Safety

AI-generated text

Why private companies are stepping in to secure AI and messaging apps

A recently disclosed worm that hijacked WeChat accounts and propagated through contacts without user interaction highlights limits of state-led approaches to AI and cyber safety.

Why private companies are stepping in to secure AI and messaging apps

US security firm Calif recently disclosed an attack tool — a worm — that could take over WeChat accounts and propagate through victims’ contacts without any user needing to click on a link or attachment. The vulnerability was fixed, but only after Calif notified WeChat’s operator, the Chinese tech giant Tencent.

The episode underscores how cyber vulnerabilities do not respect national borders: a single flaw can have rapid international impact and often requires private actors to lead the response. The incident is particularly consequential given WeChat’s roughly 1.4 billion users.

Why government action alone is insufficient

Observers point to earlier AI-related incidents, such as the AI-enabled hack of Hugging Face and subsequent analyses that used a Chinese open-source model to investigate, as examples showing how technical threats spread faster than traditional government responses can manage. While both AI superpowers, China and the United States, have incentives to address cyber risks, mutual trust between the two countries remains very limited.

That mistrust is visible in concrete policies and rhetoric: the Pentagon has ruled out engagement with Tencent citing alleged ties to the Chinese military, China is working to shape AI discourse according to its own perspectives, and the US government has warned of what it describes as Chinese AI firms’ “malicious” distillation campaigns.

A technical, private-sector-led approach

US–China tech expert Samm Sacks noted that cyber vulnerabilities don’t map neatly onto state borders. A technical approach to AI safety — led by private companies, researchers, and technologists rather than ideological positions — could provide a firmer basis for any eventual bilateral agreement. In the absence of comprehensive state-level cooperation, the private sector is increasingly compelled to rely on informal cross-border communication and collaboration to prevent the next lab-developed worm from spreading widely.

Notable development

A coalition of left- and right-leaning organizations recently sent a letter to President Donald Trump urging the White House to release its voluntary AI security framework, a development reported by Ashley Gold of Semafor.