Former Anthropic and OpenAI researcher Jacob Coxon has claimed that Chinese spies may already be inside the two leading US artificial intelligence companies. Speaking on entrepreneur Patrick Bet-David’s podcast, Coxon said he was about 90% certain that Chinese intelligence operatives had infiltrated OpenAI and Anthropic, although he did not provide evidence or identify any individuals.

Coxon’s allegation comes as competition between the United States and China over advanced AI becomes increasingly linked to national security and technological leadership. His comments also arrive amid separate concerns about attempts by Chinese AI companies to extract capabilities from leading US models through techniques such as model distillation. However, the specific claim that spies are currently inside OpenAI and Anthropic remains unsubstantiated. A source familiar with Anthropic told Business Insider that there is no evidence supporting Coxon’s allegation.

Former Researcher Makes Espionage Claim

Coxon made the claim during an interview with Patrick Bet-David that was released this week.

The former researcher said he believes Chinese spies have already gained positions inside both OpenAI and Anthropic. When asked how confident he was, Coxon reportedly put his certainty at around 90%.

He argued that such infiltration could allow China to obtain technological advances developed by US AI laboratories and reduce or eliminate America’s lead in advanced AI.

However, Coxon did not identify any alleged spies, provide evidence of specific infiltrations or describe a confirmed espionage operation involving either company.

That distinction is important because the claim is an allegation from a former employee rather than a publicly established finding.

What Coxon Is Warning About

Coxon’s argument can be summarised around three potential risks:

ConcernPotential impact
Insider accessSensitive AI research could potentially be exposed
CyberattacksExternal attackers could target AI infrastructure
Model theftCompetitors could potentially obtain valuable AI capabilities
Loss of technological leadAdvances by US companies could be replicated more quickly
Weak personnel screeningForeign intelligence risks could become harder to detect

Coxon argued that AI companies should adopt stronger background checks and security procedures for employees working on highly sensitive systems.

Why AI Labs Are a Security Target

The world’s leading AI companies are developing technology that has significant commercial and strategic value.

Modern frontier AI systems require enormous investments in computing infrastructure, training data, research talent and engineering. The resulting models can potentially be used across software development, scientific research, cybersecurity, military applications and business operations.

That makes the underlying technology valuable not only to companies but also to governments seeking technological advantages.

The theft of model weights, proprietary research or other sensitive information could potentially allow competitors to reduce the time and resources needed to develop comparable systems.

Model Weights Are Particularly Sensitive

AI model weights are the numerical parameters that determine how a trained model behaves.

Obtaining the weights of a highly capable model can potentially provide a shortcut compared with developing an equivalent system from scratch.

This is one reason US policymakers have become increasingly concerned about the security of AI laboratories.

In October, US Congressman Ro Khanna asked OpenAI, Anthropic, Google, Meta and SpaceX AI to provide information about attempts by China or other foreign adversaries to gain unauthorised access to sensitive model weights. Reuters reported that there are limited publicly known cases of actual model-weight theft, even though US AI companies have reported other forms of attempted model extraction.

Chinese AI Firms Have Been Accused of Model Distillation

Coxon’s comments also come against the backdrop of documented disputes between US and Chinese AI companies over model distillation.

Distillation involves using the outputs or behaviour of a more capable model to help train another model.

It can be a legitimate machine-learning technique, but AI companies have raised concerns when it is allegedly used to replicate capabilities without permission.

Anthropic said in September that Chinese companies including DeepSeek, Moonshot AI and Zhipu had conducted large-scale attempts to extract capabilities from Claude through what the company described as distillation attacks.

The company said the campaigns involved millions of interactions with its models.

These incidents are different from Coxon’s claim about human spies. They involve attempts to obtain AI capabilities through interactions with models rather than confirmed insiders stealing confidential information.

Anthropic Says It Takes Foreign Threats Seriously

The allegation has not been publicly confirmed by Anthropic.

Business Insider reported that a source familiar with the company said there was no evidence supporting Coxon’s claim. The source also said Anthropic treats foreign intelligence threats as a serious risk and maintains personnel vetting, access controls and insider-risk monitoring.

