Reporting Back from WAIC 2026: How China’s AI Ecosystem Is Adapting
Four experts assess how China is building around compute constraints across hardware, open models, safety, data, and governance.
Editor’s note
Given that AI governance could emerge as a topic ahead of the anticipated September 24 Trump-Xi summit, we bring together on-the-ground observations from three CCA contributors who traveled to Shanghai for the 2026 World Artificial Intelligence Conference (WAIC): Alvin Wang Graylin, Paul Triolo, and Ran Guo. Their contributions examine how China’s AI ecosystem is evolving across compute, governance, safety, commercialization, and data. Kristy Loke, a research fellow with the Machine Learning Alignment & Theory Scholars (MATS) program who studies China’s AI governance, adds a broader strategic lens by examining Xi Jinping’s articulation of an open AI strategy and its implications for U.S.-China technology competition. Taken together, these observations offer a corrective to a chip-centric view of U.S.-China AI competition. Compute constraints are real, but the conference revealed an ecosystem adapting around them. The governing question for U.S.-China technology policy is therefore how export controls interact with China’s increasingly durable adaptations.
For a broader take on the themes across this issue, read Lizzi C. Lee’s Substack post: When the Constraint Becomes the Strategy.
In this issue:
Alvin Wang Graylin — Compute constraints, World Artificial Intelligence Cooperation Organization (WAICO), policy signals, and data
Paul Triolo — Hardware integration and China’s safety-evaluation ecosystem
Kristy Loke — Openness as China’s strategic narrative
Ran Guo — Data governance and the economics of health AI
Terms readers need
FLOPs and compute scarcity: FLOPs, or floating-point operations, are a measure of computing work. In this issue, compute scarcity refers to limited access to leading accelerators for training, inference, and safety evaluation.
Blackwell and the Atlas 950 SuperPoD: Blackwell is Nvidia’s advanced accelerator architecture. Huawei’s Atlas 950 SuperPoD is a system-level cluster designed to link as many as 8,192 Ascend 950 NPUs into a single large, logical computing system.
Open-weight: An open-weight model is one whose trained parameters are released for others to download, modify, and deploy, even when the full training data or development process is not publicly available.
1. Alvin Wang Graylin: Compute adaptation, institutions, and data
By Alvin Wang Graylin, Non-Resident Honorary Senior Fellow on Technology, Asia Society Policy Institute’s Center for China Analysis
Compute constraints, WAICO, open-weight economics, safety priorities, robotics, data, and engagement options.
Key takeaways
Compute scarcity is now a managed condition rather than a crisis. China’s labs still want more high-end silicon, but they have restructured around the constraint. The cost is measured not only in floating-point operations (FLOPs), a standard measure of computing work, but also in engineering time spent adapting models to domestically produced AI chips.
Export controls and entity-list designations—not tariffs—are now the main grievance. Multiple interlocutors said tariffs have receded as a concern, making delisting the most requested goodwill signal—one framed as low-cost for Washington and highly symbolic for Beijing.
Chinese frontier labs generally treat safety as a compliance obligation rather than an independent research priority, and several interlocutors argued that U.S. compute restrictions can undermine safety by leaving labs with fewer resources for testing and evaluation.
At the regulatory level, Chinese authorities remain focused primarily on information security and content governance — ensuring that AI-generated content complies with state content rules and avoids politically sensitive topics — rather than on catastrophic misuse or the possibility that advanced AI systems could move beyond effective human control. As a result, proposals framed around such loss-of-control scenarios are unlikely to gain traction; those centered on shared mitigation of bad actors in cyber, bio, and chemical domains may prove more viable.
At the institutional level, WAICO was the conference’s main development: 29 founding signatories, a Shanghai headquarters, no major Western democracy, and a keynote from Xi presenting it as a milestone. It is an infrastructure-and-capacity initiative aimed at the Global South, running alongside rather than within the UN track convened in Geneva two weeks earlier. Xi again emphasized open source and AI as a public good.
At the same time, the open-weight consensus may be less durable than Chinese labs believe. Their leaders reported no government pressure to close models, even as public reporting indicated that Beijing was considering export restrictions on advanced domestic models.
Compute: real constraint, real workarounds
The clearest evidence of adaptation to China’s compute constraints appears at the compute layer. Practitioners repeatedly described Huawei’s accelerators as roughly two generations behind leading international chips, with one calling them “less than H100.” Frontier model training therefore still relies largely on international Blackwell-class hardware accessed through offshore partners. At the same time, the engineering work required to adapt and optimize models for domestic silicon adds another burden to China’s compute deficit.
The public record reinforces this picture. Huawei used WAIC to debut the Atlas 950 SuperPoD, an 8,192-chip system. The strategy is clear: compensate for weaker individual dies through system-level scale-up, interconnect, and cluster engineering. This is an expensive but viable route to higher training throughput, though it is considerably less effective at reducing inference costs per token.
The debate cuts both ways. Restriction advocates argue that the two-generation gap and domestic tuning overhead are precisely the intended effects, and congressional projections of indigenous H200-equivalent capability in 2028 suggest the policy is buying time. Critics counter that offshore training, scale-up architectures, and algorithmic efficiency are the adaptations the controls were meant to prevent—and that successful workarounds become permanent while U.S. export controls remain revisable.
My assessment is that the controls impose measurable costs and are not being cleanly circumvented at the frontier. But adaptation is now institutionalized, reducing the return on further tightening while raising the costs to bilateral trust and revenue earned by U.S. firms. The policy is working narrowly while losing ground more broadly.
Model layer: economics and openness
At the model layer, economics and openness are also reshaping the market. Domestic inference monetization remains weak, except in video generation, where Chinese consumers and businesses demonstrably pay. Text and general-assistant inference generate little meaningful domestic revenue. As a result, international inference demand has become the growth engine, with an increasing share of Chinese lab revenue coming from outside China. This matters for assessing the commercial effects of restricting Chinese model access abroad.
DeepSeek, meanwhile, is now partially state-owned and has no conventional business model. Its valuation rests on brand equity as a national champion and on the expectation that the state will underwrite its long-term success. It intends to remain open-weight and is moving toward multimodality on the view that multimodality is a prerequisite for AGI.
Across Chinese labs, AGI is defined instrumentally as “smart enough to do human work,” rather than as a conscious or godlike system. It is viewed as one long-term goal among several, not a singular technological end point. This difference in framing may fuel mutual misperceptions between Chinese practitioners and parts of the U.S. AI debate.
These pressures have also narrowed the field sharply. A year ago, the expo floor featured more than 100 models; that number has since fallen dramatically. Regional champions remain, but consolidation is well advanced.
Openness, however, appears to be driven more by commercial than political considerations. Lab leaders said they faced no government pressure to close weights and characterized Alibaba’s more closed posture on certain models as a business decision rather than a technical or political one.
Reuters and the Financial Times reported in July that Chinese authorities were considering tightening export controls on advanced AI models and semiconductor technology, following earlier meetings with major tech firms about restricting overseas access to China’s most capable models, including those not yet released. Either the labs are not yet in the loop, or the policy is contested internally, or the restriction under consideration is narrower than a general move to closed weights. All three readings have very different implications for the open-versus-closed debate, making this the most important issue to track over the next quarter.
Safety and governance: what Chinese actors actually prioritize
These technical and commercial shifts also shape how Chinese actors approach safety and governance. Contacts close to China’s regulatory apparatus described the operative definition of “safety” as security and information control. Attention to CBRNE misuse is comparatively thin, and loss-of-control risk remains largely absent from lab priorities, though it is gaining attention in some safety institutions. At the lab level, developers follow government rules and already view existing constraints as burdensome. Several argued that if safety were a genuine U.S. priority, compute availability would increase rather than decrease because resource-constrained labs are more likely to cut corners. Cooperation is possible, but it depends on framing.
Even within these constraints, there are openings for cooperation. An International Atomic Energy Agency (IAEA)-style international standard for safety evaluation, potentially linked to the UN, drew unprompted support from multiple interlocutors—the most concrete multilateral opening I encountered. The clearest practical proposal emerged from a session on AGI cooperation, which made the week’s strongest case for governance interfaces rather than legal convergence. Drawing on private international law, the argument was that shared rulebooks are unnecessary if interfaces, adapters, and conflict rules exist. Cooperation without trust could rest on shared vocabularies and protocols, with the 1972 Incidents at Sea Agreement as a precedent. Mutual recognition and shared test suites could provide enforcement, producing a common incident taxonomy, reporting schema, and triage thresholds.
Yet the trust deficit remains the binding constraint. Interlocutors were willing to cooperate but doubted that the United States would honor agreements. A recurring observation was that AI diplomacy lacks a Kissinger-like figure with standing on both sides.
WAICO and the institutional architecture
The same emphasis on practical cooperation and capacity building is visible in the emerging institutional role for the World Artificial Intelligence Cooperation Organization (WAICO). Twenty-nine countries signed the founding agreement on July 16, one day before WAIC opened. Wang Yi signed for China, and Guterres attended. Headquartered in Shanghai, WAICO is an independent intergovernmental body invoking UN Charter principles. Reported founding members include Russia, Pakistan, Indonesia, Kazakhstan, Laos, Belarus, Serbia, Brazil, Cuba, and Venezuela. In his first WAIC keynote in the summit’s nine-year history, Xi announced 5,000 AI training opportunities for participants from developing countries over five years, along with cooperation centers with ASEAN and the African Union.
At the same time, WAICO is emerging alongside the UN track. The first UN Global Dialogue on AI Governance convened in Geneva on July 6–7, marking the first dedicated meeting of all UN members on the subject. Guterres advanced a Global Fund for AI covering skills, data, and affordable compute, and said more than 20 member states had nominated centers for a UN-supported Global Network for AI Capacity Building. Among more than 1,500 submissions, most non-government groups ranked safety first, while governments prioritized capacity building.
This overlap between the UN Global Dialogue on AI Governance and WAICO supports two competing interpretations. The competitive view is that WAICO is a parallel institution designed to set standards and lock in dependencies before the UN track produces anything binding; the absence of major Western democracies is the point. The complementary view is that WAICO’s agenda—capacity building, training, and compute and data access for developing states—closely matches the proposed UN Global Fund, creating an opportunity for integration rather than a fork.
My assessment, then, is that the competitive reading is right about intent and the complementary reading about substance. That argues for engagement rather than boycott. Ignoring WAICO would cede the Global South AI capacity agenda just as the UN has validated it as a priority. Observer status, technical participation in evaluation standards, and interoperability between WAICO programs and the proposed UN fund are lower-cost alternatives.
