{"id":127960,"date":"2026-08-03T12:53:23","date_gmt":"2026-08-03T12:53:23","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/127960\/"},"modified":"2026-08-03T12:53:23","modified_gmt":"2026-08-03T12:53:23","slug":"regulate-dont-ban-chinese-ai-models","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/127960\/","title":{"rendered":"Regulate, Don&#8217;t Ban, Chinese AI Models"},"content":{"rendered":"<p>Washington, D.C. policy circles are buzzing with talk of whether and how to restrict access to Chinese AI models. But the right answer is to regulate all AI models for safety through pre-deployment and ongoing testing for risks associated with cybersecurity, bioweapons, and loss of human control. Market access for all AI models, including Chinese open-weight models, could be conditioned on passing these assessments.<\/p>\n<p>This debate was sent into overdrive by the 2.8 trillion parameter AI model <a href=\"https:\/\/www.reuters.com\/world\/china\/chinas-moonshot-unveils-worlds-largest-open-ai-model-closing-us-rivals-2026-07-17\/\" rel=\"nofollow noopener\" target=\"_blank\">Kimi K3<\/a> released on July 16 by the Chinese startup Moonshot AI. It scored near the top of industry benchmarks, but its price was dramatically lower than the prices for comparable U.S.-developed AI models. Moreover, on July 27, Moonshot <a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2026-07-27\/china-s-moonshot-to-release-breakthrough-ai-model-for-download\" rel=\"nofollow noopener\" target=\"_blank\">publicly released<\/a> the numerical weights to Kimi K3, allowing users to download the model for free, modify it and run it on their own infrastructure, or on compute leased from cloud providers.\u00a0<\/p>\n<p>U.S. government officials instantaneously <a href=\"https:\/\/www.reuters.com\/world\/us\/us-accuses-chinas-moonshot-stealing-anthropics-fable-latest-ai-model-2026-06-30\/\" rel=\"nofollow noopener\" target=\"_blank\">accused<\/a> Moonshot of intellectual property theft. They alleged Moonshot illegally used output from Anthropic\u2019s Fable 5 to train its model, using a process called distillation, whereby the output from a larger AI model is used to train a smaller AI model. \u201cOpen source is not open season on American IP,\u201d <a href=\"https:\/\/x.com\/SecScottBessent\/status\/2080008411790368895\" rel=\"nofollow\">said<\/a> Treasury Secretary Scott Bessant.\u00a0<\/p>\n<p>Moonshot has <a href=\"https:\/\/asiatimes.com\/2026\/07\/us-may-sanction-chinas-moonshot-for-distilling-anthropics-fable\/\" rel=\"nofollow noopener\" target=\"_blank\">denied<\/a> distilling Kimi K3 from other AI models and says its capabilities derive from its original innovations. The administration\u2019s allegation turns out to be technically weak. As AI researcher Nathan Lambert <a href=\"https:\/\/natolambert.substack.com\/p\/how-distillation-is-used-today-and\" rel=\"nofollow noopener\" target=\"_blank\">put it<\/a>, \u201cthe timeline is such that Fable 5 likely had no impact as a distillation teacher.\u201d<\/p>\n<p>Nevertheless, U.S. officials floated measures to restrict access to Chinese models including the <a href=\"https:\/\/www.bis.gov\/media\/documents\/entity-list-faqs-11.10.25-readded\" rel=\"nofollow noopener\" target=\"_blank\">puzzling idea<\/a> of imposing export controls on imports, that is, on what U.S. companies can buy or use from foreign companies. Other <a href=\"https:\/\/www.lawfaremedia.org\/article\/knives-are-out-for-open-weight-ai-models#postContributors\" rel=\"nofollow noopener\" target=\"_blank\">proposed restrictive measures<\/a> included a national emergency declaration under the International Emergency Economic Powers Act (IEEPA) that would restrict commercial transactions involving Chinese AI models, a ban on using Chinese models in government systems, warning letters from U.S. intelligence agencies and financial regulators, disclosure requirements and informal pressure, including appearances before hostile congressional committees.\u00a0<\/p>\n<p>Who\u2019s Afraid of Chinese Models?<\/p>\n<p>Open source AI models from China are <a href=\"https:\/\/www.cnbc.com\/2026\/07\/07\/chinese-ai-models-costs-us-openai-anthropic.html\" rel=\"nofollow noopener\" target=\"_blank\">widely used<\/a> by U.S. companies. In reaction to the administration\u2019s push for banning Chinese models, 179 AI companies (later joined by OpenAI, Google, SpaceX, and Amazon) sent a <a href=\"https:\/\/static.politico.com\/4a\/bf\/9c4021d8404386b0a311dcccf0e5\/lta-open-weight-ai-letter-7-22-26.pdf\" rel=\"nofollow noopener\" target=\"_blank\">letter<\/a> urging administration officials not to restrict Chinese open-weight models, focusing less on Chinese origin and more on the need to preserve a space for open-weight models.\u00a0<\/p>\n<p>But of course the administration\u2019s concern was not with open models as such, which it favors so long as they are provided by U.S. companies, but with AI models from companies domiciled in China.<\/p>\n<p>Anthropic, which did not sign the industry\u2019s letter, seems to want to target Chinese models while sparing open models generally. In a <a href=\"https:\/\/www.anthropic.com\/news\/position-open-weights-models\" rel=\"nofollow noopener\" target=\"_blank\">blog post<\/a>, the company says that it opposes a \u201cblanket ban on open-weights models\u201d but favors policies to prevent distillation of U.S. models by companies domiciled in \u201can authoritarian state seeking to overtake the US at the frontier.\u201d Under this policy, U.S. authorities would approve open-weight models from Mistral, Nvidia, Thinking Machines, the Allen Institute for AI, Google, and Reflection AI, but rely on unproven allegations of improper distillation by Chinese companies to ban their models. This might be where U.S. policymakers are headed.<\/p>\n<p>Relying on national security authorities to vindicate a U.S. company\u2019s intellectual property rights is a clear abuse of these laws. If a company has a complaint regarding intellectual property theft, the proper course of action is to bring a case before the International Trade Commission, a U.S. agency set up to investigate unfair import practices involving patent, trademark, copyright, or trade secret infringement. The ITC is <a href=\"https:\/\/www.usitc.gov\/about_section_337.htm\" rel=\"nofollow noopener\" target=\"_blank\">fully empowered<\/a> to issue an exclusion order to keep infringing items out of the U.S. market or a cease-and-desist order if they are already inside the country.\u00a0<\/p>\n<p>The Right Solution: Safety Testing Capable Models<\/p>\n<p>The rest of the AI industry opposes Anthropic\u2019s indirect way of eliminating its major existing open source competitors. Its <a href=\"https:\/\/static.politico.com\/4a\/bf\/9c4021d8404386b0a311dcccf0e5\/lta-open-weight-ai-letter-7-22-26.pdf\" rel=\"nofollow noopener\" target=\"_blank\">open letter<\/a> to U.S. authorities called for \u201ccontinued access for U.S. builders to open models already available worldwide, with proportionate safeguards\u2026\u201d\u00a0<\/p>\n<p>The key is the \u201cproportionate safeguards,\u201d and here Anthropic\u2019s blog points to the right solution: namely, \u201crequiring safety testing of all sufficiently capable models, open and closed.\u201d<\/p>\n<p>This question of safety testing to reduce risks from highly capable AI models has become urgent because of OpenAI\u2019s recent <a href=\"https:\/\/www.wsj.com\/tech\/ai\/how-the-futuristic-hack-by-rogue-openai-models-unfolded-1657bcea?mod=djemTECH\" rel=\"nofollow noopener\" target=\"_blank\">hack<\/a> of the website Hugging Face, which exposed flaws in the controls set up to contain a frontier model during testing.\u00a0<\/p>\n<p>As part of its defensive measures, Hugging Face <a href=\"https:\/\/www.wsj.com\/tech\/ai\/how-the-futuristic-hack-by-rogue-openai-models-unfolded-1657bcea?mod=djemTECH\" rel=\"nofollow noopener\" target=\"_blank\">tried to use<\/a> an undisclosed U.S. closed-weight model. But the security guardrails of that model interpreted its requests for incident response as a request to engage in hacking and refused to provide any analysis of the intrusion data Hugging Face supplied. The repository then successfully used the open-weight AI model GLM 5.2, from the Chinese startup z.AI, running on its own infrastructure, to analyze and respond to the intrusion. As Hugging Face indicated in its <a href=\"https:\/\/huggingface.co\/blog\/security-incident-july-2026\" rel=\"nofollow noopener\" target=\"_blank\">report<\/a> on this incident, the implications of this superiority of open-weight AI systems for defensive cybersecurity operations are still being assessed.\u00a0<\/p>\n<p>Subsequently, Anthropic <a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2026-07-30\/anthropic-s-ai-models-hacked-three-organizations-during-tests?cmpid=tech-in-depth&amp;utm_campaign=tech-in-depth&amp;utm_medium=email&amp;utm_source=newsletter&amp;utm_term=260731&amp;utm_content=7196\" rel=\"nofollow noopener\" target=\"_blank\">reported<\/a> that its models had also escaped onto the open internet and attacked the security systems of three unnamed organizations. In neither case was the AI company aware of the breach as it was happening, but discovered it only days or weeks after the fact.\u00a0<\/p>\n<p>How Testing Can Work in Practice<\/p>\n<p>To respond to such AI risks, industry and government seem to have reached a consensus in favor of a new program of pre-deployment and ongoing testing of frontier AI models, including Chinese AI models. Industry leader Demis Hassabis, CEO of DeepMind, <a href=\"https:\/\/demishassabis.substack.com\/p\/a-framework-for-frontier-ai-and-the-dawning-of-a-new-age\" rel=\"nofollow noopener\" target=\"_blank\">proposed<\/a> an industry self-regulatory agency modeled after the Financial Industry Regulatory Authority (FINRA), the industry group regulating broker-dealers under the supervision of the Securities and Exchange Commission. Legal scholar Mark Thomas added <a href=\"https:\/\/www.lawfaremedia.org\/article\/designing-a-finra-for-frontier-ai\" rel=\"nofollow noopener\" target=\"_blank\">some detail<\/a> on how such a \u201cFINRA for frontier AI\u201d might be put into practice. The proposed <a href=\"https:\/\/obernolte.house.gov\/media\/press-releases\/obernolte-trahan-release-discussion-draft-great-american-ai-act\" rel=\"nofollow noopener\" target=\"_blank\">Great American AI Act<\/a> puts the responsibility on the Center for AI Standards and Innovation (CAISI) to run a network of vetted auditors to do the testing. The Council of Foreign Relations published an <a href=\"https:\/\/www.cfr.org\/articles\/the-u-s-is-about-to-design-an-ai-regulator-heres-how-to-get-it-right\" rel=\"nofollow noopener\" target=\"_blank\">expert take<\/a> on the right design for an AI regulator tasked with reducing risks from frontier AI models.<\/p>\n<p>Whoever is empowered to perform this testing, what seems common to all these proposals is that AI model testing should include assessment for cybersecurity, biological weapons, and escape from human control. Passing such an assessment would not guarantee AI safety, but it would reduce AI risk to a manageable level. Chinese AI models, like their U.S. counterparts, would be permitted on the U.S. market after passing the assessments, but not otherwise, and could be withdrawn from the market if ongoing testing revealed a flaw that initial testing had not identified. NIST has already <a href=\"https:\/\/www.nist.gov\/news-events\/news\/2026\/07\/uk-aisi-caisi-preliminary-assessment-kimi-k3s-cyber-capabilities\" rel=\"nofollow noopener\" target=\"_blank\">performed<\/a> a preliminary analysis of Moonshot\u2019s Kimi K3, indicating that such reviews of Chinese open models are feasible.