关于人工智能安全,中国真正在乎的是什么

Wait 5 sec.

高安西2026年9月24日If there is one person who represents the frontier of Chinese artificial intelligence, it is Tang Jie.如果要说谁代表了中国人工智能的前沿,那就是唐杰。The soft-spoken data engineer is the co-founder, chief scientist and largest individual shareholder of China’s leading artificial intelligence lab, Z.ai, whose models have risen to the top tier of China’s performance tables and made Mr. Tang the flag-bearer for the Chinese A.I. ecosystem.这位文质彬彬的数据工程师是中国顶尖人工智能实验室智谱AI(Z.ai)的联合创始人、首席科学家兼最大个人股东。智谱AI旗下模型的性能已跃升至中国第一梯队,也让唐杰成为了中国人工智能生态系统的领军人物。In some ways, Mr. Tang’s messaging about A.I. seems to mirror that of Dario Amodei, the co-founder and chief executive of Anthropic — the American company behind Claude — and one of the most prominent voices extolling A.I.’s promise while warning of its risks. Mr. Tang pairs an almost utopian excitement with what he has called the “heaviest responsibility” of “extreme safety governance.”在某种程度上,唐杰关于人工智能的表态似乎与达里奥·阿莫迪遥相呼应。阿莫迪是Claude背后的美国公司Anthropic的联合创始人兼首席执行官,也是行业内既赞美人工智能前景又警告其风险的代表性人物。唐杰将一种近乎乌托邦式的热情与他所称的“极致安全治理”这一“最重的责任”结合在了一起。“Once a technology reaches a magnitude of power sufficient to alter the course of civilization, safety is no longer an accessory, but the fundamental precondition for that technology to survive and to be permitted for use,” Mr. Tang said in a letter to staff that was leaked to the Chinese media in July.“当一项技术抵达足以改变文明进程的力量量级时,安全就不再是附属品,而是技术得以存续与被允许应用的根本前提,”唐杰在7月曝光的一封致员工的信中这样写道。Those words may sound strikingly similar to warnings now coming from leading American A.I. labs. But they are better understood through the language of President Xi Jinping of China, for whom A.I. “safety” is ultimately bound to one overriding concern: the security of the Chinese Communist Party regime.这些话听起来或许与美国顶尖人工智能实验室发出的预警惊人地相似。但若结合中国国家主席习近平的语境来理解,其含义会更加清晰——对习近平而言,人工智能“安全”归根结底指向一个核心关切:中国共产党政权的安全。While the debate in Western capitals has centered on the dangers A.I. poses to society, the animating concern in China is the threat it poses to the state. Chinese models are already well known for filtering or avoiding politically sensitive information in ways that reflect state censorship. But developers like Mr. Tang are going further, working to embed Communist Party orthodoxy deeply into the models, with potentially far-reaching implications for the values and vulnerabilities that Chinese A.I. systems bring with them.西方多国政府将辩论焦点放在人工智能对社会构成的危险上,中国最关切的则是其对国家政权构成的威胁。中国模型因过滤或规避政治敏感信息以契合国家审查制度而广为人知。但像唐杰这样的开发者正走得更远,他们致力于将执政党意识形态深刻植入模型底层,这对中国人工智能系统所携带的价值观及其潜在脆弱性具有深远影响。Recognizing these diverging views on the technology that will shape the next century is crucial in setting expectations for the talks on Thursday between President Trump and Mr. Xi at the White House. The leaders are set to discuss how to mitigate A.I. risks. Arriving at meaningful cooperation will be difficult — if not impossible — because there are two almost entirely unrelated conversations about what A.I. safety means happening on opposite sides of the Pacific.认清对这项将塑造下个世纪的关键技术的理念分歧对于设定特朗普与习近平周四在白宫会谈的预期至关重要。两国领导人准备讨论如何规避人工智能风险。然而,要达成实质性合作将极其困难,甚至难以实现,因为太平洋两岸对于“人工智能安全”的理解完全是两套互不相干的语境。The wider stakes are potentially enormous. Mr. Tang and his colleagues are instilling values into their models that shape how they interpret the world and respond. As Chinese A.I. is increasingly being adopted globally, those values could travel with it, quietly carrying the Communist Party’s worldview far beyond Chinese shores.