Watch or listen to the High Capacity podcast on:
Is the U.S.–China AI competition really a winner-take-all race to AGI? Why has China embraced open-source AI? And are the biggest frontier models actually the greatest security threat?
In this episode, I speak with Alvin Wang Graylin, a Digital Fellow at the Stanford Digital Economy Lab, a Senior Fellow at the Asia Society Policy Institute’s Center for China Analysis, a professor of AI and technology policy at the University of Washington, and co-author of Our Next Reality.
We discuss:
• China’s AI strategy and its focus on spreading AI throughout the economy
• Why the “decisive strategic advantage” theory may misread the U.S.–China AI relationship
• The prisoner’s dilemma, the stag hunt, and the case for cooperation on AI safety
• China’s open-source AI ecosystem and the debate over open versus closed models
• Why small, specialized AI systems may pose greater security risks than frontier models
• How export controls may be accelerating Chinese AI innovation
• China’s push into robotics, manufacturing, and physical AI
• How China’s technology industry has changed over the past three decades
Read Alvin’s essays, “Misdiagnosing the U.S.–China AI Race” and “The Biggest AI Models Are Not the Biggest Threats.”
You can also follow Alvin on X and LinkedIn, or read his Substack, The Abundanist.
Transcript
Kyle (00:00)
Welcome to the High Capacity Podcast. I’m your host, Kyle Chan, a fellow at Brookings. I’m thrilled to be joined today by my guest, Alvin Wang Graylin, a longtime China AI and technology expert with over three decades of experience working in the tech industry in the US, China, and Taiwan. He’s a digital fellow at Stanford’s Human-Centered AI Institute, a senior fellow at the Asia Society Policy Institute, Center for China Analysis, and a professor of AI and technology policy at the University of Washington. He’s also the author of Our Next Reality, plugging that in here. Welcome, Alvin, and thanks for coming on the show.
Alvin W. Graylin (00:39)
No, thanks Kyle for inviting me. We’ve been talking about getting together for a while, so I’m glad it actually worked out.
Kyle (00:45)
Definitely. So big question up front, what is China trying to do with AI in your view? Is there an overarching Chinese AI strategy? How should we see China’s approach to the broader AI tech stack? And how does this compare with how the US is going about things?
Alvin W. Graylin (01:08)
Yeah, and this is actually probably one of the more misunderstood questions or answers that a lot of Americans have about China is that first of all China didn’t really have a AI strategy for a very long time. And only really in the last kind of five years or so I think things have become a lot more clear with their AI Plus plan. But in the past it was really just one of many technologies that were important and should be looked at. And that was it. It didn’t really elevate to a national level, right? But I think right now what’s happening is that China looks at AI as a technology that just like other technologies in the past that has helped to increase the productivity of its population, of its industries, and to improve its competitiveness in terms of on an economic basis, right? Whereas I feel like a lot of the labs themselves actually are not directly integrated into a China national plan. I think a lot of people used to think or thought that there was a grand national strategy around AI and particularly around open source. I feel like a lot of that actually happened on a more emergent basis, where success then brought more attention, which then made the open-source strategy more of an accepted strategy. In fact, until a few months ago, when the World AI Conference happened, Xi Jinping was never really that involved in having a public opinion about AI. And when he went and did his opening talk at the WAIC, he started to talk about open source, about kind of AI is a public good, and about AI safety. These were really not part of any major national plan in the past. The AI Plus plan has been around for about four or five years. And I think that’s probably where the current flow of resources has come from is to say, hey, the goal is for the country to get to 70% adoption of AI in its industries across 10 different industries over the next five years, and then about 90% over the next 10 years.
And I think in a lot of ways that’s really the focus. It’s all about diffusion. How do we get AI into healthcare, education, manufacturing, et cetera, et cetera, so that we can grow the industry, we can grow the GDP because for China that’s really been the long-term kind of social contract is that the government will provide economic growth and quality of life growth.
In exchange for more social stability and kind of I guess following the rules of the party, right? So that’s I think how the Chinese model has worked. I feel like the American interpretation has been a little bit more looking at it as a adversarial relationship whereas I actually don’t necessarily see a lot of adversarial perspective when I talk to the labs in China or even the government in China. Where you hear in the US is that the Chinese are creating open source so they can then destroy the American economy by turning our trillion dollar companies into less valuable companies or they’re trying to steal data from our labs. I feel like if you look at the real relationship that’s happening across the world on this industry is that open source is definitely gaining a lot of momentum, right? If you look at OpenRouter data over the last year and a half, it’s gone from about three, four percent of total traffic to about 70% of total traffic going to open source now. Of course, the money, the revenue side is definitely still on the closed-source portion. But I think what we’ll find is that over the next six months to a year, there’s going to be models that are coming out, actually models already coming out that are really good enough for most companies most of the time and especially for most individual consumers most of the time. So that the need for that truly next level frontier AI will be limited to certain segments of the business or a community or the national security community who care about being on that leading edge. So let me let you kinda respond and ask some more questions that ‘cause I feel like I’ve been talking a little too long.
