Jacob Coxon spent three years doing pretraining research at two of America's most powerful artificial intelligence companies — OpenAI and Anthropic. He resigned from Anthropic in September 2026 over safety concerns. And this week, sitting across from Patrick Bet-David on the PBD Podcast, he dropped a claim that should have every national security official in Washington reaching for their phone.
"China already has spies at OpenAI and Anthropic."
Coxon didn't hedge. When Bet-David asked how confident he was, Coxon answered: "Ninety percent. Yeah, it's almost certain that they have."
The claim would be easy to dismiss if the broader context didn't make it so plausible. Britain's MI5 identified the China General Technology Research Institute as a front connected to espionage operations, with the institute allegedly financing research in AI, cybersecurity, and covert communications. MI5 flagged over 100 UK-linked academics who contributed to institute-funded projects without realizing who was bankrolling them. China's Ministry of State Security has been running these operations for years across Western research institutions. The idea that they'd skip Silicon Valley's most valuable targets would require a kind of restraint Beijing has never demonstrated.
Coxon went further, pointing out a gap in American security architecture that's genuinely stunning when you hear it said plainly: "I don't think SpaceX can hire Chinese nationals, but these AI companies can hire foreign nationals like me, which is pretty surprising." Coxon himself is British — not exactly a security threat — but his point wasn't about himself. SpaceX, which builds rockets, has hiring restrictions that OpenAI and Anthropic, which are building what their own leadership calls the most transformative and potentially dangerous technology in human history, do not.
Let that distinction land for a second. We background-check the people building the rockets but not the people building the thing their own CEO says might end civilization.
Dario Amodei, Anthropic's CEO, has spoken publicly about existential risks from AI. Anthropic employees reportedly call themselves "ants in the anthill" — sacrificing for the mission. They hold what amount to funerary rites for defunct AI models. This is a company that takes its own product seriously enough to ritualize it. And yet the hiring pipeline for the people with access to the most sensitive weights and architectures in the world apparently gets less scrutiny than a defense contractor's janitorial staff.
Coxon also warned about the hacking dimension: "China has the ability to hack at any time. If we pull ahead, that doesn't give us a big lead. They can just step in, steal our progress at any time and catch up." The implication is that America's AI advantage — the one the Trump administration has correctly prioritized maintaining — is only as secure as the networks and personnel at a handful of private companies. Companies that, unlike defense contractors, aren't subject to ITAR restrictions, don't require security clearances for most roles, and apparently don't restrict hiring by nationality.
SpaceX can't hire Chinese nationals to work on rockets. OpenAI and Anthropic can hire foreign nationals to work on what their own founders say could be more dangerous than nuclear weapons. One of those policies will look obviously wrong in hindsight. The only question is which one.
