Chinese AI – They're Just Like Us? With Beijing-Based Concordia AI CEO Brian Tse
Summary
China’s official “AI Plus” initiative is an economy-wide deployment drive, not a publicly articulated sprint toward an AGI finish line. Brian Tse points to the August 2025 directive: six pillars spanning scientific discovery, industrial transformation, consumption, human-machine collaboration, government efficiency and governance, and international cooperation, with no mention of AGI or superintelligence. Tse’s view is that “the real AI race for China isn’t about beating the US to AGI supremacy”; it is about integrating AI into the real economy.
AI safety has moved into China’s national-security machinery, giving it more policy continuity than a voluntary corporate pledge. The 2024 Third Plenum classified AI safety as a major public-safety concern; a February 2025 emergency plan placed AI alongside cybersecurity and biological security; and an April Politburo study session covered monitoring, early warning, and emergency response. The governing metaphor from Vice Premier Ding Xuexiang: “If the braking system isn’t under control, you can’t really step on the accelerator with confidence.”
Public consumer AI in China already faces something resembling a licensing regime. A broadly available chatbot must register, grant the Cyberspace Administration of China pre-deployment access, and test against 31 risk categories; at least 96% of sampled outputs must be deemed acceptable, and regulators can demand repeated testing and fine-tuning before approval. More than 500 systems and model versions have been filed, while internal research and business-to-business deployments receive more latitude.
Chinese frontier-safety researchers are increasingly working from the same threat model as their Western counterparts. Concordia AI and Shanghai AI Lab’s framework uses “red lines” for unacceptable risk and “yellow lines” for early warning across cyber offense, biological misuse, large-scale manipulation, and loss of control; a companion evaluation tested more than 20 models for self-replication, deception, scheming, and uncontrolled AI R&D. Tse says around 31 groups in China have published papers on AI safety.
The safety implementation gap is real, but the DeepSeek evidence points to rapid iteration rather than indifference. Tse says Chinese developers use data filtering, safety fine-tuning, RLHF, Constitutional AI, and real-time monitoring, yet compliance remains concentrated on the government’s 31 categories and most companies do not publish CBRN or loss-of-control evaluations. Concordia’s SAB-Bench Bio testing found harmful-biological-prompt refusals rising from roughly 11% for DeepSeek V3 to 54% for V3.1—around the cross-model median—while DeepSeek R1’s own paper acknowledged that reasoning can expose more sensitive knowledge.
China’s commitment to open weights and compute sovereignty is strengthening together. Open releases from DeepSeek, Qwen, Kimi, and MiniMax provide transparency and global distribution, but also motivate hazardous-data filtering, tamper-resistant safeguards, responsible licenses, and platform monitoring—interventions Tse says “might not work” and remain early science. Meanwhile, distrust of H20 backdoors, non-purchase of the RTX PRO 6000D because it is viewed as low quality and somewhat overpriced, Huawei’s Atlas 950 systems, and China’s huge electricity buildout support a strategy of compensating for weaker individual chips with scale, energy, and training efficiency.
A sabotage-based balance of power looks less stable in AI than it did in the nuclear era. Tse rejects “mutually assured AI malfunction” because aggressive superintelligence development lacks an observable red line, while attacking a rival data center could become a “hair-trigger” path to war; he points to a METR graph showing the length of tasks AI can perform doubling every seven months. His alternative has three pillars: shared catastrophic-risk red lines, continuous evaluation and disclosure protocols, and pre-agreed emergency responses when warning thresholds are crossed.
China’s AI optimism coexists with material labor anxiety, especially as embodied AI moves from demos into factories and streets. Roughly 80% of surveyed Chinese students expected AI to do more good than harm, a confidence Tse links to per-capita GDP growing more than 140-fold during his parents’ lifetimes; yet youth unemployment, robot marathons, autonomous taxis, and humanoids threaten both white-collar and physical work. Tse says that state ownership of much of the critical infrastructure—energy, data centers, and land—could offer a route for distributing AI gains, but governments are addressing the employment question surprisingly little.
Deep dive
1. Concordia AI was designed to bridge institutions that rarely share one room
Tse’s path crossed the ecosystems he now tries to connect: Tsinghua University and a Chinese deep-learning hardware startup, the Centre for the Governance of AI, initially founded at the University of Oxford, Google DeepMind, the Partnership on AI, and external work with OpenAI around 2019 on the societal implications and release strategy of GPT-2.