Kyle (06:07)
No, that’s great.
Yeah, yeah, that’s perfect. Yeah. And yeah, it’s interesting to put in the context of the sort of dominant framing in the US, where it’s one of like intense competition, not just zero sum, but winner take all. Like the framing, especially coming out of Washington or Silicon Valley, is one where like whichever country or company gets to AGI first, they will have a quote unquote decisive strategic advantage.
Alvin W. Graylin (06:35)
Yes. Yep.
Kyle (06:35)
And that’s literally like a term, a DSA over the other country. And it’s always sort of interesting whenever I hear that, I always try to push whoever’s making that argument to explain exactly how that happens, how that like mechanically results in a decisive strategic advantage. Is it on cyber? Is it on military? And what if it’s not a winner take all kind of scenario? So, yeah, what’s the kind of framework you use to think about US China AI dynamics?
Alvin W. Graylin (07:01)
Yeah. So I actually specifically wrote a paper on this called Misdiagnosing the AI Race. And the idea of DSA, this type of strategic advantage was a core piece of that because I agree with you. And I think it’s a misframing that is actually quite dangerous because of exactly what you said. That it thinks that the world is zero sum, which we know the world is not zero sum. We’ve been growing our economy across the world across multiple countries.
And everybody’s been uplifted over the last several hundred years, right? And it’s been consistent because technology allows us to get more done with less resources. And also winner takes all doesn’t really make sense at all because, particularly now with software, it is very difficult to have a winner takes all. If you have a specific drug that you took a patent on and you got a certain lock-in, okay, and even then it’s a temporary advantage. And even when you look at it from a national security perspective, you talk about the Manhattan Project within four years, the Soviets also got their hands on this technology. And that’s with a technology that has very restricted access to both the equipment and the materials to make that type of a weapon. In this case, I think equating AI to a nuclear weapon is, I think, just a false narrative because the reality is that 95 to 99 percent of what AI can do is actually civilian use case. It’s
Kyle (08:39)
Mm-hmm.
Alvin W. Graylin (08:40)
for benefiting the average human or the average company. Where there are certain use cases like if you want to create chemical weapons, you wanna create bioweapons, you wanna do cyber, AI can definitely make an advantage. But there’s a very small portion of the people in the world that care about this, right? So I feel like we need to really separate the civilian case from the national security case and have a dual track approach to how we look at AI and how we look at the geopolitical relationship between countries around AI. And for anything civilian if you cannot create a monopoly and lock it down then it really eventually becomes a public good. In fact, it should be a global public good, right? Just like nobody won the electricity race. Nobody won the fresh air race. Right. It’s
Kyle (09:36)
Right.
Alvin W. Graylin (09:36)
If it’s something that is going to be accessible to everyone, if it is something that is nearly free, what can we win? Who is going to win this and be able to capture it and monopolize it? It doesn’t make sense. We need to separate that. Now, if we’re saying there are some super top secret weapons that we can create with this where we can hack into people’s machines. Sure, I think there are certain national security considerations there. But for those cases, we probably shouldn’t put that technology into the chat bot that your neighbor and my neighbor are gonna get access to, or whatever terrorists or bad actors are gonna get access to. And these models today, they can only do what they’re trained to do.
Right. If you don’t give them information about how to make bioweapons or how to make chemical weapons or how to hack, then they’re not going to be able to do that. They cannot invent new capabilities that were not taught to them. And in some cases, I actually believe that we probably shouldn’t be training general public, large models with these type of data because that is eventually going to get into the hands of bad actors. Right.
And so that’s kind of my personal view is that it’s not a zero-sum game. It’s actually a positive sum game. It’s not a winner-takes all, it’s a global public good that everybody should have. And in fact, if we see the common threats that we have around AI, collaboration actually will make the world safer. Right? When we create walls around this technology and we stop talking to each other and we call each other enemies.
We stop sharing the threat analysis that we have. We stop sharing the signatures of viruses and chemicals that could be produced. And if we do that, then there’s just more room for the bad actors out there to hide. And we know that there are bad actors that want to create instability or harm people. But right now I really don’t see the threat to America as being China—or actually any state-to-state conflict—as the main threat from AI because we’ve had technology that could have essentially destroyed each other for the last 80 years and there’s a natural balance that has existed. And using AI in a massively destructive way will eventually escalate to nuclear war. And no sane leader of any country wants that to happen. Right. So in which case whatever balance, whatever forces that has created the balance of what we have today will continue even with AI weapons that are created. Because nobody will actually want to use it and nobody wants to create a true first strike. Because we know eventually what that leads to. Now the people that will actually do the first strike are bad actors, non-state actors. And those are the people that we have to work together to monitor and to share information and to also not only bad actors but also AI itself, right? Recently there’s been a lot of I guess discussion about RSI, about runaway AI escaping from sandboxes and potential threats of swarm agents. These are issues that we have a shared risk around because I don’t think either America or China or actually any country in the world wants to have rogue agents that escape onto the internet and are able to create instability in their countries. And even whether or not you think that we’re in an adversarial environment, no I think no leader of a superpower wants to see another superpower collapse because that collapse can lead to a lot of unintended consequences.
