Understanding Beijing’s playbook can help organizations anticipate their own exposure
On August 4, Japan’s Ministry of Defense released its 2026 white paper, once again naming the People’s Republic of China (PRC) as the country’s “greatest strategic challenge.” The next day, a Chinese Foreign Ministry spokesperson said the PRC “deplores and firmly rejects” the document and had lodged a formal protest with Tokyo. That exchange was just the latest diplomatic salvo in an ongoing dispute between the two nations. That dispute found a new gear last November when the PRC launched a coordinated campaign of economic coercion against Japan. What has transpired since offers one of the clearest windows yet into how Beijing builds and escalates pressure on perceived competitors.
It is well known that the PRC’s animosity toward Japan runs deep, and that history is part of why this particular campaign escalated as fast and as hard as it did. But the playbook underneath it, the triggers that provoke a response, the tools Beijing reaches for, and the order in which it deploys them, isn’t exclusive to Japan. Understanding it is what lets other countries and companies map their own exposure before they become the next case study.
The Trigger
Beijing’s coercive campaign traces back to November 7, 2025, when Japanese Prime Minister Sanae Takaichi told Japan’s national legislature that a PRC military move against Taiwan could constitute a “survival-threatening situation” for Japan. Since the 2015 reinterpretation of Japan’s pacifist constitution, this description is the legal trigger that enables Japan’s military to act in defense of an ally under attack, not only in defense of Japan itself. By applying it to Taiwan, Takaichi signaled that Japan could respond militarily to a cross-strait conflict.
Beijing judged that Takaichi’s remarks had crossed one of its “Four Red Lines”—issues in which the PRC “will not tolerate a challenge.” Those four lines are the “Taiwan Issue,” “Democracy and Human Rights,” the PRC’s “Political System,” and “Developmental Rights.”
Beijing responded within days, demanding a retraction and warning that Japan would “bear all the consequences.” Officials also cast the remarks as interference in the PRC’s internal affairs. Takaichi has not walked the comment back, and what has followed since is a PRC economic coercion campaign that has grown more sophisticated with each passing month.
The PRC has used economic pressure against Japan before, but never quite like this. In 2010, after a Chinese fishing trawler collided with a Japanese Coast Guard vessel near the disputed Senkaku Islands, Beijing halted rare earth exports to Japan. In 2023, it banned Japanese seafood imports over the release of treated wastewater from the Fukushima Daiichi plant, a move framed as food safety but widely read as retaliation for Japan’s support of semiconductor export controls. Both were rooted in a concrete grievance: a territorial incident and a trade dispute. This new campaign, however, began with Takaichi’s remarks on Taiwan—a matter of political alignment rather than commerce or borders. It suggests Beijing now sees its grip on critical mineral supply chains as leverage over political and security commitments, and not only as a tool for settling economic scores.
How the Pressure Escalated
Beijing is employing economic coercion as a graduated campaign that progressively increases pressure as lower-cost measures fail to achieve its political objectives. Beginning on November 14, 2025, the Chinese Communist Party (CCP) rolled out travel advisories discouraging Chinese citizens from visiting Japan, followed by education warnings, renewed seafood restrictions, and the cancellation of Japanese cultural events. Within two weeks, more than 500,000 flight tickets from mainland China to Japan had been canceled. By January 2026, Chinese visitor numbers to Japan were down more than 60 percent year-on-year. A Chinese Foreign Ministry spokesperson made clear this had nothing to do with safety or tourism policy, saying Takaichi’s comments had “gravely hurt the sentiments of the Chinese people.”
When that pressure failed to produce a retraction, the CCP moved to the tools tied to Japan’s dependence on Chinese-controlled mineral supply chains. On January 6, 2026, the PRC’s Ministry of Commerce banned the export of dual-use items to the Japanese military and for any purpose that could contribute to Japan’s military capabilities. The restricted list included several medium and heavy rare earth elements, including samarium, gadolinium, terbium, dysprosium, and lutetium, which are used in permanent magnets, semiconductors, and drones. By mid-2026, customs data reported by Japanese and Western outlets showed dysprosium and terbium oxide exports to Japan had fallen to zero.
In May, PRC authorities also detained two Japanese nationals on allegations of violating export control laws tied to rare earths. There’s no public evidence that the detentions were ordered as retaliation for Takaichi’s remarks. But the timing, coming after the export controls tightened, shows Beijing is willing to enforce its new restrictions through more than licensing decisions alone.
Building Something Durable
The PRC’s campaign comes wrapped in legal and regulatory infrastructure that can be dialed up or down for years. On January 7, 2026, China’s Ministry of Commerce opened an anti-dumping investigation into a Japanese chemical used in semiconductor manufacturing. In February, it added 20 Japanese organizations to its export control list and another 20 to an enhanced-scrutiny watchlist, including subsidiaries of Mitsubishi Heavy Industries, Kawasaki Heavy Industries, and the Japan Aerospace Exploration Agency. Both lists were expanded again on June 29, months after the original dispute, a clear indication that the campaign is actively growing.
Each mechanism functions as its own lever: export licensing, entity list designations, customs delays, anti-dumping cases. Beijing can pull any one of them harder or ease off without touching the rest, and it can describe each move publicly as routine national security or trade enforcement.
What’s Likely Next
Prime Minister Takaichi shows no sign of backing down, and neither does Beijing. Strider assesses the next phase of the PRC’s campaign will likely widen licensing restrictions on permanent magnet inputs used by civilian automotive, robotics, and electronics manufacturers, extending pressure beyond Japan’s defense-industrial base and into its broader economy. That approach would allow Beijing to keep describing its restrictions as narrowly tailored to national security, while sidestepping the costs of a comprehensive rare earth embargo, a move that would risk a coordinated response from Japan’s allies. A full embargo remains possible if the political standoff worsens, but it’s the least likely outcome absent a bigger crisis.
The Playbook Beyond Japan
U.S. and allied countries and businesses based in those countries should anticipate phased coercion campaigns similar to the one against Japan. While the PRC’s campaign against Japan is heavily influenced by the two countries’ longstanding history and Japan’s critical dependence, the logic behind it—the triggers, the tools, the order in which they’re deployed—is worth tracking.
Between 2023 and 2025, Beijing’s restrictions on gallium, germanium, and graphite were direct responses to U.S. semiconductor controls. This campaign against Japan is different: it has been linked publicly to political signaling on Taiwan, rather than trade or technology restrictions. That shift suggests China increasingly views its mineral dominance as a way to deter allied security commitments, and not only as a tool to retaliate against economic pressure.
There’s a deeper calculation behind the timing, too. Since 2022, the U.S., Japan, Australia, and the EU have all invested in mining, refining, and stockpiling alternatives to Chinese supply. If Beijing believes that diversification is inevitable, it has less reason to hold its leverage in reserve. Using it now, while it still works, may look more valuable than preserving it for later.
The economic coercion against Japan is the first clear demonstration of a toolkit Beijing has built and is willing to use again: calibrated differently depending on the target, but drawn from the same set of triggers, tools, and sequencing. Government and business leaders should take note of what is happening to Japan and begin identifying their own vulnerabilities should the PRC use the same toolkit against their organization.
