What began as a contest over semiconductors and computing capacity has moved into far more fraught terrain, with commentators on both sides of the Pacific openly discussing scenarios that involve attacks on AI systems.
The tone of the discussion hardened after Hu Xijin, the former editor-in-chief of the state-backed Global Times, posted on X (formerly Twitter) a direct warning to the United States in response to recent U.S. policy proposals. Hu wrote: "If the U.S. truly dares to launch a military strike against China’s data centers, I believe China’s retaliation would not be limited to U.S. targets in the Asia-Pacific region; instead, it would directly target the U.S. mainland with missile strikes."
That public threat followed the release of a paper titled "Superpowers and AGI," authored by Jacob Stokes, deputy director of the Indo-Pacific Security Program at the Centre for a New American Security (CNAS). Stokes, who previously served on national security staff during the Obama administration, argued that the United States should develop contingency plans that include the possibility of military strikes on Chinese data centers, expanded state-backed espionage and cyber operations to prevent China from achieving artificial general intelligence, or AGI, first.
Stokes’s recommendations came shortly after OpenAI president Greg Brockman marked a milestone in generative AI by saying "Welcome to the AGI era" at the launch of GPT-6 Astra on September 3. That declaration has underscored the urgency of the scenarios Stokes lays out.
In public remarks, Stokes likened the challenge of managing AGI competition to the policy work that accompanied nuclear technology, suggesting policymakers must "work backwards based on the unique nature of the technology, in the same way that in a past era, policymakers would learn about nuclear weapons" to craft appropriate responses. He said the Department of Defense and the National Security Agency should begin considering what intelligence would be necessary to justify extreme measures, including preventive strikes prior to the emergence of Chinese AGI capabilities.
Neither the Defense Department nor the National Security Agency, nor official representatives in Beijing, have issued formal responses to Stokes’s proposals.
On the technical front, analysts at Epoch AI estimate the United States currently retains roughly a seven-month lead over China in the quality of frontier AI models. Stokes cautioned, however, that a "surprise technological breakthrough" by China remains possible and pointed to progress in robotics and other forms of embodied AI as a potential route to rapid advances.
Stokes also raised the prospect of obtaining Chinese AGI capabilities through reverse-engineering or theft, arguing that such actions could be justified "legally and normatively" given allegations of China’s prior intellectual-property theft. He noted a significant caveat: U.S. intelligence structures have not been organized for technological espionage in recent decades, and he said reorganizing those capabilities would be a necessary precondition for such an approach.
Not all experts endorsed Stokes’s proposals. William Hartung, an arms analyst at the Project on Government Oversight, warned that strikes on Chinese data centers risk triggering "a shooting war between two nuclear-armed powers that could have tragic consequences for all concerned," calling the idea "the height of recklessness."
The debate over extreme contingency measures is occurring against a sensitive diplomatic backdrop. President Trump and Chinese President Xi Jinping are scheduled to meet in Washington on September 24, and Treasury Secretary Scott Bessent has confirmed that AI governance will be included on the meeting’s agenda, according to a CNBC report dated September 2. Stokes described expectations for that summit modestly, saying the best outcome would be that discussions are "constructive" rather than producing a breakthrough on governance.
The exchange of proposals and counterstatements highlights the intersection of technology policy, national security planning and diplomacy as AI capabilities advance. The public airing of scenarios that involve potential strikes on critical infrastructure illustrates how swiftly competition over chips, models and data centers can feed into considerations ordinarily associated with higher-stakes strategic competition.