{"id":142360,"date":"2026-08-17T13:44:09","date_gmt":"2026-08-17T13:44:09","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/142360\/"},"modified":"2026-08-17T13:44:09","modified_gmt":"2026-08-17T13:44:09","slug":"test-standardize-restrict-a-u-s-policy-for-chinese-ai-models","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/142360\/","title":{"rendered":"Test, Standardize, Restrict: A U.S. Policy for Chinese AI Models"},"content":{"rendered":"<p>The release of the sprightly named Kimi K3 AI model from Chinese developer Moonshot has prompted a fresh round of debate over America\u2019s AI policy.\u00a0<a href=\"https:\/\/www.interconnects.ai\/p\/kimi-k3-the-open-weights-escalation\" rel=\"nofollow noopener\" target=\"_blank\">Kimi K3<\/a> leads a pack of Chinese AI models\u00a0with sophisticated coding capabilities, <a href=\"https:\/\/www.ntia.gov\/programs-and-initiatives\/artificial-intelligence\/open-model-weights-report\/glossary\" rel=\"nofollow noopener\" target=\"_blank\">open weights<\/a>\u2014published for anyone to download\u2014low costs, and a lack of\u00a0guardrails, a combination that has delighted technologists but alarmed national security officials. While\u00a0Washington <a href=\"https:\/\/www.axios.com\/2026\/07\/20\/ai-us-china-open-source-kimi\" rel=\"nofollow noopener\" target=\"_blank\">weighs restrictions<\/a> on Chinese models, Nvidia chief Jensen Huang dismissed concerns\u00a0<a href=\"https:\/\/www.axios.com\/2026\/07\/22\/nvidia-jensen-huang-china-open-source-ai\" rel=\"nofollow noopener\" target=\"_blank\">to Axios<\/a>,\u00a0declaring that \u201copen-source models that are excellent should be used.\u201d The July 27 <a href=\"https:\/\/www.microsoft.com\/en-us\/corporate-responsibility\/wp-content\/uploads\/2026\/07\/open-weight-models-letter-1.pdf\" rel=\"nofollow noopener\" target=\"_blank\">industry letter<\/a> on open-weight models manages not to mention China at all.<\/p>\n<p>Neither banning Chinese models nor ignoring their risks will serve American interests. What is needed is a response that builds the evidence base for government and industry to manage these risks, while the United States takes direct action to degrade China\u2019s AI developers.<\/p>\n<p>The threats these models pose to America\u2019s national security and economy\u00a0are real, as I documented in a <a href=\"https:\/\/www.cnas.org\/publications\/reports\/red-lines\" rel=\"nofollow noopener\" target=\"_blank\">recent report<\/a> for the Center for a New American Security,\u00a0and will only grow with their capabilities and adoption by businesses worldwide. The Commerce Department\u2019s Center for AI Standards and Innovation (CAISI)\u00a0<a href=\"https:\/\/www.nist.gov\/system\/files\/documents\/2025\/09\/30\/CAISI_Evaluation_of_DeepSeek_AI_Models.pdf\" rel=\"nofollow noopener\" target=\"_blank\">has<\/a>\u00a0<a href=\"https:\/\/www.nist.gov\/news-events\/news\/2025\/12\/caisi-evaluation-kimi-k2-thinking\" rel=\"nofollow noopener\" target=\"_blank\">released<\/a>\u00a0<a href=\"https:\/\/www.nist.gov\/news-events\/news\/2026\/05\/caisi-evaluation-deepseek-v4-pro\" rel=\"nofollow noopener\" target=\"_blank\">five<\/a>\u00a0<a href=\"https:\/\/www.nist.gov\/system\/files\/documents\/2026\/07\/17\/CAISI%20-%20Assessment%20of%20Z.ai%27s%20GLM-5.2.pdf\" rel=\"nofollow noopener\" target=\"_blank\">reports<\/a>\u00a0<a href=\"https:\/\/www.nist.gov\/news-events\/news\/2026\/07\/uk-aisi-caisi-preliminary-assessment-kimi-k3s-cyber-capabilities\" rel=\"nofollow noopener\" target=\"_blank\">since<\/a> January 2025 on various Chinese open-weight AI models, finding significant security vulnerabilities and deep ideological alignment with the Chinese Communist Party. Chinese model safeguards are consistently weak\u2014one DeepSeek model <a href=\"https:\/\/www.nist.gov\/system\/files\/documents\/2025\/09\/30\/CAISI_Evaluation_of_DeepSeek_AI_Models.pdf\" rel=\"nofollow noopener\" target=\"_blank\">complied<\/a> with every request CAISI made for help with hacking and online scams, from hijacking webcams to running romance-investment frauds, while comparable American models refused nearly all of them. Chinese developers are building these models by\u00a0<a href=\"https:\/\/epoch.ai\/publications\/chip-smuggling\" rel=\"nofollow noopener\" target=\"_blank\">smuggling<\/a> U.S.