Executive Summary:
Beijing is converging on a “tiered governance” approach to open weight models, under which basic capabilities would be released freely, frontier capabilities would face security review, and the most sensitive models would be confined to only domestic use.
Support for open weights is a deliberate response to constraints. It offsets a compute deficit that leaves the People’s Republic of China (PRC) roughly two years behind the United States according to leading Chinese AI founders, gives domestic chipmakers a model to optimize against, and exploits the absence of any U.S. legal tools for regulating published weights.
Open weights serve Beijing’s security priorities, which treat sovereignty and development as core components of its expansive view of national security. Possession of the weights is what allows government, financial, and military users to run models offline on classified data, free from a foreign provider that could cut off access at any time.
On July 16, the People’s Republic of China’s (PRC) artificial intelligence (AI) startup Moonshot AI (月之暗面) released its latest model, Kimi K3. In blind developer testing it beat every rival on a leaderboard for frontend coding (The Decoder, July 16; Tom’s Hardware, July 17). Dean Ball, a former senior policy advisor for AI and emerging technology in the White House who now heads strategic futures at OpenAI, wrote on social media that he was surprised Beijing still allows a model this capable to release with open weights (X/@deanwball, July 17). On July 27, Moonshot uploaded the full weights one day ahead of schedule (Hugging Face, accessed July 30).
A communist party-state that prioritizes control yet tolerates and encourages open weight models may look strange. Beijing’s bet on open weights, however, is part of a national strategy in which supporting open weights acts as a hedge against U.S. computing export bans, widens its domestic AI chip manufacturing ecosystem, and brings PRC technical standards to Global South countries. Beijing has not ignored the security risks that open weight models may have, and may introduce a “tiered governance” (分级管理) framework to balance these risks going forward.
A Gift to the Global South
At the World Artificial Intelligence Conference (世界人工智能大会) in Shanghai in July, 29 countries signed on as founding members of a new World AI Cooperation Organization (世界人工智能合作组织). Headquartered in Shanghai, this new institution aims to close the “intelligence gap” (智能鸿沟) for developing countries, through a set of promises detailed in Xi’s speech to the conference and an eight-point Action Plan from the National Development and Reform Commission (Belt and Road Portal; Xinhua; NDRC, July 17; China Brief, August 2, 2025, July 22, August 12).
The approach resembles one Beijing took more than a decade ago when it established the Asian Infrastructure Investment Bank (AIIB). As in 2014, Beijing is creating a multilateral institution that will provide resources to support the development of Global South countries before Washington or other geopolitical actors propose an alternative. With the AIIB, the key resource was development finance; with WAICO, the main provision is model access. Unlike the complex processes involved in releasing financing to fund projects, however, this time, the benefits have already been handed over. Downloads of PRC open models surpassed downloads of U.S. models for the first time in 2025, and uptake across Africa and Latin America has been quick (RAND, January 14; MIT Technology Review, April 21). Singapore’s national AI program built a recent model on Alibaba’s Qwen (Reuters, January 24). And Qwen has since spawned more than 100,000 derivatives on Hugging Face, making it the largest model ecosystem on that platform (U.S.-China Economic and Security Review Commission [USCC], March 23).
The PRC’s interest in supporting Global South countries is evident across government documents, media commentary, and academic publications. Along with mentions in both Xi’s speech at the WAIC and the NDRC’s eight-point action plan, the 2023 Global AI Governance Initiative called for “[e]fforts to conduct international cooperation with and provide assistance to developing countries, to bridge the gap in AI and its governance capacity” (面向发展中国家的国际合作与援助,不断弥合智能鸿沟和治理能力差距), and the State Council’s 2025 “AI+” action plan called for “helping Global South countries strengthen their AI capabilities” (帮助全球南方国家加强人工智能能力建设) (Office of the Central Cyberspace Affairs Commission, October 18, 2023; State Council, August 27, 2025). Numerous articles in official media reiterate these points (People’s Daily, August 2, 2025, July 20, July 24).
One recent academic article is more explicit about the strings that are attached to Beijing’s offer of high-performance open weights models as a form of “digital public good” (数字公共产品). Zhang Huibin (张惠彬), a professor at Southwest University of Political Science and Law (西南政法大学), argues that it will lead countries to “naturally accept the technical standards and governance norms that come with it” (同时自然接受与之配套的技术标准和治理规范). Zhang calls this approach “using technology to carry rules” (以技术带规则) and appreciates that it is “more sustainable and more persuasive than exporting rules on their own” (比单纯的规则输出更具可持续性和说服力) (Zhang and Xu, June 2026). [1]
Open Weights Suit Beijing’s Compute Lag
Beijing is betting on open weights because it lags the United States in terms of computing power. DeepSeek founder Liang Wenfeng (梁文峰) told investors in May that the PRC has only five percent of U.S. compute, a gap that puts it two years behind (Github, accessed August 1). Tang Jie (唐杰), a cofounder of Zhipu AI (智谱; also known as Z.ai), has made a similar point, stating that the gap between PRC and American large models in terms of both performance and compute may not have narrowed at all (PEdaily, January 11). In terms of capital expenditure, that gap may even be widening: the four largest U.S. technology companies spent at least $350 billion on AI in 2025, while their Chinese counterparts together invested under $40 billion (USCC, March 23).
