Cyber ·

Bomb China’s Data Centers to Stop AGI? The Explosive Proposal Washington Has Not Adopted

A CNAS analyst says Washington should study extreme options if China nears AGI first, including espionage, cyber operations and potentially military force. It is not official U.S. policy.

Bomb China’s Data Centers to Stop AGI? The Explosive Proposal Washington Has Not Adopted

A former White House official has argued that the United States should prepare for the possibility of military strikes on Chinese data centers if Beijing appears close to achieving artificial general intelligence first. The idea is genuine, alarming and easy to misreport: it is a think-tank recommendation to study extreme scenarios, not an adopted American war plan.

Jacob Stokes, a former Obama-era National Security Council staff member and now a senior fellow at the Center for a New American Security, authored the report “Superpowers and AGI.” CNAS is influential in Washington, but it is independent of the government. Its publications shape debate; they do not issue orders.

The report asks how U.S.-China competition might change if AGI—usually imagined as a system able to perform a wide range of intellectual tasks at or above human level—became imminent. Stokes discussed a ladder of measures including diplomacy, espionage, cyber operations, export controls and, at the extreme, kinetic attacks on computing infrastructure.

Studying an option is not recommending immediate use. Defense organizations routinely examine scenarios they hope to deter. Yet naming data-center strikes changes the political conversation because those facilities are civilian as well as strategic. They host commercial services, research, communications and potentially safety-critical systems.

The first problem is definition. No internationally accepted test establishes that a model has reached AGI, and private companies make unverifiable claims about capability. Intelligence could misread benchmarks, concealed hardware or propaganda. A state might launch a war to stop a breakthrough that did not exist.

The second problem is effectiveness. AI capability is distributed across chips, software, data, power supplies, laboratories and human expertise. Destroying one facility might delay training but not erase algorithms or knowledge. Cloud workloads can move; hardware can be dispersed; backups can survive. An attack might accelerate Chinese mobilization instead of preserving an American lead.

The third problem is escalation. China could regard strikes on mainland infrastructure as acts of war and retaliate against U.S. bases, satellites, cables or data centers. If leaders believe AGI creates an irreversible first-mover advantage, both sides gain incentives to hide progress, exaggerate threats and strike early—the same instability policymakers claim they want to prevent.

Supporters of contingency planning answer that refusing to think about dangerous possibilities does not make them disappear. If AGI could produce overwhelming military, cyber or economic power, Washington would need intelligence indicators, red lines and crisis communications before the moment arrives. Planning may help leaders understand why force would be counterproductive.

Critics see the proposal as securitizing speculative technology. Framing AI research like a nuclear breakout could undermine scientific exchange, justify industrial sabotage and empower agencies to act on uncertain forecasts. Unlike fissile material, software can be copied and improved quickly across borders.

There are less violent alternatives: verifiable compute reporting, chip controls, joint incident hotlines, restrictions on autonomous nuclear command, model evaluations and agreements not to attack civilian cloud infrastructure. These mechanisms are difficult, but their difficulty does not make bombing safer.

China will likely present the debate as evidence that U.S. technology restrictions are about preserving dominance rather than safety. Washington will point to Chinese military-civil fusion, cyber espionage and state support for frontier AI. Both narratives contain evidence and self-serving exaggeration.

The deterrence paradox

Publicly discussing strikes may be intended to deter China from hiding a breakthrough, but it may produce the opposite behavior. If Beijing believes disclosure could make its laboratories targets, officials have every reason to conceal compute, disperse facilities and avoid safety cooperation. American companies may make similar choices if they fear espionage. A race becomes less observable precisely when reliable information matters most.

There is also an alliance problem. Data centers may be owned by companies from several countries, powered by civilian grids and located near dense populations. U.S. partners asked to support an attack would demand a clear threshold and legal rationale. “China is close to AGI” is unlikely to be enough. Any serious policy must define who assesses the threshold, how evidence can be shared and what peaceful off-ramp is offered. Without those safeguards, contingency planning can turn speculative advantage into self-fulfilling confrontation.

What to watch next

Watch whether any U.S. agency formally adopts CNAS’s indicators, whether Congress debates data-center targeting and whether Washington and Beijing create AI crisis rules. The urgent question is not only who reaches AGI first, but whether fear of an undefined breakthrough could trigger a very conventional war before AGI exists.