这背后的影响可能是巨大的。唐杰和他的同事正向模型注入特定价值观,从而塑造模型理解世界与做出回应的方式。随着中国人工智能系统在全球范围内得到越来越广泛的应用,这些价值观也可能随之传播,悄然将执政党的世界观带到远超中国本土的地方。Six days after Mr. Tang’s letter to Z.ai’s staff, Mr. Xi provided a glimpse into his thinking when he convened the annual World Artificial Intelligence Conference in Shanghai on July 17. In comments translated into English by state-run media, Mr. Xi was quoted as saying that “China lays great emphasis on safety and security in A.I.” and is committed to keeping it “safe, secure and controllable.” It seemed a reassuring signal ahead of the scheduled talks with Mr. Trump.在唐杰发表致智谱员工信六天后,习近平于7月17日在上海出席年度世界人工智能大会时,展现了他的思考方向。在由官方媒体翻译成英文的表述中,习近平表示“China lays great emphasis on safety and security in A.I.”(中国高度重视人工智能的安全和保障),并致力于确保其“safe, secure and controllable”(安全、稳固和可控)。在与特朗普预定的会谈前夕,这似乎释放出了一个令人放心的信号。But Chinese state media often translates comments by the country’s leaders in ways that soften their political meaning for foreign audiences. What Mr. Xi actually said in Chinese was that China’s emphasis was on “development and security,” and on making sure “A.I. is secure, reliable and controllable.”然而,中国官方媒体在翻译领导人讲话时,往往会面向外国受众软化其政治含义。习近平中文讲话的原话是:中国坚持“发展和安全”并重,确保“人工智能安全、可靠、可控”。That may seem like a fine distinction in translation. But in Mr. Xi’s vocabulary, words like “security” and “control” ultimately refer to the political security of the Communist Party. Time and again, Mr. Xi has made clear that ensuring China’s Communist system endures in a rapidly changing world is at the heart of his agenda.这在翻译上或许看似只是微小的差别。但在习近平的语汇体系中,“安全”与“控制”等词汇归根结底指的是执政党的政治安全。他多次明确强调,确保中国的社会主义制度在快速变化的世界中稳固长久是他施政的核心议题。Today’s Silicon Valley pioneers grew up in a liberal democracy, consuming science fiction in which man builds machines that promise utopia but might ultimately destroy him. Mr. Amodei’s essay in January on A.I. risks, “The Adolescence of Technology,” opens with a scene from one of his favorite films, “Contact.” The protagonist, played by Jodie Foster, is asked what she will say to the advanced life form that has established radio contact from outer space.如今的硅谷先行者成长于自由民主社会,从小接触的科幻作品多描绘人类怀着建设乌托邦的本意,却创造了可能最终毁灭人类的机器。在今年1月发表的关于人工智能风险的文章《技术的青春期》中,阿莫迪开篇引用了他最喜欢的电影之一《超时空接触》(Contact)的场景:由朱迪·福斯特饰演的女主角被问及,她想对来自外太空并建立起无线电联系的高级智慧生命说些什么。She replies: “How did you do it? How did you evolve? How did you survive this technological adolescence without destroying yourself?”她回答道:“你们是怎么做到的?你们是如何演化的?你们是如何度过这个技术青春期而没有毁灭自己的?”The essay details how to manage the potentially catastrophic risks inherent in the technology that Mr. Amodei is helping build, including by baking safety principles into A.I. so they are inseparable from the model itself. Known as constitutional A.I., this method attempts to teach the technology what it means to be “a good A.I.” at the level of character, values and personality — “like a child forming their identity,” Mr. Amodei wrote.该文详细阐述了如何管理阿莫迪参与构建的技术所固有的灾难性风险,其中包括将安全原则融入人工智能,使其与模型本身密不可分。这种被称为“宪制人工智能”(constitutional A.I.)的方法,试图在性格、价值观和品格层面教授这项技术何为“合格的人工智能”——“就像一个正在形成自身认同的孩子,”阿莫迪写道。The values that Anthropic instills in its models borrow from the Universal Declaration of Human Rights and are weighted heavily toward access to information, rule of law, political freedom, self-determination and individual liberty.Anthropic注入其模型中的价值观借鉴了《世界人权宣言》,高度侧重于信息获取、法治、政治自由、自决权和个人自由。Similarly, Demis Hassabis, the co-founder and chairman of Google DeepMind, has developed a set of A.I. principles explicitly anchored in liberal democratic values and argues that democracies should lead in A.I. development, “guided by core values like freedom, equality, and respect for human rights.”