CIA Deputy Director Michael Ellis told an audience at the Billington Cybersecurity Summit in Washington, D.C. on September 8, 2026 that the agency's intelligence-gathering priorities now extend well past government and military targets — into private-sector breakthroughs in artificial intelligence, semiconductors, and biotechnology. Intelligence officials rarely confirm the scope of espionage targeting on the record, in public, at a named conference. That's what makes this notable: not a leak, not an anonymous "official familiar with the matter," but the CIA's own deputy director saying it into a microphone.
The story spread quickly on X on September 9, 2026, credited to New York Times national security reporter Dustin Volz (@dnvolz). explainx.ai could not independently access Volz's original NYT reporting, so this post is grounded in Ellis's confirmed public remarks as reported by Federal News Network and MeriTalk, both of whom covered the same Billington appearance with direct quotes — and it stays bounded by what those sources actually confirm.
Before getting into what this means for people who actually build with AI, here's what Ellis is reported to have said, plainly.
What Ellis actually confirmed — and what he didn't
At Billington, Ellis framed the shift around what he called a "dual use technology race" with China, saying the CIA now needs to collect intelligence relevant to "economic security" in addition to conventional political and military targets. On why semiconductors and biotech specifically require a different approach, he said:
"It means we need a different kind of workforce...we need to have different kinds of intelligence targets because that kind of information, whether it's semiconductors or biotech...it's not found in the same places that political or military foreign intelligence would be found."
That's a real, on-the-record admission that private-sector technology — not just state actors — is now squarely inside the CIA's collection mandate. What it is not, based on the reporting available, is a naming of specific companies, specific stolen technologies, or specific operations. Neither Federal News Network's nor MeriTalk's coverage of the same speech quotes Ellis naming a Chinese AI lab, chip maker, or biotech firm, or describing an active case. If other reporting on this speech surfaces specifics beyond this, treat this post as bounded by what's confirmable as of publication — not as the last word.
This is also not a brand-new position for Ellis. He told Axios something similar in May 2025, calling China "the existential threat to American security in a way we really have never confronted before" and naming AI, chips, biotech, and battery technology as areas where the CIA wants to help US firms keep a "decisive technological advantage." What changed in September 2026 is the venue and the framing — a public industry conference, with sharper language about workforce needs and where the relevant intelligence actually lives, rather than a one-on-one interview.
Why this actually matters if you build with AI
It would be easy to file this under pure geopolitics and move on — a CIA official talking about spy-agency priorities isn't, on its face, something that changes what you build tomorrow morning. But there's a real practitioner angle here, and it's worth being explicit about it rather than gesturing at "geopolitical tension."
The companies whose models and hardware you might be sourcing from are the named category. If you're evaluating DeepSeek, Kimi K3, GLM, or Qwen — or sourcing chips through supply chains that touch China — you're now operating in a space that a CIA deputy director has publicly said is a named intelligence-collection priority, distinct from and broader than the export-control fights that have dominated headlines all year. That doesn't make using these models illegal, unethical, or even risky in itself. It does mean the environment around them is getting more scrutinized, not less, and the direction of travel matters more than the day's headline.
Second-order effects are the actual story, not the speech itself. A handful of concrete, plausible consequences follow from remarks like this, even absent any new law or rule:
- Compliance posture tightens first. Regulated industries — finance, healthcare, defense-adjacent, critical infrastructure — tend to react to this kind of public signal before any formal rule exists, because procurement and legal teams treat "the CIA said this out loud" as a real data point in vendor risk assessments.
- Due-diligence expectations rise for open-weight model vendors. Expect enterprise buyers to start asking harder questions about where a Chinese open-weight model was trained, what telemetry (if any) an API-hosted version sends back, and who controls the infrastructure behind it — questions that were niche a year ago and are becoming standard.
