U.S. House War Game Warns China’s AI Cyberattacks Could Cripple American Ports, Railroads, Airports, and Utilities During a Taiwan Crisis


July 27, 2026, 4:12 a.m.

Views: 1248


House Homeland, China

U.S. House War Game Warns China’s AI Cyberattacks Could Cripple American Ports, Railroads, Airports, and Utilities During a Taiwan Crisis

A bipartisan congressional war game has exposed a dangerous reality Americans can no longer afford to treat as science fiction: if China gains access to highly advanced artificial intelligence, Beijing could use cyberattacks against U.S. ports, freight railroads, airports, utilities, and transportation networks to obstruct America’s military response during a crisis over Taiwan.

Members of the House Committee on Homeland Security and the House Select Committee on China participated in the closed-door exercise examining the consequences of the People’s Republic of China obtaining what lawmakers described as “Mythos-level” AI capabilities.

Representative Michael McCaul led lawmakers through a simulated confrontation in which an AI agent modeled Chinese and American cyber strategies and launched coordinated attacks against U.S. assets and critical infrastructure.

The exercise was not evidence that the specific simulated attacks have already occurred. It was designed to test how the United States might respond if Beijing combined its existing cyber strategy with a powerful AI system capable of identifying vulnerabilities, stealing credentials, disrupting logistics, manipulating information, and preserving hidden access for use during a military emergency.

That distinction does not make the scenario less urgent. China-linked cyber actors have spent years searching for weaknesses in American government and civilian networks, including systems connected to critical infrastructure. The danger presented by advanced AI is that it could accelerate nearly every stage of such an operation, allowing attackers to move from human-speed reconnaissance to automated exploitation at computer speed.

The war game began with China conducting a massive military exercise around Taiwan in the summer of 2027. American officials in the simulation could not immediately determine whether Beijing intended to intimidate Taiwan, impose a de facto blockade, or prepare for a full invasion. At the same time, suspected Chinese hackers began targeting transportation systems that the United States could need to move troops, equipment, fuel, and supplies across the Indo-Pacific.

This is the central threat. A future conflict with China would not necessarily begin with an attack on an American warship or military base. It could begin with freight trains routed incorrectly, port terminals forced offline, airport systems disrupted, utility networks made unreliable, and logistics companies unable to determine which information can be trusted.

Modern American military power depends on civilian infrastructure. The Pentagon does not own every railroad, port crane, commercial communications network, power provider, warehouse, or transportation platform required to deploy forces. Much of the system is operated by private businesses and local authorities that were never designed to withstand an artificial intelligence-assisted campaign conducted by a hostile government.

China could exploit this dependence by attacking the support systems behind American military power rather than confronting the military directly. Disabling a port terminal may delay equipment without sinking a ship. Corrupting railroad routing data may prevent supplies from reaching deployment centers without destroying a train. Interrupting electricity or communications may slow mobilization while allowing Beijing to deny that it has begun a conventional war.

Some simulated attacks produced immediate disruption, while others appeared intended to preserve access that Chinese operators could activate later. This second category may be even more dangerous. A hostile actor that quietly establishes itself inside American networks can wait until the moment of greatest strategic value before using that access.

Such pre-positioning transforms cybersecurity from a technical problem into a military one. Malicious access hidden inside a port, railroad, airport, power system, or logistics platform may remain dormant during peacetime. Once China moves against Taiwan, the same access could be used to slow the arrival of American forces, confuse decision-makers, increase economic pressure, and create political demands for Washington to avoid intervention.

The exercise also included attacks using stolen credentials, interference with logistics and routing systems, an AI-assisted disinformation campaign, and prompt injection against an artificial intelligence system. Prompt injection attempts to manipulate an AI model into following hostile instructions rather than its intended safeguards.

This illustrates why AI creates risk on both sides of the cyber battlefield. An advanced American model could identify and repair software vulnerabilities before attackers exploit them. Yet a model obtained, copied, distilled, manipulated, or reproduced by China could help Beijing locate the same weaknesses and attack them at enormous scale.

The congressional committees have already begun investigating the growing use of Chinese-developed AI models in American products and services. Lawmakers have raised concerns that China is attempting to close the innovation gap through model distillation, intellectual property theft, and other methods, while Chinese models may create cybersecurity and data-security risks when deployed inside American systems.

The danger is not limited to China inventing a superior AI model independently. Beijing could seek to extract capabilities from American systems, copy the behavior of leading models, obtain stolen research, or exploit commercial access offered by U.S. companies. American innovation could then become a tool used to attack American infrastructure.