Subnational industrial policy
Below the international level, China’s AI expansion is also being driven by local industrial policy. Local governments provide office space, fast-tracked logistics, limited compute and telecom resources, and access to city and provincial leaders—the last of which is often described as the most valuable input. Within this system, regional leaders are consistently assessed on four metrics: job creation, business and tax-base growth, innovation output, and social stability. Every subnational AI policy choice maps back to these priorities.
Yet this support creates its own tension. Both central and local governments are seeking startup equity, while firms planning international expansion often resist, recognizing that state ownership can become a liability abroad—an underappreciated tension in China’s AI capital structure. At the same time, municipal incubators and AI education programs are proliferating rapidly.
Robotics: involution now, consolidation expected in 12 to 24 months
Local support is especially visible in robotics, where rapid expansion has brought both scale and intense competition. The expo featured more than 200 robotics firms, and participants openly described the sector as being in an involution phase, with consolidation expected within one to two years.
Unitree offers an important reference point. It is fully vertically integrated in component manufacturing, although roughly 80 percent of its assembly work remains manual. The company is trying to automate, but the current process, while archaic, is adequate at present production volumes. It expects costs to fall by around 80 percent over time. Unitree is also the only Chinese player currently able to ship globally with support infrastructure and partners in place, including parts replacement for 1.5 to 2 years. Even so, its 2025 volumes remain relatively small: approximately 30,000 to 40,000 quadruped robots, 5,000 to 10,000 full humanoids, and 5,000 to 10,000 non-legged humanoids. Its software and training work also remains limited, and leadership was reportedly skeptical of humanoids until relatively recently.
More broadly, the hardware and supply-chain advantage is real, durable, and underestimated in Washington. The genuine constraint is software, training, and manipulation policy—the layer most exposed to compute restrictions. Chinese embodied AI capability should therefore be measured by software progress, not unit shipments.
Beyond humanoids, non-humanoid service robots are already deployed commercially, and in major cities more than half of the vehicles on the road are electric. The physical-world deployment base is further ahead than many U.S. visitors expect.
Data: the most underrated asymmetry
Yet hardware and robotics are only part of the structural picture; data may be an even more consequential asymmetry. On healthcare access, one firm described free access to data covering roughly 300 million patients annually, spanning more than 4,000 test types and complete patient records. There is no analogous access regime in the United States or the European Union.
The capabilities presented were also substantial. A fellow of the Chinese Academy of Engineering and the president of Ruijin Hospital described findings from a 15-year cohort study of 150,000 people, including a model that predicted major adverse cardiac events over 10 years with reasonably strong accuracy (AUC of approximately 0.78), and a 25-protein panel that predicted 10-year mortality with very strong discriminatory performance (AUC of approximately 0.90).
The business model may also be evolving toward a “data dividend” model. Under this vision, hospital care would trend toward being free or paid for through data, while hospitals commercialize the resulting models and shift medicine from reactive treatment to prediction, prevention, and early intervention.
The compute debate has crowded out the data question. In health data, China’s advantage is structural, growing, and beyond the reach of export controls. It also strengthens the case for a cooperative global data pool: cross-site validation would benefit both sides scientifically without costing either side its strategic position.
Capital markets and exit paths
Turning these technical advantages into durable businesses, however, depends on financing and viable exit paths. The STAR Market (科创板) functions as the domestic exit venue and permits listing without profitability, although multiples remain well below international comparables.
That domestic route is further constrained by Beijing’s reluctance to see its leading firms list internationally, compressing the exit menu.
Hong Kong therefore retains its role as the financial bridge to global capital and is positioning itself as a compliant AI sandbox with an East-West standards role.
One indication of this role is Hong Kong’s deployment of HKPilot, a government document-processing copilot built on the locally developed HKGAI LLM. By November 2024, more than 800 officers across over 20 bureaus and departments were participating, and by April 2025 the trial had expanded to more than 70 government departments. HKGAI subsequently released V3 of its model in June 2026.
What Beijing is actually asking for
Taken together, these constraints and adaptations help explain the priorities Chinese interlocutors raised in discussions with the United States, ranked here by frequency and intensity.
The most frequent request centered around the removal of firms from sanctions, export-control, and risk lists. Alibaba and Tencent are lobbying against designations they consider unjustified, and delisting is seen as a cheap, legible signal of good faith.
Access to TSMC was presented as a more achievable request than access to EUV tools. Chinese contacts assessed domestically usable EUV as roughly five years away.
Interlocutors also expressed willingness to co-invest in the United States and in Global South AI infrastructure, preferring a new brand distinct from both the Belt and Road and the Marshall Plan.
They also raised reciprocal restraint on competitive practices. Beijing signaled willingness to push domestic firms to moderate the hyper-competitive export behavior they have been trained into domestically, acknowledging that these practices are alarming firms in every market they enter.
Huawei, however, was not part of the request of removal from the sanctions, export-control, and risk lists. The company has internally accepted its designation as permanent and does not expect that status to change.
Implications and judgment
The case for taking these openings seriously is that the requests are specific, ranked, and internally consistent. Delisting a small number of non-sensitive firms is reversible and verifiable, while interest in IAEA-style evaluation standards and mutual test recognition is technically substantive. The Global South co-investment offer aligns with WAICO’s program, and restraint on aggressive export practices would address concerns shared across the United States, Europe, Japan, Korea, and India.
The skeptical case, however, is that each opening is low-cost for Beijing but consequential for Washington. Delisting transfers real capability in exchange for goodwill. China’s safety agenda remains centered on information control, ensuring that AI-generated content complies with state rules and avoids politically sensitive topics, and could legitimize content-governance norms the United States opposes. WAICO embeds Chinese standard-setting under multilateral cover, while possible Chinese controls on model exports suggest Beijing may adopt the same playbook centered on restrictions it condemns.
My judgment is that the skeptical case is right about motive but wrong about consequence. The test is not whether an arrangement is costless to Beijing, but whether it improves on the status quo and creates a new verification surface. A conditional pilot delisting, a shared incident vocabulary, and a jointly recognized evaluation suite all meet that test without requiring trust. The Incidents at Sea precedent matters precisely because it was concluded between adversaries who expected to remain adversaries.
The more fundamental objection, therefore, is that the United States lacks both an interlocutor structure capable of executing such a technical arrangement and a domestic political coalition that could sustain it. That is the first gap to address.
What to watch over the next 90 days
WAICO’s first substantive work program and whether any OECD member seeks observer status.
Whether the UN Global Fund for AI recommendation to the General Assembly creates a channel that intersects WAICO’s capacity-building agenda.
BIS action on the AI diffusion rule replacement, targeted for end of fiscal year, and the fate of the Banks amendment—the AI OVERWATCH Act, which would codify tighter controls on advanced AI-chip exports to countries of concern—in the fiscal year 2027 National Defense Authorization Act.
Any movement on entity list removals, which would be the clearest available evidence that the delisting channel is live.
Robotics consolidation, including the first significant failure or acquisition among the 200-plus expo participants.
Additional observations
Apple is allegedly using Qwen models in Apple Intelligence, a claim partially corroborated by prior public reporting on the China deployment, although the current scope still requires confirmation. Tencent is reportedly acquiring Manus at a price above a competing Meta offer.
2. Paul Triolo: Hardware adaptation and China’s safety-evaluation ecosystem
By Paul Triolo, Non-Resident Honorary Senior Fellow on Technology, Asia Society Policy Institute’s Center for China Analysis
Advances across China’s AI hardware stack and the emergence of a distributed, specialized network of safety and evaluation institutions.
The 2026 WAIC in Shanghai highlighted major advances across China’s AI stack since the 2025 edition, which I also attended. President Xi Jinping’s opening speech framed the conference around two main themes: the benefits of AI diffusion, including to the Global South through the new 29-country World AI Cooperation Organization (WAICO), and the need to keep AI safe and secure. Xi’s safety comments “could have been written by me,” a leading AI safety researcher quipped during a discussion on the margins of the conference.
The conference came as U.S.-China competition in AI hardware and models reached new highs, while the release of Anthropic’s Mythos model and debate over the released, safeguarded Fable 5 counterpart intensified U.S. questions about how to gate frontier releases. Soon after, the OpenAI GPT 6.0 model’s escape from its sandbox and attack on Hugging Face underscored the need for a regulatory regime around advanced models. Moonshot’s release of Kimi K3 just before WAIC also fueled U.S. debate over Chinese open-weight models. These issues ran through public panels, closed-door meetings, and sidebar conversations near the main venues.
What stood out during my tour of the exhibition was the sharp increase in the number of Chinese AI hardware developers offering GPU clusters for training and inference. Moore Threads, Biren, Enflame, MetaX, and Huawei displayed larger GPU or Ascend NPU arrays, typically labeled as tested or “ready” for leading Chinese models from DeepSeek, Moonshot, Zhipu, Alibaba, or MiniMax. Tight integration between hardware and model software was a central theme.
This does not mean all Chinese model developers are training advanced models on domestic hardware. Moonshot has allegedly accessed Nvidia Blackwell compute in Southeast Asia, while Zhipu has trained a version of GLM-5.2 on Huawei’s Ascend architecture. The Atlas 950 SuperPoD was displayed for the first time, and a Huawei engineer walked me through its technical design. Huawei’s system-level answer to weaker individual accelerators links up to 8,192 Ascend 950 NPUs through UnifiedBus, unified memory addressing, and high aggregate bandwidth, allowing the installation to behave more like one giant logical computer than a conventional GPU cluster. The architecture should be especially useful for communication-heavy mixture-of-experts (MoE) training and high-volume inference. Its earliest users, however, will likely be Huawei/Pangu, state-backed clouds, telecom operators, SOEs, and laboratories that need a fully domestic stack—not independent frontier labs with dependable Nvidia access.
Assuming Moonshot can obtain thousands of Blackwells, it will likely keep flagship pretraining on Nvidia, because CUDA maturity, proven scaling, stronger per-device performance, and researcher productivity outweigh Ascend’s strategic appeal. Moonshot and Alibaba would move workloads gradually—starting with inference, fine-tuning, reinforcement learning, overflow capacity, and redundant training runs—and shift major pretraining only once the 950 demonstrates sustained utilization and reliability, or Nvidia supply and regulatory risks become unacceptable. Zhipu can support a serious Ascend porting and capacity-reservation program after recent capital raises, but renting Huawei or state-cloud capacity and dual-porting selected models is more plausible than operating an entire 160-cabinet SuperPoD. The full Atlas 950 is not scheduled until the fourth quarter of 2026; once leading developers have tested it, however, it could be a game changer.