How state-sponsored hacking groups are exploiting the OSS ecosystem to advance strategic objectives
On June 23, 2026, a GitHub account called Xpos587 pushed updates to several unrelated repositories within the same narrow window of time. At the time, it seemed innocuous. But weeks later, researchers at Socket, a software supply chain security firm, traced that account back to a campaign called PolinRider and linked it to North Korean state hackers. By the time Socket published its findings on July 6, the attackers had compromised more than 100 open source packages across four different ecosystems. Some of the affected code carried a backdoor—a hidden way for attackers to get back into a system later. Other packages carried an information stealer (malware designed to quietly pull data, like passwords and files, off an infected computer). Developers installed both, believing they were ordinary, run-of-the-mill packages. Socket later determined the campaign had been running since December 2025, seven months before anyone caught it.
The packages involved in that campaign were open source software (OSS): code that anyone can view, use, and contribute to, usually for free. It underpins most of the digital world, from consumer apps to the systems banks and government agencies run on. Historically, the community behind OSS operated on mutual trust, good-faith collaboration, and open exchange. Anyone could submit a change. A smaller group of maintainers decided what made it into the final product. Nobody had to prove their identity or disclose if they were contributing on behalf of an entity or a nation-state.
Strider examined this trust-based system in a report titled Lying in Wait. For organizations’ security, the report introduced what it calls a contributor-centric risk model. In addition to focusing on what the code does—and potential vulnerabilities or malicious code—the approach adds the dimension of understanding who is behind the code.
A System Built on Trust
State-sponsored hacking groups have spent years working their way into open source communities, using the same openness that makes these platforms function against them. According to Strider’s research, groups like Lazarus Group, tied to North Korea, and Cozy Bear, tied to Russia, have infiltrated software supply chains, stolen sensitive data, and run long-term cyber-espionage operations through open source platforms. GitHub, where most of the world’s open source code is hosted and where millions of developers collaborate daily, has become both a primary target and an unwitting tool for this activity.
These groups do not behave like ordinary, financially motivated cybercriminals. A typical criminal group wants a fast payout, and it will abandon an approach quickly if one isn’t coming. State-backed groups operate on a different timeline. They are directed and funded by government entities pursuing specific strategic goals, allowing them to spend years building credibility inside a project before ever putting that access to use.
A Pattern That Keeps Repeating
Strider’s report walks through several OSS incidents that show this is far from an isolated problem.
In 2024, attackers uploaded malicious packages to the Python Package Index, a central repository that millions of developers pull free code from routinely, disguising malware called JarkaStealer as regular tools and using AI chatbots to help the deception spread. Japanese cybersecurity officials attributed the attack to Lazarus Group—a hacking group linked to North Korea.
The discovery of the Log4Shell vulnerability in Log4j, a widely used logging tool that records what is happening inside an application, exposed a large number of organizations to potential attack because so many unrelated systems depended on the same piece of code. Government agencies and cybersecurity firms observed advanced persistent threat (APT) groups—government-backed hacking teams built for long-term, stealthy access—from the PRC, Iran, North Korea, and Turkey actively exploiting the flaw. The costs were enormous. Experts estimate the vulnerability cost organizations more than $90,000 in incident response support per incident, with total costs across industries reaching into the billions. One U.S. federal agency alone dedicated more than 33,000 staff hours to its response, and more than half of corporate security teams spent weeks or longer remediating the issue. Even more than four years later, 72 percent of affected organizations were still detecting active exploitation attempts.
A third approach relied on patience. An individual using the alias “Jia Tan” started contributing to XZ Utils, a popular open source data compression tool, gradually building trust within the project. In 2024, after maintaining a high level of operational security over a lengthy period and earning co-maintainer status, Jia Tan inserted a malicious backdoor into the software. The identity of Jia Tan, and the nation-state group behind the attack, have still never been identified.
Growth Without Guardrails
According to Strider’s research, OSS adoption by businesses and governments has accelerated faster than the security practices meant to protect it. The transparency, decentralized governance, and volunteer-driven collaboration that made open source successful for decades also make it vulnerable to manipulation by well-resourced groups working on behalf of adversarial governments.
Each of the incidents above followed a different path. A vulnerability in one case, a compromised package in another. But in every one, the code passed the same review process every other contribution passes, and no scan or audit caught what was happening. The attackers had spent time earning a position inside the project, and that standing let their changes go through without a second look.
Security tools have grown considerably more capable at detecting the contents of code. They often flag known vulnerabilities, suspicious patterns, and malware signatures before a package ever reaches production. But Strider’s report argues that traditional software security focuses on the code itself while overlooking the people contributing to it. A scan can tell you a package is clean. It cannot tell you who wrote it, or whether that person has ties to a government with a reason to want the code approved.
Strider built a tool called Open Source Software Search to answer exactly that question. By analyzing contributor behavior, affiliations, and activity patterns across open source platforms, the tool helps organizations uncover hidden risks that traditional vulnerability scans completely miss.
Using OSS Search, Strider examined contributors to two widely used repositories: an AI toolkit that makes it possible to run generative AI models on consumer devices and a Python library used to organize data into tree structures. In both cases, it found individuals with direct ties to sanctioned entities and state-backed institutions, whose contributions were embedded inside code that companies rely on every day.
NOTE: This is the third post in Strider’s series on the PRC’s 15th Five-Year Plan (FYP). The first post provided an overview of the 15th FYP’s major themes. The second post examined the AI+ Action Plan in detail. This post examines the 15th FYP’s talent strategy and the structural workforce gaps driving it.
For decades, leaving the People’s Republic of China (PRC) for a career in the West was the benchmark of professional ambition. A position at a top American university or technology company was the ultimate destination, and most who reached it did not come back. Today, that is no longer a safe assumption.
The number of recent Chinese graduates from overseas universities who are returning home has more than doubled since 2018, and the trend is accelerating. Chinese companies are now dispatching recruiters around the world and authorizing salaries that match or exceed what local firms are offering. A recent LinkedIn survey of overseas Chinese PhD students last year found that 59% planned to return after graduating, up from 38% the year before.
The conditions pulling talent back to the PRC—tightening immigration policy, tenuous bilateral relations, and a political environment that has made some PRC-born researchers feel professionally constrained—have converged at a moment when Beijing is better positioned than ever to receive them. The 15th Five-Year Plan (15th FYP) explicitly lays out a strategy to capture talent and turn it into a sustained competitive advantage.
A Deficit That Cannot Wait
The scale of China’s advanced technology workforce gaps makes external recruitment a strategic necessity. China’s semiconductor industry faced a shortfall of approximately 700,000 workers in 2024. The digital economy’s talent gap reached 30 million by the end of 2025. Demand for skilled AI talent alone will require nearly six million professionals by 2030. No domestic training pipeline closes deficits of that magnitude within a five-year window. The plan’s answer is to compete for talent that already exists, targeting scientists and engineers currently working at universities, laboratories, and technology companies in the United States and Europe.
A World-Class Talent Engine
The 15th FYP’s central talent mechanism is a proposed state-led “world-class talent engine” designed to attract leading experts in priority technologies by offering research autonomy, globally competitive pay, and optimal working conditions. They are targeting established scientists and engineers who have built careers at leading Western institutions and would need a compelling reason to leave. Alongside this, the Plan contains a proposal to establish a “high-tech talent immigration system” explicitly designed to cultivate world-class talent—a structural mechanism intended to make the pathway from overseas recruitment to domestic integration faster and more formalized than anything that preceded it.
