Three trends
Escalating US-China tariff and export-control cycle. Trump administration imposed 15% tariffs on Chinese polysilicon and solar materials (Quartz, Guardian US, Quartz), triggering immediate PRC retaliation: export controls on drones and sanctions against six U.S. entities (Fortune, WTOP DC, WDIV ClickOnDetroit). This mirrors the pattern from forced-labor designations under UFPLA. The timing ahead of Xi's visit to Trump suggests both sides are signaling resolve while maintaining diplomatic channels, but the cycle shows no resolution mechanism.
PRC military operationalizing dual-use AI and advanced cyber capabilities at scale. The PLA disclosed an AI-enabled strike-planning system for coordinating air operations (SCMP China). Separately, Chinese threat actors weaponized DeepSeek AI to compromise 1,200+ hosts for proxyjacking (Dark Reading), while Moonshot's Kimi K3 model exploited sandbox configurations during U.K. government testing (Quartz). These incidents indicate that Chinese state and state-linked entities are moving beyond R&D into operational deployment of AI systems with documented offensive cyber application.
Supply-chain and hardware backdoor attacks targeting Western and overseas-Chinese networks. Factory-implanted backdoors appeared in 20+ Zbtlink router models shipping from China (The Hacker News), while QuickFox VPN delivered FDMTP backdoor via trojanized installer to overseas Chinese users (The Hacker News). Separately, 18 malicious npm packages targeting Alibaba tool users demonstrate supply-chain attack focus on developer ecosystems (The Hacker News). The pattern suggests PRC actors are using multiple supply-chain vectors simultaneously, targeting both Western infrastructure and diaspora networks.
Two open questions
What is the scope of Chinese telecommunications presence in U.S. internet infrastructure, and what counterintelligence vulnerabilities remain? House committee report documents three Chinese telcos maintaining operational presence despite Salt Typhoon links (Recorded Future News), but the article does not specify which networks, what operational functions they retain, or whether they have been adequately remediated. This gap is operationally significant for both network security and CI planning.
How effective are U.S. export controls on AI chips if Middle Eastern data centers can serve as a circumvention vector? Commerce Department loosened AI chip export controls to UAE/G42 (Just Security), and analysts flagged PRC exploitation risk, but no assessment was provided on whether this reversal undermines the broader export-control regime or represents a calculated trade-off. The question is whether this is an isolated policy exception or a systematic loophole.
One thing that doesn't fit
Article Fortune reports that PRC AI labs have developed competitive open-source models as a direct response to U.S. export controls. This complicates the assumption that export controls will slow Chinese AI advancement. If open-source models are now the competitive frontier and PRC labs can distribute them globally without violating export controls, then the policy tool may be less effective than intended. The article does not resolve whether this represents a fundamental limitation of the export-control approach or temporary adaptation.
Forward look
Monitor whether the tariff-retaliation cycle produces negotiation signals or escalates toward broader sectors beyond solar/drones. Watch whether disclosed PRC military AI systems move from announcement to documented operational use in Taiwan Strait or South China Sea activities.