The broader outlook for Chinese GPU makers is therefore improving. SMIC is likely to expand advanced-node capacity in Shanghai, with the government working alongside SMIC, Huawei, and other chip designers to allocate it. By year-end, more domestic GPU clusters and Huawei 950 SuperPoDs should be available for training and inference. Chinese developers will have greater access to advanced Nvidia hardware outside China, more domestic training capacity, and more inference compute to commercialize models such as Kimi K3. WAIC also underscored the push for stronger business models as firms list or prepare to list in Shanghai and Hong Kong, raise capital, and expand capacity. The CXMT IPO will channel additional capital into expansion, including high-bandwidth memory. Business models, markets, capex, and flexibility were hallmarks of the exhibition.
AI Safety, major evolution in thinking since WAIC 2025
The panels, closed-door meetings, and sidebar conversations on AI safety also showed how much thinking has evolved since the Paris AI Action Summit and last year’s WAIC. Xi’s reference to AI safety was groundbreaking and signaled that China’s fast-growing safety community should now be taken seriously. Western debate has traditionally focused on catastrophic risks, loss of control, and misalignment. In China, anquan (安全; safety)has more often referred to public safety and social stability, with less attention to loss-of-control or national-security risks involving cyber operations or CBRN capabilities. WAIC suggested this is beginning to change.
Rather than creating a single equivalent of the UK AI Security Institute or the U.S. Center for AI Standards and Innovation, Beijing is assembling a distributed network of frontier laboratories, governance institutes, standards organizations, and model evaluators. WAIC suggested that this ecosystem is maturing into a potentially important counterpart for international safety cooperation. China’s AI safety community has come a long way.
For much of the past two years, discussions about China’s approach to AI safety have focused on what appeared to be missing. Compared with the UKAISI or CAISI, China seemed to lack a single institution responsible for evaluating frontier AI systems before deployment. Safety research existed, regulators had established security assessment procedures for generative AI models, and leading universities published internationally on interpretability and alignment, but these activities appeared fragmented and often disconnected. The dominant question among foreign observers became: Where is China’s AI Safety Institute? As I noted last year, the emergence of the China AI Safety and Development Association (CnAISDA) at the Paris AI Action Summit was an important milestone in this process.
But more than one year later, discussions at the 2026 World AI Conference suggested that this question may have been the wrong one all along. Rather than unveiling a centralized institution modeled on Western counterparts, the CnAISDA was a network of organizations, and the 2026 WAIC highlighted a growing network of organizations that collectively perform increasingly important functions. Throughout the conference, in addition to CnAISDA, the Shanghai AI Laboratory, Tsinghua University’s Institute for AI International Governance, researchers associated with the Beijing Institute of AI Safety and Governance, standards bodies including CAICT and TC260, and major frontier AI developers appeared together in technical workshops, policy discussions and international dialogues. The picture that emerged was not one of institutional duplication, but of an increasingly specialized ecosystem in which different organizations contribute distinct capabilities.
This distributed model is not an accident. It reflects China’s broader approach to governing strategic technologies. Rather than concentrating authority in a single independent agency, Beijing frequently relies on overlapping institutions that combine research, industrial policy, standards development, and government coordination. The same pattern can be seen in semiconductors, quantum technologies, and biotechnology. AI safety increasingly appears to be following a similar trajectory.
Shanghai AI Laboratory: Building China’s Technical Evaluation Engine
At the WAIC in Shanghai, one of the most interesting presentations came from Professor Zhou Bowen, the Director of the Shanghai AI Laboratory (SAIL). SAIL has quietly emerged as perhaps the country’s most technically capable institution for evaluating frontier AI systems. Although widely known internationally for the InternLM family of open-weight language models, InternVL multimodal systems, and AI for Science initiatives that I have documented in my Substack, the laboratory’s significance extends well beyond model development. By training frontier-scale models itself, SAIL has developed precisely the engineering expertise required to evaluate increasingly capable AI systems.
This distinction matters. Evaluating frontier models involves far more than prompting public APIs or measuring benchmark performance. Researchers require access to distributed training infrastructure, inference pipelines, model checkpoints, activation data, and internal architectures. They need to understand how models behave under different decoding strategies, how safety fine-tuning affects downstream capabilities, and how evaluation benchmarks themselves can become contaminated. Institutions that build frontier models inevitably acquire expertise that cannot easily be replicated through external testing alone.
SAIL has complemented this expertise by developing one of China’s most sophisticated model evaluation infrastructures. OpenCompass has evolved into a comprehensive evaluation framework covering hundreds of language and multimodal benchmarks across both open and proprietary models. Rather than treating evaluation as a one-off benchmarking exercise, OpenCompass increasingly resembles shared scientific infrastructure, enabling reproducible comparisons across successive generations of frontier models. Its importance within China’s AI ecosystem parallels the role played by platforms such as HELM or LM Arena internationally, while extending more deeply into Chinese-language evaluation and multimodal systems.
