2 Sources
[1]
What is the risk of using Chinese open AI models like Kimi K3?
The writer is a senior fellow at New America and the Institute for America, China, and the Future of Global Affairs at Johns Hopkins University Earlier this month, I sat in the Radiohead-themed conference room of Beijing start-up Moonshot and watched a demonstration of its powerful new Kimi K3 AI model. Founder Yang Zhilin, a music fan, named his company for Pink Floyd's album Dark Side of the Moon -- a fitting reference to uncharted yet high-reward territory. Within China, the surprise release of Kimi K3 has been hailed as another chance for the country to flex its tech expertise at the expense of US rivals. More US companies are opting to lower their costs by switching to cheaper, high-performing Chinese open AI models such as K3, Z.AI's GLM, DeepSeek's R-1 and Alibaba's new Qwen 3.8 Max. "Saves us millions of $ and we're actually seeing an *increase* in performance on many core use cases. Transformative," wrote Flo Crivello, CEO of San Francisco-based digital assistant platform Lindy AI, which switched to DeepSeek this year. What is the security risk of using open-source AI models created by foreign companies? Washington seems focused on surveillance, IP theft, espionage and potential Chinese involvement in critical domestic infrastructure. The White House is reportedly exploring tools to curb the spread of, or even sanction, open Chinese models. The debate may look like a stand-off between national security and innovation, but it is not quite that simple. The first point to make is that asking whether a model has been developed by a Chinese company is the wrong question for those concerned about security. Open-source models such as Kimi K3 allow the parameters (the numbers learnt in training that determine how an AI model uses information to predict what comes next) to be downloaded and run by anyone. Companies download the weights, fine-tune the model and then run it on their own cloud or infrastructure. What matters more, therefore, is who owns and operates the server that runs the model. US users worried about data being sent to China could run the AI models on domestic hardware they control or through third-party inference providers. Chinese open models do not uniformly censor information either. Again, where the model is hosted changes things. When hosted on US infrastructure, models will answer questions that would be blocked inside China. Since weights are open, users can change content restrictions. Even if data is hosted within China, where companies are required to co-operate with the National Intelligence Law, some push back in ways that mean the government does not necessarily have unfettered access. In March this year, Chinese government inspectors seeking access to data from the ecommerce platform Pinduoduo got into a brawl with staff trying to block entry. One official left with a broken finger. The US does need a viable open-source option of its own. It is quickly becoming a crucial lever of national power projection. Kevin Xu of Interconnected Capital compares it to Disney movies and K-pop. But the real problem is that Washington lacks a comprehensive approach to shore up critical infrastructure in the face of powerful, AI-enabled cyber attacks that are no longer hypothetical. Here the transparency provided by open weights (including those from China) could in fact improve security. Last week, Hugging Face used an open Chinese AI model to analyse an AI agent cyber breach. This all happened without data leaving Hugging Face's system. Governments on all sides still insist on framing AI as a global arms race. But neither threats nor innovation map neatly on to national boundaries. Addressing data access and control in an interconnected world requires a new way of understanding security protocols.
[2]
Cheaper, open and intelligent: Chinese AI models gain ground, as they make inroads in the US
HONG KONG (AP) -- China has a hot new product in the United States: artificial intelligence. San Francisco-based Raffi Krikorian, the chief technology officer at Mozilla, which runs the Firefox browser, switched to Chinese AI startup Moonshot's Kimi K3 for many of his day-to-day activities within days of the new, powerful model's launch more than a week ago. "It just seems snappier," he said of K3, comparing it to the acclaimed and more expensive Claude Fable chatbot from San Francisco company Anthropic. Earlier, he had been using another high-performing Chinese model, Z.ai's GLM-5.2, for routine tasks such as managing his calendar, documents and email. Krikorian is one of a growing number of Americans adopting Chinese AI systems, which are gaining ground around the world because they are more affordable and increasingly efficient. U.S. companies like cryptocurrency exchange Coinbase said they're switching to Chinese AI models to help trim costs. Their popularity has frustrated some U.S. tech giants, but short of an outright ban, they're likely to continue to appeal to independent software developers in the U.S. and elsewhere. American-led restrictions block China from accessing some of the world's most advanced technologies including cutting-edge AI chips and U.S. Treasury Secretary Scott Bessent has warned more sanctions could be coming to protect American intellectual property. U.S. President Donald Trump's administration on Wednesday accused Moonshot of using "covert" but not necessarily illegal methods to build K3 off the back of Anthropic's Fable. Some U.S. politicians and AI companies including Anthropic have accused Chinese startups of illicit "distillation" of their models to extract their technologies, a claim that Beijing rejects as "groundless." China's AI models are cheaper and 'good enough' The rapid rise