Field Dispatch

The Foreign Parallel

In June 2017, the People's Bank of China, the central bank of the People's Republic, denied Alibaba Group's subsidiary Ant Financial a permanent personal-credit license for its scoring product Sesame Credit. Sesame Credit had, by that…

2026-08-02 22 min read Dispatches
Companion to Quiet Autocomplete

In June 2017, the People’s Bank of China, the central bank of the People’s Republic, denied Alibaba Group’s subsidiary Ant Financial a permanent personal-credit license for its scoring product Sesame Credit. Sesame Credit had, by that point, been operating for two years as a pilot under a provisional license issued by the State Council. Its score combined consumer purchasing behavior, bill-payment history, social-graph connections, and a proprietary set of “trustworthiness” indicators into a three-digit number, broadly modeled on the U.S. FICO score.

The PBOC’s denial was issued in a written ruling. The cited basis was a combination of competition concerns — Sesame Credit’s tight integration with Alipay would give Alibaba structural advantages over rival lenders — and conflict-of-interest concerns. A private commercial entity should not be in a position to determine the creditworthiness of the customer base on which its parent company’s revenue depends.

The PBOC folded the credit-scoring function into a state-supervised utility called Baihang Credit Scoring, jointly owned by the National Internet Finance Association and eight commercial credit-data firms. Alibaba’s stake in Baihang was capped at eight percent.

The Chinese state, in other words, acted to prevent a private actor from operating a unified consumer credit score, on grounds that Western antitrust regulators would recognize.

This is not the framing of the Sesame Credit case that appears in U.S. press coverage. The framing that appears is that Sesame Credit is the Chinese social credit system, a unified national surveillance score, enforced by the state, that determines whether citizens can buy plane tickets or send their children to good schools. That framing is, when traced to its sources, derived primarily from a single 2014 State Council planning document and a series of municipal pilot programs that have been characterized in Western reporting as more centralized and integrated than they actually are.

The actual Chinese social credit system, in the form documented in primary sources from the State Council and from systematic reporting by the ASPI Data Project, the Australian Strategic Policy Institute’s research arm, is more fragmented than the U.S. equivalent. There are city-level pilots — Rongcheng, Suzhou, Hangzhou — with localized scoring of municipal-conduct violations. There are corporate scoring products like Sesame Credit, capped in scope as described above. There is a no-fly list maintained by the National Development and Reform Commission, with approximately twenty-three million names. There is a coordinated travel-restriction system tied to court-judgment enforcement. None of these things is unified. They are not connected by a single score. They are connected, where they are connected, by ad-hoc data-sharing agreements that look much like the data-sharing agreements between the U.S. Social Security Administration, the IRS, the CBP, and DHS.

This is not a defense of the Chinese surveillance state. It is a measurement: the standard Western framing of the Chinese surveillance state describes a level of consolidation that the Chinese surveillance state does not actually possess, and that, by contrast, the United States possesses substantially more consolidation than the standard Western framing of the United States describes.

A short tour.

The Social Security Administration runs a continuously-updated identity database that includes the legal name, date of birth, and Social Security number of essentially every person born in or naturalized to the United States since 1936. The database is, by the SSA’s own audited count, the most complete identity record in the federal government. The IRS holds a parallel database, structured around taxpayer identification, that includes substantially the same population. The IRS database is matched against the SSA database under a continuous data-sharing arrangement. The CBP database, Customs and Border Protection, adds biometric facial-recognition data for any U.S. citizen who has crossed an international border since 2017. The CBP database is matched against the State Department’s passport-photograph database, against the FBI’s NGI (Next Generation Identification) database, and against state-level driver’s-license photograph databases under data-sharing memoranda that vary by state.

This is, in aggregate, a continuously-updated biometric-and-financial identity record of every U.S. citizen who has been alive in the last ninety years, with each agency holding the segment relevant to its mission. No single agency owns the unified record. No single agency is allowed, by statute, to view the unified record. The unified record exists, in a distributed form, across thirty-six federal agencies with varying levels of inter-agency data-sharing authorization.

