CIA Names Chinese AI, Chip Firms as Spy Targets; China Threatens US Companies with Espionage Law

September 13, 2026:

CIA Names Chinese AI, Chip Firms as Spy Targets; China Threatens US Companies with Espionage Law
CIA Director John L Ratcliffe testifies Senate
CIA Director John L. Ratcliffe testifies during a Senate Intelligence Committee hearing on worldwide threats in the Hart Senate Office Building on March 18, 2026 in Washington, DC.
Kevin Dietsch/Getty Images

China’s Ministry of Commerce formally threatened legal action against American companies operating on Chinese soil on Friday, invoking the Counter-Espionage Law as its retaliatory instrument of choice — a direct response to CIA Deputy Director Michael Ellis’s public declaration last week that Chinese companies in artificial intelligence, semiconductors, and biotechnology are now legitimate CIA intelligence targets. The ministry formally invoked espionage law powers against American companies, marking one of Beijing’s most direct responses to a US intelligence declaration in years. The confrontation arrives with the September 24 White House summit between President Donald Trump and Chinese President Xi Jinping twelve days away, adding a sharp intelligence-community dimension to an already complicated diplomatic agenda.

What CIA Deputy Director Ellis Actually Said: Why It Stands Out

Ellis made the declaration at the Billington Cybersecurity Summit in Washington on Tuesday, September 8, in remarks that were unusually direct for a serving intelligence official. The Federal News Network covered his Billington remarks directly. The core argument he advanced is structural: because China does not have a genuinely independent private sector — the Communist Party can absorb or direct any Chinese company at will — commercial Chinese firms in strategically important industries are not meaningfully different from state actors for intelligence purposes.

“Our economy is intertwined with theirs,” Ellis told the conference, framing the interdependence as a security vulnerability rather than a shared stake in stability. “The CIA has to respond differently.” He argued that intelligence about AI, semiconductors, and biotechnology requires different collection expertise and different workforce skills from traditional military and political intelligence.

What makes the remarks notable is less their content — CIA directors have been calling for deeper economic intelligence since Robert Gates raised the subject in 1991 and James Woolsey committed to it in 1993 — than their candor. Previous officials carefully avoided naming commercial firms, rather than state entities, as explicit intelligence targets. Ellis named sectors and justified the targeting publicly, stripping away what China’s Ministry of Commerce would later call the “fig leaf” of plausible deniability.

The declaration also reflects a documented institutional shift, not merely a policy statement. CIA Director John Ratcliffe announced a “fundamental reshaping” of the agency’s entire technology approach at an Amazon Web Services summit in Washington on June 30, creating a new Directorate of Mission Systems, cutting acquisition timelines from two years to six months, and completing roughly 400 technology contracting deals in six months. Ellis’s September remarks are the collection-mandate articulation of a reorganization already underway.

Beijing Responds with Formal Protest and Legal Threat

China’s Ministry of Commerce wasted little time after Ellis’s Billington appearance. In a formal statement released Friday, a ministry spokesperson condemned the remarks in language notably blunter than standard diplomatic protests.

The statement characterized the CIA’s declaration as exposing “the bandit logic of hegemony in broad daylight.” It accused the United States of “deliberately undermining fair competition” and “openly trampling on the norms of international trade,” invoking the phrase “Cold War mentality” — a formulation Beijing reserves for what it characterizes as US actions that frame economic rivalry as a security threat rather than legitimate competition.

But the ministry did not stop at rhetoric. It explicitly invoked two legal instruments as the basis for potential retaliation: the Counter-Espionage Law and “other regulations.” China, the spokesperson declared, possesses “the firm resolve and sufficient means to take necessary measures” against US espionage activities targeting Chinese companies. China’s foreign ministry separately characterized US intelligence actions as interfering in “normal economic competition,” warning that such interference “severely damages the expectations of businesses worldwide.”