So in general I think it’s good to have healthy competition between countries, between companies, but catastrophic outcomes are definitely something that I think everybody would like to avoid.
Kyle (14:01)
Yeah. So the common framing of this AI risk and safety issue is often a prisoner’s dilemma one where maybe both the US and China see that they and the whole world will be better off if there was some degree of cooperation, but it’s very difficult when you feel like you’re in a race or competition to hold yourself back or impose a cost on your own country.
And maybe give up the AI you quote unquote AI race to the other side. So and that’s seen as the prisoner’s dilemma because in the classic game theory case, like if you are two prisoners in different cells in theory you should figure out a way to coordinate so that you both get out. But if you’re kind of separated and focused just on your own immediate self interest, you might have cause to choose a suboptimal outcome that benefits you in the near term but is worse in the long term. Do you think that’s the right way to think about things?
Alvin W. Graylin (15:02)
I think that’s actually one of the worst ways of looking at this situation, right? From every perspective, you look at it and it is not representative of the real world, right? First of all, in the prisoner’s dilemma game, you are locked in rooms and you can’t talk to each other. From a nation to nation perspective, we have people calling each other every day. Not only can you talk to each other, you can go meet them face to face, you can go visit them.
And not only can you talk to them, you can look at the actions that they have had over time. And to me, actually, I think actions make more difference; that is more valuable and more representative than what they say. Right. Now, and also even in game theory, what you described was the single-turn prisoner’s dilemma, where the game-theory optimum is to defect, right? And the world is not single turn.
The world is an infinite, multi-turn game. And even in prisoner’s dilemma game theory, in the multi-turn game, the optimal is tit for tat, which means you do what the other person does, but you start with cooperation. You cooperate first. If they don’t cooperate, then you defect, and then you essentially punish them. And then if you punish them, and then they say, okay, I hear you. Now I go back to cooperating, and then you go back to cooperating. And in the long term, everybody cooperates.
Right. So even in game theory, the optimal situation for a long-term multi-turn game is actually cooperation. Right. Starting with a tit for tat strategy. So no matter which you start with, whether you start by defecting or cooperating, you end up with cooperating long term. Okay. Now, that game is still a zero sum game, right? Because that is assuming that essentially you either go to jail for three years or five years, but you’re both going to jail. It is actually a negative sum game. As we said earlier, the world is a positive sum game. And there’s another game-theory scenario that is more relevant to this situation and it’s called the stag hunt game. And it was something that Jean-Jacques Rousseau invented, which essentially involves two hunters going into the forest.
And they can choose to hunt for the hare, the rabbits, which will feed their family for a few days, or they can work together and go hunt for the big stag, and that’ll feed both their families for a month. Right. And so it is a big payoff or a big game, or you can work by yourself, but having enough to survive and to at least get to kind of the next episode.
But it is actually a positive case ‘cause in both cases you come out with a positive sum if you both agree to just hunt hares or you both agree to hunt the stag. The worst case scenario is when one party goes and hunts for the stag—the big game—and then even if they get it, they can’t get it out ‘cause it’s too big and heavy, and you don’t get your reward from it.
Or because it’s so big, it’s smart, it gets away from you and you spend a few days and get nothing back and your family goes home, you’re going home hungry. Now, so the worst case is one person goes for the stag and the other one goes for the hare, right? And that’s exactly what’s happening today is that America is spending exorbitant resources trying to get the stag. This AGI or ASI grand prize.
While China is saying, hey, I wanna make good enough AI. I want to make open source AI, I want to make it available to all my people so I can keep that normal growth going. Right. So we’re right now in a scenario where China’s going for the hare, we’re going for the stag, and if we don’t get it, then we’ve spent trillions of dollars building these data centers and investing in something, creating market fragility for potentially no return or maybe a negative return in the sense of if a technology comes and we aren’t able to get the return on that investment and the stock market then corrects so you’ll have both an economic crisis as well as potentially an employment crisis because the technology will still be there and it will still displace workers. So at the same time the market comes down, the employment also goes down.
Which then creates social instability because America has a relatively thin social safety net, and forty to fifty percent of Americans have one month of savings. That combination of things happening at the same time can really create a major crisis for the country. So this is essentially the stag hunt game playing out where you don’t achieve getting the stag.
So I would rather us look at it from that perspective. And the smart thing to do in that scenario is until we know how to manage and control AI so that it doesn’t become a negative threat, doesn’t become a runaway rogue system that hacks its own way into our financial systems or into whatever and destabilizes society, we probably should be pacing it in a way where we allow it to be able to bring growth to our economy without bringing instability into our society. And that actually requires some level of coordination with China. So the stag hunt game in that case is let’s both go for the hare. Let’s both go for reasonable investments for reasonable returns for the near term. Once our AI researchers figure out, okay, how do we manage this so that we can actually make sure that the AI aren’t doing malicious things that we don’t understand. And then when both countries understand, then we start to ramp up the investments to get it to that next level, right? I think that’s actually the smart thing to do from both a technical perspective, a safety perspective, an economic perspective, and a geopolitical perspective.