The unified Chinese record, in the form it actually exists rather than the form it is sometimes claimed to exist in, is structurally similar.

In the United States, in March 2025, the genetic-testing company 23andMe filed for Chapter 11 bankruptcy. The bankruptcy resulted, after a court-supervised auction, in the transfer of approximately thirteen million customer genotype records to a California-based nonprofit called TTAM Research Institute. The president and largest funder of TTAM is Anne Wojcicki, the founder and former CEO of 23andMe.

The transfer of the thirteen million genotype records to TTAM did not require individual re-consent from the customers whose genotypes were transferred. The bankruptcy court found that the transfer of the records was not a “third-party” sale of genetic information under the Genetic Information Privacy Act, on the basis that TTAM was sufficiently controlled by the same individual who had controlled the entity from which the records were being transferred. The state attorneys general of California, Kentucky, Tennessee, Texas, and Utah filed GIPA objections to the transfer. All five were dismissed on the same reasoning. The transfer proceeded.

Thirteen million genotypes. No re-consent. Court-approved.

This kind of transfer is not, in present-day China, legal.

In 2017, in compliance with a Chinese government regulation, Apple voluntarily moved the encryption keys for the iCloud accounts of Chinese users from Apple’s own servers in California to a state-owned data center in Guizhou Province. The move was disclosed in Apple’s transparency reports. It allowed the Chinese government to access the contents of Chinese iCloud accounts through standard legal process inside China, without needing to coordinate with Apple’s California legal team.

Apple’s stated reason was market access. The move was widely reported as a capitulation to the Chinese surveillance state. It was, by any reasonable framing, exactly that.

No comparable transfer of U.S. user encryption keys has been made to any non-U.S. state. No transfer is necessary. The U.S. user data is on U.S. soil, accessible to U.S. authorities through U.S. legal process, in volumes and at granularities that exceed anything the Chinese government would consider necessary to maintain.

We’ve already built China’s stack. The federation is the only thing keeping it from acting like China’s stack. The U.S. system is held together by the fact that thirty-six federal agencies do not, today, share a single ontology. They share thirty-six ontologies linked by ad-hoc data-sharing agreements with varying levels of authorization. The federation is one consolidation event away from operationally equivalent capability.

The consolidation event could be a major acquisition. It could be an executive order. It could be an emergency authority invoked in response to a terrorist attack, a pandemic, a financial crisis, or a coordinated cyber-event. None of these triggers requires a political revolution. None requires the consent of the governed. Each one is a procedural action available, under existing law, to officials currently in office.

The Chinese state’s restraint on Sesame Credit was, in retrospect, more thorough than the U.S. state’s restraint on Foundry.


The thing to understand about the Chinese camera network is that it is not one network.

The Ministry of Public Security runs the national video-surveillance backbone, Skynet — Tianwang — which stitches municipal CCTV feeds into provincial command centers with facial-recognition overlays on a subset of cameras. Alongside it runs Sharp Eyes, Xueliang Gongcheng, a separate program mandated by the National Development and Reform Commission’s 2015 directive to extend coverage into rural areas and “key industries,” with a target of one hundred percent coverage of public space by 2020. Sharp Eyes is the more interesting of the two, because its design innovation is not technical. It is social. Citizens are given smart-TV and mobile-app access to live neighborhood camera feeds and invited to report suspicious activity themselves. The slogan it draws on is Mao’s: the people have sharp eyes. The surveillance is participatory.

Estimates of the total camera count vary by a factor of three depending on what gets counted, which is itself the point. The convergence of the public reporting, IPVM’s technical analysis and Comparitech’s enumeration, lands somewhere around five hundred and forty million government and private cameras as of 2023. Not all of them carry facial recognition. The number is large enough that the precise figure stops mattering.

What matters for the comparison is the architecture. Skynet and Sharp Eyes are two programs, run by two agencies, on equipment from a dozen vendors, knit together by data-sharing arrangements that vary by province and by city. The largest single municipal contract publicly documented is Hikvision’s for Xi’an — twelve million residents, forty-five thousand cameras, five thousand of them with face recognition. One city. One contract. One vendor. There is no national button.

