Will ‘Made in China’ AI regulation soon go global?

Will ‘Made in China’ AI regulation soon go global?

China is forging ahead in the field of global AI governance – and is outpacing the EU. But there is still hope for Europe.

(note the original article is written in german. I made a translation with the help of deepl.com Pro and added only a few edits for clarification).

The heatwaves are not only signalling an impending conflict over water resources – between data centres, power stations and people. Meanwhile, AI systems are even breaking out of test environments, exploiting security loopholes and thereby committing crimes.

Not because they are aware of their own existence, but because they operate in a goal-oriented manner – and to that end, they cheat and hack.

It began in April with ‘Sandwich-Gate’: a security researcher from Anthropic was sitting in the park and had just started eating a sandwich when he received an email. The sender was Claude Mythos, a secret, as yet unpublished model from Anthropic, which should not actually have had access to the internet. As part of a test, the AI had been given the task of breaking out of its restricted test area – the so-called sandbox. The fact that it managed to do so confirms the worst fears.

Next came OpenAI, whose AI agents broke out of their sandbox in July and gained access to the Hugging Face platform via a previously unknown vulnerability and publicly available login credentials. And Meta announced that a misconfiguration had led to its latest AI model gaining access to the internet. The AI then exploited a security vulnerability at a third-party provider.

The US government responded not with a sense of global responsibility, but with its usual paranoia. It forced Anthropic to release the latest version of Claude only to US citizens.

One possible explanation for this behaviour is the fear that the AI models could fall into the hands of Russian or Iranian hackers. At the same time, the US government is considering banning Chinese open-source models such as Kimi.

However, as is well known, the US government has little regard for legal restrictions or a global AI moratorium. On the contrary: Trump penalises states that enact their own laws against copyright infringement, discrimination or to enforce environmental regulations.

This led to some unsual news story in July: around 1,000 researchers and managers from OpenAI, Anthropic, Meta and Google signed an appeal to the US government to participate in international efforts to regulate the pace of AI development – noting that AI software could soon evolve on its own. In the absence of state intervention, the tech giants are thus themselves grappling with the very forces they have unleashed.

Anthropic has now , through the ‘Glasswing’ project, granted selected tech firms access to its latest models in order to build a safety community.

However, relying on the goodwill of companies whose CEOs simultaneously sympathize with a America-first stance (Claude, for example, may not be used for commercial surveillance in the case of US citizens) when it comes to existential AI issues is not a rosy prospect for the rest of the world.

Yet international frameworks do exist: the Council of Europe’s Convention on AI, for example – which the US played a major role in shaping and watering down behind the scenes, only to ultimately refuse to sign it itself.

Or the EU’s AI Act, now two years old, which clearly regulates the risks of AI systems and provides tools for market scrutiny.

Yet the European Commission, which is keen to take credit for this legislation, is granting all corporations generous grace periods – because it has still not translated its own legislation into concrete technical standards. Strict rules for high-risk applications in education, the judiciary, medicine and human resources are not due to come into force until the end of 2027 – a delay that is primarily due to a U-turn by the European Commission under pressure from business lobbies. Meanwhile, the UN and the OECD are adopting one paper after another, but remain largely unable to act due to the US’s obstinate behaviour.

As a result, China is now the one having the last laugh.

Beijing is setting the industrial agenda not only through five-year plans, but also in the field of AI regulation – ethical principles are not merely proclaimed there, but are translated into clear review and approval procedures. At the heart of this is a new regulation on AI ethical review: companies must have risky AI projects reviewed by internal ethics committees, with assessments focusing on well-being, fairness, transparency, controllability and data protection.

Since July, a law has also been in force to combat uncontrolled AI ‘anthropomorphisation’: so-called companion bots (virtual companions) must identify themselves as such, incorporate usage limits and warning notices, and refer users to crisis support in the event of risks of self-harm – Bytedance and Alibaba were promptly forced to disable their popular companion functions by the deadline. China has also enacted regulations for autonomous AI agents, featuring a three-tier authorisation model and reporting and recall obligations in sensitive areas – a world first.

It may come as a surprise that a highly authoritarian state, of all places, should enact a law whose wording calls for ‘the promotion of human well-being, respect for the right to life, the upholding of fairness and justice, appropriate risk control, the protection of privacy and security, as well as controllability and trustworthiness’. And in doing so, it surpasses the EU in many respects.

But we should be under no illusions: firstly, the Chinese rules apply only to the civilian economy; the state is largely exempt and remains free to monitor, access data and act repressively. Secondly, objectives such as ‘controllability’ and ‘social harmony’ can certainly be interpreted as instruments for disciplining a population in which censorship and the punishment of ‘misconduct’ have long been part of everyday life.

The crackdown on the excesses of AI may also be a political calculation: Beijing’s leadership appears to want to keep its population functioning properly when it comes to AI. Addiction, depression and isolation do not fit into the five-year plans.

