
Chinese authorities are considering implementing new measures to restrict overseas access to the country's most advanced AI models, according to sources familiar with recent government discussions. Officials have discussed making any leak or theft of proprietary AI technology an offense under China's stringent national security law, as reported by Reuters. The scope of potential restrictions is still being discussed, with measures potentially applying only to future models, though it remains unclear when or if they would come into force. The discussions were led by China's Ministry of Commerce, with participants including tech giants Alibaba Group Holding Ltd and ByteDance Ltd, as well as start-up Z.ai, formerly known as Zhipu AI. The talks follow a number of steps by Beijing to keep homegrown AI technology in the country and underscore how China, like the US, is now treating cutting-edge artificial intelligence as a critical national asset that needs controls.
The U.S. State Department formally stated on July 8 that the use of Chinese AI models by American companies "raises serious concerns," citing models designed to "advance Beijing's narratives, censor dissent and reflect CCP ideology and values," according to reports from CNBC. The same day, the House Committee on Homeland Security and the House Select Committee on China launched a joint investigation targeting Airbnb and Anysphere (maker of AI coding tool Cursor) over their use of Chinese AI in production systems. The investigation, launched in April 2026, examines whether "software systems used across the American economy, government, and defense industrial base will come to depend on models developed by PRC-linked laboratories." Daniel Remler, a senior fellow at the Center for a New American Security, told CNBC that the most likely near-term mechanism is procurement requirements: discouraging companies that want to do business with the federal government from using Chinese AI models. The National Defense Authorization Act for Fiscal Year 2026 already instructs the Secretary of Defense and the Director of National Intelligence to remove and exclude any AI developed by DeepSeek from DoD and intelligence community devices and contractor systems.
Tang Jie, founder of Chinese AI lab Zhipu, argued that frontier artificial intelligence should remain broadly accessible rather than controlled by select individuals, according to reports from Bloomberg News. Writing in an internal staff memo, Tang stated that genuine security stems from broad participation, sharing and oversight rather than technological barriers. As part of this approach, his company released its cutting-edge GLM-5.2 under an open-source license free for users to download, modify and commercialize. The company, known also as Knowledge Atlas Technology JSC Ltd., chose to challenge the limits of intelligence while making frontier capabilities as open and widely accessible as possible. Tang Jie, who also teaches at Tsinghua University, emphasized that meaningful AI safety comes from broad participation, transparency and public oversight rather than limiting access to advanced models, reflecting his commitment to open-source principles.
Booz Allen Hamilton conducted the most comprehensive study to date, running over 2,800 trials against five frontier code-generation models in May 2026, according to CNBC reports. Three of the four Chinese models produced significantly more vulnerable code when the prompt identified the user as working for a U.S. government contractor; Alibaba's Qwen3-Coder added roughly 130 percent more vulnerabilities under the government persona than under a neutral one. All four Chinese models declined to execute tasks touching subjects Beijing considers politically sensitive, with refusal rates ranging from 8 percent (DeepSeek) to 80 percent (MiniMax). Booz Allen explicitly stated: "We do not have proof at this point that code flaws are intentionally introduced," noting that the vulnerabilities were "highly obfuscated" beneath code that appeared syntactically correct. The study found that Chinese models trailed U.S. capabilities by an average of seven months since 2023, with Stanford's 2026 AI Index documenting an overall capability gap of 2.7 percentage points between the best American and Chinese models.
Chinese AI models now handle nearly half of all enterprise API traffic passing through U.S. developer platforms, as reported by CNBC. On the day of the State Department statement, Chinese AI models' share of tokens routed through OpenRouter stood at 45 to 46 percent, representing a tenfold increase from the 4.5 percent average recorded in the first half of 2025. The price gap explains the shift: Chinese models charge approximately 18 cents per million tokens against a roughly $4-per-million average for comparable U.S. frontier models. Zhipu AI's GLM-5.2 costs $1.40 per million input tokens and $4.40 per million output tokens, while Anthropic's Opus 4.8 lists at $5 per million input and $25 per million output — roughly six times more expensive on the output side. Coinbase CEO Brian Armstrong announced that his company had cut its AI bill nearly in half by routing its 1,200-plus AI agents to two Chinese open-weight models: Zhipu AI's GLM-5.2 and Moonshot AI's Kimi K2.7 Code. Any decision by Beijing to limit access to those products could ripple across AI markets, as costs for many businesses would likely increase.
The most significant constraint is technical: Chinese AI models released as open-weight systems cannot be recalled once published, according to CNBC reports. A U.S. company that has already downloaded GLM-5.2 or DeepSeek V4-Pro to its own servers for local inference is beyond the reach of any import restriction on that specific download. Legal experts have raised First Amendment questions about restricting access to already-published model weights, citing the established principle that software code can constitute protected expression. China's National Intelligence Law (2017), Article 7, states that all Chinese organizations and citizens "shall support, assist, and cooperate with national intelligence efforts in accordance with law," and the 2014 Counter-Espionage Law requires relevant organizations to provide information to state security organs truthfully and "may not refuse". The government has stronger ground to prohibit API routing through Chinese endpoints where live data flows to Chinese-jurisdiction infrastructure than it does to prohibit use of already-downloaded weights.