After returning to Beijing, he worked with the Beijing Academy of AI on one of the first AI-ethics principles from Chinese institutions. He founded Concordia AI to build “a more cohesive global conversation on AI safety,” combining an Asian perspective with work across academia, industry, and policy.
Concordia’s three pillars are national standards and policy consultation; direct collaboration with leading labs on safety frameworks and practices; and international convening through Chinese and Singaporean conferences, UN forums, and global AI summits. Unlike a pure research nonprofit, it participates directly in Chinese standard-setting committees.
2. China’s AI map is geographically distributed but politically connected
Beijing hosts Baidu, ByteDance, Moonshot AI, and Zhipu AI, with Tsinghua supplying an unusually dense network of researchers and founders. Shanghai houses MiniMax and other multimodal startups while the World AI Conference concentrates industry, investment, research, and policy attention.
Hangzhou is home to Alibaba and DeepSeek; its “six little dragons” label, popularized in 2025, also covers robotics companies such as Unitree. Shenzhen anchors Huawei and Tencent. Concordia documented around 31 groups in China that have published papers on AI safety, concentrated in Beijing, Shanghai, Hangzhou, Shenzhen, and Hong Kong.
Tse says the more important distinction from the United States is that China’s technology and policy ecosystems are “quite intertwined,” whereas Silicon Valley and Washington, DC, often operate with different cultures and incentives.
3. Chinese optimism about AI is grounded in remembered transformation
Limited surveys suggest the Chinese public generally expects AI’s benefits to exceed its harms. One post-ChatGPT survey found people could believe AGI carries existential risk yet still support developing it because they regarded the risks as largely controllable; another found roughly 80% of Chinese students expected AI to do more good than harm.
Tse’s explanation is historical rather than technological boosterism. His parents, born around the 1960s in Fujian, lived through a more than 140-fold increase in Chinese per-capita GDP and a decline in extreme poverty from approximately 88% in the early 1980s to nearly zero.
“When you have witnessed that level of transformative progress firsthand or through your parents,” he argues, technology plus competent governance looks like a plausible engine of improvement. Labenz accepts the extraordinary rebound while noting that it began after an exceptionally low and damaging period.
4. China follows the foundation-model mainstream without treating it as the only path
Commercial developers largely follow the same stack familiar in the West: foundation-model scaling, multimodality, advanced reasoning, agents, and greater compute across training, post-training, and inference. Tse says Chinese researchers and companies followed Western developments closely, particularly after GPT-3’s success.
A prominent alternative emphasizes embodied AI: intelligence trained and deployed in the physical world, where China’s manufacturing base could become strategically important. This direction receives attention from scientists and national policy documents, not merely robotics startups.
The Beijing Institute for General Artificial Intelligence pursues systems that reason and plan toward complex goals with minimal initial input. Its director contrasts a “small data, big task” approach with the “big data” route used to train large foundation models.
Labenz’s recurring conclusion is that even these alternatives have Western analogues, from embodied-intelligence programs to ARC-AGI-style work on adaptation and sample efficiency. The differences are matters of emphasis, not wholly separate scientific traditions.
5. “AI Plus” makes diffusion through the economy the finish line
Tse sees far less Chinese discussion of precise AGI timelines or a decisive finish line. Entrepreneurs concentrate on technological self-sufficiency, useful applications, profitability, and open sourcing models for countries and communities that lack AI capacity.
Released in August 2025, the central government’s “AI Plus” initiative treats AI as a general-purpose technology comparable to electricity or the internet. Its first pillar is scientific discovery—including social science and philosophy—because Beijing sees research acceleration as a force multiplier for everything downstream.
Other pillars cover autonomous factories, logistics, agricultural drones and robots, new consumer experiences such as the metaverse and brain-computer interfaces, AI agents as human collaborators, more efficient government and proper governance, and international cooperation through open tools and models, particularly for the Global South.
The omission is decisive for Tse: the blueprint does not mention AGI or superintelligence. He also rejects the older utopian suggestion that AI could make comprehensive central planning work; realistic government uses include disaster-warning systems, not “a unifying silver bullet to societal issues.”