This response highlights an important distinction between the existence of a security threat and evidence that a particular organisation has already been infiltrated.

Major AI laboratories can reasonably be expected to face attempts at espionage, hacking and intellectual-property theft because of the value of their technology. That does not establish that specific foreign intelligence agents have successfully gained employment or access inside those companies.

OpenAI and Anthropic Face Growing Security Pressure

The latest allegations arrive during a period of increasing scrutiny over AI security.

In recent months, AI companies have faced concerns ranging from model theft and cyberattacks to the misuse of AI systems by state-linked actors.

Anthropic’s September threat-intelligence report said its Claude models had been targeted in campaigns involving Chinese AI companies, as well as other actors linked to cyber espionage and biological-weapons research.

The company said it disrupted several attempts to misuse its systems.

These incidents demonstrate that AI security is becoming a broader problem involving both traditional cybersecurity and new techniques specifically designed to exploit AI systems.

The Threat Is Not Limited to Insider Espionage

AI companies face several potential attack surfaces.

They include:

  • Employee accounts and credentials.
  • Cloud infrastructure.
  • Model-training systems.
  • Proprietary source code.
  • Model weights.
  • Research documents.
  • Internal communications.
  • AI APIs and model outputs.
  • Supply-chain vulnerabilities.

As AI systems become more capable, the value of each of these assets is likely to increase.

Coxon’s Broader Concerns About AI Development

Coxon became publicly prominent after leaving Anthropic in September.

At the time, he criticised the rapid development of advanced AI and argued that leading companies were moving toward increasingly capable systems without sufficient safeguards.

He later testified before the New York City Council alongside other former AI researchers, warning that current AI safety measures could fail as systems become more sophisticated.

His latest comments shift the focus from AI safety to national security.

Coxon argues that even if US companies deliberately slow the development of frontier AI, China could still obtain technological advances through espionage or cyber operations.

The National Security Dimension

The allegations also reflect how the AI race has increasingly become connected to national-security policy.

Advanced AI can potentially contribute to military planning, intelligence analysis, cyber operations, scientific research and autonomous systems.

As a result, governments are increasingly treating frontier AI models and the infrastructure used to develop them as strategically important technology.

The possibility of intellectual-property theft therefore extends beyond the financial interests of individual companies.

If sensitive AI technology were obtained by a foreign government, policymakers could view the consequences through the broader lens of technological competition and national security.

Why the Claim Needs Caution

The most important caveat surrounding Coxon’s statement is the absence of publicly presented evidence.

Coxon has worked at both OpenAI and Anthropic, giving him experience with the operations of major AI laboratories. However, his previous employment does not by itself establish that his current allegation is accurate.

Neither the identity of any alleged spy nor a documented infiltration has been provided publicly.

Anthropic has also indicated that it has security measures designed to address foreign-intelligence and insider risks.

Therefore, the claim should currently be understood as an allegation rather than a confirmed security finding.

The Bigger Picture

Coxon’s warning highlights a genuine strategic concern even though his specific claim remains unverified: frontier AI companies possess technology that governments and competitors have strong incentives to obtain.

The AI industry’s security challenge is therefore expanding beyond conventional hacking. Companies must protect research, model weights, computing infrastructure and employees while also preventing legitimate access from being exploited by insiders.

At the same time, stronger security measures must be balanced against the need for international research collaboration and access to global technical talent. The debate over how AI laboratories should vet employees, restrict sensitive access and protect intellectual property is likely to intensify as AI capabilities become more strategically important.

Looking Ahead

OpenAI and Anthropic are likely to face continued pressure from policymakers and security experts to demonstrate how they protect sensitive AI research from foreign intelligence operations. The specific allegation made by Coxon will require independent evidence before it can be treated as an established fact.

The broader issue, however, is unlikely to disappear. As the United States and China compete to develop increasingly capable AI systems, protecting model weights, research and computing infrastructure could become as important as developing the technology itself. For AI companies, cybersecurity and insider-risk management are increasingly becoming core parts of maintaining a technological advantage.

Get the day’s top stories in your inbox

One concise email. No spam, unsubscribe anytime.