Extended Discourse on MAIM: Early Sabotage Under Uncertainty
Should China MAIM early in a world of strategic ambiguity?
This post intends to explore the following idea: “If China has high uncertainty regarding where the U.S. stands on superintelligence development timelines, then ‘precautionary’ MAIMing might be justified” (h/t David Krueger).
For purposes of this post, we’re going to evaluate the premise independent of MAIM’s structure, since Superintelligence Strategy largely doesn’t consider a world where mutual visibility is low. So, taken at face value, the question I’ll be considering today is something like: in a world where the U.S. has achieved strategic ambiguity, should China– or any other country– sabotage under uncertainty?
I believe precautionary MAIMing is rational only if both of the following hold:
The strike must be effective, and
The MAIMing country must believe one of the following:
The strike will not trigger escalatory retaliation;
Any escalatory retaliation will be minimal;
The risk of heavy retaliation is still outweighed by the benefits of the strike.
*A critical factor in 2a is attribution. If China believes it can execute a MAIM strike with sufficient ambiguity– either avoiding detection entirely or creating enough uncertainty that the U.S. cannot justify retaliation– the likelihood of attack increases substantially. This connects to broader questions about proxy-mediated operations and other mechanisms for obscuring responsibility; I’ll explore these and other factors affecting MAIM attack probability in an upcoming post.
In the remainder of this post, I’ll focus on evaluating condition #1: strike effectiveness.
1A. FOR: Striking early is more likely to succeed
If the U.S. is actively working on hardening, then China may want to MAIM early before those defenses are complete, since the longer they wait, the harder it will be to pull off a MAIM attack successfully.
1B. AGAINST: An early strike speeds up hardening
MAIMing early will likely accelerate the process of hardening. Early strikes face a triple cost: (1) they reveal capabilities that could be patched, (2) they provide political justification for hardening budgets that might otherwise be constrained, and (3) they give the U.S. a blueprint of vulnerabilities to address. The strike may buy time, but at the cost of making all subsequent strikes harder.
1C. AGAINST: Later strikes are likely to be more effective (note: high uncertainty)
Later strikes potentially destroy more value and cause longer delays, though the magnitude of this effect is uncertain. In theory, target value scales with investment: a MAIMing strike on a nascent project destroys less accumulated capital, research, and infrastructure than one targeting a massive training run. If you corrupt weights after $10B of compute, that’s more damaging than corrupting them after $100M.
But practically, we don’t know: (1) whether strategic AI projects maintain sufficient checkpointing and redundancy to recover quickly from physical destruction, (2) whether cyber sabotage can be both severe enough to require re-training yet subtle enough to evade detection (though this is also conditional on risk tolerance, a factor I’ll be examining further in later analysis), (3) to what extent frontier labs hedge with parallel development approaches, and (4) how algorithmic progress during recovery periods affects net delay. The strongest version focuses on wasted sunk costs in accumulated assets and investment fallout from high-profile failures, but even this depends on project structure: losing one path matters far more if you’re pursuing a single massive training run than if you’re running multiple experiments concurrently.
Therefore, the strength of this argument depends less on absolute investment levels than on project topology; monolithic training runs are far more vulnerable to late-stage disruption than diversified, parallelized development strategies.
2A. FOR: Strikes can be conducted in subtle, non-detectable ways
This is a common counterargument I’ve heard against 1B— that MAIMing early speeds up hardening.
Covert maiming operations can be sustained over extended periods without triggering escalation, making timing less critical than for overt strikes. Unlike kinetic attacks, cyber sabotage can be calibrated for deniability: intelligence agencies can poison datasets, compromise supply chains, or recruit insiders in ways that look like ordinary research failures. Training run failures are expected; labs regularly abandon approaches that don’t work. This means China could MAIM continuously at low intensity, gradually degrading U.S. progress while maintaining strategic ambiguity.
2B. AGAINST: Sustained covert access is operationally fragile
Maintaining persistent access to adversary AI infrastructure over years requires an implausibly long chain of unbroken successes. The operational security challenge compounds over time: the longer operations continue, the more opportunities for detection, the more personnel involved, and the greater the risk of defection or capture. Even sophisticated intelligence agencies struggle to maintain persistent access to hardened targets for years. The assumption of “continuous low-level degradation” requires sustained personnel security, network defense, and superior counterintelligence, a remarkably optimistic assumption when targeting a strategic program that will likely receive intense defensive resources.
2C. AGAINST: Covert operations face detection-effectiveness tradeoffs
Sabotage subtle enough to evade detection for years is unlikely to cause catastrophic damage; projects will simply iterate around problems, attribute failures to normal research challenges, and eventually find success through alternative approaches. Activities that are simultaneously severe enough to meaningfully delay superintelligence development and subtle enough to avoid detection will likely be extremely difficult to pull off.
Conclusion
Whether early MAIMing is advantageous appears to depend critically on operational capabilities; if a country can execute sustained, covert degradation over extended periods while maintaining deniability, then early action is preferable. Establishing persistent access before hardening measures are implemented enables years of continuous sabotage that compounds over time.
However, if sustained covert operations are infeasible and strikes must be discrete events, the calculus becomes far less clear. Early strikes risk accelerating hardening while revealing capabilities, potentially making all subsequent attacks impossible. Later strikes might destroy more accumulated value (though this depends on uncertain assumptions about checkpoint resilience, parallel development strategies, and recovery dynamics).
Critically, these uncertainties are not static: for example, observed U.S. project structure should update MAIM incentives. If China sees frontier labs shifting toward parallelism, ensemble methods, or rapid iteration cycles, the value of late MAIM collapses even if sunk costs rise.
Any decision to MAIM also hinges on the second condition: retaliation dynamics. In Part 3, I’ll examine how attribution ambiguity, proxy operations, and escalation risks shape retaliation calculations.

