Former OpenAI and Anthropic researcher says China has spies inside both firms, but offers no evidence

Former OpenAI and Anthropic researcher says China has spies inside both firms, but offers no evidence

N
News Editor
2026-10-08 07:11:57
Jacob Coxon, a former pre-training researcher at OpenAI and Anthropic, said on the PBD Podcast that he is "90%" sure China has already placed spies inside both companies. He did not provide evidence and said he would not identify any individual. Coxon also argued that China could hack the companies at any time, which in his view would make it difficult for the US to maintain a durable lead in AI. He said the issue had come up inside OpenAI, though he described those discussions as casual and not taken seriously by colleagues. As a policy response, Coxon said AI labs should be nationalized and subject to background checks similar to security clearances. He also claimed that part of China’s current progress comes from "distillation," meaning training domestic models on responses generated by US systems rather than acquiring the models themselves. The report also noted pushback. Triolo of DGA-Albright Stonebridge Group called the remarks irresponsible, while data cited from MacroPolo showed the composition of top AI talent in the US but did not support any espionage conclusion. It also referenced the case of former Google engineer Ding Linwei to draw a legal distinction between taking trade secrets and acting as a spy for a foreign government.

Jacob Coxon, a former pre-training researcher at OpenAI and Anthropic, said on the PBD Podcast that he is 90% sure China has already placed spies inside both companies. He did not present evidence and did not accuse any specific person.

What Coxon said on the podcast

Coxon, who previously worked on pre-training research at OpenAI and Anthropic, made the comments in a recent appearance on the PBD Podcast, which the report said has 3 million subscribers.

Host Patrick Bet-David asked whether China would stop if the US chose to slow down. Coxon replied that if the US hit the brakes now, China would try to catch up. He then said, 「China already has spies in OpenAI and Anthropic」, and added that China could also hack the companies at any time, meaning the US would struggle to open a lasting gap even if it stayed ahead.

When Bet-David asked how confident he was, Coxon answered: 「90%. Definitely. It’s almost certain.」

He still left himself some room. Asked whether this had ever been discussed inside OpenAI, Coxon said yes, but described it as something colleagues treated half-jokingly because no one really took it seriously. He then added: 「This is actually serious. There are definitely spies.」

When asked whether he had seen any suspicious individuals, Coxon said he had not. He said he did not want to label anyone and would not name names. After the host pressed him to identify senior figures, Coxon again said he was not trying to start a witch hunt.

On how such claims should be checked, Coxon said he was not an expert in that area and only believed the industry should take the issue more seriously.

His proposed response and his view on China’s progress

Coxon said AI labs should be nationalized and subjected to background checks modeled on security clearances.

He also said a meaningful share of China’s current progress comes from "distillation" — using responses from US models to train domestic systems — rather than obtaining the underlying models themselves.

Background on Coxon

The report said Coxon is 27 and British. He spent the past three years working on pre-training research at OpenAI and Anthropic.

On Sept. 8, he announced on X that he was leaving Anthropic. That post drew more than 170 million views. At the time, he wrote on social media that the people building AI genuinely believe it could kill everyone before the end of this decade.

Pushback and verifiable facts

Triolo, a partner at consulting firm DGA-Albright Stonebridge Group who studies China tech policy, responded on social media: 「Sorry, but this seems really irresponsible.」

The report also cited a MacroPolo talent-tracking study mentioned by the South China Morning Post. Using NeurIPS paper authors as its sample, the data showed that among top AI talent working at US institutions in 2022, 38% were of Chinese origin and 37% were of US origin. In 2019, those shares were 27% and 31%.

It also stressed that "origin" in that dataset is defined by the country of undergraduate education. That is not the same as nationality, and it does not indicate intelligence ties. The figures describe talent composition, not espionage.

The Google case and the legal threshold

The report pointed to one of the highest-profile AI trade-secret cases in recent years. Former Google engineer Ding Linwei was accused of uploading more than 500 confidential files. In January 2026, a jury found him guilty of trade secret theft and economic espionage.

But in August, Judge Vince Chhabria vacated all espionage counts, saying the evidence was insufficient to show an intent to benefit the Chinese government. On Sept. 1, Ding was sentenced to nearly one year in prison for trade secret theft.

The report drew a legal distinction here: taking confidential material is not the same as serving as a spy for a foreign government, and the evidentiary bar for the latter is much higher.

Similar warnings have surfaced before

The concern is not new. Anthropic co-founder Dario Amodei said at a Council on Foreign Relations event in March 2025 that algorithmic secrets worth $100 million could amount to just a few lines of code, adding, 「I’m sure people want to steal them, and they may already have.」

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.