Kyle (21:18)
Yeah, this is super helpful. And I wanted to ask you sort of more areas where you think that the US and China could coordinate or even cooperate on AI. So you mentioned for example, pacing development. Like is that something where you think Beijing or the Chinese companies will be willing to be part of that? And also you mentioned other issues like non-state actors, risks of AI being used for malicious purposes—maybe by hackers for ransomware attacks or even for developing biological weapons sort of guardrails or controlling the data pipeline. Yeah, what areas do you see as the most interesting for US China cooperation on AI?
Alvin W. Graylin (22:03)
Yeah, right now I think the most clear common threat that we have is the bad actor misuse and also the runaway kind of AI misalignment risk, right? Because these are risks that both countries share and both countries want to avoid, and you can only achieve it by coordination. You cannot compete your way out of having a bad actor act against you.
In fact, the more you compete, the worse that situation gets because there’s then more room for the bad actors to hide. So what’s happening in the next few weeks or next few months with the AI safety talks, I think it’s a good start. I don’t know how much will come out of it, because I feel like there seem to be forces within the US right now that are trying to derail the safety talks. The fact that last few days you’ve come out there’s been a new letter coming out of I think the NSA saying there’s been massive distillation attacks and China is trying to steal our data. I mean, I actually read through that report and there was no new data there. Nothing more than what was said back in the April letter, and really no data beyond what was put out in a few press releases by Anthropic. And even when you look at the numbers that they give, they’re talking about tens of thousands of accounts getting billions of tokens over a three-year period from three different labs, right? Billions of tokens is on the order of, I don’t know, tens of thousands or hundreds of thousands of dollars maybe, if you’re looking at expensive API. And over a three-year period right now modern AI models are trained on tens of trillions of tokens. To get to a few billion tokens.
I don’t know how much that really bought anyone. It may have helped some of the labs catch up a little bit, but I think you have to give the Chinese credit for some of the innovations that they have created over the last few years. And distillation is useful when you have your own models that are relatively open, that will allow you to get full chain of thought traces.
So that you can take that information to train. But the closed models have significantly limited chain-of-thought output, so nobody can really see more than a tiny summary. When you have that limited level of access, the value of these distillation attacks is, I think, somewhat overrepresented, right?
And in fact, if you think about this, right, every month Meta spends somewhere between $100 to $300 million on Anthropic tokens. That’s an order of magnitude, or several orders of magnitude,
Kyle (25:08)
Right.
Alvin W. Graylin (25:09)
More than what we were just talking about over a three-year period. And it’s striking that Meta has had such a crappy model for so long that only in the last month have they started to have a competitive model.
If distillation was so easy and they can catch up so quickly, they should have been one of the first companies to be at par or near par with Anthropic and OpenAI of the world. And same for xAI.
Kyle (25:38)
Mm-hmm.
Alvin W. Graylin (25:39)
They’ve also fallen far behind and only after they bought Cursor have they now come back to becoming a somewhat competitive company. So yeah, it Distillation may have some use, but it is not the reason why the Chinese models are as capable as they are. And, in fact, if anything, I think the American export control policies have actually contributed to the innovation that’s happening in the Chinese models, right? And whether it’s to improve the memory efficiency or improve the compute efficiency or quantization.
All of that was because they didn’t have access to the chips, they didn’t have access to the latest chips, they didn’t have access to the memory, and that forced them to innovate, right? We all hear that necessity is the mother of invention, and our export policies created the necessity for them to innovate. But the good news that came from that is that all those innovations were actually published in papers.
And within months of them being published, those same innovations were then integrated into the American closed models. Right. So i if China really thought that they were in an all-out race to AGI, there would be zero reasons for them to take these innovations that essentially could have given them a hardware advantage because they have probably one-tenth as much compute.
As the US does. And some of these innovations allow you to essentially have a 10x or 20x reduction in the memory or compute necessary to do the same work. If they really thought they were in a race with America, the government would have forced these labs to say, don’t publish anything. The fact that they are publishing and sharing these innovations with the world shows, in some part that the government doesn’t see this as a zero-sum game, right?
If the Chinese government thought they were in this zero sum game, they would not be limiting their own labs from buying the H200s. The H200s are it’s a generation and a half old. But compared to the Huawei chips, it’s still better, right? And I was just in China for the WAIC and every lab I talked to, they said, Yeah, we could definitely use more chips. We’d love to get more chips, but we’re told not to buy more chips. So that again shows that really I think this narrative of US versus China is not the right framing. And then I think we’re shooting ourselves in the foot by overinvesting right now in data center build outs. And because you’re overinvesting, everything inflates because of supply and demand. We’re short on memory, we’re short on generators and transformers and GPU. Yeah.
