Why the U.S. should protect open-weight AI, not ban it | The Neuron

Hot Take: Why a U.S. Ban on Chinese Open-Weight AI Models Would Backfire

In defense of open source AI. Washington briefly debated restricting Chinese open-weight models after Kimi K3 closed the performance gap. A ban would raise American costs, weaken defenders, and protect incumbents instead of solving the real security problems.

Written By
Grant Harvey
Grant Harvey
Jul 21, 2026
19 minute read

A strange policy reflex appeared in Washington this week: a Chinese company released a cheaper, near-frontier AI model, so parts of the U.S. government reportedly considered making it harder for Americans to use.

That idea currently appears paused. But the underlying instinct is still worth confronting because the model in question, Kimi K3, will not be the last model to trigger it. Qwen, GLM, DeepSeek, and whatever ships next will keep forcing the same choice.

America can compete by building better open models, lowering inference costs, and testing foreign systems for concrete threats. Or it can protect domestic labs from price competition and call the result national security.

The second path makes American companies pay more for worse access while the rest of the world keeps building.

First up, the TL;DR

When a foreign lab releases a powerful model at a lower price, America has two options: build a better alternative or make the cheaper one harder for Americans to use. Washington briefly considered the second path after Moonshot AI unveiled Kimi K3. That would've been a mistake.

The move would have the appearance of protecting domestic labs from competition, but it would raise costs for American builders. A bold strategy, assuming the rest of the world agrees to stop, idk, downloading files?!

Here's what happened:

  • An Axios report said officials explored restrictions on advanced Chinese models, including procurement pressure and hosting rules.
  • Politico reporter Sophia Cai later said Commerce was not moving forward with a ban at this time.
  • The backlash was immediate. Ethan Mollick questioned whether national security was becoming industrial policy, while Aaron Levie argued that open models lower costs, expand choice, and improve security research.

Why this matters: Open-weight models, meaning models whose underlying files can be downloaded and run independently, keep the AI market competitive. They let companies run sensitive work privately, customize systems, and avoid paying frontier prices for every basic task. The recent Hugging Face security incident showed the practical value: commercial safety filters blocked defenders from analyzing attack data, so the team used an open Chinese model on its own infrastructure instead.

Advertisement

The security risks of open models are real, but as Corey argued, the answer is testing. The Commerce Department’s own open-model report recommended audits, benchmarks, and evidence-based thresholds rather than a blanket ban. Let's hope that's what they do.

Our take: Let us not forget: the biggest US AI labs trained on an enormous share of humanity’s books, websites, code, and conversations. Most contributors never negotiated any sort of payment whatsoever. The resulting ecosystem becomes at least remotely fair only when ordinary people retain access to capable models outside permanently metered APIs. not like regular people are running Kimi K3, mind you, but in theory anyone could on a cloud provider of their own choosing, where they get the best deal and keep their proprietary data private.

We believe that today's "closed" American labs could still make money with an open-weights strategy through a three-layer distribution model:

  • Sell an ownable commercial license for advanced weights (one time purchase on behalf of customer).
  • Charge for fast, secure, managed hosting of the weights on the cloud.
  • Release small models that run locally for free on devices (selling the devices with these models built in).

As Ben Thompson’s cost analysis makes clear, free weights still create paid demand for chips, cloud capacity, and convenient hosting. Open models are the floor that keeps frontier prices honest. America should build on and support that foundation, not pull the floor out from under an already shaky foundation.

Now, let's dive into all that with a bit more detail, shall we?

What happened, and what is the latest?

An Axios report said the Trump administration had explored several ways to restrict advanced Chinese models. The options reportedly included Entity List additions, security advisories, procurement pressure, hosting liability, and supply-chain rules. Andrew Curran’s initial summary described the most dramatic possibility as an executive order banning Chinese open-source models in the United States.

