Transcription
Hello again. Welcome to AI Decoded.
The race between America and China for AI dominance is the defining contest of our age. It will dictate the shape of the global economy, the balance of military power, the rules that govern the technology that billions of us rely on. And within that race to be first, there is a shadow war underway.
A couple of weeks ago at Koala Lumpa airport, customs officials seized 72 servers that were packed with advanced AI chips worth $13 million, labeled as ordinary computer parts. Customs in Malaysia said they were on their way to another Asian country, thought to be China.
In a quite separate case, Anthropic, the company that makes Claude, has accused Alibaba of conducting the largest known distillation attack in AI history. 25,000 fake accounts were conducting millions of interactions with Claude. The goal to systematically extract Claude's most advanced capabilities and transfer them into Alibaba's own model.
Our panel this week: Gregory Allen, who oversaw the Pentagon's AI strategy, is now the founder and CEO of Decision Tree Research. It's an independent analysis company that specializes in strategic technologies, public policy, and geopolitics. Ran Mitta holds the chair in US Asia relations at the Harvard Kennedy School. He's one of the leading uh historians on modernday China. And also here, our co-host and AI specialist, Dr. Stephanie Hair. Welcome to you all.
Gregory, I want to start with you, if I may, on uh what this represents. You run the Pentagon's AI strategy. You know better than most what these chips represent in military and economic terms. So, what is the significance then of this operation in Malaysia? And what does it tell us about the nature of the race?
>> Well, I think it tells you a few things. The first of which is that Chinese companies and the Chinese government are still extremely eager for US AI chip technology. Really, those chips made by Nvidia. And while this Malaysian smuggling ring that was uncovered is talking about chips worth $13 million, other reporting by the Wall Street Journal, by the Information, by the New York Times has talked to smugglers showing receipts for transactions in the hundreds of millions of dollars.
So for example, a few months ago, the Trump administration made it legal to sell Nvidia H200 chips to China. And in a way that was kind of a media circus, China said, "Actually, we're not going to allow H200 chips in China." And most folks thought that that was because China was pursuing a strategy of independence and self-reliance. But actually, I think the clearer explanation is that China was pursuing a strategy of smuggling in the higher quality chips. H200s are last year's news. If you can steal B100s or B200s, why buy H200s? And I think that's where we are is unfortunately US companies uh unwillingly are actually supporting China's ability in the race to out compete American companies.
>> This customs operation in Koala Lumpa was directed really by Washington and they've put pressure on Malaysia because they know there is this flow of chips to China. But the way in which these chips have been disguised, the manner in which the shipment was disguised within these servers says to me that actually it's quite a futile battle trying to stop it. The smuggling operation was notably significant and sophisticated and we've already understood that this is true for quite some time. The Department of Justice indictment said that the smuggling ring included one of the co-founders of Super Micro, which is one of the largest Nvidia customers around the world for building the servers that integrate Nvidia chips. So if the smuggling campaign involves, you know, executives up to that extremely high level, that's a really ability to use obfuscation and other tactics. And what they're doing, just so everybody understands, is they're relabeling the GPUs as CPUs or saying that, you know, these GPUs are actually older GPUs and basically purchasing them in a way that is designed to fool inspectors, whether that's from Nvidia or anyone else.
>> Who is behind this, Ron? Is it the Chinese state uh directing a covert operation to acquire these chips? Is it Chinese companies who are acting in their own commercial interest or is it criminal networks?