-designed chips, accessing\u00a0<a href=\"https:\/\/carnegieendowment.org\/research\/2026\/05\/the-geopolitical-debates-over-controlling-cloud-compute\" rel=\"nofollow noopener\" target=\"_blank\">overseas data centers<\/a>\u00a0to skirt U.S. export controls, and distilling U.S. models. Their\u00a0adoption <a href=\"https:\/\/cset.georgetown.edu\/publication\/pulling-back-the-curtain-on-chinas-military-civil-fusion\/\" rel=\"nofollow noopener\" target=\"_blank\">by the Chinese military<\/a>\u00a0threatens American citizens, and their diffusion among American firms is displacing America\u2019s own open-source AI developers.<\/p>\n<p>Open weights do have several characteristics that insulate users from some of these risks. The models can be inspected, fine-tuned, and run entirely on American hardware, so no data flows to China and no application programming interface (API) can be manipulated from Beijing. That is true, but it is not enough given the complexity of the models and the potential risks. A locally hosted Chinese model still carries CCP talking points, such as denying the Tiananmen Square massacre happened and presenting Beijing\u2019s territorial claims as settled fact. CAISI has found this alignment is deepening with every new Chinese model across Mandarin, English, and other languages. As these models are integrated into search, enterprise software, and consumer products around the world, Beijing\u2019s version of history and politics becomes the global default. These risks are becoming apparent even beyond topics directly related to China\u2014<a href=\"https:\/\/raport.valisluureamet.ee\/2026\/en\/6-asia\/6-3-chinese-artificial-intelligence-distorts-perceptions\/\" rel=\"nofollow noopener\" target=\"_blank\">Estonia\u2019s foreign intelligence service<\/a> found DeepSeek-R1 distorting facts about the Baltic states.\u00a0<\/p>\n<p>Chinese models have also demonstrated significant security vulnerabilities such as an elevated susceptibility to <a href=\"https:\/\/www.kelacyber.com\/blog\/follow-up-alibabas-qwen2-5-vl-model-is-also-vulnerable-to-prompt-attacks\/\" rel=\"nofollow noopener\" target=\"_blank\">prompt injection<\/a>, in which an attacker hides instructions in content the model reads. These vulnerabilities may interact in troubling ways with CCP ideological alignment. The <a href=\"https:\/\/www.crowdstrike.com\/en-us\/blog\/crowdstrike-researchers-identify-hidden-vulnerabilities-ai-coded-software\/\" rel=\"nofollow noopener\" target=\"_blank\">cybersecurity firm CrowdStrike found<\/a> that when DeepSeek-R1 is prompted on topics the CCP considers politically sensitive, the likelihood that it produces code with severe security vulnerabilities rises by as much as half. The line between critical uses\u2014defense systems, critical infrastructure, or government networks\u2014and ordinary commercial use is also unstable, as code written for a startup today may end up with a defense contractor tomorrow. Major AI coding platforms <a href=\"https:\/\/www.aei.org\/foreign-and-defense-policy\/code-red-is-the-future-of-american-ai-being-built-in-beijing\" rel=\"nofollow noopener\" target=\"_blank\">Cursor and Windsurf<\/a> have already integrated models from Chinese AI company Zhipu, meaning Chinese systems may process millions of fragments of proprietary American code each day.<\/p>\n<p>While the status quo is untenable, a rush to ban the models is bound to fail. Once model weights such as those from Kimi K3 are downloaded onto a server or other local hardware, <a href=\"https:\/\/www.lawfaremedia.org\/article\/the-next-mythos-moments\" rel=\"nofollow noopener\" target=\"_blank\">they cannot be recalled<\/a> by a prohibition. Imposing a ban without published evidence looks arbitrary to businesses and allied governments, conceding the argument to those who claim there is nothing to worry about.<\/p>\n<p>Testing and Transparency<\/p>\n<p>The first step is to test Chinese models and release the results to the public, rectifying the current imbalance in transparency. American AI developers conduct rigorous evaluations and publish extensive documentation, but Chinese developers\u00a0<a href=\"https:\/\/crfm.stanford.edu\/fmti\/December-2025\/index.html\" rel=\"nofollow noopener\" target=\"_blank\">do<\/a>\u00a0<a href=\"https:\/\/concordia-ai.com\/research\/state-of-ai-safety-in-china-2026\/\" rel=\"nofollow noopener\" target=\"_blank\">neither<\/a>. That imbalance has been exacerbated by the lopsided focus of much of the international AI policy community, which has scrutinized American models while giving China a free pass. Kimi K3 is the first Chinese model to receive a standalone assessment from the United Kingdom\u2019s AI Security Institute, which has been <a href=\"https:\/\/www.adalovelaceinstitute.org\/feature\/aisi\/\" rel=\"nofollow noopener\" target=\"_blank\">in operation since 2023<\/a> and is widely considered the most capable such government body. Its extensive publication record had until this year covered U.S. systems alone. U.S. government testing of Chinese models has been slow and sporadic but could be much faster. While leading AI diplomacy at the State Department, I saw CAISI test DeepSeek-R1 within a week of its release, only for the results to languish internally for months while Commerce Department leadership proved indecisive.