X Close

Did Prevent’s focus on ‘vulnerability’ let Rudakubana slip through the net?

Expanding Prevent's remit will only lead to more failures. Credit: Getty

Expanding Prevent's remit will only lead to more failures. Credit: Getty

February 7 2025 - 1:00pm

When, at the end of last month, Keir Starmer announced a public inquiry into the Southport massacre, he vehemently condemned Axel Rudakubana, who he couldn’t bring himself to name, and promised that he would “not let any institution of the state deflect from their failure”.

He was specifically referring to Prevent, the UK’s counter-radicalization scheme, to which the killer had been referred three times. “Yet on each of these occasions,” he said, “a judgment was made that he did not meet the threshold for intervention. A judgment that was clearly wrong. And which failed those families.”

On Wednesday, the Government published an independent “learning review” into Rudakubana’s contact with Prevent over a 17-month period between 2019 and 2021. The review is long, poorly-written and full of jargon such as “extreme vulnerability” (read: susceptibility to extremism). But the overall narrative endorses Starmer’s conviction that Prevent failed badly.

The review shines a vivid light on Rudakubana’s case management and gives a detailed picture of why he was referred. It also tells us quite a bit about his thoughts, his interests, and his “issues”. Notes highlight his disruptive behavior in class, including asking an art teacher if “we have a picture of a severed head”. One note in particular stands out: “AMR [Rudakubana] has been researching school shootings, has been talking about stabbing people and that the terrorist attack on the MEN [the 2017 Manchester bombing] was a good thing.”

What the review also makes vividly clear is that he was at no point radicalized, and that he had no ideology other than a sadistic interest in violence — and this was despite the best efforts of Prevent police officers to find one. According to one note from 2020: “AMR did not display any extremist views or ideology.” Many other notes similarly record the absence of ideology throughout his contact with Prevent.

What the Southport killer did have, however, was an abundance of grievances, but these were personal, not political, and were aimed at various schoolmates and teachers. Indeed, he saw himself not as an aggressor but as a victim. “He felt he was being persecuted by his teachers who were trying to get him into trouble,” says one note. Despite the overwhelming evidence that Rudakubana was not radicalized, the review concludes that Prevent still nevertheless failed in managing his risk and that he should have been prioritized for Channel, a voluntary program intended to foster ideological change in the thinking of extremists.

The entire argument that sustains this conclusion rests on the concept of vulnerability — that because Rudakubana had autism and had been bullied he was somehow highly susceptible to being “drawn into terrorism”. According to this argument, it doesn’t matter that he had no ideology; what mattered instead was that, because of his “extreme vulnerability”, as the review puts it, he theoretically could have been radicalized and could have gone on to commit an act of terrorism. “Static vulnerabilities can make an individual highly susceptible [to violent extremism],” the review observes, suggesting that the Prevent officers were so preoccupied with finding ideology that they missed his “vulnerability”.

But here’s the problem: there just isn’t any solid evidence to show that “vulnerability” is a driver, much less a predictor, of violent extremism. This is further compounded by the vagueness with which the Prevent scheme identifies vulnerabilities, which range from “a need to dominate and control others” to “being at a transitional time of life”. Nor is there a shred of evidence to support the review’s assumption that a Channel intervention would have diverted Rudakubana from his path toward terrible violence.

The other problem with the review is that it gives support to the idea, currently afoot within the Government, of widening the remit of Prevent to include behaviors that are outwardly disturbing — watching gore, say, or idolizing Andrew Tate — but which have little relation to violent extremism or terrorism.

This idea is bad not just because it risks stigmatizing a lot of troubled people who are not extremists, but also because adding countless misfits and malcontents to Prevent’s already overburdened caseloads is likely to create further confusion and drift in a scheme that is already in disarray.


Simon Cottee is a Senior Visiting Fellow at the Danube Institute


China is threatening America in the AI race

Reports sugget Zhipu AI  has released a new model that can rival leading US systems. Credit: Getty

Reports sugget Zhipu AI has released a new model that can rival leading US systems. Credit: Getty

July 1 2026 - 10:18am

China is trying to catch up with America on artificial intelligence. The Wall Street Journal has reported that Zhipu AI — one of China’s six “AI tiger” LLMs — has released a new model that can rival leading US systems, including Anthropic’s Mythos, in cybersecurity tasks such as pinpointing security bugs. While this marks a milestone in China’s drive to catch up with Western AI capabilities, strong performance on a single benchmark does not mean it has taken the lead. Chinese models still lag behind their Western counterparts in broader capabilities, such as autonomous operation. Skepticism is therefore warranted before resorting to hysterical conclusions, but complacency about the geopolitical implications of China’s AI advances would be an even greater mistake.

On the infrastructure side, Chinese AI is still constrained by access to advanced chips, with American labs way ahead in computing capacity as well as investment. Analysis from earlier this year suggests that Chinese models are likely to be at least a few months behind those in the US. But they are still continuing to make progress, or that the geopolitical importance of AI will be decided only by whose LLM has ventured deeper into the technological frontier. The practical applications of AI, countries’ to capture foreign markets, and the application of AI into the real economy will matter just as much.

Here, China may hold an advantage. As with its dominance across many critical supply chains, Beijing may not need to produce the most advanced AI systems — only those that are affordable and widely deployable. In doing so, it could consolidate global influence by supplying functional, low-cost AI at scale.

Beijing seems to be pursuing exactly that path, developing an AI “open-source” strategy that offers affordable, widely available AI models for companies and individuals to use and modify as they wish. The production of the DeepSeek AI model, which matched the performance of Silicon Valley tools such as ChatGPT at a fraction of the cost for users, created goodwill among Chinese models with developers.

The four most popular models on OpenRouter, an AI hardware platform for developers, are now all Chinese. The goal for China is not only to win the frontier-model race, but to make its systems the default layer of AI adoption across industries and global markets. For most economies, the choice is increasingly between an affordable tool they can deploy now and a more robust one that may be out of reach.

And while the countries adopting Chinese models may be exposed to political pressure and cyber threats from Beijing, safer and more capable alternatives matter little if they are unaffordable. American AI companies are already under pressure to monetize products whose operating costs are rising. If Chinese open-source models become the cheap default for startups, universities, governments and businesses across the developing world, then America’s AI lead will be eroded from below.

Perhaps more concerning for America in the long run is how AI can give Chinese manufacturing even more strength, through the ongoing integration of AI as a general-purpose technology. China’s new Five-Year Plan mentioned AI more than 50 times and includes an “AI+” action plan aimed at spreading AI across the economy.

Beijing has been pioneering automation of its critical infrastructure for years, with promising recent results in increasing warplane production capacity. In that regard, China’s open-model strategy and manufacturing dominance will reinforce each other. Cheap, adaptable models accelerate deployment across the real economy while those deployments generate real-world data and use cases that can feed back into further model improvement.

The United States should not dismiss the importance of its lead in the AI race. That lead worries Beijing, not least because a more automated Chinese economy would also become more vulnerable to AI-generated cyber threats. But nor should Washington assume that China cannot catch up with American capabilities over time.

This AI competition represents part of a broader struggle over tech supply chains and geopolitical influence. Decisions over whether to adopt US or Chinese models could produce a more fragmented global reality, with different regions relying on different cloud providers, chips and security structures. The result will likely be a global economy which is divided into competing spheres, rather than one which produces a single winner.


Miquel Vila is a political and geopolitical risk consultant focusing on industrial strategy, critical infrastructure and global supply chains.

miquelvilam