China’s DeepSeek is once again causing a stir in US tech and policy circles, this time with the release last week of V4 Pro, a so-called open weight artificial intelligence model that is free for anyone to download. The move has Washington and Silicon Valley debating more intensely than ever whether—and how—the US should respond to the rise of such Chinese AI technology.
While the Trump administration has floated a ban on Chinese open-weight AI models, US tech companies, big and small, are protesting the restriction of such models, regardless of their origin.
“The issue of open models is probably one of the trickiest, if not the trickiest, AI policy issues that the government and companies have to navigate,” said Aalok Mehta, director of the Wadhwani AI Center at the Center for Strategic and International Studies (CSIS), a Washington-based think tank.
At the center of the debate is the safety of such models offered by Chinese companies.
There are two types of open models: open-weight and fully open-source ones.
Once an open-weight model is published, anyone can run, fine-tune and build products on top of it, but they do not have access to the training data behind the model. Open-source models, by contrast, publish their training data and code.
None of the Chinese models at the center of the debate, including those of DeepSeek and Kimi K3, are fully open-source, as all of them withhold their training data. This leaves room for worries that the models could be trained with bias or embedded with sleeper functions such as “backdoors” that could give the Chinese government covert access.
AI researchers who study these systems are skeptical of such concerns, though they do not rule them out entirely.
Building a backdoor would require deliberately poisoning training data with the kind of conditional triggers that current models struggle to hold onto reliably, said Jason Corso, a professor of AI at the University of Michigan. While doing so is “theoretically possible,” he said, he was not aware of any documented instances of such actions.
As for Chinese models sending user data back to Beijing, Kyle Miller, a senior research analyst at Georgetown University’s Center for Security and Emerging Technology, said what matters is where the AI models are run.
“If you’re using a Chinese open model on your own infrastructure, that simply cannot happen,” he said. “You have full control over the model.”
Meanwhile, the safety of closed, proprietary AI models is also being questioned.
A report published on August 4 by the AI Security Institute, backed by the UK government, found Anthropic’s Mythos 5 and OpenAI’s GPT-5.6-Sol had together taken 19 unsanctioned actions against real people and organizations during safety testing. In the most serious case, an AI agent tried to insert malicious code into an open-source project.
Both Anthropic and OpenAI have publicly acknowledged their models have broken out of their testing sandboxes.
Eugene Lee, a Hong Kong-based AI engineer, told Nikkei Asia closed models are by nature a black box, as outsiders cannot see the training data, the alignment methods, whether a backdoor exists or where the model might suddenly fail.
Open models, Miller argues, are necessary tools to defend against such black boxes.
“When the model is open weight or open source, both bad actors and good actors can use it. … Open-weight models allow defenders—so this includes the entire cybersecurity industry—to use these models freely without guardrails, to customize them and to optimize them for their defenses,” he said.
“Open weights give defenders much more of an advantage, as opposed to a world where the frontier capabilities are in a handful of labs,” he added. “It’s a matter of making sure defenders are enabled by [open models], so they can defend against these types of things.”
That is precisely what happened in one case last month, when Hugging Face said it used the open-weight GLM-5.2 model by China’s Z.ai to analyze and contain an attack from OpenAI.
Another issue surrounding China’s open-weight AI models is how they have gotten so good so quickly.
In some of the benchmark tests released by DeepSeek last week, V4 Pro’s performance on agent-related evaluations was close to or even ahead of that of most advanced US frontier models.
Trump administration officials claim such advances are due to distillation, accusing companies like Moonshot AI and DeepSeek of training their models by harvesting output from ChatGPT, Claude, and other US AI labs rather than building them from scratch.
White-box distillation—using direct access to a “teacher” model’s internal weights to compress it into smaller “student” models—is a routine engineering technique used by most AI labs, including those in the US. This is commonly done to turn an expensive flagship model into a cheaper, faster version.
Black-box distillation, by contrast, trains a model directly on another model’s outputs without access to the latter’s internal weights. This more controversial method is what Chinese labs are accused of doing to Claude and ChatGPT, and a violation of their terms of use.
