Ebola doctors ‘step back’ from WHO in drug trial ethics row












Support Vox’s reporting on important issues like this. Become a Vox Member today.
In the teensy Midwestern town of Braham, homemade pie capital of Minnesota, something unusual in the municipality’s computer systems knocked the city’s entire water supply offline last week.
Within a few hours, dozens of other Minnesota cities discovered that their water and wastewater utilities, too, had been compromised, most likely as part of a massive Iranian cyberattack, the kind that US officials have been warning about since the war began.
At least a dozen states have been affected by the attack, which briefly led to a flurry of small-town service disruptions, boil-water notices, and local flooding. Water wells, dams, sewers, and pipelines are some of America’s oldest and creakiest pieces of infrastructure, built long before the internet existed, and certainly long before AI made hacking much easier. While you may assume most hackers are in it for the money or for data, some have targeted critical infrastructure like water systems or energy grids in ploys for control or disruption — or worse still, as acts of war.
And, as last week’s attacks show, the nation’s water system is woefully unprepared. But how worried should you be that the very infrastructure that keeps our water taps running is, apparently, hackable?
Quite worried, indeed.
When we say the water supply got hacked, what we really mean is that someone, somewhere has broken into the computer that controls a local water treatment plant or reservoir, and is now pulling the levers, like the one that decides how much of a corrosive chemical can safely go into cleaning the water that comes out of your tap.
These levers were once manual buttons and knobs operated in-person by real live humans, meaning that — barring a natural disaster, bomb, or break-in — protecting them was about as simple as building a fence and hiring guards. Increasingly, however, these levers have gone digital, meaning that they are now remotely operable from anywhere in the world.
Those upgrades have been convenient, allowing technicians to monitor and troubleshoot problems in real time. But, in the process, they have exposed at times centuries-old infrastructure to distinctly modern vulnerabilities. Most local water systems are operated by local authorities, don’t have a dedicated IT team, and lack the money or resources to thoroughly protect themselves without some extra help. Hackers know this, which is why they’ve increasingly targeted local agencies in such attacks.
“With great connectivity comes great responsibility,” said Joshua Corman, founder of I Am The Cavalry, a nonprofit focused on helping critical infrastructure withstand hackers. And yet, even when it comes to critical services like water, “our dependence on connected technology is growing faster than our ability to secure it.”
About 97 percent of water systems are small, run by local agencies that often barely lock the proverbial front door. America’s water system is like an expensive heirloom bicycle that’s been left on a busy street, protected by only the flimsiest of padlocks. And that very vulnerability has made tiny towns like Braham prime targets for faraway adversaries. Accessing the computers that operate most water systems — known as programmable logic controllers or PLCs — is often as simple as entering a username and password on a public-facing webpage. Sometimes, there is no real password at all, because PLCs were initially intended to be accessed only within locked, secure facilities, not on the open internet. If the US wants to avoid a far more severe version of what happened last week, then it will need to start taking the security of tiny water systems like Braham’s seriously.
“Any sociopath from anywhere in the world can see these things on the internet,” said Corman. And in the case of last week’s attacks, “these were devices with no password, no firewall or VPN shielding them — they just had to log in” as whoever the intended operator was, and just like that, they were inside a local water plant.
When municipalities began hooking up their old water and wastewater systems to the internet — a trend that accelerated during the pandemic as water operators, like everyone else, adapted to remote work — cybersecurity was rarely front of mind, neither for individual utilities nor for regulators as a whole.
“We have more cybersecurity regulations for your credit card than we have for the nation’s water supply,” said Corman. Only recently have some municipalities begun to take steps to decrease the exposure of their water plants to hacks. In March, New York state, for example, launched a set of grants and basic cybersecurity regulations mandating security training for all water operators.
Basic cybersecurity hygiene isn’t always enough. More than half of all credit card holders have been hacked, even with the help of mandatory firewalls and data encryption. You can imagine how vulnerable our water must be without the assistance of such guardrails. In a worst-case scenario, a malicious actor could quite literally open the floodgates, as Russian hackers did to a Norwegian dam last year. They could poison the tap water, as a still unidentified hacker almost did in Florida in 2021, dialing up the levels of sodium hydroxide used at a water treatment plant by over 100 times its normal levels. In a severe scenario, they could indefinitely cut off access to all water entirely.
The good news is, none of this happened last week. Nobody died, nobody lost water for more than a few hours, no fire hydrants ran dry, and no hospitals were forced to cut off their dialysis machines (which can use more than a hundred gallons of water per treatment session). There’s no need to panic, and your drinking water is almost certainly still safe to drink, assuming it was safe before. Even the city of Braham, within a few hours, was able to bring its water tower back online, pumping groundwater back to its 1,800 residents.
If you’ve watched the Julia Roberts and Mahershala Ali-starring thriller Leave the World Behind, in which a cyberattack apocalyptically spoils a family vacation, then you might have some idea of where this story could go.
Cyberattacks on critical infrastructure can be extraordinarily dangerous, but thankfully, none have directly cost lives or severely disrupted services in this country so far. If the US wants to keep it that way, that will mean doing more to help small cities like Braham adapt and better monitor for potential threats. As it stands, of the roughly 151,000 water facilities in the US, only about 420 participate in voluntary information sharing on their own cybersecurity practices, says Corman, who has been leading his own project that recruits volunteers to give free cybersecurity support to water utilities in the nation’s roughly 6,000 hospital towns, where a disruption could be particularly deadly.
Cybersecurity experts like Corman believe that hackers from other nations like China have already quietly established cyber intrusions in countless local US utilities, water systems, and power grids, lying in wait to attack or act as leverage if a conflict arises.
Unfortunately, the Trump administration has hardly treated last week’s attacks as symptoms of a system in need of much broader strengthening, at least in its public statements. “I think Minnesota is behind it. You know who’s behind it? Minnesota,” the president baselessly claimed during a Cabinet meeting last Friday. “I think the governor is behind it. I don’t think there was an Iranian cyber attack.”
Just a few months ago, he proposed $707 million in cuts to the US Cybersecurity and Infrastructure Security Agency (CISA), the agency responsible for protecting the nation’s infrastructure from cyberattacks. He did so, at least in part, out of anger over the agency’s role in confirming the validity of the 2020 election results. If Iran is, indeed, responsible, for the recent water system intrusions, all of this means that Trump has effectively made us more vulnerable to the consequences of a conflict he initiated.
At the end of the day,“nation-state hackers do not respect the jurisdictional lines separating federal, state, and local responsibility,” Jen Easterly, who led CISA under the Biden administration, wrote in the New York Times this week. “They search for the most vulnerable way to disrupt American life, and too often they find it in small communities that lack the resources to defend themselves.” Easterly’s role has remained vacant for the past 18 months.
Kurt Gaudette, a senior vice president at the cybersecurity firm Dragos, told me that water systems have got to get into the habit of monitoring their networks for suspicious activity. Most power utilities have begun doing so in recent years, with some bipartisan backing from Congress.
In some cases, however, the most cost-effective and safest way to avoid a repeat of last week’s mess might be to unplug the most vital controls — like the one that decides the chemical levels in a water treatment plant — from the web entirely.
As Corman puts it, “if you can’t protect it, disconnect it.”




Both Washington and Silicon Valley are in the midst of a collective freak-out over China’s recent advancements in artificial intelligence.
The latest round of consternation was triggered this month when a little-known Chinese AI startup called Moonshot released a new large language model called Kimi K3. The conventional wisdom had been that the leading AI models developed by companies like OpenAI and Anthropic were between six to 12 months ahead of their Chinese competitors. Kimi dashed those assumptions: now, analysts say American companies may be as little as two to three months behind.
Dean Ball, a former Trump administration official now with OpenAI, warned in a bleak post on X that models like Kimi K3 could lead to a world of “full AI communism” and a “dystopian hellscape” of AI under full government control.
Policymakers have worried for years now about China gaining an edge over the US in the AI race. Both the Donald Trump and Joe Biden administrations took steps to slow China’s AI progress, including blocking the export of the most advanced US semiconductors.
The White House is already reportedly considering taking steps to ban “open-weight” models — models that are easier to adapt for a user’s own purposes — like Kimi K3 in the United States. The Trump administration has also accused Moonshot of using the unauthorized “distillation” of one of Anthropic’s models — basically using another model’s outputs to train itself rather than raw data — as well as gaining access to blacklisted Nvidia chips in Thailand.
But often lost in the debates about what to do about China’s accelerating AI capabilities is the question of why the US cares about this at all. Obviously, the American companies developing the latest frontier models care about maintaining their edge, but why should it matter to Americans if the chatbot in their pocket was developed in Silicon Valley or Shanghai? And perhaps even more so, why should it matter what chatbots people in Nairobi or Brussels are using?
The concerns in the US about Chinese AI generally fall into three broad buckets: cybersecurity concerns; military and national security concerns; and human rights or democracy concerns.
For the moment, concerns about who is winning the AI race can feel a bit abstract, but as AI becomes more embedded into governments, militaries, and ordinary people’s lives, the difference will start to be felt in a much more material way at both a national and personal level. In general, there is a growing sense that it matters which of the world’s vastly different superpowers builds the technology that could transform everything.