>> Um, I mean Kristen, it's a whole mixture, a whole ecology you might say of different actors coming together. So I think Gregory's quite right that it's as well to be clear that um simply because uh China has openly said that it doesn't want to buy a particular series of chips, the H200s from Nvidia, because it can make its own, that doesn't mean that industrial espionage has stopped at all. It is true though that China has been putting a tremendous amount more uh investment and also sheer thinking power into trying to indigenize as much of its production as possible. So certainly getting hold of the best American technology and that can be done in several ways, including the tactic of distillation which you mentioned a bit earlier. In other words, trying to draw as much of the capability from American models as possible. But at the same time, huge amounts of time and effort is going into trying to make sure that there are also Chinese systems that are as self-sufficient as possible. China's currently spending something like 2.4% of its uh GDP uh on research and development, broadly defined. That's been true probably for about a decade and a half at least, maybe even longer than that. And that's in large part because the way in which AI is embedded into Chinese society as a whole of course is very much tied to military uses. And that's one of the main things of course that Gregory, as a Pentagon veteran, will know about. But it sits within that wider ecology of a much wider use for AI already in Chinese society. That can be everything from the everyday, such as you know, getting directions from one place to another, or areas like healthcare, where China's biotech industry is also tied up with the idea that say, having an AI doctor who diagnoses you is not some futuristic prospect, but actually something that Chinese seniors and elders see today. So those aspects all fit into the wider model that China's looking to put forward.
>> Is it all one way, Stephanie?
>> uh, I mean, Ron has just said there that each side wants to know what the other has. Is America copying what China has?
>> Well, I think it also is about motivation. So this story of IP theft is nothing new between the United States and China. I mean, those of us who are long enough to remember the '90s, that was, you know, '80s and '90s, this is already happening then with with different types of hardware and software. So this is just the AI version of this old story. And then I think the second thing is China wanting to copy what America has is happening. I think for different reasons than why America is wanting to keep an eye on China, right? So there's commercial interests. Like Nvidia's CEO Jensen Wong would love it if there were no export controls on Nvidia chips at all. He wants his, his strategy is a very different one to the US government at the moment, which is let's just sell to China, get American technology baked into everybody's technology stack from chips up the model, up and down the model, applications, data centers, energy, everything. If you're building on the American technology stack, you create dependency. China doesn't want to become dependent on American technology. But what it does want is to be competitive with it. And I would love to ask Ron about this. What to what extent this is part of the Belt and Road initiative? Because China has been of course trying to roll out its financial package and tech for years.
>> When you look at who is actually in charge of this, it's the, it's the, it's the vice premier who who oversees the whole strategy, Ding Shang. He is the man who is tasked with with creating this AI structure within China. So it is tied in in some ways to to the Belt and Road initiative and to the wider strategic direction of the economy.
>> It is Christian, but it also has a commercial imperative as as as Stephanie was uh was saying. Ding, who is one of the top seven in China, one of the members of the Politburo Standing Committee and very close personally to Xi Jinping. He's essentially the tech czar, you might say. Perhaps czar is not quite the right word. Tech emperor might be a better phrasing for someone in in the Chinese system. But the point is that compared to say, you know, the system of economy of the economy under Chairman Mao 50 years ago, China's technology majors are commercial entities too, and therefore they have to have incentives for what they're doing at the moment, which is certainly something that China is seeking to do, which is to create a technological path dependency in emerging markets. I mean, they'd like to do it in all markets. And an example of an advanced market for that would be somewhere like the EV market in Western Europe, in Germany in particular, where Chinese tech is now a subject of high controversy amongst German manufacturers who can't aren't quite sure how to move on from the internal combustion engine. But if you think about somewhere like um Venezuela, where of course there was this immensely daring raid which uh renditioned President Maduro back in January, feels like a long time ago now. It's worth noting that if you look at the 4G provision in Venezuela, the president may have changed, but the 4G provision I think is still being provided by two Chinese companies, as indeed I think is cloud computing. So in other words, the question of who's really winning long-term when green tech, AI, 5G, EVs are so uh solar technology as well, all of these are very, very much tied up to Chinese interests. And of course, they are also commercially profitable in the long term once China develops near monopolies or monopolies on them.
Um, just on the the point of the chips before we just move on to to to distillation, which is another part of this story, Gregory, the US Congress did respond to this fight earlier in the year and they encouraged through the Chip Security Act companies to embed directly into the chips something that could identify where their physical location was, almost like a tracker. Is that the answer? Is that the way to stop these smuggling networks?
