- U.S. officials appear more likely to treat individual Chinese models as national-security cases than impose a blanket open-weight ban, according to The New York Times, which cited four people familiar with the discussions. [1] - No official target list, capability threshold or proposed rule has been published. Moonshot AI’s Kimi K3 is central to the current debate, while congressional investigators have separately scrutinized DeepSeek, Alibaba, Moonshot and MiniMax. [2][3][4] - Commerce’s Entity List could restrict named developers’ access to U.S. technology, but it would not directly prohibit Americans from running model files already downloaded. Broader transaction restrictions would require a separate legal basis. [5][6] - The administration’s existing policies support open models and reject mandatory model-release licensing, complicating any attempt to regulate open weights as a category. [7][8] - A July 24 industry statement, whose current signatory list includes 50 companies and organizations, urges targeted action against unlawful extraction rather than broad restrictions on open models.
[9] The Trump administration is leaning toward restrictions on selected Chinese artificial-intelligence models or developers rather than a blanket prohibition on foreign open-weight systems, The New York Times reported Saturday, citing four people with knowledge of the discussions.[1]
The reported approach could let Washington act against companies it accuses of intellectual-property theft, cybersecurity failures or links to the Chinese state while preserving access to other downloadable models. But as of July 26, neither the White House nor the Commerce Department had published a rule, executive action or target list implementing that policy. Independent reporting instead describes an unresolved debate between White House officials seeking stronger controls and Commerce officials who view broad restrictions as difficult to administer.[2][3]
The government has not defined a target #
The immediate debate has centered on Moonshot AI’s Kimi K3, whose price and performance have intensified concern in Washington about China’s progress in open-weight AI. The White House has accused Moonshot of using distillation to copy capabilities from Anthropic’s Claude Fable model, but it has not released technical evidence establishing that claim. OpenAI co-founder Greg Brockman said last week that it was too early to determine whether recent Chinese models had been distilled from OpenAI systems.[10]
Open-weight models make their trained parameters available for download, allowing users to run and usually modify them on independent infrastructure. The term does not necessarily mean fully open source: developers may withhold training data, training code and other materials needed to reproduce the model.[11]
No official document identifies which systems would face restrictions. An April congressional investigation named AI products or services developed by DeepSeek, Alibaba, Moonshot AI and MiniMax, but the inquiry neither established a government target list nor imposed restrictions. The committees cited alleged distillation, data-security risks, censorship and dependence on technology developed under Chinese jurisdiction.[4]
The administration’s clearest published position is an April 23 memorandum from White House science adviser Michael Kratsios. It says the government has information indicating that foreign entities, principally in China, used proxy accounts and jailbreaking techniques in industrial-scale campaigns to extract capabilities from U.S. frontier models. The memorandum directs agencies to share threat information and explore accountability measures, while also describing legitimate distillation as a vital development technique and promising support for an open AI ecosystem.[7]
Those assertions remain government allegations. The administration has not published model-specific cybersecurity tests, evidence of a backdoor in Kimi K3 or a technical standard that would separate a restricted Chinese model from one that remains permitted. The 2025 AI Action Plan directs the Commerce Department’s AI standards center to evaluate Chinese frontier models for censorship and alignment with Chinese Communist Party positions, but no relevant assessment has accompanied the reported deliberations.[8]
Existing authorities have different—and limited—effects #
The Commerce Department could add selected Chinese developers to the Entity List, as Axios reported it previously considered doing. A listing would generally require licenses before U.S. persons export, reexport or transfer covered American commodities, software or technology to the named entity. It could restrict access to chips, cloud infrastructure and development tools, but it would not by itself ban Americans from possessing or running Chinese model weights already in circulation.[2][5]
Commerce also administers the Information and Communications Technology and Services program under Executive Order 13873. That program permits the department to prohibit or mitigate certain transactions involving technology supplied by a foreign adversary when officials find an unacceptable national-security, infrastructure or public-safety risk. The authority is potentially broader than the Entity List, although the government has not said that a model download, cloud-hosting arrangement or domestic deployment of open weights would qualify for action under it.[6]
Treasury sanctions, procurement exclusions and government security advisories offer other forms of pressure. Treasury Secretary Scott Bessent has publicly raised sanctions as a possible response to covert distillation, according to WIRED. Procurement rules or advisories could cause agencies, contractors, cloud marketplaces and regulated companies to avoid a named model without prohibiting every private use.[3]
Open weights make a comprehensive technical ban difficult. Once files have been downloaded and mirrored across repositories, action against the original developer or hosting platform cannot recall every copy. Restrictions would be more effective at regulated choke points—commercial cloud services, government contracts and access to U.S. infrastructure—than against an individual running an existing copy locally.
The administration’s June 2 cyber executive order adds an important boundary. It creates a voluntary process for government evaluation of highly cyber-capable frontier models and explicitly says the order does not authorize mandatory licensing, preclearance or permits for developing, publishing or distributing new models. Any China-specific prohibition would therefore need to rely on other national-security, trade or sanctions authorities rather than that evaluation framework.[12]
OpenAI straddles the industry divide #
A July 24 statement hosted by Microsoft urges policymakers to avoid premature restrictions on open models and to address unlawful extraction through targeted legal and commercial frameworks. The page’s current list contains 50 signatories, including OpenAI, Google, Nvidia, Microsoft, Meta, AMD, Hugging Face, IBM, Palantir and Y Combinator. Anthropic is not listed.[9]
The signatory list expanded after publication, which explains earlier reports describing 25 initial backers and listing OpenAI and Google as absent. The revised page supports the companies’ opposition to broad restrictions, but it does not establish that every signatory opposes action against a specific Chinese developer accused of illegal conduct.
OpenAI separately advocates a federal framework in which the Commerce Department’s Center for AI Standards and Innovation evaluates the most capable frontier models. Axios has reported that OpenAI and Anthropic are aligned in warning policymakers about risks from powerful Chinese open-weight systems, even though the companies differ in their public participation in the open-weights letter.[13][14]
Roughly 200 smaller technology companies have also urged the administration not to impose an outright ban, according to WIRED. Startups and researchers often favor open weights because they can customize and self-host models without paying a closed-model provider for each query.[14]
A case-by-case policy would be less disruptive than banning an entire model category, but its effect would depend on definitions the administration has not provided: whether a target is selected because of its developer, training provenance, cyber capability, safeguards, government ties or demonstrated conduct. Until those criteria and the legal instrument are public, businesses using Chinese open weights face policy risk rather than a defined prohibition.
Companies mentioned #
Further sources #
[[1] The New York Times, “Silicon Valley Splits Over Closing the Borders to Chinese … ↗](https://www.nytimes.com/2026/07/25/technology/open-source-silicon-valley-china.html)
[[2] Axios, “The secret Trump administration battle to fight Chinese AI,” July 20, 2… ↗](https://www.axios.com/2026/07/20/ai-us-china-open-source-kimi)
[[3] WIRED, “The White House Is Trying to Figure Out What to Do About Chinese AI,” J… ↗](https://www.wired.com/story/the-white-house-is-trying-to-figure-out-what-to-do-about-chinese-ai/)
[4] House Committee on Homeland Security, joint investigation into national-securit… ↗
[[5] U.S. Bureau of Industry and Security, Export Administration Regulations Part 73… ↗](https://www.bis.gov/regulations/ear/734)
[[6] U.S. Department of Commerce, Information and Communications Technology and Serv… ↗](https://www.commerce.gov/issues/ict-supply-chain)+8 more
The stories that matter, in one email. Free — unsubscribe anytime.