6. Chinese and Western researchers still inhabit one scientific commons
Since the deep-learning revolution around 2012, researchers have attended the same conferences, published on arXiv, and treated venues such as NeurIPS and ICML as more prestigious than Chinese-language journals. Most papers are written only in English, sometimes followed by Chinese blog summaries.
Tse cites a 2024 Nature analysis of more than five million AI papers finding that US-China collaborations produced more impactful and novel work than either country alone. He also recalls evidence that China, not the United States, was the United Kingdom’s most common AI-research partner.
English is the field’s lingua franca, with historical “cultural gravity” rooted in Western industrialization and colonialism. Most scientists at leading Chinese labs can read and understand it, and many can converse comfortably; everyday consumers meanwhile access plentiful free cloud chatbots and video tools, while developers can use open weights.
7. Beijing has elevated AI safety into national-security machinery
At the 2024 Third Plenum, China’s leadership called for an oversight system and classified AI safety as a major public-safety concern. A February 2025 national emergency-response update then placed AI risk alongside cybersecurity, biological security, and natural disasters—not merely within content control.
An April 2025 study session for the Politburo’s roughly 24 senior officials went further. President Xi described both “unprecedented development opportunities” and “unprecedented risks and challenges,” while the readout specified monitoring, early warning, and emergency response as distinct stages of AI-risk management.
These meetings signal priorities to local officials, investors, companies, and other institutions. Tse cautions that top-down direction does not ensure perfect coordination—actors interpret and respond dynamically—but it can mobilize a whole-of-society effort around a multi-year objective.
8. Continuity and coherence make Chinese safety signals operational
Tse’s first contrast with Washington is continuity: Chinese national plans can remain in force for years or decades, whereas one US administration’s AI executive order may not survive the next. The second is coherence: the Politburo establishes a tone that agencies and local governments broadly implement.
Academics also have unusual policy access. Chinese scholars worried about catastrophic AI risk have briefed the leadership through study sessions and other channels; Tse connects that influence to a long tradition in which scholarship held greater status than entrepreneurship, potentially reducing exposure to commercial lobbying and regulatory capture.
Chinese debate appears less polarized between immediate-pause advocates and effective accelerationists. The prevailing position is closer to “the middle,” with greater willingness to regulate and no assumption that safety and capability must form a zero-sum trade.
Vice Premier Ding Xuexiang’s Davos metaphor captures the governing stance: “If the braking system isn’t under control, you can’t really step on the accelerator with confidence.” The associated “45-degree line” means safeguards should strengthen alongside dangerous capability, even where particular controls impose latency or user-experience costs.
9. Local experiments feed national rules instead of regulatory fragmentation
China’s “mayor economy” historically rewarded provincial officials for GDP, infrastructure, real estate, and investment. Adding environmental metrics changed behavior and contributed to improved Beijing air quality—Tse’s example of how national goals become effective only when translated into local promotion incentives.
AI plans from Shanghai, Shenzhen, and other provinces use the same experimental tradition. Autonomous-driving zones test different automation levels before national institutionalization; Tse says the state of the art in China, including Baidu’s Apollo project, is broadly comparable with Waymo, though society may want such systems to be “maybe 10 times safer” than humans.
A national rule beginning in September 2025 requires explicit labels and implicit metadata for AI-generated text, audio, video, and even simulated environments. Shanghai assembled companies such as MiniMax and platforms such as RedNote to make watermarking and provenance interoperable, but China’s binding AI regulations remain primarily national rather than province-by-province.
10. Public deployment passes 31 tests, while internal use gets room
Labenz’s comparison was deliberately stark: in the United States, xAI could launch Grok 4 while Grok 3 was identifying itself as “MechaHitler,” without any mandatory pre-deployment review. Chinese developers of publicly available chatbots instead register with the government and provide regulators early model access.
A national standard covers 31 risk categories, with at least 96% of sampled answers required to be acceptable. Local cyberspace authorities receive test accounts, run red-team exercises, and can initiate repeated cycles of feedback, fine-tuning, and reassessment; more than 500 systems and model versions were filed over the previous two years.
The 96% threshold reflects technical compromise. An initial draft approached perfect truthfulness and reliability, but a three-month public and industry consultation established that this was infeasible for language models, so the final rule relaxed the standard rather than pretending hallucinations could be eliminated.