of cutting-edge Chinese AI models this year shows the China-U.S. race in AI has moved on from early last year, when Chinese startup DeepSeek shook up the U.S. technology industry and put China on the map with an AI model that performed on par with those in the U.S. but much more cheaply. The latest AI models launched by startups Z.ai, or Zhipu, in June, and Moonshot in July are nearly as intelligent as the frontier models from OpenAI and Anthropic, experts say. Also in July, China's Alibaba previewed its Qwen3.8 Max AI model. In April, DeepSeek rolled out previews of its latest V4 model, challenging OpenAI's GPT and Google's Gemini. Those constant advances are bearing fruit. Curt Meinhold, a Greensboro, North Carolina-based technology executive, said he increasingly prefers to use DeepSeek for tasks such as finding business leads or ways to generate sales. "At the end of the day, most of us, the vast majority of us, 90 plus percent, don't need (Anthropic's) Mythos or Fable," said Meinhold, who founded digital legacy platform LilyList. "Like, we just don't need it, we need something good enough." Chinese AI models are reaching a "critical stage" for wide adoption, U.S. investment bank Goldman Sachs wrote in a July research report, especially when a surge of global "agentic" AI usage, which requires the AI models to autonomously conduct multistep, complex tasks, is driving higher demand for cost effective AI models. AI prices are calculated per million tokens for both input and output, so the use of AI "agents" is dramatically compounding cost differences, according to analysts including Alex Colville of the Australian Strategic Policy Institute. "The Chinese models, you know, I find them to be pretty close on code and research," said Meinhold. "If I can pay a handful of cents per million output tokens versus 30 bucks or 40 bucks or 50 bucks, then it's good enough." Moonshot's Kimi K3 leads, but Chinese AI models have limits Based on data over the past month, the top five most popular models on OpenRouter, a platform that tracks data across AI models, were Chinese. Estimates from Sensor Tower, a market intelligence firm, showed Kimi had more than 930,000 downloads during the week after K3's July release, an increase of 200% from the week before. In the U.S. it was downloaded around 86,000 times, a 387% jump. K3 proved so popular that Moonshot had to temporarily suspend new subscriptions after overwhelming demand pushed its capacity close to its limits. Still, while Chinese models are becoming serious competitors to the U.S., they lag American AI leaders across their overall, full-range capabilities, said Anastasios Angelopoulos, co-founder and CEO of Arena, a platform for evaluating AI systems. And U.S. AI firms are also looking for more options to reduce pricing, such as with cheaper alternatives of competitive models, added Yasir Atalan, with the Center for Strategic and International Studies. US policy could boost Chinese AI models Most Chinese AI models are open-source -- meaning anyone can examine and build on them -- at a time when frontier models from U.S. companies like Anthropic and OpenAI are closed-source. Chinese model vendors are expected to leverage open-source software to promote their global usage and adoption, said Lian Jye Su, of the technology research and advisory group Omdia. As Chinese open-source models are increasingly almost as good as closed systems made by leading U.S. companies, said Mozilla's Krikorian, "the open frontier is becoming increasingly Chinese-built." While the U.S. weighs restricting Chinese AI models, a group of American tech firms including Microsoft, Meta and Nvidia signed an open letter published Friday backing "open" AI models. Other U.S. tech policies also at times give China an upper hand, some experts say. China's Z.ai released its GLM-5.2 model in mid-June, not long after the Trump administration put export controls on Anthropic's Fable and Mythos models, keeping them offline for more than two weeks. "Restricting an American model can immediately create an opening for a Chinese competitor," said Arena's Angelopoulos. Chinese AI models look to expand globally In China, people and businesses have rapidly embraced AI technologies that have prospered with state support. Chinese tech companies like Huawei and Tencent are also embedding AI in devices such as smartphones, AI glasses and humanoid robots. Now China is increasingly looking to dominate AI abroad, too. At a flagship technology summit in Shanghai, Chinese President Xi Jinping championed open-source AI models and the importance of promoting greater global equity, while pledging Chinese involvement in raising AI capabilities especially in developing nations. As is true for many other industries in China, intense competition at home is driving companies to expand globally. Leading Chinese AI startups are now raising more funding to support that effort, including through public share offerings. Both China and the U.S. will want to "encourage widespread adoption of their AI ecosystems, while safeguarding technologies that could materially strengthen strategic rivals," said Chelsey Tam, with investment research firm Morningstar. "The competition is no longer simply the United States against China; the Chinese labs are also putting a lot of pressure on one another," Angelopoulos said. But as is the case in the U.S., huge investments in AI have also raised concerns over sustainability of these Chinese startups. Z.ai, for example, reported its revenue surged 132% to 724 million yuan ($107 million) last year, but net loss jumped 60% to 4.7 billion yuan ($694 million). For now, Chinese AI models will likely continue to march ahead including in the U.S. "I would highly recommend anyone doing any serious AI load to at least evaluate it," said Krikorian. ___ O'Brien reported from Providence, Rhode Island. AP Business Writer Kelvin Chan in Toronto contributed to this report.
