Jacob Coxon, a former pre-training researcher at OpenAI and Anthropic, said on the PBD Podcast that he is 90% sure China has already placed spies inside both companies. He did not present evidence and did not accuse any specific person.
What Coxon said on the podcast
Coxon, who previously worked on pre-training research at OpenAI and Anthropic, made the comments in a recent appearance on the PBD Podcast, which the report said has 3 million subscribers.
Host Patrick Bet-David asked whether China would stop if the US chose to slow down. Coxon replied that if the US hit the brakes now, China would try to catch up. He then said, 「China already has spies in OpenAI and Anthropic」, and added that China could also hack the companies at any time, meaning the US would struggle to open a lasting gap even if it stayed ahead.
When Bet-David asked how confident he was, Coxon answered: 「90%. Definitely. It’s almost certain.」
He still left himself some room. Asked whether this had ever been discussed inside OpenAI, Coxon said yes, but described it as something colleagues treated half-jokingly because no one really took it seriously. He then added: 「This is actually serious. There are definitely spies.」
When asked whether he had seen any suspicious individuals, Coxon said he had not. He said he did not want to label anyone and would not name names. After the host pressed him to identify senior figures, Coxon again said he was not trying to start a witch hunt.
On how such claims should be checked, Coxon said he was not an expert in that area and only believed the industry should take the issue more seriously.
His proposed response and his view on China’s progress
Coxon said AI labs should be nationalized and subjected to background checks modeled on security clearances.
He also said a meaningful share of China’s current progress comes from "distillation" — using responses from US models to train domestic systems — rather than obtaining the underlying models themselves.
Background on Coxon
The report said Coxon is 27 and British. He spent the past three years working on pre-training research at OpenAI and Anthropic.
On Sept. 8, he announced on X that he was leaving Anthropic. That post drew more than 170 million views. At the time, he wrote on social media that the people building AI genuinely believe it could kill everyone before the end of this decade.
Pushback and verifiable facts
Triolo, a partner at consulting firm DGA-Albright Stonebridge Group who studies China tech policy, responded on social media: 「Sorry, but this seems really irresponsible.」
The report also cited a MacroPolo talent-tracking study mentioned by the South China Morning Post. Using NeurIPS paper authors as its sample, the data showed that among top AI talent working at US institutions in 2022, 38% were of Chinese origin and 37% were of US origin. In 2019, those shares were 27% and 31%.
It also stressed that "origin" in that dataset is defined by the country of undergraduate education. That is not the same as nationality, and it does not indicate intelligence ties. The figures describe talent composition, not espionage.
The Google case and the legal threshold
The report pointed to one of the highest-profile AI trade-secret cases in recent years. Former Google engineer Ding Linwei was accused of uploading more than 500 confidential files. In January 2026, a jury found him guilty of trade secret theft and economic espionage.
But in August, Judge Vince Chhabria vacated all espionage counts, saying the evidence was insufficient to show an intent to benefit the Chinese government. On Sept. 1, Ding was sentenced to nearly one year in prison for trade secret theft.
The report drew a legal distinction here: taking confidential material is not the same as serving as a spy for a foreign government, and the evidentiary bar for the latter is much higher.
Similar warnings have surfaced before
The concern is not new. Anthropic co-founder Dario Amodei said at a Council on Foreign Relations event in March 2025 that algorithmic secrets worth $100 million could amount to just a few lines of code, adding, 「I’m sure people want to steal them, and they may already have.」