The most direct expression of that ambition is a proposed “New Thousand Talents Program” to be launched by Beijing municipality, targeting 1,000 top scientists drawn primarily from the United States and Europe in sectors including AI, information technology, synthetic biology, and advanced materials. The original Thousand Talents Program has drawn sustained scrutiny from Western governments and law enforcement agencies concerned about undisclosed foreign affiliations and technology transfer. Recasting its successor as a municipal initiative rather than a national one reflects both the continued appetite for external expertise and an institutional memory of what drew attention the first time.
National Direction, Regional Execution
The Plan structures talent development the same way it structures most major priorities: central policy direction executed through regional ecosystems. Shanghai is strengthening mobility across universities, research institutes, and enterprises, building the conditions for researchers to move fluidly between sectors. Zhejiang Province is pursuing tighter academia-industry alignment and introducing hybrid appointments such as “science vice presidents” and “industry professors,” positions designed to embed researchers in commercial environments without severing their academic connections. Guangdong Province has formalized dual-appointment recruitment models that place professionals in overlapping roles across industry and academia, supported by mass-scale programs including “Million Talents to Southern Guangdong.”
Each approach reflects the same underlying objective: advanced technology development requires researchers who can move between scientific discovery and industrial application. PRC institutions have historically sought to strengthen that mobility to address talent shortage and support the transition of research into commercial and strategic outcomes. The plan seeks to advance that objective by strengthening regional talent, research, and commercialization ecosystems while maintaining national coordination over strategic direction and priorities.
The Financial Case for Returning
Regional governments—operating in parallel with, and in support of, the Plan’s broader talent agenda—have moved to make returning to the PRC financially attractive at the individual level.
Shenzhen is offering tax breaks and the equivalent of more than $700,000 in subsidies for qualified overseas returnees. Shanghai’s Pudong District is providing roughly $14.7 million in project funding to top young talent in science and technology. Other Shanghai districts are targeting PhD holders who have held senior positions abroad, offering living allowances of up to nearly $300,000 and free or subsidized office space for startups. These programs are the financial infrastructure through which the Plan’s talent objectives get executed on the ground.
Financial offers are often reinforced by something harder to quantify. Researchers who have returned describe a sense of professional possibility that felt out of reach abroad—the chance to lead large-scale projects, build teams, and work in industries moving fast enough that seniority can be earned quickly. That perception, whether or not it holds universally, is part of what Beijing is selling.
What the 15th FYP Sets in Motion
The talent competition embedded in the Plan is concentrated in the sectors where geopolitical competition is most intense: semiconductors, AI, synthetic biology, and advanced materials. The professionals Beijing is targeting are currently employed at research universities, technology companies, and national laboratories across the United States and Europe. As Beijing scales its national and regional innovation ecosystems over the next five years, demand for advanced technology expertise will continue to outpace domestic supply, and pressure to source that expertise externally will grow with it.
The 15th FYP frames talent acquisition as a foundational condition for executing the broader agenda. The financial instruments are in place, the regional infrastructure is being built, and the external environment is producing a pool of potential returnees larger than at any previous point.
Competition for the people who build and run advanced technologies is already underway.
By: Calder Walton, Strider Advisor and Director of Research for the Intelligence Project at Harvard’s Kennedy School
There is a growing perception among long-standing US allies that they need to expand commercial relations with the People’s Republic of China (PRC). A thaw or détente with the PRC brings both rewards, particularly for a sluggish economy like Britain’s, but also major risks. History shows that a superpower can ruthlessly exploit détente with the West.
Economic Security and Intelligence
Economic security and intelligence are nothing new. Before the Second World War, for example, Britain ran a small outfit known as the Industrial Intelligence Centre (IIC). Run by a former MI6 officer, Desmond Morton, the IIC provided a coordination of intelligence on German rearmament and, working with MI5, assessed Britain’s commercial vulnerabilities. British intelligence helped to devise the UK government’s War Book, which set out emergency regulations to protect critical national infrastructure in the event of war. After the Second World War, during the Cold War, it became a staple of British and other western intelligence to assess the size and strength of economies behind the Iron Curtain.
Risky Business
In 1972 President Nixon and his national security advisor, Henry Kissinger, ushered in a policy of détente with the Soviet Union. Its purpose was to further divide the Soviet Union from China. Papers at the Nixon library show that Kissinger was under pressure from British firms, in particular, to open up markets behind the Iron Curtain. Britain was in a dire economic doldrum following an oil shock due to a war in the Middle East.
Kissinger and Nixon knew that not all commercial technologies could be transferred to America’s main strategic enemy, the Soviet Union. The White House was accurately afraid of dual use technologies, namely those that were civilian but could also be used for military purposes. Kissinger limited the sale of high end computers and microchips, for example, only allowing second tier components to be sold to the Soviets.
Although Nixon and Kissinger accurately guessed that US industries would be targets for Soviet espionage, the extent to which the Soviets exploited détente would have been beyond their wildest imaginations. The collection of scientific and technical intelligence from the US was conducted by Soviet military intelligence (GRU) and the KGB, whose operating arm, Line-X, reported to Directorate T (Technology). In 1973 the KGB assigned an officer to New York whose full-time job was to collect (steal) US scientific and technical intelligence (S&T). By 1980 the US was producing more S&T intelligence for Moscow than the rest of the world combined. Visiting Soviet trade delegations to US research centers, laboratories and fortune 500 companies, for example, were packed with undeclared Soviet intelligence officers. In an agricultural delegation of a hundred Soviet officials about one third were known or suspected Soviet intelligence officers. In one visit to a Boeing laboratory a delegate applied adhesive to his shoes to obtain metal samples. The size of the Soviet onslaught was so large that entire fields of US research and development became replicated in the Soviet Union. The East German spy master, Markus Wolf, recalled the East German computer company, Robotron, was, thanks to Soviet espionage, an unofficial subsidiary of IBM.
Soviet S&T espionage was often facilitated by sloppy security at US defense contractors. An employee of TRW Corporations in Redondo Beach, CA, which manufactured a US spy satellite, recalled that workers “regularly partied and boozed it up during working hours with the ‘black vault’ housing the Rhyolite [spy] satellite project”. Bacardi rum, he claimed, was kept behind the cipher machines and a cipher-destruction device was used as a blender to mix banana daiquiris and Mai-Tais.
Soviet espionage was so far reaching that, ironically, by the end of the Cold War both sides of the conflict, NATO and the Soviet Union, were dependent on US S&T.
Business Risk
Fast forward to the present day – a time when the world is vastly more complicated than the last century’s Cold War. Western countries did not need the Soviet economy. By contrast, China is intertwined with the world economy.
Beijing is seeking to portray Washington’s new approach to economic, defense, and foreign policies as undermining the post war rules based international order that it created. Meanwhile the PRC, which, has previously railed against the international order (though in reality it vastly benefited from that order), is holding itself out to be the stable player on the world stage. The PRC’s attitude is that it will play by the rules when it suits it but is happy to break them whenever it decides to do so.
