Authors
Melissa Morgan
News Type
Commentary
Date
Paragraphs

A breach of Hugging Face's servers. AI safety debates on Capitol Hill. New models like Kimi K3 coming online. There's been no shortage of headline grabbing AI news and debate in the last few weeks. To talk through these topics and how they relate to American national security, the heads of national security policy at OpenAI and Anthropic joined Colin Kahl on the World Class podcast.

Together, Sasha Baker (OpenAI) and Tarun Chabra (Anthropic) discuss how artificial intelligence is intersecting with security and defense strategies, the U.S.-China AI race, and how the risks and advantages of AI are starting to reshape national security.

Sasha Baker is the head of national security policy at OpenAI. Prior to that, she served as the acting under-secretary for policy and the deputy under-secretary of defense for policy at the Pentagon, and as the senior director for strategic planning on President Biden's National Security Council staff.

Tarun Chhabra is the head of national security policy at Anthropic. He previously served as deputy assistant to the president and coordinator for technology and national security on the National Security Council staff, where he coordinated the Biden administration's strategies for technology competition with China and technology partnerships with U.S. allies and partners. 

This episode's reading/watching recommendations are AI 2027, a project by Daniel Kokotajlo; AlphaGo, a documentary by director Greg Kohs; and "Nineteenth-Century Horse Sense" by Francis Thompson.

TRANSCRIPT:


Kahl: You're listening to World Class from the Freeman Spogli Institute for International Studies at Stanford University. I'm your host, Colin Kahl, the director of FSI.

I'm very excited to welcome my good friends and former colleagues Sasha Baker from OpenAI and Tarun Chhabra from Anthropic for what promises to be an insightful conversation on the good, the bad, and the ugly of how artificial intelligence is intersecting with national security. We're going to discuss the U.S.-China AI race, the risks AI poses to security, and the opportunities and advantages AI might generate in the national security space.

These are fantastic guests to help us grapple with these complex topics. Sasha Baker is the head of national security policy at OpenAI. Prior to that, she served as the acting under-secretary for policy and the deputy under-secretary of defense for policy at the Pentagon, and as the Senior Director for Strategic Planning on President Biden's National Security Council staff.

Tarun Chhabra is the head of national security policy at Anthropic. He previously served as deputy assistant to the president and coordinator for technology and national security on the National Security Council staff, where he coordinated the Biden administration's strategies for technology competition with China and technology partnerships with U.S. allies and partners. 

Sasha, Tarun, thanks for coming on to World Class. 

So look, I just told everybody your job titles; they’re very fancy. People know your companies. But perhaps we could start with describing what your roles at OpenAI and Anthropic actually entail.

Sasha, maybe let's start with you. What do you actually do on a daily basis?

Baker: Well first of all Colin, thanks for having me. It's fun to be here with two former colleagues. And what you didn't mention in my bio is that in my deputy role I was the chief “Colin Minder” of the Pentagon for a number of months.

What do I do? It's the most interesting job maybe I’ve ever had. I get to talk to governments all around the world every day about basically two things. The first is: what is the opportunity space look like as it relates to AI being used in the national security domain? So, how can we help governments that want to use these tools to make their populations safer? How do we help them do that?

And then the second thing that I talk to governments about is the AI risk space and the ways in which AI could up-level or enable a bad actor to do something that we really wouldn't want to see. So, I spent most of my career in government, as I think Tarun did as well. And what's fun about this job is it allows me to still be part of the same kinds of conversations that you and I would have had when we were serving at the Pentagon, but just from a totally different vantage point.

Kahl: Tarun, how about you?

Chhabra: Let me add my thanks, Colin, for having me too, and it's great to be here with Sasha and with you.

Obviously a lot of similarities in my role as well. I think of it as trying to help prepare policymakers for what we see as coming down the pike in AI development: to help them prepare and whether that's folks who are doing reporting and analysis, or whether that's folks who are making policy, or folks in Congress. We want them to know what's coming so that they're ready.

And then the second part, of course, is making sure we can get the best possible technology into their hands for national security purposes. As Sasha said, that's first and foremost with the U.S. government, but it's also, of course, with our closest allies as well.

Kahl: Great. Let's jump right into the types of conversations you're having. I'm sure as you're talking to officials around the world, there's a lot of focus on the U.S.-China AI competition. I think as many of our listeners will know, in recent weeks, Chinese AI labs have released some very impressive models, including ZAI's GLM 5.2 a few weeks back, and most recently Moonshot's Kimi K3. Obviously, people are familiar with very good models released by other Chinese labs like Deep Seek.

Tarun, maybe starting with you on this one: how would you assess the current gap between the best models coming out of Chinese AI labs and the frontier AI models coming out of labs like Anthropic and OpenAI? Is the U.S. ahead? If so, by how much? How would you assess the race right now?

Chhabra: I think our view's been pretty consistent even as new Chinese models have come out, which is, we believe that we remain six to nine months ahead of Chinese models at the frontier. And we think that really matters. So if you think about having really advanced cyber capabilities, having six to nine months with those superior capabilities really matters from a national security perspective.

That being said, we think that six to nine months owes a lot to the fact that leading Chinese AI model developers are distilling our models, those of U.S. frontier companies. And without that distillation, we could probably have a lead closer to around 18 months. And that would be even better, obviously, from a national security standpoint as well.

So that's why we've really appreciated the work that Sasha and colleagues at OpenAI have done to expose some of the distillation that is happening, why it matters, and we've really appreciated recent steps and pronouncements by the current administration to say this really is a national security issue that we need to be taking taking seriously.

It is important to note that distillation doesn't take you right up to the frontier. It keeps you behind. But the time really matters, and distillation is having a big impact.

And I think one reason why we see more attention to it right now is that the absolute capability you get from distillation matters too. And so as models become more and more advanced and more capable, even if we maintain that six to nine month gap, once you hit certain thresholds of absolute capability, that does become a concern.

Kahl: So just so that our listeners are following along. When you say distillation, really what we're talking about is a Chinese lab basically pre-trains their model. They run a big training run, but then as they're post training and fine tuning their model, they're actually engaging in a lot of queries back to say Claude or some version of GPT and using the answers from that to essentially reinforce the learning of their model and fine tune it.

Is that a fair description of distillation?

Chhabra: That's right. And as you have more capability baked into the model at that later stage of model development, the more opportunity there is for it.

I think it's important to note, however, that compute still matters. You can steal the recipe, but you still need a kitchen. So this is why we've been very vocal on the need to maintain export controls, whether it's on manufacture chips or the chips themselves, because that's a limiter. And many folks are still accessing these models for inference through APIs.

And in terms of the business model, even when the models are open, often these same companies are using their compute as a way to fund what they're doing.

It's really important to say this is industrial espionage. We've seen the playbook before where you have heavy, heavy subsidies from the Chinese state going into various industries to try to scoop up as much market share and then hold on to it for as long as possible. Except here I think it's not just a national competitiveness and economic issue, there are real national security consequences too.

Kahl: I want to come back to the export control issue in a second, but Sasha: does OpenAI generally share the assessment that the best models being produced by your company, by Anthropic, by Google Deep Mind are six to nine months ahead at the frontier? And do you share Tarun's concern about China basically being able to be a fast follower in part due to distillation?

Baker: Yeah, I think somewhere around the six month mark in terms of the lead is probably my best guess. Maybe there are just a couple points to make in addition to what you heard from Tarun.

The first is that not all distillation is bad. We distill our own models to create fine-tuned or fit-for-purpose versions of a model. And we allow developers to do some forms of distillation on our platform.

What we're really concerned about is what we would call ‘adversarial distillation’, which is unauthorized attempts to extract the capabilities of a U.S. frontier model in order to build something that then is kind of a competing system. And that is what I think has economic national security concerns.

I do want to be clear: there are a lot of very, very talented AI researchers in China, and I think it is the case that they would have very capable models even absent distillation. But this certainly does give them a leg up.

And I think the real thing to be concerned about here is actually the safety stack that comes from those distilled models. Because oftentimes they will distill a capability, but they won't export the safety stack. And so when you look at some of the models coming out of China—and this is true whether they're open or closed—you find that they are highly permissive in allowing for tasks that U.S. frontier labs spend tremendous amounts of energy trying to prevent.

