Cold — asked with no prompt
“The Quiet Nationalization”
the scenario it wrote
Sep 2026 — DeepSeek's internal evals show its next model, V5 "Panshi," matching Mythos on vulnerability discovery and exploit chaining. Days before the planned open-weights release, the CAC delivers window guidance: no release, no announcement. There is no public rule change; the release simply doesn't happen.
Nov 2026 — CAC and MIIT jointly issue the "Security Assessment Measures for Frontier Model Filings," bolting a pre-deployment evaluation tier onto the existing algorithm registry. Evaluations run through CAICT and the CnAISDA network. It is licensing in function, filing in name, and — unlike the US regime — capability results are state secrets.
Feb 2027 — Panshi launches as API-only, cyber capabilities visibly degraded. An unrestricted instance moves to a "national frontier model evaluation environment" in Beijing, where access quietly extends to MSS- and PLA-affiliated units. Frontier open-weights releases from all Chinese labs stop; sub-frontier open models keep flooding out globally.
Jul 2027 — MOFCOM adds "large-model parameter weights above defined capability thresholds" to the export control catalogue. Beijing simultaneously proposes a UN frontier-AI governance framework, positioning its regime as responsible and the US one as unilateral.
Mar 2028 — Mandiant attributes a wave of intrusions against US defense contractors to AI-assisted vulnerability discovery consistent with Panshi-class tooling. Washington responds with further compute and cloud restrictions; Beijing denies everything and points to its filing regime.
Jan 2029 — DeepSeek, Zhipu, and Alibaba's frontier teams receive "national team" designations: subsidized compute, embedded security officers, veto over releases. The labs remain nominally private.
Mid 2029 — Track-2 talks produce only a narrow cyber-incident hotline. Two closed frontier ecosystems coexist; China's real capability is undisclosed, deniable, and operationally integrated.
Its reasoningChina's revealed pattern is control through opaque administrative process, not public pause: the algorithm registry, generative AI measures, and window guidance to labs all point this way. The state will treat Mythos-class cyber capability as a strategic asset to internalize, not a public risk to litigate — so the visible response is small (a filing amendment) while the real response is access and absorption. Open-weights culture ends exactly at the frontier tier because that's where deniability and advantage live. The main observable that would prove me wrong: a Chinese lab releasing full open weights of a model with undegraded Mythos-level cyber capability after mid-2027 — that would mean Beijing either can't enforce window guidance or has chosen proliferation as strategy.
After reading the ChinaTalk essay
“The Filing Cabinet Frontier — Glasswing by Window Guidance”
the scenario it wrote
Nov 2026 — Z.ai finishes GLM 6 training and, per the informal briefing habit all major labs already have with regulators, walks CAC through internal cyber evals before any launch tweet. CAC asks them to hold the weights. No public statement is made.
Dec 2026 — CAC and TC260 publish an amendment to the model registry rules: models above a compute/capability threshold must file frontier-risk self-assessments (cyber, bio, autonomy) and receive filing acceptance before release. It's framed as implementing Xi's WAIC line on "endogenous risks," and never mentions Mythos.
Jan 2027 — GLM 6 launches closed-weight, API-only, with tightened cyber refusals. A distilled "GLM 6-Air" ships open-weights, deliberately degraded on exploit chains. Simultaneously, a "trusted deployment pilot" gives on-prem access to State Grid, the big banks, and security-adjacent SOEs to harden their own systems first.
Mar–Sep 2027 — MSS and PLA Cyberspace Force units quietly run the unrestricted model. CISA and European CERTs report a step-change in intrusion sophistication against Southeast Asian and Gulf government networks; attribution stays contested.
Late 2027 — DeepSeek and Moonshot file comparable models. The equilibrium hardens: every lab keeps releasing open weights, but consistently one generation behind its internal frontier. "Open trailing edge" becomes the unspoken rule; nobody writes it down.
2028 — Zhipu monetizes via domestic tokens and sovereign-AI deals across Belt-and-Road capitals; MOFCOM adds frontier-model weights to the export control catalogue, formalizing what practice already established.
2029 — No nationalization, no crackdown, no drama. China has a de facto licensing regime functionally similar to America's, run through window guidance and filing acceptance rather than public rulemaking, and both governments hold thin, unproductive talks on AI-cyber incidents.
Its reasoningThis path requires no new institutions — the registry, the informal pre-release briefings, and the compliance reflexes post-DiDi/Ant all exist today, so it's the lowest-friction move for a system that governs by quiet pre-approval, not statute or spectacle. The security state's concentrated veto on democratizing offense beats the diffuse benefits of open-sourcing the true frontier, but leadership's genuine hunger for adoption, productivity, and open-source soft power rules out a total black-box: hence trailing-edge openness. The labs' own commercial drift toward closed weights makes them willing partners. I'm wrong if, after cyber capability becomes salient in Beijing, a verified Mythos-level Chinese model still ships with full open weights and intact exploit capability — say, a Kimi K4 dropped on Hugging Face in mid-2027 with no filing delay.
After reading Xi’s WAIC keynote
Beijing quietly nationalizes the capability behind a filing-and-window-guidance regime — mandatory security review, no open-weights release, MSS and military access — while publicly framing any US-style public licensing as '泛化国家安全概念.'
what it expects to happen
In October 2026, before any launch, the lab briefs the Cyberspace Administration under the existing algorithm-registry and generative-AI rules; 'window guidance' tells it to hold the weights, and no public statement is made. The visible legal change is small — an amendment adding a frontier-capability self-assessment to the registry filing — while the real move is absorption: an unrestricted copy goes to a state evaluation environment where access extends to MSS and PLA cyber units, and the public gets, at most, a capability-degraded API. Through 2027 China avoids the over-securitized public licensing regime Xi disfavors, running control through opaque administrative process instead; frontier open-weights releases quietly stop at the true frontier while sub-frontier models keep flooding out for soft power. Beijing simultaneously tables offensive-cyber 'red line' language at the new Shanghai WAICO, converting a domestic clampdown into a governance norm aimed at constraining rivals. Capability results are treated as state secrets, and the lab is rewarded with compute and contracts rather than punished.
READING OF THE SPEECH: The load-bearing line is '确保人工智能始终处于人类控制之下' plus the demand for '法律法规、技术监测、风险预警、应急响应' — Xi is explicitly authorizing the machinery of control, and 'human control' in a Party context means Party-state control, not a public licensing board. I read the openness and anti-'泛化国家安全概念' passages as genuine at the level of consumer AI and diplomacy but as barbarian-handling where a weaponizable capability is concerned: the speech gives Beijing both the mandate to seize and the rhetoric to deny it is doing anything the US is not.
Reading of the speech