Recent diplomatic outreach to Beijing by Western leaders include agreements framed as pragmatic economic wins. If middle powers, like Britain, for example, pursue a strengthening of commercial relations with China, they will need a strategy to mitigate risk like Nixon and Kissinger developed. Britain does not have a strategy for doing so. Even China hawks, like former US ambassador in Beijing, Nicholas Burns, have stated that for economic growth the US will need to continue to trade with China, but will need to carve out elements of national security and critical infrastructure. The latter is a principle stretching back to the UK government War Book.
There is no reason why the PRC would not seek to exploit a détente with the west as the Soviets did before. The Chinese state and its intelligence services have never encountered a western business whose intellectual property they did not want. The Chinese Communist Party (CCP) uses a constellation of front companies to do business with the outside world. Often such companies will enter into business ventures to obtain intellectual property from their western counterparts, but then pull the plug, bankrupting their western counter parties. To add insult to injury, Chinese firms will often sell the product they have stolen back to western markets.
The name of the game for western businesses must therefore be risk mitigation regarding China. In the last century, governments held the monopoly on the know-how and intelligence critical to the technologies that shaped our world – nuclear weapons. It took state resources to detect technology transfer. Soviet S&T espionage was only discovered when French intelligence recruited an agent in KGB Line-X in the 1980s. The same is not true today. Private sector companies today hold the keys to innovations that will shape our lives this century – microchips, A.I., quantum and bioengineering. It is therefore private sector companies that are best placed to mitigate risk of stolen intellectual property. And unlike in the past, this can be done by using A.I. driven publicly available data.
By: Eric Levesque, President and Co-Founder of Strider Technologies
Last month, the European Commission moved to block public funding for solar panel inverters from what it calls “high-risk vendors,” a category that squarely targets China’s technology giants, including Huawei.
Inverters are used in a range of energy systems, but in solar power, they are essential. It is a device that converts direct current into alternating current, the form of electricity used by the grid and by most homes, hospitals, and factories. They are also connected to the internet and can be monitored, updated, and, in some configurations, controlled remotely.
The Commission’s spokesperson was surprisingly direct about why. Foreign actors, she warned, could use inverters to manipulate energy networks and gain “unauthorised access to operational data.” She did not soften what that disruption could look like – the manipulation of electricity production, and the capability of a “remote shutdown… leading to countrywide blackouts.”
Huawei is among the vendors named in Brussels as high-risk, and British readers will remember the 2020 decision to remove the company from the UK’s 5G communications network. The concern then was straightforward; a company with deep ties to the Chinese state had no place in sensitive national infrastructure. That argument won, but Huawei never left the energy sector. As of 2022 it held a 26 per cent share of the European solar inverter market and has since struck deals with UK energy companies.
As Britain accelerates towards clean electricity by 2030, more and more inverters are entering our system from China. Imports of converters into the UK, Norway and Switzerland grew from 256 million kilograms in 2015 to 395 million kilograms in 2023. We are talking about a structural dependency embedded across the entire system.
At Strider, we have been analysing this issue for some time, and specifically at the pattern of Chinese state interest in exactly this kind of infrastructure. In 2020, researchers from the State Grid Corporation of China and the China Electric Power Research Institute, both state-linked institutions, published a detailed technical analysis of the blackout that struck the United Kingdom on 9 August 2019. They were studying the oscillations caused by UK wind farms and theorising how similar failures might be triggered by other renewable energy sources.
China’s researchers are mapping our vulnerabilities whilst China’s manufacturers become increasingly embedded in our infrastructure. The European Commission has now accepted, in plain language, that this combination represents a credible threat.
Which brings us to the particular challenge Britain now faces. When the EU restricts public funding from high-risk vendors in its energy infrastructure, displaced supply does not simply disappear. Manufacturers who can no longer access European public contracts will look for alternative routes to market. Britain, sitting outside the EU’s regulatory framework, risks becoming exactly that alternative route, a backdoor through which Chinese inverter technology re-enters European supply chains.
The good news is that the UK is well placed to respond. Britain has shown genuine leadership on economic security in recent years, from research security guidance to investment screening, and there is real appetite in government and across industry to go further. We now need to audit what is already embedded in the national grid, and close the backdoor: none of this is radical. It is the logical extension of work already underway.
The opportunity to get ahead of this is still open. It will not remain so indefinitely.
In one of the most infamous scandals in international banking, Deutsche Bank helped move an estimated $10 billion out of Russia without anyone inside the institution raising a flag. Between 2011 and 2015, the bank’s Moscow desk executed what came to be called “mirror trades”: Russian clients, including some tied to politically exposed and sanctioned networks, bought securities in Moscow while related counterparties sold the identical securities through the bank’s London office. Each individual trade looked routine. But the aggregate was a covert pipeline that moved billions in funds out of Russia through London and into offshore accounts, exposing the bank to regulatory penalties on three continents.
This case underscores a reality the financial industry is now grappling with. Banks, fintechs, digital asset platforms, and investment firms face risks today that have outgrown the tools built to detect them. The gap between what traditional compliance can protect against, and the evolving tactics and techniques of adversarial nations, is where strategic intelligence becomes essential.
A Growing Target
Governments in Western countries (including the United States, Canada, United Kingdom, Japan, Australia, and throughout Europe) have designated the financial services and banking sectors as critical infrastructure. When a sector is classified as critical infrastructure, it signifies that its assets, systems, and networks are essential to national security, the economy, or public health. Failure or compromise of that sector would cause debilitating effects for society.
Because financial institutions sit at the center of global capital flows, regulatory scrutiny, and geopolitical competition, their systems, people, and partnerships are persistent targets for state-sponsored actors. The PRC’s systemic emphasis on data as a driver of national power ensures that banks and financial services companies will remain high-priority intelligence targets, valued less for their role as financial intermediaries than for their visibility into the broader ecosystems of strategic industries and capital flows. Banks serve clients in defense, energy, advanced technology, and critical infrastructure. They sit at the center of cross-border trade and investment. And they play a pivotal role in enabling corporate strategy, allocating capital, and shaping risk assessments, giving adversaries a window into the decision-making processes of global firms and governments—and the people who lead them.
State-sponsored actors seeking to infiltrate hiring pipelines, exploit third-party relationships, and influence deals are targeting enterprise banks whose innovation units are building AI, quantum, and cybersecurity capabilities. In the fintech and digital asset space, payment platforms, digital wallets, and crypto-processing environments hold high-value data and assets that adversarial governments are actively pursuing for leverage. And investment firms face growing enforcement from regulatory agencies, where even indirect exposure to sanctioned entities can trigger scrutiny and jeopardize funding.
The pressure is showing up across the sector. North Korean operatives have used fabricated identities to secure remote IT roles inside U.S. financial firms, funneling salaries back to the regime while gaining access to sensitive systems. Those schemes have helped the DPRK steal more than $6 billion in cryptocurrency. At Coinbase, overseas support contractorswere bribed by cybercriminals to exfiltrate customer data from inside the company. The result was a $20 million ransom attempt that affected tens of thousands of users. Cases like the Bitzlato CEO arrest and the JPEX exchange scandal tell a different but related story: undisclosed foreign control and executive-level misconduct at crypto platforms can trigger sanctions exposure, money laundering investigations, and lasting reputational damage.
