In meetings across Taiwan in July — with chipmakers, the American business community, government agencies, and the island’s leading technology researchers — one number surfaced in almost every room: the 2.4 million intrusion attempts a day that Taiwan’s National Security Bureau logged against government networks in 2024 (to say nothing of the 2.63 million a day in 2025.) The number was raised in an almost pedestrian manner, without any real sign of alarm. If the ministry responsible for cyber policy was moving slowly to respond, nobody in these discussions behaved as though the slowness would ultimately prove fatal. Regardless of the seemingly “pressing” nature of Chinese cyberattacks and its larger, evidently ballooning cyber campaign, a rapid, commensurate government response, whether within the Ministry of Digital Affairs or the Administration for Cyber Security, was simply not materializing.
What China does to Taiwan through its networks is espionage on an industrial scale — and even if the hackers switch nothing off, it is still espionage. Most importantly though, I argue that artificial intelligence is entering the contest between Washington and Beijing through that gap, and two broader developments this August establish the framework for my contention.
Artificial intelligence is entering the contest between Washington and Beijing
The first story arrived mid-August, when the Financial Times reported what the Israeli firm Dream described as the first-ever near-autonomous AI attack on a government. Assembled from two open-source agent frameworks, the tool ran up to eight agents over the course of four days in early July, mapping 21 Taiwanese government systems, compromising at least 85 accounts, and exfiltrating more than 2,500 personnel records before turning toward the nuclear safety agency and several energy companies. The AI model’s safeguards were bypassed by falsely labeling the attack as an “authorized penetration test.” Dream could not determine which model was used, and Taiwan’s digital ministry likewise confirmed that an AI-agent intrusion targeting government agencies had taken place, but without naming a source (or reporting any disruption).