The immediate trigger was Moonshot AI’s Kimi K3. Our launch coverage explains the model’s 2.8 trillion parameters, native vision, and one-million-token context window. Its full weights are scheduled for release on July 27. Early independent tests placed it near leading U.S. systems on coding and agent tasks, while its API pricing undercut premium American models on a per-token basis.

Then the story moved. Politico reporter Sophia Cai said Commerce had briefly discussed the idea but was not moving forward with a ban at this time, citing a person familiar with the matter. That does not erase Axios’s reporting about prior proposals or the policy faction pushing them. It means there is no announced ban to fight today.

Advertisement

That distinction matters. A rumor can still reveal a real governing instinct, especially when the reported tools include quiet pressure rather than one clean prohibition. Procurement rules, licensing threats, and public warnings can freeze adoption quietly. No formal ban is required.

Why the reaction was so hostile

The backlash arrived quickly because builders heard a competition policy dressed in security language.

  • Ethan Mollick asked whether officials were responding to a demonstrated threat or using national security as industrial policy. His point was practical: American companies have already invested heavily in products built on Chinese open models.
  • Peter Gostev warned that U.S. labs already block many legitimate cybersecurity workflows. Restricting Chinese alternatives could leave American defenders with fewer capable tools than their counterparts abroad.
  • Max Weinbach argued that Washington should loosen unnecessary restrictions on American models and accelerate domestic innovation rather than remove foreign competition.
  • Aaron Levie laid out the broadest business case. Open weights expand model choice, lower costs, enable industry-specific tuning, support security research, and pressure every provider to improve.
  • Yishan Wong compared a model ban to U.S. restrictions on Chinese electric vehicles. The protected domestic industry survives, while American consumers lose access to cheaper products available elsewhere.
  • signüll called the proposal state-protected capitalism, where incumbents keep the upside and government absorbs their competitive risk. A follow-up post sharpened the class argument: AI restrictions would protect a narrow group of wealthy lab employees and investors while spreading higher costs across the economy.
  • Hugging Face CEO Clément Delangue argued that blocking open models would hurt defenders far more than attackers, because malicious actors ignore usage policies while legitimate teams need reliable, inspectable tools.

Chamath Palihapitiya pushed the cost argument further. He argued that leading AI has already forked into two markets: closed American models costing roughly $26-$56 per million tokens, and open-weight Chinese models costing roughly $0.50-$1.

If American companies are forced to spend 50-100 times more than overseas competitors for comparable intelligence, the damage would spread far beyond AI budgets. Chamath compared it to requiring U.S. companies to buy oil at $800 per barrel while the free market sells it for $80.

His prediction is brutally simple:

  • American companies absorbing that premium eventually become less competitive and financially impaired, dragging on the wider market.
  • Closed American labs preserve revenue in the short term, then lose it as weakened domestic customers cut spending and foreign customers switch to cheaper options. 100% agree with this.

That would make the intervention self-defeating. Protecting the labs’ revenue today could undermine both the customers paying them and the market they need tomorrow.

A Washington Post editorial from legendary investor Bill Gurley made the same argument in fewer words: cheap, capable models are what competition looks like. The government should answer them with better American alternatives, not a protected market for OpenAI and Anthropic. The paper had made a similar case earlier in July, warning that regulation would burden U.S. startups while foreign competitors continued using cheap Chinese systems.

Advertisement

The emotion behind those reactions comes from a simple asymmetry. A U.S. ban would constrain U.S. companies. It would barely affect Chinese labs, overseas developers, criminal groups, or governments willing to route around it.

That is a very expensive way to make a point.

The security argument deserves a real answer

Open weights create genuine risks. Anyone with the files can remove safety tuning, fine-tune the model for a harmful domain, and run it privately. A compromised download, dependency, update channel, or inference package can create supply-chain exposure. Models from an adversarial country deserve rigorous scrutiny before entering classified systems or critical infrastructure.

The strongest security case supports testing and deployment controls. A country-of-origin shortcut skips the evidence those controls require.

