Home

Donate
Perspective

Trump and Xi Should Talk About Worms

Howard Fei / Sep 22, 2026

US President Donald Trump and Chinese President Xi Jinping attend a welcome ceremony at the Great Hall of the People on May 14, 2026 in Beijing, China. (Photo by Alex Wong/Getty Images)


Republish

When United States President Donald Trump and China President Xi Jinping meet in Washington, D.C., on Thursday, artificial intelligence will loom over the summit as a central arena of strategic competition between the two countries. Ahead of the meeting, US and Chinese officials considered establishing a “hotline” for serious AI incidents that threaten national security. AI-enabled adaptive computer worms offer a concrete example of the kind of crisis such a mechanism could help manage. By revising their attack strategies as they spread, such malware could exploit vulnerabilities at scale and place sophisticated cyber capabilities within reach of non-state actors. The summit therefore offers an opportunity for Washington and Beijing to begin building a framework for cooperation against an emerging threat that could endanger both countries.

Computer worms are a type of malware that can self-replicate and autonomously spread across networks. Once deployed, they can move far beyond their initial targets and cause widespread damage. In 2017, Russia deployed a computer worm known as NotPetya against Ukraine. The attack disrupted Ukrainian government agencies and critical infrastructure before spreading beyond the country through the networks of multinational companies operating there. NotPetya compromised at least 2,000 organizations in over 60 countries, including Russia itself. It caused over $10 billion in damage, making it one of the most destructive cyberattacks in history. NotPetya’s global spread demonstrated the transnational risk posed by computer worms, as an attack intended for a single target or country can inflict damage worldwide.

The damage caused by computer worms could become far more severe as advances in AI give them new capabilities to adapt, evade defenses, and exploit systems as they spread. Traditional worms spread automatically, but their attack logic is largely hard-coded and predetermined before deployment. Attackers must anticipate the vulnerabilities and system configurations a worm will encounter in advance, and its spread can stall when those assumptions prove incorrect. In June, researchers demonstrated a proof-of-concept adaptive computer worm, powered by a large language model, inside an isolated test network. Unlike traditional worms that rely on predefined attack logic, the worm could reason about the systems it encountered, generate and revise attack strategies, exploit vulnerable machines, and continue self-replicating without human intervention. It could also run on a locally hosted open-weight model, allowing it to operate without relying on a cloud service or commercial AI provider. As the worm spread, compromised machines with sufficient computing power could provide additional resources for reasoning and further attacks.

The geopolitical significance of AI-enabled adaptive worms lies in their potential to enable non-state actors to conduct cyberattacks at a scale previously beyond their reach. By reducing the need for human involvement in each individual compromise, adaptive worms could allow attackers to carry out tailored attacks across far more systems than a team of human operators could manage. AI is separately reducing the human effort required to build such tools. The Palo Alto cybersecurity firm Calif reported that AI helped its researchers develop a computer worm, called WeWorm, that could hijack WeChat accounts through unanswered calls in about a week, work that would previously have taken a larger team months. AI-enabled adaptive worms’ ability to run on locally hosted open-weight models could further lower barriers by reducing attackers’ dependence on cloud-based AI providers and limiting the effectiveness of safeguards such as service refusals, account suspensions, or API restrictions. Together, these capabilities could make sophisticated cyber operations more accessible to cybercriminal organizations, terrorist groups, and other non-state actors that previously lacked the resources or expertise required to carry them out.

AI-enabled adaptive worms could outpace existing approaches to cyber incident response. Investigations, attribution, and law-enforcement responses generally occur after an attack has begun and can take months or years. Historically, this delay has been partly manageable because defenders can often contain or disrupt malware while those processes continue. The WannaCry outbreak, for example, was curtailed after researchers discovered a kill switch, while botnets can often be disrupted by seizing their command-and-control infrastructure. AI-enabled adaptive worms could make these containment strategies far more difficult. A worm capable of revising its attack strategy as it spreads could continue propagating even after defenders patch the vulnerability it initially exploited. Its ability to operate from compromised machines also makes centralized disruption more difficult, since disabling a cloud service or command-and-control server would not necessarily stop the worm’s proliferation. Once such a worm is spreading autonomously, identifying or arresting the original operator may likewise do little to halt the attack.

The transnational nature of AI-enabled adaptive worms creates a common interest in preventing their deployment and containing their spread. Both the United States and China have already experienced the consequences of large-scale computer worm attacks. During the 2017 WannaCry outbreak, China’s national computer emergency response center reported that roughly 18,000 Chinese IP addresses were affected, with disruptions reaching universities, energy systems, and other critical networks. The US was also affected, with the Department of Health and Human Services reporting significant operational disruptions at two large, multi-state hospital systems. WannaCry demonstrated how self-replicating malware can cross borders and disrupt systems far beyond its initial targets. AI-enabled adaptive worms could magnify this mutual risk, threatening both countries regardless of where an attack originates or whom it initially targets.

AI-enabled adaptive worms could provide an early test of whether limited U.S.-China cooperation on AI governance is possible. Preventing non-state actors from gaining access to the most capable AI models is one area where the two governments have already signaled shared interest. During the May 2026 U.S.-China summit in Beijing, Treasury Secretary Scott Bessent said the two sides would establish a protocol for best practices aimed at preventing non-state actors from exploiting the most powerful AI models. This week, US and Chinese officials proposed establishing a bilateral notification mechanism for serious AI-related incidents that pose national security risks. Such a “hotline” could allow cybersecurity authorities to quickly exchange information during a major outbreak without waiting for attribution. Trump and Xi could go further by agreeing to limits on the use of AI-enabled adaptive worms against civilian systems and critical infrastructure, while also pledging to investigate and disrupt non-state actors that deploy them. Together, these measures could create a limited framework for preventing and responding to AI-enabled adaptive worms without requiring broader agreement on AI governance.

Reaching even a narrow agreement would require overcoming significant mistrust between Washington and Beijing. AI cyber capabilities are inherently dual-use, since the same capabilities that can help identify vulnerabilities and strengthen cyber defenses can also support offensive operations. Yet the US and China have already shown that broader strategic competition does not preclude agreement on specific AI risks. During President Joe Biden and Xi’s November 2024 meeting, the two leaders affirmed that decisions to use nuclear weapons should remain under human control. The meeting did not resolve broader disagreements over AI or national security, but it demonstrated that the two countries could establish a narrow principle around a single high-consequence AI risk. Cooperation on AI-enabled adaptive worms could extend this approach to the proliferation of advanced cyber capabilities to non-state actors. Such cooperation would not resolve broader disagreements over AI governance, but it could establish another precedent for addressing risks emerging from this technology.

This week’s summit offers a rare opportunity to act before a shared risk becomes a shared crisis. Conventional computer worms have already caused billions of dollars in damage, and AI could make future attacks significantly more destructive and difficult to contain. The threat from AI-enabled adaptive worms is no longer theoretical, but such systems have not yet appeared at scale in real-world attacks. That gives Washington and Beijing a narrow window to establish guardrails and put the proposed AI emergency “hotline” into operation before it is urgently needed. The first major AI-enabled worm attack should test US-China preparedness, not mark the beginning of US-China cooperation.

Support Tech Policy Press
If you've found our work helpful, consider supporting us.

Authors

Howard Fei
Howard Fei is a master’s candidate at the Johns Hopkins University School of Advanced International Studies (SAIS), where he focuses on AI policy and US-China technology competition. He currently serves as a teaching assistant to Dr. Ben Buchanan, Former White House Special Advisor for AI. Prior to ...

Topics

Related

Podcast
AI Governance Reaches Crisis Point Ahead of Trump-Xi SummitSeptember 13, 2026
Perspective
US, China Psy-Op Accusations Signal Deep Distrust on AI RegulationSeptember 21, 2026