Analysis: How Frontier AI Models Reshape US-China Tech Race
The rapid rise of frontier AI models is reshaping the debate over AI regulation in Washington as the United States and China compete to develop increasingly powerful systems. Reporter Lily LaMattina speaks to Giulia Neaher, a research analyst at The Stimson Center, who explains why restricting access to advanced AI models will not stop bad actors, especially as China's open AI models continue to advance.
REPORTER:
Hi Julia, there's been a growing debate in Washington over AI regulation. Why was Anthropic's Mythos model such a pivotal moment, and what lesson do you think policymakers took away from it?
Giulia Neaher (RESEARCH ANALYST, THE STIMSON CENTER):
The issue really, from a cyber perspective with Mythos, was the capability to identify vulnerabilities at scale, at a speed and with a comprehensiveness that had not really been present before. And so when I talk about the Mythos moment, I'm talking about kind of the response to this announcement. The US government in particular up until now has had a very hands-off approach to AI.
It was a concrete demonstration of the cyber capabilities of advanced frontier models, in a way that made government kind of stop and say, okay, you know what? This actually is dangerous. We need to do something about it.
It sparked kind of like a chain of events of people, particularly in the US government, trying to figure out how to regulate it, how to restrict access to these kinds of models. And the access restriction piece is where I think kind of the wrong lesson comes in here.
REPORTER:
So, the US approach has largely focused on restricting access to these advanced models to prevent them from falling into the hands of bad actors. Why do you believe this approach won't work in the long term?
Giulia Neaher (RESEARCH ANALYST, THE STIMSON CENTER):
China is obviously doing extremely well in open models right now. Many of the most advanced open models are coming out of China.
Mythos is currently the only model that we know of that has this level of advanced cyber capability. But like I said, nine months, a year from now, we're almost certain to see that same level of advancement in open spaces. And so, I think that, for the US government a year from now, they're going to need to be considering either blocking access to open models, which is something that they can only really enforce in the US. Or they can try to engage in trade diplomacy or in this kind of like AI development, deployment, export diplomacy that's been happening coming out of the US recently. But they're not really going to reliably be able to block bad actors in foreign countries from using advanced open models.
And the last piece just about the wrong lesson is that I think partly with Mythos and Anthropic. I worry about setting a precedent where Silicon Valley is the one who tells us when and how we're able to access AI models without a lot of input from the public or even from government stakeholders.
REPORTER:
You argue that governments should focus less on restricting access and more on building resilience. What would that approach look like in practice?
Giulia Neaher (RESEARCH ANALYST, THE STIMSON CENTER):
Well, I think that actually supporting open model infrastructure is a great way to build up our resiliency within the US. I think that one of the great advantages of openness is the ability for kind of community auditing, review of code, deployment of code in different contexts and kind of insight into potential cyber vulnerabilities and risks.
I also think, as I mentioned before, there is low hanging fruit that already exists in the cyber domain. So, for example, with Mythos, we're seeing a really sped up, rate at which vulnerabilities can be detected and located.
We really need to have the infrastructure to then address and patch those vulnerabilities as they come up. So, this could look like funding better systems that provide risk management frameworks coming out of the US government that give companies guidance on how to boost their internal processes. It could look like direct funding or tax incentives for better cybersecurity practices. There are a whole kind of range of different approaches that the government could take, and that I think we should be considering more seriously.















