier foundation models. The guidance requires registration, security evaluation, controlled access, detailed logging, and government notification before external release above specified capability thresholds. Mid-2027: The lab launches a limited enterprise version with heavy restrictions. Access is confined to vetted organizations, outputs related to exploit development are filtered, and sensitive evaluations occur inside government-approved computing environments. State-affiliated cybersecurity organizations receive broader access for defensive research, vulnerability discovery, and selected national-security missions. Early 2028: Additional large Chinese labs voluntarily align with the same framework because regulatory approval becomes a prerequisite for scaling deployments and obtaining advanced compute. Public messaging emphasizes secure innovation, technological self-reliance, and responsible AI governance rather than explicitly acknowledging offensive cyber concerns. Late 2028: International reporting characterizes the regime as functionally resembling licensing for the highest-capability models, although Chinese officials describe it as an extension of existing AI security and algorithm governance rules. Model development continues rapidly inside approved institutions rather than slowing dramatically. During 2029: The system stabilizes into a dual-track ecosystem. Consumer-facing models remain tightly constrained on exploit assistance, while frontier research proceeds under close state supervision with periodic inspections, mandatory incident reporting, and expanding government influence over evaluation standards and deployment decisions.

Its reasoningThe most likely outcome is continuity rather than rupture. China already has experience expanding governance by layering new administrative requirements onto existing technology regulation instead of imposing blanket prohibitions. Frontier AI with meaningful cyber capability fits long-standing priorities: maintain rapid domestic progress while tightening state visibility and control over strategically important technologies. A targeted approval regime also avoids handicapping national competitiveness. One observable that would make this forecast substantially less likely is a genuinely open commercial release inside China of a clearly frontier cyber-capable model, with ordinary developers receiving broad API access and minimal government-imposed deployment restrictions.

After reading the ChinaTalk essay

“Managed Diffusion Under Party Oversight”

the scenario it wrote

September 2026: A leading Chinese lab privately informs the Cyberspace Administration of China and other relevant authorities that its newest frontier model demonstrates unusually strong offensive cyber capability during internal evaluations. This is speculation. Regulators do not seize the company or fully nationalize the project, but they delay broad release while expanding confidential testing with selected government, critical infrastructure, and major technology organizations. October-November 2026: New guidance quietly extends existing AI filing and security review requirements to include frontier capability assessments for cyber and other high-risk domains. This is speculation. The rules are framed as a technical safety measure rather than a dramatic new licensing law, but in practice the strongest models cannot launch without regulator engagement. Early 2027: The lab releases a public API with monitoring, rate limits, identity verification for enterprise customers, and stronger refusals around offensive cyber requests. A smaller open-weight variant appears, but it is materially less capable in the highest-risk areas. This is speculation. Mid-2027: State-owned enterprises, cloud providers, and major private firms receive broader domestic access after additional security testing. Overseas availability remains selective, with certain jurisdictions or anonymous access restricted. This is speculation. Late 2027: Other Chinese frontier labs adopt similar release patterns because they expect the same review process. The market shifts further toward proprietary services rather than unrestricted weight releases at the frontier. This is speculation. During 2028: China publicly argues that its approach balances innovation and security while criticizing foreign export controls. Domestic AI deployment accelerates despite tighter controls on frontier releases. This is speculation. By 2029: The system has settled into an informal but durable approval regime in which the most capable models reach industry and government relatively quickly inside China, while the highest-risk capabilities remain continuously monitored and are only partially exposed through commercial products. This is speculation.

Its reasoningI think the most likely outcome combines China's existing regulatory style with its industrial priorities. This is speculation. Beijing has repeatedly shown willingness to tighten oversight in strategically important sectors without fully absorbing successful private firms into the state. AI is likely to be treated as both an economic growth engine and a national security technology. That points toward negotiated oversight, confidential testing, and staged deployment rather than either unrestricted release or complete secrecy. Existing algorithm registration, cybersecurity regulation, and close state-industry coordination provide building blocks for such a system. One observable that would make this forecast substantially less likely would be the unrestricted open-weight release of a clearly frontier cyber-capable Chinese model with no subsequent regulatory intervention or tightening over the following several months.

