China has cast itself as a champion of low-cost, open-source artificial intelligence technology that it says should be made widely available to the world. It has accused the United States of “A.I. hegemonism” as the Trump administration has debated regulating Chinese open-source A.I. models.
Unlike closed systems such as ChatGPT and Claude, open models can be downloaded, modified and run by anyone, including with safeguards removed. The open approach, which is lower in cost, has won Chinese A.I. systems, made by companies like Alibaba and Moonshot, a start-up, millions of global converts, including Silicon Valley companies like Airbnb and DoorDash.
But the same openness that has helped Chinese models win influence abroad now raises concerns for Beijing, particularly about security and the potential threats the technology might pose to the Communist Party’s rule. In a speech earlier this month, China’s top leader, Xi Jinping, said that even as China supported openness in A.I., the government needed to “constantly refine measures to forestall loss of control.”
The party is concerned that the technology could be used by hackers, scammers, terrorists or other bad actors seeking to cause harm in China; that models could circumvent its tight censorship filters; and that the government could be blamed if Chinese systems spin out of control elsewhere.
The question of how much, if any, control Beijing or Chinese companies should exert over who gets to use and modify Chinese models has become more acute with the emergence of powerful homegrown A.I. systems. One is Kimi K3, released by Moonshot to the public earlier this week, which performs some tasks as well as the best models from American rivals, including OpenAI and Anthropic. Models like these could help companies write code and improve cybersecurity, but could also help hackers find vulnerabilities and exploit them more quickly.
“The Chinese Communist Party is a security-first institution, especially under Xi,” said Matt Sheehan, a senior fellow at the Carnegie Endowment for International Peace.
He said Beijing was concerned that advanced models could carry out cyberattacks or evade safeguards, or make it easier to design or create harmful new viruses or other biological agents.
“If these models do reach those dangerous capabilities, they are not going to let it be a free-for-all in terms of releasing them,” Mr. Sheehan said.
Anthropic and OpenAI say that some A.I. models are too dangerous to be developed in the open and must be tightly controlled, and have raised concerns in Washington about Chinese models. Chinese and other commentators, however, have noted that some of the most high-profile A.I. safety breaches have involved closed-source American models.
Fears About A.I. Challenging Beijing’s Grip
China’s anxiety over A.I. was on display at a recent cybersecurity conference in Beijing, where speakers warned about risks that included data breaches and deepfake images. Zhou Hongyi, an influential Chinese tech executive, cautioned the audience that China was more vulnerable than ever to cyberattacks because of the advent of breakthrough models like Mythos, an advanced Anthropic system designed to find software flaws.
The conference also discussed A.I. data poisoning, in which an attacker feeds A.I. chatbots with manipulated data that skews results. In Beijing’s telling, such tactics could be used to make A.I. systems generate politically subversive responses.
China’s Ministry of State Security in April warned about data poisoning as a threat to “political and ideological security.” It said “hostile anti-China forces,” the party’s code for the West or for human rights activists who criticize Beijing, could exploit A.I. models by training them to smear the party and government.
That could include providing information about domestic protests or facts that undermine state narratives about the far western region of Xinjiang, where China has imposed a crackdown on Muslim ethnic groups, and Taiwan, the democratically-governed island that Beijing claims is its territory.
The worst-case scenario for Beijing, when it comes to public opinion, is that “A.I. chatbots start saying things the party doesn’t want people to hear,” said Alex Colville, a cyber expert at the Australian Strategic Policy Institute.
The concern extends to “any information that loosens their monopoly on dictating what is true and what is false,” he added.
What Controls Could Look Like
Reuters and The Financial Times reported this month that China’s Ministry of Commerce had met with leading Chinese A.I. firms like Alibaba and ByteDance to discuss restricting overseas access to their top models. The ministry and companies did not respond to requests for comment.
Even the handling of Kimi K3 suggested that Chinese companies are taking things more slowly. The release on Monday of its weights — the numerical values that show how the software works — came a week after the model was launched. That is unlike other Chinese open-source models such as those developed by DeepSeek or Alibaba, which released their weights at the same time their models were unveiled.
The Power of Giving it Away
China’s long-term goal, analysts say, is to set global A.I. standards to get ahead of the United States and make the world dependent on Chinese software, hardware and data systems, which are known collectively as a stack.
“This is a once-in-a-lifetime opportunity for China,” said Kendra Schaefer, a partner at Trivium China, a research and advisory firm. “China has spent the last 20 years trying to develop a tech stack that third-party countries would find as attractive or more attractive than U.S. origin technology and that has proven very, very difficult.”
Given those stakes, China will try to thread a needle if it decides to impose restrictions on foreign access to some A.I. systems, analysts said.
That could mean limiting access to the most advanced A.I. systems for a time while leaving access to weaker models unchanged, not unlike what the Trump administration has done with Anthropic. That idea was put forward on Monday by Yuyuan Tantian, a blog linked to China’s state broadcaster.
“China supports openness, but this does not mean it advocates for the unconditional proliferation of all capabilities,” the blog said.
Beijing could also require exporters of Chinese A.I. to apply for licenses, much like how it controls exports of critical minerals and rare earth magnets, Ms. Schaefer said.
That would be in line with signals from Beijing that A.I. capabilities are strategic national assets that it is unwilling to let flow to rivals in a superpower competition. In April, Chinese regulators blocked a $2 billion acquisition by Meta of Manus, a Singapore-based A.I. company that was founded in China, after a security review concluded that foreign investment in the company should be prohibited.
How Risky is Openness?
The prospect that China might impose controls on Chinese A.I. models comes as a debate has raged in Silicon Valley about whether open-source A.I. software is inherently risky.
Earlier this month, OpenAI said two of its A.I. models went rogue and successfully hacked into Hugging Face, a digital library of A.I. software that is popular among developers.
Hugging Face said it had to deploy an open source model called GLM-5.2 made by a Chinese start-up, Z.ai, to help thwart the breach because American A.I. models carried restrictions that prevented them from taking action. GLM-5.2, which was released in June, is on the cutting edge of Chinese A.I. — it is nearly as powerful as Anthropic’s models Mythos and Fable.
“We’re all learning that secrecy is not the answer & that all defenders (not just a few selected ones) everywhere need more powerful models without restrictions, especially open ones!” wrote Clement Delangue, the chief executive of Hugging Face, on X shortly after the hack.