Scope preserves some entrepreneurial freedom: internal research and business-to-business systems do not face the same rules, but broadly available chatbots and recommendation products do. Beijing separately bars hospitals from issuing AI-generated prescriptions without a human in the loop; companion-character apps exist, alongside familiar paternalistic limits on children’s gaming time.
11. Frontier-risk thinking converges on red lines and loss of control
TC260’s AI Safety Governance Framework v2.0 addresses catastrophic risk, including loss of control, biological misuse, and cyberattacks. It highlights data curation and removal of hazardous knowledge during pre-training, though Tse says such upstream measures are not yet binding regulation.
Concordia and Shanghai AI Lab’s Frontier AI Risk Management Framework draws on safety-critical industries and international practice. “Red lines” mark unacceptable thresholds that no developer should cross; “yellow lines” provide early-warning triggers for stronger safety and security measures.
Covered domains include offensive cyber capability, biological risk, large-scale manipulation and persuasion, and loss of control. A companion technical report evaluated more than 20 proprietary and open-weight models, decomposing loss of control into self-replication, deception, scheming, and the capacity to conduct uncontrolled AI R&D.
Labenz’s synthesis is that the largest present difference lies at the consumer-regulation layer, not in technical risk taxonomies. China and the West increasingly name the same failure modes and propose similar defense-in-depth responses, while Western discourse remains more fascinated by AGI’s event horizon.
12. DeepSeek reveals the gap between regulated safety and emerging risk
Responding to Dario Amodei’s criticism that DeepSeek R1 lacked biological-weapons guardrails, Tse says China’s safety regime is government-led: companies spend heavily meeting existing requirements, which can reduce appetite for evaluations outside those rules. Their practices nevertheless include data filtering, safety fine-tuning, RLHF, Constitutional AI, and real-time misuse monitoring.
The weak point is disclosure and prioritization. Most Chinese developers have not publicly released CBRN or loss-of-control results because their defenses are primarily engineered around the regulated 31 categories, illustrating how a detailed compliance regime can lag a changing frontier-risk landscape.
DeepSeek R1’s peer-reviewed Nature paper candidly says open weights can be fine-tuned to defeat protections and reasoning models may reveal more sensitive knowledge. Its reported overall safety was comparable with other state-of-the-art systems, including GPT-4o, rather than categorically outside the international range.
Concordia’s independent SAB-Bench Bio results show movement: refusal of harmful biological prompts increased from roughly 11% for DeepSeek V3 to 54% for V3.1, around the median of tested models. Labenz’s pushback remains: both countries still tend to build capability first, discover the danger, and attach controls “just in time.”
13. Open weights remain strategic, with safety pushed into the stack
China’s July 2025 Global AI Governance Action Plan treats open source as beneficial to innovation, access, and even safety, broadly aligning with the pro-open-source US action plan. Chinese documents nevertheless acknowledge misuse risks, and the registration system could expand to CBRN, agentic systems, loss of control, or open-weight governance.
Tse’s stated direction is defense in depth: remove hazardous knowledge before training where possible, then consider tamper-resistant safeguards, responsible-use licenses, and platform-level monitoring. “Many of those might not work,” he cautions; open-weight risk management remains an immature science.
Labenz proposes a split stack: widely released models would ideally be genuinely unable—not merely refusal-trained—to answer the most dangerous virology questions, while fuller scientific systems might remain on controlled infrastructure. Tse agrees that a defense-in-depth approach is needed but does not claim that this specific split-stack design is solved.
14. Export controls are accelerating China’s compute-sovereignty strategy
Tse says Chinese AI circles show less “fear and paranoia” about US secret models than American discourse shows about China. But export controls are widely seen as an attempt to stifle Chinese technological progress and preserve US dominance, with civilian costs spanning generative art, medical diagnosis, and other compute-intensive applications.
As of September 22, Chinese companies were not purchasing NVIDIA’s RTX PRO 6000D, which was viewed as low quality and somewhat overpriced. Chinese regulators also raised concerns about possible backdoors in H20 chips, specifically remote location tracking and remote shutdown functionality, making dependence on an adversary’s stack a security issue as well as a supply issue.
