Google reports that Chinese-linked hacker groups are now using AI agents to automate attacks against U.S. AI research and tech firms, accelerating intrusion timelines and raising serious national security concerns.
The latest findings from Google’s Threat Intelligence Group paint a stark picture: state-aligned hackers tied to China are shifting from manual hacks to automated AI agents that can run entire campaigns in hours. That change dramatically compresses the time defenders have to detect and respond, and it hands speed and scale to actors already motivated by economic and strategic gain. This is not theoretical; the technology is in use and the targets include academic, medical and military research in North America.
Google’s report shows the new playbook: AI agents handle wide swaths of intrusion work that used to require hands-on effort, which lets attackers move faster and cover more ground. In some cases campaigns that once took days or weeks can now be executed in less than six hours, shrinking windows for countermeasures and evidence gathering. For technology companies racing to commercialize AI, that means intellectual property and model training data are at greater risk than ever.
Hackers working for Chinese intelligence are increasingly targeting American AI research and using AI in their operations, Google said Tuesday.
In its latest quarterly report, Google’s Threat Intelligence Group said that several hacker groups, including both intelligence agencies and cybercrime gangs, have moved from basic AI prompting to using AI agents that automate wide swaths of their intrusion.
The switch means hackers spend drastically less time actively hacking, and in some cases can conduct an entire campaign in less than six hours, the report says.
Google said that one Chinese group in particular, which it has tracked since 2023, has relentlessly focused on academic, medical and military research organizations in North America and has specifically gone after proprietary AI research. Google did not name any of the victims.
While American intelligence agencies also have powerful cyberespionage capabilities, the U.S. has long accused China of hacking its companies for economic advantage, a tactic Western countries generally say is unacceptable.
Liu Chang, spokesperson for the Chinese Embassy in Washington, broadly denied the claims.
“China opposes hacking activities and fights such activities in accordance with the law. That said, we firmly reject vilification and smears under the pretext of cybersecurity,” he said.
Independent reporting and private sector analysis back up Google’s warning: a 2026 CrowdStrike study found China-aligned groups were behind more than 58 percent of state-sponsored cyberattacks on tech firms over a 12-month span, and researchers cautioned that these efforts aim to steal AI capabilities the adversary cannot build fast enough on its own. CrowdStrike spelled it out bluntly: “China-nexus adversaries are escalating espionage against technology organizations to steal the AI capabilities and intellectual property they cannot build fast enough on their own,” which ties directly to the economic objectives driving these intrusions. Those figures matter because they show a coordinated pattern tied to specific industrial priorities, not random theft.
China’s ability to deploy low-cost models and rapidly iterate on them creates a dangerous dynamic: if you can copy or exfiltrate key datasets and architectures, you shortcut years of domestic development. Reports show Chinese developers are catching up in many AI capabilities, often using cheaper compute and leaner models to match commercial features at a fraction of the price. That economic leverage turns cyberespionage into a practical tool for shifting the longer-term balance in AI leadership and the manufacturing and investment that follow it.
Sen. Ted Cruz (R-TX) captured the stakes plainly: “China is well aware that it matters enormously who wins. Whoever wins that race, the result is going to be trillions and trillions of dollars of investment and millions of jobs. And so we want those jobs in America. We don’t want those jobs in China. We want to have them here.” His point is strategic and economic at once, and it explains why Republicans are focused on both defending intellectual property and shaping industrial policy to keep AI investment and jobs onshore. The lawmaker further stated that if the Chinese regime wins this AI race, “AI will embrace the Chinese values of surveillance, of espionage, of propaganda, of social control, social scores, using AI to try to control your life.”
https://x.com/innovationcncl/status/2097394845039907214
For policymakers and industry leaders the math is straightforward: faster, automated intrusions plus the high value of AI research equals urgent risk management priorities, and the recommendations will look like hardened security, focused counterintelligence and clearer export controls. Those steps are necessary because the adversary’s playbook is evolving with the technology; defensive posture that worked against human-only adversaries will not suffice against autonomous agents that can pivot at machine speed. A practical response requires aligning defense with industrial strategy to keep research, jobs and capital in friendly hands while denying the fruits of American innovation to hostile states.
This shift to AI-driven intrusion also rewrites how we think about attribution, response and deterrence, because attacks that are faster and automated complicate forensic trails and shorten reaction times. As the technology spreads, defenders must adapt detection, threat hunting and legal authorities to contend with campaigns that are more automated, more scalable and deeply tied to strategic state interests. The central reality is that AI is changing the dynamics of cyber conflict, and policy choices made now will determine whether those dynamics favor American freedom and prosperity or strategic rivals that do not share our values.




