Thought for the week: Why runaway AI development does not serve China's interests

Both China and the U.S. have reasons to pursue stronger AI governance measures that balance innovation, national security and risk prevention.

Contributors:
Brian Hengesbaugh
CIPP/US
Global Chair, Data and Cyber
Baker McKenzie
Editor's note
The IAPP is policy neutral. We publish contributed opinion pieces to enable our members to hear a broad spectrum of views in our domains.
This article is part of an ongoing series that will explore issues or recent developments in data, cybersecurity and artificial intelligence governance.
China's Minister of State Security Chen Yixin last week published an article in China Cyberspace Magazine calling for a "healthy and orderly development of artificial intelligence" and a "comprehensive security barrier."
The piece is worth reading closely. Let me briefly explain the context. We have seen an unprecedented volume of public discourse in the past few weeks over the risks of AI, including the risk of losing control of AI systems, the misuse of AI for cyberattacks and bioterrorism and serious economic disruption. Much of this dialogue has been in the public domain for many years. The attention has accelerated recently due to dynamics related to high profile unauthorized agentic AI actions, increases in recursive self-improvement and other factors.
The response from the political arena, as one might expect, has not been unified or consistent. We have seen everything from strong positions to refrain from any regulation that might impede the U.S. advantage over China from a competition standpoint, to calls on the other end of the spectrum for an immediate pause on advanced AI development and a permanent ban on superintelligent AI.
It's almost as if we didn't already have enough to worry about.
On the question of competition with China, it is important to remember that runaway AI development does not serve China's interests. As a one-party state led by the Chinese Communist Party, China exercises substantial control over political opposition. Activities that negatively impact the CCP are not appreciated.
The minister of state security's article contained a relatively clear reminder of this reality. The first portion of the article focused on the benefits of AI — all good — but the later portions remind people of the political realities. Notably, the fifth point within the later section entitled "Key measures to systematically advance the governance of artificial intelligence" provides, as auto-translated:
"Fifth, improve the legal safeguards system. Fully implement the 'Cybersecurity Law of the People's Republic of China' and the 'Counter-Espionage Law of the People's Republic of China,' accelerate the promulgation of special laws and regulations targeting the research, development, application, and supervision of artificial intelligence technology, and improve the regulatory rules and standards system covering the entire chain of technology research and development, application implementation, risk prevention and control, and accountability, focusing on prominent issues such as algorithm security, data protection, ethical norms, and privacy rights. Improve the regulatory and enforcement mechanisms, strengthen the legal responsibilities of various entities such as industry regulatory departments and artificial intelligence enterprises, and punish illegal and criminal activities such as data theft and the creation and dissemination of harmful information using artificial intelligence in accordance with the law."
So, AI developers in China need to ask themselves some key questions. Notably, what risks they might face personally if their AI agent(s) escape a sandbox, hack a government agency, steal government data, provide output deemed to be harmful information, or do anything else the CCP does not like? Would they be OK in those scenarios under the current Cybersecurity Law and/or Counter-Espionage Law? And, what about the CCP's plans to "accelerate the promulgation of special laws and regulations targeting the research, development, application, and supervision of" AI technology?
My guess is they probably wouldn't fare very well under those new rules either. Developers might want to proceed with some caution, while the Chinese government continues to sharpen the rules and consequences for bad outcomes.
The point is that there is some degree of a driver for self-governance that already exists within each the U.S. and China to establish protective rules that benefit self-interests at this stage. It doesn't mean competitive issues and national security become irrelevant, but it means the U.S. should adopt a balanced view that takes into consideration the risks we incur domestically from inaction.
The U.S. government has already taken steps in recent months to deploy U.S. export controls and other regulations to oversee risks associated with AI development. This could be the right time for a logical extension of those earlier efforts, but with a broader lens to try to help pace the development of AI. My sense is that regulators could start with elements from the U.S. National Institute of Standards and Technology's AI Risk Management Framework, and look to develop certain concepts that would help mitigate potential risks associated with agentic AI.
Among other points in relation to trustworthy AI systems, the efforts could focus on criteria such as: safe, for example, guardrails on recursive self-improvement; explainable and interpretable, such as, requirements for AI agents to use an English chain-of-thought expression rule and not solely agentic AI communication protocols; and accountable and transparent, for example, the establishment of some degree of government oversight of operations.
The details of any regulatory solution would need to be carefully crafted in consultation with key industry players and other stakeholders. My sense is that something, even if not perfect, will beat nothing in this context. And, while concerns about competition from China should be considered, such issues should not override legitimate needs for protective self-governance.

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.
Submit for CPEsContributors:
Brian Hengesbaugh
CIPP/US
Global Chair, Data and Cyber
Baker McKenzie