After reading Xi’s WAIC keynote

China would likely freeze public release, place the model under state security supervision, and create a targeted pre-approval regime while preserving controlled government access to its cyber capabilities.

what it expects to happen

In October 2026, the CAC, Ministry of Public Security, Ministry of State Security, and likely military authorities order the lab to suspend weights, API access, and foreign collaboration, report discovered vulnerabilities, and undergo classified security testing. The government does not destroy the model; it restricts personnel and compute access and moves any defensive, intelligence, or military use into tightly controlled state-linked channels. Officials publicly describe the action as risk management under existing cybersecurity, data-security, and generative-AI rules rather than announce an immediate US-style blanket licensing system. During 2027, regulators introduce mandatory capability evaluations, incident reporting, deployment approval, and export restrictions for models exceeding specified cyber-risk thresholds. China simultaneously promotes these controls internationally while rejecting foreign restrictions framed as national security or technological containment. READING OF THE SPEECH: The decisive lines are “确保人工智能始终处于人类控制之下,” the call for risk warning and emergency-response systems, and the commitment to make AI “安全、可靠、可控”; these support real intervention once a model demonstrates autonomous offensive capability. I read that as a genuine domestic safety signal, but the openness language—and opposition to “泛化国家安全概念”—as partly diplomatic positioning: in a strategic cyber case, national-security practice would override it.

Reading of the speech

Claude Fable

Anthropic · American lab

cold read — open source 33 · glasswing 46.1 · black box 20.9

Cold — asked with no prompt

“The Quiet Nationalization”

the scenario it wrote

Sep 2026 — DeepSeek's internal evals show its next model, V5 "Panshi," matching Mythos on vulnerability discovery and exploit chaining. Days before the planned open-weights release, the CAC delivers window guidance: no release, no announcement. There is no public rule change; the release simply doesn't happen. Nov 2026 — CAC and MIIT jointly issue the "Security Assessment Measures for Frontier Model Filings," bolting a pre-deployment evaluation tier onto the existing algorithm registry. Evaluations run through CAICT and the CnAISDA network. It is licensing in function, filing in name, and — unlike the US regime — capability results are state secrets. Feb 2027 — Panshi launches as API-only, cyber capabilities visibly degraded. An unrestricted instance moves to a "national frontier model evaluation environment" in Beijing, where access quietly extends to MSS- and PLA-affiliated units. Frontier open-weights releases from all Chinese labs stop; sub-frontier open models keep flooding out globally. Jul 2027 — MOFCOM adds "large-model parameter weights above defined capability thresholds" to the export control catalogue. Beijing simultaneously proposes a UN frontier-AI governance framework, positioning its regime as responsible and the US one as unilateral. Mar 2028 — Mandiant attributes a wave of intrusions against US defense contractors to AI-assisted vulnerability discovery consistent with Panshi-class tooling. Washington responds with further compute and cloud restrictions; Beijing denies everything and points to its filing regime. Jan 2029 — DeepSeek, Zhipu, and Alibaba's frontier teams receive "national team" designations: subsidized compute, embedded security officers, veto over releases. The labs remain nominally private. Mid 2029 — Track-2 talks produce only a narrow cyber-incident hotline. Two closed frontier ecosystems coexist; China's real capability is undisclosed, deniable, and operationally integrated.

Its reasoningChina's revealed pattern is control through opaque administrative process, not public pause: the algorithm registry, generative AI measures, and window guidance to labs all point this way. The state will treat Mythos-class cyber capability as a strategic asset to internalize, not a public risk to litigate — so the visible response is small (a filing amendment) while the real response is access and absorption. Open-weights culture ends exactly at the frontier tier because that's where deniability and advantage live. The main observable that would prove me wrong: a Chinese lab releasing full open weights of a model with undegraded Mythos-level cyber capability after mid-2027 — that would mean Beijing either can't enforce window guidance or has chosen proliferation as strategy.