So I think physical security measures on the chips are actually a pretty attractive idea. And essentially what that would involve is we would have transmitters located around the world and you ping, you send a ping from these transmitters and the chips can pick them up and then if they do not respond in a certain time frame, well then just based on the speed of light, you know how far away they are. So you can say that chip is supposed to be in Vietnam, which, you know, traveling at the speed of light responding to this ping should take so long. Oh, it took 45 nanoseconds longer than that. That's very interesting. Perhaps it's not, you know, where it's supposed to be and we can use that as justification to go launch an inspection of the data center in question.
>> Well, the the first story was about hardware and the chips. Uh, the second is is a a type of theft, Stephanie, that is less visible and potentially just as important: distillation. So the ability to copy the capabilities of a leading AI model simply by talking to it repeatedly, systematically, at enormous scale. Can you explain that and what Alibaba have done here to mimic in some ways the model that Anthropic has built?
>> It's almost, I think we're like overcomplicating it. It's like reverse engineering, right? If you just play with something long enough, you figure out how it works. So, they're trying to figure this out and then you get the American model companies. So Anthropic isn't a great example of this because they were reporting that it was happening to them, trying to come up with ways to block it or at least detect that it's happening and then themselves launch a counter strategy. So if you know you're being spied on, if you know you're having your model extracted and you know, hoovered up effectively, what you can then do is deliberately mess with it. So you're being like a double agent. You start handing stuff over that they think is the crown jewels, but it's actually dirty data. It's a model that's deliberately been toyed with, so it's not going to work the way that they think it's going to work. So, and again, you know, it's both fascinating and really tiresome because what you want, if you're looking at a planetary view of how we could roll out AI that benefits everybody, is safe, doesn't lead to accidents that could create existential risk to humanity. What you'd really love is for China and the United States to sit down and work out some protocols together and come up with some standards and find a way to trade and be partners in this exciting revolution. Instead, we're getting this competition tit for tat. It feels very 1980s to me.
>> Yeah. Can I >> jump in here?
>> Yeah, of course.
>> Great. So, there's a couple things I want to say. The first is about how distillation works because it's actually quite interesting. So the difference between machine learning software and traditional software is that in traditional software, there's a human being who's typing out every line of computer code. In machine learning software, you're actually exposing a learning algorithm to a training data set and then it's spitting out the computer code. So I'm oversimplifying here, but not by a ton. In the machine learning sense, it the system is programming itself based on what it learns from data. So think about a chess-playing AI. If the United States or any company wanted to develop one of these from scratch, they would have to go get a very large library of chess game training data and then they would feed that to a learning uh algorithm and then on the other side of that comes a chess-playing AI model that is probably pretty good at chess if your training data is pretty good. Well, China is using distillation to sidestep the training data acquisition because their their training data in this chess example, instead of going out and finding historical chess games, they're just playing against the AI that the Americans made, right? They're having those chess games be the raw training data. And it turns out that this is much, much cheaper as a training data acquisition strategy. And almost all of the training data is very high quality because in this example, you already have a world-class chess-playing AI. So you don't have to have all these loser games by amateurs. All of your games are gold medal Olympic team quality chess games in your training data set. So you incur a fraction of the cost, but you incur most or all of the benefit. And that's a huge threat to American AI companies. The countermeasures that we have against distillation right now can increase the cost of executing a distillation attack maybe by tenfold, but using a distillation strategy is a thousand times cheaper than doing your own training data acquisition and your own model training runs. So, it's really hard to persuade the Chinese to stop this.
>> Here's the question I have there, Ron. That's a really good explanation of of of what is happening. And China's critics would say this is what they've majored in for many, many years: intellectual property theft. But why would they want to do that when they've had such control over social media? Why would they want to copy or to elicit the training data of a model that is effectively being trained on Western culture?