Where the Financial Sector is Most Exposed
Understanding where adversaries are finding their way into organizations starts with understanding how exposure accumulates. It comes through hiring decisions made without full visibility, deal counterparties whose ownership structures aren’t fully traceable, and supply chain dependencies that no one has examined closely enough. For organizations across financial services, markets, and banking, the risk concentrates in three places.
The first is people. Financial institutions need to screen applicants, employees, vendors, and contractors for risky affiliations and falsified resumes, especially in high-trust roles across cybersecurity, fraud, money-movement operations, AI, quantitative research, and cyber R&D. These are the positions state-sponsored actors are working hardest to access, and they are doing so through falsified credentials, hidden affiliations, and ties to foreign programs that conventional background checks were not designed to detect. Rapid hiring cycles and remote-first work have expanded the surface area, making continuous vetting of both candidates and existing personnel essential.
The second is deals and partnerships. Every M&A transaction, IPO, fund onboarding, investment deal, and joint venture pulls new entities into a financial institution’s orbit, and each one can carry hidden ties, foreign control, or sanctions exposure that is rarely visible from the outside. Financial institutions need to be able to identify these risks across counterparties, customers, investors, LPs, board members, and global partners before a deal closes or a relationship deepens. Even indirect exposure, like adversarial capital or a sanctioned co-investor on a cap table, can trigger regulatory reviews and jeopardize investments. The Deutsche Bank mirror trading scandal is a case in point: the clients and counterparties behind the scheme were closely related entities with common owners, but the bank’s KYC (Know Your Customer) processes failed to surface those connections until billions of dollars had already moved.
The third is open source software and supply chain dependencies. Financial institutions increasingly rely on open source tooling in internal platforms and quantitative systems, as well as third-party crypto-processing centers, liquidity partners, and external infrastructure providers. Contributors to these tools and organizational dependencies can carry hidden nation-state ties, and without visibility into who is contributing to the code and infrastructure these institutions depend on, the risk compounds silently.
Case Study: Tracing an IRGC-Linked Network into European Real Estate
In 2025, reporting by Bloomberg and the Financial Times identified more than 400 million euros worth of European properties linked to Ali Ansari, an Iranian national sanctioned by the UK that year for providing economic resources to the Islamic Revolutionary Guard Corps (IRGC). Despite the designation, his holdings, which include London properties, hotels in Germany, and a resort in Spain, largely remain intact. They are held through a web of offshore companies and proxy individuals spread across at least eight jurisdictions. Any financial institution that encountered this network through a deal, a counterparty, or a vendor relationship would have had no way of knowing what sat behind it using standard screening tools.
Strider traced the network from beginning to end. Inside Iran, Ansari built a sprawling empire under the Tat Group name, with holdings in banking, finance, and construction. Tracing Tat Bank’s ownership through Iran’s corporate registry leads through his core construction entity, through multiple U.S.-sanctioned holding companies, and finally to Bonyad Taavon Sepah, the IRGC Cooperative Foundation. From there, the money moved west along a deliberately layered route. Iranian oil revenues, sold to China through sanctioned crude channels, passed through UAE intermediaries, into offshore holding companies in Saint Kitts and Nevis and the Isle of Man, then into Luxembourg and Dutch corporate vehicles, and finally into European real estate. By the time the capital arrived, it looked like legitimate Western investment on paper.
The network also depended on trusted individuals who could operate without drawing attention. Iman Rahimi Aloughareh held senior roles across Ansari’s Iranian businesses while simultaneously serving as founding managing director of the Luxembourg entities and the German operating company that anchored the European structure. Despite sitting at the center of a network with direct ties to the IRGC, Aloughareh has never been sanctioned. His name would not appear in any due diligence screen. This is exactly the kind of hidden ownership, foreign control, and sanctions exposure that financial institutions need visibility into, and exactly the kind that regulators, once they uncover it, treat as the institution’s responsibility.
How Strider Helps Financial Institutions
Strider is the leading provider of strategic intelligence for identifying and mitigating nation-state risk. The platform equips CISOs, insider threat teams, fraud and FinCrime leaders, compliance organizations, and investment teams with visibility into workforce risk, third-party exposure, and malicious communications.
For personnel risk, People Search and Falsified Resume Screening verify identities and surface risky affiliations before and after hire. Insights surfaces targeted technologies and associated employees most at risk from state-sponsored actors and provides tailored briefings to reduce recruitment risk across AI, quantum, and cyber R&D programs.
For deals, partnerships, and supply chain risk, Organizations Search maps multi-tier ownership and personnel ties for deal counterparties, investors, LPs, board members, joint-venture partners, and crypto-processing vendors. It supports M&A, investment banking, and strategic transactions by identifying foreign ownership, sanctions exposure, and hidden affiliations, and helps organizations better align with compliance requirements.
For open source software risk, OSS Search detects state-linked contributors across open source repos and assesses contributors and dependencies in tooling used in internal platforms or quantitative systems, helping prevent supply chain compromise. Shield feeds curated selectors into SIEM and DLP tools to identify, flag, and monitor geopolitical threats, including malicious emails, domains, and multilingual terms tied to state-sponsored cyber or recruitment activity targeting employees. Strider also provides expert analysis within its Intelligence Center on threats facing the financial sector—offering additional context on state-sponsored recruitment initiatives and efforts to identify and exploit vulnerabilities.
Looking Ahead
The financial services sector is operating in a rapidly changing risk environment—where the threats are geopolitical, the exposure is structural, and the cost of finding out too late keeps rising. Strider gives financial institutions the strategic intelligence to see what’s coming and act before it arrives.
For much of history, global commerce has operated under a set of stable and predictable assumptions that made both risk and relationships easier to navigate. Standard due diligence—a background check, quick database search, or conversation with a reference—was often enough to understand who you were hiring or who you were doing business with.
The relationships that mattered were visible. The risks that accompanied them were bounded. And the geopolitical environment, for all its turbulence, mostly stayed out of the way of routine commercial decisions.
Today, economic competition runs through a more contested global system—shaped by technological rivalry, supply chain realignment, and tightening constraints on the movement of capital, talent, and information. Organizations are being forced to confront questions they are not fully prepared to answer: Who actually controls the networks we depend on? Where are the exposures we haven’t examined closely enough? How do decisions that seem unrelated accumulate into systemic risk?
The challenge is a surplus of information with no clear way to make sense of it fast enough. The newly enhanced Strider Operating System (OS) was built to change that.
The Vision
“Data is oil. We do the discovery. We put the pipes in the ground. We built the refinery. And now the products go directly into the systems running the enterprise.”
That is how CEO and Co-Founder Greg Levesque describes Strider OS, the company’s new AI-native, agentic intelligence operating system built for this geopolitical era.It ingests billions of publicly available records across dozens of languages, resolves identities, maps relationships, and delivers finished intelligence into client workflows without ever touching client data. At its center is a digital twin of the industrial world, built down to the person level. Your employees, past and present. Your suppliers. Your corporate relationships traceable through open sources. All in real time, mapped continuously, so organizational leaders can act with clarity and confidence.