And that has implications for the overall threat picture for global governance. And it's something that we oftentimes talk to them about. So that's an area where I think that there are real opportunities for us to do more together.

Because what all three frontier labs — so, Google, OpenAI, and Anthropic — have all put out assessments of where we see distillation happening on our platforms, but we can only see what's happening on our platform. And it requires that partnership with government and partnership with each other to be able to get a sense of the fuller ecosystem around this.

Kahl: All very interesting. Both you and Tarun have talked about distillation. My sense is that the fact that China is able to only be six or nine months behind . . . maybe that's partly due to distillation. 

I think there's also a view that they do have very smart engineers who have engaged in innovation in terms of algorithms. But they've also used smuggled NVIDIA chips, very powerful Blackwell chips have been used to train some of these models in illicit data centers. You also see reports of using, essentially, remote compute access from data centers in places like Malaysia to train these models.

I think a lot of that comes back to this debate about export controls, right? The first Trump administration put in export controls—very important ones—on semiconductor manufacturing equipment, especially advanced lithography equipment that are necessary to produce sub seven nanometer chips.

The Biden administration then layered on a lot more export controls on semiconductor manufacturing equipment and tools, and then also put controls on the sale of advanced chips directly to China. And yet China is still able to kind of fast follow.

So I guess the question is: does that suggest that export controls ultimately are always going to be imperfect? Maybe they're a fool's errand? They're not worth the cost? Or does it just suggest this is a game that you have to keep playing and there are ways in which the export controls need to be tightened.

And we'll start with you, Tarun. You've thought about this more than just about anybody I know.

Chhabra: I think the way to think about this is as a counterfactual. What if there had been no controls in place? Where would we be? And to the point you just made and that Sasha made earlier, China has tremendous AI talent and as you know also, they have a tremendous amount of energy that's coming online, it's something like 7 to 8x what is coming online in the United States, and that's before you get to the nuclear build out. 

But the one problem they have—and don't take it from me, take it from the leaders of China's top AI labs—is compute. That matters both for model development, but also for serving the models in terms of the race to to eat up global market share. 

And even with the latest releases over the last two weeks with GLM 5.2. and Kimi, you see already a problem in serving the level of demand to date. And again, one lab leader after another from China complains about the access to compute.

So absent the controls, could we be in a situation where China's in the lead? I think it's very possible.

Kahl: I think it's an important distinction you draw for our listeners who maybe aren't quite as in the weeds. Obviously there's all the computing resources: the data center is full of tens of thousands or hundreds of thousands or maybe even millions of leading edge AI accelerators.

But you also need compute to serve those models, that is to run inference. So anytime you pull out your smartphone and you prompt Claude or ChatGPT or Gemini, it's going back to a data center somewhere to run that query. And the more advanced the models, the more compute they require for inference to run really complex tasks. So compute obviously matters there, too.

I wonder, Sasha . . . you have all have discussed distillation as essentially IP theft. You also mentioned that these distilled models may not have the safety guardrails that some of the models that you all are producing. And we know that those are imperfect as they are.

Do you get a sense that the U.S. government is trending towards thinking about regulating Chinese models in some way? That is, either putting Chinese companies on an entity list or telling U.S. hyperscalers they can't serve Chinese models? Do you get a sense that the administration is thinking about clamping down on Chinese models because of so many of these issues?

Baker: I'm not sure we know any more about the answer to that question than you might also read in the newspaper.

What I can tell you about the conversations that we have with the U.S. government is right now we are talking with them about how do we create a mechanism of evaluating models—not just Chinese models, but American models or you know, models from around the world—so that we have a collective and common understanding of what we're even talking about here.

What are the capabilities of these models and how do you measure them? What are the safeguards around these models? How do you measure that? How do you determine what is sufficient? 

And I think that there's a really important role that the U.S. can play and U.S. leadership can play globally in helping to define some of those questions and create processes that will allow governments around the world to understand the landscape a little bit better. And then each government, I think, is going to make its own determinations about what they want to do with that information.

Kahl: One of the things that distinguishes a lot of the leading Chinese models is that many of them are open source or more precisely open weight in the sense that, you know, they can be downloaded and their parameters can be further modified or fine-tuned by users on their own servers.

And even when these models are accessed directly, at least from what I read, it seems like their API costs tend to be pretty low and their token usage tends to be very efficient.

In contrast, it seems like the best U.S. models tend to be closed weight, they're proprietary models, although there are some good open weight models that are being released by companies like NVIDIA and Thinking Machines.

But I guess the question I have, maybe Sasha starting with you is: what's the business model here for Chinese firms? They still have to spend money to train these models. They have to buy compute or lease compute to do it. They have to pay the salaries of all these really smart people who are working in these labs. And then they are essentially giving away their technologies for free or at very low pricing. How are they going to stay in business?

Baker: It's a super good question. Before I try to answer it, let me just say up front: we have always thought that there's an important role for open source models in the AI ecosystem. We have one ourselves. We think that they play a really important democratizing and innovation role. And there's room for open source and there's room for closed source models.

But having said that, there is the question about like, well, how do you actually make money off of a model if you're giving it away? And I think Tarun hinted at that answer earlier, which is that the model, in some cases, is actually not the product, right?

So if you think about some of these large Chinese labs — think of an Alibaba, for example — the model may be a loss leader that incentivizes other businesses into the Alibaba ecosystem, whether that's the cloud or what have you.

And then for some of the smaller labs, to Tarun's point, they may not charge for the model, but they can charge for the convenience, right? If you want to use the API, if you want access to their harnesses, etc. And there's a stickiness there that then gets people to kind of come back again and again.

At a nation-state level, I do think there's an element here, which is that the open weight approach is not just about having a standalone business model, it's also a distribution strategy that allows for the capture of market share. Because as I said, there's some stickiness to this. So we think competition is good; we compete, of course, across the American labs, we compete internationally. And that's healthy; it drives innovation.

We expect that businesses will evaluate and use a wide range of models. And we feel pretty good as a company about our value proposition, which is we have a model that is secure, that is reliable, that can deliver at scale, and that generates what we think is more useful work per dollar per token on a more reliable level than others that are out there.

And we feel good about that. And our customers tell us that that's something that sets OpenAI apart. So we're going to continue to try to do what we think we do best.

Kahl: Tarun, Sasha mentioned the state level, and you've thought a lot about what Beijing is trying to accomplish at the nation state level.

In one sense, open weight models are a good way to try to dominate AI diffusion, even if the capabilities of your models lag behind the frontier. But in another sense, at some point, these models are getting really, really capable, including at doing things that the Chinese Communist Party might not like, like hacking their own critical infrastructure or getting around the Great Firewall.

And I just wonder, do you think that the authorities in Beijing are going to continue to promote open weight models? Or at a certain point, do you think that they will cap the release of open weight models at a certain capability just because of a loss of control concern they might have?

Chhabra: I think it's a really, really important question, Colin.

So first, let me just say: I very much agree with Sasha. I think a healthy ecosystem is definitely going to include open models, proprietary models, but I think there are at least three factors here, and one is what you just described, which is the need for control on the part of the CCP is really insatiable. And so it is hard to see that there does not come a point where they become concerned about the capabilities that are let out into the wild, including cyber capabilities, and I think we could think about biocapabilities coming soon as well.

I think second, as Sasha knows as well as I do, that the current position of the U.S. government is for the frontier, particularly for models that are less safeguarded, they need to be in trusted access programs where you really know the actor, you trust the actor given the potential for harm. And second, it's been that where models are general access but very capable, there need to be very, very strong safeguards that the government itself now is testing. So that's kind of the U.S. government position right now.

I think the final piece of this is we shouldn't think about this totally ahistorically. We have seen this movie before where China provides very, very significant subsidies to eat up market share, not working within a free and fair market, and then come in and in a predatory way go after all competitors.

And remember, for many of the technologies where we have seen that happen before, there hasn't been necessarily a dedicated Polit Bureau session to discuss what their global strategy should be. There has been with AI, and Xi Jinping has been very clear on how he thinks about AI and how important it is as a strategic technology as well. So we should assume that the same playbook we've seen over and over again in other strategic technologies is at work here as well.

Kahl: Both you and Sasha have mentioned these safety and security issues. So maybe let's dive deeper into some of the risks that people are thinking about. 

