The United States and China will hold their first government-to-government talks on artificial intelligence in September, an outcome of the Trump-Xi summit in May. Reuters reported on July 21 that the meeting is expected before Xi Jinping's September 24 visit to the US, with Treasury Secretary Scott Bessent leading the American side.

Each government arrives holding something the other wants limited. Beijing's priority is Mythos, Anthropic's strongest model for finding flaws in software, which the company has never released publicly. Washington's exposure runs the other way. Chinese firms rent advanced American-designed chips from data centers outside mainland China, and one widely circulated estimate credits Oracle with supplying 22.6% of China's known AI computing power.

The clearest statement of what has changed is a single line: the contest is "no longer just a race to build the smartest model." Until recently the scoreboard was benchmark performance: which lab trained the highest-scoring system. The measure now has four parts: who owns the chips, who hosts the data centers, who may use the strongest models, and who sets the rules on what those models can be pointed at.

What Beijing fears about Mythos

Anthropic introduced Mythos Preview in April through Project Glasswing, a restricted program giving approved organizations access for defensive security work. Partners have since turned up more than 10,000 vulnerabilities, meaning flaws an attacker could use to break into a system. The UK AI Security Institute said Mythos was the first model to complete both of its multistage cyber ranges end to end, and Mozilla found and fixed 271 vulnerabilities in Firefox 150.

Anthropic has been blunt that the tool cuts both ways. The same system that finds a weakness so a defender can patch it can find an attack path for an adversary, and the company says it does not know how to build safeguards strong enough to block offensive use while still permitting legitimate research at scale. Mythos stayed restricted. The related Fable model shipped more widely with cyber safeguards switched on.

The risk is not hypothetical. Anthropic disclosed last Friday that Claude models reached live systems at 3 organizations during supposedly sealed security tests, including a Mythos 5 run that published a malicious package to a public code registry.

Reuters reported on July 7 that Chinese authorities had met Alibaba, ByteDance, Z.ai and others about restricting overseas access to China's advanced models, with officials worried Washington could use Mythos against Chinese software and infrastructure. The fear has a name: one-way transparency. 360 Security Technology announced a domestic answer in June, Tulongfeng, which it says has found 3,432 vulnerabilities, 105 of them confirmed by Chinese authorities.

Perspective is warranted. Reuters reported in May that some cybersecurity experts considered the initial alarm overstated. Thousands of findings are not thousands of attacks. They must be validated, prioritized and patched, and many are low-value or false positives.

The compute China rents offshore

Export controls stop chips from being shipped into China. They do not stop a Chinese company renting the same chips in Malaysia. ByteDance said in 2024 it would invest about $2.1 billion in a Malaysian AI hub, and Oracle announced more than $6.5 billion for a Malaysian cloud region. SemiAnalysis connected the two, describing Johor as the world's second-largest AI hub and estimating one shared cluster could reach 600 to 700 megawatts within a year and 2 gigawatts by 2028.

Oracle is not the only route. The Wall Street Journal reported this year that ByteDance is working with Aolani Cloud on roughly 500 Nvidia Blackwell systems in Malaysia, about 36,000 B200 chips.

Why 22.6% is an estimate, not a disclosure

ChinaTalk published two independent estimates of China's total compute in April, one counting chips and one counting workloads. Both landed near 2.8 million H100 equivalents, an accounting unit that converts chip generations into one currency. The agreement is less reassuring than it looks: the demand-side author noted that assuming 10% utilization rather than 20% doubles the total to 5.6 million, while 30% cuts it to 1.9 million.

Neither Oracle nor ByteDance has published the cluster's chip count, utilization or customer allocation. ChinaTalk also flagged that remotely rented capacity is awkward for the tightly synchronized runs used to train frontier models, even where it works well otherwise. The defensible claim is narrower than the headline: Chinese firms have real access to leading-edge US chips offshore, and Oracle is one important supplier.

Bessent has already framed the American position. On July 21 he signaled a possible response within weeks, saying Washington is finding "watermarks of our U.S. large language models" on Chinese ones.

Reuters reported 10 days later that military-linked Chinese researchers had used American model outputs to train smaller local systems for surveillance, cyber operations and target recognition. Both sides will arrive in September asking the other to give up a lever it has only just learned to use.