A 2.6 trillion yuan target. A 70% penetration rate for 'new generation intelligent terminals and agents.' Government subsidies and 100 demonstration scenarios. Chengdu’s AI+ action plan reads like the whitepaper of a high-TVL DeFi protocol. But after two decades dissecting smart contracts—from Zeppelin’s SafeMath to Terra’s seigniorage model—I have learned one rule: if it isn’t formally verified, it’s just hope. This plan, for all its ambition, has no runtime environment, no audit trail, and no pre-mortem risk assessment. It is a contract with undefined state variables and a flawed economic model waiting to be exploited.
Context: The Protocol
The plan, published by the Chengdu municipal government, sets a 2027 target of 70% penetration for ‘new generation intelligent terminals and agents’ across ‘thousands of industries,’ aiming for a 2.6 trillion yuan AI core industrial scale by 2030. It structures this through a ‘Double Hundred’ initiative—100 innovative products and 100 demonstration scenarios—with 20 annual flagship scenarios funded by government procurement. The policy explicitly avoids detailed technical mandates, leaving the implementation to market forces. As a government strategy, it prioritizes scale and scenario coverage over technological originality. However, from a systems engineering perspective, this is equivalent to launching a DeFi protocol without specifying the tokenomics, the oracle model, or the liquidation logic.
Core: Technical and Economic Stress Tests
Technology Roadmap: Undefined State Variables
The plan uses ‘new generation’ without defining the technical stack. Is it edge-side LLMs, embodied intelligence, or agent frameworks? This ambiguity is dangerous. In 2017, I audited the Zeppelin library and found 14 integer overflow vulnerabilities because the SafeMath contract allowed unchecked arithmetic—the documentation didn’t specify the overflow behavior. Chengdu’s plan similarly leaves the core technology undefined. Based on local infrastructure (Intel, Foxconn), it likely defaults to edge-AI and AIoT. But edge-AI requires on-device inference chips (Qualcomm, MediaTek) and optimized frameworks (TensorFlow Lite, ONNX). Without specifying the training paradigm or model architecture, the 70% penetration target becomes a floating-point number with no fixed decimal—impossible to verify. If the standard is obsolete before the mint finishes, the entire project is a memory leak waiting to happen.
Commercialization Model: Liquidity Mining Without a Yield Curve
The plan’s commercialization relies entirely on government subsidies and procurement—a classic ‘subsidy-driven’ model. In DeFi, we see liquidity mining programs inflate TVL until the token rewards stop, then the capital drains. The plan does not mention any exit strategy or a path to sustainable B2B/B2C revenue. The 2.6 trillion target implies a 30% CAGR, but national AI industry growth is ~15%. This discrepancy is like a DeFi protocol promising 30% APY on a stablecoin with no yield-bearing assets backing it. In 2020, I simulated Compound’s interest rate model under extreme volatility and identified a convergence flaw that could cause systemic insolvency. Chengdu’s plan has no such stress test. The ‘100 demonstration scenarios’ are akin to whitelisted pools—they create immediate demand but distort the market signal. When the subsidy stops, will enterprises pay? The plan provides no data on willingness-to-pay or unit economics. This is a token sale without a vesting schedule.
Security Void: No Compliance Layer for High-Risk Execution
The plan contains zero mentions of AI safety, ethical review, algorithm filing, or data privacy. In the current regulatory landscape (EU AI Act, China’s Generative AI measures), this is equivalent to launching a smart contract without a proxy upgrade mechanism or emergency pause. The plan proposes deploying AI in healthcare, finance, and government—high-risk domains where algorithmic bias and accountability must be defined. During my 2024 institutional custody architecture design for a tier-1 bank, we dedicated 200 pages to security specifications, including BLS threshold signatures and HSM integration. Chengdu’s plan offers no equivalent. The absence of a security framework means that when an AI system causes harm (e.g., a misdiagnosis or an accident), there is no clear liability—the government, the developer, or the user? This is the ‘code is law, but law is interpretive’ problem amplified. Without a formal verification of the governance contract, the entire ecosystem is a series of unchecked external calls.

Infrastructure Bottleneck: Gas Costs Exceeding the Budget
The plan relies on two computing centers: the National Supercomputing Center (100 PFLOPS) and the Tianfu Intelligent Computing Center (targeting 1000 PFLOPS by 2025). However, 70% penetration of AI terminals demands massive inference and training compute. In 2023, I analyzed ZK rollup proving costs and found that unless gas prices return to bull-market highs, operators bleed money. Similarly, AI inference at scale requires cheap, continuous compute. Chengdu’s advantage is hydroelectric power, but carbon caps may limit expansion. More critically, the plan does not mention compute coupon subsidies or whether enterprises will be forced to use local compute (vendor lock-in). If the cost per FLOP is higher than alternatives (e.g., AWS China), firms will outsource, and the target collapses. The compute layer is the base fee—if it’s too high, no one can execute the transaction.
Contrarian: The Omission as a Strategy
Critics will say the lack of technical detail is intentional—it allows flexibility. I argue the opposite: the omission is a security blind spot crafted to maintain administrative optionality. Governments rarely commit to specific stacks because they want to avoid accountability for failures. But in reality, this creates a governance vacuum. When the first major AI accident occurs in Chengdu (e.g., an autonomous vehicle hit during a pilot), the plan provides no recourse. The liability will be retroactively assigned through litigation—the most expensive and inefficient method. In 2022, I published a pre-mortem of Terra’s algorithm, predicting the de-pegging due to a structural flaw in the mint-and-burn loop. Local bureaucrats are now creating a similar positive feedback loop: subsidies attract enterprises, enterprises claim AI output, government celebrates growth, but no one verifies the actual productivity gain. When the subsidies stop, the loop unwinds. This is a classic governance token without a timelock.
Takeaway: The Vulnerability Forecast
Chengdu’s AI+ plan is an ambitious proof-of-stake consensus—every participant (enterprises, government, universities) can validate blocks, but no one checks the underlying data availability. The 2.6 trillion yuan is a synthetic asset with no underlying collateral. Until the government publishes a formally verified implementation plan—including auditable milestones, a defined technology stack, a security compliance framework, and an exit mechanism for failed projects—this remains a whitepaper with no code. The standard is obsolete before the mint finishes. Trust the hash, not the hype. I have seen this pattern before in ICOs, in DeFi, in NFTs. The lesson is always the same: if you cannot write a test that passes, you cannot deploy to mainnet. Chengdu has not even written the test.