China Weighs Locking Down Qwen and Doubao Just as the World Adopted Them China's Ministry of Commerce met with Alibaba, ByteDance and Z.ai on July 7 to discuss restricting foreign access to AI models Qwen, Doubao and GLM-5.2, which now account for a third of global AI usage and half of Silicon Valley startup traffic, according to Reuters. The proposed tiered system would require basic models to file, more capable ones to undergo security review, and frontier systems could be barred from public release or locked to domestic use, though no decision has been made and rules may only apply to future models. Beijing is discussing whether to wall off overseas access to Qwen, Doubao and GLM-5.2, the same open-weight Chinese models that just captured a third of global AI usage and half the traffic running through Silicon Valley's own startups. China's Ministry of Commerce met with Alibaba, ByteDance and the startup Z.ai on July 7 to discuss restricting foreign access to the country's most advanced AI models, according to Reuters, which cited three sources familiar with the talks. The proposal on the table is a tiered system. Basic open-source tools would need only a simple filing. More capable models would face a formal security review. The most sensitive frontier systems could be barred from public release altogether, or locked to domestic use only. Nothing has been decided. Reuters reported that the rules, if adopted, may apply only to future models, not the ones already downloaded millions of times. MOFCOM, the National Development and Reform Commission, Alibaba, ByteDance and Z.ai all declined to comment. The timing is what makes this strange. Alibaba's Qwen has built the largest open-model ecosystem on Hugging Face, with more than 113,000 derivative models built on top of it, enough to surpass Meta's Llama in cumulative downloads. ByteDance's Doubao passed 100 million daily active users in December, according to company disclosures, and now handles 120 trillion daily token calls. Z.ai's GLM-5.2 has drawn attention in Silicon Valley for matching close to US-level performance at a fraction of the cost. These are not lab curiosities. They are infrastructure. The talks reportedly went beyond access controls. Officials floated classifying the leak or theft of proprietary Chinese AI as a national security violation, and discussed limiting which investors are allowed to fund domestic AI startups at all. Put together, the picture is a government that spent two years building an open-weight strategy to outflank US export controls, and is now nervous about what that strategy exported along with it. That nervousness has a direct American mirror. On June 12, the US Commerce Department's Bureau of Industry and Security ordered Anthropic to suspend foreign access to its Fable 5 and Mythos 5 models, after Amazon researchers reportedly found jailbreak methods that could let users extract cyber-offensive capabilities from the systems. Anthropic couldn't reliably screen users by nationality, so it disabled both models worldwide. The Trump administration reversed course on June 27, restoring access after Anthropic agreed to additional safeguards, according to Axios. China is now weighing the same tool Washington just used and then walked back, for the same underlying fear: that a powerful model in the wrong hands is a security problem no matter which government issued the passport. Frankly, the harder problem for Beijing isn't the models still on the drawing board. It's the ones already loose. Chinese models accounted for roughly 63% of US usage on OpenRouter, the AI model marketplace, according to Gurufocus reporting on recent traffic data, up from near zero a year earlier. US lawmakers have opened investigations into Airbnb and Anysphere, the maker of the coding tool Cursor, over their reliance on Chinese models for cost and speed. You cannot claw back weights that are already sitting on a hard drive in San Francisco. That's the trap. A tiered filing-and-review regime works cleanly on the next release. It does nothing about Qwen3, Doubao or GLM-5.2 as they exist today, already forked, fine-tuned and running in production at companies that never asked Beijing's permission in the first place. If China locks the door on future models while the current generation keeps propagating through Hugging Face and OpenRouter, the restriction becomes symbolic faster than officials might like. There's also a quieter irony. Open-weight releases were China's answer to US chip export controls, a way to win adoption and influence without needing the most advanced silicon. Now the same openness that made Qwen and Doubao globally dominant is the thing Beijing is being asked to rein in. Washington spent June discovering that disabling a model for Also read: Anthropic drops plan to charge extra for Fable 5 as Chinese rivals close in https://startupfortune.com/anthropic-drops-plan-to-charge-extra-for-fable-5-as-chinese-rivals-close-in/ • South Korea's Record Exports Show How Deep Its AI Chip Bet Really Goes https://startupfortune.com/south-koreas-record-exports-show-how-deep-its-ai-chip-bet-really-goes/ • A federal judge just approved Anthropic's $1.5 billion settlement with authors https://startupfortune.com/a-federal-judge-just-approved-anthropics-15-billion-settlement-with-authors/