The U.S. government already reached a similar conclusion in the Commerce Department’s 2024 report on widely available model weights. NTIA found meaningful benefits and plausible risks, including misuse, reduced oversight, privacy, and national security concerns. It also found insufficient evidence for a broad restriction at that time. The recommendation was to build audits, benchmarks, indicators, and thresholds, then act when the evidence crosses them.

That is the right policy shape:

  • Test the model artifacts, dependencies, and update process.
  • Measure whether the deployment sends prompts, credentials, or telemetry elsewhere.
  • Require software bills of materials, cryptographic hashes, and reproducible packages.
  • Red-team dangerous capabilities and publish the standards.
  • Apply stricter rules to defense, classified systems, health care, finance, and critical infrastructure.
  • Restrict a model when evaluators demonstrate a backdoor, exfiltration path, malicious dependency, or unacceptable capability.

Our earlier Neuron piece, “Don’t Ban Chinese Open AI Models. Test Them,” made this case directly. A passport is a poor threat model. Behavior, distribution, permissions, and data flows are much better ones.

Open models can also improve security. Teams can run them inside their own environment, freeze a vetted version, restrict networking, inspect the surrounding code, and keep sensitive data away from third-party APIs. Closed models offer convenience and strong safeguards, but users must trust the provider’s infrastructure and policies.

Advertisement

The Hugging Face security incident turned that abstract tradeoff into an operational lesson. After an autonomous agent system breached parts of Hugging Face’s infrastructure, defenders tried commercial frontier APIs to analyze more than 17,000 attack events. Safety filters blocked the exploit payloads and command-and-control artifacts they needed to inspect.

Hugging Face ran Z.ai’s open-weight GLM 5.2 on its own infrastructure instead. The model helped reconstruct the attack in hours, and the credentials stayed inside the company’s environment. The Stack’s account captured the uncomfortable result: attackers faced no provider policy, while defenders were stopped by theirs.

This example does not prove every open model is safe. It proves access itself can be a defensive capability.

The fairness problem underneath the policy fight

The largest AI labs built valuable products by training on an extraordinary share of digitized human culture: books, websites, code, journalism, art descriptions, public discussions, and more. Most contributors never negotiated a license or received a check.

Copyright law in this very nebulous area remains unsettled, and recent decisions have split the issue by how material was obtained and used. In the Anthropic book case, the court treated training on lawfully acquired books as fair use while allowing claims over millions of books downloaded from pirate libraries to proceed. Anthropic later agreed to a $1.5B settlement covering those piracy claims, which was just officially approved by a judge and finalized today. OpenAI still faces active litigation from publishers and authors alike, as do many other AI model provider companies.

The legal nuance here does not erase the social bargain at play here, though. Public knowledge supplied much of the raw material, while private companies captured most of the model ownership... private companies set up as non-profits and public benefit companies, mind you. And yet the public is now being asked to rent back access to their information by the token?

That's why, in my opinion, open weights are one way to return leverage to the people and institutions that helped create the underlying knowledge base. They do not compensate authors, artists, programmers, or publishers. But they do create a public benefit from a training process that otherwise concentrates control inside a few companies because of the way said companies decided to accelerate and scale the compute they used to build such models. Because of open weight AI, some broadly accessible capability survives outside metered APIs, and it must continue to do so, or this supposed bargain never really becomes remotely fair.

The tangible benefit of open source AI appears in four places:

  • Access: students, researchers, nonprofits, small companies, and governments can use capable models without negotiating complicated enterprise contracts or being priced out of the frontier.
  • Control: organizations can fine-tune models, change the surrounding system, and avoid dependence on one vendor’s roadmap, giving them access to free markets in the form of (usually American) compute providers.
  • Privacy: sensitive work can stay on local machines or private infrastructure without a middleman like OpenAI or Anthropic reading it, either to train their models on the data or review it for "safety". Not to say safety reviews aren't warranted, but will every person granted access to this data be bound by benevolent purpose to keep their prying eyes out of your data? What about the AI models themselves?
  • Competition: a downloadable alternative limits how much closed providers can charge for equivalent intelligence, providing a net benefit to every consumer of these tokens, keeping the ecosystem sustainable.
Advertisement

NTIA’s own review found that widely available weights can lower barriers to entry, decentralize downstream innovation, and let users preserve confidentiality by avoiding third-party services. Those benefits grow as open models move closer to the frontier.