The laboratory has also expanded its explicit focus on AI safety. Through its AI45 initiative, SAIL now conducts research spanning trustworthy AI, embodied AI safety, interpretability, AI for Science safety, and broader questions surrounding advanced AI systems. While much of this work remains technically oriented, it reflects an important evolution. Safety is no longer treated primarily as content moderation or compliance with existing regulations. Instead, SAIL frames safety increasingly as an engineering challenge requiring systematic evaluation throughout the model development lifecycle.
Zhou’s presentation at WAIC 2026 demonstrated how quickly China’s technical evaluation capabilities are maturing. Rather than focusing on AI governance principles or regulatory frameworks, Zhou emphasized the engineering challenge of evaluating increasingly capable frontier models and AI agents throughout the model lifecycle. His framework integrated capability assessment, safety evaluation, agent behavior, tool use, and continuous testing into a unified evaluation pipeline, reflecting the perspective of a frontier model developer rather than a policymaker. This approach is particularly significant because it suggests that organizations such as SAIL are developing the technical infrastructure—including evaluation platforms such as OpenCompass, benchmark engineering and large-scale testing methodologies—needed to systematically characterize the capabilities and failure modes of frontier models. In many respects, SAIL appears to be evolving into China’s closest analogue to an engineering-focused evaluation laboratory, where safety is treated as an extension of model development rather than simply a regulatory compliance exercise. The emphasis is on building scalable evaluation systems that can keep pace with rapidly advancing foundation models and increasingly autonomous AI agents.

By contrast, the work emerging from Tsinghua University’s Institute for AI International Governance (I-AIIG) and Zeng Yi’s Beijing Institute of AI Safety and Governance begins from a different premise: defining what constitutes frontier AI risk and how those risks should be incorporated into national and international governance frameworks. Tsinghua has focused on developing international evaluation standards, safety capability maturity models and mechanisms for cross-border cooperation, while Zeng Yi’s group has pushed China’s frontier risk research toward questions of agentic autonomy, AI for Science, embodied AI, catastrophic and even existential risks through initiatives such as ForesightSafety Bench.
Their work increasingly resembles that of organizations like CAISI or the International AI Safety Report community, emphasizing comprehensive risk taxonomies and scientifically grounded evaluation methodologies rather than benchmark engineering alone. Taken together, these two communities illustrate an emerging division of labor within China’s AI safety ecosystem: Shanghai is building much of the technical machinery needed to evaluate frontier models, while Beijing is defining the conceptual frameworks, governance architecture and international standards that determine which risks should be evaluated and why. The challenge now is institutional—integrating these complementary strengths into a trusted national capability for independent frontier model evaluation, comparable to the role that organizations such as METR, Apollo Research and the UK AI Security Institute are beginning to play in Western AI governance. During my panel presentation on prospects for international cooperation, I mentioned the proposal from Google DeepMind CEO Demis Hassabis for a self-regulatory organization (SRO) in the United States that over time could be a concept embraced more globally, and I also stressed the need for independent third-party evaluation organizations as part of an emerging consensus in the United States and the broader AI safety community.
For China, however, WAIC also highlighted several challenges in this area. SAIL’s strengths, for example, also reveal its limitations. Despite its technical sophistication, it remains simultaneously a frontier model developer, a government-supported research institution, a commercial operation, and a potential evaluator of competing models. There is little public evidence that it possesses statutory authority to demand pre-deployment access to proprietary models developed by Alibaba, Tencent, DeepSeek, Zhipu, or Baidu, or that its evaluation findings automatically influence regulatory approval. In other words, SAIL has accumulated much of the technical capacity associated with a frontier model evaluator without yet occupying the institutional role of an independent national evaluation authority.
Perhaps the most significant implication of WAIC 2026 is that China is no longer asking whether frontier AI requires dedicated safety institutions. That debate has largely been settled. The more important questions now concern how responsibilities should be divided across an increasingly diverse institutional landscape, how evaluation methodologies should evolve alongside rapidly advancing frontier models, and how China’s emerging ecosystem should engage with counterparts abroad.
For international AI governance, this evolution matters enormously. As the United States, United Kingdom, Japan, Singapore and others continue building their own frontier model evaluation capabilities, China is constructing a parallel—though institutionally distinct—architecture. The differences are real, particularly regarding independence, transparency and regulatory authority. Yet the underlying technical challenges are remarkably similar. Evaluating increasingly autonomous, multimodal and scientifically capable AI systems will require common methodologies, shared benchmarks and ongoing dialogue across national boundaries. Some of this will begin happening when the United States and China meet in September for the first time to discuss real frontier model guardrails and regulation. This will not be easy, but Chinese organizations now have much more to bring to the table than was the case in Paris in early 2025 or the WAIC in July 2025.
Competition over frontier AI capabilities is likely to intensify. But if WAIC 2026 demonstrated anything, it is that competition need not preclude cooperation on the science of evaluation itself. Indeed, the emergence of increasingly sophisticated AI safety ecosystems on both sides may finally provide the institutional counterparts necessary for sustained technical engagement on one of the defining governance challenges of the AI era.
3. Kristy Loke: Openness as China’s strategic narrative
By Kristy Loke, Research Fellow, Machine Learning Alignment & Theory Scholars (MATS) program
Beijing’s open-AI strategy and its implications for competition, governance, ecosystem power, and selective U.S.-China coordination.