Kyle (28:44)
It’s spilling over to the rest of the economy. Like now we don’t Have enough memory production capacity for other chips for other devices.
Alvin W. Graylin (28:51)
Yeah, exactly.
Now, the prices of the Macs are going up and the iPhones are
Kyle (28:55)
Right, right.
Alvin W. Graylin (28:55)
Going up because that people have shifted capacity from DRAM to high bandwidth memory. Right. This is something that we really need to look at with a more reasonable mindset because I think a lot of this narrative is not necessarily really driven by national security concerns, but really more driven by private companies looking to deregulate.
By private companies wanting to get faster approvals or advantageous contracts with the government. And putting together this narrative of a geopolitical race is a playbook that has been used by the military-industrial complex for 67 years. And essentially, I feel like right now the AI industry has kind of taken advantage of that model that has been proven to be effective in the US government and just ran that playbook but ran it harder, right? I don’t know if but right now there’s something like two lobbyists for every member of Congress in DC for the military-industrial complex, for the defense industry. Okay. But there are four times as many lobbyists for AI-related causes in DC as there are.
Defense-related lobbyists. So we already know that there’s a lot of defense lobbyists, but there are four times as many AI lobbyists. That should be something that should be troubling because why would an industry that creates value for the world need that many lobbyists to go and talk on their behalf? Right? So I just think we need to we need to be a little bit more rational.
Kyle (30:41)
Yeah. Well, one dimension of this that I like to ask you about is the closed- versus open-source debate. And the elephant in the room here is obviously Chinese open-source models that are very capable, that are getting into the sort of same class as the top US frontier models, at least. And yeah, there’s a debate going on where some argue that closed models are the future because closed models can have guardrails, they can be controlled, they can be monitored. And others argue that open source models are really crucial for cyber defenders and that we need to actually have more access to these tools for doing our own red teaming and our own sort of patchwork of our own systems rather than continuing to restrict access to a very small group of companies.
Where do you fall on that and how do you think the Chinese models factor into all that debate?
Alvin W. Graylin (31:42)
Yeah, so I actually specifically wrote a paper about this about a month ago, published in The Cipher Brief and it was called The Biggest AI Models Are Not the Biggest Threats, right? So the title gives you my
Kyle (31:56)
Pretty clear.
Alvin W. Graylin (31:57)
My position. And the reason I say that is I went back and I looked at 20 AI models that have actually been deployed and mapped model size on the x-axis against actual realized threats on the y-axis. And what I found was that there was essentially zero correlation between size of model and the amount of threat. You can have a 10 to 100 million parameter chemical model that can create chemical weapons that would be as dangerous or more so than VX. You can have a one to 20 billion parameter biological model that can create viruses.
That in fact last I think maybe two or three weeks ago somebody announced that they created like 16 new viruses and
Kyle (32:44)
Yeah, yeah.
Alvin W. Graylin (32:45)
That model was a tiny model that was around 10 billion parameters, right? That will actually run on my laptop. And the chemical model, they created like 60,000 chemicals over a six hour period on a laptop. So it’s very unmanageable. And even in cyber, we hear a lot about the Mythos class and how it’s able to find all these vulnerabilities. In fact, if you look at the CyberGym results, actually the best model maybe up until Astra came out was the MDASH harness from Microsoft. And it’s actually just a harness system that draws on a hundred or so small models from around the world and some that specialize in different things.
And it was able to get a 95 score on the Cyber Gym, whereas Mythos was only about 85, right? So something that again would run on a small server or maybe a high-end kind of Mac Studio is able to outperform something that would run on multiple racks and
Kyle (33:50)
Mm, mm-hmm.
Alvin W. Graylin (33:51)
in a data center. So from a threat perspective, bigger is not always more dangerous, right? And But one thing that you did say just now was very important was that larger models with bigger contexts allow you to have a broader perspective and find vulnerabilities better and sweep things better and be a better manager, right? So a larger model that then manages a lot of small agent models could actually be a really good defender. And I think from that perspective it’s already proving out because if you look at what happened with the Hugging Face incident:
The protector of Hugging Face was not an OpenAI model or an anthropic model. It was actually GLM, right? I think it was GLM 5.2 or 5.3 that was a Chinese
Kyle (34:37)
Z dot AI, Chinese company.
Alvin W. Graylin (34:39)
open-source model that was downloaded to help find and secure their network against the OpenAI model that was attacking them. And the reason was because of the harnesses you’re talking about, because of the safeguards they put
Kyle (34:55)
Mm-hmm. Mm-hmm.
Alvin W. Graylin (34:56)
prevented Hugging Face from using it as a defender because it couldn’t tell whether you were using it to attack somebody or trying to find vulnerabilities to attack or whether you’re trying to find vulnerabilities to patch. Right. I think the need for less restricted systems to allow people to patch their own systems is a necessity, right? Because Right now, if you look whether you’re talking about the Glasswing program from Anthropic or the equivalent from OpenAI, they’re talking about dozens of companies around the world that have access to their latest kind of unfettered, unnerfed model. But the world has a lot more than a few dozen important companies that need to be protected. Right.