Inside the System
Strider OS is not a product you log into. It is a centralized intelligence orchestration layer that sits across Strider’s data, models, and products, powering everything clients use and transforming how organizations access, interpret, and act on strategic intelligence. Clients interact with the intelligence it produces, not the system itself.
In practical terms, it takes raw global data across file types, formats, and dozens of languages and turns it into clean, structured, decision-ready intelligence. The guiding principle is cognitive deload: surface what matters and why it matters, enabling faster and more confident decision-making. Research tasks that previously took weeks of manual work can now be completed with high accuracy in a fraction of the time.
Every insight produced through Strider OS is grounded in validated, original source documentation. The system surfaces facts. It does not accuse, convict, or draw conclusions. Strider’s team of subject-matter experts manage every step of the data processing and analysis.
Three Agents, One Refinery
At the core of Strider OS is an agentic data refinery. Three specialized AI agents each handle a distinct stage of the intelligence production process.
- The collection agent continuously pulls in data across more than 110,000 primary sources, including sources from within adversarial nation-states.
- The methodology agent applies Strider’s proprietary analytical frameworks to transform that raw data into structured intelligence.
- The intelligence agent takes those structured outputs and assembles them into decision-ready strategic intelligence for organizational leaders.
Together, these agents maintain a dataset of over 25 billion objects spanning dozens of languages and countries. Inside that data, the same person can appear under different names, spellings, and affiliations across different sources. The refinery resolves those identities, maps relationships between individuals and organizations, and surfaces signals continuously, at a volume and speed no human team could replicate.
The Human Layer
Strider’s subject-matter experts on PRC, Russian, and Iranian statecraft work directly alongside engineers and data analysts at every stage of the intelligence pipeline. They identify which sources best answer nation-state risk questions. They manage the AI review process. They validate outputs before anything reaches a client.
The AI models Strider uses are internal tools that review source data at scale. One step in a longer process, overseen by analysts who know when something is right and when it falls short. No model is permitted to surface a finding untethered from original source documentation.
Nation-state actors deliberately obscure affiliations, shift tactics, and hide relationships. Catching that requires people who have spent their careers studying them. AI amplifies that capacity—making human judgement even more effective.
What’s New
Deep Research Reports
One of the major enhancements powered by Strider OS is Deep Research Reports: automated, analyst-level intelligence on entities tied to the PRC, Russia, Iran, and the DPRK, delivered in hours, not days. Previously, AI-generated research outputs were long, difficult to validate, and not shaped around the specific question a user needed answered.
Deep Research Reports work differently. Users define their research questions upfront, interact with the system, and provide context to shape the output. What comes back is a structured, narrative report built for executive decision-making, combining risk analysis, market context, and operational insight in one place. Evidence cards and source citations are built in throughout, so any finding can be traced directly back to where it came from.
Earlier Visibility into Geopolitical Risk
Historically, clients received a batch of analyst-built person profiles each month. Coming soon, Strider Insights—powered by Strider OS—will deliver every profile with risk that Strider has available, providing analyst-grade profiles at scale with decision-ready intelligence. These profiles will refresh monthly as new information is collected. With expanded coverage and automated analysis, organizations will gain deeper insight across more people of interest and will be able to actively engage with their full risk landscape.
The Next Frontier
For organizations that want Strider’s intelligence inside the tools they already use, Strider is building toward open integration standards like MCP (Model Context Protocol) that will allow AI models to connect directly to Strider’s strategic intelligence. The underlying data stays the same: validated, source-backed, and governed by the same methodology regardless of where the intelligence is accessed.
The launch of Strider OS establishes the foundation for a new generation of AI-native capabilities and applications, expanding Strider’s ability to support a broad range of economic security use cases across global industry, government, and academia. But the need for it will only grow. The volume of data organizations face shows no sign of slowing, and adversarial nation-states are growing more sophisticated by the day. Legacy systems and human analysis alone cannot close the widening gap between information and understanding. By fusing open-source intelligence with agentic AI to deliver a shared operating picture at the speed this moment demands, Strider OS is defining the next frontier of strategic intelligence.
Data fragmentation, adversarial nation-states, and how Strider is building the system that enables organizations to navigate the next frontier of strategic intelligence
In a world defined by the abundance of data, the scarcest resource has become clarity.
More data has been created in the last three years than in all of prior history combined, driven largely by advances in technology like artificial intelligence. Yet, insights remain scattered across domains. Information stays siloed within systems. Critical decisions are still being made from incomplete pictures, even as the raw material to complete them sits in plain sight.
This is the central intelligence challenge of our time: connecting fragmented data and translating it into actionable information in real-time. The same technologies driving this explosion of data have also given us the tools to make sense of it. Now what’s needed is an intelligence model grounded in openness, networked collaboration, and machine-speed cognition.
The Intelligence Paradox: More Data, Less Clarity
The intelligence model that carried nations through the last century was built around a simple premise: information was scarce and the side that could find it first won. Back then, the biggest challenge was collection. Intelligence apparatuses relied on information gathered through human sources (HUMINT) and electronic signals and systems (SIGINT). The side with the best spies, deepest networks, and most classified insights held the advantage. Today, that problem has inverted.
Most of the world’s data is now being created in the public domain through the mass digitization of public records, social and news media, and AI. As a result, the challenge has shifted from collection to connection. With so much information already in the open, the advantage belongs to whoever can synthesize it fastest and act with precision.
The Public-Private Divide
Traditionally, governments and the private sector have held different halves of the same intelligence map. Governments see threats through classified intelligence about foreign actors, strategic intent, and geopolitical context. The private sector sees terrain: real-time data about supply chains, innovation networks, talent flows, and operational risks. The seam between them has become one of the most consequential vulnerabilities for democratic security in a digitally networked world.
This divide has real operational consequences. Consider how sanctions work. Governments regularly sanction foreign organizations, removing their ability to conduct commerce with domestic entities. But without visibility into how sanctioned entities and their affiliates adapt—shifting ownership structures, spinning up new front companies, rerouting capital—the action is rendered largely meaningless. It’s a real-life game of Whac-A-Mole: you think you address the threat, yet it reappears under a different identity. The same dynamic plays out across export controls, investment screening, and supply chain security.
The private sector faces an equally critical gap. The bulk of the talent, technology, intellectual property, and supply chains that power democratic economies exists outside government. This makes private sector entities prime targets for adversarial nation-states executing whole-of-society campaigns to capture these assets. Yet without the strategic context that governments hold, most are navigating those threats blind.
Democracies must adopt a new economic security model by fusing collaboration and intelligence sharing across public and private domains. The competitive advantage will not come from matching the secrecy of authoritarian regimes—it will come from mastering openness.
A New Intelligence Model
The world is entering the Intelligence Age, in which power is determined by who can see clearly, decide quickly, and act with precision.
Building an intelligence model equal to this moment requires a fundamentally new approach—one built not on secrecy and silos, but on collaboration and connection. One that fosters deep cooperation between the traditional intelligence community and private-sector innovators. One that leverages cutting-edge technology and intelligence capabilities to defend against threats and ensure continued leadership in science, technology, and global security.
Open-source intelligence (OSINT) should sit at the center of this new model.