- It's a leading indicator, not a trailing one. Public remarks like this from a senior intelligence official have historically preceded rather than followed formal export-control or entity-list action — see the pattern across Trump's chip export framework and the Fable 5 / Mythos export restrictions earlier this year. Treat this as a signal worth watching, not a rule you need to comply with today.
- Chilling effects compound gradually. Each new data point — Taiwan's B300 smuggling indictments, China's own restrictions on overseas model access, and now a CIA official confirming expanded targeting — makes it incrementally harder for a compliance-conscious enterprise to justify standardizing on Chinese open-weight infrastructure, even when the technical case for doing so (price, performance, license terms) remains strong.
The asymmetry worth noticing
There's a real tension in this story that's easy to miss if you only read it as "CIA vs. China." US builders have spent much of 2026 making the case — repeatedly, and often persuasively — that Chinese open-weight models offer real advantages: lower cost, faster iteration, permissive licensing, and in some benchmarks, competitive or superior performance to closed US labs. explainx.ai has covered why open weights matter as a genuine technical and economic argument, not just an ideological one. Ellis's remarks land squarely on top of that argument, because they reframe the sourcing decision as one with a national-security dimension attached — regardless of whether any individual company or user is doing anything wrong.
That's the actual "so what" here: this isn't a story about spies. It's a story about the compliance and sourcing calculus for anyone choosing between a US-based closed model and a Chinese open-weight one getting measurably more complicated, on the same week China's own AI token economy is reportedly processing 500 trillion tokens a day — a reminder of just how much daily usage sits on the other side of this widening gap.
What to actually do with this
Nothing here demands an immediate architecture change. What it should prompt:
- Document your model and hardware sourcing decisions now, while they're still uncontroversial, rather than reconstructing the reasoning later under regulatory pressure.
- Watch for follow-through, not just rhetoric. A speech is not a rule. The pattern this year has been remarks first, formal action (export controls, entity-list additions, procurement bans) weeks to months later — Ellis's comments fit that pattern rather than breaking it.
- Separate the technical evaluation from the compliance evaluation. A Chinese open-weight model can be the objectively better technical choice for a workload and still carry a compliance overhead that a closed US model doesn't — that's a real cost, not a hypothetical one, for regulated buyers specifically.
- Expect vendor questionnaires to catch up. If you sell software that embeds or recommends AI models, expect enterprise security reviews to start asking which underlying models and chip supply chains you use, in a way they didn't eighteen months ago.
What's still unconfirmed
To be precise about the boundary of what's actually known: Ellis's confirmed remarks describe an expanded category of intelligence targets — private-sector semiconductor and biotech information, alongside AI — and a stated need for a more technical CIA workforce to collect it. They do not, in the reporting available to explainx.ai, name specific Chinese AI companies, describe specific stolen technology, or confirm any specific operation. The X-thread digest summarizing this as a broad crackdown on "major private Chinese companies in AI, semiconductors, and biotechnology" is a reasonable characterization of the direction Ellis described, but it is a secondary aggregation of his general remarks, not a report of named targets — and this post treats it that way rather than inventing specifics to fill the gap.
Related reading
- Trump's AI chip export controls target China's cloud access loophole
- Taiwan indicts 9 over Nvidia B300 servers smuggled to China
- US government bans Fable 5 and Mythos 5 under export control
- China may restrict overseas access to its own top AI models
- GLM-5.2 beats Fable 5 on reasoning, 24 hours after the US export ban
- China's AI token economy: credit cards, bank loans, and 500 trillion tokens a day
- US vs. Chinese AI startups: a practical comparison
- Why explainx.ai supports open-source AI
External sources: Federal News Network, "CIA eyes 'more technical' workforce amid cyber, AI challenges" · MeriTalk, "CIA Seeks More Technical Workforce for China Tech Race" · Axios, "Tech race with China is top intel priority, deputy CIA director says" (May 2025)
Version and policy details in this post are accurate as of September 9, 2026. Intelligence-agency remarks and export-control actions can move quickly — verify current status before making sourcing or compliance decisions on Chinese AI models or hardware.
