Key Takeaways
- US export controls are expanding from advanced chips to frontier models, model weights and distillation.
- Tighter restrictions on US models could increase global demand for cheaper, open-weight Chinese alternatives.
- Enterprises should assess each model’s capabilities, provenance and risk rather than relying on its country of origin.
US export controls once concentrated on advanced chips and manufacturing equipment, but in 2026, Washington’s attention has widened to model access, model weights, distillation and Chinese open-weight systems.
Anthropic took its Fable 5 and Mythos 5 models offline in early June after the Trump administration directed it to prevent their use by foreign nationals — a decision that was reversed on June 30.
Meanwhile, a White House order also established classified benchmarks for “covered frontier models” and a voluntary process for giving the government and trusted partners early access.
Models with advanced cyber capabilities could be abused, while extraction can transfer expensive intellectual property to rivals. Yet controls intended to protect the US may also make cheaper, more open Chinese alternatives more attractive abroad.
US Policy Shifts From Hardware to Frontier Models
A Senate Intelligence Committee bill would make it US policy to restrict adversaries’ access to the most sophisticated American chips and models while exporting the full US AI stack to allies meeting strict security standards.
Another House bill would expose foreign entities that illicitly access US models to export controls and sanctions.
Washington must balance three goals:
- Keeping dangerous capabilities away from adversaries
- Protecting model weights and intellectual property from extraction
- Preserving global demand for US models and AI services
Tim Law, IDC research director for AI and automation, warned of a competitive cost, pointing out the frontier model landscape is “truly globalized” at this point.
“Countries that erect barriers will put their companies and their countries at risk of falling behind in AI, which would have potentially devastating economic consequences.”
Paul Bischoff, consumer privacy advocate at Comparitech, added that foreign developers may not face the same limits.
“The idea is that the frontier models can overcome the cybersecurity risks posed by former models. AI companies in other countries might not follow the same restrictions, which could make them more competitive,” he said.
US Restrictions Could Boost Chinese AI Rivals
“I believe this is a false dichotomy. The future AI, frontier model and agentic landscape will be varied, with all types and sizes of models from all different geographies, with varied architectures and a huge variety of AI agents.”
- Tim Law
Research Director for AI & Automation, IDC
Chinese developers increasingly compete on openness, deployment flexibility and price. Models like DeepSeek are proving particularly appealing in developing markets because they are often more affordable than largely closed US offerings.
Moonshot AI’s Kimi K3, for example, adds lower costs and downloadable weights to near-frontier performance. (Though some skeptics — including the US government — are claiming Moonshot distilled Anthropic’s Fable 5 for its Kimi K3 model.)
We have information that Moonshot AI distilled Anthropic’s Fable for the development of its K3 model.
— Director Michael Kratsios (@mkratsios47) July 22, 2026
To do this they developed a sophisticated internal platform to conduct large scale distillation against U.S. models, allowing them to quickly switch between multiple methods of…
If customers face barriers to capable American systems, they have an incentive to build around alternatives. Each deployment expands a rival ecosystem of developers and applications.
Law said he rejects the assumption that one national ecosystem will displace the other.
“I believe this is a false dichotomy. The future AI, frontier model and agentic landscape will be varied, with all types and sizes of models from all different geographies, with varied architectures and a huge variety of AI agents.”
From his perspective, the long game is a global market, as has been seen with other technologies.
“The important factor here is not necessarily dominance, but parity,” he said.
Chip Controls Push China Toward AI Self-Reliance
Chip restrictions have increased the incentive to improve domestic hardware, train efficiently and release open models that do not depend on a US vendor’s API.
Denying advanced chips can raise costs and slow development. It also pushes Chinese companies toward efficiency, domestic supply chains and models that perform on less capable infrastructure.
The result could be two increasingly self-reliant stacks within a market that still mixes both. China is promoting its systems abroad, while US policymakers consider procurement rules, sanctions and other barriers.
Bischoff said overtaking American developers would require less reliance on US systems.
“Chinese competitors would have to stop using distillation to surpass American counterparts. If they can do that, and the US heavily regulates AI and data centers, then Chinese AI companies could surpass them,” he said.
Distillation Claims Intensify the US-China AI Fight
Distillation can legitimately transfer capabilities from a larger model to a smaller one. US officials and AI companies contend it can also copy frontier models at a fraction of the original development cost.
A House investigation launched in April focused on claims that Chinese companies used proxy accounts and access-control evasion to extract capabilities from US models. Anthropic, for example, has accused three Chinese AI companies — Moonshot AI, DeepSeek and MiniMax — of running large-scale distillation attacks, claiming the labs generated more than 16 million exchanges with Claude through around 24,000 fraudulent accounts.
We’ve identified industrial-scale distillation attacks on our models by DeepSeek, Moonshot AI, and MiniMax.
— Anthropic (@AnthropicAI) February 23, 2026
These labs created over 24,000 fraudulent accounts and generated over 16 million exchanges with Claude, extracting its capabilities to train and improve their own models.
Bischoff explained many Chinese alternatives train their AI using distilled information from American AI models. “Rather than answering prompts based on primary-source data, it answers based on answers given by ChatGPT, for example.”
For enterprises, national origin is not a security control. Law’s recommendations offer a best practices baseline:
- Treat every model, agent and physical robot as untrusted by default
- Grant each system only the access required for its assigned task
- Track model provenance, training methods and potential IP exposure
Law says enterprises should assume a zero-trust posture and follow least-trust principles with any AI, whether a model, an agent or a physical robot.
“Model distillation can be employed as a technique for intellectual property theft,” said Law.
“We will have to develop an entirely new international legal framework to deal with these types of attacks.”
Why Nationality Is a Poor Measure of AI Risk
“Frankly, there are no such things as ‘Chinese models’ and ‘US models.’ The categories are somewhat meaningless."
- Tim Law
Research Director for AI & Automation, IDC
Weak controls could expose frontier capabilities and American intellectual property, while controls that are too broad, opaque or slow could shrink the international market for US models while accelerating demand for Chinese alternatives.
The White House order, for instance, creates a secure early-access framework but stops short of mandatory licensing or preclearance.
For business leaders, the risk is in assuming every American model is safe or every Chinese model is unsuitable.
Analysts say each must be evaluated against its workflow, deployment environment, data sensitivity and autonomy. Law said model-level scrutiny is more useful than a flag attached to the developer.
“Frankly, there are no such things as ‘Chinese models’ and ‘US models.’ The categories are somewhat meaningless,” he said. “You need to look at the specific model, the specific version, its capabilities, its architecture, its training and its risk profile.”
Editor's Note: For more on the China-US AI skirmish…
- White House Accuses China's Moonshot AI of Stealing Anthropic's Fable Model Through Covert Distillation — White House accuses Moonshot AI of distilling Anthropic's Fable for Kimi K3 — days after Anthropic's own $1.5B copyright settlement.
- Kimi K3's 2.8T Open Model Exposes the Fragile Economics Behind AI's Business Model — If a free model can match Claude and GPT, who pays for the $250 billion in data centers being built to run them?
- AI Model Prices Are Falling At The Worst Moment For The US Frontier Labs — The price war is on. What happens to OpenAI and Anthropic?