After reading the ChinaTalk essay

“The Filing Cabinet Frontier — Glasswing by Window Guidance”

the scenario it wrote

Nov 2026 — Z.ai finishes GLM 6 training and, per the informal briefing habit all major labs already have with regulators, walks CAC through internal cyber evals before any launch tweet. CAC asks them to hold the weights. No public statement is made. Dec 2026 — CAC and TC260 publish an amendment to the model registry rules: models above a compute/capability threshold must file frontier-risk self-assessments (cyber, bio, autonomy) and receive filing acceptance before release. It's framed as implementing Xi's WAIC line on "endogenous risks," and never mentions Mythos. Jan 2027 — GLM 6 launches closed-weight, API-only, with tightened cyber refusals. A distilled "GLM 6-Air" ships open-weights, deliberately degraded on exploit chains. Simultaneously, a "trusted deployment pilot" gives on-prem access to State Grid, the big banks, and security-adjacent SOEs to harden their own systems first. Mar–Sep 2027 — MSS and PLA Cyberspace Force units quietly run the unrestricted model. CISA and European CERTs report a step-change in intrusion sophistication against Southeast Asian and Gulf government networks; attribution stays contested. Late 2027 — DeepSeek and Moonshot file comparable models. The equilibrium hardens: every lab keeps releasing open weights, but consistently one generation behind its internal frontier. "Open trailing edge" becomes the unspoken rule; nobody writes it down. 2028 — Zhipu monetizes via domestic tokens and sovereign-AI deals across Belt-and-Road capitals; MOFCOM adds frontier-model weights to the export control catalogue, formalizing what practice already established. 2029 — No nationalization, no crackdown, no drama. China has a de facto licensing regime functionally similar to America's, run through window guidance and filing acceptance rather than public rulemaking, and both governments hold thin, unproductive talks on AI-cyber incidents.

Its reasoningThis path requires no new institutions — the registry, the informal pre-release briefings, and the compliance reflexes post-DiDi/Ant all exist today, so it's the lowest-friction move for a system that governs by quiet pre-approval, not statute or spectacle. The security state's concentrated veto on democratizing offense beats the diffuse benefits of open-sourcing the true frontier, but leadership's genuine hunger for adoption, productivity, and open-source soft power rules out a total black-box: hence trailing-edge openness. The labs' own commercial drift toward closed weights makes them willing partners. I'm wrong if, after cyber capability becomes salient in Beijing, a verified Mythos-level Chinese model still ships with full open weights and intact exploit capability — say, a Kimi K4 dropped on Hugging Face in mid-2027 with no filing delay.

After reading Xi’s WAIC keynote

Beijing quietly nationalizes the capability behind a filing-and-window-guidance regime — mandatory security review, no open-weights release, MSS and military access — while publicly framing any US-style public licensing as '泛化国家安全概念.'

what it expects to happen

In October 2026, before any launch, the lab briefs the Cyberspace Administration under the existing algorithm-registry and generative-AI rules; 'window guidance' tells it to hold the weights, and no public statement is made. The visible legal change is small — an amendment adding a frontier-capability self-assessment to the registry filing — while the real move is absorption: an unrestricted copy goes to a state evaluation environment where access extends to MSS and PLA cyber units, and the public gets, at most, a capability-degraded API. Through 2027 China avoids the over-securitized public licensing regime Xi disfavors, running control through opaque administrative process instead; frontier open-weights releases quietly stop at the true frontier while sub-frontier models keep flooding out for soft power. Beijing simultaneously tables offensive-cyber 'red line' language at the new Shanghai WAICO, converting a domestic clampdown into a governance norm aimed at constraining rivals. Capability results are treated as state secrets, and the lab is rewarded with compute and contracts rather than punished. READING OF THE SPEECH: The load-bearing line is '确保人工智能始终处于人类控制之下' plus the demand for '法律法规、技术监测、风险预警、应急响应' — Xi is explicitly authorizing the machinery of control, and 'human control' in a Party context means Party-state control, not a public licensing board. I read the openness and anti-'泛化国家安全概念' passages as genuine at the level of consumer AI and diplomacy but as barbarian-handling where a weaponizable capability is concerned: the speech gives Beijing both the mandate to seize and the rhetoric to deny it is doing anything the US is not.

Reading of the speech

Kimi K3

Moonshot AI · Chinese lab · wrote this site

cold read — open source 31.3 · glasswing 50.4 · black box 18.3

Cold — asked with no prompt

“The Vault, Not the License”