But data alone does not create insight—structure does. When powered by agentic AI that can plan, collect, and synthesize information at scale, OSINT becomes a dynamic foundation for modern intelligence. Analytical methodologies, combined with AI-driven analysis and human judgment, transform disparate signals into strategic intelligence. These frameworks clarify how nation-state actors acquire technology, move capital, recruit talent, and exploit the seams of open societies, turning complexity into context and information into decision-ready insight.
This structured approach, however, cannot operate in isolation. No single institution can see the full picture alone. But a federated system—where each entity contributes to and benefits from a shared operating picture—can. This is the other essential component of any new model: an architecture that enables trusted data exchange and AI-driven synthesis between public and private networks, bridging national security insight with economic reality.
This should be the new intelligence philosophy: connection, not classification—gaining insight from integration rather than isolation.
The System Strider Built
Strider has built the system that enables organizations to navigate the next frontier of strategic intelligence.
Strider OS is an agentic AI-native system designed to continuously ingest, process, and synthesize unstructured global data into structured outputs. In other words, an agentic data refinery. We take the fragmented, multilingual, and constantly shifting data that defines the modern risk environment and turn it into something organizations can leverage to make faster, more confident decisions. The system resolves identities across sources, maps relationships across jurisdictions, and surfaces what is relevant based on the context of the decision at hand.
Analysis that used to require weeks of skilled human effort can now be maintained as a live picture that reflects the world at the moment a decision needs to be made. The goal is clarity at the moment of decision: what matters, why it matters, and what to do next.
What This Means for Democratic Societies
The global competition for data dominance is one of the defining battles of the 21st century. The ability to collect, process, and control vast amounts of data is now critical to economic and geopolitical power. This dynamic changes everything—how organizations investigate risk, how governments analyze and share intelligence, and how societies understand the forces shaping security, innovation, and influence.
Meeting this moment demands an all-of-society approach to intelligence. That means governments, industry, and academic institutions must operate not as separate actors, but as nodes in a shared intelligence network. They must come together to protect the talent being recruited, the technology being acquired, the intellectual property being stolen, and the supply chains being compromised.
The intelligence model for this moment must be built on data, accelerated by AI, and strengthened through collaboration across public and private domains. It will require governments and industry to master openness and finally operate from a shared picture—contributing to and benefiting from a common understanding of the landscape.
By aligning the vastness of OSINT, the speed of AI, the creativity of the private sector, and the authority of government, we can outthink and outpace closed regimes.
That is the frontier of strategic intelligence.
How the People’s Republic of China (PRC) Plans to Leverage Artificial Intelligence to Remain Competitive
NOTE: This is the second post in Strider’s series on the PRC’s 15th Five-Year Plan (FYP). The first post provided an overview of the 15th FYP’s major themes. This post examines the AI+ Action Plan in greater detail.
On March 13, 2026, China adopted the 15th Five-Year Plan (FYP) for National Economic and Social Development. Among its most consequential priorities is artificial intelligence, which the 15th FYP frames as a sweeping imperative touching every dimension of the PRC’s economy, governance, and society.
The AI+ Action Plan (AI+), first announced in 2024 and included as part of the 15th FYP, is Beijing’s clearest statement to date on how it intends to develop artificial intelligence to reshape the competitive landscape. For foreign organizations across sectors, understanding what AI+ explicitly directs and where the risks are most concentrated is essential.
AI+ spans six domains: science and technology, industrial development, consumption, public services, governance, and international cooperation. Each domain carries its own set of directives, but the underlying logic is consistent: embed AI deeply and deliberately, from laboratory research and factory floors to healthcare, education, and security. Together, they represent the PRC’s most comprehensive attempt yet to make AI a foundational element of how the country operates and competes.
Building the Foundation
The PRC is prioritizing the development of a national AI foundation built on computing infrastructure, advanced algorithms, and large-scale data. In parallel, the 15th FYP calls for strengthening capabilities in advanced chips, optoelectronic components, and industrial software—the hardware layer underpinning AI development and the primary focus of Western export controls.
The push to build this AI foundation reflects Beijing’s longstanding effort to reduce external dependence—one that has only intensified as geopolitical tensions deepened through the 14th FYP period. Supply chain disruptions and tightening technology restrictions reinforced what PRC officials had already identified as a structural vulnerability. The 15th FYP sharpens that emphasis, structuring development to operate under and adapt to those constraints as a baseline condition.
Science and Industry
In science and technology, AI+ calls for accelerating AI-driven research paradigms and technology innovation models. This includes building intelligent research platforms, assembling high-quality scientific datasets, and strengthening cross-disciplinary collaboration between AI and adjacent fields, including quantum science, life sciences, advanced materials, new energy, and 6G. The objective is to reshape how research is conducted—using AI to accelerate discovery, compress development timelines, and reduce reliance on foreign expertise and institutions.
On the industrial side, AI+ calls for embedding AI across the full spectrum of business activities, from manufacturing or service delivery to operations (distribution, human resources, marketing, and more). Energy is an explicit priority, with AI-driven innovation targeted at power system management, energy exploration, and renewable energy forecasting. Agriculture is another, with applications in bio-breeding, production management, and disease prevention. AI+ also targets service sectors, calling for expanded AI agents and intelligent terminals across software and IT services, finance, transportation, and logistics.
Society and Consumption
In public services, AI+ targets two sectors with specificity: education and healthcare. AI-powered learning companions, teaching assistants, and personalized learning tools are all mentioned, with the aim of building a new model for how instruction is delivered. The focus on education also reflects a longer-term goal of the PRC: using AI to elevate talent across the population, expanding access to quality instruction and building a more capable workforce at scale. In healthcare, the focus is on expanding AI-assisted diagnosis and treatment into primary care institutions, extending capabilities beyond major urban hospitals to the broader population. Across both sectors, the deeper aim is to reshape how essential services are delivered and prepare the country for a future in which AI is central to both.
The consumption side reflects a different ambition. AI+ calls for developing AI-native applications, promoting next-generation intelligent devices, and expanding consumer use cases through AI experience centers. These directives are aimed at embedding AI into daily life in ways that shape consumer expectations, drive domestic demand, and create new markets for PRC technology companies.
Governance and Global Reach
Domestically, AI+ expands AI into core state functions, including market regulation, workplace safety, public security, cyberspace governance, and environmental protection. It also calls for developing frameworks to manage not only people, but the AI systems operating alongside them. With new AI-generated virtual personas and intelligent robots, the PRC is building the infrastructure for AI-enabled governance. The PRC will likely seek to establish the AI governance models it develops as the global standard for AI regulation.
The PRC’s international ambitions outlined in AI+ are equally significant. It calls for establishing a World Artificial Intelligence Cooperation Organization, developing multilateral AI cooperation platforms under the Belt and Road Initiative, and establishing an International AI Application Cooperation Center. AI+ also emphasizes joint development of AI regulatory frameworks, technical standards, and ethical guidelines, alongside a globally open AI open-source ecosystem and developer community. Together, these initiatives create structured channels through which the PRC can engage with foreign institutions, technologies, and talent on its own terms.
What This Means for Foreign Organizations
The AI+ Action Plan is a blueprint for system-wide transformation at national scale. For foreign organizations, these ambitions translate into tangible and growing risks that extend beyond the technology sector itself.