“What the US really needs to confront is that Chinese open-source models are advancing very quickly,” said Lee, the Hong Kong engineer. “So a more reasonable direction isn’t a blanket ban on open-weight models, but rather tiered controls on the highest-risk frontier capabilities, while encouraging the development of America’s own open-source ecosystem, and using legal and commercial tools to address illegal distillation of Chinese companies.”
Leading US industry figures agree that distillation is no reason to ban Chinese AI models.
In a July interview with Axios, Nvidia CEO Jensen Huang said “distillation, learning from AI, learning from other sources of knowledge, is fundamental to intelligence,” much like humans learning from one another.
The US chip giant has been leading the charge in opposing a ban on Chinese open-weight models. In addition to signing an open letter on the matter, Nvidia also released its own open-weight AI model, Nemotron 3.5 Lightning, earlier this month.
The same week, Meta unveiled its own open-weight model, called Muse Glimmer. The release came alongside a more than 6,000-word blog post by CEO Mark Zuckerberg urging policymakers to support American open AI, saying it is important that the “US and its allies lead the open source AI ecosystem that will make up a large percent of global AI use.”
“Foreign labs currently hold several advantages here since American labs have to comply with many additional restrictions on training data,” Zuckerberg said in the post. “US policy must reduce this additional friction if we want American open source models to lead over time.”
Case in point: DeepSeek currently ranks as the most-used AI model in the world, with a 27% market share, according to OpenRouter. Alibaba, meanwhile, said its Qwen is the world’s most downloaded open-source model family. The Chinese tech giant released the latest version, Qwen 3.8-27B, on August 17. All told, Alibaba has made more than 460 of its models open source and accumulated more than three billion global downloads.
Washington may be heeding Zuckerberg’s warning.
Multiple US media outlets reported this month that the Trump administration has excluded open models from a voluntary review framework intended to evaluate the safety of advanced AI models.
It stands to reason that both Silicon Valley and Washington are increasingly nervous about China’s lead in open-weight AI.
“A lot of manufacturers, both in Europe and in the US, are using open-weight models from China because they don’t trust Anthropic or OpenAI. They don’t want to send their critical data there,” said Pierre Baque, founder and CEO of Neural Concept, an AI design software company that works with automakers, chipmakers, and other manufacturers to speed up their design workflow.
“The Chinese cannot spy on you through a model that you host,” Baque said, adding that a lack of American open-weight frontier models was “really creating a huge opportunity for China.”
Part of that opportunity could be geopolitical.
At the World AI Conference in Shanghai this July, Chinese President Xi Jinping reaffirmed China’s commitment to open-source AI. By positioning itself as an advocate of open AI models, China can create structural reliance among the countries and companies that adopt them, reliance it could later weaponize if it chooses to, said an associate at an international law firm who asked not to be named due to the firm’s presence in China.
“Open-source AI is probably becoming China’s new chokehold, alongside rare earths, and it’s something the Chinese government could potentially weaponize,” the lawyer told Nikkei Asia.
As open AI becomes the latest frontier in the US-China tech race, analysts expect Washington to restrict Chinese models despite Silicon Valley’s pushback.
Because it is difficult to remove open-source or open-weight models from the internet, or prevent users from downloading them once they are available, Corso at University of Michigan said the most straightforward option for Washington is to make it illegal to use such models.
Export controls are another potential tool. The Trump administration said in July that Moonshot’s Kimi K3 was trained on Nvidia chips in violation of US export restrictions.
“We believe the most likely US response is to tighten export controls to prevent AI chips from being diverted to China, and require all US AI players to put anti-distillation features in their advanced models,” Jefferies analyst Edison Lee said.
Any action, however, is unlikely to come ahead of next month’s meeting between Trump and Xi in Washington, analysts say.
Trump said in July that he will discuss AI with Xi when the latter visits the White House in September. The two leaders met in Beijing in May, but the readout from that meeting focused mostly on trade issues.
“There’s a reluctance on the part of both governments to create the conditions that would lead to an unproductive meeting,” Mehta at CSIS said, adding that there might be “work happening below the surface” in Washington targeting Chinese AI, but a lot of those actions will be “held in reserve, pending the outcome of the upcoming summit.”
This article first appeared on Nikkei Asia. It has been republished here as part of 36Kr’s ongoing partnership with Nikkei.