<\/p>\n<p>Last month\u2019s <a href=\"https:\/\/www.nist.gov\/news-events\/news\/2026\/07\/uk-aisi-caisi-preliminary-assessment-kimi-k3s-cyber-capabilities\" rel=\"nofollow noopener\" target=\"_blank\">joint assessment of Kimi K3<\/a> with the United Kingdom shows what is possible\u2014with clear direction, the U.S. government can work with allies to assess new models and publish results in days. The United States and nine other governments, including the United Kingdom, <a href=\"https:\/\/www.gov.uk\/government\/news\/efforts-to-share-best-practices-on-ai-measurement-and-evaluations-driven-forward-through-the-international-network-for-advanced-ai-measurement-evalua\" rel=\"nofollow noopener\" target=\"_blank\">already share<\/a> evaluation methodologies through the International Network for Advanced AI Measurement, Evaluation and Science. Extending its methodological work into standing joint assessments among close partners would build a common evidentiary base and make any resulting restrictions much harder for Beijing to dismiss as American protectionism. This work could also include AI evaluation bodies in allied governments outside of the Network, such as India, Israel, the Netherlands, Poland, and Taiwan.<\/p>\n<p>Testing is a necessary prelude to developing standards that would mitigate risk. The U.S. government should work with American AI developers, both open and proprietary, to craft testing standards that define what a trustworthy AI model looks like. Susceptibility to jailbreaks, <a href=\"https:\/\/www.nist.gov\/system\/files\/documents\/2025\/09\/30\/CAISI_Evaluation_of_DeepSeek_AI_Models.pdf\" rel=\"nofollow noopener\" target=\"_blank\">agent hijacking<\/a>, and prompt injection, <a href=\"https:\/\/arxiv.org\/abs\/2512.09742\" rel=\"nofollow noopener\" target=\"_blank\">the<\/a> <a href=\"https:\/\/nvlpubs.nist.gov\/nistpubs\/ai\/NIST.AI.100-2e2025.pdf\" rel=\"nofollow noopener\" target=\"_blank\">presence of backdoors<\/a>, and <a href=\"https:\/\/academic.oup.com\/pnasnexus\/article\/5\/2\/pgag013\/8487339\" rel=\"nofollow noopener\" target=\"_blank\">ideological alignment<\/a> with a foreign adversary are all measurable. Such measurements would inform risk thresholds, and mitigations for those risks could be embedded in standards. If a model\u2014large or small, open-weight or closed, American or foreign\u2014could pass such standards, it would be considered safe. On the evidence to date, no Chinese model would come close.<\/p>\n<p>The Commerce Department\u2019s National Institute of Standards and Technology (NIST), which houses CAISI, already has <a href=\"https:\/\/www.cnas.org\/publications\/reports\/prepared-not-paralyzed\" rel=\"nofollow noopener\" target=\"_blank\">authority<\/a> to issue such guidelines under its <a href=\"https:\/\/uscode.house.gov\/view.xhtml?path=\/prelim@title15\/chapter7&amp;edition=prelim\" rel=\"nofollow noopener\" target=\"_blank\">organic statute<\/a>, though it cannot make them binding. NIST products work by being adopted voluntarily and then absorbed into binding instruments\u2014<a href=\"https:\/\/csrc.nist.gov\/pubs\/sp\/800\/171\/r3\/final\" rel=\"nofollow noopener\" target=\"_blank\">SP 800-171<\/a> began as guidance for protecting controlled unclassified information and is now a <a href=\"https:\/\/www.acquisition.gov\/dfars\/252.204-7019-notice-nistsp-800-171-dod-assessment-requirements.\" rel=\"nofollow noopener\" target=\"_blank\">contractual condition<\/a> for defense contractors. Model testing standards could follow a similar path. Cloud providers and enterprise buyers would adopt them first to meet sophisticated customer and auditor expectations, and federal procurement would follow. What is missing today is a clear directive from the secretary of commerce and a sufficient budget for regular testing. CAISI is underfunded even relative to its <a href=\"https:\/\/www.commerce.gov\/news\/press-releases\/2025\/06\/statement-us-secretary-commerce-howard-lutnick-transforming-us-ai\" rel=\"nofollow noopener\" target=\"_blank\">current mandate<\/a>, but just $60 million annually <a href=\"https:\/\/s3.us-east-1.amazonaws.com\/files.cnas.org\/documents\/Report_AI-Preparaed_TECH_Nov-2025_Final.pdf\" rel=\"nofollow noopener\" target=\"_blank\">could cover<\/a> a robust operational capacity, including regular evaluations of Chinese models.