What happened
CFR published a major report by Matthew Ferren, Adam Segal and Rush Doshi (published September 17, 2026) arguing that China has built a hacking apparatus that is 'pre-positioning malware and maintaining dormant access to critical systems' in US water, energy, telecom and transport networks, while the United States 'lacks the defenses or the credible deterrent' to change that calculus. The report sets out a four-pillar strategy — building shared visibility into Chinese campaigns, imposing costs on Chinese operations, enhancing network resilience, and rebuilding federal capacity — supported by eighteen specific recommendations with agencies and congressional committees mapped in an appendix. It treats frontier AI as the accelerant: 'The emergence of artificial intelligence (AI) models with advanced coding and cybersecurity capabilities has injected new urgency into this competition… The United States currently leads China in AI capabilities, but only by months,' and it calls for AI-enabled defensive hardening, mandated information-sharing by major tech providers, and vendor liability for insecure products.
Why it matters
The AI section reframes the compute/export-control debate around cyber tradecraft and asks critical-infrastructure operators and the tech vendors that supply them to absorb mandatory data-sharing, threat-sensor and liability obligations — board-relevant exposure changes ahead of the Trump–Xi summit.
Action needed
Map the report's resilience and shared-visibility recommendations against your own critical-infrastructure footprint and vendor contracts; prepare position for mandatory information-sharing and software-liability policy shifts.