# The U.S. wants to contain China’s AI. Silicon Valley keeps using it

> Source: <https://restofworld.org/2026/china-siliconvalley-ai-moonshot-kimi/?utm_source=rss&utm_medium=rss&utm_campaign=feeds>
> Published: 2026-07-22 10:00:00+00:00

When Anthropic’s chief national security officer and former Biden administration export control architect Tarun Chhabra [recently highlighted](https://x.com/vince_chow1/status/2077446050269331577) model distillation as an emerging national security concern, one detail stood out. Chhabra identified Chinese AI developer Zhipu among the companies that have allegedly distilled capabilities from frontier American models. The warning fits neatly into Washington’s narrative: Chinese firms are racing to close the AI gap by leveraging innovations pioneered by Silicon Valley.

But only hours after Chhabra’s comments, that narrative became considerably more complicated. Mira Murati’s Thinking Machines — which raised $2 billion on the strength of her reputation as OpenAI’s former chief technology officer — [revealed](https://www.ft.com/content/ef486929-d2c2-480b-8b00-9cb98bda6acf?syn-25a6b1a6=1) that its first foundation model was built in part using Chinese models. Inkling’s architecture drew on DeepSeek-V3, and its post-training process incorporated synthetic data generated by Moonshot AI’s Kimi K2.5. This is how the open-weight/source model world works: One company [builds on top](https://restofworld.org/2026/tiezhen-wang-china-us-open-source-ai/) of another’s innovation.

The juxtaposition is striking. One of America’s leading frontier companies is warning that Chinese laboratories are learning from U.S. models at precisely the moment one of Silicon Valley’s newest flagship ventures openly acknowledges learning from Chinese ones. That apparent contradiction says far more about the state of frontier AI than either announcement.

The word “distillation” has rapidly become one of the most politically charged terms in AI and now in geopolitics, driven by [accusations](https://restofworld.org/2026/openai-deepseek-distillation-dispute-us-china/) from leading U.S. closed-source model developers that Chinese companies are able to stay close to the frontier by leveraging this practice. Increasingly, it is presented almost interchangeably with intellectual property theft. But distillation is neither new nor particularly exotic. It has been part of machine learning for more than a decade. A larger “teacher” model generates outputs that are then used to train a smaller “student” model capable of reproducing much of the original model’s behavior at a fraction of the computational cost.

Today, however, the technique has expanded well beyond simply compressing large models. Synthetic data generated by one model routinely becomes [training material](https://www.wired.com/story/elon-musk-distill-openai-models-partly-xai/) for another. Frontier laboratories increasingly rely on teacher models to improve reasoning, coding, multilingual performance, and post-training alignment. In many cases, the most valuable training data is no longer collected from humans at all — it is generated by other AI systems. This practice is not confined to China.

Indeed, almost every leading laboratory now employs some version of teacher-student training. OpenAI, [Anthropic](https://alignment.anthropic.com/2025/modifying-beliefs-via-sdf/), Google DeepMind, Meta, Alibaba, Tencent, Moonshot, DeepSeek, and Zhipu all publish research describing synthetic data generation, reasoning distillation or related techniques. The competitive question now is not *whether* laboratories use distillation, but whose models become the teachers.

As frontier models become more capable, the value of their outputs has increased dramatically. If billions of dollars invested in training can be even partially replicated through extensive querying of commercial APIs, the incentive to extract those capabilities naturally grows. That is why OpenAI and Anthropic have steadily tightened API protections, implemented behavioral monitoring, limited automated querying, and invested in techniques designed to [detect large-scale output harvesting](https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks).

The recent headlines demonstrate how difficult it has become to draw clean technological boundaries. While American firms understandably seek to prevent unauthorized extraction of their frontier capabilities, they are themselves [more willing](https://restofworld.org/2026/when-americans-choose-chinese-ai/) to incorporate advances from China’s rapidly improving open-weight ecosystem. Thinking Machines acknowledged incorporating Chinese models into its own development pipeline.

This should not be surprising. Chinese open-weight models have become extraordinarily competitive over the past year. DeepSeek, Moonshot, Alibaba’s Qwen family, and Tencent’s Hunyuan models are now regularly benchmarked alongside Claude, GPT, and Gemini by researchers. For engineers building new systems, as opposed to government regulators, the nationality of a model increasingly matters less than its performance, architecture, and licensing terms.