For any American company with employees, assets, or operations in China, that language is not abstract. It signals that Beijing may reframe ordinary business activities — data collection for due diligence, market research, financial analysis — as espionage-related conduct justifying enforcement under a legal framework that has already been used to raid foreign firms.

China’s Counter-Espionage Law: What It Actually Authorizes

The Counter-Espionage Law Beijing invoked is not a narrow instrument. The Library of Congress analyzed the 2023 revision in detail. First enacted in November 2014 and substantially revised in April 2023 — with the revisions taking effect July 1, 2023 — the law was expanded to cover not just “state secrets” but all national security documents and data, a category Chinese authorities have discretion to define broadly.

That 2023 expansion alarmed foreign legal counsel precisely because it removed a clear definitional floor. Under the original law, a firm’s exposure depended on whether it touched classified information. Under the revised law, the question is whether the information relates to “national security and interests” — a category that Chinese authorities have discretion to define broadly. Legal analysts at Crowell & Moring, De Brauw Blackstone Westbroek, and the Library of Congress all noted that ordinary commercial due diligence could, in theory, fall within the revised law’s scope.

The revised law also expanded enforcement powers directly. Pillsbury’s analysis of key provisions notes that Article 28 allows state security bodies to summon individuals for questioning, while Article 8 requires all organizations and citizens to support counter-espionage efforts. Authorities may access electronic devices, personal data, documents, and financial information during an investigation. When the revision passed in 2023, China’s state security ministry broadcast enforcement actions against US-linked consultancy and due diligence firms nationally — a visible demonstration that the new powers would be used.

The 2023 raids affected named firms including Mintz Group and Bain & Company, leaving multinational legal advisers to warn clients that routine China-related research now carries enforceable legal risk.

An Expanding Legal Arsenal, Already in Use

The Counter-Espionage Law is not Beijing’s only available instrument. Over the past eighteen months, China has constructed a layered retaliatory legal framework that, when fully deployed, could subject US companies to simultaneous enforcement actions across multiple regulatory regimes. Baker McKenzie’s supply chain compliance analysis covers the multi-regime exposure in detail.

Two new State Council instruments enacted in spring 2026 are particularly significant. State Council Decree No. 834 — the Regulations on the Security of Industrial and Supply Chains, effective March 31, 2026 — established formal supply-chain risk authority authorizing Chinese authorities to investigate and restrict companies perceived as posing supply-chain risks. State Council Decree No. 835 — the Regulations on Countering Improper Extraterritorial Jurisdiction by Foreign States, effective April 7, 2026 — created a Malicious Entity List targeting foreign entities that “promote” or implement foreign sanctions affecting Chinese companies, with no grace period.

Both decrees complement Beijing’s Anti-Foreign Sanctions Law, which China’s Ministry of Commerce invoked in August 2026 to place six US entities on a Countermeasure List, prohibiting any China-based entity from transacting with them. As of August 7, 2026, that list had grown to cover 78 individuals, senior management at nine entities, and 89 organizations total.

Linklaters and Jones Day have both published guidance warning multinational companies that a single corporate action — terminating a Chinese supplier to comply with US export controls — can now simultaneously trigger supply-chain investigations under Decree 834, counter-extraterritoriality measures under Decree 835, Anti-Foreign Sanctions Law designation, and potential Unreliable Entity List action. What previously required a deliberate escalation by Beijing is now a multifront compliance exposure built into the legal structure.

The Precedent Risk: What Happens When the “Private Company” Distinction Dissolves

Ellis’s core argument — that Chinese companies cannot be treated as genuinely private because the Communist Party can direct them at will — has a structural consequence that the diplomatic framing underplays.

The same logic is symmetrical. If the CIA’s position is that a company incorporated in China is not genuinely private because the Chinese state can legally compel its assistance, intelligence services in other countries can apply the same argument to US companies. American AI, semiconductor, and biotechnology companies work closely with US defense agencies, receive federal research funding, and are subject to legal processes — including FISA orders and National Security Letters — that require cooperation with US intelligence. A Chinese intelligence agency advancing the same analytical framework Ellis used could argue that Nvidia, Google DeepMind, or any major US semiconductor firm is a legitimate intelligence target because it is not genuinely independent of the American national security apparatus.

