China Moves to Tighten Exports of Top AI Models, Marking a Major Turning Point for Its Open-Source Strategy

China may restrict exports of frontier AI models, potentially upending its open-source global strategy.
Beijing is reportedly in closed-door talks with major Chinese AI companies about restricting overseas access to frontier AI models — including open-weight models from Alibaba, ByteDance, and Z.AI — signaling a shift from openness-for-influence to control-for-security. Simultaneously, DeepSeek is quietly developing its own inference chips to reduce dependence on Nvidia and Huawei, reflecting a broader push toward AI self-sufficiency in China.
Beijing Is Rethinking the Open Boundaries of Its AI Models
China's AI industry has risen dramatically on the global stage over the past two years, largely thanks to one key word: openness. From DeepSeek R1's stunning debut to Alibaba's Qwen building a massive developer community on Hugging Face, and Z.AI's GLM series approaching the capabilities of top American models at a fraction of the cost — Chinese open-weight models have become a go-to choice for developers worldwide, thanks to their combination of strong performance, low cost, and ease of deployment.
What are open-weight models? Open-weight models are AI models whose trained parameter files (the "weights") are publicly released, allowing anyone to download, deploy locally, and modify them. Unlike closed-source models that only offer API access, open-weight models give users complete control — no internet connection required, no fees, and no need to disclose use cases to the original developer. This makes them especially popular in fields with strict data privacy requirements, such as government agencies, healthcare, and finance. For Chinese AI companies, the open-weight strategy also carries unique geopolitical value: it bypasses potential U.S. restrictions on API services, allowing global developers to use and depend on Chinese models even without access to Chinese servers. Qwen series models on Hugging Face have accumulated hundreds of millions of downloads. This approach of "claiming infrastructure first, then building ecosystem lock-in" has been the core method Chinese AI companies use to establish a presence in the minds of global developers.
However, according to Reuters, this landscape may be approaching a turning point. Beijing has reportedly held multiple closed-door consultations over the past month with major domestic AI players including Alibaba, ByteDance, and startup Z.AI, focused on whether to restrict overseas access to China's most advanced AI models. Three people familiar with the matter said officials from China's National Development and Reform Commission (NDRC) also participated in the discussions, though no decisions have been made yet.
What the NDRC's involvement signals The participation of China's National Development and Reform Commission in discussions about AI export controls reveals the administrative level and industrial policy nature of these talks. The NDRC plays a central role in China's economic governance, handling macroeconomic strategic planning and industrial policy coordination. Its involvement typically signals that an issue has moved beyond simple market regulation into the realm of national strategic resource allocation — similar to how China manages rare earths, aerospace, or nuclear technology. Previously, China's primary AI regulatory forces were the Cyberspace Administration of China (responsible for algorithmic recommendations and generative AI registration) and the Ministry of Industry and Information Technology (responsible for industry standards and chip industry support). The NDRC's entry means AI governance is being folded into a broader framework of strategic asset management. This foreshadows a potential paradigm shift in AI governance — from technical regulation toward resource control.

Interestingly, these discussions are not limited to closed-source systems. They reportedly also cover open-weight models, including Alibaba's Qwen, ByteDance's Doubao, and Z.AI's GLM. This is the most striking aspect: openness is precisely the foundation of China's global AI presence. If even this is tightened, the implications would be far greater than most people imagine.
Behind AI Export Controls: A Strategic-Level Control Framework
Based on information that has emerged, these consultations go far beyond simply deciding whether to restrict access. They represent a comprehensive strategic-level control framework for frontier AI.
According to people familiar with the discussions, topics on the table include: classifying the leakage or theft of proprietary AI technology as a national security crime with substantial criminal penalties; and restricting the types of foreign capital allowed to invest in Chinese AI startups. Piecing these signals together, a clear picture emerges — Beijing appears to be moving toward treating frontier AI as a strategic asset on par with other controlled technologies: something to be protected and controlled, not simply exported for goodwill or market share.