Beijing cannot pile up hardware in the way its peer competitor does, so it compensates in software, releasing its models and letting developers around the world improve them. This offsets some of the U.S. export controls on advanced AI chips. Zheng Xiaolong (郑晓龙) of the Chinese Academy of Sciences describes the result as a PRC path in which “the government sets the stage, the market operates, and research does the heavy lifting” (政府搭台,市场运作,科研攻坚), securing technological autonomy while activating a global innovation network via an open-source community (People’s Tribune, June 18, 2025).
Open weights can also solve problems for PRC domestic AI chips. Liang says that domestic products are “rapidly dismantling” (快速瓦解) the moat Nvidia’s CUDA ecosystem has been able to maintain until now, though production capacity remains a constraint, with four Huawei chips needed to match the capability of a single Nvidia one (Github, accessed August 1). When the weights are published, domestic chipmakers can optimize for the model directly, which decouples software from hardware. Washington can control exports of advanced chips, but it cannot impact the software ecosystem growing around PRC chips.
Washington currently has no legal tool for controlling model weights. The Framework for Artificial Intelligence Diffusion, issued in January 2025, imposed a worldwide licensing requirement on the weights of advanced closed-weight models while leaving models whose weights had been published untouched (Federal Register, January 15, 2025). The rule was rescinded two days before it was due to take effect, however, and no alternative has appeared to replace it (Akin, May 16, 2025). PRC legal scholars have noticed. In their view, uploading weights to platforms like Hugging Face now still counts as publishing the weights under U.S. laws, which permits PRC models to “spread around the world without and barriers and become a source of technological spillover that the American regulatory system finds hard to block” (能够在全球范围内无障碍扩散,成为美国监管体系中难以堵截的科技溢出源) (Zhang and Xu, June 2026). [2]
Even without a push from Beijing, PRC firms have their own reasons to go with open weights. Li Zixuan (李子玄), Director of Product and genAI Strategy at Zhipu, says the company’s flagship model was closed-source in 2024, but the release of DeepSeek’s R1 model led to a change in the Zhipu leadership’s mindset. He said in an interview that “[w]e realized that you can be really famous for open sourcing your model while getting some business return through API or other collaborations. You need to expand the cake first and then take a bite of it.” He added that the choice also involves gaining trust. As a PRC company, he says, Zhipu has to be open or it will not get into the American market at all, since “people just don’t accept your API” (ChinaTalk, November 21, 2025). [3]
Tiered Approach to Balance Security and Development Goals
On face value, releasing open weights models still appears antithetical to the aims of an authoritarian regime. Once the weights are published they cannot be recalled, and after the files have been modified and passed along, neither the developer nor the regulator can see where they went. PRC scholars recognize this. Gu Lingyun (辜凌云) of Beijing University’s School of Intelligence Science and Technology voiced the same worry at a roundtable convened in May by the Intellectual Property Court of the Supreme People’s Court (PRC Supreme Court, May 24).
Resolving this apparent contradiction requires understanding Beijing’s conception of security, which is expansive and its deeply integrated with development and sovereignty (Wang, 2022). [4] At the same roundtable, Gu Lingyun described open weights in the PRC as “digital infrastructure carrying implications for sovereignty” (具有主权意涵的数字基础设施) (PRC Supreme Court, May 24). Relying on foreign closed models means handing critical systems over to an external black box. Data leaves the country, oversight is impossible, and users are vulnerable to the model’s proprietor who can cut off service at any time. Switching to a domestic closed model solves the first two of these challenges, but not the third (Zhang and Xu, June 2026). [5] For Beijing, only possession of the weights allows the government, finance, and military to deploy models entirely offline and to test and fine-tune on classified data. Viewed in this way, open weights align with Beijing’s national security priorities perfectly well.
The current scale of the PRC’s most advanced models also means that publishing the weights changes little, according to a senior machine learning engineer at Zhipu (Author’s interview, July 17). This is because most people lack the compute to deploy the models at any scale that would threaten PRC national security, and the one actor with that capacity, the United States, already fields stronger models of its own.