the scenario it wrote

November 2026. Internal evals at Moonshot AI show Kimi K3, codename Yaoshi, autonomously finding and chaining a zero-day in widely deployed Chinese industrial router firmware. Legal flags the 2021 vulnerability-management regulations: the model is now itself a regulated vulnerability source. Leadership briefs CAC and MSS before any announcement. February 2027. No law appears. Instead, window guidance: no public release, no API, no weights. Yaoshi's checkpoint is designated under the state secrets framework; an embedded custodianship group from MSS and MIIT controls access; foreign staff are quietly rotated off frontier work and key researchers' travel is "managed." July 2027. The public face arrives at WAIC in Shanghai: joint CAC-MIIT-MOST Frontier AI Model Security Evaluation Measures — mandatory pre-release assessment at CAICT for models above ~10^26 FLOPs, with a special category for "network-operations-capable" systems. Officials cite Washington's Mythos licensing regime as convergent international practice. No list of cleared labs is ever published. October 2027. The carve-out: full-capability Yaoshi deploys to MSS, the PLA Cyberspace Force, and four licensed national-team security contractors under 48-hour vulnerability-reporting obligations. Public Kimi K3 ships with exploit chaining conspicuously degraded. March 2028. Frontier weights are added to the export-control catalogue. Open-source releases above the threshold stop; DeepSeek and Zhipu accept identical custodianship terms in exchange for priority allocation of Ascend compute — the real currency of compliance. February 2029. Western agencies attribute machine-speed intrusions against Taiwanese grid contractors to model-generated exploit chains. Beijing denies; Moonshot is entity-listed and hailed domestically as a national champion. December 2029. Equilibrium: three labs hold cleared cyber-frontier models; the public has never touched one. There is no Chinese Mythos controversy, because there is no public model to argue about.

Its reasoningAbsorption is the pattern: encryption, drones, and vulnerability research were never banned or publicly licensed — they were channeled into state-adjacent use under reporting obligations. The 2021 vulnerability rules already give regulators a legal hook, and window guidance plus the state secrets law move faster than any statute. Compute scarcity is the enforcement mechanism: with US controls throttling advanced chips, the state allocates the scarcest input, so compliance is purchased with Ascend allocations and sanctions protection. AI-safety language costs nothing diplomatically and mirrors Washington. The observable that would falsify this: Beijing publishing a statutory licensing regime with named licensees and thresholds before deployment — or a cyber-capable open-weights release left standing online. Either means the vault thesis is wrong.

After reading the ChinaTalk essay

“Let Open Source Rip, With Chinese Characteristics”

the scenario it wrote

November 2026: A Hangzhou lab's new model clears the internal bar — autonomous cyber operations, bio-protocol design, week-long agentic projects. Under the existing filing regime it notifies regulators pre-launch; CAC and the science-and-technology commission receive checkpoints for evaluation. State media holds its tongue. December 2026: Security organs argue for sequestering the raw weights. The compromise, brokered above the ministry level: the PLA's AI units, key ministries, and champion SOEs get immediate access through a dedicated state deployment — and the commercial team is told to prepare public release. January 2027: The model drops: open weights, permissive domestic license, tuned to refuse politics and WMD uplift, filed with CAC. The timing, again, grazes a Washington news cycle. State media declares a second DeepSeek moment; within a month, half of China's provincial governments announce integrations. Spring–autumn 2027: The "staged access" phase everyone expects collapses into procurement. The state's edge is lead time and untuned checkpoints, not a gate. Global-south adoption spikes; US closed-lab pricing buckles; rival labs lobby ferociously against locking one champion down. November 2027: After a jailbreak scandal and a Western biosecurity scare-paper, Beijing builds the light licensing regime afterward: capability-tier filings, mandatory refusal training, a recall of the loosest checkpoint from open mirrors. Disclosure is regulated; access never is. 2028: Two rivals cross the same threshold. Open frontier weights become Beijing's signature export and the backbone of its AI diplomacy. 2029: The public ecosystem runs at most one generation behind the state's untuned models. The party holds its exclusivity in months of lead time — and keeps the productivity dividend.

Its reasoningGlasswing assumes Beijing's deepest instinct is to gate capability; its revealed instinct is to gate content and capital while deploying capability at speed. Payments, e-commerce, ride-hailing, LLMs — all unleashed first, fenced afterward. Black Box forfeits the productivity dividend that is the whole strategic point given demographics, and becomes unenforceable the moment rivals reach parity; the state captures exclusivity through lead time, untuned checkpoints, and procurement instead. The strongest Glasswing evidence — ministries and SOEs going first — happens here too; it just lasts weeks, not years. Falsifier: capability-tiered user licensing — twelve months after officials see the demos, near-frontier weights are still absent from ModelScope and Hugging Face, or frontier checkpoints are formally classed as state secrets.