The Taipei Times editorial published September 10 noted that this framing “is not a new insight in Taipei” — Taiwan has operated on the assumption that Chinese commercial capital is a potential delivery mechanism for state power for three decades. The consequence is a bilateral intelligence posture in which neither side can credibly claim that the other’s commercial sector is off-limits — a structural shift from the Cold War model, in which state-sector intelligence targets and commercial actors were, at least nominally, distinct.

Does Ellis’s Declaration Change Espionage Reality: New Practice or New Visibility?

A critical distinction for TechTimes readers: Ellis’s remarks do not necessarily describe a new practice. CIA directors have acknowledged collecting economic intelligence against foreign commercial actors since at least the early 1990s, when the end of the Cold War prompted a public debate about whether the agency should redirect resources toward economic competition. Former CIA Director James Woolsey acknowledged in 2000 that the United States collects economic secrets from foreign firms and their governments.

What is new is the public framing of Chinese commercial firms — by sector, explicitly — as intelligence targets, and the justification offered: not to give collected intelligence to US companies for competitive advantage (the policy the US has historically maintained it does not follow) but to understand the strategic-industrial dimensions of a rival that the CIA characterizes as an existential threat.

“China is the existential threat to American security in a way we really have never confronted before,” Ellis told Axios in May 2025. That framing has now produced an operational consequence: a public mandate to treat Chinese commercial firms in three sectors as intelligence targets, stated at a conference, covered by federal government reporters, and promptly transmitted to Beijing.

For China’s Ministry of Commerce, the public declaration — not the underlying practice — appears to be the specific provocation. Its statement accused the United States of having “torn away the fig leaf that once concealed intelligence agencies’ covert theft.” The rhetorical complaint is about transparency: that what was once done covertly is now being declared.

The September Shadow

The timing of Ellis’s Billington appearance — September 8, two and a half weeks before the scheduled September 24 summit — cannot be dismissed as coincidental. Whether the remarks were intended to signal toughness going into the summit, to stake out a mandate for CIA collection activities regardless of any diplomatic accommodation, or simply reflected conference-circuit candor from a senior official, Beijing read them as a deliberate act.

The September 24 summit agenda is already dense: AI governance, semiconductor trade, Taiwan, and the architecture of the bilateral trade relationship before the November 10 deadline for the Kuala Lumpur trade truce. TechTimes has covered China AI safety preconditions for the September talks in detail. Treasury Secretary Scott Bessent confirmed that AI would feature on the agenda at the G20 Finance Ministerial in Asheville, North Carolina, on September 1. A bilateral AI safety protocol aimed at keeping advanced models out of non-state actors’ hands had been under discussion, and China’s semiconductor tariff situation adds further pressure to the summit’s already complicated agenda.

China’s formal government protest and its explicit invocation of the Counter-Espionage Law inject new friction into preparations that the two sides had managed with some care since the May 2026 Beijing summit. Whether the September 24 meeting proceeds in an atmosphere that allows progress on AI governance — or whether the intelligence confrontation becomes another item on a dispute ledger that is already crowded — remains to be determined.

What US Companies with China Operations Should Watch For

The practical question for TechTimes readers with corporate exposure to China is whether Beijing follows rhetoric with enforcement. The legal architecture to do so already exists and is already operational: Countermeasure List designations, supply-chain investigations, Counter-Extraterritoriality measures, and Counter-Espionage Law enforcement have all been used against US-linked entities in 2026 already.

Several indicators will signal whether enforcement escalates in response to Ellis’s declaration:

Any new designations on China’s Countermeasure List or Unreliable Entity List that cite “espionage activities” or “intelligence support” as the basis, rather than trade-related conduct, would indicate China is specifically operationalizing its counter-espionage legal toolkit against US companies rather than its trade-retaliation toolkit.