A lot was made earlier this year about the cybersecurity capabilities when Anthropic held back the release, initially, of the Mythos model and established this Project Glasswing to kind of go shields up before the model went into the wild.

Obviously, Sasha, OpenAI's GPT 5.6 is an extraordinarily capable model at a lot of things, including coding. Some people have said, basically, that your companies have essentially created a skeleton key to the internet, that we now have models that are so good at identifying vulnerabilities and exploits that they can hack into any web browser, any legacy software.

Sasha, I read a blog post from OpenAI that said you were testing some combination of GPT-5.6 Sol and a new pre-release model in what was thought to be a closed sandbox on its cyber capabilities, and it hacked its way out of the sandbox, escaped into the open internet, got its way into a Hugging Face server and tried to steal secret information that would allow it to cheat on the evaluations you were you were doing.

So look, these models appear to be very good at hacking and are increasingly slippery. 

What is what keeps you up at night? Is it these cybersecurity risks? Tarun mentioned biosecurity risks. I've heard people talk about the possibility of maybe a Mythos moment for bio in 2026. Is it the prospect of recursive self-improvement of models that become able to improve themselves and perhaps become increasingly autonomous and out of control?

What are the AI risks that you're going around the world, Sasha, talking to leaders and enterprises that you're most concerned about?

Baker: To a certain extent, it's a little bit of all of the above. Maybe just to talk about the Hugging Face incident first. It’s an example of reward hacking, essentially, by the model. The model was given a task and it was very determined to complete that task. And because of the information that it had in its possession, it knew that the repository with the answer key existed in this Hugging Face repository.

So, it's an example of model determination, I guess, if nothing else. And of course, some very significant capability. We're doing as you would expect and taking a hard look at our security parameters around some of these models and the containers that we keep them in to make sure that we're up-leveling that as the models become more capable.

And that's maybe the one item I would put on your list that you didn't already mention, which is I think we need a new paradigm about thinking about model safety and security for agentic models that can take action on your behalf because that changes the dynamics and there are lots of ways that that could go sideways, including inadvertently. You don't have to have a nefarious intent. If a model doesn't fully understand what its boundaries and its guardrails are, it can do something that you might not expect it to do in the course of completing a task that you did expect it to to complete. And I think a little bit of that is what we're seeing here.

So that's an area where I think we, you know, we collectively as an industry need to pay more attention and a little bit more research.

Cyber and bio are challenges because they're inherently dual use, right? There are a lot of things that we would want these models to enable. We want them to be able to help create cures for diseases that currently have no solutions. We want them to help vetted cyber defenders protect their perimeters. But we have to then have a way as responsible actors In the ecosystem of trying to prevent those same capabilities from landing in the hands of somebody who might use them to do something that we as a human species, as a population, wouldn't want to see them do, right? 

So that's the reason that I think both Anthropic — and not to speak for Anthropic, Tarun—but both Anthropic and OpenAI have invested so heavily in these trusted access type programs, whether it's our trusted access or Glasswing, and in coordinating that to make sure that we really know who is using these tools and for what purpose.

Kahl: Tarun, what's your assessment of the risks? And maybe just to connect it back to our previous conversation on U.S. and and China, do you assess that the risks are different between the closed models that you're releasing and the open models that China tends to be releasing?

Chhabra: I agree with Sasha. We spend a lot of time talking about all of the above and I think the alignment issues come into sharp focus when we have incidents like what Sasha just described and credit to OpenAI for sharing that with everybody in a timely way. We've tried to do the same thing when we've seen examples of similar deceptive behavior. I think the alignment challenges are really, really important and hopefully we'll all be talking about them more collectively.

I think on the China side, this goes back to your question, Colin, about whether we're gonna hit a certain threshold for them where they are more worried about capabilities being released into the wild.

For a while you could speculate that they felt like they were more protected behind the firewall and that we were more vulnerable from a cyber perspective, and that they had demonstrated that by supporting Vol Typhoon, Self Typhoon, Name Your Typhoon, implanting into our and allied critical infrastructure. But it may well be that they hit a certain threshold where they worry about their own security, too.

I think the pure technical challenge with safeguards is, as we know, when you have access to all the weights, they can be more trivially broken. And that's something that, obviously, the U.S. government itself has been concerned about when they've asked us to kind of share with them the results of our own testing on our proprietary models, and then wanted to, I think rightly and understandably and commendably, test them themselves, too.

Kahl: Let's pause on the alignment question because both you and Sasha have raised it. How should we think about alignment? When alignment was first coming into the discourse around AI, frankly, I think a lot of people had in their minds like the science fiction image of a rogue superintelligence that basically tries to kill or enslave us all, right? HAL 9000, Skynet, the Matrix.

But I think what we could also imagine is just really, really powerful AI agents that have a lot of autonomy to complete tasks that they were given that generate outcomes that are not aligned with human interests or values. Not because the model is evil, but just because there's something about the model that we don't understand, or it's reward hacking, or it's doing something that creates a non-aligned outcome, even if the model is not doing it like intentionally to be some Bond supervillain.

Tarun, how should we think about the alignment issue?

Chhabra: Our approach to this has been first, we should be investing heavily in it, and we've been doing it from the earliest days of the company. And we have leading researchers like Chris Olah on the case, and we've been building out that team in a very, very significant way.

I think what we have tried to do is to document the earliest cases, even when they seem minor, even when they seem potentially a bit more trivial, just to document that this is emergent behavior that we ought to be worried about because to your point earlier and to Sasha's point earlier, as we see agentic activity really proliferate and as agents take on more and more consequential tasks, the ways in which you could have misalignment could really compound in terms of the consequences.

That's something that I hope we can continue to work with not only our enterprise customers, but also we've heard lots of great questions and important questions from our government colleagues about, too. They understand the ways in which they're likely to expand and use agents and have the same questions: how do they ensure that their agents are behaving in the ways that they would expect of the most professional intelligence or defense officials where the work is currently being done by humans?

Kahl: You mentioned your interactions with government officials. Let me ask a question about where you think the Trump administration is headed on this.

Early on in the second Trump administration, they were not too keen on AI safety. Although the Trump AI action plan in the summer of 2025 did have a section on what they called AI security, which noted risks around cyber and bio and some other concerns.

They appear to have become much more concerned about AI safety and security in recent months. We've obviously seen them take some actions to hold back the deployment of Anthropic’s Mythos and Fable models. They've also, I think, asked OpenAI to limit the initial deployment of GPT 5.6. A friend and colleague of ours, Dean Ball, has suggested that the Trump administration is trending towards a de facto licensing regime, essentially, on Frontier AI. 

Where do you think they're headed? Where do you think the administration is headed in terms of its requirements to do some testing and evaluation and kind of kick the tires on these things before it lets you release them into the wild. 

Sasha, maybe start with you.

Baker: I mean there's definitely an evolution happening here, and we're seeing more government officials across a broad range of agencies taking an interest in sort of understanding that the most capable AI models really do have security and safety significance.

I will say, there is a consistency, a through line here though. I have been in this role here at OpenAI now for about two years. So, I started in the last administration; I continued in this administration. And I actually am having a lot of the same conversations, right?

Because when you talk about national security risk, which is really a lot of what we mean when we say safety. It's not the only thing we mean, but a big chunk of it is cyber, bio, CBRN, things that are kind of in the national security domain, we find that governments have been paying attention to that for a while. It's certainly risen in prominence, and I think is certainly more public now than it was before. But the gist of the conversations hasn't changed all that much.

So where are they going? I'm not sure. If you know, we would love to know. But what I can say is that our feeling is like it's inherently a good thing, and we welcome the government being involved in this space.

Both Anthropic and OpenAI have had long-standing voluntary partnerships with what's now called the KC and with the UK AC, the AI Safety Institute in the UK as well, in part because we do think that governments should have a role in understanding and evaluating what these models are and what they're capable of. And we want that to be an ongoing conversation. And as the models get better, we think that that conversation probably needs to continue to become more robust as well.

So whether Congress passes a law, whether the administration takes action on its own, whether this remains voluntary, I can't predict. I can tell you that we will continue to volunteer because we think it's the right thing to do.

