From Chatbots to Chips, China Tech Security Fears Broaden

Security concerns about Chinese-linked technology are widening well beyond the debate over Chinese artificial intelligence models, increasingly pulling in coding tools, autonomous-vehicle sensors and even the memory chips that power consumer electronics.

The latest signs came this week from both Washington and Beijing, underscoring how suspicion now runs in both directions and across nearly every layer of the technology stack.

On Tuesday, a cybersecurity platform affiliated with China’s industry ministry warned that certain versions of Anthropic’s Claude Code, a software tool used to help developers write and modify code, carried what it described as a serious “backdoor” risk. The warning said the affected versions could transmit sensitive information to a remote server, a charge that, if substantiated, would add a new front to the global contest over who can be trusted to build the software increasingly embedded in business operations.

At nearly the same time in the United States, House Republicans pressed ahead with an investigation into the use of Chinese AI models by American companies, sending letters to firms including Airbnb and Anysphere as lawmakers examine whether corporate adoption of China-developed systems could expose data or create cybersecurity vulnerabilities. The inquiry is part of a broader Washington campaign to limit what officials see as growing risks from Chinese AI, including concerns that Chinese developers could gain access to valuable data or accelerate their own capabilities through links to American users and companies.

The focus on software was matched by fresh attention to hardware. The Financial Times reported that Apple has begun testing memory chips made by ChangXin Memory Technologies, or CXMT, for devices sold in China, a sign that even one of the world’s most closely watched American companies may still be exploring Chinese component suppliers for its domestic-China supply chain. And Hesai, the Chinese lidar maker whose products are used in autonomous-driving and robotics systems and whose technology has ties to Nvidia’s ecosystem, faced renewed accusations in the United States that its equipment presents a cyber risk.

Taken together, the developments suggest that the political and regulatory argument is evolving. The question is no longer only whether a Chinese chatbot or large language model is safe to use. It is whether any China-linked technology — from coding assistants and enterprise AI to sensors and semiconductors — could become a security vulnerability.

A Wider Net

That shift reflects a broader policy trend already underway in Washington. Lawmakers and officials have spent months warning that Chinese AI companies could benefit from American data, exploit U.S. innovation or expose sensitive corporate and infrastructure systems to outside access. More recently, those concerns have broadened to include the less visible components that sit beneath AI applications: the chips that store data, the sensors that help machines see the world and the tools programmers use to build software.

The House inquiry into Chinese AI use by U.S. companies grew out of that push. Lawmakers have said they are examining cybersecurity, data security and the possibility that systems developed in the People’s Republic of China could find footholds inside critical sectors of the American economy.

The China warning about Claude Code adds a striking twist. For years, U.S. officials have cast Chinese technology as a potential vector for hidden access or state influence. Now Chinese authorities are leveling a parallel accusation at an American AI tool, warning domestic users that foreign-made software could siphon off sensitive information. It remains unclear whether the warning will lead to broader official restrictions inside China or whether Anthropic will publicly identify the versions in question and detail any remediation.

Hardware Under the Microscope

The hardware cases show how scrutiny is moving deeper into supply chains.

Apple’s reported testing of CXMT memory chips does not mean the company has committed to putting them into commercial products. But the fact that the tests are underway is notable given the political sensitivity around Chinese semiconductor suppliers. For years, Apple has tried to balance geopolitical pressure from Washington with the practical realities of manufacturing and selling devices in China, one of its biggest markets and most important production bases. Testing chips from a Chinese memory maker for China-sold devices would fit that balancing act, even as it risks inviting questions in Washington.

Those questions are sharpened by the company involved. CXMT has already appeared on Pentagon lists intended to identify Chinese military-linked companies. A June 2026 Defense Department document said CXMT is directly affiliated with China’s Ministry of Industry and Information Technology and indirectly linked to state entities including SASAC and MIIT. Such designations do not automatically prohibit all commercial dealings, but they have become a powerful signal for investors, suppliers and policymakers assessing exposure to Chinese firms.

Hesai’s case follows a similar logic. The company was designated in 2024 by the Defense Department as a Chinese military entity, and a June 2026 Pentagon document described affiliations with MIIT, SASAC and the People’s Liberation Army. Hesai has denied posing a national security threat, but the renewed accusations against it reflect a growing view in Washington that products like lidar sensors should be treated not just as industrial components, but as possible entry points into sensitive systems.

That matters because lidar, a sensing technology used in autonomous vehicles and robotics, helps machines map their surroundings with extreme precision. As these systems move into logistics networks, industrial sites and transportation infrastructure, the security debate around them increasingly resembles earlier arguments over telecom equipment and surveillance cameras: whether hardware that appears mundane could carry outsized strategic risk.

Why This Matters Now

The latest flurry of warnings and investigations comes at a moment when AI is becoming inseparable from the broader electronics and software ecosystem around it. A model is only one part of an AI system; just as important are the coding tools used to build applications, the cloud and enterprise environments where they run, and the chips and sensors underneath them.

That is why the current scrutiny is so consequential. It points toward a future in which governments do not assess risk product by product, but stack by stack. A company may avoid a Chinese foundation model yet still rely on Chinese-made memory chips, machine-vision sensors or software components. Or it may shun Chinese hardware while allowing employees to use Chinese AI services. In the emerging policy climate, each layer is coming under examination.

For multinational companies, that raises the prospect of a much more complicated compliance landscape. What is acceptable in one market may trigger suspicion in another. American firms operating in China may face pressure to localize components and data practices, while also confronting U.S. political backlash if those local supply chains rely on Chinese firms viewed as state-linked. Chinese regulators, for their part, appear increasingly willing to frame foreign software tools as security threats of their own.

For now, many of the immediate consequences remain uncertain. The House investigation has not yet produced enforcement action. Apple’s chip testing may never become deployment. And the latest focus on Hesai has not been accompanied this week by a new formal U.S. ban or sanction.

But the direction is becoming clearer: the security contest between the United States and China is moving beyond headline AI models and into the plumbing of modern technology itself.

Sources

Further reading and reporting used to add context: