+44 (0) 203 816 9970

China: AI’s open weights and closed doors

Date first published: 28/07/2026

Key sectors: technology, artificial intelligence

Key risks: export controls, AI cybersecurity; regulatory changes; trade disruptions

Risk development

Moonshot AI, a Beijing-based startup backed by Alibaba, released Kimi K3 on 16 July, a 2.8tn parameter model it calls the largest open-weight system yet built. Independent evaluators placed K3 third among all model families on several composite benchmarks, ahead of Anthropic’s Opus 4.8 and behind only Fable 5 and OpenAI’s GPT 5.6 Sol. The release reopened a debate in Washington over whether open-weight models should face restrictions similar to those already placed on advanced chips.

Why it matters

Chinese models generally trail the US frontier by months rather than years. While they may be less advanced, they are able to compete on cost and openness. Where Anthropic and OpenAI keep their model weights – the internal parameters that determine how a system behaves – private and accessible only through a paid API, Moonshot and DeepSeek publish theirs openly. That openness lets any enterprise download the model and run it on its own servers, avoiding per-token fees and keeping sensitive data off a third party’s infrastructure entirely.

Moonshot priced K3 well below Anthropic and OpenAI’s offerings even through its own API, while DeepSeek’s V4 family has pushed input token prices far lower. If Chinese models are good enough, Enterprise adopters will route through cheaper models, and Chinese models overtook their US rivals in weekly token volume earlier this year.

The underlying problem for closed-weight companies is that intelligence becomes commoditised – where the output from each model is nearly identical. If accurate, that would narrow the case for paying a premium for closed US systems and squeezing the margins Anthropic and OpenAI need to fund frontier research. That anxiety fed into a public dispute on 24 July when Nvidia’s Jensen Huang, joined by two dozen companies including Microsoft and Meta, published a letter urging policymakers not to restrict open-weight models, arguing this would simply cede the field to Chinese labs facing no equivalent limit.

Background

Washington’s export controls on advanced semiconductors, tightened repeatedly since 2022, are an attempt to prevent Chinese frontier labs from competing with the US, targeting both the chips themselves and the machinery used to make them. Nvidia’s most advanced chips, the graphics processors that train frontier models, are made almost entirely by Taiwan Semiconductor Manufacturing Company, whose leading-edge fabrication capacity Chinese firms cannot access. Washington’s 2022 restrictions barred export of Nvidia’s most capable chips to China outright, a policy that remains in place despite revisions. Huawei’s Ascend line is Beijing’s closest domestic answer, working at roughly 60 per cent of the inference performance of Nvidia’s H100, a gap Chinese firms have partly offset by deploying chips in far larger clusters. Domestically, memory maker CXMT has expanded dynamic random-access memory (DRAM) output using older deep ultraviolet (DUV) tools and is targeting early production of high-bandwidth memory this year.

The controls also block Chinese firms from buying extreme ultraviolet (EUV) lithography systems, the tools capable of etching the smallest, most advanced transistor patterns, and from servicing older equipment already installed in Chinese fabs. Dutch equipment maker ASML holds an effective monopoly over EUV, leaving Beijing without a legal route to the technology at any price. China has instead pushed forward with DUV lithography tools, an older and less precise class of machine that its own manufacturers can now reportedly build domestically.

Risk outlook

US models are likely to retain a capability edge; however, most commercial applications do not require frontier performance, and given the cost advantage of Chinese models, that could prove existential for US frontier labs. Another question concerns safeguards: once weights are public, controls built by the original developer can be stripped out or bypassed, a potential cybersecurity risk. Restricting open weight releases risks handing the growing developer base to Chinese alternatives, potentially with fewer checks and constraints.

×

Thematic Report Download

To download this report, please enter your details below.