无独有偶,Google DeepMind联合创始人兼主席德米斯·哈萨比斯也制定了一套明确锚定于自由民主价值观的人工智能原则,并主张民主国家应当在“自由、平等和尊重人权等核心价值观的指引下”引领人工智能的发展。China’s new generation of tech leaders has been brought up in an altogether different environment, an authoritarian world where liberal values are labeled hostile to China and technology is developed and controlled for the benefit of the Communist Party.中国的新一代科技领袖则成长于截然不同的环境——在一个威权体系中,自由主义价值观被标记为对华敌对,技术的开发与管控完全服务于执政党的利益。Mr. Xi’s minister for state security, Chen Yixin, made that clear in an essay published this month on the dangers of A.I. Mr. Chen made no mention of the existential threat of artificial intelligence turning against its masters, the fear that preoccupies leading American A.I. figures. Instead, he said China needed to raise its defenses against hostile human forces that would use this powerful new tool for a “direct assault on our political security, institutional security, and ideological security.”习近平任命的国家安全部部长陈一新在本月发表的一篇关于人工智能风险的文章中清晰阐明了这一点。陈一新完全没有提及困扰美国人工智能领军人物的生存威胁,即人工智能失控反噬人类的恐惧。相反,他强调中国必须加强防御敌对势力,防止其利用这一强大工具“直接威胁我政治安全、制度安全、意识形态安全”。A.I. safety, in Mr. Chen’s telling, lies in aggressively pushing forward the development of Chinese artificial intelligence so that it does not fall behind the United States, a prospect that he implied posed the technology’s biggest danger for China. The country’s evolving A.I. regulatory system also places threats to socialist values, state power and political stability among the government’s core safety concerns.在陈一新的论述中,人工智能的安全在于大力推进中国人工智能的发展,以防落后于美国,他暗示这种落后才是该技术对中国构成的最大危险。中国不断完善的人工智能监管体系也将对社会主义价值观、国家权力和政治稳定的威胁列为政府的核心安全关切。Very little personal information is known about Mr. Tang, who rarely speaks publicly. He formed Z.ai by joining together with other members of the Knowledge Engineering Group, a research unit at Beijing’s prestigious Tsinghua University. The group developed sophisticated tools for analyzing social networks and information flows, including systems for profiling and locating researchers in China and other countries and mapping their relationships, which were presented as recruiting tools.外界对极少公开发言的唐杰个人信息知之甚少。他联合北京名校清华大学的知识工程实验室其他成员共同创立了智谱AI。该团队曾开发出用于分析社交网络和信息流的先进工具,包括用于对国内外研究人员进行画像、定位及绘制关系图谱的系统,它们被定位为人才招聘工具。In Mr. Tang’s July letter, he rejected the idea of “bolt-on” safety patches for A.I., saying instead that behavioral principles must be embedded in the foundations of the company’s models, including writing Chinese national laws, strategy and security concerns — in other words, the Communist Party’s political interests — into the A.I.’s basic DNA. In August, Mr. Tang went a step further, publishing a commentary that argued in favor of laws to impose ideological conformity on the Chinese artificial intelligence industry.唐杰在7月的一封信中,拒绝了对人工智能采取“外挂式”安全补丁的做法,而是主张必须将行为准则植入公司模型的底层架构中,包括将国家法律、战略与安全关切——换言之,即执政党的政治利益——写入人工智能的基础基因。8月,唐杰更进一步,发表了一篇评论文章,主张通过立法对中国人工智能产业强制实施意识形态的一致性。Last month, his company released one of China’s most powerful A.I. models, GLM-5.3 — which Z.ai markets as a cheap, accessible and capable open-weight cyberdefense tool approaching the abilities of Mythos 5, Anthropic’s powerful cybersecurity model. Users can download and modify open-weight models, fine-tuning them for specific tasks, though deeply embedded behaviors may be difficult to strip out. Z.ai argues that advanced tools like these should be made widely available to developers and cybersecurity teams around the world, an approach that contrasts with the more closely guarded proprietary models of Anthropic and OpenAI.