This is not happening in isolation. Since the beginning of this year, China has been steadily tightening the channels through which AI technology flows abroad. Regulators have reportedly been investigating whether some Chinese AI startups that relocated overseas violated export control regulations, and have launched separate inquiries into companies like Manus that moved operations offshore. A package of regulatory measures introduced in early June expanded government review to cover nearly all cross-border transactions involving Chinese capital, technology, or data. There are also reports that Alibaba internally instructed employees to stop using Anthropic's models and agent tools, switching to the company's in-house assistant instead — regardless of whether this is directly related to the government consultations, the direction is highly consistent: self-sufficiency and ecosystem control.
The Mirror Standoff: U.S. and China AI Controls Face Off
Understanding the context for this potential policy shift requires looking at what's happening across the Pacific. The United States has been steadily tightening export controls on advanced AI models in recent years, partly out of concern that frontier systems may possess serious cyberattack capabilities. The U.S. has restricted overseas access to some of its most powerful models, citing fears that the technology could be misused by military or intelligence agencies in so-called "countries of concern."
The evolution of U.S. AI export controls U.S. export controls on AI-related technologies are nothing new, but the granularity of controls has increased significantly in recent years. In 2022, the U.S. Commerce Department added high-end GPUs like Nvidia's A100 and H100 to its export restriction list for China. Nvidia then introduced the "downgraded" A800/H800 to work around the thresholds, but by late 2023 these reduced-spec products were also banned. In 2024, the Biden administration introduced the "AI Diffusion Rule," attempting to control API access to advanced AI models by country, dividing nations into three tiers with the strictest restrictions applied to "countries of concern." The Trump administration revoked this rule in 2025 but quickly introduced an updated control framework. Notably, controls have extended from hardware to software — certain "frontier AI models" with advanced cybersecurity capabilities are themselves being treated as controlled "dual-use technologies." China's current discussions mirror this framework closely, reflecting a deep convergence in how both countries are approaching AI governance.
Interestingly, Chinese officials are reportedly also worried about the "reverse problem": advanced U.S. AI models focused on cybersecurity could potentially be used to discover and exploit vulnerabilities in Chinese software. Both sides are thus circling the same fear from opposite directions — each worried that the other's models will be weaponized against its own systems.
This is fundamentally evolving into a "mirror standoff": the very capabilities that make a model useful for defense are exactly what makes the other side uncomfortable with its existence. AI has been elevated from a purely commercial technology to a strategic dimension of U.S.-China tech competition.
A Tiered Export Framework: Chinese AI's Open Model at a Crossroads
If this policy actually takes shape, what might the specific rules look like? Based on what has emerged from discussions, a capability-based tiered control system is taking form:
- Basic open-source models: May only require registration with regulators through a lightweight process;
- High-performance models: May require formal safety review before release;
- The most sensitive frontier models: May be completely prohibited from public release, or restricted to domestic use only.

For an AI industry that has built its global reputation on "open and accessible," this would represent a significant pivot. Companies like Alibaba had previously embraced openness enthusiastically — releasing weights for free, letting global developers download and build on them. Even partially walking back that openness would change how the world engages with Chinese AI, and could push international developers back toward American labs.
For now, nothing has been decided. Some sources suggest the final rules may be more lenient than rumored, perhaps only affecting models not yet released rather than versions already in circulation. If that's the case, the actual impact on existing ecosystems would be far smaller than the headlines suggest. But the open-weight model angle is worth watching most closely — it is the foundation of China's global AI reputation. Many developers chose Qwen or GLM precisely because they are "free and good." Once that premise changes, so does their logic for choosing them.
DeepSeek Builds Its Own Chips: From Model Company to Integrated Hardware-Software Player
On another front, another equally significant piece of news has surfaced. According to Reuters, DeepSeek is quietly building its own chips. Three people close to the project say the effort has been underway for about a year, with the goal of reducing dependence on Nvidia and Huawei.

