Safety

Leaked data suggests Chinese firm explored AI to predict future political dissenters

Leaked internal files indicate that Geedge Networks, in collaboration with a state-linked research lab, worked on AI models to profile Chinese citizens and identify potential future political opponents.

Leaked data suggests Chinese firm explored AI to predict future political dissenters

Leaked internal data indicates that a Chinese company working with a state-linked research lab developed AI-based methods intended to identify individuals who might become political opponents in the future.

What was revealed?

Researchers at Vanderbilt University found the plans inside a more-than-500-gigabyte dataset released during one of the largest internal leaks tied to China’s internet censorship apparatus, the Great Firewall. The files originated from the MESA laboratory of the Chinese Academy of Sciences Institute of Information Engineering and from Geedge Networks, a commercial company connected to censorship technology.

What did the project aim to do?

According to the leaked minutes and materials, Geedge’s research team in early 2024 worked on creating behavior-based profiles of individuals using location data, telecommunications records, and social media information. They planned to classify those profiles with AI models to detect what the Chinese Communist Party’s terminology calls “harmful information” or people who might pose political risks in the future.

The documents show that the developers attempted to infer potential dissent from seemingly mundane signals such as which movies a person watches or what books they read.

Who was involved?

Geedge Networks, founded in 2018, has investors including Fang Pin-hsing, who is associated with early infrastructure for the Great Firewall. Geedge sells a commercial version of Great Firewall–style tools and has deployed internet-monitoring and censorship-capable systems in multiple countries, including Pakistan, Myanmar, Kazakhstan, and Ethiopia.

Technical and political constraints

The New York Times reports that there is no evidence the system was completed or operational, and that the company faced substantial technical limits. U.S. export controls put in place during Joe Biden’s administration have made it difficult to acquire the most advanced AI chips, and leaked materials indicate that in 2024 Geedge could not obtain the chips needed to run the predictive models efficiently.

U.S. officials told the Times the company currently only has access to chips sufficient for existing products, but not the advanced processors required for high-performance predictive technology. Limited chip capacity complicates attempts to use tapped phone conversations and surveillance camera footage to identify future ‘‘thought crimes.’’ Researchers also note that Chinese security firms often suffer from data overload — they have ‘‘too much information’’ rather than the processing power to turn it into reliable predictions.

Context in expert debate

Western experts such as Daniel Sprick of the University of Cologne have long warned that predictive policing in China is likely to be used for political repression as much as for crime prevention. A 2009 encrypted government document—cited by the Associated Press—explicitly described the goal of predictive policing as ‘‘strengthening the power of the Communist Party.’’

Potential impacts

The leaked files raise ethical and legal concerns about combining massive personal datasets with automated forecasting: predictions could lead to pre-emptive action against people who have not committed crimes. At the same time, the company’s difficulties—especially the chip shortage—show that practical deployment is not guaranteed.

What happens next?

How long those constraints remain is uncertain: China is pushing to develop its own chip industry, and geopolitical policies can change. The leaks underline the risk that linking surveillance with AI can create powerful tools that threaten political freedoms when used for state control.

Timeline — key dates and events

  • 2009: A classified Chinese government document (reported by the AP) describes the goal of predictive policing as strengthening the Communist Party’s power.
  • 2017: The Financial Times reported attempts to use face-recognition camera systems to anticipate possible offenders.
  • 2018: Geedge Networks was founded.
  • 2019: Chinese officials told the BBC that authorities aimed to ‘‘catch people on the verge of committing crimes.’’
  • Early 2024: Geedge and the MESA lab materials surfaced in the large censorship-related data leak; the research team worked on behavior-based profiles and AI classifiers.
  • 2024: Geedge experienced difficulties obtaining advanced chips due to U.S. export restrictions.
  • (Last December): Donald Trump authorized a limited sale of an advanced Nvidia chip to China; reports say Beijing did not allow Chinese firms to purchase it.

Note

The disclosed documents and expert commentary together highlight that where mass surveillance, large datasets and automated decision-making intersect, political rights can be particularly vulnerable if such systems are used for state-directed repression.