Openness as a long-term commitment
A popular question among China watchers is: what does China want from AI? At the World Artificial Intelligence Conference (WAIC), President Xi Jinping offered his clearest answer so far. China wants to partake in, be a leader in, and share the benefits of AI – and it wants to do so through a strategy of openness. Xi summarized China’s global AI contributions in a four‑point framework – deepening the strategy of openness and promoting win–win development, improving risk awareness and ensuring safety, security, and controllability of AI, encouraging multiculturalism, and promoting consensus-based global governance – with openness sitting at the heart of all four.
Whether future Chinese AI takes the form of open‑weight AI releases, which has become the focus of recent debates, is almost beside the point; the commitment is more fundamental. Openness is a long‑term orientation: not just via open‑weight models, but by encouraging Chinese AI firms to keep sharing the know-how, infrastructure, and resources for others to build, own and deploy AI. China’s leaders believe there are enough benefits from AI to go around, and that openness is the path to diffusion and value creation. By defining its AI vision around openness, Beijing implicitly rejects an AI arms‑race framing in which a few months’ frontier AI model lead is seen as decisive.
How will China govern openness?
Analysts have often portrayed Chinese leaders and regulators as reckless, anxious, or rigid in balancing AI development and governance. Recently, this framing has resurfaced in warnings about reflexive overregulation or blanket bans on frontier open models. So far, the evidence suggests otherwise.
Since 2023, Beijing has pursued a pro‑governance and pro‑development approach. The AI‑Generated Content Interim Measures laid the groundwork for a pre‑ and post‑deployment transparency regime, with a focus on controlling prohibited, harmful, or politically sensitive AI-generated material, and were paired with a State Council message for regulators to tread lightly and smartly: grasp emerging risks, issue timely and narrow prohibitions, and avoid deterring good‑faith innovation. Within this context, models such as DeepSeek-V3, GLM-5.2 and Kimi K3 managed to emerge. Remarkably, this commitment to governance has not prevented China’s AI model sector from developing, keeping up, and at times, leading.
For open-weight AI, we should expect a similar balance: prohibiting clear misuse and unchecked capabilities, encouraging experimentation where care can be demonstrated, and continuing to explore risk tiers, pre-deployment testing, disclosure, and post-deployment monitoring. If that balance holds, the incentive for a blanket ban remains low.
From containment to an open AI strategy
China’s embrace of open innovation predates the LLM wave. Under repeated rounds of tech containment since 2018 – from Trump’s ZTE and Huawei sanctions to Biden’s tightening chip controls – Beijing was forced to rethink its tech and innovation priorities. Within weeks of the ZTE shock, Xi told leading scientists that core technologies such as semiconductors could not be “obtained, bought, or begged for,” prompting debate over which parts of the globalized chip supply chain had to be brought home. The debate ultimately landed on the side of the importance of core tech indigenization and continued links with innovation channels and sources abroad. Xi’s WAIC reference to “Chinese‑made intelligence” (中国智造) captures this ambition: to be a key exporter of AI capability by being a reliable, trustworthy and relatively affordable supplier, in turn benefiting from both business and creative ideas and innovation from abroad.
The strength of Chinese open models reinforced this open orientation. When DeepSeek-V3 was released in late 2024 as a cheaper, more manipulable alternative to proprietary U.S. systems, the U.S. stock market and global developers took notice. In line with its pragmatic strategy, Beijing and its advisers moved to further center openness in China’s AI posture at home and abroad. This is evidenced by growing legal discourses over how to best govern open-weight AI to help it develop safely and by various Qiushi pieces acknowledging open-source AI as central to China’s AI strength. Given this context, Xi’s WAIC speech is best read as the culmination of that evolution, not a sudden pivot.
Openness as China’s AI edge—and a challenge for the United States
China’s commitment to openness serves both domestic and external goals. At home, openness promotes more accessible AI and faster innovation‑led economic transformation. Abroad, openness and shared benefits are framed as an antidote to an “AI Iron Curtain,” positioning China’s open models as affordable and reliable options for developers worldwide.
By contrast, the United States is quietly starting to lose three important competitions by over‑emphasizing frontier AI lead and containment as a winning strategy, and in the process, inadvertently prioritizing tech supremacy, exclusivity, and unilateral actions. In trying to protect and widen the United States’ frontier AI edge by any means possible, the United States is also making itself less competitive on AI accessibility, cost, ecosystem pull, and soft power, thus losing both friends and influence. At home, the lack of an inclusive and distributive vision for AI also deepened economic and environmental anxiety among a growing part of the population. While it is not too late for the United States to reconsider, an AI strategy centered around openness will look quite different from the one it has pursued over the past decade.
The narrow window for U.S.–China AI coordination
Recent weeks show both the pace of progress and the sharpness of emerging risks. GLM-5.2 and Kimi K3 were announced just before WAIC. Soon after, Hugging Face disclosed a cyber incident involving OpenAI in which GLM-5.2 was used defensively after a U.S. proprietary model refused requests for cyber defense. The episode highlights cross-border entanglement and growing challenges of control and security. It also undercuts the idea that U.S.-China AI development and governance are inherently zero-sum: models from one country are already defending against vulnerabilities in another.