This is why the AI competition cannot be reduced to which country releases the most impressive chatbot. Frontier AI can discover software vulnerabilities, automate portions of cyber operations, generate deceptive content, analyze enormous data sets, and assist attackers in adapting their methods more rapidly than human teams can respond.

During a congressional demonstration, lawmakers were shown how an advanced model could identify a vulnerability in a bank and exploit it, while also being capable of finding and fixing vulnerabilities defensively. Committee Chairman Andrew Garbarino later warned that the United States cannot continue defending at human speed while adversaries attack at computer speed.

That warning should shape American policy. Federal agencies responsible for civilian cybersecurity need secure access to leading American AI systems so they can continuously search for weaknesses in critical infrastructure. Waiting for an attack, investigating the damage, and issuing patches afterward will not be sufficient when hostile AI agents can scan thousands of targets simultaneously.

Ports, rail companies, airports, utilities, manufacturers, cloud providers, and telecommunications firms should conduct regular exercises based on a coordinated Chinese campaign rather than isolated ransomware incidents. They must determine what would happen if several sectors failed at once, communications became unreliable, and attackers combined real disruptions with fabricated reports intended to create panic.

The United States must also improve coordination between government and private infrastructure operators. In the war game, lawmakers had to decide which networks to defend first and how closely to cooperate with companies controlling essential systems. That reflects a real weakness: Washington may understand the strategic threat, but private firms own and operate much of the infrastructure that would be attacked.

Private companies cannot be expected to fight a foreign intelligence service alone. A railroad operator, port authority, regional utility, or logistics company may have strong commercial cybersecurity but still lack access to classified warnings, nation-state indicators, or intelligence about a developing Taiwan crisis.

The federal government should provide faster threat intelligence, secure reporting channels, AI-assisted defensive tools, emergency communication systems, and clear rules for coordinated action during a national-security emergency. Exercises should include state and local authorities because disruption of transportation and utilities will first be experienced in American communities, not inside federal briefing rooms.

The United States must also protect the data used to train and operate defensive AI. The congressional scenario examined how models trained on vulnerable data sets could weaken America’s defensive posture. If training data are poisoned, manipulated, incomplete, or exposed to foreign access, the resulting system may make unreliable recommendations precisely when officials need it most.

China could exploit that weakness by corrupting data, planting misleading information, or designing inputs intended to manipulate automated decision systems. An AI model assisting with logistics might be induced to prioritize the wrong routes. A cybersecurity model could be tricked into overlooking malicious activity. A public-information system could spread false instructions during an emergency.

America therefore needs more than powerful models. It needs trusted models, protected data, secure computing infrastructure, independent testing, human oversight, and the ability to continue operating when systems are under attack.

The scenario also demonstrates why Taiwan’s security is directly connected to homeland security. Americans sometimes view a Taiwan conflict as a distant military contest in Asia. The war game shows that Beijing could bring the conflict into the United States through digital attacks on the systems Americans use every day.

A Chinese operation targeting ports and freight rail would affect commercial shipments as well as military logistics. Attacks on airports could disrupt civilian travel. Utility failures could affect hospitals, homes, and businesses. Disinformation could deepen political division at the same time physical disruptions create fear and anger.

Beijing’s objective would not necessarily be to destroy every system. It could seek to generate enough delay, confusion, and domestic pressure to make American leaders hesitate. If the United States cannot move forces reliably or the public believes intervention will trigger widespread disruption at home, China may calculate that it has greater freedom to act against Taiwan.

That is why cyber resilience is part of deterrence. China is less likely to launch such a campaign if Beijing believes the United States can identify intrusions, isolate compromised systems, maintain transportation and power, rapidly restore operations, and continue supporting its allies.

America must also maintain a decisive lead in advanced AI without recklessly deploying insecure systems. Leadership means developing powerful models, preventing their theft, restricting access by foreign adversaries, protecting the chips and computing infrastructure required to run them, and ensuring American defenders can use them before Chinese attackers do.

The committees’ war game was valuable because it forced lawmakers to confront cyberattacks as part of physical warfare rather than as a separate technical issue. A future war may involve missiles and ships, but it may also be decided by software controlling cargo routes, electrical systems, port schedules, network access, and public information.

China does not need to invade the American mainland to threaten the American homeland. It needs access to the digital systems connecting American industry, infrastructure, and military power.

The United States should treat the exercise as a warning delivered before the crisis, not as an interesting scenario to be filed away afterward. Washington, state governments, infrastructure operators, and technology companies must prepare for a Chinese AI-assisted campaign capable of striking several sectors simultaneously.

The race is no longer simply about who builds the most advanced artificial intelligence. It is about whether America can protect the physical systems on which its citizens, economy, military, and alliances depend before the Chinese Communist Party turns AI into a weapon against them.


Return to blog