Trump Administration Revives Push to Block Chinese AI Models as Open-Weights Complicate Enforcement

Trump Administration Revives Push to Block Chinese AI Models as Open-Weights Complicate Enforcement

The Trump administration is quietly reviving efforts to ban leading Chinese artificial intelligence models from the American market, according to people familiar with the matter. The renewed push follows the release of Kimi K3 by Beijing-based Moonshot AI and the growing popularity of DeepSeek's open-weight models among US companies — two products that share a trait Washington finds hard to police: anyone can download them.

Artificial neural network chip concept

The administration has dusted off options first floated last year: adding Chinese AI labs to the Commerce Department's Entity List, drafting an NSA-led advisory warning companies off Chinese models, and even an executive order that would hold US firms liable for security breaches traced to hosted Chinese AI. Those measures were shelved after internal pushback, but according to an Axios report published July 20, they are back on the table — and moving faster than before.

"We are at a critical inflection point in AI policy," wrote David Sacks, an outside White House AI adviser, in an X post on Sunday. "The leading closed labs, already a duopoly in terms of AI model revenue, want the government to eliminate their open-source competition."

Why US companies are running Chinese AI in the first place

The adoption that is worrying Washington starts with a simple number: price. DeepSeek-V4-Pro charges $0.87 per million output tokens. Anthropic's Claude Fable 5 charges $50 for the same work. That is a 57x gap — and American companies have noticed.

Coinbase CEO Brian Armstrong told investors the exchange now runs models like Kimi and Z.ai's GLM-5.2 in production, cutting overall AI spending almost in half even as token consumption climbed. Industry sources say dozens of mid-size tech firms have quietly begun evaluating or deploying Chinese open-weight models for internal tasks like code generation, customer service summarization, and document processing.

The appeal is not just cost. Open-weight models let enterprises download the actual trained parameters and host them on their own private servers. No data leaves the building, no API keys are needed, and no third party sees the prompts. For hospitals handling patient records under HIPAA, banks dealing with transaction data, and defense contractors — the audit-trail advantages are real.

But that same portability is what makes a ban so hard to enforce.

The enforcement puzzle

Unlike a cloud API — where the provider can cut off access for anyone it spots using a US IP address — an open-weight model lives as a folder of files. Once those files land on Hugging Face, GitHub, or a BitTorrent tracker, they never fully go away.

As one source close to the administration told Axios, the strategy is not to stop downloads entirely — everyone knows that is impossible — but to pressure US companies to drop the models voluntarily. The tools include procurement rules, Entity List threats against firms that keep using Chinese AI, and a public campaign to highlight potential security backdoors.

"Push to highlight potential backdoors and lack of security with Chinese models, and the governance issue that brings," the source said, describing the plan.

The administration has fresh ammunition. Last week Kimi K3 became the largest open-weight model ever released, with 2.8 trillion parameters, beating Meta's Llama 4 and DeepSeek V4 on several benchmarks including MATH-500 and HumanEval. Its release triggered a wave of developer downloads across Hugging Face, where the model surged past 50,000 downloads in its first 48 hours. The release renewed the security debate inside the White House, where officials had previously shelved action after pushback from free-market advocates.

Critics of the ban — and they include former White House adviser Sriram Krishnan — argue that blocking Chinese models hands OpenAI and Anthropic a government-protected duopoly. "The move would negatively impact innovation," Krishnan warned, while handing market control to the same closed labs that just got their own models temporarily blocked by US security vetting rules under an earlier executive action. The irony is not lost on industry watchers who note that Anthropic's Mythos and OpenAI's GPT-5.6 Sol were both briefly restricted by the same government that now wants to block their Chinese competitors.

A data center with server racks

What a ban would actually look like

Current proposals being debated include three layers.

A Commerce Department Entity List expansion would add DeepSeek, Moonshot AI, and Z.ai to the trade blacklist. That would bar them from buying American chips and cloud services — but it would not stop US companies from downloading weights that are already public on open repositories.

A joint NSA-ONCD advisory would warn US businesses that Chinese AI models could contain hidden backdoors, data-exfiltration channels, or compelled compliance with Beijing's surveillance laws. The advisory would be the first official US government document to label specific AI models as national security risks, setting a precedent for future actions.

And a procurement rule would require any company that contracts with the federal government to certify it does not use Chinese AI models in its operations. Since the US government is the world's largest buyer of IT services — spending over $100 billion annually on technology contracts — that rule would ripple across the entire tech industry, forcing compliance teams to audit internal model usage.

But enforcement gets creative at the edges. Companies that self-host Chinese models inside air-gapped data centers leave no cloud provider logs. Modified versions — fine-tuned, quantized, or distilled with corporate data — blur the line between foreign and domestic, making provenance hard to prove in court. Even the Entity List carries a structural loophole: it blocks sales to listed entities, not a US company's use of their published open-source software.

For enterprises that want to keep using DeepSeek or Kimi under a theoretical ban, the simplest workaround is deploying through a foreign subsidiary that leases GPU time from a non-US cloud provider such as Oracle's European data centers or Alibaba Cloud. Know-your-customer rules at AWS, Azure, and GCP might catch some of those flows, but the extraterritorial reach of US export controls has limits in practice, especially when the model runs on GPUs that were never subject to US export restrictions.

The geopolitics driving the move

The revived push is the latest front in a broader technology decoupling that has accelerated since Washington began restricting advanced chip exports to China in 2022. Beijing responded by pushing domestic companies to build their own AI stacks — and the strategy is working. Chinese models now match or exceed American counterparts on several key benchmarks while undercutting them on price by wide margins.

The Trump administration has made clear it intends for the US to dominate the AI race. But blocking the cheapest models from the market while American labs charge 50x more creates tension with the White House's stated goal of democratizing AI access across the economy.

European regulators are watching closely. The EU's AI Office has taken a softer stance on Chinese models so far, but officials have privately expressed concern about data sovereignty and the potential for Beijing to demand model-level access under China's 2024 cybersecurity regulations, which require technology companies to cooperate with state security requests.

What happens next

The administration has not made a final decision. An executive order on Chinese AI models could come within weeks, according to the Axios sources, or the push could stall again under industry lobbying from tech giants with exposure to both markets.

Either way, the debate has already changed the conversation. US tech leaders who six months ago dismissed Chinese AI as a copycat story now acknowledge it as a genuine competitive threat. And companies that quietly adopted DeepSeek or Kimi for cost savings now face a compliance question nobody had a clean answer for: what do you do if the government tells you to stop using a model you have already downloaded into your production pipeline?

Read more: US Opens Security Vetting of Frontier AI Models

AI · Semiconductors · Cybersecurity

Sources: Axios, Tom's Hardware, Coinbase investor call, Commerce Department filings

← Back to Home