>> Well, first of all, Christian, you're right to point out that actually lots of things that will exist in that huge body of data will be very problematic politically from the Chinese Communist Party's point of view. And in fact, we've seen at least with some of the earlier models, uh, DeepSeek and so forth, that putting in sensitive terms, Tiananmen Square might be an obvious one, uh, can lead to, uh, uh, unresponsive, uh, uh, replies. But broadly speaking, at the moment, the real battle, I think, is for data to have the massive, the maximum amount possible and the biggest amount that you can actually process. Now, within China itself, again, because China operates uh on a basis where there is a very strong capacity to be able to surveil and to be able to control what is actually put out there in the social media environment, that you can have all of this processing going on. Large parts of it might be taken off for use confidentially. They might be used in the military and elsewhere, and the part the general public will get to see will often be quite limited. Having said that, it's also worth noting that China's own social media environment actually is much broader than many people imagine from the outside. Yes, it's certainly the case that if you try and, you know, ferment some sort of revolution against the Communist Party, you'll find yourself being censored and probably arrested very quickly indeed. But wider social problems and evils, for instance, things that you might not imagine the state would want to talk about, actually are discussed quite widely. Financial problems and economic problems, for instance, are widely discussed in the Chinese social media environment. And of course, from their point of view, they're able not only to draw on this huge English language ecology that the American companies are also of course uh um drawing on, but also a huge Chinese language environment which China, by definition, is much better equipped to pick up on.
>> Quick couple of questions for you, Stephanie. I mean, there's there's another new front that's opened in this in this competition between US and China. It's called open-weight local AI models. We talked about the the way that China is going and dispersing its AI technology to developing countries. But there are systems in China that have migrated from the cloud to laptops and mobile devices where they can answer quick questions on on code, complete tasks, speak to a central server without speaking to a central server. So they're localized. It seems to me that that the difference in the battle or the real battle that's going on is not about who builds the smartest model. It's going to be about who builds the model that everyone actually uses.
>> Yes, as ever, the question is, does it scale? There's an energy and cost equation that everybody's having to work out as well. So going back and forth to the cloud is intensive in every way.
>> Energy intensive.
>> Exactly. So you might, for many tasks, it's going to make people get really mindful about what they want their AI to do. So if you can run it locally off of your own machine, great. There might be things that you decide to then want because you're doing a bulk, right?
>> For instance, you're doing something that's far more intensive. That's going to cost you more. People are, we're now seeing because remember, everybody's been given access to these tools so far for free or very, very low costs, that they're being picked up right now by the companies as everybody gets hooked on it, gets baked into their workflows, etc. Not that cheap if you're paying for tokens, right?
>> You're seeing the cost now coming up, right? And that's now happening. But remember, this is only what we're four years.
>> Two different models, two different ways of approaching this.
>> Exactly. And so then comes the question of going open source versus open models versus closed models. You've raised up the question of waiting. There's the security risks of these, right? So there's trade-offs for each one of these. And again, depending on how regulated you are, that's going to be a factor. So as companies and countries are working through this and individuals too, we're going to see greater choice.
>> Craig, one, >> uh, also one of the other tactics which China has used in other aspects of technology, I think we're likely to see in this context of tokens as well and and the costs of AI. China subsidizes very heavily to try and get hold of monopolies. And in this particular sphere too, it will almost certainly use state resources to make sure that its AI models are much cheaper, again, particularly for those emerging markets we've mentioned about, until they essentially hold the kind of position they now do in green tech and other areas where they have a near monopoly.
>> Just a quick thought before we move on.
>> Wait, could I jump in here?
>> Yeah.