Enforcement actions against US-linked consultancy, market research, or due diligence firms using the Counter-Espionage Law’s revised 2023 language — invoking “national security and interests” rather than “state secrets” — would indicate the broader scope of the 2023 revision is being deployed.

Any detention or interrogation of employees at US-linked companies in China under the Counter-Espionage Law’s expanded summons authority would represent an escalation with direct human consequences for American workers.

The November 10 Kuala Lumpur trade truce deadline remains the structural constraint on escalation: neither government has an interest in a legal confrontation that disrupts the trade architecture before that date. But the Counter-Espionage Law threat, once made publicly and formally by the Ministry of Commerce, is now part of the legal and diplomatic landscape regardless of what happens at the September 24 summit.


Frequently Asked Questions

Can China actually use its Counter-Espionage Law to target US companies?

Yes, and it has already done so. Since the law’s 2023 revision, which expanded its scope from “state secrets” to “all documents, data, materials and articles concerning national security and interests,” China’s authorities have conducted enforcement actions against foreign firms including Mintz Group and Bain & Company. The law allows security agencies to summon individuals, access electronic devices, and freeze assets of suspected violators. The question after Friday’s Ministry of Commerce statement is whether China will explicitly cite US intelligence activities as the rationale for new enforcement actions against American companies — using the law as a direct counter-intelligence instrument rather than as an economic-dispute tool. The Library of Congress reviewed the 2023 revision in full.

What does the CIA’s “legitimate targets” declaration actually change for US companies in China?

The declaration itself does not change the legal environment for US companies operating in China — China’s Counter-Espionage Law was already in force and already broadly defined. What it changes is Beijing’s justification for deploying that law. Prior enforcement actions cited economic or trade-related grounds. Ellis’s public declaration gives China’s security apparatus a documented US statement to cite as evidence that American firms’ normal business activities — data collection, market research, due diligence — may be in service of CIA intelligence objectives. That rhetorical shift makes legally expansive interpretations of the Counter-Espionage Law politically easier to defend domestically. Crowell & Moring analyzed this business risk when the 2023 revision took effect.

Why is the CIA now publicly declaring it treats Chinese companies as spy targets — isn’t this normally done quietly?

It largely has been. Since the early 1990s, CIA directors including Gates and Woolsey have acknowledged economic intelligence collection, but officials have generally avoided naming commercial sectors as explicit targets. Ellis’s Billington remarks are unusually direct: he named sectors (AI, semiconductors, biotechnology), explained the rationale (Chinese companies are not genuinely independent of the state), and connected the collection mandate to the CIA’s broader institutional reorganization. The most likely explanation is that the Trump administration’s CIA leadership views public declaration as consistent with a broader posture of strategic transparency about US intelligence priorities — signaling capability and intent as a deterrent or negotiating asset, rather than maintaining the ambiguity that intelligence services traditionally cultivate. The Ratcliffe CIA technology reshaping announcement at the AWS Summit provides the institutional context.

Could this logic be applied symmetrically — could other countries declare American tech companies spy targets?

Yes, and the structural logic supports it. If Chinese companies are legitimate intelligence targets because the CCP can legally compel their cooperation with state intelligence work, US tech companies are arguable targets by the same reasoning: American AI, semiconductor, and defense-adjacent technology companies work under contracts with US military and intelligence agencies, are subject to FISA orders, and operate in sectors that the US government has classified as national security priorities. The counter-argument is that US companies are not directly state-controlled, but that distinction was precisely what Ellis’s remarks questioned in the Chinese context. The precedent risk is real and worth monitoring, particularly as other major intelligence services — the UK’s GCHQ, France’s DGSE, Russia’s FSB — process the implications of the CIA’s public framing. A Taipei Times editorial analyzed the dual-use logic and its symmetrical implications.

Source link