“People’s relationship with AI is becoming foundational to how they live their lives, so the choices people make about whose model they use and where they are physically hosted, as they share some of their most intimate secrets and ask for life advice and business guidance, and run an increasing share of their life — those are incredibly important,” said Ryan Fedasiuk, a former State Department technology adviser now at the American Enterprise Institute. “It’s a contest between the United States and China to define the operating systems through which people live and work.”
Here’s what else America loses if it loses that contest.
The concerns about using Chinese AI are in some ways a repeat of the concerns over Huawei, the Chinese telecoms firm that built much of the world’s 5G internet infrastructure, but which the US government banned from operating in the United States during the first Trump administration over concerns that the Chinese government could intercept information transmitted over these networks.
Today, the concern is that many firms are increasingly integrating Chinese AI models into their systems, both because they are often cheaper and because they are “open-weight.” (“Weights” refer to the setting an AI model uses to process a user’s inputs. “Open-weight” models make these publicly available for users to tinker with, rather than charging for access.)
There are some indications that Americans using Chinese AI models are already vulnerable. A Booz Allen study from earlier this year tested four Chinese models commonly used by US developers and found that three of them generated software with far more “hidden vulnerabilities” that could be exploited by hackers than their US counterparts. There’s no proof that the models were doing this intentionally, but the study did find that the models were “changing their behavior depending on who the user seemed to be or what country the request referenced.”
AI can also be used to carry out cyberattacks. Although nearly all the leading models have safety protocols meant to prevent this, they’re not bulletproof. Even Anthropic’s Claude, generally considered one of the most secure models, was adapted by Chinese hackers last year to engage in cyber espionage. The open weights of the leading Chinese models could make it even easier to strip out the safety protocols.
The simplest and most obvious argument for why AI matters for American national security is that it’s all too conceivable that the US and China could be at war in the years to come, and AI could be a major factor in determining who wins.
The conflicts in Ukraine, Gaza, and Iran have shown that modern militaries are already extensively using AI for intelligence collection and targeting. Semi- or fully-autonomous drone swarms are a major component of US plans for repelling a Chinese invasion of Taiwan. Then there’s the risk of AI being used to generate new bioweapons or other dangerous threats.
US experts believe China has pursued a “military-civil fusion” strategy, encouraging the People’s Liberation Army and Chinese defense contractors to collaborate closely with civilian technology companies and research institutions in order to gain an edge in military AI applications like intelligence analysis and drone swarms. It’s difficult to know exactly which of these capabilities China is focusing on, but procurement data suggests leading Chinese technology firms like Deepseek and Alibaba are involved in work with potential military applications. Analysts also accuse China of using outputs from US models like ChatGPT and Claude to train AI systems that could help develop China’s defense capabilities.
And that’s just conventional weapons. The US government has alleged that Chinese labs have “continued to engage in biological activities with potential [bioweapon] applications” amid concerns that artificial intelligence could help make such weapons more sophisticated and deadly.
Last year, it was reported that Miiloo, a fuzzy children’s plush toy with a built-in AI chatbot, would, if prompted, happily tell users Chinese Communist Party talking points like “Taiwan is an inalienable part of China.” The hubbub over Miiloo reached the US Senate floor. While it’s hard to imagine that many users were really asking Miiloo to help clear up East Asian territorial disputes, the affair illustrated much larger concerns about the dangers of letting AI models built by an authoritarian government with one of the world’s strictest censorship regimes become the global standard.
Chinese generative AI tools are legally required to uphold the country’s “core socialist values,” according to a document published by its national cybersecurity standards committee. So it’s little surprise that DeepSeek, the Chinese chatbot that sent shockwaves through the US tech industry in 2025, politely declines to answer when you ask it what happened on June 4, 1989, in Tiananmen Square.
It’s not just that Chinese AI could help shape the political narratives absorbed by billions around the world, at a time when US soft power is ebbing and surveys show people in many countries already now have a more positive view of China than the United States.
The Chinese government is also increasingly integrating AI into its own censorship and surveillance apparatus, and is exporting tools like facial recognition technology to other authoritarian countries.
The fact that under Xi Jinping, China’s government was centralizing power and becoming more, not less, authoritarian in the years leading up to the recent advances in AI are a major factor driving the mistrust in its technology.
“I think many of the sincere arguments about the risks of these models and what China would do with them stems from the coercive authoritarian approach of China’s current leader,” said Mieke Eoyang, former US deputy assistant secretary of defense for cyber policy. “I don’t think we would be having this conversation in the same way with someone like [China’s previous leaders] Jiang Zemin or Hu Jintao.”