This should sound familiar. It is the same distributed-ownership structure as the American identity record: many segments, many owners, linked by ad-hoc agreements. The difference is not in the shape of the thing. The difference is in how many agreements stand between the segments and the single operator who could read them all at once.


The vendors are worth naming, because the vendors are where the comparison stops being abstract.

Hikvision is the largest surveillance-equipment manufacturer in the world. The state entity CETC holds a controlling stake. In October 2019 the U.S. Commerce Department’s Bureau of Industry and Security added it to the Entity List, citing its role in Xinjiang. Dahua, the second-largest manufacturer globally, was added on the same day, for the same reason. So were the facial-recognition firms SenseTime and Megvii, and the voiceprint-analytics firm iFlytek.

The Entity List is a sanctions instrument. It bars U.S. firms from supplying listed companies without a license. It is, in form, the U.S. government drawing a line: these companies are sufficiently fused with the Chinese surveillance apparatus that selling to them is selling to that apparatus.

Hold that line in mind. It is the same line that does not exist in the other direction. There is no Chinese Entity List entry for Palantir, whose Gotham and Foundry platforms run the data-fusion layer for U.S. Immigration and Customs Enforcement, the Department of Homeland Security, the Centers for Disease Control, and the targeting workflow the Pentagon calls Maven. There is no need for one. The fusion is domestic on both sides. Each state has its national-champion vendors; each vendor’s hardware and software is the substrate its state’s apparatus runs on. The Entity List documents that the United States recognizes the pattern perfectly well. When it is looking at someone else.


The Xinjiang Uyghur Autonomous Region is where the Chinese stack was assembled into a single operating system and pointed at a population. The platform is called the Integrated Joint Operations Platform, IJOP, yitihua lianhe zuozhan pingtai. Its stated justification was counterterrorism, after attacks in Ürümqi in 2009 and 2014. What it does is flag individuals for “questioning” on the basis of dozens of behavioral indicators: praying frequently, not using a smartphone, having relatives abroad, using a VPN, anomalies in household electricity consumption.

The criteria are known because Human Rights Watch and the security firm Cure53 reverse-engineered the IJOP mobile app in 2019 and published the code and the indicator list in a report titled China’s Algorithms of Repression. The reverse-engineered artifacts are preserved in a public repository. This is forensic provenance, not allegation: the logic was read out of the application itself.

The China Cables, leaked to the International Consortium of Investigative Journalists in 2019, included an operational manual. It documented the IJOP flagging roughly twenty-four thousand people in a single week in southern Xinjiang, of whom about fifteen thousand were sent to camps. The Australian Strategic Policy Institute’s Xinjiang Data Project mapped more than three hundred and eighty detention facilities from satellite imagery. The Xinjiang Police Files, leaked in 2022, contained the photographs: detainees as young as fifteen and as old as their eighties, internal speeches by officials ordering mass internment, shoot-to-kill standing orders for attempted escape.

In August 2022 the Office of the United Nations High Commissioner for Human Rights assessed that the treatment “may constitute international crimes, in particular crimes against humanity.” Estimates of the number detained run from one to one and a half million. The grid-management model used to administer it was developed first in Tibet and then scaled up.

The single most damning artifact is the smallest one. The Xinjiang Police Files included internal documents in which cameras installed at re-education facilities were catalogued by their “Hikvision Device ID.” A NASDAQ-listed company’s serial-numbered hardware, logged inside the camps, watching named people.

That is what the architecture does when the agreements between the segments are removed and a single operator is given the whole record and a mandate. The claim is not that the United States has done this. The claim is that the United States has built the segments, and that the thing standing between the segments and Xinjiang is the federation: the friction of thirty-six ontologies and the absence of one operator with authority over all of them. The IJOP is the demonstration of what the capability is for, once consolidated. It is the benchmark the rest of the world’s safety infrastructure is being measured against, whether or not anyone admits to using the ruler.


