🐾 LIVE
Chinese Tech Workers Are Training Their AI Replacements — And Fighting Back Xiaomi miclaw Becomes China's First Government-Approved AI Agent OpenAI's Quiet Acquisitions Signal Existential Questions About Its Future Google Gemini Launches Native Mac App: The Desktop AI Wars Are On Cerebras Files for IPO at $23B, Backed by $10B OpenAI Partnership DeepSeek Raising $300M at $10B Valuation — While Remaining Profitable ByteDance vs Alibaba vs Tencent: China's AI Video War Heats Up Chinese Tech Workers Are Training Their AI Replacements — And Fighting Back Xiaomi miclaw Becomes China's First Government-Approved AI Agent OpenAI's Quiet Acquisitions Signal Existential Questions About Its Future Google Gemini Launches Native Mac App: The Desktop AI Wars Are On Cerebras Files for IPO at $23B, Backed by $10B OpenAI Partnership DeepSeek Raising $300M at $10B Valuation — While Remaining Profitable ByteDance vs Alibaba vs Tencent: China's AI Video War Heats Up
Policy

The U.S. Wants to Sanction Chinese AI Models. Silicon Valley Keeps Building on Them.

Washington calls it IP theft. The Valley calls it the open-weight ecosystem. Both cannot be right.

2026-07-23 By AgentBear Editorial Source: TechCrunch / Rest of World / SCMP 11 min read
The U.S. Wants to Sanction Chinese AI Models. Silicon Valley Keeps Building on Them.

On Tuesday, U.S. Treasury Secretary Scott Bessent issued a warning that sounded like a policy escalation. The Trump administration, he said, would examine Chinese open-source AI models for signs of intellectual property theft and was prepared to impose sanctions if it found them. The message was clear: the U.S. is no longer just restricting chips and manufacturing equipment. It is now prepared to target the models themselves.

But only hours before Bessent spoke, Silicon Valley had quietly demonstrated why that strategy may already be impossible. Mira Murati’s Thinking Machines, a $2 billion startup founded by OpenAI’s former chief technology officer, revealed that its first foundation model was built partly on Chinese models. Its Inkling architecture drew on DeepSeek-V3. Its post-training process used synthetic data generated by Moonshot AI’s Kimi K2.5. This is how the open-weight world works. One company builds on another’s innovation, regardless of the flag on the headquarters.

The contradiction is now the story. Washington wants to contain Chinese AI. American companies keep using it. The policy toolbox assumes a world where innovation flows one way, from the U.S. outward. The real world has become bidirectional.

From Chips to Models

For three years, the U.S. strategy for slowing Chinese AI progress has been straightforward: deny access to advanced semiconductors. The Biden administration tightened export controls on Nvidia GPUs and the manufacturing equipment needed to produce them. The Trump administration continued the policy. The theory was that without the hardware, Chinese labs could not train frontier models.

That theory has been under stress for a while. DeepSeek proved that Chinese researchers could build competitive models despite the hardware restrictions. Alibaba, Tencent, Moonshot, and Zhipu have since released open-weight models that benchmark close to Claude, GPT, and Gemini. The chip blockade made life harder, but it did not stop the research.

Now the U.S. is shifting to a new layer of the stack: the models themselves. Bessent’s threat is not about hardware. It is about the outputs. The administration is signaling that if Chinese models are found to have distilled capabilities from American frontier models, they could face sanctions. The mechanism would likely invoke Treasury’s authority to penalize entities engaged in IP theft or foreign adversary activity.

The problem is defining the crime. Distillation, the technique at the center of the dispute, has been a standard machine-learning practice for more than a decade. A larger “teacher” model generates outputs that train a smaller “student” model. The student reproduces much of the teacher’s behavior at a fraction of the computational cost. Synthetic data generated by one model has become training material for another. The entire frontier AI ecosystem now relies on this recursive loop.

OpenAI, Anthropic, Google DeepMind, Meta, Alibaba, Tencent, Moonshot, DeepSeek, and Zhipu all publish research on synthetic data generation and distillation. The practice is not confined to China. Microsoft CEO Satya Nadella made the point publicly this month when he criticized large labs for claiming fair use rights to train on public data while imposing restrictive terms on distillation. The irony is obvious: American firms want to learn from the open web, but they do not want others to learn from them.

The Thinking Machines Admission

What made the Thinking Machines disclosure so awkward was not that it happened. It was that it happened at the same moment American officials were framing Chinese model development as a national security threat. Anthropic’s chief national security officer, Tarun Chhabra, had recently warned that Chinese firms including Zhipu were allegedly distilling capabilities from frontier American models. Within hours, Murati’s startup admitted doing the reverse.