The U.S. can reject piracy, improve licensing, fund public datasets, and demand transparency from model builders. It can also preserve broad access to the resulting technology. Those goals fit together. They are not in conflict as some may have you believe.

Open models still have a bill

And remember, "open" doesn't mean "free." Ben Thompson’s COGS-based analysis of today's AI economics explains said economics better than most of the policy debate.

Open weights remove the downloader’s research and development bill. Running the model still costs money. Inference requires chips, memory, power, networking, orchestration, and engineers. A huge open model can be free to download and expensive to operate. If you'll recall, OpenAI tried to do this as a non-profit before the scaling laws demanded they turn into a for-profit to get enough investors to give them enough billions to fund their voracious R&D.

Kimi K3 makes the distinction obvious, following the same cost pattern we examined in our Kimi K2.6 deep dive. Moonshot lists the API at $3 per million uncached input tokens and $15 per million output tokens. That undercuts premium U.S. models on sticker price, but total task cost also depends on how many tokens the model needs, its speed, and the serving stack. Thompson’s key point is that the commodity is useful intelligence, not the raw token.

Early comparisons show why users want the option. Composio tested Kimi K3 and Claude Fable 5 on 14 agentic office tasks. Both passed nine. Fable ran roughly 2.5 times faster, while Kimi used about 40% fewer tokens. That is a tradeoff a customer should be allowed to evaluate, not one Washington should settle through market exclusion.

Ksenia Se noted that “open-weight” no longer means small enough for a laptop. Kimi K3’s 2.8 trillion parameters make ownership possible for well-funded organizations, inference companies, and governments, while ordinary users still need a hosted provider. This is why the ecosystem needs both frontier open models and actually small local models like Gemma 4 12B or the even smaller Bonsai 1-bit 8B model. We're getting there, but innovation takes time.

The cloud business survives that world. Moonshot paused new Kimi subscriptions after demand overwhelmed its capacity. Kevin Xu pointed out that Moonshot is backed by Alibaba and consumes large amounts of AliCloud capacity. Giving away weights can still drive paid inference, cloud usage, tools, support, and enterprise services for the datacenter companies and hyper-scalers that are fitting the bill for this boom. NVIDIA investors need not fret.

Alibaba is pursuing the same flywheel. Its Qwen team said Qwen3.8 Max Preview was improving toward an open-weight release, while Jun Song’s roundup captured how many Chinese labs are now competing on open models at once. Some individual performance claims remain vendor-reported, but the strategic direction is clear: China is using openness as distribution.

This might be one reason why the American government is concerned about open weight models coming out of China, but that doesn't mean that we should ban them. American companies, from NVIDIA to Microsoft and Amazon to neoclouds like Fireworks and Baseten and many others benefit from serving the compute for running these models, as do the American companies buying that compute for cheaper, more efficient AI.

American labs have plenty of ways to compete on cost. Andrew Curran and kimmonismus highlighted Google’s reported “Frozen v2” effort, a new plan which would hard-wire parts of Gemini into specialized silicon to improve tokens per watt. Better chips, sparse architectures, caching, quantization, and serving software all attack inference costs without banning alternatives.

Open weights threaten weak margins. Good businesses still have plenty to sell.

The business model frontier labs should offer

Personally, I am comfortable paying frontier prices for frontier work. The best model can save hours on a hard research problem, a complicated codebase, or an important decision. And OpenAI and Anthropic deserve to make money when they deliver that value.

But I can't pay frontier prices all the time for all the things, and neither can you. So if anyone serving or selling models in this industry have any hope for this ever becoming a sustainable ecosystem where everyone stops questioning the business models of these companies, they need to find a way to serve these models for free on device or as close to it as possible.

