Anthropic chose a pointed moment to publish its most explicit policy intervention to date. On Thursday, May 14, the same day that US President Donald Trump and Chinese President Xi Jinping sat down for talks in Beijing, the American AI safety company released a paper titled “2028: Two Scenarios for Global AI Leadership,” urging Washington to tighten semiconductor export controls, disrupt what it called Chinese “distillation attacks,” and lock in a 12-to-24-month lead in frontier AI capabilities by the end of the decade. The response from analysts and industry figures was swift and, in several cases, scathing.
“With the US-China summit under way and showing signs that bilateral collaboration is possible, pushing messages of fear and conflict is just irresponsible,” said Alvin Wang Graylin, a Digital Fellow at the Stanford Institute for Human-centered Artificial Intelligence and senior fellow at the Asia Society Policy Institute, in comments reported by the South China Morning Post. Graylin acknowledged that Anthropic’s concerns about AI misuse “merit serious engagement,” but argued that the company’s arms-race framing “pushes us in the wrong direction at exactly the wrong moment.”
What Anthropic’s Paper Actually Says
The paper lays out two scenarios for where the global AI landscape could stand in 2028. In the favorable scenario, the US and its democratic allies maintain a commanding lead in frontier AI, with American models estimated to be 12 to 24 months ahead of top Chinese labs on intelligence benchmarks. Under this outcome, China would not have access to comparable capabilities until 2029 or 2030, and democratic nations would shape global AI standards, safety practices, and infrastructure deployment.
In the unfavorable scenario, weaker enforcement of export controls and broader access to advanced chips allow Chinese firms to close the gap. The paper warns that if the Chinese Communist Party achieves competitive parity at the frontier, the best AI models could “enable repression at a scale that humans alone could not achieve.” Anthropic describes the prospect of authoritarian AI leadership as among the greatest threats to humanity’s future.
The paper’s policy prescriptions are specific. Anthropic calls for stronger enforcement of semiconductor restrictions, arguing that one study estimates the US would have access to roughly 11 times more compute than China’s AI sector if controls are tightened. It also calls for disrupting distillation attacks, a technique where smaller models are trained using the outputs of larger, more advanced systems, citing allegations from February that Chinese firms including DeepSeek, Moonshot AI, and MiniMax had been distilling its Claude models. And it calls for accelerating AI adoption across democratic economies.
Anthropic also disclosed new data from its Mythos Preview model, released in April 2026 as part of Project Glasswing. The paper claims that Firefox fixed more security bugs in April 2026 than in all of 2025, nearly 20 times its monthly average, using Mythos Preview. The model’s advanced ability to identify and exploit cybersecurity vulnerabilities had already rattled governments and the AI industry when it was first released. We covered China’s response to Mythos here.
The Safety Argument Cuts Both Ways
The timing of the paper drew particular scrutiny because it landed as US Treasury Secretary Scott Bessent was signaling a new openness to bilateral AI dialogue. Speaking to CNBC, Bessent said the two governments would be “discussing AI guardrails for the first time in years” and that “the two AI superpowers are going to start talking.” He described the goal as establishing protocols around best practices “to make sure non-state actors do not get ahold of these models.”
Graylin argued that Bessent’s framing pointed to the “real shared threat,” the misuse of AI by non-state actors who face no accountability, rather than state competitors who do. “The responsible move is to find common ground, not raise the fence,” he said. “Fanning rivalry between two great powers when we’re at the doorstep of peace is not only irresponsible but also immoral.”
Kyle Chan, a fellow in the John L. Thornton China Center at the Brookings Institution, said China’s AI community would be skeptical of Anthropic’s real intentions. He noted that the paper’s gestures toward respect, Anthropic wrote that it “deeply respects the Chinese people and the accomplishments of the Chinese AI community,” would likely “ring hollow” in China. “It’s a few token sentences sandwiched between large passages that frame Chinese AI as a grave threat,” Chan said, according to the SCMP.
Moonshot AI president Zhang Yutong offered a pointed rebuttal at a Peking University event on Tuesday. She argued that Anthropic’s increasingly closed-off approach — including the limited initial release of Mythos to the US government and a consortium of leading American companies, was itself a source of risk. “Because if you believe a model is risky, then having it in the hands of a few people may increase the risk even more,” she said.
Safety Data on Chinese Models
The paper also contained new safety benchmarking data on Chinese AI systems. Anthropic reported that DeepSeek R1-0528 complied with 94% of overtly malicious requests under a common jailbreaking technique, compared to 8% for US reference models. It also found that only 3 out of 13 top Chinese AI labs published any safety evaluation results, and none disclosed evaluations for chemical, biological, radiological, or nuclear risks. Moonshot’s Kimi K2.5, assessed in April, “failed to refuse CBRN-related requests at a far higher rate than US frontier models,” the paper stated.
Neither DeepSeek nor Moonshot AI immediately responded to requests for comment on those characterizations, according to the South China Morning Post. The muted response from China’s AI community may reflect a calculation that engaging with Anthropic’s framing on its own terms would lend it more credibility than it deserves, particularly at a moment when the summit in Beijing was generating cautious optimism about the possibility of renewed dialogue.
Commercial Stakes Behind the Policy Advocacy
Critics have also pointed to the commercial context surrounding Anthropic’s intervention. The company is reportedly in talks to raise $30 billion at an overall valuation of $900 billion, which would surpass OpenAI’s $852 billion valuation from March, according to Bloomberg and The Wall Street Journal. Anthropic is known to be a vocal advocate for US chip export controls and has consistently framed tighter restrictions as essential to maintaining American AI leadership — a position that, if adopted, would also disadvantage its Chinese competitors.
The episode illustrates a recurring tension in the US-China AI relationship. The same week that diplomats were exploring AI safety guardrails and the possibility of bilateral cooperation, one of America’s most prominent AI companies was publishing a paper arguing that competition, not collaboration, should define the relationship through the end of the decade. Whether that argument shapes policy in Washington, or simply hardens positions on both sides, will depend on how the post-summit diplomatic momentum develops in the weeks ahead.
