GeopoliticsMarket noteThursday 1 October 2026, 22:48
US AI labs are making the case against cheap Chinese models
OpenAI accused Moonshot of copying its models, and Anthropic warned that a free Chinese model can build working exploits. Both say they oppose a ban. Their rivals sell for far less.
By The Notebook Desk
In two days this week, America’s two leading AI labs published warnings about Chinese rivals. On Wednesday OpenAI said that people linked to Moonshot AI, the maker of the Kimi models, ran a campaign to extract the hidden reasoning of its models. The activity peaked on 24 and 25 July with 16,000 requests from more than 4,000 users, and related activity spread across more than 15,000 users, The Next Web reported. OpenAI called it “adversarial distillation”: using one model’s outputs to train another without permission.
A day earlier, Anthropic said that GLM-5.3, a model from Zhipu AI that anyone can download, comes close to its own Claude Mythos Preview at building exploits for software flaws. On one test it produced a working exploit in 50 of 410 attempts, against 56 for Mythos Preview, The Decoder reported. Its safeguards were easy to remove.
Both warnings concern safety and security. Both also concern rivals that sell similar models for a fraction of the price.
The price gap
Chinese models have won a large share of one closely watched market in a year. The share of tokens, the units in which AI work is billed, that US companies ran on Chinese models through OpenRouter, a platform that routes requests to many models, has been above 30% every week since 8 February and has reached 46%, CNBC reported in July. In the first half of 2025 it averaged 4.5%.
Price explains it. Chinese open models can be “60% to 90% cheaper” than the leading Anthropic and OpenAI models, Justin Summerville of OpenRouter told CNBC. Kyle Chan of Brookings put them “six to nine months” behind the best American models. For many tasks, that is good enough.
Washington noticed. In July the Trump administration was reported to be weighing a ban on Chinese AI models, and Scott Bessent, the Treasury secretary, said officials would examine Chinese open models for intellectual property theft and could sanction the companies behind them, Tom’s Hardware reported. Two House committees are investigating Airbnb and Anysphere, the maker of the Cursor coding tool, over their use of Chinese models, Tech Times reported. Zhipu has been on the Commerce Department’s Entity List since January 2025.
Who says what
On 24 July Nvidia and 24 other companies signed a letter, “Open Weights and American AI Leadership”, that urged Washington not to restrict models that can be downloaded. Within a day it had 50 signatories. OpenAI and Google signed. Anthropic and Amazon did not, AI Weekly noted.
Three days later Dario Amodei, Anthropic’s chief executive, set out his position. “Anthropic has never advocated for a ban on open-weights models,” he wrote. A ban on their use by American businesses “would protect US AI companies from competition, but that has never been my goal.” He called instead for three things: no sales of powerful chips to China, action against “industrial-scale distillation”, and mandatory safety tests for every capable model, open or closed.
OpenAI says the same of this week’s report. “Our concern is about violation of our terms of service, not open models or legitimate distillation,” Caroline Zier of OpenAI told Bloomberg. David Sacks, Trump’s former AI adviser, does not accept that. He has called such reports a push to get the US to ban rival open models, Bloomberg reported.
A ban by another name?
Neither lab is asking for a ban. But the evidence they publish is the evidence a ban would need, and the rules they do ask for would fall hardest on cheap Chinese models. Mandatory testing costs money and time. A crackdown on distillation targets the method that lets Chinese labs get close to the frontier with fewer chips. Even The Decoder, which reported Anthropic’s findings, noted that its call for government testing “invites suspicion of regulatory capture”, where rules end up protecting established firms.
There are limits to what any rule can do. Weights that are already public cannot be recalled, and unlocked versions of GLM-5.3 appeared within days of its launch, Anthropic said. A ban could reach only the legitimate US businesses that use these models, which are the customers the labs compete for. As Amodei put it, open models “don’t cost anything besides the compute needed to run them.”
What to watch
Whether Washington moves from inquiries to rules: sanctions from the Treasury, a ban on government use, or mandatory testing. Each would raise the cost of Chinese models for American buyers. The next Chinese release will be the test. If it again comes within months of the American frontier at a fraction of the price, the pressure on prices, and on Washington, will grow.
Disclosure
This is analysis and opinion, not investment advice.