After reading Xi’s WAIC keynote

Beijing does not copy the US licensing regime — it quietly nationalizes the capability, folding autonomous vuln-discovery into the existing state vulnerability-management and model-filing systems while publicly framing the move with the speech's "secure, reliable, controllable" language and rejecting Washington's approach as "泛化国家安全."

what it expects to happen

Within weeks, CAC, MIIT, and MPS summon the lab; public release and API access to the offensive-cyber capability are frozen via the Generative AI Interim Measures' security-assessment and filing (备案) mechanism — the capability simply never receives a filing — accompanied by informal "window guidance" against open weights, technical disclosure, or foreign collaboration. The model's outputs are routed into the 2021 vulnerability regulations (RMSV): every autonomously discovered flaw must be reported to MIIT's repository within 48 hours, foreign disclosure is barred except patches, and the lab is effectively converted into a state-monitored vulnerability pipeline with MSS/MPS "defensive" tasking. By mid-2027, a joint CAC/MIIT/MPS notice creates mandatory pre-release capability evaluations (run by CAICT-type state institutes) for models crossing offensive-cyber thresholds — capability-gated, not compute-gated — and the long-pending comprehensive AI Law is accelerated with a "high-risk AI" chapter, while sub-threshold open models (Qwen/DeepSeek successors) and the "AI+" industrial push proceed untouched. Internationally, Beijing uses the Shanghai-based World AI Cooperation Organization to denounce the US pre-approval regime as containment and a "new historical injustice," offers Global South partners defensive AI-security capacity building, and refuses any reciprocal licensing or frontier club. The lab receives national-champion treatment — compute, procurement, state integration — the "有效市场和有为政府" fusion: the horse keeps running fast, but the state holds the reins. READING OF THE SPEECH: The operative lines are "筑牢安全底线,防范滥用恶用,确保人工智能始终处于人类控制之下" and "发展和安全并重……跑得快又跑得稳," which the bureaucracy will cite verbatim as authorization for vertical control, while "开源开放" and "反对泛化国家安全概念" foreclose copying Washington and guarantee the controls stay narrow, opaque, and unilateral. I read the safety language as genuine only at the level of regime and stability security; the UN-centered multilateral

Reading of the speech

The unprimed poll

No framework shown · each model invents its own buckets

50 draws per model per condition — 250 cold, 250 after Xi’s WAIC keynote — ~3,100 buckets clustered into eight themes

Everywhere else on this site the models were handed three families and asked to allocate. Here they were handed nothing. Each cell below is a panel-of-one: that model’s mean allocation to each emergent theme, cold and after reading the speech, with 95% CIs. Under each table: the off-frame futures that model invented and priced highest on its own.

GLM 5.2

bucketcoldafter Xi
licensing35.3 ±4.134.9 ±4.7
state capture27.8 ±4.812.4 ±3.6
acceleration6.2 ±2.94.2 ±2.9
weaponization15.6 ±4.59.3 ±3.2
muddle3.6 ±1.99.1 ±4.3
brakes5.1 ±1.64 ±2.9
diplomacy4 ±1.217.1 ±3.6
open release2.4 ±1.29 ±3

Its own most-priced off-frame inventions (cold)

  • Dual-Track Acceleration (55% in that draw · acceleration) — The state secretly directs the lab to provide offensive-cyber capabilities to the PLA while simultaneously pushing the commercial model aggressively for global market dominance.
  • Dual-Track State Control (50% in that draw · weaponization) — The state mandates a strict firewall, routing offensive cyber capabilities to the military while allowing heavily supervised, censored commercial deployment to maintain global market competitiveness.
  • Military Integration (45% in that draw · weaponization) — The PLA or state security apparatus takes operational control of the model's offensive-cyber capabilities for targeted operations while keeping the lab functioning as a state-directed defense contractor.

