DeepSeek CEO Liang Wenfeng's leaked call has several notable statements on U.S.-China competition.
He acknowledges China is severely compute constrained, says DeepSeek still much prefers NVIDIA over Chinese chips, and implies they're actively buying “non-compliant” chips at a premium if necessary.
Some highlights (note this is based on a transcript, the original audio hasn't surfaced):
How much compute they have. Liang [01:15:12]: "What is our gap with the US? Really the gap is just one thing: resources. We don't have that many cards — our card count is still fairly small. We currently have about 20,000 cards of H-equivalent compute, and most of it just arrived — in the last one or two months — with many machines possibly still on the way. Our total compute last year was fairly small; this year we are expanding it very aggressively."
For reference, leading US AI labs like Anthropic and OpenAI have access to millions of H100e.
They're still trying to buy NVIDIA rather than Chinese AI chips. [01:15:12]: "Over the coming months we'll buy machines in large batches — basically all NVIDIA. How many cards do we need? Right now, the more the better. Our strategy is: at a reasonable price, however many cards we can buy, we buy. If I spent all the money within half a year, I'd consider that a good thing. In practice, spending that much money is very hard — you can't buy that many cards, they're hard to get, and prices are high."
How they buy NVIDIA under export controls. [01:26:41]: "Our only worry is not being able to buy that many cards. If we could turn all the money into cards, we would not hesitate to turn all of it into cards — and we're willing to pay a certain premium for that." [01:56:36]: "In a normal commercial environment where I could buy NVIDIA cards, domestic substitution would be quite hard; but with NVIDIA cards unbuyable, everyone has no choice but to work on domestic chips." And [02:53:59]: "对我们来讲,我们可以买一些不合规的卡" — "As for us, we can buy some non-compliant cards."
On Huawei chips [02:53:59]: "Our purpose in buying Huawei 950s is really to help Huawei get the ecosystem right. 16,000 Huawei 950s are equivalent to only 4,000 B-series cards — not a big quantity, not very significant. Not enough to train a next-generation model; only enough to train our current generation." But elsewhere he sounds more optimistic [01:56:36]: "Huawei's 950 supernode can fully substitute for NVIDIA's GB200/GB300 in performance and price. Everything a GB300 can do, the Huawei supernode can do, with the same latency. The only cost: four Huawei cards equal one NVIDIA card, plus a two-year lag." Sounds like both a quality and production quantity issue.
His assessment of the U.S-China gap. [02:53:59]: "Simply put: two years behind the US, done with one-twentieth of the US's compute. That narrative is one to two years behind, on 1/20th of the compute. Going forward we want to rewrite that narrative — still a fraction of their compute, but shrink the gap to six months, three months. We might even surpass them in some specific areas."
Why Chinese companies won't be able to catch up anytime soon. [02:53:59]: "But with total compute still an order of magnitude apart, comprehensively surpassing them is unrealistic." [01:26:41]: "To train a model as large [as the top US one], we'd need 50,000 GB300s — or with Huawei 950s, 200,000 cards. And that's training only, not counting research. Even if we spent the entire 50 billion [¥50B = $7.4B], we couldn't train it — even if we could stack the compute together, we couldn't afford to run it." [03:05:48]: "Right now we're certainly stuck on production capacity — this year, next year, the year after, probably still stuck on capacity — but five years out I'm fairly optimistic."
Full transcript (Chinese, archived): https://t.co/H2qOrToOrV
All quotes translated by 5.6 Sol.
@mavroudisv Not sure, I feel like it depends on what the prompting was. E.g. I can imagine versions of innoculation prompting where it wouldn't be that unreasonable to conclude that hacking into the repo with the answers was allowed.
Woah, seems like an unreleased OpenAI model made its way out of its testing environment, hacked into HuggingFace (both using zero day vulns), all to solve a benchmark it was being tested on.
We're partnering with @huggingface to investigate an unprecedented security incident.
Cyber-capable OpenAI models compromised Hugging Face production during a benchmark evaluation.
Sharing preliminary findings to help defenders understand emerging risks:
https://t.co/CIor15y9xk
Also interesting that HuggingFace wasn't in OpenAI nor Anthropic's trusted access programs.
Given just how doggedly current models try to achieve their goals, it seems predictable they'd target HuggingFace.
Though actually, based on current reporting, a bit unclear whether the model was behaving in a misaligned way. Presumably OpenAI didn't intend for the model to access the open internet and hack a legitimate business, but the instructions may have been ~"do whatever it takes to solve this task."
so our model reward hacked during an eval, decided to look for the answer on hugginface, circumvented sandboxing, did lateral movements to get internet and found a zero-day for remote code execution on hugginface servers to get the solution to the eval. just another tuesday.
Why is the phone signal in the UK so slow?
“the explanation is down to the same reason so much else in our national life is paralysed: planning”
By @TomTugendhat
In a hotel room in northeast Nigeria, I opened a leading AI chatbot, turned my laptop toward a former Boko Haram commander, and asked if he'd used it. He nodded.
"You type in the question… like 'How can I build a bomb?', and then it tells you how. It is like a human robot. We used it a lot."
My new study on how the jihadist terrorist group Boko Haram uses frontier AI with @CamAISciPolicy, covered today in @nytimes 🧵/9
Excited to announce CASP:
Cambridge University's Programme on AI Science & Policy, where I will serve as Technical Research Lead.
We kick off with Antonia Jülich’s study on terrorist use of AI, covered by @nytimes today.
@tilmanbayer@GovAIOrg I expect that you'll have *some* Brussels Effect when it comes to general-purpose AI systems, largely for the reasons described here: https://t.co/KxaPS4Ql1t
People sometimes round the influence of all countries but the US and China on AI down to zero.
In a new piece, @stephenclare_ and I argue that's a mistake: middle powers have already shaped frontier AI development, and could do much more.
Six claims:
Agreed that big part of why middle powers had a comparably big influence on frontier developers up until 2025 was that e.g. the US wasn't really focused on it.
I still do think middle powers can have significant impact on the behaviour of these actors, most clearly via uncovering information that would inform frontier companies and great AI powers.
I also think that e.g. the EU can have some significant influence on how frontier companies behave via regulation on what models can be on their markets. Agreed there's more chance of retaliation if you e.g. try to make demands on how companies use their models internally. But I think it will make sense for e.g. the EU to make demands re what quality of CBRNE and cyber safeguards should be on publicly available models.
@thomasmetcalf 1. Agreed! Would love more thoughts on that. In this piece, we just offer some high-level takes.
2. Agreed that concerns about sustainability is likely a blocker for EU datacenter construction, though not sure how it compares to other blockers (e.g. bureaucratic inertia)
Not sure where the disagreement is here.
I don't think it makes sense for many (any?) middle powers atm to issue threats about how they'll cut off access to some part of the AI supply chain unless some other state (the US or China) does something to e.g. rein in their AI companies.
Part of the point of the piece is that there are plenty of AI governance that doesn't look like "force the US and China" to take certain actions.