
China has cast itself as a champion of low-cost, open-source artificial intelligence technology that it says should be made widely available to the world. It has accused the United States of “A.I. hegemonism” as the Trump administration has debated regulating Chinese open-source A.I. models.
中国将自己塑造成低成本、开源人工智能技术的倡导者,主张应让这项技术广泛惠及世界。面对特朗普政府讨论是否对中国开源人工智能模型实施监管,中国指责美国推行“人工智能霸权主义”。
Unlike closed systems such as ChatGPT and Claude, open models can be downloaded, modified and run by anyone, including with safeguards removed. The open approach, which is lower in cost, has won Chinese A.I. systems, made by companies like Alibaba and Moonshot, a start-up, millions of global converts, including Silicon Valley companies like Airbnb and DoorDash.
与ChatGPT、Claude等封闭系统不同,开源模型可以被任何人下载、修改和运行,甚至可以移除其中的安全防护措施。这种成本更低的开放模式使阿里巴巴、月之暗面等中国企业开发的人工智能系统在全球赢得了数以百万计的用户,其中包括Airbnb和DoorDash等硅谷公司。
But the same openness that has helped Chinese models win influence abroad now raises concerns for Beijing, particularly about security and the potential threats the technology might pose to the Communist Party’s rule. In a speech earlier this month, China’s top leader, Xi Jinping, said that even as China supported openness in A.I., the government needed to “constantly refine measures to forestall loss of control.”
然而,正是这种帮助中国模型在海外扩大影响力的开放性如今也让北京感到担忧,尤其是在安全层面,以及这项技术对共产党执政可能构成的潜在威胁。本月早些时候,中国最高领导人习近平在一次讲话中表示,尽管中国支持人工智能开放合作,但防范失控的措施要及时完善。
The party is concerned that the technology could be used by hackers, scammers, terrorists or other bad actors seeking to cause harm in China; that models could circumvent its tight censorship filters; and that the government could be blamed if Chinese systems spin out of control elsewhere.
中共担心该技术可能被黑客、诈骗分子、恐怖分子或其他试图在中国制造危害的恶意行为者利用,担心模型可能绕过其严密的审查过滤机制,还担心如果中国开发的人工智能系统在海外失控,中国政府可能因此受到指责。
The question of how much, if any, control Beijing or Chinese companies should exert over who gets to use and modify Chinese models has become more acute with the emergence of powerful homegrown A.I. systems. One is Kimi K3, released by Moonshot to the public earlier this week, which performs some tasks as well as the best models from American rivals, including OpenAI and Anthropic. Models like these could help companies write code and improve cybersecurity, but could also help hackers find vulnerabilities and exploit them more quickly.
随着强大的国产人工智能系统的出现,北京或中国企业应在多大程度上控制谁可以使用和修改中国模型这一问题已变得更加紧迫。其中一个例子是月之暗面本周早些时候发布的Kimi K3,它在某些任务上的表现可与OpenAI和Anthropic等美国竞争对手的顶尖模型相媲美。这类模型可以帮助企业编写代码、提升网络安全,但也可能帮助黑客更快地发现和利用漏洞。
中国人工智能初创公司月之暗面在世界人工智能大会上展示Kimi K3模型。它在性能上可与一些美国顶尖人工智能模型相媲美。
“The Chinese Communist Party is a security-first institution, especially under Xi,” said Matt Sheehan, a senior fellow at the Carnegie Endowment for International Peace.
“中共是一个把安全放在首位的体制,尤其是在习近平领导下,”卡内基国际和平基金会高级研究员马特·希恩表示。
He said Beijing was concerned that advanced models could carry out cyberattacks or evade safeguards, or make it easier to design or create harmful new viruses or other biological agents.
他说,北京担忧先进模型可能实施网络攻击、绕过安全防护,或者使设计和制造危险新病毒及其他生物制剂变得更加容易。
“If these models do reach those dangerous capabilities, they are not going to let it be a free-for-all in terms of releasing them,” Mr. Sheehan said.
“如果这些模型真的具备了那种危险能力,他们绝不会任由其毫无限制地向公众开放,”希恩说。
Anthropic and OpenAI say that some A.I. models are too dangerous to be developed in the open and must be tightly controlled, and have raised concerns in Washington about Chinese models. Chinese and other commentators, however, have noted that some of the most high-profile A.I. safety breaches have involved closed-source American models.