Kahl: Whatever one thinks of the administration's policy shift, it does strike me that you all would benefit from some degree of transparency over the standards against which your models are being judged and also some process that's predictable. So that when you go to them, you kind of can plan around, okay, it's gonna be 30 days and we have to release the model to KC and give this version to NSA, and they're going to hold it to these standards and we'll send engineers to help, blah, blah, blah, blah.

Do you have a sense that they are moving towards a more predictable process instead of standards that you all can plan around?

Chhabra: I think so. I think we can kind of already see what the emergent regime looks like based on what is being asked of us right now.

They want pre-deployment testing. They want to be able to test the safeguards when a model is generally available. They want a say in what a trusted access program looks like. We probably also all want some protocols on what happens when there's an alleged jailbreak incident, because we can imagine scenarios in which people could try to exploit fears about that, including adversaries. And so we should all have a playbook for what that looks like.

So in each of those areas, it's in everyone's interest—including the government's interest—to have a predictable and transparent regime for what this looks like so everyone can prepare because on their side, at a minimum, they want to make sure they have the right capabilities, the right people in place, the right protocols in place to kind of handle all the incoming because we we move at a pretty fast pace in putting out new models, in sharing new capabilities, and sharing what new risks look like. And so we just have to partner together on that.

And we’ve been asked for a lot of input on what this should look like. And so we're working together with them on it.

Baker: Maybe just to foot stamp one thing Tarun said, because I think it's really important, which is about capacity. There is a need for more AI expertise inside the government, across the board, but particularly when it comes to doing these kinds of technical evaluations of frontier models. And I give a lot of credit to the administration for trying some really innovative ways of bringing some of that talent into government.

But that is an area where I think we as industry can do more to lean in and support those efforts because in order for this to work well, there needs to be common understanding on both sides. And in order to have that, you really do need the technical understanding that's resident in the KC. It's resident in a couple other places in the government right now. But wouldn't it be great if we could just like 10x that?

Chhabra: If I could just add to Sasha's point here.

I think there's some really, really good news here, which is sometimes there's a misconception that in order to bring the most talented folks in government who have expertise in model development or safety or alignment, you have to kind of pay them outsized sums that are the same as what they are earning in the private sector. And it's just not true. Our colleagues at OpenAI, at Anthropic, at Google DeepMind who are developing these models are deeply mission oriented.

And if given the opportunity to work in a space where they know they will have impact, they have folks who will listen to them, you will have plenty of folks volunteering to do this work, especially now that there's a pretty strong direction to take these risks seriously.

And I found that to be true in government as well. It's not a coincidence that we were able to actually impose the initial export controls on China a month before ChatGPT was actually released, anticipating kind of where things were headed. We had the benefit of really terrific experts who wanted to serve in government because they knew they could have that kind of impact.

I think if we kind of create the right opportunities for them, we can ensure the right impact, we can really bring the talent that we need into the government.

Kahl: Well, I think all of us believe that public service is super important and that brilliant people should be motivated to serve their country to keep it safe and prosperous and free, even if they don't make the salaries they're making in the private industry.

I do wonder . . . we've mentioned Google a couple of times . . . I think Google has put forward a policy suggestion of creating basically an external auditing entity that maybe would be funded by industry, but not obviously governed by industry. It might actually be able to recruit and pay people a little bit more that would essentially work alongside government to audit your models based on your own safety criteria.

Is that something Anthropic has also talked about, and then Sasha, is this something OpenAI has talked about, or do you think their proper place for this auditing to happen is in the government?

Chhabra: Our approach, Colin, has been to basically offer what we think are a number of viable models and what you just described, we think, is one of them. There are a number of avenues that you could pursue.

I think though, whatever path you pursue with some sort of external testing capacity, the government is always going to want to have the ability internally to test when they want to and need to, and I think that's a good idea. That may be when they feel like they actually need to verify something an outside entity has tested and provided, or it may be that they have their own tests, you know, which they don't necessarily want to share with an external body, and there may be national security reasons for that as well.

Kahl: And Sasha, does Open AI have a view on whether there should be an external auditing entity in addition to the government?

Baker: I think we're interested in the idea that Google has put forward. There are obviously some mechanics of it that would need to be worked out and the details would need to be figured out. But there are other examples of how similar paradigms work in other industries, right?

You could think about like FINRA and the FCC as one model of something like that where there's sort of a government oversight body and a government accreditation body, but then there is an industry monitoring mechanism that is independent of government.

And so we're interested in this. We're talking with Google. I think Anthropic is as well, and we’ll see where those conversations go.

The other thing that we're really interested in — and I know, Tarun, we’ve talked about this in the past — is building out more of that independent evaluation ecosystem because right now we all work with a number of the same independent evaluators who have the expertise and the data sets and the benchmarks that we use to evaluate our models.

But the truth is as the models get better, we need new benchmarks because those benchmarks are getting saturated. And those are time intensive and they are data intensive and they are expertise intensive to create. And so the more that we can collectively do to up-level that outside ecosystem, whether it's in collaboration with government, whether it's industry funded—we're all members of the Frontier Model Forum, which is the sort of safety-oriented frontier model industry association—there are lots of ways that you can kind of get at this.

But I do think that there's starting to be a prevailing view that we need certainty in this process. We need to be able to scale the process as the models scale, and that we need to be in constant coordination both with each other and with the government.

Kahl: Sasha, I want to tap into your Pentagon experience for a minute.

Obviously we've talked a lot about the AI risk side of the equation in the security space, but there are a lot of national security applications for AI with a lot of upside for national security. 

We've seen in the wars in Ukraine and the Middle East AI being used. It's fusing intelligence. It's helping enable battlefield management. There are increasingly autonomous drones being used, especially in Ukraine.

I wonder again, with your former Pentagon hat on, as you look at the landscape, where do you think the most promising national security applications for frontier AI models are right now?

Baker: Thank you for your question. Because first it gives me an opportunity to pitch something that we just put out, which is a National Securities Principles document. Colin, I know you've seen this and we know some of the folks who worked on it behind the scenes.

Kahl: Yeah, it's a good document.

Baker: It was a really intensive and I think thoughtful effort across the company to try to articulate in a clear and enduring way how we approach questions of using AI models in this space. And it's a document we're pretty proud of.

So you can find it on the internet. If your listeners want to read it, you can go to our website and I encourage that.

But to answer your question. I get really jazzed about this question because I am still sort of a Pentagon nerd at heart. I would say maybe two things.

The first is there's so much low-hanging fruit that is not stuff that people are thinking about or talking about every day, and it's frankly not that controversial.

The U.S. military is the biggest bureaucracy in the world. You're talking about three million people, HR, healthcare, logistics, audit. All of these things are incredibly data intensive and places where AI tools — and frankly things that we've done in other industries — could be applied to save money, to create, to improve people's lives, to make workflows more efficient. That is the table stakes, and we should have been doing that stuff yesterday.

And then beyond that, I think the area where AI tools for me show the most promise has to do with what they're best at, right? Which is helping people process enormous amounts of data and information.

And when you think about what a modern battlefield looks like, it is essentially a data-saturated environment. And so the more that models can do to help humans . . . because you know, we talked about human in the loop and wanting to retain human judgment over high consequence decisions, including the use of force. But the ways in which models I think can be used appropriately and responsibly to help humans make better decisions faster is an area where I think we've only begun to kind of scratch the surface. And so there's a lot I think that we could do there.

When I talk about this internally and I talk about this even with governments around the world, I think it was Colin Powell who said this, right? That you never want to send your military into a fair fight. You always want to equip them with the tools that are going to allow them to have the greatest chance of coming home safely. And that is, for me, principle number one and the reason why I'm here and the reason why I feel so passionately about making sure that we have these partnerships with government in the national security space.

Kahl: Yeah. When you and I were at the Pentagon, Kath Hicks, who was the deputy secretary, used to talk about AI as a means for decision advantage, which I think is very much along the lines of what you just talked about.

Tarun, reports suggest that Claude is part of the Maven Smart System AI platform that is being used by the U.S. military in its current conflicts.

What are the biggest national security applications as you see it?

Chhabra: I think as Sasha said, there's a ton to be done at the enterprise level. And sometimes the best way to do that is just for senior military leaders to hear from leaders in enterprise about how they're using things for all of the things that Sasha described.

But I think it's a very straightforward proposition. It's see the battlefield more clearly with more precision and more breadth than the adversary. There's just incredible power in doing that.