To be clear, these chips are aimed at inference rather than training — running already-trained models, not training new ones. DeepSeek has been quietly recruiting chip engineers without posting public job listings, and has already been in talks with manufacturing and memory partners.
The fundamental difference between inference and training chips Training chips are used to "teach" models from vast amounts of data, requiring extremely high parallel floating-point computing power and high-bandwidth chip-to-chip interconnects. Nvidia's H100/H800 are designed for exactly this purpose — large model training often requires thousands or even tens of thousands of these chips working in concert for months. Inference chips, by contrast, are used to run trained models in response to user requests, emphasizing low latency, high energy efficiency, and high throughput, with far lower requirements for chip-to-chip interconnects than training scenarios. DeepSeek's choice to start with inference chips is pragmatic: the commercial value of its R1 model lies in being called billions of times, not in repeated retraining. Inference chip design is also relatively less complex, and in the context of U.S. export controls blocking access to top training chips, self-developed inference chips represent a more achievable breakthrough. Google's TPU and Amazon's Inferentia followed a similar path — starting from the inference side to achieve independent control.
The timing is noteworthy. DeepSeek started as a model company — its R1 model shocked the industry with its extremely low operating costs and briefly rattled U.S. tech stocks. R1 was trained on Nvidia H800 chips before the U.S. ban took effect. Now building its own inference chips is about bridging "the gap between computing power and supply chains" — DeepSeek can currently only use chips it can actually buy, and Huawei's chips still lag behind Nvidia's top products. Having proprietary chips means greater control over costs and supply chains.
DeepSeek is not alone. OpenAI just unveiled its own chip in partnership with Broadcom, and Anthropic is reportedly exploring chip development too. More and more AI companies want to "own" rather than "rent" hardware. But for DeepSeek there is an additional motivation: China has been pushing domestic AI enterprises to develop their own chips to counter U.S. export restrictions. This chip development comes as DeepSeek raises outside funding for the first time — reportedly around $7 billion at a valuation of nearly $55 billion, a major shift for a company that had always avoided external investors.
Some analysts note that Nvidia is already locked out of the Chinese market, and DeepSeek's chips almost certainly won't be sold externally either. But domestically, if these chips work effectively, they will stand alongside Alibaba and Baidu as another strong competitor to Huawei in the self-developed chip space. Following the news, Nvidia's stock dipped slightly in pre-market trading.
Conclusion: Control Is Becoming the Dominant Theme
Whether through investment restrictions, national security classifications, or the potential model access controls now under discussion, Beijing is steadily tightening its grip on AI as it becomes an increasingly critical strategic asset in U.S.-China tech competition. DeepSeek's self-developed inference chips are yet another footnote to the industry-level trend toward "integrated hardware-software, self-sufficiency."
Both pieces of news point in the same direction: Chinese AI is gradually moving from a phase of "trading openness for influence" to a new phase of "pursuing security through control." The final shape of this transition has yet to be determined, but its potential impact on the global AI developer ecosystem is well worth continued attention.
Key Takeaways
Related articles

Disaster and Glory of the Apollo Program: The History We Must Revisit Before Returning to the Moon
From the fatal Apollo 1 fire to Apollo 8's daring lunar orbit to Apollo 11's successful landing—revisiting the disasters, fears, and compromises of the Apollo program and their lessons for today's return to the Moon.

Netflix Trust Exercise Turns Into Firing Trap: Where Are the Boundaries of Corporate Trust?
A Netflix employee was fired after sharing private info in a trust exercise. We analyze the risks of corporate trust exercises and how employees can protect themselves.

AMD CDNA5 Architecture Deep Dive: Technical Evolution and the AI Computing Competition Landscape
Deep analysis of AMD's CDNA5 architecture covering Chiplet packaging upgrades, HBM memory evolution, and low-precision compute optimization, examining how AMD challenges NVIDIA's AI chip dominance.