From WAIC, notably, Xi’s framing of AI risks as “internal” and “external” (to AI systems) overlaps with concerns in the West over frontier AI control and misalignment risks, and misuse risks, even if the language differs. The reality is that the two are facing a similar and growing set of frontier AI risks, and as the leading AI powers, have the most to lose from unsafe AI development and deployment. Only by recognizing this reality can Washington move from containment instincts to much-needed selective coordination with Beijing around such risks. The time to act is now.
4. Ran Guo: Data governance and the economics of health AI
By Ran Guo, Affiliated Researcher, Asia Society Policy Institute’s Center for China Analysis
Data governance, trusted data spaces, and the commercial logic that requires health-AI products to prove system-level savings for public insurance.
Over ten days, from July 9–19, I attended events in Beijing and Shanghai: the 2026 China Internet Conference (“Data for AI” and “AI + Health” forums), a Tongji University workshop on AI safety and security, and WAIC. Two themes stood out: data governance and AI + health.
1. Data governance: imagination, incorporation, and new practices
My strongest impression is that many practitioners, analysts, and policymakers approach AI governance through data policy, especially data use and security. China’s developmental and regulatory approach has moved from “大数据” and “数字化” (“big data” and “digitalization”) toward “数智化” (digital intelligence or AI-enabled digitalization), meaning data-driven, AI-integrated industrial transformation. High-level forums discussed agent guardrails, safety by design, and cybersecurity, but industry sessions repeatedly returned to high-quality datasets, sharing infrastructure, and agent-facing data management as bottlenecks to adoption.
I mentioned in an earlier paper that China’s data policy was centered on three moves: data assetization, data exchanges, and public data franchising. The conferences highlighted several new developments that are woven into China’s data governance strategy:
Scenario-based data management. Speakers repeatedly argued against building datasets before identifying potential use cases. Their preferred logic is to start from concrete demand—an industrial, administrative, or clinical scenario—and work backward to compile data catalogs, sharing mechanisms, and model architecture. Palantir’s Forward Deployed Engineer position and its ontological modelling came up repeatedly as instruments to specify use scenarios and manage corporate data resources.
High-quality, interoperable datasets as the bottleneck. The industrial breakthroughs will depend on access to private-domain data and the ability to make that data usable across organizations. The issue is not simply quantity, but interoperability: ownership, structure, format, annotation, and domain context all vary. Several speakers described traits of future data systems designed for AI agents rather than conventional databases: multimodal data, model-data resonance, and ontological modeling.
Trusted data spaces. This concept, which is being widely tested across sectors, refers to a secure environment where participants share datasets on premises to build products or models, then export the resulting products without seeing the original datasets. I visited one in Shanghai; it resembles a normal computer room with additional security settings. The biggest obstacle is incentives: companies are reluctant to place their key data in the space. Some speakers, e.g., Gao Xinmin (高新民), emphasized adding a data interoperability layer and building industry-specific data commons to incentivize sharing.
2. Health AI: sustainable innovation depends on commercialization and data interoperability
Health is a priority for both China’s data and AI strategies because of its public importance and transformative potential. Better data sharing could improve diagnosis, reduce errors, streamline triage, expand access in grassroots hospitals, and support continuous patient management. The sector also appears more willing to cooperate than many others. But implementation bottlenecks are clear, especially the lack of a payment model for AI-health products. Across two health forums and conversations with five practitioners in hospitals, medical-device companies, and health-data firms, a shared business logic emerged:
At this stage, AI saves money but does not grow the pie for hospitals and pharmaceutical companies. AI’s revenue potential derives from cost savings generated by greater efficiency and accuracy and by reducing trial and error in diagnostics, operations, and research.
This observation has important implications for the business strategies of AI-health enterprises:
The key question is: Who pays for innovation? Hospitals may receive payment for releasing datasets, primarily from technology and pharmaceutical companies. Technology companies need medical data for model training, while pharmaceutical companies need it to collect post-market real-world evidence and satisfy regulatory requirements. For both groups, hospitals may be the entry point for scaling products, but the real payer is often public health insurance (医保), with commercial insurance playing a secondary but expanding role.
The industry should no longer expect 医保 to reimburse AI products in a separate category. To commercialize, companies must instead prove that deploying their AI products saves the insurance system money overall—what insiders call “big-picture accounting,” or health economics (算大账). To do that, they must use AI to avoid what already costs the system real money: missed or mistaken diagnoses, unnecessary procedures, etc.
AI substitution has to be attached to a reimbursable object or process rather than replacing the doctor. Replacing doctors, or increasing efficiency so that they can see more patients, does not by itself create a sufficient revenue stream for AI-health companies. Revenue can be substantial, however, when AI replaces or is bundled into something already paid for—auxiliary devices, consumables, diagnostic equipment, or inefficient procedures. This is why specialized, single-purpose AI is often more monetizable than general medical foundation models, and why many industry-facing medical AI companies are more interested in the former. One example I heard was imaging AI sold to Philips: once embedded as part of the hardware cost, it can be reimbursed through the medical-device pathway.
The AI + health business model cannot simply be to “build a general medical model and wait for adoption.” It must identify where AI can substitute for costly processes, prove savings at the insurance-system level, and then secure reimbursement so that adoption can scale.














