US AI policy is suffering from whiplash. It veers between the temptation of imposing strong export controls and the fear that protectionism will only help China catch up. 

The administration banned allies from obtaining access to Anthropic’s Mythos and Fable 5, only to backtrack and open access. It abandoned early ideas of mandatory government checks, only to backtrack again and impose a voluntary framework under which AI labs would give authorities access to frontier models 30 days before their release.  

The release of Moonshot AI’s Kimi K3 highlights the confusion. The model costs only half of OpenAI’s GPT-5.6 Sol, yet its capabilities are not far behind. Not surprisingly, startups in both the US and Europe are shifting to Chinese alternatives such as DeepSeek, Qwen, and now K3. Open-weight models allow companies to freely download the parameters learned in training, build on top of them, and then run the model in their own cloud.

Washington is divided on how to respond.

One camp supports designating Chinese models as a national security risk and restricting their use by American companies. Another believes that protectionism would prove counterproductive and exclusively benefit expensive proprietary models developed by US leaders like OpenAI and Anthropic. 

The case for banning Chinese open models rests on two claims: that they were built on stolen American technology, and that the models carry national security risks. White House Office of Science and Technology Director Michael Kratsios alleges that K3 trained on Anthropic’s models and export-controlled NVIDIA chips. While so-called “distillation” training is standard industry practice, Treasury Secretary Scott Bessent has hinted at possible sanctions on Chinese companies that practice it. 

The second argument against the Chinese models concerns their safety. Anthropic CEO Dario Amodei has warned that open-weight models pose unique risks because developers cannot revoke access, update safety guardrails, or prevent misuse once released. The UK’s AI Security Institute found it easy to bypass cybersecurity safeguards on Chinese open models. 

Get the Latest
Sign up to receive regular Bandwidth emails and stay informed about CEPA's work.

Dean Ball, a former White House staffer who drafted the US AI Action Plan and now serves as Head of Strategic Futures at OpenAI, has advocated for government guidance and recommendations that add regulatory risk to using Chinese open-weight models.

Most of the American AI industry rejects these arguments. Restricting access to open-weight models would only entrench the power of leading labs at the expense of smaller companies, former White House AI adviser David Sacks has asserted. Nearly 200 startups sent a letter to the administration arguing that Chinese open-weight models have become a critical resource for smaller developers that cannot absorb the cost of frontier models. 

“There’ll be hundreds of companies that instantly die,” said Suhail Doshi of the startup Particle. AI powerhouses NVIDIA, Meta, and Microsoft agree, cautioning that a ban would undermine competition and innovation.

Critics also reject the open is unsafe argument. Closed AI models are not inherently safer than open ones, NVIDIA, Meta, Microsoft, Google, OpenAI, AMD, Hugging Face, and more than three dozen other companies wrote in a recent public letter. They can be breached, misused, or fail in ways outsiders cannot detect. Concentrating advanced capability behind a handful of closed systems creates single points of failure, rather than eliminating risk. 

Although no side can yet claim total victory, this anti-protectionist camp seems to be winning. Commerce Secretary Howard Lutnick is reportedly considering measures to encourage US labs to release open-source models. And the administration’s new pre-release framework applies only to closed models. 

But winning the open-source debate has not made American AI policy more coherent.

American AI labs have built their business models around proprietary subscription models, and their commercial advantage relies not only on performance but on customers believing access will remain reliable. This has left US labs facing additional regulatory burdens while competing against cheaper rivals, even as allies remain uncertain about continued access.

The new framework’s secrecy makes this a geopolitical problem. For allies that cannot see the benchmarks against which the models will be tested, they are left without knowing what the safety criteria is, and cannot rule out that those criteria will change at the administration’s discretion. Nor does the US government necessarily have the expertise to run these evaluations alone, as the work of third parties like the UK AI Security Institute has shown.

The question for Washington is no longer how to restrict China’s models, but how to restore confidence in American AI. Should AI governance prioritize denying capabilities to China or cultivating a competitive AI industry? Those two goals are becoming difficult to pursue simultaneously.

Marta Granados Hernández is a US Google Public Policy Fellow at the Center for European Policy Analysis and a master’s candidate at Georgetown University’s Master of Science in Foreign Service program, concentrating in Science, Technology, and International Affairs. 

Ian Hoerr was an intern for the CEPA Tech Policy Program in the Summer of 2026. 

Bandwidth is CEPA’s online journal dedicated to advancing transatlantic cooperation on tech policy. All opinions expressed on Bandwidth are those of the author alone and may not represent those of the institutions they represent or the Center for European Policy Analysis. CEPA maintains a strict intellectual independence policy across all its projects and publications.

Tech 2030

A Roadmap for Europe-US Tech Cooperation

Learn More
Read More From Bandwidth
CEPA’s online journal dedicated to advancing transatlantic cooperation on tech policy.
Read More