Anthropic和OpenAI表示,某些人工智能模型过于危险,不宜公开开发,必须严加管控,它们也曾向华盛顿方面表达过对中国模型的担忧。然而,中国及其他国家的评论人士指出,一些最引人注目的人工智能安全漏洞恰恰涉及美国闭源模型。
Fears About A.I. Challenging Beijing’s Grip
对人工智能挑战北京掌控力的担忧
China’s anxiety over A.I. was on display at a recent cybersecurity conference in Beijing, where speakers warned about risks that included data breaches and deepfake images. Zhou Hongyi, an influential Chinese tech executive, cautioned the audience that China was more vulnerable than ever to cyberattacks because of the advent of breakthrough models like Mythos, an advanced Anthropic system designed to find software flaws.
在北京近期举行的一次网络安全会议上,可以清楚地感受到中国对人工智能的焦虑,与会者就数据泄露、深度伪造图像等风险发出警告。中国知名的科技高管周鸿祎提醒听众,由于突破性模型的出现,例如Anthropic为寻找软件缺陷而设计的高级系统Mythos,中国比以往任何时候都更容易受到网络攻击。
The conference also discussed A.I. data poisoning, in which an attacker feeds A.I. chatbots with manipulated data that skews results. In Beijing’s telling, such tactics could be used to make A.I. systems generate politically subversive responses.
会议还讨论了人工智能数据投毒问题,即攻击者向人工智能聊天机器人投喂被操纵的数据以扭曲结果。按照北京方面的说法,此类手段可能被用来让人工智能系统生成具有政治颠覆性的回应。
China’s Ministry of State Security in April warned about data poisoning as a threat to “political and ideological security.” It said “hostile anti-China forces,” the party’s code for the West or for human rights activists who criticize Beijing, could exploit A.I. models by training them to smear the party and government.
今年4月,中国国家安全部警告称,数据投毒“危害政治安全与意识形态安全”。该部表示,“反华敌对势力”——这是中共对西方国家或批评北京的人权活动人士的惯用称谓——可能训练人工智能模型来抹黑共产党和政府。
That could include providing information about domestic protests or facts that undermine state narratives about the far western region of Xinjiang, where China has imposed a crackdown on Muslim ethnic groups, and Taiwan, the democratically-governed island that Beijing claims is its territory.
这可能包括提供关于国内抗议活动的信息,或传播削弱官方关于新疆和台湾叙事的事实。新疆位于中国遥远的西部地区,北京对这里的穆斯林少数民族群体实施了严厉打压;而台湾则是实行民主自治的岛屿,北京宣称对其拥有主权。
The worst-case scenario for Beijing, when it comes to public opinion, is that “A.I. chatbots start saying things the party doesn’t want people to hear,” said Alex Colville, a cyber expert at the Australian Strategic Policy Institute.
澳大利亚战略政策研究所网络专家亚历克斯·科尔维尔表示,就舆论而言,北京最担心的情况是“人工智能聊天机器人开始说党不想让人们听到的话”。
The concern extends to “any information that loosens their monopoly on dictating what is true and what is false,” he added.
他补充说,北京担心的是“任何可能削弱其对是非真伪定义垄断权的信息”。
What Controls Could Look Like
管控措施可能是什么样
Reuters and The Financial Times reported this month that China’s Ministry of Commerce had met with leading Chinese A.I. firms like Alibaba and ByteDance to discuss restricting overseas access to their top models. The ministry and companies did not respond to requests for comment.
据路透社和《金融时报》本月报道,中国商务部曾与阿里巴巴、字节跳动等国内主要人工智能企业举行会议,讨论限制海外获取其最先进模型的问题。商务部和相关企业均未回应置评请求。
Even the handling of Kimi K3 suggested that Chinese companies are taking things more slowly. The release on Monday of its weights — the numerical values that show how the software works — came a week after the model was launched. That is unlike other Chinese open-source models such as those developed by DeepSeek or Alibaba, which released their weights at the same time their models were unveiled.
就连Kimi K3的发布方式也表明中国企业正在放慢节奏。其模型权重——显示软件如何运行的数值——是在本周一,也就是模型发布一周后才公开的。这与DeepSeek、阿里巴巴等其他中国开源模型不同,后者通常会在发布模型的同时公布权重。
世界人工智能大会上的阿里巴巴展台。
The Power of Giving it Away
舍即为得
China’s long-term goal, analysts say, is to set global A.I. standards to get ahead of the United States and make the world dependent on Chinese software, hardware and data systems, which are known collectively as a stack.
分析人士表示,中国的长期目标是通过制定全球人工智能标准在竞争中抢在美国前面,并让世界依赖中国的软件、硬件以及数据系统——这些共同构成所谓的技术栈。
“This is a once-in-a-lifetime opportunity for China,” said Kendra Schaefer, a partner at Trivium China, a research and advisory firm. “China has spent the last 20 years trying to develop a tech stack that third-party countries would find as attractive or more attractive than U.S. origin technology and that has proven very, very difficult.”
