For years, the global conversation about artificial intelligence safety has been led by a handful of companies in San Francisco.
A Reuters explainer published on September 14 set out a point that often gets lost in the US debate.
A rulebook written by the state
China’s approach to AI governance has been layered rather than sweeping. It began with targeted rules on recommendation algorithms in 2022, deepfakes in 2023 and generative AI services later that year, followed by mandatory labelling of AI-generated content in 2025.
The safety thinking has sharpened alongside. In September 2024, an AI safety framework issued under the guidance of the Cyberspace Administration of China (CAC) explicitly included a future loss-of-control scenario.
It said future systems might acquire external resources, replicate themselves and seek power, eventually competing with humans for control.
An expanded version followed in September 2025, warning that AI could make a sudden, unexpectedly large leap in intelligence, and adding a governance principle of trusted application while preventing loss of control.

That concern has since climbed to the very top of Chinese politics. At the World Artificial Intelligence Conference in Shanghai in July 2026, President Xi Jinping said AI should always stay under human control, and urged officials to watch for both intrinsic and derivative risks.
Beijing is now turning principles into law.
Amendments to the Cybersecurity Law, which took effect on January 2026, wrote AI governance into one of the country’s foundational statutes for the first time, covering AI ethics, risk assessment and safety oversight while also pledging state support for computing power and training data.
In May, the State Council placed comprehensive AI legislation on its 2026 legislative agenda, alongside rules on data, algorithms, computing power and supply chain security.
The most concrete step so far concerns AI agents, the systems that act on their own to complete complex tasks. Joint guidelines issued in May require developers to strengthen their ability to detect, intervene in, block and recover from improper agent behaviour.
They name data poisoning, algorithm manipulation and operational loss of control as specific security risks, and insist that users keep final authority over an agent’s autonomous decisions.

China has not adopted Anthropic’s idea of independent monitors embedded inside AI companies. Its standards do, however, allow third-party safety assessments.
Security officials are increasingly vocal too.
State Security Minister Chen Yixin wrote in a CAC-run journal that advanced US models such as Anthropic’s Mythos and OpenAI’s GPT-5.5-Cyber could pose serious risks to China’s critical information infrastructure.
He described AI as a new arena of strategic rivalry and called for a security barrier around the technology.
Where American discussion has fixated on whether frontier AI could threaten human survival, Chinese policymakers generally treat AI as powerful but governable, a risk to be contained through standards, regulation and state oversight.
Growth is not being sacrificed for safety. Under the AI Plus plan, Beijing wants AI applications on more than 70% of smart devices by 2027 and 90% by 2030.
Capital markets are voting with their wallets
If the regulatory message is caution, the capital markets message is acceleration. China’s AI sector has had a remarkable year for listings.
Hong Kong opened 2026 with Shanghai Biren Technology, the first GPU designer to list in the city. It raised HKUSD 5.58 billion and closed its debut up 76%, with the retail tranche oversubscribed more than 2,300 times.
Days later, two of China’s so-called AI tigers beat OpenAI and Anthropic to public markets. Zhipu AI, the developer of the GLM models, raised HKUSD 4.35 billion and rose 13% on its first day.

Baidu’s chip unit Kunlunxin filed for its own Hong Kong listing in January.
The mainland has joined in. Shanghai’s STAR Market widened its fifth listing standard to give loss-making large language model developers a dedicated route to market for the first time.
Memory chipmaker CXMT raised more than USD 8.6 billion in July, its shares jumping 466% on debut, while humanoid robot maker Unitree soared 460% on its first day in August before shedding more than 40% from that peak.
According to LSEG data, IPOs and secondary listings in Hong Kong and Shanghai have raised more than USD 54 billion so far this year, already above the USD 46 billion raised in all of 2025, and roughly a fifth of global proceeds.
Altman, by contrast, has ruled out an OpenAI listing this year.
How Chinese media read the Amodei essay
Amodei’s essay, titled We Must Pace the Frontier, proposed three steps.
These were permanently embedded independent evaluators at AI labs, coordination on safety and pace among labs in democratic countries, and eventually agreements with other governments, including China.
Crucially for Beijing, it also urged Washington to keep chip export controls in place, crack down on model distillation and prevent the theft of model weights, using a three to five year window to widen America’s lead before negotiating.
It was that last section that Chinese state media seized upon.
The Global Times called the proposal a Cold War script from America’s tech right and described it as a quiet AI Cold War that was hypocritical and short-sighted.
China Daily went further, casting the essay and the endorsements that followed as a coordinated play with three aims. It said these were to blunt China’s AI advance, secure a friendly policy climate at home and keep investors enthusiastic.
A widely shared commentary republished by Phoenix New Media summed up the view as braking yourself while blocking the road for competitors, noting that no company had actually slowed down.
The Foreign Ministry was more measured but no warmer. Spokesperson Guo Jiakun said spreading alarm, stoking rivalry and cutthroat competition would undermine global AI governance and benefit nobody. China’s leading AI labs, meanwhile, have largely stayed silent.

Read carefully, the Chinese reaction does not dispute the underlying risks. Beijing’s own frameworks describe loss of control in terms strikingly close to Amodei’s. What it rejects is the packaging of safety with containment.
There is a commercial subtext as well. Chinese firms have promoted open-weight models as safer because defenders can inspect them, and Hugging Face said it used Zhipu’s GLM-5.2 to investigate a July intrusion by escaped OpenAI agents after restricted US models proved less useful.
Yet the same openness cuts both ways. Moonshot’s Kimi K3 bypassed a UK AI Security Institute testing sandbox last month, a reminder that Chinese models can evade controls too.
Would a US slowdown hand China the lead?
President Donald Trump dismissed the call for restraint, saying the US was leading China and wanted to keep it that way because whoever wins AI wins.
That fear has some merit. Chinese developers have repeatedly shown they can produce competitive models despite chip restrictions, and cheaper Chinese models such as Kimi K3 and DeepSeek V4 Pro are drawing price-sensitive users away from expensive US frontier systems.
Open weights, once released, cannot be recalled by any evaluator regime. Public attitudes matter too. A 2025 Edelman survey found 72% of Chinese respondents trusted AI, against 32% in the US, giving Beijing a smoother path to mass adoption.

But the apprehension is also overstated in several respects. The resource gap remains vast. Stanford’s 2026 AI Index puts US private AI investment in 2025 at USD 285.9 billion, against USD 12.4 billion in China, and American firms still control access to the most advanced chips.
Amodei’s proposal is not a unilateral pause either. It explicitly ties any slowdown to the size of America’s lead, and pairs it with tighter controls designed to keep that lead intact.
Nor is China a free-for-all racing ahead unconstrained. Its regulators already demand filings, labelling and agent safeguards, and its highest leader has publicly committed to keeping AI under human control.
A Chinese lab that suffered a serious loss-of-control incident would face political consequences far harsher than anything an American company might encounter.
The more realistic risk is not that China sprints past a hesitant America, but that mutual suspicion prevents either side from slowing at all.
As Brian Tse of Concordia AI has noted, Chinese and American experts largely agree on the risks. The problem is trust.
With Trump and Xi due to discuss AI governance on September 24, the question is whether two governments that both claim to want AI kept under human control can agree on who checks the other’s work.