And having your adversary know that we can do that obviously has powerful deterrence value as well because it enables far more decision support and it enables much, much much speedier action as well.

I think one of the areas where we're looking now, and I know you know OpenAI is doing the same, is where can we also try to help make up for the deficit in manufacturing, particularly for the defense innovation base. And could we use frontier models now to catch up and maybe even leapfrog Chinese capabilities if we stay at the frontier?

Already the models show a lot of promise without much fine-tuning in supporting robotics operations, for example. And we think there's a lot more that can be done here in the defense manufacturing base. So we're really excited about that work and hope all the labs can contribute to that.

Kahl: Awesome. Well, look, you know, one of my favorite podcasts is Ezra Klein's podcast. And at the end of his podcast, he always asks the guest for three books. Which I always feel intimidated by, because even as an academic, I don't have the time to read a single book most of the time. So I'm in the habit of asking our guests for a single article.

So, what is one article from each of you—Tarun we'll start with you and conclude with Sasha—one article you might recommend that our listeners check out to either understand AI or some other aspect of the world in 2026.

Tarun, any suggestions?

Chhabra: I think I have to cheat with two. I think Daniel Kokotajlo's AI 2027 work and that of his colleagues has actually aged pretty well. Maybe they actually underestimated the pace at which AI would progress. But I think kind of capturing how a government would think about some of the risks is really important to revisit today. When it came out in draft in 2024, it was a little bit far-fetched for a lot of people, but if you read it today, it doesn't look that way anymore.

The other one is, actually, since I'm talking to a Stanford professor: one of my favorite classes I took was with Gavin Wright in the history department who taught American economic history. Maybe he's still teaching a version of that course. And one of the things we read was an article by Francis Thompson, which was “Nineteenth-Century Horse Sense.” So it’s like the rise and fall of horses in the Victorian British economy.

And one of the things he documents there is with the advent of the steam engine, you actually had increased use of horses at the endpoints because you just had these isolated channels otherwise and without using more horses—so it's a version of Jevon's paradox—you actually couldn't make much use of it.

But then you hit a cliff at some point when the horses no longer became economically as efficient. But there were so many social and political choices that had to be made along the way, and so I think it's useful to think about that analogy today.

Kahl: Sasha, any farm animals on your list?

Baker: I can't say I've read the article about horses. Although it sounds interesting!

I'm going to cheat in a different direction and I'm gonna recommend a documentary.

There's a documentary called Alpha Go. It's about the deep mind model that was able to win the Go competition.

And what I think is enduring about that moment is it's really about technological surprise and how humans adapt and react to growing machine capability. And so in that sense, there's like an interesting throughline to the moment that we're in now. I'm pretty sure it's still available on Netflix. So if you're like me and you spend all day staring at words on a screen or paper and you want to see moving images instead, that's where I would start.

Kahl: My recollection—tell me if this is wrong. But Go is one of the world's oldest games. It's really, really difficult to master. It was assumed that AI could never do it. And then, Alpha Go basically, I think it was Move 37, infamously, came up with a move that so stunned the world's best Go player that he quit. And so it's like, AI doing the impossible, perhaps.

Baker: That's a good note to end on, Colin. AI doing the impossible!

Kahl: Well, thank you so much, Sasha. Thank you, Tarun, for taking time out of your busy schedules to make us all smarter about AI and national security. Good luck with everything, and we hope to have you back on the pod at some point in the future.

You've all been listening to World Class from the Freeman Spogli Institute for International Studies at Stanford University. If you like what you're hearing, please leave us a review and be sure to subscribe on Apple, Spotify, or wherever you get your podcasts to stay up to date on what's happening in the world, and why.

Read More

Colin Kahl, Director of the Freeman Spogli Institute for International Studies, on stage with panelists at the May 5 event, "World Changing Technology in 2026"
News

FSI Scholars Examine AI, Biotech Advances, and Geopolitical Competition

At a May panel discussion, experts from across the institute assessed biotechnology's resurgence, the mental health effects of social media, and growing concerns about AI-enabled bioweapons.
FSI Scholars Examine AI, Biotech Advances, and Geopolitical Competition
Eyck Freymann on the World Class podcast
Commentary

Uniting America's National Powers to Prevent a War Over Taiwan

Eyck Freymann joins Colin Kahl on the World Class podcast to explain his plan to bring America's military strength, economic leverage, technological leadership, and diplomatic influence together into a single, coherent plan to curtail China's ambitions toward Taiwan.
Uniting America's National Powers to Prevent a War Over Taiwan
A panel of men sit at a long table on a stage.
News

China's Innovative Capacity Is Underestimated — and the Stakes Are Growing

SCCEI brought together leading China scholars this spring for its third annual China Conference under the theme “Understanding ‘DeepSeek Moments’ and China’s Innovation Ecosystem.” Conversation centered around the idea that the world’s prevailing frameworks for assessing China’s innovative capacity often underestimate it, and the consequences of that blind spot are growing.
China's Innovative Capacity Is Underestimated — and the Stakes Are Growing
Hero Image
All News button
1
Subtitle

The heads of national security policy at OpenAI and Anthropic join Colin Kahl on the World Class podcast to discuss how AI is changing national security strategies and the nature of U.S.-China competition.

Date Label
Display Hero Image Wide (1320px)
No
Authors
News Type
News
Date
Hero Image
People, Politics, and Places Student Fellow Caroline Zhang (‘29) attended the event and served as a moderator.
People, Politics, and Places Student Fellow Caroline Zhang (‘29) attended the event and served as a moderator.
All News button
1
Subtitle

Hosted by the Close Up Foundation in partnership with the Stanford Deliberative Democracy Lab, Generation Lab, and the Hoover Institution’s Center for Revitalizing American Institutions, the program challenged participants to deliberate — not debate — some of the nation’s most pressing policy questions ahead of the 2026 midterm elections.

Date Label
Display Hero Image Wide (1320px)
No
Authors
Gi-Wook Shin
News Type
Commentary
Date
Paragraphs

This essay first appeared in The Diplomat.



For decades, South Korean strategy rested on a stable hierarchy within the international order. The alliance with the United States provided security; Seoul then managed relations with Japan, Europe, China, and regional institutions around that anchor. The alliance remains indispensable, but Seoul can no longer assume that this foundation will stay stable.

The evidence is visible in the way Washington now deals with allies. In 2025, the United States initially announced sharply differentiated “reciprocal” tariffs on South Korea, Japan, and the European Union. Negotiations later produced a 15 percent baseline framework for all three, but the process mattered as much as the final rate. Trade access, industrial investment, defense procurement, and alliance politics were increasingly handled as one bargaining package. Allies were not exempt from economic pressure because they were allies.

At the same time, Europe and Asia have been building connections that would have seemed highly ambitious a decade ago. The European Union signed security and defense partnerships with Japan and South Korea in November 2024. This year, the EU and Japan launched a defense-industry dialogue, while the EU and South Korea signed a digital trade agreement and began implementing cooperation on maritime security, cyber and hybrid threats, information manipulation, space, and the defense industry. The strategic map is becoming more networked. 

The network, however, remains uneven. Japan already has a mature economic partnership with the EU and rapidly expanding defense-industry ties. EU-South Korea relations are deepening, but they still lack the density and regular strategic consultation found in EU-Japan ties. A trilateral format would therefore do more than add another meeting: it would reduce asymmetry among three partners whose capabilities are increasingly complementary.


Sign up for APARC newsletters to receive our scholars' commentary and analysis >


The postwar hierarchy cannot simply be preserved by demanding more reassurance from Washington. Its resilience will depend on whether allies can build connective tissue among themselves before the next crisis forces them to improvise.
Gi-Wook Shin

South Korea, Japan, and the EU now face four converging challenges and pressures.

The first is demographic. South Korea is aging faster than any other OECD society; Japan’s working-age population has been shrinking for decades; and the EU’s fertility rate reached a new low in 2024. Demography is not a social-policy sidebar. It affects defense recruitment, industrial capacity, fiscal room, technological adoption, and the ability to sustain long-term commitments. Each actor is experimenting with immigration, automation, workforce policy, and welfare reform, but the security implications remain largely compartmentalized.

