When Beijing entrepreneur Yang Zhilin released Kimi K3 last month, it matched the capabilities of Anthropic’s most advanced system. And he gave it away for free.

Zhilin is the talent that the American scientific enterprise was built to retain: a Tsinghua-trained engineer who earned a PhD in computer science at Carnegie Mellon and interned at Google Brain and Meta. But he turned down a job at Apple and went home. In Beijing, he founded Moonshot AI. Its Kimi K3, a 2.8-trillion-parameter open-weight model, was reportedly the first time an open model had pulled ahead of proprietary rivals on a major coding benchmark.

Washington’s reaction was to recast Moonshot AI’s technical achievement as theft, accusing the company of building a “sophisticated internal platform” on US intellectual property. A year and a half earlier, Chinese hedge fund manager Liang Wenfeng released DeepSeek-R1, a language model that could match the reasoning ability of American rivals. He, too, gave it away for free.

The strategy of restricting China has shown its limits.

If Washington is serious about outcompeting Beijing rather than merely delaying it, going it alone won’t be enough. Restricting chip sales buys American companies a handful of years of lead time. In the long term, export controls will not indefinitely prevent China from developing its own advanced semiconductor manufacturing, given the country’s resources and talent pool.

A similar logic applies to the concern that authoritarian governments might build AI models more powerful than America’s and use them to entrench permanent military superiority or deepen domestic repression. It is a real risk, and not one to dismiss. But preventing China from reaching advanced AI capability is likely to prove ephemeral. Beijing will get there sooner or later, probably within a handful of years.

DeepSeek’s Liang earned both his degrees at Zhejiang University, and reportedly made a point of building the lab’s research team out of homegrown talent. Whatever mix of distillation, novel architecture, and sheer engineering expertise actually went into K3 and R1, the fact that two Chinese frontier AI labs are succeeding demonstrates that Chinese researchers are simply talented.

American strategy has to reckon with a hard truth: AI is a tool that both authoritarian and democratic governments will possess. The right response is not to silo access to it. That will simply convince authoritarian states to build the frontier without American input. The US must instead push to institute rules of the road that apply regardless of who is in power. This includes verification regimes, testing standards, crisis hotlines between labs and governments, pre-agreed red lines on catastrophic capabilities, and incident reporting channels for the rare cases where both sides have identical incentives to know immediately.

None of this requires trusting Beijing. It only requires that both sides recognize that a catastrophic AI failure doesn’t respect borders, which gives even asymmetric rivals a shared stake in not letting one happen.

Get the Latest
Sign up to receive regular Bandwidth emails and stay informed about CEPA's work.

In what may be the most unusual show of unity Silicon Valley has produced in years, NVIDIA, Meta, Microsoft, Dell, IBM, Hugging Face, and more than 20 other companies (many of them bitter rivals) published a joint letter rejecting a ban on open weights. OpenAI added its signature days later.

The tech companies rejected the charge that Kimi is based on stolen material. Policymakers should not conflate distillation — described in the letter as “the practice of using one model’s outputs to help train or improve another” — with unlawful misappropriation, which should be addressed through “targeted legal and commercial frameworks,” rather than sweeping restrictions on a technique every major lab uses.

With Chinese and American models now closing in on parity, compute is the deciding factor, and it’s a fight America can still win, for now. Huawei, China’s telecom and chip company, remains capped at a fraction of the advanced chips that US fabs can produce. Washington should press its advantage in fabs, power, and grid capacity. Whoever commands the most compute will very likely determine who wins the AI race.

The Silicon Valley coalition also rejected a ban on open weights. Closed AI models, the tech giants argued, are not inherently safer. They can be breached, misused, or fail in ways outsiders cannot detect. Concentrating advanced capability behind a handful of closed systems creates single points of failure, rather than eliminating risk.

Open models, by contrast, let a broad community of researchers examine behavior, find vulnerabilities, and build safeguards in public. “Just as open-source software demonstrated that transparency can be more secure than obscurity,” the letter argued, “AI safety may depend on giving more people the ability to test and strengthen the models on which society relies.”

Three distinct positions are now on the table:

  1. The White House’s reported proposal to ban Chinese open-weights models outright, aimed at protecting American firms from being out-competed.
  2. AI company Anthropic opposes the White House ban but wants industrial-scale training curtailed and mandatory pre-release safety testing applied to every sufficiently capable model, regardless of where it was built or whether its weights are open.
  3. The rest of the industry wants distillation left alone and treats openness itself as the safety solution.

Of the three, only the ban is genuinely indefensible. The other two aren’t far apart. Both are steering Washington away from a knee-jerk ban — Anthropic by insisting that nuance matters, the rest of Silicon Valley by prioritizing openness and treating jailbreak mitigation as secondary.

Beijing has as much invested in functioning supply chains, and in its own Party’s survival and power. A government with that much at stake is a poor candidate for deliberately unleashing a catastrophic AI pathogen it cannot contain. If a nightmare scenario is catastrophic enough to justify real caution, it is also catastrophic enough that the US and China cannot responsibly try to solve it unilaterally.

The US cannot continue to restrict its own labs from releasing competitive open models while pretending American competitiveness collapsed because of distillation. The US cannot out-compete China by restricting it alone. It has to out-build it — investing aggressively in talent, compute, and infrastructure.

Elly Rostoum is a Senior Resident Fellow with the Center for European Policy Analysis (CEPA).  

Bandwidth is CEPA’s online journal dedicated to advancing transatlantic cooperation on tech policy. All opinions expressed on Bandwidth are those of the author alone and may not represent those of the institutions they represent or the Center for European Policy Analysis. CEPA maintains a strict intellectual independence policy across all its projects and publications.

Tech 2030

A Roadmap for Europe-US Tech Cooperation

Learn More
Read More From Bandwidth
CEPA’s online journal dedicated to advancing transatlantic cooperation on tech policy.
Read More