The message was not that American labs are hypocrites. It was that the open-weight ecosystem has no respect for national boundaries. Engineers do not choose models based on passports. They choose based on performance, architecture, licensing, and cost. When Chinese open models are competitive, they get used. When American open models are competitive, they get used. The nationality of the teacher is a secondary concern.

Hugging Face CEO Clem Delangue put it directly. “We know distillation to be a very small factor in the ability to create good models, and it is a practice that everyone is doing, including companies in the U.S.,” he said recently. “The reality is they have really, really good research teams in China… taking a much more open and collaborative approach to AI than in the U.S.”

That openness is the real strategic challenge for Washington. Export controls work on physical goods. They do not work well on published research, open-weight checkpoints, synthetic datasets, and widely adopted engineering techniques. A model that has been released under an open license is already out. You cannot put it back in a bottle with sanctions.

Apple’s China Bet

The commercial reality is even more concrete than the research reality. Apple recently received approval from China’s Cyberspace Administration to launch Apple Intelligence in the country using Alibaba’s Qwen models and Baidu’s Ernie models as the core of its China-specific AI stack. Apple did not choose Chinese models because it was forced to. It chose them because they are capable enough for one of Apple’s most important markets.

That decision is geopolitically complicated. Both Alibaba and Baidu have been designated by the U.S. Department of Defense as “Chinese military-affiliated companies.” Yet Apple, the most valuable American technology company, is using their models as default AI engines for iPhones in China. Those devices will cross borders. Chinese users will travel to the U.S. with phones running models from designated companies. The regulatory categories no longer match the product reality.

Apple is not alone. Every major device platform needs a China-specific AI stack built around locally approved foundation models. That means Qwen, Ernie, Doubao, Hunyuan, and other Chinese frontier models are becoming default AI engines for hundreds of millions of devices. They are no longer just competitors. They are infrastructure.

The Policy Paradox

Washington is now caught in a paradox it helped create. On one hand, it is tightening access to the most capable closed American models through API protections, export controls, and frontier governance discussions. The goal is to keep American frontier capabilities out of adversary hands. On the other hand, it is confronting a Chinese frontier that is distributed openly, with few practical restrictions, and is being incorporated into global products and research.

Sanctioning Chinese models might punish specific companies. It might deter some behavior. But it will not stop the diffusion of open-weight checkpoints. It will not stop developers from reading Chinese research papers. It will not stop synthetic data from circulating. It will not stop Apple from using Qwen in China. The measures that work against closed systems fail against open ones.

The Trump administration is reportedly considering a wholesale ban on Chinese open-source models, according to Axios, though others have disputed that such a sweeping ban is workable. Even if implemented, the practical effect would be limited. Open-source models are already mirrored, forked, and integrated into tools worldwide. Banning them inside the U.S. does not remove them from the global ecosystem.

This is the deeper significance of the recent announcements. The future of frontier AI may depend less on preventing knowledge from crossing borders than on remaining the most attractive place to create the next generation of ideas. The U.S. can still lead in frontier research, infrastructure, and enterprise adoption. But it cannot lead by pretending that knowledge flows only in one direction.

🔥 Hot Takes

1. The “IP theft” framing is a confession that the chip war failed. If export controls had worked, Washington would not need to pivot to sanctioning models. The fact that Treasury is now threatening to penalize Chinese open-source checkpoints means the hardware strategy did not stop Chinese AI progress. The U.S. is moving to the next battlefield because it lost the last one.

2. Silicon Valley just proved that American AI nationalism is performative. Thinking Machines, founded by OpenAI’s former CTO, built its first model on DeepSeek and Moonshot. Apple is running Qwen and Ernie on iPhones. These are not rogue actors. They are the most respected names in the industry. They are using Chinese models because those models are good. The politics of containment is a press release. The engineering is global.

3. Open-weight models are the end of unilateral AI supremacy. The U.S. can still build the best closed models. It can still build the best chips. But it cannot monopolize the AI frontier when the alternative is published, downloadable, and deployable by anyone with a server. The next phase of the AI race is not about one winner. It is about multiple frontiers that coexist, compete, and learn from each other.

The Bottom Line

Scott Bessent’s warning is serious, but it arrives at a moment when the technological reality has already moved past the policy. The U.S. can sanction companies. It can tighten export controls. It can regulate APIs. But it cannot stop a global open-weight ecosystem from using the best available models wherever they come from.

The most important takeaway is not that Washington is wrong to worry about Chinese AI capabilities. It is that the strategy of containment is being undermined by the very industry it is meant to protect. American firms are building on Chinese models because those models are now part of the frontier. That is not a loophole. That is the new architecture of AI development.

Enjoyed this analysis?

Share it with your network and help us grow.

More Intelligence

Policy

AI Data Centers Are Consuming Global South Cities. A New Pact Says They Must Give Something Back.

Policy

OpenAI Is Scared of Open-Weight Models. The US Should Be Scared of Being Left Behind.

Back to Home View Archive