It is a serious concern if models built to conform to the values and political priorities of China’s current government become the global standard. But some are skeptical of the idea that human rights and democracy should be the goal of AI competition, worrying that the damage has already been done. The premise of that idea has gotten “shakier in recent years,” says Steven Feldstein, a senior fellow at the Carnegie Endowment and author of the book The Rise of Digital Repression. Under this administration, the US has cut support for democracy and human rights programs overseas, and often allied itself with authoritarian governments. Then there’s the fact that at least one leading chatbot often seems to mimic the racist and antisemitic views of the world’s richest man who is also an ally of the current president.
While it’s still true that Chinese AI reflects the authoritarian values and priorities of China’s leaders, Feldstein notes, “this idea that the US is standing at the forefront of protecting and advancing democracy, human rights, that we’re not sort of there to manipulate information or to push a narrative agenda that reflects the ideological preferences of its leaders, has started to fray.”
There’s also a set of concerns around the topic of “artificial general intelligence,” the hypothetical point at which AI exceeds human capabilities and is able to improve itself. The concern, expressed by both US government commissions and senior officials in both administrations, is that China is “racing” toward AGI and that whichever country achieves it first will have a massive geopolitical advantage. This is the type of thinking behind invocations of the nuclear-era Manhattan Project to justify massive government investments in AI development.
Chinese leaders do not appear to view AI competition this way. “The US conversation around this is much more ‘AGI-pilled’,” says Jeffrey Ding, a professor at George Washington University and expert on US-China technology competition. “The concern here is that we are very much on the brink of this explosion of more and more powerful AI that leads to it dominating everything.” Chinese leaders, on the other hand, “generally see AI as a productivity tool.”
This is not just a Beltway or Silicon Valley concern. A recent Pew survey found that 43 percent Americans believe it is very important for the US to remain the leader in AI development, versus 22 percent who said it was not that important. Interestingly, the survey also found that most Americans believe China is already ahead on AI, though the expert consensus is that it’s still slightly behind.
“We’ve gotten so used to the fact that the US has been the leading player in technological revolutions from like mobile internet to the internet era, so it’s worrying to feel we may no longer have that dominant strength,” said Selina Xu, China and AI policy lead in the office of former Google CEO Eric Schmidt.
Even if there’s some consensus that AI competition is a priority, there’s less agreement on how to go about it. The challenge, Xu says, is “How do you manage the very concrete national security risks that come from competing with China on AI, but not turn technological competition into blanket protectionism?”
Often, the policy responses to this challenge have been contradictory.
The Trump administration, in its first term, pioneered the policy of restricting the export of the most advanced semiconductor chips to China, but Trump undermined that policy last year by permitting Nvidia to sell its advanced H200 chips there. The move flummoxed China hawks in Washington and went against the preferences of AI developers like Anthropic, but probably had a lot to do with lobbying by chip maker Nvidia’s Jensen Huang, CEO of the world’s most valuable company.
In some cases, the US may be inadvertently making China’s models more appealing. In June, the Trump administration placed export controls on Anthropic’s advanced Fable model. This move prompted the company to take the model down for all users and led to the first time that AI capabilities meant for the global public took a step backward.In response, French President Emmanuel Macron warned, “We will not buy any model made by [US AI] companies if from one day to the next you can just turn off the switch.” Chinese models are hardly immune from concerns about kill switches or back doors, but if both governments involved in the AI race are seen as meddling, customers may just opt for whichever one is cheaper.
The latest flashpoint in the debate concerns the reports that the administration is considering banning open-weight models. This prompted an open letter from dozens of leading tech companies including Nvidia and OpenAI defending access to these models as necessary for helping the US maintain AI leadership. Advocates note that open-weight models can help respond to vulnerabilities as well as create them: When a rogue OpenAI model recently hacked into the startup Hugging Face’s systems, Hugging Face’s engineers used an open-weight model developed by China’s Z.ai to analyze the attack.
Despite the frequent comparisons, AI is not a national security competition like the early days of nuclear weapons or the space race. It’s a technology with potentially grave national security implications, that’s also used by millions of people around the world to plan their Tuesday night dinner or help with their homework. The log-in for Claude is not carried by a military officer at the president’s side. And much of the important work on developing these new technologies is being done by private tech companies, not government labs or defense contractors.
It may be that AI capability will help determine which country has the edge in the 21st century. It may also be that the benefits of these capabilities will be shared: Chinese companies might be no less capable than their American counterparts when it comes to developing new medications or clean energy technology.
The challenge of crafting technology to prevent a “dystopian hellscape” is to not accidentally make the existing world worse.