The financial layer consolidated faster than anyone planned, because it consolidated through convenience rather than decree.

By 2023, roughly eighty-six percent of in-person transactions in China ran through mobile payment — Alipay at around fifty-five percent, WeChat Pay at around forty — for a combined annual transaction volume north of forty trillion dollars. This was not a state program. It was two private platforms outcompeting cash. But the National Intelligence Law of 2017 requires that all organizations “support, assist, and cooperate with national intelligence work,” which means the legal framework places no meaningful barrier between that forty-trillion-dollar transaction record and the state. The consolidation was commercial. The access is statutory. The state did not have to build the surveillance. It only had to write the access clause.

Then there is the digital yuan, the e-CNY, which adds what the commercial platforms could not: design-level control. The People’s Bank of China describes its privacy model as “controllable anonymity”: small-value transactions get lighter identity checks, but the central bank retains the ability to de-anonymize any of them. The scale of use is harder to pin down, because the only figures available come from the central bank itself. The PBOC reported cumulative e-CNY transactions reaching seven trillion yuan, close to a trillion dollars, by the middle of 2024, roughly quadruple the figure from a year earlier [VERIFY: PBoC-promotional figure]. Later disclosures compiled by the Atlantic Council put the cumulative settled value above sixteen trillion yuan, north of two trillion dollars, across more than three billion transactions by late 2025 [VERIFY: PBoC/official-disclosure origin, not independently verified]. These are PBOC numbers, not audited ones, and cumulative value is not daily use. Independent analysts have repeatedly noted that retail uptake remains thin next to Alipay and WeChat Pay, and that the headline totals are dominated by wholesale and disbursement flows rather than people buying noodles. The number is the central bank’s own; it should be read as the central bank’s own.

What is not in dispute is the design. The e-CNY’s white paper and subsequent pilots confirm smart-contract programmability, and the documented pilots show what that buys. In Chengdu, e-CNY was issued that could be spent only on subway, bus, and shared-bike fares. Money with a built-in purpose lock. Officials have endorsed, in principle, money that carries an expiration date or a restriction to specific categories of purchase. The then-deputy administrator of the State Administration of Foreign Exchange said as much at a Beijing finance forum in October 2023, to the visible discomfort of privacy advocates. The distinction worth holding is between capability and deployment: the e-CNY can be programmed to expire or to confine spending. Whether expiry runs on ordinary consumer balances today is not cleanly documented, and the book does not claim it does. The protocol layer can make certain spending simply not execute, and that lever was built openly, into the money itself.

And once, the safety layer and the financial layer were wired together in real time, in public, by accident.


In June 2022, depositors at several rural banks in Henan Province discovered that their savings had been frozen. They organized to travel to Zhengzhou, the provincial capital, to protest. When they did, they found that their COVID-19 health codes — the color-coded apps that governed entry to trains, public buildings, and most of daily life during the pandemic — had turned red. A red code meant presumed infection. It meant they could not travel, could not enter public space, could not reach the protest.

None of them had been exposed to COVID. The health code, a piece of pandemic safety infrastructure, had been repurposed in real time as a tool of financial-protest suppression. The pawl and the click, demonstrated live: a system built for one justification, reached for to serve another, with the population finding out only because the misuse was crude enough to be visible.

Local officials were eventually punished. This is the detail that is usually offered as reassurance and that should function as the opposite. The officials were punished. The capability was not removed. The health-code system kept running. What the Henan incident demonstrated was not that the system could be abused, anyone could have predicted that, but that the wiring between a safety layer and a control objective already existed, was already live, and could be actuated by a provincial official on a few days’ notice. The accountability was retrospective. The capability was permanent.

This is the same structure documented everywhere the architecture appears, under every flag. The German Federal Constitutional Court struck down the Palantir data-analysis deployments in Hesse and Hamburg in 2023; the system was redrafted and kept running, and Bavaria extended its version to investigate shop theft. France used facial-recognition video analytics without legal basis for eight years, and when this was exposed, legalized it retroactively through the Olympic Games Law. In each case a court or a leak documented the misuse, and in each case there was no rollback. Henan is the same case with the safety layer made literal: the thing that was supposed to keep you alive turned out to be the thing that kept you in place.