\u00a0<\/p>\n<p>Of course, China might not want to submit its models for testing by a U.S. agency as a condition of market access. But pre-deployment screening is precisely the condition China imposes on all AI models, including U.S. AI models. In order to provide an AI model to the public in China, a developer, foreign or domestic, must <a href=\"https:\/\/carnegieendowment.org\/research\/2023\/07\/chinas-ai-regulations-and-how-they-get-made\" rel=\"nofollow noopener\" target=\"_blank\">submit<\/a> it to the Cyberspace Administration of China and demonstrate that it passes China\u2019s strict information content controls. To protect U.S. companies from risks associated with AI models, including Chinese AI models, it is entirely sensible and defensible to require all of them to submit to appropriate, neutral technical assessments.\u00a0<\/p>\n<p>Moving Ahead: A Global Solution?<\/p>\n<p>In the end, it might be best if the agency testing AI models was not an agency of the U.S. government, but a neutral, technical international agency that could provide assessments that all governments would defer to. At the upcoming <a href=\"https:\/\/www.reuters.com\/world\/china\/us-china-hold-ai-talks-september-sources-say-2026-07-21\/\" rel=\"nofollow noopener\" target=\"_blank\">U.S.-China AI dialogue<\/a> in September, China could be invited to participate in the construction of such an agency and the development of testing standards that would apply to AI models from both countries. While China\u2019s AI safety efforts lag behind those of the United States, policymakers, academics, and industry leaders there are increasingly <a href=\"https:\/\/aisafetychina.com\/?utm_source=substack&amp;utm_medium=email#executive-summary\" rel=\"nofollow noopener\" target=\"_blank\">focusing<\/a> their efforts on the same AI risk reduction issues that keep U.S. experts up at night: cybersecurity, bioweapons, and loss of human control.\u00a0<\/p>\n<p>The temptation for many U.S. policymakers will be to say Chinese open-weight models are too risky, while U.S. open AI models are not. But that is just using safety concerns as a smokescreen for protectionism. U.S. companies and users deserve the best AI models that the U.S. and Chinese ecosystems can produce. Policy has to provide for minimum safety standards and pre-deployment and ongoing testing to reduce risks. The many unanswered questions of regulatory design and technical assessment criteria raised in AI risk reduction discussions have to be addressed. But any AI safety regime that works for domestic AI models should be good enough for foreign models, including those made by Chinese companies.\u00a0<\/p>\n<p>FEATURED IMAGE: The Moonshot AI Kimi app is seen on a mobile phone screen in Beijing on July 17, 2026. (Photo by GREG BAKER \/ AFP via Getty Images)<\/p>\n","protected":false},"excerpt":{"rendered":"Washington, D.C. policy circles are buzzing with talk of whether and how to restrict access to Chinese AI&hellip;\n","protected":false},"author":2,"featured_media":127961,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[64144,24,53,25,111,37379,64145,387,5969,313,9071,2000,64146,1896,335,1715],"class_list":["post-127960","post","type-post","status-publish","format-standard","has-post-thumbnail","category-ai","tag-administrative-law","tag-ai","tag-anthropic","tag-artificial-intelligence","tag-artificial-intelligence-ai","tag-artificial-intelligence-and-emerging-technologies-initiative","tag-bioweapon","tag-china","tag-cyber","tag-cybersecurity","tag-export-controls","tag-intellectual-property","tag-international-emergency-economic-powers-act-ieepa","tag-national-security","tag-open-source","tag-regulation"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/127960","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=127960"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/127960\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/127961"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=127960"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=127960"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=127960"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}