The Moonshot AI Kimi app is seen on a mobile phone screen in Beijing on July 17, 2026.

Regulate, Don’t Ban, Chinese AI Models

Washington, D.C. policy circles are buzzing with talk of whether and how to restrict access to Chinese AI models. But the right answer is to regulate all AI models for safety through pre-deployment and ongoing testing for risks associated with cybersecurity, bioweapons, and loss of human control. Market access for all AI models, including Chinese open-weight models, could be conditioned on passing these assessments.

This debate was sent into overdrive by the 2.8 trillion parameter AI model Kimi K3 released on July 16 by the Chinese startup Moonshot AI. It scored near the top of industry benchmarks, but its price was dramatically lower than the prices for comparable U.S.-developed AI models. Moreover, on July 27, Moonshot publicly released the numerical weights to Kimi K3, allowing users to download the model for free, modify it and run it on their own infrastructure, or on compute leased from cloud providers. 

U.S. government officials instantaneously accused Moonshot of intellectual property theft. They alleged Moonshot illegally used output from Anthropic’s Fable 5 to train its model, using a process called distillation, whereby the output from a larger AI model is used to train a smaller AI model. “Open source is not open season on American IP,” said Treasury Secretary Scott Bessant. 

Moonshot has denied distilling Kimi K3 from other AI models and says its capabilities derive from its original innovations. The administration’s allegation turns out to be technically weak. As AI researcher Nathan Lambert put it, “the timeline is such that Fable 5 likely had no impact as a distillation teacher.”

Nevertheless, U.S. officials floated measures to restrict access to Chinese models including the puzzling idea of imposing export controls on imports, that is, on what U.S. companies can buy or use from foreign companies. Other proposed restrictive measures included a national emergency declaration under the International Emergency Economic Powers Act (IEEPA) that would restrict commercial transactions involving Chinese AI models, a ban on using Chinese models in government systems, warning letters from U.S. intelligence agencies and financial regulators, disclosure requirements and informal pressure, including appearances before hostile congressional committees. 

Who’s Afraid of Chinese Models?

Open source AI models from China are widely used by U.S. companies. In reaction to the administration’s push for banning Chinese models, 179 AI companies (later joined by OpenAI, Google, SpaceX, and Amazon) sent a letter urging administration officials not to restrict Chinese open-weight models, focusing less on Chinese origin and more on the need to preserve a space for open-weight models. 

But of course the administration’s concern was not with open models as such, which it favors so long as they are provided by U.S. companies, but with AI models from companies domiciled in China.

Anthropic, which did not sign the industry’s letter, seems to want to target Chinese models while sparing open models generally. In a blog post, the company says that it opposes a “blanket ban on open-weights models” but favors policies to prevent distillation of U.S. models by companies domiciled in “an authoritarian state seeking to overtake the US at the frontier.” Under this policy, U.S. authorities would approve open-weight models from Mistral, Nvidia, Thinking Machines, the Allen Institute for AI, Google, and Reflection AI, but rely on unproven allegations of improper distillation by Chinese companies to ban their models. This might be where U.S. policymakers are headed.

Relying on national security authorities to vindicate a U.S. company’s intellectual property rights is a clear abuse of these laws. If a company has a complaint regarding intellectual property theft, the proper course of action is to bring a case before the International Trade Commission, a U.S. agency set up to investigate unfair import practices involving patent, trademark, copyright, or trade secret infringement. The ITC is fully empowered to issue an exclusion order to keep infringing items out of the U.S. market or a cease-and-desist order if they are already inside the country. 

The Right Solution: Safety Testing Capable Models

The rest of the AI industry opposes Anthropic’s indirect way of eliminating its major existing open source competitors. Its open letter to U.S. authorities called for “continued access for U.S. builders to open models already available worldwide, with proportionate safeguards…” 

The key is the “proportionate safeguards,” and here Anthropic’s blog points to the right solution: namely, “requiring safety testing of all sufficiently capable models, open and closed.”

