Foreign Affairs warns China is building an AI cyber-crisis playbook
What “mythos” means in practice: the incentives, narratives, and security assumptions shaping AI conflict readiness.

Foreign Affairs frames a coming AI cyber crisis as China prepares its own mythos for how conflict and disruption will unfold. For decision-makers, it signals a shift in threat planning from one-off incidents to crisis-scale, system-wide resilience.
Foreign Affairs is not writing about a future vibe. It is warning that an AI cyber crisis is something states will prepare for, not merely respond to. And in that preparation, China is portrayed as doing something more strategic than stocking firewalls or buying more incident responders: it is building a “mythos,” a narrative structure for how its side expects cyber conflict to look, how it expects adversaries to behave, and what kinds of actions will be treated as decisive.
That matters because AI changes the tempo and shape of cyber operations. The original summary is blunt: “Preparing for an AI cyber crisis.” The crisis, in this framing, is not just malware and outages, it is a world where AI tools compress decision cycles, automate reconnaissance and exploitation, and blur the line between normal digital activity and coordinated disruption. When disruption can scale, speed up, and look plausible, the operational question becomes: will your organization, sector, or country be able to hold together when the incident is no longer a single event, but a multi-front pressure campaign?
A “mythos” sounds literary until you translate it into governance. In cyber security, narratives influence doctrine. Doctrine influences training. Training influences procurement. Procurement influences the talent you hire and the systems you prioritize. In other words, if the story your planners believe about how an AI-driven cyber crisis will unfold is wrong, your defenses become a set of well-designed responses to the wrong movie. Foreign Affairs is essentially arguing that China is trying to reduce that mismatch by shaping its expectations in advance, which can make the state more coherent when stress hits.
There is also a second-order implication for organizations outside government. Boards and executives do not just manage risk, they manage uncertainty. They also manage blame, because after a crisis comes a review, and reviews often lead to accountability. If China is preparing for an AI cyber crisis as a narrative-driven, scenario-based readiness challenge, then private firms operating in critical infrastructure, cloud, telecom, energy, logistics, or defense-adjacent supply chains should expect similar scenario thinking to spread beyond government agencies. That can show up as new compliance requirements, new tabletop exercises, and new “prove your resilience” demands from regulators and major customers.
Regulatory background is the other lever that turns “preparation” into real behavior. Over the last several years, regulation in cyber and data governance has increasingly tried to force minimum standards and reporting discipline. Even when rules do not name AI directly, they tend to define outcomes: continuity, incident disclosure timelines, data protection obligations, and security controls. In an AI cyber-crisis context, this creates a practical constraint for decision-makers. You cannot treat AI as an isolated technology risk. You have to integrate it into incident readiness, third-party risk management, and crisis communications. If an attacker can use AI to speed up lateral movement, generate convincing phishing, or accelerate exploit development, then your control framework needs to assume that your attacker is not waiting on human scheduling.
This is where “mythos” becomes more than a story about China. It is a reminder that states and large institutions plan with identity, not just arithmetic. They prepare not only for what attackers can do, but for how their own organizations will behave under pressure. The crisis you prepare for will become the crisis you rehearse. And what you rehearse becomes what you can execute quickly.
For executives, the strategic stakes are immediate. If AI-driven cyber conflict is treated as a single-incident challenge, you buy point solutions and run standard incident response. If it is treated as a crisis-scale contest, you invest in broader resilience, spanning detection and recovery, supply chain continuity, and cross-team decision rights. That difference is board-level, because it affects capital allocation and risk tolerance. Boards care about the “so what” under worst-case conditions: Can you keep critical operations running? Can you coordinate with regulators and partners quickly? Can you recover without cascading failures?
Foreign Affairs is pushing readers to take the planning premise seriously: an AI cyber crisis is coming, and China is preparing for it by building an overarching narrative framework that shapes expectations and readiness. If you are running a company or governing an institution in a world where AI can compress attack timelines and increase operational ambiguity, you need your own organization to be ready for the crisis you actually face, not the one you hope for.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Politics

Iran’s Esmail Baghaei says Oman talks start shipping via Hormuz, not US talks yet
Temporary route plans with Oman aim to restart commerce while Tehran says Washington dialogue is not on the table.

Standards watchdog opens probe into Reform UK deputy leader Richard Tice over interests
The parliamentary standards commissioner says it began an investigation on 28 July into a possible undeclared interest.

Michigan primaries test whether progressives can win battlegrounds, not just safe seats
El-Sayed, plus two House primaries, could reshape how Democrats message in Michigan and beyond before November.