<\/p>\n<p>From Standards to Restrictions<\/p>\n<p>Cloud service providers, coding platforms, agent harnesses, and enterprise software vendors would be the primary targets for these standards. <a href=\"https:\/\/azure.microsoft.com\/en-us\/blog\/deepseek-r1-is-now-available-on-azure-ai-foundry-and-github\" rel=\"nofollow noopener\" target=\"_blank\">Microsoft\u2019s announcement<\/a> that it would host DeepSeek-R1 remains the only instance in which a major provider has publicly claimed to have specifically tested a Chinese model. Amazon and Google have never publicly made similar claims for any Chinese model. Microsoft has since narrowed even this initial claim. The <a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/foundry\/concepts\/safety-evaluations-transparency-note\" rel=\"nofollow noopener\" target=\"_blank\">company\u2019s documentation<\/a> today states that models it does not sell directly\u2014which includes open-weight Chinese models\u2014\u201chave not been evaluated by Microsoft,\u201d and assigns risk and safety evaluation to the customer.<\/p>\n<p>Nor are these relationships likely to remain at arm\u2019s length. <a href=\"https:\/\/github.com\/MoonshotAI\/Kimi-K3\/blob\/main\/LICENSE\" rel=\"nofollow noopener\" target=\"_blank\">Kimi K3\u2019s license<\/a> requires any company operating a model-as-a-service business whose total annual revenue exceeds $20 million over 12 months to enter an unspecified \u201cseparate agreement\u201d with Moonshot before commercial use. Should a major American provider decide to offer Kimi K3 as a managed service, it would first have to strike a commercial arrangement with Moonshot on terms that customers might never see.<\/p>\n<p>Standards would give enterprise customers a basis for comparing providers and give providers a reason to compete on assurance rather than speed. Far from constraining American firms, these standards would protect them from becoming potential conduits for espionage, sabotage, and propaganda, an exposure that would cost far more in user trust than a narrower model catalog. Labeling services that use Chinese AI models, <a href=\"https:\/\/www.nytimes.com\/2026\/07\/29\/opinion\/ai-china-us-free-models.html\" rel=\"nofollow noopener\" target=\"_blank\">as some have suggested<\/a>, would be meaningless without the context provided by robust public evaluations.<\/p>\n<p>Testing and standards would also provide the evidentiary basis for U.S. government action. One available authority is the Commerce Department\u2019s <a href=\"https:\/\/www.bis.gov\/OICTS\" rel=\"nofollow noopener\" target=\"_blank\">Information and Communications Technology and Services<\/a> (ICTS) program, which could bar American firms from hosting Chinese models or routing traffic to Chinese APIs, with two precedents for how it could be implemented. The June 2024 <a href=\"https:\/\/www.federalregister.gov\/documents\/2024\/06\/24\/2024-13532\/final-determination-case-no-icts-2021-002-kaspersky-lab-inc\" rel=\"nofollow noopener\" target=\"_blank\">Kaspersky designation<\/a> prohibited a single company\u2019s products on the basis of its subjection to Russian jurisdiction and control. The Commerce Department found that because Russian law compelled cooperation with the intelligence services, the Kaspersky antivirus software\u2019s privileged access to user systems posed an unacceptable risk regardless of how well the product performed. Applied in this case, that would mean designating specific developers such as Moonshot on the basis of ties to Chinese security services, a similar process to how Zhipu was added to the Commerce Department\u2019s <a href=\"https:\/\/www.federalregister.gov\/documents\/2025\/01\/16\/2025-00704\/addition-of-entities-to-and-revision-of-entry-on-the-entity-list\" rel=\"nofollow noopener\" target=\"_blank\">Entity List<\/a>, which restricts exports to entities determined to be acting contrary to U.S. national security or foreign policy interests.