That reality presents an uncomfortable challenge for policymakers. Much of the current debate surrounding export controls and frontier AI governance continues to assume that innovation flows largely in one direction — from the U.S. outward. Increasingly, however, the flow is reciprocal. U.S. AI laboratories lead in many frontier capabilities, but as the [DeepSeek Moment](https://restofworld.org/2025/deepseek-china-r2-ai-model-us-rivalry/) made clear, Chinese laboratories are now generating ideas, architectures, and open-weight models that are being incorporated into global AI development, including in Silicon Valley firms.

## Policy paradox

The policy implications of this dynamic extend beyond commercial competition. If frontier AI increasingly advances through iterative improvement across a globally [interconnected research ecosystem](https://restofworld.org/2026/china-us-what-ai-race/), governments may find it far more difficult to construct durable technological barriers. Export controls remain highly effective at constraining access to advanced semiconductors and manufacturing equipment. They are bound to be much less effective at limiting the diffusion of published research, open-weight models, synthetic data sets, and widely adopted engineering techniques.

That is ultimately the deeper significance of the recent announcements. The future of frontier AI may depend less on preventing knowledge from crossing borders than on remaining the most attractive place to create the next generation of ideas. Distillation has become a symbol of that broader transition — not because it replaces innovation, but because it illustrates how innovation itself has become increasingly global.

Yet another recent development underscores how rapidly Chinese frontier models are becoming embedded in the global AI ecosystem. After a lengthy regulatory review, Apple [received approval](https://www.cac.gov.cn/2026-07/15/c_1785861480767004.htm) from the Cyberspace Administration of China to launch Apple Intelligence in China using Alibaba’s Qwen models and Baidu’s Ernie models as core components of its China-specific AI stack. The arrangement reflects both Beijing’s insistence that generative AI deployed in China rely on approved domestic models for content compliance, and Apple’s recognition that Chinese foundation models have become sufficiently capable for deployment in one of its [most important markets](https://restofworld.org/2025/apple-china-dependence-tariffs-india-shift/).

Apple has effectively acknowledged that leading Chinese models now form part of the world’s commercial AI infrastructure. The importance of this development cannot be understated. Both Alibaba and Baidu have been [designated](https://media.defense.gov/2026/Jun/08/2003945537/-1/-1/1/ENTITIES-IDENTIFIED-AS-CHINESE-MILITARY-COMPANIES-OPERATING-IN-THE-UNITED-STATES-IN-ACCORDANCE-WITH-SECTION-1260H.PDF) by the U.S. Department of Defense as “Chinese military affiliated companies.” Still, Apple is using models from these companies, and Chinese users of iPhones will be travelling to the U.S. with devices sporting models from the designated companies.

The significance extends well [beyond smartphones](https://restofworld.org/2026/silicon-valley-china-strategy-apple-tesla-nvidia/). Every major device platform now effectively requires a China-specific AI stack built around locally approved foundation models. That means Qwen, Ernie, Doubao, Hunyuan, and other Chinese frontier models are no longer confined to domestic cloud services — they are becoming default AI engines for hundreds of millions of devices sold in the world’s largest smartphone market, where they will be crisscrossing borders.

As Apple, Thinking Machines, and other Western companies have acknowledged in different ways, Chinese frontier models are no longer simply competitors to evaluate; they are becoming core infrastructure that global technology companies are building on.

This creates a policy paradox. Washington continues to tighten access to the most capable closed frontier models from companies such as Anthropic and OpenAI through API protections, export controls and, increasingly, discussions around licensing and frontier governance. At the same time, policymakers are becoming concerned about the capabilities of Chinese frontier models — particularly systems such as Zhipu’s recently released GLM-5.2 — that are distributed far more openly and remain available to developers around the world with few practical restrictions.

In other words, the U.S. is steadily erecting guardrails around its own frontier while simultaneously confronting the reality that another frontier is emerging outside its regulatory reach. That may prove to be one of the defining governance challenges of the next phase of the AI race: not simply protecting American models from distillation, but adapting to a world in which multiple global frontiers coexist, compete, and learn from one another.