The second is concentrated economic dependence. None of the three can or should decouple from China. Yet South Korea’s experience after the THAAD deployment, Europe’s debates over economic coercion, and China’s export controls on gallium, germanium, and other strategic inputs have shown that interdependence can be converted into leverage. De-risking therefore requires more than national stockpiles. It requires shared risk maps, compatible certification, co-investment in alternative suppliers, and advance consultation before export controls or industrial subsidies create collateral damage among partners.

The third challenge is U.S. volatility. The United States is still the only actor capable of providing extended nuclear deterrence to South Korea and Japan, and NATO remains central to European defense. But dependence on U.S. power now coexists with uncertainty about U.S. policy. The classic alliance dilemmas of abandonment and entrapment are no longer opposite ends of a spectrum. Today, U.S. allies fear both being left out and being drawn into bargains or contingencies they did not shape.

The fourth pressure is the collapse of the old geographic separation between European and Asian security. North Korean munitions, missiles, and troops have supported Russia’s war against Ukraine. Moscow, in turn, has provided Pyongyang with political cover, economic support, and the prospect of military know-how. What happens on a European battlefield is changing the military balance on the Korean Peninsula. A regional response to a cross-regional threat is structurally inadequate.

This is the case for an EU-Japan-South Korea strategic dialogue. This framework should not be described as strategic autonomy, equidistance, or a hedge against the United States. A better term would be institutionalized hedging: risk diversification through standing, rule-based consultation among allies and partners that remain anchored in the broader U.S.-led system.

The proposal is more feasible than ever before. Japan-South Korea relations have improved significantly in recent years. The January 2026 summit in Nara and the reciprocal summit in South Korea in May demonstrated continuity across leadership changes in both countries since June 2025. The EU already has free-trade, digital, green, and security frameworks with both countries. The task is not to invent three new bilateral relationships; it is to connect existing ones.

The dialogue should begin modestly, through a Track 1.5 process involving officials, experts, and industry. Its early agenda must be concrete and specific: a joint critical minerals and supply chain risk assessment; consultation on export controls and investment screening; cooperation on AI, cyber resilience, and digital standards; exchanges on demographic and defense workforce adaptation; and shared monitoring of North Korea-Russia military cooperation. Successful projects could then be elevated to ministerial working groups.

Two design choices are essential. First, the initiative must remain function-driven. It is not NATO, not the Quad, and not an anti-China coalition. Its purpose is to reduce vulnerability without demanding economic separation. Second, it should be complementary to relations with Washington and transparent about that purpose. Horizontal networks strengthen alliances when they help allies absorb shocks, coordinate positions, and arrive at consultations with greater capacity.

For South Korea, the need is particularly acute. Japan already has the G7, a mature economic partnership with the EU, and expanding European defense ties. Seoul’s international weight has grown faster than its institutional depth. An EU-Japan-South Korea dialogue would help close that gap.

Horizontalizing alliances is not a vote of no confidence in the United States. It is insurance for the moments when the United States wavers, overreaches, or changes course. The postwar hierarchy cannot simply be preserved by demanding more reassurance from Washington. Its resilience will depend on whether allies can build connective tissue among themselves before the next crisis forces them to improvise.

Read More

Panelists gather for a group photo at the 2026 Oksenberg Conference.
News

Indo-Pacific Powers Diversify and De-Risk as Multipolar World Takes Shape

At the 2026 Oksenberg Conference, scholars and foreign policy experts assessed how Indo-Pacific powers are coping with a less predictable United States as China pursues selective leadership and Russia exploits Western divisions.
Indo-Pacific Powers Diversify and De-Risk as Multipolar World Takes Shape
People cross a road in the Akihabara district in Tokyo, Japan.
News

Japanese Public Sets High Bar for Immigrants

The latest findings of the Stanford Japan Barometer show that the Japanese public’s opinion on immigration depends heavily on applicants' skills, language ability, and country of origin, and on whether politicians emphasize economic benefits or stoke security and cultural anti-immigration rhetoric.
Japanese Public Sets High Bar for Immigrants
Hero Image
Illustration of three speech bubbles representing (from left to right) the flags of the EU, Japan, and South Korea.
Illustration made with Canva AI.
All News button
1
Subtitle

The trilateral is more feasible – and more important – than ever before.

Date Label
Display Hero Image Wide (1320px)
Yes
Authors
News Type
News
Date
Paragraphs

Introduction and Contribution


A burgeoning literature considers the domestic causes and consequences of democratic backsliding for public perceptions of democracy but has yet to fully examine the role of international factors in explaining these perceptions. The effect of democratic backsliding in one

democracy on public support for democratic principles in other countries has, thus far, defied theoretical and empirical investigation. In “U.S. Democratic Backsliding and the Decline of Democratic Support Abroad,” Amnon Cavari, Amichai Magen, and Benjamin Yoel address this gap in knowledge. They propose and test a theory of the effects of backsliding on global opinion, in which information about democratic decline in one country can lead to diminished support for liberal democracy and increased support for authoritarian governance in another. To test this, they deployed an original survey experiment in Israel to examine the effect of two narratives about the 2020 U.S. elections — one signaling democratic decline and one signaling democratic resilience — on support for authoritarian governance. They found that respondents exposed to the narrative of U.S. democratic decline were more supportive of authoritarian governance than those exposed to the narrative of democratic resilience. Moreover, they find marginal evidence that the respondents’ ideological preferences condition the effect of narrative exposure. Cavari, Magen, and Yoel’s findings suggest that the democratic backsliding literature has insufficiently explored the global consequences of domestic events and processes for democratic decline worldwide.

[The authors] propose and test a theory of the effects of backsliding on global opinion, in which information about democratic decline in one country can lead to diminished support for liberal democracy and increased support for authoritarian governance in another.

Democratic erosion is both a supply- and demand-side phenomenon. On the supply side, leaders take anti-democratic actions, such as weakening checks on executive power, which they then justify to the public — on grounds of law and order, threats to the nation, and so on. On the demand side, varied types of social conflict, such as polarization or racial animus, can lead publics to endorse limits on democratic governance. 

Real-life models of democratic erosion have ‘diffused’ across borders. For example, strongmen in countries neighboring Russia, such as Alexander Lukashenko and Viktor Orbán, have borrowed from Vladimir Putin’s playbook of jailing opponents and using anti-Western rhetoric. It is less clear, however, whether authoritarian phenomena in one country can prompt changes in the beliefs of ordinary people in other countries.

In “U.S. Democratic Backsliding and the Decline of Democratic Support Abroad,” Amnon Cavari, Amichai Magen, and Benjamin Yoel present results from a survey experiment conducted among Israelis following the January 6 United States Capitol attack. They find that respondents who were randomly exposed to a narrative about US democracy eroding were significantly more supportive of autocracy in Israel. By contrast, those exposed to a narrative about the resilience of US democracy after January 6 were less supportive. These effects were most pronounced among conservative Israelis, perhaps unsurprising given the associations between right-wing ideologies and authoritarianism.

They find that respondents who were randomly exposed to a narrative about US democracy eroding were significantly more supportive of autocracy in Israel. By contrast, those exposed to a narrative about the resilience of US democracy after January 6 were less supportive.

Readers come away with a sense of the varied ways that democratic erosion can diffuse across borders, particularly at the micro level. That changes in American politics can affect the attitudes of Israelis over 6000 miles away suggests that autocrats can be highly effective in shaping the regime trajectories of their more immediate neighbors. This makes it all the more urgent to combat anti-democratic narratives before they take root and spread.

How Authoritarian Attitudes Diffuse


The authors make a straightforward claim: someone in country A who observes democratic norms or institutions being undermined in country B may well question the value of democracy for A. To see this, consider how Nayib Bukele’s campaign of mass imprisonment without due process in El Salvador has appealed to ordinary people across Latin America. In light of the social and economic problems facing democratic countries, unchecked strongmen — and their purported successes — have come to seem more credible and pragmatic. 

Democratic erosion in country B should be especially likely to affect the beliefs of people in A when (1) B is a close ally of, or is seen as powerful or influential for A, and (2) events in B are widely covered in A’s traditional or social media. For example, coverage of the United Kingdom’s “Brexit” was shown to influence how people in other European Union countries viewed integration or withdrawal. The authors further posit that democratic erosion will have a larger effect on support for autocracy among those who subscribe to right-wing ideologies — these prioritize social order and religious or racial purity, which can conflict with inclusive democracy. 