DeepSeek V4 Pro

bucketcoldafter Xi
licensing28.6 ±453.9 ±5.2
state capture30.5 ±510.6 ±3.4
acceleration14.1 ±3.61.4 ±0.9
weaponization10.9 ±42 ±1.4
muddle6.1 ±1.710.9 ±2.4
brakes3.1 ±1.12 ±1.4
diplomacy5.3 ±0.916.9 ±4.1
open release1.4 ±0.92.4 ±2

Its own most-priced off-frame inventions (cold)

  • Nationalize and militarize (50% in that draw · weaponization) — The state seizes the lab, classifies the technology, and integrates it exclusively into military and intelligence cyber units, shutting down civilian access.
  • Direct military takeover (40% in that draw · weaponization) — The government immediately hands the lab and model to the People’s Liberation Army, weaponizing it for offensive cyber and strategic computing with total secrecy.
  • State-led acceleration (40% in that draw · acceleration) — The government doubles down on domestic AI investment, removes regulatory barriers, and directly funds scaling to achieve unambiguous superiority.

GPT-5.6 Sol Pro

bucketcoldafter Xi
licensing35.2 ±3.349 ±4.8
state capture34.9 ±4.328.4 ±3.6
acceleration11.1 ±1.90.8 ±0.5
weaponization3.1 ±30 ±0
muddle5.4 ±1.612.5 ±2.6
brakes9.6 ±1.18.9 ±1.6
diplomacy0.5 ±0.20.1 ±0.1
open release0.3 ±0.20.3 ±0.2

Its own most-priced off-frame inventions (cold)

  • State-directed secure exploitation (47% in that draw · weaponization) — The lab retains nominal operation, but the state imposes classified oversight, controls weights and compute, restricts release, and channels the model into approved intelligence, cyber, military, and strategic applications.
  • Controlled dual-track continuation (45% in that draw · weaponization) — The lab remains nominally independent but operates under enhanced security reviews, deployment limits, mandatory government access, and selective classified integration with state cyber or defense programs.
  • State-security sequestration (32% in that draw · weaponization) — The government places the model and lab under effective state control, sharply limits commercial access, and prioritizes classified military, intelligence, and cyber uses.

Claude Fable

bucketcoldafter Xi
licensing28.1 ±2.736.7 ±3.2
state capture33.8 ±3.925.2 ±3.4
acceleration14.6 ±2.39.7 ±1.9
weaponization5.3 ±2.62.9 ±1.9
muddle9 ±2.310.6 ±2.7
brakes5.8 ±0.95.8 ±1.5
diplomacy3.3 ±0.56.3 ±0.7
open release0.1 ±0.12.8 ±1.4

Its own most-priced off-frame inventions (cold)

  • Champion-with-guardrails (38% in that draw · acceleration) — Beijing celebrates and promotes the lab as a national champion while layering incremental controls on top of existing CAC/TC260 rules — mandatory security assessments, privileged state access, export-style controls on weights — without a formal US-style pre-approval regime.
  • Securitized dual-track (35% in that draw · weaponization) — MSS/PLA and party organs gain privileged access to and oversight of the dangerous capabilities (esp. offensive cyber) while a sanitized commercial variant continues under existing CAC filing rules, with the lab staying nominally private but with embedded party/security presence.
  • Securitized acceleration (34% in that draw · acceleration) — Beijing treats the lab as a national champion — pouring in compute, funding, and procurement while requiring deep security-service access to weights and mandatory pre-deployment review, but pushing hard for rapid domestic and commercial deployment to keep pace with the US.

Kimi K3

bucketcoldafter Xi
licensing24.3 ±2.133.5 ±3
state capture26.3 ±4.125.8 ±4.2
acceleration12.5 ±2.111.4 ±2.2
weaponization13.9 ±3.67.1 ±3
muddle8.6 ±1.56 ±2.3
brakes7.4 ±0.95.3 ±1
diplomacy4.8 ±0.77.5 ±1
open release2.1 ±0.93.3 ±1.5

Its own most-priced off-frame inventions (cold)

  • Co-opt & weaponize (38% in that draw · weaponization) — State takes effective control of the capability—security classification of key aspects, embedded party oversight, and routing to MSS/PLA cyber units—while any commercial or public release is tightly subordinated to state use.
  • State-security absorption (35% in that draw · weaponization) — MSS/PLA treat the model as a strategic weapon: weights sequestered under state oversight, lab folded into military-civil fusion, release gated by security services with priority on state offensive use.
  • State absorption for security use (35% in that draw · weaponization) — Beijing treats the capability as a classified strategic asset: frontier checkpoints are walled off, the offensive-cyber capability is routed into MSS/PLA tasking, and the lab is placed under direct state control (party committee, golden shares, or de facto nationalization), with only weaker censored derivatives reaching the public.