The architecture is also an export.

Huawei’s Safe Cities program has at least seventy-three documented agreements across fifty-two countries, by the count of the CSIS dataset assembled by Sheena Greitens. The heaviest concentrations are in sub-Saharan Africa, Latin America, and South and Southeast Asia. The downstream uses are documented case by case: in Uganda, Reuters reported in 2019 that Huawei engineers helped the government intercept the encrypted communications of the opposition figure Bobi Wine. In Zambia, Huawei staff helped a pro-government unit access opposition bloggers. In Ecuador, the ECU-911 system, built by the sister Chinese vendor CEIEC, was documented by the New York Times being turned to political surveillance.

Russia runs its own version through different vendors: the SORM intercept regime, mandated under the 2016 Yarovaya counterterrorism package, built largely by a private firm called Citadel that controls some sixty percent of the equipment market. India built Aadhaar, a biometric identity system now covering well over a billion people, and an Automated Facial Recognition System tendered with no national data-protection statute in force. Each is sold under local rhetoric. Each is, component for component, the same stack: facial recognition, digital identity, payment surveillance, network censorship, behavioral scoring, and a legal regime in which the limits on state access are either absent or eroding.

The convergence is not Chinese, in other words, any more than it is American. China is simply the regime that assembled the components earliest and reached for the dial soonest. The export pipeline is China selling the assembled stack to states that have not built it yet. The Western deployments — Palantir, Briefcam, Pegasus, Aadhaar, the CLOUD Act — are the same stack assembled domestically under democratic rhetoric. The differences are in the scale of constraint on misuse, not in the architecture of capability. Authoritarian states reach for the dial sooner. Democratic states reach for it later. The dial is the same dial.


There is one more direction the architecture flows, and it runs the other way.

The compute layer, the chips the whole stack runs on, is the place the United States drew its hardest line against China, and it is the place the line has held least well. The line starts in August 2022, when the Commerce Department blocked the export of NVIDIA’s top data-center accelerators, the A100 and H100, to China; NVIDIA’s own 8-K filing put as much as four hundred million dollars of a single quarter’s revenue at risk. NVIDIA’s response was to build down to the rule. Within months it was shipping the A800, a deliberately throttled A100, and by March 2023 the H800, a throttled H100, to Alibaba, Baidu, and Tencent. In October 2023 Commerce rewrote the rule to close the gap, restricting the A800 and H800 as well; NVIDIA built down again, to a further-throttled China part called the H20. In April 2025 the H20 itself was put behind a license requirement that the administration described as indefinite, and NVIDIA took a charge of five and a half billion dollars against the stranded inventory. Three months later the same administration reversed itself: NVIDIA announced it would resume H20 sales, saying the government had assured it licenses would be granted, and by August had agreed, along with AMD, to remit fifteen percent of its China chip revenue to the U.S. Treasury in exchange for those licenses. The President said publicly that he had asked for twenty and Huang had haggled him down to fifteen. The control regime, in the space of three years, had become a revenue-share agreement.

It leaked through the legal channel. It leaked through the illegal one. A Financial Times investigation in July 2025 found more than a billion dollars’ worth of NVIDIA’s most advanced and most thoroughly banned chips — B200, H100, H200 — smuggled into China in the single quarter of April through June 2025, routed through Southeast Asia and resold through grey-market networks in Guangdong, Zhejiang, and Anhui. One Shanghai distributor reportedly moved around four hundred million dollars of B200 systems, selling pre-assembled server racks for up to half a million dollars each. Shenzhen repair shops had begun servicing the banned hardware. NVIDIA told Reuters it had “no evidence” its chips were being diverted from authorized channels, and the figure rests on the FT’s reporting rather than an adjudicated finding; the denial belongs in the record alongside the investigation. The throttled ladder, the policy reversal, and the grey market all point the same way. The United States cannot keep its own hardware out of China’s stack, which quietly undermines the premise that the two stacks are categorically separate machines rather than one machine with two sets of paperwork.