Huawei’s response includes Ascend chips and an announced Atlas 950 SuperPoD supporting more than 8,000 chips, with an associated Atlas 950 SuperCluster described as using more than 500,000. Tse sees export controls as a catalyst for domestic substitutes, while China’s leverage over critical minerals and rare earths complicates any one-way dependence narrative.
Labenz preserves the Western countercase: over the next five years, the NVIDIA-TSMC-centered supply chain may still produce comfortably more than an order of magnitude more advanced chips than China. If so, rejecting available H20s could be a costly choice even while domestic capacity improves.
15. Energy abundance could compensate for weaker individual chips
Tse’s first offset is architectural scale. Huawei’s CloudMatrix 384 uses more than five times as many Ascend chips but, in his telling, more than compensates for their weaker per-chip performance relative to NVIDIA Blackwell GPUs.
Its principal disadvantage is energy efficiency, which matters less if China can supply immense power. Tse says China added generation capacity equivalent to the entire US grid during the last decade, backed by some of the largest solar, hydro, and wind installations in the world and a potentially leading role in nuclear-energy deployment.
The resulting strategy is “scale over power density”: manufacture or acquire more chips, tolerate higher electricity consumption, and use state-supported infrastructure to run them. Distributed training, efficient parameter communication, and reinforcement learning also weaken the old assumption that every frontier run requires one tightly connected, cutting-edge data center.
The second offset is algorithmic efficiency. Tse characterizes DeepSeek R1 as achieving its performance with roughly 500 NVIDIA H100 chips, reinforcing the broader claim that raw leading-edge GPU counts do not map one-for-one onto useful model capability.
16. “Mutually assured malfunction” fails the observability test
Tse credits the superintelligence-strategy proposal for rejecting one-country AI domination, but its nuclear analogy breaks at the red line. A nuclear launch is detectable; “aggressive development of superintelligence” is not, especially when a METR graph depicts the length of tasks AI can perform doubling approximately every seven months.
From Beijing, US leaders predicting AGI around 2027 while imposing export controls could already look like a monopoly race. If that perception can trigger sabotage, the doctrine supplies no reliable distinction between ordinary development, dangerous acceleration, and an intelligence explosion.
The escalation problem is worse: destroying a rival’s data center means attacking one of its most valuable national assets and critical infrastructure. Far from stabilizing deterrence, formalizing that willingness could create a “hair-trigger” environment shaped by poor visibility, false positives, and fog-of-war intelligence.
Tse’s alternative has three pillars: internationally agreed prohibitions on systems enabling WMD proliferation, uncontrolled self-replication or self-improvement, and an intelligence explosion that humanity or other countries could no longer comprehend and control; continuous evaluations with shared warning protocols; and prepared emergency responses such as stronger controls, mandatory human oversight, and crisis communication.
17. Cooperation must connect safety research to jobs, robots, and lived legitimacy
Existing mechanisms offer a base: the US and China have built toward an agreement keeping humans in control of nuclear command and control, while Track 2 scientist dialogues echo the Pugwash Conferences on Science and World Affairs held regularly since 1957. Singapore adds a relatively neutral meeting point, a strong assurance ecosystem, offices from both countries’ companies, and a safety agenda developed by more than 100 experts.
Tse favors portfolios of safety leaderboards—not one “MMLU for morality”—and a global frontier-risk framework analogous to international aviation standards. The 2023 Bletchley Park summit brought 28 countries together and led to the nomination of Yoshua Bengio to lead an independent report with contributions from 100 experts, an attempted “IPCC for AI safety.”
China’s frontier-safety field has expanded from jailbreak defense and RLHF into scalable oversight, mechanistic interpretability, embodied AI, and superhuman-system control. More than 20 major Chinese companies have signed voluntary commitments covering agentic and embodied systems; Unitree dances, robot marathons, and planned humanoid-versus-human competitions turn abstract capability into visible public benchmarks.
Those spectacles also expose the political economy: autonomous vehicles have prompted driver protests, while educated young people already face weak white-collar hiring and may fall back on delivery or DiDi work that automation can also threaten. State ownership of much of the energy, data-center, and land infrastructure might help distribute AI profits, but Tse’s closing prescription is deliberately unglamorous: pursue shared standards, joint research, people-to-people exchange, and “the low-hanging fruit” governments still leave untouched.