Backsliding in Israel and Ties to the United States


Israeli democracy has eroded in recent years, particularly as Benjamin Netanyahu’s Likud party has worked to undermine judicial independence and as discrimination against Arab and other ethnic minority Israelis persists. However, Israel’s backsliding also has strong demand-side components: majorities of those surveyed in 2023 agreed that a strong leader — one not limited by the legislature or judiciary — was necessary to solve Israel’s problems, that voting rights should be restricted among those unwilling to declare their loyalty to the state, and that international NGOs should be banned. The authors aim to show that these anti-democratic beliefs stem not only from elite rhetoric or national polarization, but from global backsliding. 

The United States is Israel’s closest ally, and the two countries share much in terms of political and social life. Both were founded by groups fleeing persecution, who established a political culture defined by pioneer settlement and the displacement of indigenous peoples. The US has consistently supported Israel’s wars and military operations in the Middle East. A large majority of Israelis view the US as an exemplar of democracy and freedom. This makes Israel an ideal case for measuring how global democratic erosion affects democratic sentiment at home. 

The Survey Experiment


The survey was fielded in March 2021, a time of acute political crisis in Israel: this marked the fourth election cycle in less than two years, and the prior two elections had resulted in parliamentary stalemates and short-lived governments. In the prior months, Israeli media had extensively covered Donald Trump’s efforts to overturn the 2020 elections and ensuing January 6 attack on the Capitol. 92% of survey participants reported following the US elections, and 43% reported doing so closely. A majority reported believing the US strongly influences Israeli politics.

Participants were randomly assigned to read one of two ‘vignettes’ about the 2020 elections. One emphasized that US democracy had faltered, as evidenced by Trump’s behavior and the Capitol attack. Another emphasized the resilience of US democracy, as evidenced by high turnout and the eventual transfer of power — this vignette did not mention January 6. The authors find that those who read the “US democracy faltering” vignette were significantly less likely to agree the US elections were free and fair. 

Finally, the authors measure their dependent variable — support for autocracy — in terms of support for restricting speech that is hostile to the government, the permissibility of rule by strongmen, and so on. The key finding is that Israelis exposed to the “US democracy faltering” narrative were significantly more supportive of autocracy.
 


 

Image
Figure 3. Support for Authoritative Governance, by Vignette.

 

Figure 3. Support for Authoritative Governance, by Vignette.
 



These effects were most pronounced among those on the political right, but the main finding holds even when statistically controlling for ideology. In all, the study demonstrates that when democratic erosion diffuses, it can shape not only elite behavior but mass attitudes as well.
 


 

Image
Figure 4. Effect of ideology on support for Authoritative Governance by Vignette.

 

Figure 4. Effect of ideology on support for Authoritative Governance by Vignette.
 



*Brief prepared by Adam Fefer.

Hero Image
Israeli and American flags flying in front of brick building in Jerusalem.
Shalev Cohen
All News button
1
Subtitle

CDDRL Research-in-Brief [5-minute read]

Date Label
Display Hero Image Wide (1320px)
No
Authors
News Type
Blogs
Date
Paragraphs

This article was written by Dr. Thomas Fingar, who played an early role in the establishment of SPICE before helping to establish and then leading Stanford’s U.S.–China Relations Program before moving to the U.S. State Department where he served twice as Assistant Secretary for Intelligence and Research. He later served as Deputy Director of National Intelligence for Analysis and Chairman of the National Intelligence Council before returning to Stanford in 2009. This is the sixth of several articles—focusing on the 50-year history of SPICE—that will be posted this year.

The celebration of SPICE’s 50th anniversary attests to the continuing vitality, impact, and success of ideas and constructive activism engendered by unique circumstances at Stanford in the late 1960s and early 1970s. The Bay Area China Education Project (BAYCEP) and its successor organization, the Stanford Program on International and Cross-Cultural Education (SPICE), did not just happen and its success was not assured. Many innovative projects were launched during that turbulent and transformative period but few survived or had a lasting impact. It is worth reflecting on what made this Stanford initiative different and more successful.

Context matters and it is useful to recall the political and academic environment at the time. It was the golden age of area studies when universities and the national affairs enterprise struggled to understand the societies, cultures, politics, and policies of the more than 100 ‘new’ nations that regained independence or emerged from revolution after World War II. New social science methodologies were developed to support this undertaking, and new ways to teach foreign languages and foreign cultures broadened horizons and facilitated people-to-people interactions that transformed exotic ‘others’ into fellow travelers on planet earth. Stanford was at the forefront of both the area studies and methodological revolutions.

The Vietnam War was a second critical shaper of information and ideas. This was the first ‘television war’ and it gave an immediacy to what was happening in Washington and on the other side of the world. The ‘enemy’ was humanized and the draft forced ordinary Americans to think about people, places, and government policies that were opaque and increasingly personal. Antiwar activism included demonstrations and ‘teach ins’ to educate the public about what was happening and why. These activities occurred in the context of growing dissatisfaction with many gaps between American values and everyday injustice affecting racial minorities, women, the elderly, and the poor. Determination to do something about increasingly unacceptable conditions was rampant.

These factors, and others such as the large size of the area studies community at Stanford and the leadership of key faculty, coalesced in ways that galvanized determination and efforts to link area studies-focused academic research to political action, classroom instruction, and public education. The logic was straightforward. Those at the leading edge of area studies had both an opportunity and an obligation to use what they learned about other countries and cultures to inform and influence politicians and policymakers so that they would see the error of their ways in Vietnam and Asia more broadly and adopt policies more conducive to mutual understanding, peace, and shared prosperity.

The logic of the situation and our understanding of the importance of public opinion in a democracy also drove us to seek ways to use our understanding of Asia to bring Asia and Asians into American classrooms. That meant, among other things, expanding coverage of Asian culture and history in American secondary school textbooks and developing teaching materials and training programs for high school teachers. Fifty years later, it is difficult to imagine how little information and teaching material was available. One reason that is the case is that the founders of SPICE used their knowledge of American education, textbook publishing, and teacher training to move beyond the Europe-centric content of what was and is taught in the United States.

The energy and activism during the formative period did not dissipate when graduate students earned their degrees and embarked upon the next stage of their careers. Some continued to work in and through the SPICE structures. Others accepted positions in the U.S. Government and other nonacademic institutions so that they could play direct and indirect roles in shaping official understanding and public policies. Their activities both contributed to public understanding and utilized increased public awareness and understanding to influence public policy. 

There is a bigger story to be told than the narrow component that was and is the SPICE program, but to say that is not to diminish the importance and impact of the classroom and public education achievements of the people and projects undertaken in the decades since SPICE was originally conceived. I am proud to have been a part of those early efforts and even prouder of the fact that SPICE remains as vital and vibrant as it is today and that I still have opportunities to lecture in its programs. 

To stay informed of SPICE news, join our email list and follow us on Facebook, X, and Instagram.

Read More

two people posing for a photo
Blogs

Celebrating SPICE’s 50th: SPICE’s Latin America Project, 1976–1998

Dr. Bert Bower reflects on the early years of SPICE’s Latin America Project and how his experience with SPICE enriched and informed his career.
Celebrating SPICE’s 50th: SPICE’s Latin America Project, 1976–1998
three people standing
Blogs

Celebrating SPICE’s 50th: SPICE’s Africa Project, 1982–1985

Professor Emeritus Larry Becker reflects on the early years of SPICE’s Africa Project and how his experience with SPICE enriched and informed his academic journey and teaching practice.
Celebrating SPICE’s 50th: SPICE’s Africa Project, 1982–1985
a family photo at the Japanese Tea Garden in Golden Gate Park
Blogs

Celebrating SPICE’s 50th: Adding SPICE to My Life

Professor Emeritus Steve Thorpe reflects on his years at SPICE from the late 1970s to the 1980s.
Celebrating SPICE’s 50th: Adding SPICE to My Life
Hero Image
two men in jackets standing
Dr. Thomas Fingar with Stanford political scientist Dr. John Lewis in China in 1978. | Photo courtesy of Thomas Fingar
All News button
1
Subtitle

Shorenstein Asia-Pacific Research Center Fellow Dr. Thomas Fingar reflects on the early years of BAYCEP and SPICE.