Kyle (35:43)
Mm-hmm. Mm-hmm.
Alvin W. Graylin (35:45)
I think what you just said is super important, is that we do need to have larger models that can defend.
But the danger doesn’t necessarily come from larger models. And right now, all of the tests, evaluations, policies, and restrictions are all about big models. And so we’re really taking our eye off where the danger is because all those models that I just talked about, the 10 million, 100 million, the 10 billion, those models are all already available for download on the public internet. Anyone can have access to these, right? Ransomware and hacks into public networks have gone up two or three hundred percent over the last year. So these things are starting to be used. And that’s kind of early stage before I think the bad-actor community has really fully leveraged this. But I would expect these incidents are going to go up much, much higher. The other thing to also remember is that even when you have a patch, it usually takes weeks to months to actually deploy the patches into the real world because you need the patch deployed at every single opening into a network. So if you have a perfect patch, but if one person’s computer was offline for a while, he didn’t download and deploy the patch, when he got online and somebody had an exploit for his system, they could get into that entire network just from one system that wasn’t updated, right?
And I spent a number of years in the cybersecurity community, and I can tell you that bad actors will absolutely use whatever means they have and they move a lot faster than the IT managers do in deploying patches. Because to be honest, in defense of the IT managers, they don’t want to be deploying a patch that’s unproven because that patch
Kyle (37:39)
Right, right.
Alvin W. Graylin (37:40)
Could actually take down their network. And if it takes
Kyle (37:42)
Right.
Alvin W. Graylin (37:42)
Down their network because somebody made a mistake in a patch.
He could lose his job. Right. So he wants to see other people do it first and confirm that it works. And it doesn’t hurt anything. There are no surprises. Okay, after a few weeks, then he’ll deploy. But at the same time, those few weeks is when bad actors can get in and do things before he even knows about it, right? And so the human aspect of this is something that very few people talk about when we’re considering defense versus offense. And I think it’s pretty much universally understood that in cyber, offense has an asymmetric advantage. Right.
Kyle (38:24)
Mm-hmm, mm-hmm.
Alvin W. Graylin (38:25)
If you’re talking about back in the old days where you have a castle and attackers that are trying to siege a castle, then yes, the defender has an advantage. You need about three times as many attackers as defenders. But in the case of a cyber attack, it’s the opposite, right? Some kid in his basement with the right tools can take down a corporation with thousands of people in their IT department.
Kyle (38:54)
Yeah. I mean it’s shocking, but yeah, and you don’t need to have necessarily the absolute frontier models in order to pull it off. Right. Yeah.
Alvin W. Graylin (39:02)
No, no. And So if you can run the models on a laptop, that means you cannot track it. You cannot monitor it. You don’t
Kyle (39:08)
Mm-hmm.
Alvin W. Graylin (39:09)
have telemetry, which is also why some of the larger models are actually safer, right? Because you have telemetry, if somebody tries to use it to make a virus or to do something bad, you can see where they came from, what their IP address is, what the log of all of their prompts were, and it gives you information for you to diagnose that and then that allows you to then share with the police or whatever security instruments that you have to deal with it, right? And I feel like that’s something that people don’t realize. So larger models in some ways are safer because they can be managed, because they have to be run on large systems. That said,
Kyle (39:46)
Mm-hmm.
Alvin W. Graylin (39:47)
We also need to realize that you can also distill large models into smaller models. And
Kyle (39:52)
Right, right, right.
Alvin W. Graylin (39:53)
So over time, very capable models will eventually become accessible to laptops and servers in somebody’s home
Kyle (40:05)
Yeah, yeah. So where do you think China will go on the open source question? So do you think that Beijing, Chinese policymakers, will over time push for more of a closed approach, given that you have more sort of control and monitoring? Or do you think the open source strategy is now so integral to China’s overall AI approach that will remain dominant in the near future?
Alvin W. Graylin (40:34)
I think one thing that’s very different in the Chinese ecosystem versus the American one is that the Chinese model has actually had and enforced regulations for several years, right? For three or four years they’ve had kind of data provenance regulation, they’ve had anti-addiction and anthropomorphic AI restrictions, they’ve had labeling restrictions, they’ve had certification of models—all the things that essentially I think we should perhaps have in America to keep our children safe and to keep the information online clear of what is and what is not AI generated, they’ve had for a while. And they’ve had over, I think, seven or eight hundred models now that have gone through the CAC certification. And that certification probably started out more as a kind of propaganda censorship model, but now it will start to add additionally more and more safety testing into it. Right. So the things that we’ve been talking about doing from the US perspective—taking the most advanced frontier models and having what the Americans call voluntary validation or testing whereas in China it is mandatory. If you’re not tested you cannot be put online. Right.
Kyle (41:58)
Mm-hmm, mm-hmm.