上个月,他的公司发布了中国最强大的AI模型之一GLM-5.3。智谱AI将其定位为一款廉价、易获取且功能强大的开源权重网络防御工具,其性能已接近Anthropic强大的网络安全模型Mythos 5。用户可以下载并修改开源权重模型,针对特定任务进行微调,尽管其中深度嵌入的行为可能难以彻底清除。智谱AI主张将这类先进工具向全球开发者和网络安全团队开放,这一路线与Anthropic和OpenAI严格保密的闭源专有模型形成了鲜明对比。Despite Mr. Tang’s rhetoric of openness, Z.ai has otherwise offered little transparency into how its models are trained and evaluated. And Chinese citizens, business and other entities are subject to a National Intelligence Law that obliges them to support state intelligence work when called upon. Z.ai’s financial reports state that vulnerabilities uncovered by its models are submitted to Chinese authorities, including the National Vulnerability Database, which collects and analyzes information on cybersecurity flaws. The database is managed by Mr. Chen’s Ministry of State Security.尽管唐杰高调宣传开放,智谱AI在模型训练和评估方式方面却几乎没有透明度。此外,中国公民、企业及其他实体均须遵守《国家情报法》,该法规定他们有义务在接到要求时配合国家情报工作。智谱AI的财务报告显示,其模型发现的安全漏洞会提交给中国当局,包括收集和分析网络安全缺陷信息的国家安全漏洞数据库。而该数据库正是由陈一新主管的国家安全部负责管理。This raises a troubling question, especially as use of Chinese open-weight models spreads overseas: When Z.ai finds a dangerous flaw, who learns about it first — the company that needs to fix it, or the Chinese state?这引发了一个令人不安的疑问,尤其是在中国开放式模型在海外广泛应用的背景下:如果智谱AI发现一个危险的安全漏洞,究竟谁会首先获知——是需要修复该漏洞的公司,还是中国政府?Researchers at leading American A.I. labs and government agencies in Washington and allied capitals are already voicing growing concern over the potential threat from “sleeper agents” — malicious hidden instructions that can be planted in A.I. models and remain dormant until triggered, making them difficult to detect or remove. Those dangers are amplified by newer “agentic” A.I., which is often given greater and more autonomous access to computer systems.美国顶尖人工智能实验室的研究人员,以及美国与盟友国家的政府机构,已经对“潜伏特工”(sleeper agents)带来的潜在威胁表达日益强烈的担忧。这类恶意隐藏指令可以预先植入人工智能模型中,保持潜伏状态,直至被特定条件触发,极难被检测或清除。而随着具有更高自主权限、可直接访问计算机系统的“智能体式”人工智能的发展,这种危险被进一步放大。All of these things underscore the pressing need for the United States and China to find common ground on A.I. — and, at the same time, why that will prove exceedingly difficult.所有这一切都凸显出美中两国在人工智能领域寻求共识的紧迫性——但同时也说明了为什么达成共识将极其困难。The Communist Party’s obsession with gaining an advantage over the United States and prioritizing regime security leaves little room for agreement on the catastrophic risks of A.I. Mr. Trump, too, seems to feel strategic competition outweighs the danger of unchecked A.I. development, recently dismissing the need for regulation in public comments and on social media.中共执着于在与美国的竞争中取得优势,并将政权安全置于首位,这令双方几乎没有就人工智能的灾难性风险达成共识的空间。而特朗普似乎也认为,战略竞争的重要性超过了不受约束的人工智能发展所带来的危险,他最近在公开讲话中和社交媒体上均对监管的必要性持否定态度。Trump’s free-market attitude misses the larger contest taking shape. The race over A.I. is no longer only about technological superiority. It is also a contest over whose concepts of freedom, security and the role of the state become embedded in the powerful systems that are increasingly shaping how societies think, make decisions and wield power.特朗普这种自由市场的态度忽视了正在形成的更大博弈。围绕人工智能的竞赛已不仅仅关乎技术领先地位,更是双方关于自由、安全以及国家角色等理念的角逐。胜出的理念将被融入日益深刻地塑造社会思维方式、决策过程和权力运作方式的强大系统之中。图片来源:Alex Wong/Getty Images高安西(John Garnaut)是地缘政治风险咨询公司Garnaut Global的创始人。他曾任《悉尼先驱晨报》驻华记者及澳大利亚前总理麦肯·腾博的高级顾问,著有《薄氏家族的陨落》(The Fall of the House of Bo)。翻译:纽约时报中文网点击查看本文英文版。获取更多RSS:https://feedx.net https://feedx.site