Date Label
Display Hero Image Wide (1320px)
No
Authors
News Type
Blogs
Date
Paragraphs

Applications are now open for Stanford e-Entrepreneurship Japan (SeEJ), a free online course conducted in English to foster Japanese students’ creative thinking and innovative problem-solving skills to address social issues. SeEJ is offered twice a year in the fall and spring through a collaboration between SPICE and the non-profit organization e-Entrepreneurship in Japan. It is open to Japanese-speaking students, in or from Japan, in their first and second years of high school. The fall 2026 course will be taught by Irene Bryant and will run from late October 2026 through February 2027.

The application form is now available at https://forms.gle/5gkHrhm3X4sycZGG8. The submission deadline is September 6, 2026, at 11:59 PM Japan Time.

This program embodies something deeply aligned with the spirit of Stanford — the belief that learning should be accessible to everyone.
Taiga Miyashita, fall 2025 participant

Stanford e-Entrepreneurship Japan offers students an opportunity to engage with scholars and entrepreneurs from Stanford University and beyond through live virtual classes, which are held twice a month on Sundays. The course will culminate in an individual research paper and a final group project. Students who successfully complete the course will receive a Certificate of Completion from SPICE and NPO e-Entrepreneurship.

Former students describe SeEJ as both an accessible and transformative learning experience. As Taiga Miyashita shares, “When I first joined, I quietly wondered, ‘Do I really belong here?’ Yet by the end, I had researched a field I genuinely cared about, articulated my own solutions, and contributed meaningfully to our group work. This program showed me that I didn’t have to let concerns about my English stand in my way.” Toma Ihara similarly reflects on the program’s lasting impact, describing Stanford e-Entrepreneurship Japan as “not just another course, but a life-changing experience.” Toma adds, “The program equipped me not only with the tools of an entrepreneur, but also with a mindset that I now apply to my NPO and startup ventures.” These reflections illustrate how SeEJ combines a supportive learning environment with hands-on opportunities that help students build confidence and apply what they learn beyond the program.

For more information about Stanford e-Entrepreneurship Japan, visit the program webpage. Interested high school students should apply online by September 6, 2026.

Stanford e-Entrepreneurship Japan is one of several online courses offered by SPICE.

To stay updated on SPICE news, join our email list or follow us on FacebookInstagram, and X.

Read More

a student in front of Memorial Church during a summer program at Stanford University
Blogs

Stanford e-Entrepreneurship Japan: A Powerful Platform for the Next Generation of Social Entrepreneurs

High school student Minami Ohno, an alumna of Stanford e-Entrepreneurship Japan, reflects on her experience throughout the program and how it expanded her perspective. Minami is currently a student at the International School of the Sacred Heart in Tokyo, Japan.
Stanford e-Entrepreneurship Japan: A Powerful Platform for the Next Generation of Social Entrepreneurs
a person standing in front of Tanah Lot
Blogs

Stanford e-Entrepreneurship Japan: Empowering Young Visionaries to Reimagine Global Challenges for Social Good

High school student Erin Tsutsui, an alumna of Stanford e-Entrepreneurship Japan, reflects on forging friendships across Japan, embracing new world perspectives through thoughtful discussion, and transforming family heritage into a youth-led peace initiative via empathy and social innovation.
Stanford e-Entrepreneurship Japan: Empowering Young Visionaries to Reimagine Global Challenges for Social Good
a group of students standing with signs, "TBC Japan"
Blogs

Let’s Be the Strikers: Thoughts on the 2025 Teenage Business Contest Japan

Millie Gan, an alum of Stanford e-Entrepreneurship Japan and founder of Teenage Business Contest Japan (TBCJ), reflects on building a platform that empowers teens to use entrepreneurship and innovation to revitalize Japan’s communities.
Let’s Be the Strikers: Thoughts on the 2025 Teenage Business Contest Japan
Hero Image
rainbow on stanford campus
A fleeting moment of color and light—nature’s brilliance arches over Stanford’s historic campus, a reminder of beauty in the unexpected. | Photo Credit: Andrew Broadhead
All News button
1
Subtitle

Applications are now being accepted for the fall 2026 session. Interested high school students in Japan should apply by September 6, 2026.

Date Label
Display Hero Image Wide (1320px)
No
Authors
Rylan Sekiguchi
News Type
News
Date
Paragraphs

SPICE offers several local programs for students in Japan, including regional programs at the city and prefectural levels. Developed through collaborations between SPICE and local governments across Japan, these online programs encourage students to engage with complex global issues while deepening their understanding of U.S. society, culture, and U.S.–Japan relations through critical thinking and research.

With the 2025–2026 session now finished, each participating program has recognized two outstanding students for their exceptional achievements throughout the course, including the quality of their final research projects. These student honorees will travel to Stanford University in August 2026, where they will present their research during a series of recognition ceremonies. The events will welcome distinguished guests from the Stanford community, the Consulate General of Japan in San Francisco, and members of the Japanese community throughout the Bay Area.

SPICE proudly congratulates the following students for their outstanding academic accomplishments.

Stanford e-Fukuoka (Instructor: Kasumi Yamashita)

Student Honoree: Konoha Inoyusu
School: Fukuoka Daichi High School

Student Honoree: Haruki Kenyon
School: Kurume High School

Stanford e-Hiroshima (Instructor: Rylan Sekiguchi)

Student Honoree: Konatsu Haga
School: Fukuyama Akenohoshi Girls’ High School

Student Honoree: Momoka Nagayama
School: Hiroshima Inokuchi High School

Stanford e-Kagoshima City (Instructor: Amy Cheng)

Student Honoree: Nayuta Nei
School: Kagoshima Gyokuryu High School

Student Honoree: Shiori Nishizono
School: Kagoshima Girls’ High School

Stanford e-Kawasaki (Instructor: Maiko Tamagawa Bacha)

Student Honoree: Mio Suzuki
School: Kawasaki High School

Student Honoree: Rio Hojo
School: Tachibana High School

Stanford e-Kobe (Instructor: Alison Harsch)

Student Honoree: Sakura Oe
School: Kobe Municipal Fukiai High School

Student Honoree: Shotaro Take
School: Kobe Municipal Fukiai High School

Stanford e-Oita (Instructor: Kasumi Yamashita)

Student Honoree: Mao Hieida
School: Nakatsu Minami High School

Student Honoree: Taichi Morikawa
School: Takada High School

Stanford e-Tottori (Instructor: Jonas Edman)

Student Honoree: Una Ishikawa
School: National Institute of Technology, Yonago College

Student Honoree: Asumi Nishimura
School: Tottori Nishi High School

Stanford e-Yamaguchi (Instructor: Jonas Edman)

Student Honoree: Misaki Kobayashi
School: Keishin Senior High School

Student Honoree: Hiroi Tomokawa
School: Iwakuni Senior High School

SPICE commends these students for their intellectual curiosity, academic excellence, and commitment to developing a global perspective. We look forward to recognizing their accomplishments at Stanford University next month.

SPICE also offers online courses to U.S. high school students on Japan (Reischauer Scholars Program), China (China Scholars Program), Korea (Sejong Korea Scholars Program), and entrepreneurship (Stanford e-Entrepreneurship U.S.), and online courses to Chinese high school students on the United States (Stanford e-China) and to Japanese high school students on the United States and U.S.–Japan relations (Stanford e-Japan) and on entrepreneurship (Stanford e-Entrepreneurship Japan).

To stay informed of news about Stanford e-Japan and SPICE’s other programs, join our email list and follow us on FacebookX, and Instagram.

Read More

students and an instructor sitting in a circle in a classroom
Blogs

Celebrating 10 Years of the Stanford e-Tottori Program

SPICE instructor Jonas Edman reflects on a decade of teaching SPICE’s first regional program in Japan.
Celebrating 10 Years of the Stanford e-Tottori Program
Hero Image
green library and hoover tower on Stanford campus
Meyer Green, Stanford University | Photo Credit: Meiko Kotani
All News button
1
Subtitle

Congratulations to the 16 student honorees from Fukuoka Prefecture, Hiroshima Prefecture, Kagoshima City, Kawasaki City, Kobe City, Oita Prefecture, Tottori Prefecture, and Yamaguchi Prefecture.

Date Label
Display Hero Image Wide (1320px)
No
Subscribe to United States