In the wake of Kimi K3’s release and Chinese president Xi Jinping’s public support for open AI models, there’s been a great deal of argument over how America ought to handle publicly available AI. I’ve seen several articles attempting to spin the question as a black-and-white, us-or-them dilemma, but the reality is significantly more complicated than “open source AI good, closed source bad”, or even “American AI good, Chinese AI bad.”
To begin, an important distinction that was missing from last week’s coverage is the difference between open source and open weights. Open-weight AI models can be downloaded by anyone, but the data and code used to train them might be kept secret. Open-source AI developers publish everything, including the algorithms and datasets used to create a model. Most of the big-name open weight models are not fully open source, but many articles still conflate the terms.
So what’s been happening in the world of open weight AI? Well, Chinese tech giant Alibaba has released a new model, Qwen3.8 Max, which it says is better than every other model except Anthropic’s Fable. Since Alibaba has offered zero evidence to back up this claim, I do not believe them.
By contrast, the Kimi K3 model, released last week, seems at least pretty competitive with leading U.S. models. Its maker, Moonshot AI, received so many new users in a few days that it was forced to pause signups.
Chinese AI models might be relatively cheap to run, but serving many APIs with 2.8 trillion parameters still requires a lot of very expensive hardware. For now at least, Chinese companies don’t have access to many high-end AI chips.
Despite these limits, some worry that open-weight models undercut U.S. AI companies just by existing. Why would American companies pour billions into proprietary AIs, when public models nearly as capable are available more cheaply, and with fewer restrictions?
(This dynamic was one reason that the writers of AI 2040 proposed making all AI research open: In theory, there’s less commercial incentive to develop new techniques for building dangerously smart AI if you can’t conceal the techniques from competitors and profit from the secrets.)
A recent autonomous attack against Hugging Face, the world’s largest repository of open AI models, illustrates some important wrinkles in this debate. AI hackers infiltrated Hugging Face systems, “executing many thousands of individual actions across a swarm of short-lived sandboxes.”
Hugging Face initially turned to American AIs to help trace and counter the intrusion. But they ran headlong into the safeguards intended to prevent abuse, which are conservative in rejecting requests that might be hacking-related. Blocked from the most capable American models, Hugging Face turned to a Chinese open-weight AI, GLM 5.2, hosted on Hugging Face’s own servers.
Being an open source repository themselves, Hugging Face might be a tad biased in their decision to give up on closed models. And they haven’t said much about what the attackers did or stole, making it hard to verify the story. But the general trend, of users turning to open weight AI for reasons of cost or frustration, is real.
Axios reports that the U.S. government might be planning to discourage use of Chinese AI models to protect American firms. The possibility has ruffled some feathers. In a Washington Post article, a former venture capitalist argues that any attempts to restrict open models, Chinese or otherwise, are just “regulatory capture” by American firms.
It’s true that open source software has done a lot of good, and it’s true that industries often lobby to regulate their competition out of existence. It’s even true that open weight models can help groups like Hugging Face tighten their security. It would be a mistake, I think, to outright block U.S. companies from using Chinese AI on protectionist grounds.
But I also think many of these views make a critical mistake in treating AI like any other software. Open weight AI models are already enabling mass cyberattacks, and may soon help bad actors design dangerous bioweapons as well. That’s not something an open-source spreadsheet can do, and it completely changes the landscape of sensible policy.
We can’t keep treating this like a fight between the U.S. and China, or between open source and closed. In the words of Yale research fellow Gautam Mukunda:
The lesson from Kimi K3...is that any regulatory regime must be international, because the models and labs that make it necessary surely will be.
The analyses and opinions expressed on AI StopWatch reflect the views of the individual contributors and the sources they cover, and should not be taken as official positions of the Machine Intelligence Research Institute.



