Chengdu's AI+ Plan: A Blockchain Security Autopsy of Missing Layers

Events | CryptoPanda |

July 12, 2026 — The Chengdu municipal government released a document titled AI+ Action Plan (2025–2030), setting targets of CNY 260 billion in AI industry scale and over 70% adoption of “next-generation intelligent terminals” by 2027. An auditor’s first instinct: these numbers are pretty. But the deeper pathology—the absence of security, ethics, and compliance frameworks—resembles every DeFi project that promised 100x TVL before the rug was pulled. The ledger bleeds where logic fails to bind.

Context: I’m Olivia Harris, 29, crypto security audit partner based in Shenzhen. My early career included dissecting the 0x Protocol v2 reentrancy bugs in 2018 and later reverse-engineering the MakerDAO price feed during DeFi Summer. These experiences taught me that policy documents, like smart contracts, need to be audited line by line. The Chengdu AI plan is no exception. It claims to catapult the city into an AI application hub, but the text is riddled with the same symptoms I’ve seen in unaudited protocols: missing safety rails, undefined metrics, and a blind trust that market forces will self-correct.

Core: Systematic Teardown of Seven Dimensions

1. Technical Route: No Base Layer Specified The policy references “next-generation intelligent terminals and agents” but never defines the underlying stack—no mention of training frameworks, model architectures, or consensus mechanisms. As a blockchain auditor, I see parallels to projects that pitch “next-gen DeFi” without revealing whether they’re using an audited Solidity version or a fork of a fork. The omission is dangerous. Without a technical standard, compliance cannot be audited. Last year, I analyzed a Layer-2 sequencer that claimed “decentralized sequencing” without publishing its node architecture. It turned out to be a single AWS instance. Chengdu’s plan risks a similar centralization trap. Code does not lie; it merely waits.

2. Commercialization: Subsidy-Driven, Not Market-Verified The plan offers 20 “benchmark scenarios” per year and “dual 100” projects (100 innovation products, 100 demonstration scenes). This is basically liquidity mining without an expiry date. Governments hand out grants, companies build for the grant, and when the tap stops, the TVL vanishes. I witnessed this pattern in the 2021 NFT minting bot exploit: projects raised money on hype, deployed lazy contracts, and when the market turned, the bots ate the retail exit liquidity. Chengdu’s model creates a moral hazard: companies optimize for subsidy capture, not sustainable unit economics. The real question: what is the ratio of subsidy to self-sustaining revenue? The document omits this metric entirely.

3. Industry Impact: Beneficiaries Are Hardware/Finance, Not AI Core The plan claims to “empower a hundred industries,” but the primary beneficiaries are existing sectors: electronics manufacturing, automotive, financial services, cultural tourism. From a blockchain perspective, this is like a Layer-1 chain that only supports ERC-20 transfers but calls itself a “global settlement layer.” The real AI innovation—foundation model training, agent frameworks, edge inference chips—receives zero specificity. The hidden assumption is that Chengdu can ride the coattails of national champions (Huawei, Alibaba) rather than build indigenous capabilities. In 2022, during Terra-Luna collapse, I noted that algorithmic stablecoins failed because they relied on external collateral that was itself fragile. Similarly, Chengdu’s plan depends on external AI stacks, making it vulnerable to sanctions, export controls, or vendor lock-in.

4. Competitive Landscape: Positioning vs. Reality Chengdu aims to be “China’s No.1 AI application city,” differentiating from Beijing (research), Shenzhen (hardware), and Hangzhou (cloud). This echoes the blockchain city race: Beijing has the academic output, Shenzhen has the miners, Hangzhou has the DApp ecosystem. Chengdu’s advantage—cheaper labor, strong software parks—is real but eroding. Xi’an is building a western computing hub; Chongqing is accelerating smart EVs. The policy window is roughly two years. Without headquarter moves by major AI labs (Baidu, ByteDance), the talent pool will thin. As a security professional, I watch for talent outflow indicators: when the best engineers leave for Shanghai or Bay Area, it’s time to short the local token.