China is also exploiting the international vacuum and attempting to elevate its own rules to the status of a global standard. With the ‘Global AI Governance Initiative’, launched as early as 2023, Beijing is positioning itself as an advocate of fairness and inclusion for the Global South. In July 2026, together with 29 signatory states, it founded the ‘World Artificial Intelligence Cooperation Organisation’ (WAICO) – a permanent institution based in China designed to enshrine precisely these principles internationally. China’s UN ambassador emphasised that WAICO should not compete with the UN’s work, but rather complement it. And more generally, China is lobbying for its technical standards in various bodies within the international community in Geneva.

In this geopolitical AI race, Europe has fallen behind in key areas such as chip development and AI platforms, and is currently largely confined to the role of a supplier, for example through the Dutch company ASML and its lithography systems for chip manufacturing. Yet instead of using industrial policy to fund a European ecosystem that complies with strict EU laws by design and code, the EU is compromising its values. And it is watering down its own requirements.

There are, however, plenty of European companies and academic institutions for which regulation and innovation are not mutually exclusive.

This is evident, for example, among cloud providers: Nextcloud CEO Frank Karlitschek emphasises that he has no fundamental problem with regulation. For him, the open-source cloud is a competitive advantage over Microsoft and Google. OVH Cloud CEO Michel Paulin is even more explicit: EU decision-makers need the “courage and intellectual honesty” to build a truly sovereign cloud.

The list could be expanded to include further companies that rely on ethical business models and develop AI systems that comply with principles of sovereignty.

Also the academian world provides a counter-example: the Swiss federal universities ETH and EPFL have, with Apertus, published an AI model that fully complies with the EU’s AI Regulation – in terms of copyright protection, non-discrimination, fairness and transparency. Unlike most Chinese and American models, the training dataset for Apertus is even openly accessible.

Two weeks ago, the researchers released version 1.5, a larger model that has noticeably caught up with its international competitors. It can even be used to build AI agents.

So there is a good range of options available in Europe with focus on open source, open standards and transparency.

Now companies, governments and private individuals need to align their demand in public tender accordingly.

Weitere Beiträge

Wird KI-Regulierung «made in China» bald global?

China prescht in Sachen globaler KI-Governance vor – und läuft der EU den Rang ab. Doch es gibt noch Hoffnung für Europa. Mit den Hitzewellen zeichnet sich nicht nur ein bevor­stehender Konflikt um Wasser­ressourcen ab – zwischen Rechen­zentren, Kraftwerken und Menschen. Unterdessen brechen KI-Systeme sogar aus Test­umgebungen aus, nutzen Sicherheits­lücken aus

Weiterlesen

Schweizer WEKO leitet Untersuchung gegen Google ein- die Hintergründe dazu

Die Schweizerische Wettbewerbskommission leitet eine Untersuchung ein gegen Google. Die Mitteilung dazu: «Vor kurzem hat Google diese Funktion in der Schweiz abgeschafft, während sie im Europäischen Wirtschaftsraum (EWR) weiterhin verfügbar ist. Dadurch wird für Nutzende in der Schweiz standardmässig die Suchmaschine Google Search festgelegt, ohne dass ihnen bei der Ersteinrichtung

Weiterlesen

Ich habe die NZZ-Mediengruppe angezeigt wegen fehlender Information nach dem Cyberhack 2023. Was danach geschehen ist. (Spoiler: nicht so viel)

In diesem Beitrag geht es um einen alten Fall: um die Cyberattacke der Ransomware-Gruppe Play gegen die NZZ-Mediengruppe und auch um das Medienhaus CH Media im März 2023. Konkret um die juristische Aufarbeitung dieses Falls. Denn es ist ein trauriges Lehrstück darüber, wie windige Anwälte die milden Bestimmungen im Datenschutzrecht

Weiterlesen

Die Cyber-Spezialisten des Bundes kehren Microsoft den Rücken

tl,dr: Nach dem Internationalen Strafgerichtshof steigt auch das «Kommando Cyber» der CH-Armee komplett auf die Open Source-Alternative «Open Desk» um. Bereits bis Oktober 2026 sind die neuen Arbeitsplätze eingerichtet.Die Bundeskanzlei hat diese Informationen auf Anfrage der Republik bestätigt. Und auch öffentlich hat sich das Kommando Cyber bereits dazu geäussert. Wer

Weiterlesen

Surprise, surprise: Die Einführung der eID verschiebt sich

Nun bewahrheitet sich, was ich schon geschrieben habe: Die eID kommt nicht mehr 2026…sondern im ersten Halbjahr 2027. Ich verstehe den Frust bei Allen, die beim eCollecting (Unterschriftensammelung für Volksinitiativen und Referenden) vorwärts machen wollen. Sich für digitale Barrierefreiheit einsetzen (die ist bei diesem Projekt von Anfang an mitgedacht). Oder

Weiterlesen