A Fee for China's Chips, a Police Force for Its Models
Washington charges a 25 percent fee for the AI chips it treats as threats, and saves its real policing for a different boundary: the market share of Chinese AI models.
Since August 2022, U.S. export rules have barred Nvidia from selling its most advanced AI chips to Chinese companies on national-security grounds [1]. Since October, those chips have carried a posted price instead. Under the truce Donald Trump and Xi Jinping struck that month, an arrangement the two governments tied to their critical-minerals and rare-earth disputes, Washington postponed for a year the rules that ban technology shipments to thousands of Chinese companies. It also conditionally cleared three of the largest — Alibaba, ByteDance (TikTok's parent) and Tencent — to buy more than 400,000 of Nvidia's H200s (among the most powerful AI chips on the market), in sales worth up to $16 billion [2][3]. The fee to cross is 25 percent. The president announced the terms himself.
I have informed President Xi, of China, that the United States will allow NVIDIA to ship its H200 products to approved customers in China, and other Countries, under conditions that allow for continued strong National Security. — Donald Trump
Enforcement of the arrangement belongs mostly to the seller. The license terms carry a Know-Your-Customer mandate, assigned in this case to the chipmaker itself. Commerce Secretary Howard Lutnick described who put the terms together in February.
The license terms are very detailed. They've been worked out together with the State Department, and those terms Nvidia must live with. — Howard Lutnick
John Moolenaar, the Michigan Republican who chairs the House committee on China, argues that chips sold to nominally civilian Chinese users end up in military hands no matter what the license says [2].
If even the world’s most valuable company cannot rule out the military use of its products when sold to (Chinese) entities, rigorous licensing restrictions and enforcement are essential to prevent such assurances from becoming superficial formalities. — John Moolenaar
The traffic that crosses without a license has a case history of its own. In August 2025, the Justice Department arrested two Chinese nationals who ran ALX Solutions, a California company, on charges of at least 20 unlicensed shipments of Nvidia chips to China between October 2022 and July 2025, routed through Singapore and Malaysia to hide where the cargo was headed [4]. This August, the Commerce Department opened an investigation into Apex Logistics, a freight forwarder owned by the shipping giant Kuehne+Nagel, over 47 shipments of American AI hardware that reached China in 2024 on false paperwork routed through Hong Kong. It is the first attempt to hold a transport company accountable. The American manufacturers whose hardware moved are not accused of wrongdoing [5]. And the Bureau of Industry and Security, the Commerce Department office that administers the chip rules, has found Chinese firms including Alibaba accessing restricted chips remotely, through Singaporean shell companies renting capacity in foreign data centers. Whether the rules can reach remote cloud access at all is contested, and a bipartisan Senate bill to close the gap is still pending [6]. All of it arrives after the cargo has moved, and every defendant or subject is an intermediary: a broker, a forwarder, a shell. The boundary that gets policed ahead of time is a different one. Washington first leveled the accusation in an April memorandum that named DeepSeek, Moonshot AI and MiniMax as industrial-scale extractors of American models [7]. On September 13, three federal security agencies, the NSA, CISA and the FBI, jointly accused six Chinese AI firms of stripping capability worth billions of dollars through bulk distillation [8]. The document is an advisory: an accusation with agency letterhead and no statute behind it. House committees have opened investigations into two American companies, the AI-coding firm Cursor and Airbnb, for building products on low-cost Chinese models, on the stated ground that the choice advances Chinese Communist Party ideology [9]. The National Archives, meanwhile, was running a Federal Register search tool on Alibaba's Qwen model until it was pulled after social-media exposure this week [10]. Washington's idea of a blanket ban on the models has run into two obstacles. A 1965 Supreme Court ruling, Lamont v. Postmaster General, protects Americans' right to receive foreign materials. And the models are open weights. The instrument under discussion is therefore the money: restrictions on payments between American users and Chinese developers, a commercial tool for a problem described in security language [11]. None of this makes the danger imaginary. Federal testers at NIST, the national standards institute, found that AI agents built on DeepSeek followed malicious instructions 12 times as often as American models did. The government's own threat assessment, though, is denominated in market share: the U.S.-China Economic and Security Review Commission, Congress's China assessment panel, warned in March that Chinese open-source models threaten American leadership and noted that roughly 80 percent of U.S. AI startups now build on Chinese open-source base models. The same report conceded that export controls are a poor fit for the way Chinese AI actually advances, which runs through deployment and data rather than the chips the rules restrict [12]. The instruments point where the assessment puts the threat. Through all of that, no American ban on the models ever became law. DeepSeek's app downloads fell from 171 million in 2025 to 35 million in the first half of 2026, as mainstream consumers and large enterprises moved to American providers. Developers, meanwhile, kept using the Chinese models privately, because they cost less [13]. The downloads moved. The legislation never did. The plainest statement of the stakes has come from the Treasury.
If they were to pull ahead of us on AI, then nothing else matters. — Scott Bessent
The next instrument being weighed fits that scoreboard exactly. The payments ban is the one tool in the set built to act before anything happens and to keep acting: a switch on the money between American users and Chinese developers, not a gate on the traffic [11]. Whether the courts let money be switched off where speech could not be banned is the question the instrument will eventually put to them.
- 1. U.S. AI Chips Smuggled Into China Despite Export Controls
- 2. US Lawmakers Accuse Nvidia of Aiding Chinese Military AI
- 3. Commerce Secretary Lutnick Orders Nvidia to Follow China Chip Rules
- 4. US Arrests Two Chinese Nationals for Illegal AI Chip Exports
- 5. US Investigates Apex Logistics for Smuggling AI Chips to China
- 6. U.S. Reviews Chinese Access to Restricted Nvidia Chips
- 7. U.S. Accuses Chinese AI Firms of Industrial-Scale Model Theft
- 8. U.S. Agencies Accuse Chinese AI Firms of Model Distillation
- 9. US and China Escalate AI Conflict Over Security and Exports
- 10. National Archives Removes Alibaba AI Tool From Federal Register
- 11. US Debates Legal Feasibility of Banning Chinese AI Models
- 12. US Commission Warns China's Open-Source AI Threatens US Leadership
- 13. Governments Bar DeepSeek AI Over Chinese State Censorship