Alvin W. Graylin (41:59)
That allows them to essentially test for whatever things that they think are potentially harmful to the country. So I think that allows them to maintain an open-source system which enables more rapid diffusion into their industry domestically and also into the global economy on a wider basis. So The fact that I think Xi Jinping mentioned open source specifically in his speech at WAIC is a signal and most people who are China watchers they watch for specific words very carefully of what the leadership says, because that essentially is a signal to all the companies of kind of which direction to move in. And when he specifically said AI should be a public good and AI should be open source, that is a good thing.
That is a sign that, at least in the near term, I don’t see any movement from an open- to a closed-source policy.
Kyle (43:09)
Yeah. So I want to ask you about physical AI next. I think that
Alvin W. Graylin (43:13)
Yes.
Kyle (43:14)
A lot of the discussion in the US is about AI on the digital side, computer use, having AI agents do your PowerPoint presentations for you or do data analysis. And China has that as well, but they’re really, really focused on robotics, autonomous hardware systems. And how do you see China’s approach to physical AI? Why are they going so all out on that aspect of AI and what do you think their longer term goals are there?
Alvin W. Graylin (43:47)
I mean, right now I think something like thirty or thirty-two percent of global manufacturing is done in China, right? They are the biggest manufacturing powerhouse in the world. It’s supposed to go to around 40% by the next five or ten years. That position in terms of manufacturing capability is similar to what Americans enjoyed after World War II. America was somewhere between forty to fifty percent of global manufacturing capability and that allowed America to essentially become the country that it is today is because it was able to create a global marketplace for all of its goods. And all the allies in Europe and other parts of the world started to buy American goods. And in some ways that’s I think that is what the Chinese are trying to do is to utilize its advantage in terms of physical manufacturing capabilities. And we already see that today with the EVs, where there’s really no way for any other country in the world right now to compete in EVs in terms of price and performance and capabilities and capacity of what the Chinese have done. And same for solar panels and batteries and other things, right? So Integrating AI into that is essentially just a natural progression. The other thing to also realize is China does have a demographic problem where there’s an inverse pyramid happening with the youth population. And that the need to automate is becoming more and more acute. And I think both the government and the population realizes that. And so integrating and having more Manufacturing and physical replacements for a lack of human labor is something that is highly desirable. So both from a domestic policy perspective as well as a global kind of economic growth and expansion perspective, integrating AI into these devices of all types is something that I think China can execute better than anybody else in the world.
And it’s something that I actually think that the Americans should learn from, right? America has actually outsourced its manufacturing over the last 30 years, going from about equal or maybe higher than China’s, to about half of China’s manufacturing capacity. In a world where cognitive labor becomes increasingly commoditized, America—where right now, 65 to 70% of the workforce are white-collar workers. That risk of displacement is higher in America than almost anywhere else in the world. Right? In China, around 40% are white-collar workers—so we’re accelerating the creation of an instrument for the displacement of our highest export to the world. At the same time, China is trying to increase its capabilities in the area where it has the greatest exports in the world, which is physical goods. Right. So I feel like America is actually shooting itself in the foot in its current strategy of trying to make AI so capable so quickly that it actually will disrupt its own economy. And having to spend ten times as much on CapEx as the Chinese are to get a two, three, or four month lead, that doesn’t really make economic sense.
Kyle (47:42)
Mm-hmm. Mm-hmm. Yeah. I think people taking a step back from the so-called AI race, will reasonably ask, what is this buying us exactly? What is that level of investment and is it sustainable? So there’s a lot of questions there. To wrap up, I wanted to ask you a last question just about your own personal experience in the tech industry. What has it been like seeing China’s tech industry change over the years and the decades in which you’ve seen its evolution. When you started, the average income of even a Chinese city resident was orders of magnitude lower and that has changed pretty dramatically.
Alvin W. Graylin (48:30)
Yeah, probably under a thousand dollars, probably actually a few hundred dollars, even in Shanghai. When I was there in ninety-four, I helped Intel open its Shanghai office. And yeah, I mean essentially we were some of the highest-paid employees at the time and we were essentially giving a couple hundred dollars per month to very well educated engineers.
So now, if you look at some of the high-paid white-collar workers in the big cities, they’re pretty similar to American salaries, particularly for managers, executives, and some senior workers. But not necessarily at the Silicon Valley levels, because Silicon Valley is actually a little bit crazy.
Kind of average American level income for white-collar workers. But the tech industry has definitely improved because back then bicycles were everywhere. There weren’t even cars, right? So to move
Kyle (49:42)
Yeah.
Alvin W. Graylin (49:43)
to move from a time when people’s primary mode of transportation was bicycles to now high-speed rail and airplanes and electric cars everywhere, you can see and feel viscerally the change in quality of life for the population there. And I think this is also why if you look at the American kind of willingness to accept AI versus the Chinese willingness to accept AI is actually completely reversed, right? The American percentage is something like 70% negative and 30% positive. The Chinese are 70 to 80 percent positive and maybe 20% negative.