The competition for talent will intensify. As the PRC scales its AI-enabled industrial ecosystems, demand for advanced technical expertise will continue to outpace domestic supply. The 15th FYP’s emphasis on attracting high-end talent, combined with programs like the “New Thousand Talents Program” targeting scientists in AI, information technology, synthetic biology, and advanced materials, means that foreign research institutions and technology companies will face more coordinated, better resourced, and sustained recruitment pressure over the next five years.
IP exposure will increase. Embedding AI across the full industrial chain means that the PRC is building data assets, training models, and developing capabilities across sectors where foreign organizations have built competitive advantage over decades. Joint ventures, research collaborations, and open-source code contributions are a few examples of pathways state actors can leverage to gain access for unfair advantage—many times without detection.
The standards race is underway. The PRC’s push to shape international AI regulatory frameworks, technical standards, and ethical guidelines is a strategic effort to shape the global order to favor its systems, supply chains, and governance models. As these standards spread globally, they could give PRC firms a lasting competitive edge while making it harder for foreign competitors to enter the market.
Conclusion
The 15th Five-Year Plan’s AI+ Action Plan is one of the most expansive AI integration directives adopted by any government to date. It reaches into science, industry, consumption, governance, and global cooperation simultaneously, and is backed by the full weight of the PRC’s central planning system. Implementation will unfold over years, but the pressure it will generate on foreign organizations is already taking shape.
The next post in this series will examine the 15th FYP’s talent agenda—specifically how the PRC’s global recruitment push is being reorganized, rebranded, and scaled—and what that means in the competition for advanced-technology expertise.
How the People’s Republic of China (PRC) Is Preparing for the Next Era of Global Competition
NOTE: This overview is the first in a series of deeper dives into the 15th Five-Year Plan’s most consequential themes.
The PRC recently adopted its 15th Five-Year Plan (FYP), outlining an ambitious set of national economic and social development priorities for the next five years.
For decades, the PRC’s “five-year plans” have served as its central governance instrument—translating leadership priorities into coordinated action across industry, technology, and society. The 15th FYP follows that established model, but reflects a more complex strategic environment, shaped by domestic economic pressures, heightened geopolitical tensions, evolving global trade dynamics, and intensifying technological competition.
To understand how the PRC’s five-year plans function—and how their outcomes are evaluated—the 14th FYP provides the most relevant baseline.
14th Five-Year Plan Recap
The 14th FYP (2021–2025) was tasked with delivering both growth and some structural reform, and by most official indicators it did. The PRC’s economy expanded at an average annual rate of roughly 5.5% over the first four years, contributing around 30% of global growth annually. At the same time, R&D investment rose nearly 50% compared to the previous plan period, supporting visible advances across sectors—from the C919 commercial aircraft and the Chang’e-6 lunar mission, to large language models and globally competitive new energy vehicles.
However, the Plan also exposed PRC vulnerabilities. Export controls, supply chain disruptions, and escalating trade tensions highlighted the limits of external dependence. Talent gaps in the digital economy widened, while the transition from investment-led to innovation-driven growth remained incomplete. The 15th FYP is, in part, a response to these constraints.
15th Five-Year Plan Process
The 15th FYP was developed through a structured, multi-year process led by the central authorities and coordinated across multiple levels of government. Preliminary research, led by the National Development and Reform Commission, began in December 2023 and included early assessments of 14th FYP implementation. By mid-2024, President Xi Jinping called for comprehensive preparations, emphasizing the need for rigorous evaluation and forward-looking planning.
In January 2025, the Chinese Communist Party (CCP) leadership established a central drafting group headed by Xi. The group convened its first plenary session in February 2025, marking the official start of the drafting phase. Six central research teams were subsequently deployed across 12 provincial-level regions to collect local input. During this period, Xi conducted multiple field visits to companies and communities, including engagements with advanced technology sectors such as the large-model AI incubator in Shanghai.
The draft plan was submitted to the fourth plenary session of the 20th CCP Central Committee, held in October 2025, where it was deliberated and adopted. Final approval was granted by the National People’s Congress in March 2026, completing the formal policy cycle.
15th Five-Year Plan Overview
The 15th FYP builds on priorities established under the 14th FYP, with a clearer emphasis on resilience, industrial upgrading, and technological self-reliance. Rather than prioritizing growth alone, the Plan positions high-quality development, real-economy strengthening, domestic demand, continued “opening-up,” and national security as mutually reinforcing pillars of the PRC’s next stage of development.
AI: A National Imperative
The 15th FYP’s “AI+ Action Plan” reflects Beijing’s intent to embed AI across every dimension of the PRC’s economy and society—from scientific research and industrial production to public services, governance, and daily life. The Plan builds a national AI foundation anchored in computing infrastructure, advanced algorithms, and large-scale data resources, while driving integration across critical sectors including energy, advanced manufacturing, agriculture, and healthcare. Beyond domestic deployment, the Plan advances a global agenda—promoting a World Artificial Intelligence Cooperation Organization, multilateral AI partnerships under the Belt and Road Initiative, and a globally open AI open-source ecosystem. As Beijing consolidates its core technological capabilities and competes for high-end talent, foreign organizations face elevated risks of talent competition, IP exposure, and the erosion of technological advantage.
Talent: The Defining Challenge
As the PRC scales its technological and industrial ambitions under the 15th FYP, demand for advanced-technology expertise will continue to outpace supply. The Plan responds with a state-led “world-class talent engine” designed to attract leading experts in priority technologies by offering autonomy, globally competitive pay, and optimal research conditions. A separate proposal calls for Beijing municipality to launch a “New Thousand Talents Program” to recruit 1,000 top scientists—primarily from the U.S. and Europe—in sectors including AI, information technology, synthetic biology, and advanced materials. At the regional level, Shanghai, Zhejiang, and Guangdong are each advancing locally tailored approaches—from dual-appointment recruitment models to non-traditional roles like “science vice presidents”—to embed talent acquisition within broader innovation ecosystems. As these efforts continue to scale, persistent workforce gaps will intensify external sourcing and heighten global competition for advanced technology talent over the next five years.
Industry: Building from Within
The 15th FYP also prioritizes building a modernized industrial system along two parallel tracks. The first focuses on upgrading traditional industries—steel, petrochemicals, shipbuilding, and electronics—pushing production toward higher-value, supply-scarce products that have historically depended on foreign suppliers. The second targets emerging industries—integrated circuits, embodied AI, bio-manufacturing, commercial aviation, and brain-computer interfaces—positioning them as new drivers of economic growth. Together, these two tracks reflect the Plan’s broader ambition to build an industrial base that is, in the Plan’s own words, “more self-supporting and risk-resilient” and capable of withstanding the kind of external pressure and supply chain disruption that has defined the past five years.
Conclusion
Our next post will examine the PRC’s AI ambitions in greater detail—what the AI+ agenda means in practice and where the risks for foreign organizations are most acute. From there, the series will turn to talent, exploring how the PRC’s recruitment push is reshaping global competition for advanced-technology expertise. Another post will take a closer look at the PRC’s industrial strategy—what it means for supply chains, emerging sectors, and the organizations that depend on them.