\u00a0<\/p>\n<p>Another approach to using ICTS is illustrated by the January 2025 <a href=\"https:\/\/www.federalregister.gov\/documents\/2025\/01\/16\/2025-00592\/securing-the-information-and-communications-technology-and-services-supply-chain-connected-vehicles\" rel=\"nofollow noopener\" target=\"_blank\">Chinese connected vehicles<\/a> rule, which defined a category of covered technology and prohibited it wherever it was designed, developed, or supplied by entities subject to Chinese or Russian jurisdiction. Testing results for Chinese models would provide the technical parameters for an ICTS rule using this second approach that would determine which models, which developers, and for which uses there would be restrictions. Such restrictions grounded in evidence would be more credible to the American public and foreign partners, as well as more likely to survive a potential legal challenge.<\/p>\n<p>Degrading China\u2019s AI Ecosystem<\/p>\n<p>The most durable way to mitigate the risks of Chinese AI models and maintain America\u2019s edge is to go on offense against China\u2019s AI developers. Michael Kratsios, director of the White House Office of Science and Technology Policy,\u00a0<a href=\"https:\/\/x.com\/mkratsios47\/status\/2079933645888880708?s=46&amp;t=pODdoC9LSnWNtEUOtIPYdw\" rel=\"nofollow\">has said<\/a>\u00a0that Moonshot, the creator of Kimi K3, accessed advanced chips both directly and through clusters in Thailand, and distilled Anthropic\u2019s Fable 5 model to build Kimi K3. Closing these pathways through <a href=\"https:\/\/ifp.org\/should-the-us-sell-hopper-chips-to-china\/\" rel=\"nofollow noopener\" target=\"_blank\">stronger export controls<\/a> and <a href=\"https:\/\/lawreforminstitute.org\/DOJFTC041526.pdf\" rel=\"nofollow noopener\" target=\"_blank\">closer coordination<\/a> among American developers would throttle the AI development that powers China\u2019s military, intelligence services, and surveillance state. A slate of pending bills, including the <a href=\"https:\/\/www.congress.gov\/119\/bills\/s4456\/BILLS-119s4456is.pdf\" rel=\"nofollow noopener\" target=\"_blank\">AI Overwatch Act<\/a> and <a href=\"https:\/\/www.congress.gov\/119\/bills\/hr3447\/BILLS-119hr3447ih.pdf\" rel=\"nofollow noopener\" target=\"_blank\">Chip Security Act<\/a>, would tighten restrictions and enforcement on chip exports, and Treasury Secretary Scott Bessent should make good on his\u00a0<a href=\"https:\/\/www.cnbc.com\/2026\/07\/21\/bessent-china-ai-sanctions.html\" rel=\"nofollow noopener\" target=\"_blank\">warning last week<\/a>\u00a0to sanction Chinese companies engaged in adversarial distillation.<\/p>\n<p>Huang is right that capable models like Kimi K3 will be used. The question is whether the U.S. government will know what is in them before that use becomes difficult to unwind, and whether it will take action to make the next Chinese model harder to build.<\/p>\n<p>FEATURED IMAGE: In this photo illustration, a smartphone displays the Kimi K3 logo in front of a screen showing an enlarged Moonshot AI symbol on July 18, 2026, in Shenzhen, Guangdong Province, China. Moonshot AI introduced Kimi K3 on July 16, describing it as its most capable model to date, featuring 2.8 trillion parameters, native multimodal capabilities and a context window of up to one million tokens. (Photo illustration by Cheng Xin\/Getty Images)<\/p>\n","protected":false},"excerpt":{"rendered":"The release of the sprightly named Kimi K3 AI model from Chinese developer Moonshot has prompted a fresh&hellip;\n","protected":false},"author":2,"featured_media":142361,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[24,25,111,1069,387,70224,5969,313,8783,26257,1715,8926],"class_list":["post-142360","post","type-post","status-publish","format-standard","has-post-thumbnail","category-ai","tag-ai","tag-artificial-intelligence","tag-artificial-intelligence-ai","tag-big-tech","tag-china","tag-chinese-communist-party-ccp","tag-cyber","tag-cybersecurity","tag-emerging-technology","tag-national-institute-of-standards-and-technology-nist","tag-regulation","tag-united-states-us"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/142360","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=142360"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/142360\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/142361"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=142360"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=142360"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=142360"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}