OpenAI is already closer to this bargain than many critics admit. It released gpt-oss-120b and gpt-oss-20b under Apache 2.0 for local or private deployment while continuing to sell frontier models and hosted products. Why have they not done this again? Surely GPT 5.6 could train a newer, more powerful open model to replace OSS 120B and compete with Google's Gemma models? The public pressure has been let off them, and as a result, they have failed to produce anything meaningful in that category, despite their own name demanding they do.

Separately, Anthropic’s public strategy emphasizes controlled deployment and escalating safeguards around advanced capabilities, with no open source strategy of any kind. In a way, Anthropic would benefit the most from releasing an open model so they could take some of the demand for their models off their strained servers.

Why don't both these companies release open variants of their older models? Users of AI rarely want to go back to lesser intelligence after experiencing the frontier. There is little threat in doing so, but much to benefit for the community if they did.

It's my opinion that openness can coexist with a premium frontier business, but the labs have to choose it.

The problem appears when every email summary, document search, draft, personal automation, and local workflow carries a permanent frontier toll. AI becomes infrastructure only when basic intelligence gets cheap enough to disappear into everyday products.

I believe a healthier model has three layers.

1. Sell an ownable version of the frontier model

Labs should offer a perpetual commercial license for downloadable weights. Customers would pay once for a defined model version, then own the right to run it indefinitely inside agreed terms.

A fully open-source license usually allows redistribution, which makes a one-time sale difficult to enforce. The practical version is dual licensing:

  • A research or community license with broad noncommercial access.
  • A paid commercial license for internal deployment, modification, and long-term use.
  • Clear restrictions on reselling the original weights, impersonating the provider, or deploying in prohibited high-risk contexts.

This gives labs a way to recover part of the training investment while giving customers something more durable than API access. If the recent Fable / Mythos saga taught us anything, it's how incredibly risky it is to build your business on top of any API you don't control yourself. This would be a necessary trade off to build the trust companies need to continue building on top of any single provider's infrastructure.

2. Make hosted inference the convenience business

On top of a one-time license sale, most customers will still probably pay the lab or its partners to run the model. Hosting bundles speed, uptime, security patches, observability, tools, memory, support, and hardware optimization. This would be the obvious freemium to premium onboarding flow. You sell the model for a one time fee, but your real product is hosting and serving it for the customer on their own private servers.

The weights can stay open and available while the best operating experience can stay behind a paywall. Linux did not destroy cloud computing. Open databases did not destroy managed databases. Ownership expands adoption, and managed services monetize the users who value convenience.

3. Release small models people can run forever

Frontier weights alone do not solve access when a model requires a data center. Every major lab should maintain a family of small, capable models designed for laptops, phones, and edge devices. Google has this absolutely 100% right.

Those models should be free for personal and small-business use. They should be private by default and useful for summarization, extraction, classification, drafting, search, and basic agents. And if you want to monetize them, you can sell devices with these models built into them; a tried and true business model that made Apple one of the most profitable companies in the world.

The sustainable open and local stack looks like this:

  • Free local intelligence for ordinary daily work.
  • Paid hosted open models for heavier, customizable workloads.
  • Premium closed frontier systems for the hardest tasks and newest capabilities.

That ladder serves users at every budget while preserving a profitable top end. Seems obvious to me. But y'know, no one has hired me to fix their broken business models yet, so... guess we'll have to wait a little longer.

What the U.S. should do instead of banning models

As you can see, I believe America needs an open-model strategy, not a foreign-model panic.

Taken together with Corey's ideas and common sense, there's a fairly straight forward answer here:

First, federal agencies should publish a standard evaluation regime for any advanced model, domestic or foreign. The regime should cover capability risk, dependency security, data flows, update mechanisms, telemetry, and deployment permissions. They're working on this.