Share
Copy Link
Chinese AI models including Moonshot's Kimi K3 are rapidly gaining adoption among US companies and developers, offering significant cost savings and competitive performance. But Washington remains concerned about potential security risks including surveillance, IP theft, and espionage, even as experts debate whether the focus on model origin misses the real issue of infrastructure control.
Chinese AI models are making significant inroads in the United States, with Moonshot's Kimi K3 leading a wave of adoption among American companies and developers. San Francisco-based Raffi Krikorian, chief technology officer at Mozilla, switched to Kimi K3 within days of its launch, describing it as "snappier" compared to Anthropic Claude Fable
2
. The appeal is clear: these models are cheaper open and intelligent alternatives that deliver competitive performance at a fraction of the cost. Flo Crivello, CEO of San Francisco-based Lindy AI, reported that switching to DeepSeek "saves us millions of $ and we're actually seeing an increase in performance on many core use cases"1
.
Source: Seattle Times
The numbers tell a compelling story. Kimi K3 saw more than 930,000 downloads during the week after its July release, representing a 200% increase from the previous week. In the US alone, downloads jumped 387% to around 86,000
2
. Based on data over the past month, the top five most popular models on OpenRouter were Chinese, signaling a dramatic shift in market dynamics2
.The economics are hard to ignore. Chinese AI models from Moonshot, DeepSeek, Z.AI's GLM, and Alibaba Qwen offer dramatic cost advantages over American competitors. Curt Meinhold, a North Carolina-based technology executive, explained the calculus: "If I can pay a handful of cents per million output tokens versus 30 bucks or 40 bucks or 50 bucks, then it's good enough"
2
. For most users who don't require the absolute frontier capabilities of models like Anthropic's Mythos or Fable, these Chinese alternatives deliver sufficient performance at transformative price points.Goldman Sachs noted in a July research report that Chinese AI models are reaching a "critical stage" for wide adoption, particularly as agentic AI usage surges globally. These AI agents autonomously conduct multistep, complex tasks, dramatically compounding cost differences between Chinese and American models
2
. Companies like cryptocurrency exchange Coinbase have publicly announced switches to Chinese AI models to trim costs.Washington's response has focused on potential security risks including surveillance, IP theft, espionage, and Chinese involvement in critical domestic infrastructure. The White House is reportedly exploring tools to curb the spread of, or even sanction, Chinese open-source models
1
. US Treasury Secretary Scott Bessent has warned that more sanctions could be coming to protect American intellectual property2
.The Trump administration accused Moonshot of using "covert" methods to build K3 off the back of Anthropic's Fable, though not necessarily illegal ones. Some US politicians and AI companies including Anthropic Claude have accused Chinese startups of illicit distillation of U.S. models to extract their technologies, claims Beijing rejects as "groundless"
2
.Experts argue that focusing on whether a model was developed by a Chinese company misses the point. Open-source models like Kimi K3 allow parameters to be downloaded and run by anyone. Companies download the weights, fine-tune the model, and run it on their own cloud or infrastructure
1
. What matters more is who owns and operates the server that runs the model. US users worried about data being sent to China could run the AI models on domestic hardware they control or through third-party inference providers.When hosted on US infrastructure, Chinese models will answer questions that would be blocked inside China. Since weights are open, users can change content restrictions
1
. This nuance suggests that blanket concerns about Chinese models may overlook the technical realities of how open-source AI actually works.Related Stories
The real challenge, according to security analysts, is that Washington lacks a comprehensive approach to shore up critical infrastructure in the face of AI-driven cyber threats that are no longer hypothetical
1
. The transparency provided by open weights—including those from China—could actually improve security. Last week, Hugging Face used an open Chinese AI model to analyze an AI agent cyber breach, all without data leaving Hugging Face's system1
.Open-source AI has become a crucial lever of national power projection, comparable to cultural exports like Disney movies, according to Kevin Xu of Interconnected Capital
1
. The US needs a viable open-source option of its own, but most frontier models from OpenAI GPT and other American companies remain closed.While Chinese models are becoming serious competitors, they still lag American AI leaders across their overall, full-range capabilities, according to Anastasios Angelopoulos, co-founder and CEO of Arena
2
. US AI firms are also exploring cheaper alternatives of competitive models to address pricing pressures. The debate between national security and innovation continues, but neither threats nor innovation map neatly onto national boundaries. Addressing data access and control in an interconnected world requires new security protocols that account for where and how models are actually deployed1
.Summarized by
Navi
13 Jul 2026•Policy and Regulation

18 Jul 2026•Policy and Regulation

22 Dec 2025•Policy and Regulation

1
Technology

2
Technology

3
Technology