That’s because they’ve lived the last few decades seeing that every technology innovation that has happened has somehow made their lives better—allowed them to make more money, allowed their education to get better, allowed them to travel around the world more. I think the Chinese have something like 120 or 130 million travelers who leave the country every year to see the world. That was impossible for 99.99 percent of people when I first got there. Right. And technology has been credited for a lot of this has happened. And some of the biggest heroes are tech entrepreneurs. In fact, some of the US tech entrepreneurs are some of the biggest heroes over there. People like Elon Musk are probably some of the best-known people over there, or the late Steve Jobs. So a lot of people want to mimic the American Silicon Valley kind of ethos. And it has affected the desire to be an entrepreneur and to innovate. I remember when I was first recruiting back in the 90s that the job to have was not a corporate job, but a government job.
Because a government job was the most stable, and you get
Kyle (51:48)
Mm.
Alvin W. Graylin (51:49)
Benefits, you get housing. And then a few years later it became international, multinational jobs were the best jobs because you get American or Western pay and you get to travel around the world. And then it became big Chinese tech corporates. And now everybody wants to be in a kind of late stage startup because who’s going
Kyle (52:12)
Mm-hmm.
Alvin W. Graylin (52:12)
to IPO?
Right. So it’s becoming
Kyle (52:13)
Yeah.
Alvin W. Graylin (52:14)
more and more and more like the more and more like the American kind of California dream. So
Kyle (52:23)
Right. Yeah, yeah, yeah. That’s a great way to put it. Yeah. I mean you can always look at sort of where the top graduates are going, what industries, what sectors are they going into. And that’s sort of an interesting indicator of just the state of the economy and which areas are flourishing and where people see the most growth potential. And yeah, I think you’re right, the previous focus on stability of a safe government job has shifted.
Alvin W. Graylin (52:49)
Yeah. And in fact, they asked Liang Wenfeng why DeepSeek wanted to go public if it doesn’t care about revenue. He said, look, I need to have stock, I need to have a certain amount of money from an IPO so I can keep my staff. Because the consistency and stability of the staff is the number one criterion to creating long-term technology innovation. Right. So even a company as famous as DeepSeek has retention issues if it can’t offer upside to its staff.
Kyle (53:26)
Yeah, so it boils down to talent and competing over this talent pool, and that’s very much the case as well in Silicon Valley.
Alvin W. Graylin (53:34)
Yes, yes.
Yeah, and this is why you had Meta with their billion-dollar packages, which I think is a little crazy, but
Kyle (53:42)
Ha.
Alvin W. Graylin (53:43)
And it didn’t even help them. That was a sad thing. They spent all their money and then they’re still not—I mean, they’re getting more competitive, but they’re not at the frontier.
Kyle (53:52)
Yeah. We’ll look back at that time as a sort of head-scratching moment in history, I think. Yeah. So I want to thank you so much for this conversation. I learned a ton from your work. You do really outstanding projects and research and I’ll be sure to include links to all the papers that we talked about. If people want to follow you and your work, how can they do so?
Alvin W. Graylin (54:19)
Yeah, I think you can just go to X and it’s @AGraylin, or Alvin Graylin on LinkedIn or Substack. I write The Abundanist Substack. I’ll also publish articles under the Stanford side as well. In fact, there was one thing we were talking about: I just came back from Burning Man and I’m working on a new research paper
Kyle (54:42)
Yeah.
Alvin W. Graylin (54:43)
About how a gifting economy, a non-monetary economy that has been practiced for 40 years at Burning Man could actually be a proto-economy for a post-AGI, post-monetary future that if
Kyle (54:57)
Well
Alvin W. Graylin (54:57)
If everything goes well and AI and robots make all the productive work in the world.
We can then be liberated to spend more time on art and music and community, which is what happens at Burning Man one week every year. So
Kyle (55:13)
Yeah. Yeah. What was previously a luxury will become more available, this sort of community building and personal relationships.
Alvin W. Graylin (55:22)
Yeah, I mean to be honest that even though you call it luxury, but I think that’s the most basic level of humanity.
Kyle (55:28)
Mm. Yeah, yeah.
Alvin W. Graylin (55:29)
For a hundred or two hundred thousand years, we really just relied on each other as a small troop or a small band of people who relied on each other to survive and who enjoyed music and the company of each other versus money or products that went beyond ourselves. And that’s the kind of lifestyle that happens in the Burning Man kind of festival. And so I wanted to study it and I’m doing it together with the head of the Stanford Digital Economy Lab. So it’ll be a rigorous academic study of this issue.
Kyle (56:06)
Ha.
Alvin W. Graylin (56:07)
So look for that when it comes out in a few months.
Kyle (56:10)
Absolutely. Absolutely. Well, thank you so much, Alvin.
Alvin W. Graylin (56:14)
Yeah, no, thank you again for inviting me, Kyle, and look forward to seeing you in person again soon.
Kyle (56:19)
Sounds good. All right. So to wrap up, if you like this episode, please rate and subscribe on YouTube, Spotify, or Apple Podcasts. You can find episode transcripts and more information on the High Capacity newsletter at highcapacity.org. I’m your host, Kyle Chan. Thanks for joining and see you next time.