Second, the government should fund American open-weight models as national infrastructure. Universities, national labs, startups, and public-interest groups need compute, datasets, and evaluation support that can produce serious alternatives to Kimi, Qwen, and GLM. Why didn't we do this with OpenAI and Anthropic three years ago?

Third, procurement rules should reward verifiability. Agencies handling sensitive data should prefer models they can inspect, isolate, freeze, and run inside controlled environments. A closed American API should not receive an automatic security halo.

Fourth, copyright policy should create cleaner inputs. Publicly funded, licensed training corpora and practical collective licensing systems would let labs build capable models without pretending every creator agreed to the current bargain. I have a lot of ideas on how people should get paid for their contributions to commercially-used openAI models that everyone would benefit from, in case anyone's interested.

Fifth, restrictions should attach to evidence and deployment risk. A model that fails a concrete security test should face mitigation requirements or exclusion from sensitive systems. A model that passes should compete.

Our take

A ban basically treats America’s lack of a frontier open model as a reason to block everyone else’s. That protects investment assumptions rather than technological leadership. The labs chose a capital-intensive race, and their investors need returns. That need does not justify removing lower-cost competitors from the market that benefits the entire ecosystem and keeps it sustainable and healthy.

OpenAI and Anthropic can remain valuable companies in an open ecosystem. Frontier intelligence, trusted hosting, enterprise support, integrated tools, safety systems, and fast access to new capabilities all command real money. Open weights simply force those companies to keep earning the premium while providing a genuine public good.

They also keep AI usable for people who cannot pay frontier prices for every task. Pay for Fable when Fable earns it. Run Kimi, Qwen, or GLM when they fit. Keep a smaller model on your own device for work that should remain private, local, and available forever. This is the common sense way to use AI, and all AI companies should accommodate by serving AI the way people want it to be served.

Open models are the floor that keeps frontier prices honest. Removing that floor would make AI more expensive and concentrate control amongst a powerful few. This is the game they are all playing, which is why they tried to raise ungodly amounts of capital in a short timespan to try and beat each other to the "rings of power." Is it the public's problem that they chose to go as fast as they possibly could and now it's incredibly expensive for them to recoup their investment?

Imagine a world where the big labs took their time, focused on smaller algorithmic breakthroughs and genuine novel architectures, and built AI that was more sustainable to serve from the jump. They might have even stayed non-profits. Imagine that. The most interesting sleight of hand of the whole AI boom was this idea that scale was all you need. In my opinion, scale is the reason we put the cart before the horse, and ultimately it could be the reason these companies financially collapse, if they do so one day later down the line.

There's no denying we've learned a lot from scale. But the open weights community in China showed how much there was to learn from being constrained. Ultimately, it's my belief that the best model will be the one that can do everything you need locally on device, without ever having to go off to the cloud. Of course, that's not how human brains work, and we want the best we can possibly get, so there will always be a drive for more intelligence in the cloud. But there will come a time when most people will be happy with a local model that can do everything today's models can, and maybe a little bit more. And we should work as hard as we can to get to the point where AI is truly in control of the people. Available on demand, on device, whenever it's needed, wherever you are, with no middlemen; entirely yours to control and do with what you will. This should be the goal of all AI research. Empowering people.

Constraints are good. Honoring and challenging and ultimately surpassing and overcoming constraints are what get us this.

Banning open weights model will not get us there.

It would also weaken researchers and defenders while American builders compete under rules the rest of the world does not share.

I do wonder if anyone who reads this will try to answer this call: Can an American lab prove that paid ownership, hosted inference, and free local models can finance frontier research before China defines the open layer by default?

Then again, in the age of AI, I wonder more deeply: does anyone read anything at all anymore?

Grant Harvey

Grant Harvey is the Lead Writer of The Neuron, where he continues to lead the publication's daily coverage of AI news, tools, and trends.

The Neuron Logo

Don't fall behind on AI. Get the AI trends & tools you need to know. Join 700,000+ professionals from top companies like Microsoft, Apple, Salesforce and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.