China is about to flip the script on global artificial intelligence — and not necessarily in the direction you would expect.
While the world watched the United States build walls around its most advanced models back in June, Beijing was quietly heading to the negotiating table with some of the country’s biggest tech companies. According to Reuters reporting, the Chinese government spent the past month in closed-door conversations with Alibaba, ByteDance, and startup Z.ai about restricting who gets access to their technology.
The subject of those meetings, coordinated by China’s Ministry of Commerce, was exactly that: limiting foreign access to the most powerful AI models China has to offer — including ones that haven’t even hit the market yet. The information came from three sources who spoke on condition of anonymity.
It is a shift in posture that few expected this soon. After all, the meteoric rise of Chinese AI on the global stage was built precisely on openness and affordable pricing of its models.
If these restrictions actually materialize, the main competitive advantage of this technology on the world stage could simply vanish — and the ripple effects reach far beyond the borders of the two countries locked in this standoff. 🌐
What is being discussed in Beijing
To understand what is going on, you need to look at the details of these conversations. Participants discussed imposing limits on both closed-source models and so-called open-weight models — the ones developers can download, run locally, and modify at will. On top of that, officials raised the possibility of turning any unauthorized disclosure or theft of proprietary AI technology into a crime under Chinese national security law.
On a separate front, participants also put new measures on the table to restrict which investors can fund domestic AI startups. In other words, the control would not just cover the outflow of technology but also who puts money into the ecosystem.
Worth noting: the scope of any restrictions is still being debated. Two sources told Reuters the measures might apply only to future models, not the ones already on the market. No timeline has been set, and there is no guarantee anything actually takes effect. Still, the mere fact that the conversation is happening says a lot.
The Chinese AI pyramid
How these restrictions would work in practice is still unclear, but some clues surfaced in a summary published in a journal of China’s Supreme People’s Court. The document outlined a May roundtable with Chinese legal experts on open-source AI regulation.
The proposal that emerged was a three-tier framework that works roughly like this:
- Basic open-source tools: would require only a simple registration with the government.
- More advanced technologies: would go through security reviews before release.
- The most sensitive frontier models: would be blocked from public release or restricted to domestic use only.
This framework would represent a massive reversal for Chinese AI companies, whose global gains came almost entirely from openness. Alibaba‘s Qwen series built a huge following on Hugging Face, the world’s largest open-source AI model repository. ByteDance’s Doubao is one of the dominant AI products inside China. And Z.ai’s GLM-5.2 caught the attention of American researchers by matching top U.S. models on certain benchmarks while charging a fraction of the cost for API access. 🎯
The United States went first
This story did not start in China. Late in the afternoon of June 12, Anthropic received a letter from the Bureau of Industry and Security at the U.S. Department of Commerce ordering the company to suspend all access to its Claude Fable 5 and Mythos 5 models for any foreign national — including Anthropic’s own non-American employees.
Since there is no clean way to fence off a live API endpoint by passport, Anthropic simply pulled both models offline globally within hours. It was the first time the U.S. applied export controls to an AI model already deployed, rather than just targeting the chips that train it.
The models came back online on June 30, after Anthropic retrained its safety classifiers and the Department of Commerce lifted the restrictions. Four days earlier, the same pattern had already played out with OpenAI, Anthropic’s main competitor. The company launched the GPT-5.6 Sol, Terra, and Luna models, revealing it had shown previews to the U.S. government and, at Washington’s request, initially released them to about 20 trusted partners, each individually vetted by federal officials.
OpenAI stated that government-controlled access should not become the long-term standard. An executive order from President Trump, dated June 2, had already called on developers to voluntarily submit frontier models to a federal cybersecurity review before public launch.
Beijing was watching
China had good reasons to pay attention. Officials were alarmed by the possibility that Mythos, Anthropic’s cybersecurity model restricted in June, could be reverse-engineered and used against Chinese infrastructure to exploit software vulnerabilities.
Adding to that was the concern that Anthropic might be employing spyware-like tactics to track Chinese users — a topic that gained traction on social media and heightened the defensive urgency of discussions inside the country.
Qihoo 360 founder Zhou Hongyi made the alarm explicit at the ISC.AI 2026 event in Beijing, calling on China to build a domestic equivalent while unveiling Tulong Feng, a homegrown AI vulnerability agent. The tiered framework proposed in the Ministry of Commerce discussions directly mirrors how the U.S. handled chip export controls over the past three years.
Beijing, for its part, had already been tightening the screws before any of this. Its state planning agency ordered Meta to unwind a 2 billion dollar deal for startup Manus back in April. It also began requiring Moonshot AI and StepFun to obtain government approval before accepting American capital in their funding rounds. 🚨
The escape valve is closing
The prevailing logic since DeepSeek R1 went viral in early 2025 was simple: American restrictions on frontier AI create a natural market for Chinese open-weight models.
The numbers back that up. Chinese open-weight models jumped from less than 2% of total token usage on OpenRouter — a critical global AI distribution hub — at the end of 2024 to about 61% by mid-2026. While the U.S. played defense, Beijing gained a global distribution advantage that it did not win on raw technical superiority alone.
But that logic only works if Chinese models stay open. If Beijing restricts foreign access to its frontier systems — whether closed-source or open-weight — the escape valve shuts. Z.ai’s GLM-5.2 built its entire value proposition around borderless access under an MIT license. Restricting that distribution basically cancels the proposition.
And there is a structural problem that applies to both sides: national AI restrictions do not stay national. More than two-thirds of top AI researchers working in the U.S. were trained abroad; in leading labs, the share of foreign-born talent reaches 70%, according to MacroPolo data. A nationality-based access control ends up locking out the very engineers needed to fix the vulnerabilities that motivated the control in the first place. China faces the same problem, just in reverse.
ByteDance and Alibaba are already pulling back on human-like agent features before new Chinese regulations kick in — showing that when Beijing decides to restrict a capability, it moves at a pace that does not wait for market feedback.
This could spell trouble for small labs and developers around the world who rely on and build on top of open-source technologies, since China had been leading precisely in that space. French President Macron went so far as to warn at the G7 summit that European governments would stop buying American AI products if access could be cut off overnight. Canadian Prime Minister Carney called concentrated AI dependence a strategic mistake. Both were operating on the assumption that Chinese AI was the no-strings-attached alternative.
China built its strength in global AI through openness. Now, it may be choosing the opposite path — and the entire world is going to feel the shift.
