Would America Bomb China to Stop AGI? Inside the Think-Tank Scenario That Could Turn the AI Race Into War
A CNAS report urges Washington to examine espionage, cyber operations and, at the most dangerous extreme, kinetic action if China nears AGI first. It is an analyst's scenario—not adopted U.S. policy.
A Washington think-tank report has placed an extraordinary possibility into the public debate: if China appeared close to achieving artificial general intelligence first, the United States should already have studied options ranging from stealing the technology to cyber operations and, at the most dangerous extreme, physical attacks.
The proposal is real. The viral translation—“the United States has decided to bomb Chinese AI centers”—is not.
Jacob Stokes, a former National Security Council official and now a senior fellow at the Center for a New American Security, wrote the August 27 report “Superpowers and AGI.” CNAS is influential and many former officials work there, but it does not make U.S. policy. Its paper asks officials to rehearse hypothetical crises before technical competition produces one.
AGI usually means a system capable of performing a broad range of intellectual tasks at or above human level. No government or scientific body has an agreed test for when that threshold is crossed. Companies can demonstrate impressive benchmarks without showing reliable general reasoning, and intelligence services may see only fragments of secret programs.
That uncertainty is the first danger. If policymakers believe the first AGI will give its owner overwhelming military, cyber and economic power, ambiguous evidence can look like an approaching strategic defeat. A data-center expansion, chip shipment or model-training run could be interpreted as a point of no return even when analysts are wrong.
The report describes a ladder. Washington might seek diplomacy and reciprocal limits; collect intelligence or reverse-engineer a rival system; disrupt development through cyber means; and examine coercive or kinetic actions if lesser measures fail. Stokes presents military force as the highest-risk option, not a casual recommendation.
Planning defenders argue that governments examine catastrophic contingencies precisely so presidents understand their consequences. A scenario exercise could reveal that attacks are ineffective, create escalation pathways and should be rejected. Refusing to discuss a possibility does not prevent military organizations from confronting it later with less preparation.
Critics answer that publishing the option can normalize preventive war over a speculative technology. Chinese leaders may infer that American concern about AI safety masks a desire to preserve technological dominance. Beijing could disperse facilities, restrict research contacts, intensify espionage and place military protection around civilian computing sites.
There is also a practical problem: AI is not a single reactor. Capability resides across chips, software, data, electrical grids, researchers and copied model weights. Bombing one center might kill civilians and interrupt services without erasing the knowledge. Cyberattacks can spill into hospitals, finance and communications. Espionage risks creating the very race for theft that both sides fear.
The escalation ladder would be steep. China could retaliate against U.S. cloud infrastructure, undersea cables, satellites or regional bases. A preventive attack on mainland China would cross a threshold far beyond export controls and could trigger conventional or even nuclear crisis dynamics. The assumption that force would remain limited deserves more scrutiny than the assumption that AGI will arrive on schedule.
Less dramatic measures exist: reporting requirements for enormous training runs, safety evaluations, hotlines for AI-related incidents, rules preventing autonomous systems from controlling nuclear weapons and mutual commitments not to attack civilian data infrastructure. Verification would be difficult, but difficulty is not evidence that missiles are safer.
The most valuable part of the controversy may be the warning it reveals. Treating AGI as a winner-take-all weapon encourages secrecy, exaggeration and first-strike thinking. Treating it only as a commercial product ignores real security risks. Washington and Beijing need a framework that recognizes both dangers.
The historical analogy is not the Manhattan Project alone. States have repeatedly exaggerated “gaps”—missile gaps, bomber gaps and technology gaps—to justify spending or riskier policy. Sometimes the underlying competition was genuine; sometimes uncertainty and bureaucratic incentives magnified it. Frontier AI adds private companies whose valuations benefit when governments believe their systems are strategically decisive. Their forecasts should be examined, not treated as neutral intelligence.
China faces the same incentive problem. Beijing may conceal progress to avoid controls or advertise it to attract talent and deter pressure. An accident, espionage allegation or unexplained data-center outage could then be interpreted through the most hostile lens. This is why crisis protocols should be developed before either side believes a breakthrough is imminent. The report's greatest contribution may be forcing policymakers to confront how little reliable information they would possess at the moment they were asked to make an irreversible decision.
What to watch next
Watch whether the White House, Pentagon or Congress adopts any CNAS recommendations, whether intelligence agencies create formal AGI indicators and whether China responds diplomatically. The central question is no longer simply who builds the strongest model. It is whether fear of losing an undefined AI race could cause two nuclear powers to start a very human war.