Beijing has not left open weight models entirely uncontrolled. Several prominent experts have argued in recent years for tiered and classified regulation, including Zhang Huibin, Zhou Hui (周辉) of the Chinese Academy of Social Sciences, who led the drafting group for the Model Law on Artificial Intelligence (人工智能示范法); and Zhang Linghan (张凌寒), director of the Institute of AI Law at China University of Political Science and Law. [6] Some scholars, such as Huang Li (黄丽), go further. In research supported by a major National Social Science Fund project, Huang calls for the government to create a negative list for open-sourcing models that carry national security risks, under which any model whose weights could be used to work out how to synthesize the components of biological or chemical weapons, or whose published parameters could be used to find system vulnerabilities, should be barred from publishing weights (Huang, 2026). [7]
The idea of a tiered classification system is beginning to gain traction. At the Supreme People’s Court roundtable mentioned above, Chen Bing (陈兵) of Nankai University proposed a three-tier scheme of controls. Under Chen’s proposal, basic and general-purpose open-source technology would be handled through a regulatory filing process; strategic and frontier open-source technology would face substantive export controls and be required to undergo security assessment; and core technology bearing on national security would in principle not be open-sourced at all, or would be opened only in a limited way within a strictly controlled scope (PRC Supreme Court, May 24). By late July this logic was being explained to ordinary audiences nationwide by Yuyuan Tantian (玉渊谭天), a commentary account run by CCTV (Sina Finance, July 27).
Conclusion
Beijing’s choice for supporting open-weight models is a calculated strategy. Its domestic chips need real applications to mature, and its main competitor, the United States, has no good instrument now for controlling weights. Security concerns have not yet altered this decision, because Beijing’s view of security places importance on sovereignty and development, which open-weight models currently support. What risk remains is likely to be handled by a tiered regulatory system. For now, such as system remains a conversation among legal scholars and in the Party’s mouthpiece, but it appears to be gaining support. Although it has not yet made its way into legislation, the Ministry of Commerce has already convened Alibaba, ByteDance, and Zhipu to discuss limits on the most advanced models, and officials at those meetings raised the idea of treating the leakage or theft of AI technology as an offence under the National Security Law (Reuters, July 7).
This article originally appeared in China Brief. Check it out here!
Sunny Cheung is a Fellow for China Studies at The Jamestown Foundation.
Shijie Wang is a Deputy Editor for China Brief.
Notes
[1] Zhang Huibin [张惠彬] and Xu Lei [许蕾], “ From Open-Source Code to Open Weights: The Logical Evolution of Large Model Weight Opening and China’s Regulatory Approach [从代码开源到权重开放:大模型权重开放的逻辑变迁与中国规制路径],” Journal of University of Electronic Science and Technology of China (Social Sciences Edition) [电子科技大学学报(社科版)] 28, no. 3 (June 2026): 43–54, https://doi.org/10.14071/j.1008-8105(2026)-3007.
[2] Ibid. These views from PRC legal scholars all date from the first half of this year. By July, the discussion in Washington had shifted toward banning open-weight models by country of origin and requiring country-of-origin labeling (see Tech Startups, July 22); Supra 1.
[3] However, open weights are not yet a consensus position inside PRC technology elites. ByteDance keeps its Doubao (豆包) models closed. Alibaba has open-sourced most of the Qwen family while holding Qwen 3 Max back as a closed model sold through its API. PRC media described a disagreement inside Alibaba in January 2026, with the technical team arguing for releasing weights in full and management placing more weight on API revenue, a split that may have contributed to the departure of then Alibaba Cloud CTO Zhou Jingren (周靖人) (The Paper, January 30).
[4] Wang, Howard. 2023. “‘Security Is a Prerequisite for Development’: Consensus-Building toward a New Top Priority in the Chinese Communist Party.” Journal of Contemporary China 32 (142): 525–39. doi:10.1080/10670564.2022.2108681.
[5] Supra [1].
[6] The Model Law on Artificial Intelligence is a product of independent research at the Chinese Academy of Social Sciences instead of a legislative text drafted at the request of the NPC Standing Committee or the State Council. It came out of a major research project at the academy, “A Survey of the State of Ethical Review and Regulatory Institution Building for Artificial Intelligence in China” (中国人工智能伦理审查和监管制度建设状况调研). Its full title has always carried the words “expert draft for suggestions” (专家建议稿), and it is positioned as a reference for future legislation (see China Law Net, September 7, 2023; 21st Century Business Herald, April 16, 2024). Zhou Hui [周辉], “Legal Governance of Open-Source Artificial Intelligence Models [开源人工智能模型的法律治理],” Journal of Shanghai Jiao Tong University (Philosophy and Social Sciences) [上海交通大学学报(哲学社会科学版)] 32, no. 8 (2024): 18–33; Zhang Linghan [张凌寒] and He Jiaxin [何佳欣], “Legal Safeguards for Responsible Innovation in Open-Source Artificial Intelligence [开源人工智能负责任创新的法律保障],” Law-Based Society [法治社会], no. 3 (2025): 32–48; Zhang and Xu, “From Open-Source Code to Open Weights,” 50–51.
[7] Huang Li [黄丽], “ Uncertainty Risk Governance of Open Source Large Models [开源大模型的不确定风险治理],” Science and Technology Management Research [科技管理研究], no. 9 (2026): 181–189.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.