>> Um, the reason why the models are so cheap is they stole all the training data and didn't have to pay that part of the cost. Um, the distillation story and the low-cost story are two sides of the same coin. Um, the other thing that I think is really important here is the open-source strategy is kind of a spoiler strategy, which is to say you can't make a lot of money giving away your AI for free, and that's what China is doing. So the main strategic benefit that they are getting by doing this open-source strategy is number one, there is that surrounding ecosystem of software, hardware, and services that you can sell, you know, around the model itself that you gave away as open source. But the real main strategic benefit is just hurting the ability of US companies to make money, right? By by providing a competitor product uh that does that. The second thing that I want to say is I remember when Claude and Anthropic made Fable 5 available. This is the latest and greatest version of Anthropic's models. It's the open version of Mythos. And the difference between that and the prior generation of models, Opus, was just jaw-dropping. And even though I only had Fable 5 for a week, wow, do I miss it really, really badly. And so there's a different, there's a portfolio of applications that you might use AI for. You might be using it for heavy-duty software development in customer mission-critical type applications. You probably do want to pay for the latest and greatest models in that area. On the other hand, you have the sort of thing that Airbnb might be using Chinese open-source models for, which is basically just going to the frequently asked questions list and fetching information and then returning that in a conversational chat interface. That's not very sophisticated. You can use a cheap, crummy, or even free uh model to you to do that sort of thing. And so I think there might be, this is a plausible scenario to me, a repeat in the AI model ecosystem of what we've seen in the smartphone ecosystem, which is to say Apple does not make a majority of global smartphone revenues. Far from it. They make something like 15 to 20% of global smartphone revenues, but they make 60 to 70% of global smartphone profits. And so the question here is not just, you know, whose model is going to be used most widely, but whose model is going to be used most widely by customers that actually pay money.
>> What's striking about everything that we've discussed is that the United States and China don't appear to be on the same strategy. There's one which Gregory has just set out, which is really treating it as an arms race. We're going to jealously guard everything that we've built. uh we are going to take economic, defense, corporate advantage from what we what we're building and everybody else will keep outside. Whereas you could define this as a space race where you have multilateral treaties. It's for the good of mankind. We're going to share for the benefit of humanity. Why is it being set up as an arms race?
>> I would say Christian, it's a hemispheric race. Let me just say briefly what I mean by that. And first of all, I think it's right, and Gregory's made this point very clearly, that at the governmental level, there is a genuine competition. One of the reasons why it's going to be very hard to get a cold war type agreement on, you know, mutual non-retaliation or kind of mutual inspection and so forth is that both sides want to win and they don't trust each other at all. They can't trust and they can't verify to adapt.
>> But that's because you're setting it up as an arms race. If you define it as an arms race, it becomes an arms race.
>> And I think there are aspects of both governments which uh, you know, would argue that that's uh that's not inaccurate. But in terms of the wider usage in society, I said hemispheric because the further east you go in the world, the less concern there is overall about the wide roll-out of AI throughout society as a whole. And I think we can't separate what might be seen as governmental and military use from the wider acceptance of AI in society. There's still a great deal of reluctance, as we know, in parts of Western Europe and even in North America as well. In China as a whole, of course, it's an authoritarian state, but nonetheless, AI is now embedded throughout society and is becoming so actually in plenty of other more democratic societies in that part of the world as well. Also, there's emerging markets in the global south, I've mentioned, very keen to make use of the economic benefits of the technology too. So, in that sense, it's almost as if there's two separate things going on: a US-China race between the two for um the highest quality and supremacy which has a military aspect, and the wider ecological roll-out in terms of how society is being transformed in everything. Just to finish that point. Yeah.
>> With what end in sight? Is it to disperse it as widely as possible and then to monetize it later down the line?
>> Well, in China's case, there's a very specific issue which is to do with the fact that its demographics means that there won't be that many young workers actually doing kind of uh various types of labor in a generation or two's time. So having AI take part of that place over time is is important. More broadly speaking, China also has an ideological aim which is not necessarily in opposition to the US. It partly is, but it's also about being seen as the face of the future, the cutting edge, being the society in the world. It already is to some extent where AI is more embedded than anywhere else in the world. Helps to sell the story that the future is not America, which the Chinese would talk about being in decline, but instead that China is at the forefront.
That's all we have time for. Gregory Allen, Ranom, Dr. Stephanie H. Thank you all for your thoughts. Next week on AI Decoded, uh uh we will of course get to many of your questions. So do keep those coming. AI decoded atbc.co.uk. Uh the QR code is on screen which takes you straight to the AI Decoded YouTube playlist. Do take a look at that. Some really good interesting uh back topics there. And every episode of course is on the BBC iPlayer. We'll see you next time. Thanks for watching.