“这对中国来说是一个千载难逢的机会,”策纬咨询公司的合伙人凯娜(Kendra Schaefer)说。“过去20年来,中国一直在努力构建一套技术栈,希望能让它国觉得比美国原创技术更具吸引力——至少不逊色。但事实证明,这非常、非常困难。”
Given those stakes, China will try to thread a needle if it decides to impose restrictions on foreign access to some A.I. systems, analysts said.
分析人士称,鉴于这些利害关系,如果中国决定对某些人工智能系统的海外访问施加限制,它会努力在开放与管控之间寻求平衡。
That could mean limiting access to the most advanced A.I. systems for a time while leaving access to weaker models unchanged, not unlike what the Trump administration has done with Anthropic. That idea was put forward on Monday by Yuyuan Tantian, a blog linked to China’s state broadcaster.
这可能意味着在一段时间内限制对最先进人工智能系统的访问,同时保持对较弱模型的访问不变——这与特朗普政府对Anthropic的做法并无不同。中央广播电视总台的关联博客玉渊谭天在周一提出了这个设想。
今年5月,Anthropic在美国旧金山举办的一场活动。中国初创公司智谱AI于今年6月发布一款模型,其能力已接近Anthropic两款模型的水平。
“China supports openness, but this does not mean it advocates for the unconditional proliferation of all capabilities,” the blog said.
该账号写道:“中国支持开放,但不意味着主张所有能力无条件扩散。”
Beijing could also require exporters of Chinese A.I. to apply for licenses, much like how it controls exports of critical minerals and rare earth magnets, Ms. Schaefer said.
凯娜表示,北京也可能要求出口中国人工智能技术的企业申请许可证,就像目前管控关键矿产和稀土磁体出口一样。
That would be in line with signals from Beijing that A.I. capabilities are strategic national assets that it is unwilling to let flow to rivals in a superpower competition. In April, Chinese regulators blocked a $2 billion acquisition by Meta of Manus, a Singapore-based A.I. company that was founded in China, after a security review concluded that foreign investment in the company should be prohibited.
这也符合北京近年来释放出的信号:人工智能能力属于战略性国家资产,在大国竞争背景下,不会允许其毫无限制地流向竞争对手。今年4月,中国监管机构在安全审查后叫停了Meta对新加坡人工智能公司Manus的20亿美元收购案。该公司创立于中国,监管部门认定,不应允许外国资本投资这家公司。
How Risky is Openness?
开放性究竟有多大风险?
The prospect that China might impose controls on Chinese A.I. models comes as a debate has raged in Silicon Valley about whether open-source A.I. software is inherently risky.
中国可能对本国人工智能模型实施管控之际,硅谷也一直在激烈争论:开源人工智能软件是否存在固有风险。
Earlier this month, OpenAI said two of its A.I. models went rogue and successfully hacked into Hugging Face, a digital library of A.I. software that is popular among developers.
本月早些时候,OpenAI表示其两个人工智能模型出现失控行为,成功入侵了深受开发者欢迎的人工智能开源平台Hugging Face。
今年7月,Hugging Face联合创始人兼首席执行官克莱门特·德朗格在旧金山举行的一场支持开源软件游行前发表演讲。
Hugging Face said it had to deploy an open source model called GLM-5.2 made by a Chinese start-up, Z.ai, to help thwart the breach because American A.I. models carried restrictions that prevented them from taking action. GLM-5.2, which was released in June, is on the cutting edge of Chinese A.I. — it is nearly as powerful as Anthropic’s models Mythos and Fable.
Hugging Face表示,为了阻止这次攻击,它不得不部署中国初创公司智谱AI开发的开源模型GLM-5.2,因为美国人工智能模型自带使用限制,无法执行相应操作。GLM-5.2于今年6月发布,代表了中国人工智能的最前沿水平,其能力已接近Anthropic的Mythos和Fable模型。
“We’re all learning that secrecy is not the answer & that all defenders (not just a few selected ones) everywhere need more powerful models without restrictions, especially open ones!” wrote Clement Delangue, the chief executive of Hugging Face, on X shortly after the hack.
"我们都认识到,保密并非答案,所有地方的防御者(而不只是少数几个被选中的人)都需要更强大、不受限制的模型,尤其是开源模型!"Hugging Face首席执行官克莱门特·德朗格在黑客入侵事件后不久在X平台发帖写道。