American AI May Not Survive Chinese Open-Source

Roadtripwithraj/CCTV Headquarters in Beijing

The AI industry has been rocked by recent large-language model (LLM) releases from Chinese labs, most notably the Kimi K3 model from Moonshot. K3 performed similarly to Anthropic’s Fable model on AI benchmarks, and its release follows the established norm among Chinese labs of being open-weights—that is, the model itself is given away online for others to run on their own hardware. The release of K3 came at an especially notable time, just a week after Anthropic’s Fable model was re-released to the public following a U.S. government restriction over concerns about its potential use as a cyber weapon. To release an open-weight model, completely lacking active monitoring and controls, that is approximately as powerful as a proprietary model that the U.S. government is treating like something just shy of a nuclear weapon was a stunning blow to the U.S. AI regulatory regime.

Chinese AI labs receive significant state support but are still heavily constrained in both financial resources and access to advanced chips compared to U.S. AI labs. There’s much debate in the AI industry about how a Chinese lab was able to pull off this remarkable coup with far fewer resources. A leading theory for this overperformance is distillation—that instead of training on text data from the internet, books, and other (oftentimes expensive) sources, Chinese models have been trained on prompts and responses from superior American models directly. This process allows the distiller to create a model that accurately mimics the source model at a fraction of the training cost.

Creating new models requires immense investment in research and compute, and in the United States this cost is financed by private investment with the primary goal of serving civilian demand. Unsurprisingly, these models have also found ample military applications in both kinetic and cyber use cases. LLMs have now been used for targeting purposes in Iran, and the CYBERCOM AI budget increased 2,660 percent in a single year as published doctrine has caught up, treating AI cyber capabilities as a core state capacity.

The United States’ lead in AI is likely to become an increasingly key strategic defense advantage as model applications diffuse past supporting operational intelligence and cyber warfare. As an industry, AI massively impacts every other industry through dramatic upscaling of R&D productivity, and defense technology is no different. Increasingly, the nation-state with access to the best AI will have the decisive advantage that begets the most advanced naval vessels, fighter jets, and drone technology. Furthermore, the specter of recursive self-improvement (RSI), a practice in which AI models directly drive R&D on future AI models at a level beyond what human researchers can perform, makes AI a unique security technology in that its advantage increases over time. Atomic weapons and stealth technology were temporary advantages that eroded quickly. The first country to reach RSI may find itself with a permanent decisive advantage. Their models may “take off” in capability as RSI models continue to train new, more powerful RSI models. The cyber warfare capabilities of such models could even prove to be a weapon that disrupts other states’ ability to train their own models.

In this light, AI begins to seem like a permanent strategic advantage technology that must be pursued at nearly any cost. If such assumptions hold, then the situation of such technology currently being financed by the private sector for applications such as assisting programmers and providing recipes is an almost comical mistake of history.

Viewed in this light, the Chinese open-weight strategy is fascinating. If one models China as a homogeneous and rational actor, the strategy of distilling American AI models and giving away the weights for free can be viewed as a brilliant tactic to kneecap a foreign industry rushing towards permanent strategic advantage. One could debate whether open-weights releases qualify as dumping in a trade sense or if they represent an open-source commoditization play—Chinese labs giving away a layer that they cannot hope to monopolize—but the outcome is potentially devastating to our domestic AI industry regardless. The cost of researching and training models can be over half of compute costs at major labs, with inference (the cost of serving models to users) making up the remainder. A firm that can skip training costs and simply charge for inference using an open-weight model is at a distinct economic advantage compared to labs such as OpenAI and Anthropic that must also bear the cost of development. This challenge to frontier lab economics is not just a matter of concern for those firms and their investors. Destroying American labs’ incentives to invest in AI model development may have major implications for U.S. military supremacy going forward.

The proper response to this economic attack on U.S. military development is debatable. Dean Ball, Head of Strategic Futures at OpenAI, a former Trump administration official, and a former colleague of mine at the Mercatus Center, drew controversy by posting on X that the Trump administration might feel moved to soft-ban foreign open-weight models through regulatory restraints and uncertainty. Complete bans on open-weight models are nigh impossible given their easy accessibility through the internet, but large companies and organizations with regulatory exposure could be pressured into avoiding open-source models, thus securing an industrial user base for U.S. frontier labs that will ensure further model development.

While the soft-ban approach may indeed save the lucrative industrial business that frontier labs require, it’s worth considering what the end game of further development would be. If any model that is publicly available can be distilled by foreign actors, it’s worth questioning if it’s in the interest of the United States to have the next Anthropic model be commercially available at all. The current generation of bleeding-edge models—Anthropic’s Fable 5 and OpenAI’s 5.6 Sol—are already exhibiting astonishing advances in capabilities that make clear that we are on the doorstep of autonomous RSI. What will Fable 6 and ChatGPT 6 be capable of?

A better response for national security purposes may then be subsidization. The U.S. government may partner with frontier labs to provide guarantees or direct financing for model runs. The heavily neutered models that are released to the public will continue to support a more anemic commercial business that competes with foreign labs that distill their value, while the U.S. government and its partners retain access to the full capabilities of these models. As RSI becomes an increasingly reliable method of improving models, commercial models will mostly stagnate and further training runs become entirely financed and consumed by government.

Treating the most capable models this way isn’t outside of the Overton window—in fact, it’s current policy. Anthropic’s Fable is a reduced-capability version of Mythos, which has been made available only to government and selected cybersecurity customers because of concerns over its application as a cyber weapon. As model capabilities progress, it’s only natural that they will mostly be withheld from public consumption. The only true policy change in the above proposal is that the U.S. government should help bear the cost of developing these models whose commercial viability they so aggressively constrain.

It’s also worth noting the populist AI safety dimension that makes this policy equilibrium feel increasingly inevitable. Fears of AI have crossed over from obscure Berkeley academic discussion into mainstream concern, animating pushback against data center construction and mass concern about labor replacement. Anxieties over the economic will rapidly extend to the physical after the first AI agent discovers and executes a zero-day exploit in a situation with higher stakes than the recent Hugging Face incident. At that point, armed with the argument that China could reach the same level of capability, it will be easy to justify national expenditure to support and control more advanced models.

Of course, there is still the chance that this all may be unnecessary. Frontier labs are still remarkably well-funded businesses with valuations closing in on $1 trillion. It may be that commercial users continue to prefer American-made models, even if they are more expensive to run, and consumers want to stick with the personalities they like in Claude and ChatGPT, an arrangement that would continue to subsidize the more advanced models that increasingly serve large institutions and the U.S. military. But if enough users bolt from proprietary models to open-weight alternatives to challenge the fundamental economics of frontier labs, do not expect a rational U.S. government to let American AI dominance perish to subsidized foreign competition like so many steel mills and tire factories before it. The consequences of future control of AI may reach far beyond any technology that has come before.

Daniel Francis is the CEO of Abel Police, an AI company that serves law enforcement. He previously worked as an engineer at X and as a researcher at the Mercatus Center in Washington, D.C.