This question of safety testing to reduce risks from highly capable AI models has become urgent because of OpenAI’s recent hack of the website Hugging Face, which exposed flaws in the controls set up to contain a frontier model during testing. 

As part of its defensive measures, Hugging Face tried to use an undisclosed U.S. closed-weight model. But the security guardrails of that model interpreted its requests for incident response as a request to engage in hacking and refused to provide any analysis of the intrusion data Hugging Face supplied. The repository then successfully used the open-weight AI model GLM 5.2, from the Chinese startup z.AI, running on its own infrastructure, to analyze and respond to the intrusion. As Hugging Face indicated in its report on this incident, the implications of this superiority of open-weight AI systems for defensive cybersecurity operations are still being assessed. 

Subsequently, Anthropic reported that its models had also escaped onto the open internet and attacked the security systems of three unnamed organizations. In neither case was the AI company aware of the breach as it was happening, but discovered it only days or weeks after the fact. 

How Testing Can Work in Practice

To respond to such AI risks, industry and government seem to have reached a consensus in favor of a new program of pre-deployment and ongoing testing of frontier AI models, including Chinese AI models. Industry leader Demis Hassabis, CEO of DeepMind, proposed an industry self-regulatory agency modeled after the Financial Industry Regulatory Authority (FINRA), the industry group regulating broker-dealers under the supervision of the Securities and Exchange Commission. Legal scholar Mark Thomas added some detail on how such a “FINRA for frontier AI” might be put into practice. The proposed Great American AI Act puts the responsibility on the Center for AI Standards and Innovation (CAISI) to run a network of vetted auditors to do the testing. The Council of Foreign Relations published an expert take on the right design for an AI regulator tasked with reducing risks from frontier AI models.

Whoever is empowered to perform this testing, what seems common to all these proposals is that AI model testing should include assessment for cybersecurity, biological weapons, and escape from human control. Passing such an assessment would not guarantee AI safety, but it would reduce AI risk to a manageable level. Chinese AI models, like their U.S. counterparts, would be permitted on the U.S. market after passing the assessments, but not otherwise, and could be withdrawn from the market if ongoing testing revealed a flaw that initial testing had not identified. NIST has already performed a preliminary analysis of Moonshot’s Kimi K3, indicating that such reviews of Chinese open models are feasible. 

Of course, China might not want to submit its models for testing by a U.S. agency as a condition of market access. But pre-deployment screening is precisely the condition China imposes on all AI models, including U.S. AI models. In order to provide an AI model to the public in China, a developer, foreign or domestic, must submit it to the Cyberspace Administration of China and demonstrate that it passes China’s strict information content controls. To protect U.S. companies from risks associated with AI models, including Chinese AI models, it is entirely sensible and defensible to require all of them to submit to appropriate, neutral technical assessments. 

Moving Ahead: A Global Solution?

In the end, it might be best if the agency testing AI models was not an agency of the U.S. government, but a neutral, technical international agency that could provide assessments that all governments would defer to. At the upcoming U.S.-China AI dialogue in September, China could be invited to participate in the construction of such an agency and the development of testing standards that would apply to AI models from both countries. While China’s AI safety efforts lag behind those of the United States, policymakers, academics, and industry leaders there are increasingly focusing their efforts on the same AI risk reduction issues that keep U.S. experts up at night: cybersecurity, bioweapons, and loss of human control. 

The temptation for many U.S. policymakers will be to say Chinese open-weight models are too risky, while U.S. open AI models are not. But that is just using safety concerns as a smokescreen for protectionism. U.S. companies and users deserve the best AI models that the U.S. and Chinese ecosystems can produce. Policy has to provide for minimum safety standards and pre-deployment and ongoing testing to reduce risks. The many unanswered questions of regulatory design and technical assessment criteria raised in AI risk reduction discussions have to be addressed. But any AI safety regime that works for domestic AI models should be good enough for foreign models, including those made by Chinese companies. 

Filed Under

, , , , , , , , , , , , ,
Send A Letter To The Editor

DON'T MISS A THING. Stay up to date with Just Security curated newsletters: