China Weighs Export Controls on AI Models, Including Open Weight LLMs
China’s Ministry of Commerce (MofCom) is considering a significant tightening of export rules for AI and semiconductor technology. According to a report by the Financial Times, regulators have spent weeks consulting the country’s leading domestic AI and chip companies on how to prevent advanced Chinese technology and flagship start-ups from ending up in Western hands. Companies drawn into the consultations reportedly include Alibaba, ByteDance and Zhipu (Z.ai).
Two issues are at the centre of the discussions: the transfer of training data abroad, and whether foreign users should continue to be able to freely download the model weights of Chinese AI systems. Access to the models as a service — via APIs and cloud offerings — would remain available, according to the FT. What would be restricted, in other words, is not usage but possession.
The deliberations are not new; they are gathering pace. In early July, Reuters reported that MofCom, together with the planning agency NDRC, had held talks with Alibaba, ByteDance and Z.ai about limiting overseas access to China’s most capable models — explicitly including models not yet released. A tiered regime was floated: simple filing requirements for less capable open-source models, security reviews for stronger systems, and a possible ban on public release for the most capable ones. Officials also discussed treating the theft or leaking of proprietary AI technology as a violation of China’s national security law, Reuters reported.
Chip designs and acquisitions also in scope
The FT further reports deliberations on barring foreign chipmakers such as TSMC and suppliers including Qualcomm from producing advanced semiconductors based on designs developed by Chinese companies — Huawei, Alibaba and ByteDance are named. Additional restrictions could apply to foreign acquisitions of strategic technology companies, for instance in agentic AI. The trigger, according to the FT, is a loophole that Beijing believes enabled Meta’s $2bn acquisition of the agent start-up Manus — a deal Chinese authorities later ordered to be unwound.
The measures would reportedly feed into the next revision of China’s catalogue of technologies prohibited or restricted from export. Alongside two control lists covering dual-use items, that catalogue is one of the country’s three central export control regimes; its most recent revision in 2025 added several lithium-ion battery manufacturing technologies, on top of existing controls over strategically important technologies such as rare earths. The update now under discussion would be the most far-reaching in years, according to the people cited by the FT.
Nothing has been decided, however. The proposals remain at the consultation stage, with regulators weighing industry feedback. And that feedback appears to be critical: several companies have told regulators that tighter rules would slow their own development and weaken China’s chances in the global technology race, the FT reports. MofCom, ByteDance, Alibaba, Zhipu and Huawei did not respond to requests for comment from the FT.
Why open weights have become a political question
That Beijing is considering export controls on freely available models at all reflects a shift over the past 18 months. The strongest models from the US — from OpenAI and Anthropic — are closed and accessible only via API. The strongest Chinese models are the opposite: they are published as open-weight models, meaning they can be downloaded, run on a user’s own servers, fine-tuned and reused. That is precisely what has made Qwen (Alibaba), DeepSeek and Kimi (Moonshot AI) the default choice for many developers worldwide — including in Europe, where sovereignty arguments carry weight.
Moonshot AI’s latest release shows how far this has gone. On 16 July, the Beijing lab published Kimi K3, a mixture-of-experts model with 2.8 trillion parameters, natively multimodal and with a context window of roughly one million tokens. That makes it the largest open-weight model released to date; the full weights are scheduled for 27 July. Independent evaluations by Artificial Analysis place K3 near the top: it ranks third on their Intelligence Index, behind Claude Fable 5 and GPT-5.6 Sol but ahead of Anthropic’s Claude Opus 4.8 — at roughly half the cost per task. In the Frontend Code Arena on Arena.ai, K3 leads the field outright. Moonshot attributes the gains in part to architectural changes such as Kimi Delta Attention and Attention Residuals — efficiency rather than raw compute, a point analysts have highlighted in light of US chip export controls. (For context: independent testing found K3 more accurate than its predecessor, but also measured a higher hallucination rate.)
For the first time, then, a model at near-frontier level is not only cheap but also something that can be given away permanently. And that is where Beijing sees the problem: once weights are published, they cannot be recalled. API access can be switched off; a downloaded file cannot. Export controls on open-weight models therefore only work prospectively — on future releases, not on what has already been distributed.
Both superpowers are increasingly reaching for the same instrument. In the US, the Commerce Department applied export controls to Anthropic’s Fable 5 and Mythos 5 models in June, before lifting them roughly two weeks later. For European organisations that have built their AI strategies on the availability of open models from China and the US, an assumption that recently seemed self-evident is now in question: that the next generation of open weights will simply be there.