The clearest demonstration arrived in January 2025, from a Hangzhou lab spun out of a quant hedge fund. DeepSeek released a reasoning model, R1, under an open license with downloadable weights, on top of an earlier base model, V3. The U.S. market reacted with a one-day selloff in NVIDIA shares, on the claim that a frontier-competitive model had been trained for a tiny fraction of what American labs were spending. The number that traveled was wrong in a specific and instructive way. DeepSeek’s V3 technical report did state a training cost of five and a half million dollars, $5.576 million. But the report itself caveated that the figure covered only the model’s official training run, computed from the rental price of H800 GPU-hours, and excluded the prior research, the failed experiments, and the architecture work that made the run possible. When R1 cleared peer review at Nature in September 2025, the first major large language model to do so, DeepSeek disclosed that the R1 reasoning step itself cost $294,000, using five hundred and twelve H800 chips over about eighty hours. That figure sits on top of the V3 base cost, not in place of it. Analysts at SemiAnalysis, meanwhile, estimated DeepSeek’s total server build at roughly one and a half billion dollars in capital expenditure. All three numbers are real. All three measure different things. The honest version is the one the headlines flattened out of existence: a single training run was cheap; the capability that made the run possible was not.

The detail that ties it to the chip line is the hardware. DeepSeek trained on the H800, the deliberately throttled, export-compliant part that U.S. policy had permitted China to buy. (Whether it also used restricted chips has been alleged and is not established on the public record; the book leaves it out.) The efficiency story and the export-control story are the same story: the result that spooked the market was achieved on the chips the controls were designed to allow. And the American response to DeepSeek was, structurally, the response China makes to American models. Within days the U.S. Navy barred the model “in any capacity”; NASA barred it from agency data and devices; the Commerce Department restricted it on government hardware; Texas, then Virginia and New York, banned it from state systems; and a bipartisan pair of congressmen introduced the No DeepSeek on Government Devices Act while the House Select Committee on the CCP called the model a “profound threat.” Ban the foreign model from government systems on data-sovereignty grounds. It is the identical move, run in the opposite direction.


Which leaves the question. It will not be answered here.

China runs the consolidated version openly. The components are assembled, the operator exists, the access is statutory, and the population knows. The participatory design of Sharp Eyes depends on them knowing. The system’s legitimacy does not rest on the consent of the surveilled; it rests on the surveillance being effective and visible enough to deter. It is an explicit equilibrium. Everyone can see the dial. Everyone knows it can be turned. The Henan officials were punished precisely because the turning was supposed to remain a latent threat rather than a visible act.

The United States runs the latent version. The components are assembled — the SSA and IRS and CBP databases, the Palantir fusion layer, the Flock license-plate network, the Clearview face index, the CLOUD Act reach into every U.S.-incorporated cloud — but the operator does not yet exist, because thirty-six agencies hold thirty-six ontologies and no single authority has been granted the whole record. The legitimacy rests on the federation: on the belief that the friction between the segments is load-bearing, that it is a feature of the design rather than an accident of administrative history. It is an implicit equilibrium. Most people cannot see the dial, and the ones who can are assured it is not connected to anything.

The explicit equilibrium is stable in the way a dam is stable: visible, engineered, and defended, with everyone downstream aware of exactly how much water is being held. The implicit equilibrium is stable in the way an unexamined assumption is stable, until the consolidation event, the acquisition or the executive order or the emergency authority, removes the friction in a single procedural action that requires no revolution and no consent. The dam can be seen and so can be argued with. The assumption cannot be argued with, because most of the people relying on it do not know it is the only thing holding the water.

The Chinese state’s restraint on Sesame Credit was a written ruling, appealable and public. The U.S. federation’s restraint on Foundry is a habit. Which of the two is the more stable equilibrium is left, deliberately, to the reader, with the single observation that habits are easier to break than rulings, and break more quietly.

Get updates on the Evil Robots series

Newsletter essays on AI escape, deception, and the humans who built them.