Both Countries Built AI Gates. Both Gates Leak.
The US and China have each built gates to contain the other's AI, and the commodity now drifts through both — carried by the companies the gates were supposed to constrain.
A Microsoft executive described the arrangement in terms most companies would bury in a compliance filing.
The one company bringing those two places together is Microsoft. — Judson Althoff
The arrangement is this: Microsoft sells OpenAI's frontier models to Chinese firms through Azure data centers in Singapore, where US export controls do not reach. ByteDance alone spends more than a billion dollars a year on the service. [1] The traffic moves the other way, too. Roughly 80 percent of US AI startups now build on Chinese open-source base models, according to the US-China Economic and Security Review Commission. [2] Pinterest runs DeepSeek R-1 for its recommendation engine. Airbnb uses Alibaba's Qwen for customer service. Pinterest's CTO said open-source techniques produced models "30% more accurate than the leading off-the-shelf models." [3] Chinese models have now led global token usage for five consecutive weeks — 12.96 trillion tokens against 3.03 trillion from US rivals — offered at roughly one-tenth the cost. [4] Two directions, one dynamic. The commodity drifts west-to-east through Azure and Singapore, east-to-west through open weights and a ten-to-one cost advantage. Both governments have built gates to stop it. Neither gate holds. The congressional commission that monitors US-China security policy diagnosed the structural problem in March. Export controls target what it called the "digital loop" — restricting access to advanced chips used for frontier model training. The commission was explicit about what the controls miss.
US export controls primarily target the digital loop, restricting access to advanced chips used for frontier model training — but are not well suited to addressing the physical loop of deployment-driven data creation and accumulation across China’s manufacturing base. — U.S.-China Economic and Security Review Commission
The gate architecture does not match the threat vector. The commission said so. By summer, both governments had responded by building more gates. House committees opened investigations into American firms — Cursor, Airbnb — for using low-cost Chinese models. [5] China, meanwhile, began constructing its own mirror. Beijing is considering national-security laws to restrict API access, block model-weight downloads, and designate AI technology leaks as national-security offenses. [5] It certified nine domestic AI chips under a national-security procurement framework. [6] DeepSeek excluded Nvidia and AMD from its V4 optimization, granting Huawei exclusive early access. [7] Nvidia CEO Jensen Huang saw where this was heading.
if they can’t buy from us, they’ll build their own — and then we’ll have a competitor we wouldn’t have otherwise created. — Jensen Huang
Huawei's rotating chairman was more direct about what the gate produced.
If the US hadn't forced our country, our companies, and our industry, we wouldn't have done something like this. — Xu Zhijun
The evidence bears them out. Alibaba has delivered 560,000 Zhenwu-series domestic AI chips to more than 400 customers across 20 industries, with mass production achieved and a roadmap through 2028. [8] Zhipu AI's GLM-5.2 — an open-weight model that former Trump AI czar David Sacks acknowledged is "as good as the currently available models from OpenAI and Anthropic" — gained traction among Silicon Valley developers on OpenRouter at roughly one-sixth the cost of US counterparts. [9] Stanford's 2026 AI Index confirmed the US-China model performance gap has "effectively closed," with Anthropic holding only a 2.7 percent advantage as of March. [10] The symmetry runs deeper than the technology. In late July, OpenAI signed a coalition letter with Nvidia, Google, and 50 other companies urging the US government not to restrict open-weight models. [11] The same company has simultaneously lobbied for restrictions on Chinese open-weight models. A single company holds both sides of the gate: protect our open weights, restrict theirs. Meanwhile, Microsoft — OpenAI's largest backer and the commercial conduit through which its models reach Chinese customers — runs the Singapore pipeline that makes more than a billion dollars a year from ByteDance alone. [1] The US-China Economic and Security Review Commission identified the architectural mismatch in March: the gates target chips, but the leakage runs through open weights, API access, and distillation. Seven months later, both governments have responded by building more of the architecture that does not match the threat. And through it all, the commodity drifts both ways — OpenAI lobbied for restrictions on Chinese open-weight models while its largest backer sold OpenAI's own models to Chinese firms through Singapore. The gate and the leak run through the same companies.
- 1. Microsoft Sells OpenAI Models to Chinese Firms via Azure
- 2. US Commission Warns China's Open-Source AI Threatens US Leadership
- 3. U.S. Enterprises Adopt Chinese Open-Source AI Models
- 4. Chinese AI Models Outpace U.S. Rivals in Global Token Usage
- 5. US and China Escalate AI Conflict Over Security and Exports
- 6. China Certifies Nine Domestic AI Chips Under National Security Framework
- 7. DeepSeek Excludes US Chipmakers From V4 Model Optimization
- 8. Alibaba Unveils Zhenwu M890 AI Chip to Counter Nvidia Restrictions
- 9. Zhipu AI Launches GLM-5.2 to Rival U.S. AI Models
- 10. Stanford Report Says US-China AI Performance Gap Has Closed
- 11. Moonshot AI Releases Kimi K3 Open-Weight Model