5. Ethics & Safety: The Missing Audit Trail This is the biggest red flag. The document contains zero references to AI safety, algorithm registration, data privacy, or ethical review. In China, the Interim Measures for Generative AI Service Management took effect in August 2023, requiring content safety review and filing. Chengdu’s plan ignores this entirely. For a blockchain auditor, this is like a DeFi protocol launching without a code audit. Every timestamp is a potential crime scene. The “70% penetration” of smart terminals implies billions of IoT devices with AI spying on personal data. Without safety standards, these terminals become botnet fodder. In my analysis of the 2020 MakerDAO crisis, I traced the failure to a single oracle latency issue that cascaded into systemic liquidations. Chengdu’s plan repeats the same mistake: assuming terminal adoption won’t create attack surfaces.

6. Investment & Valuation: Short-Term Catalysts, Long-Term Distortion CNY 260 billion industry scale implies >30% CAGR, outpacing the national average (~15%). This will spark a local stock rally (Chengdu-listed AI-related stocks like Jiafa Education, Creative Information). But history shows local government plans hit less than 60% of their targets. The market may price in perfection, leaving a gap when reality bites. In the NFT space, I saw PFP projects promise “metaverse interoperability” that never materialized; investors who bought the narrative lost heavily during the bear. The same applies here: differentiate between “AI core revenue” and “traditional product + AI sticker.” The plan does not define measurement methodology, making the target a marketing number, not an accountability tool. Trust is a variable, never a constant.

7. Infrastructure: Compute as the Hard Ceiling Chengdu boasts the National Supercomputing Center (100 PFLOPS) and Tianfu Smart Computing Center (planned 1000 PFLOPS by 2027). This is decent, but insufficient for 2600 billion scale. Training a single frontier model (like GPT-4 class) consumes ~10^25 FLOPs, equivalent to 10 million A100 GPU-hours. Even if all local compute were pooled, it wouldn’t serve a handful of serious AI labs. The document is silent on cross-province compute arbitrage or partnerships with eastern cloud providers. In the blockchain world, compute is the bottleneck for ZK proofs and full nodes. If Chengdu cannot guarantee green energy and low latency, AI companies will flee to cheaper regions. The risk is a hollow cluster with shiny buildings but no active GPUs.

Contrarian Angle: What the Bulls Got Right Despite the flaws, the plan has three strengths often ignored by cynics. First, the focus on “application” is actually rational for a secondary city. Trying to replicate Beijing’s foundation model R&D would waste resources. Second, Chengdu’s existing industrial base—electronics, automotive, fintech—provides genuine demand signals, unlike pure hype loops. Third, the plan’s explicit target penetration rates (70% by 2027, 90% by 2030) are bold enough to force execution. In my experience auditing DeFi protocols, aggressive but measurable goals (e.g., “reduce oracle latency to 1 block” rather than “improve stability”) lead to better outcomes. So maybe the bulls are right that Chengdu will become a testing ground for vertical AI integration—if they can solve the safety gap. This is the “unused table stakes” that could flip a bearish take to neutral.

Takeaway: Accountability or Another Collateralized Debt Obligation? Chengdu’s AI+ Action Plan is not a fraud, but it is a gamble. It assumes that market incentives and government push can substitute for engineering rigor, security audits, and ethical guardrails. As someone who has seen $40,000 vanish in a race condition and a $60 billion stablecoin collapse in 72 hours, I know that ignoring safety is not a bug—it’s a feature of rushed deployments. The question for investors, developers, and regulators: will this plan build genuine value or become the next souped-up DeFi project that impress on paper but leaks wealth in practice? Silence in the logs screams louder than alerts. The first major exploit of a Chengdu AI terminal will be the real audit. Until then, treat the 2600 billion as a mark-to-myth figure.