Open weights, hard choices: The Chinese statecraft behind open AI
In mid-July, the Beijing laboratory Moonshot released Kimi K3, an open-weight large language model that independent benchmarks placed alongside the strongest US frontier systems, at roughly 40 per cent less than the models it rivalled. Within days, a senior White House official accused Moonshot of distilling Anthropic’s Fable and running Nvidia chips barred from export to China, raising the prospect of sanctions. The moment arrived as Beijing was institutionalising its open-source diplomacy through a new World AI Cooperation Organisation in Shanghai and an APEC ministerial statement in Chengdu endorsing ‘trusted open-source AI’.
The significance of these developments lies less in the rivalry they dramatise than in what the rivalry obscures. Openness in artificial intelligence has become an instrument of statecraft and of corporate strategy at once – for China a means of diffusion, for the US an uncomfortable choice between diffusion and containment, and, beneath both, a contest among firms over the value of a rapidly commoditising technology.
Most ‘open’ models, by the conventional definition, fall short of bring open source. What China exports are open-weight models, where the parameters are published with the training data and the code withheld. More than half of the foundation models released in 2025 came with open weights. Notwithstanding the definitional ambiguity, “open source,”or kaiyuan (开源) in Mandarin, is not a slogan the state stumbled into after DeepSeek’s breakout last year. The 2017 New Generation AI Development Plan listed ‘open source and openness’ among its four guiding principles. In 2021, the phrase entered a national Five-Year Plan for the first time, framed as self-reliance. What changed this year is the ambition. The Government Work Report of March 2026 no longer speaks of catching up, as the 2017 plan already had set the goal of drawing levels with the leading AI powers by 2020 and leading the world by 2030. But it records, as an accomplishment, that domestically made large models have led the global open-source ecosystem.
Denied the most advanced chips, Chinese laboratories possess neither the inference capacity, i.e., the computing power needed to answer millions of user queries, through paid interfaces nor a capability lead sufficient to command premium prices. The release of weights resolves both constraints, transferring the cost of serving to users while accumulating adoption. That the approach is succeeding is difficult to dispute. In 2025, China reported that it had released 1,509 of the world’s 3,755 large models, more than any other country. Alibaba’s Qwen family has overtaken Meta’s Llama in cumulative downloads, and DeepSeek, Zhipu’s GLM and Kimi ship under permissive licences, free to run. Kimi K3, comprising some 2.8 trillion parameters yet activating only a fraction at any moment, which keeps it cheap to run, indicates that the capability gap with the American frontier has contracted to a matter of weeks.
In short, a downloadable Chinese model now matches the best US models. Beijing treats open weights as a way both to circumvent export controls on proprietary technology and to shape AI standards abroad through the wide adoption of its low-cost models. However, as analysts describe it, open release is just one part of an industrial policy that covers the ‘full stack’ from chips to applications. Every layer in China is funded by state investment funds, a national computing network and many state-linked laboratories.
What it means for the rest of the world
For states that will build no frontier of their own, the consequences are more immediate than the rivalry suggests. Cost and control, not benchmark rank, usually decide technology markets. Chinese models are inexpensive, run on a user’s own hardware, and are now capable enough that even American firms are adopting them. For the rest of the world, then, a capable model that is cheap and self-hosted outweighs the best and rented ones.
Here, the philosophy of openness becomes decisive. Open weights carry the values of their makers by default – for instance, a model trained under Chinese content rules may decline to discuss Tiananmen) – such that the entity supplying the base model sets the defaults on which subsequent developers build. Although the weights are modifiable and these defaults can be edited through fine-tuning, adaptation cannot supply knowledge that was never encoded during pretraining. This generates a durable path dependency where the provider of the base that a generation fine-tunes also sets the tokenisers, licences, benchmarks, and evaluation cultures that the ecosystem inherits. At the same time, open weights are difficult to govern once released. Guardrails implemented at the application layer can be removed or bypassed when the model runs on infrastructure outside the original provider’s control.
The harder choice is being forced by American policy. The accusation against Moonshot marked a shift in vocabulary, from export control to accusations of theft, that follows from the nature of open weights themselves. Washington is internationalising the rivalry. In April, the US State Department instructed its missions to warn governments against Chinese models. It is weighing liability for firms that deploy them, and in June, it briefly barred foreign nationals from its own most capable systems. A world that split into two rival open stacks would fall hardest on countries that cannot train frontier models of their own and rely on cheap, downloadable weights.
India’s own posture, courting American compute while cautioning against Chinese applications is the hedge of a state reluctant to choose. The caution is more advisory rather than outright prohibition. For instance, the Finance Ministry has warned officials off apps such as DeepSeek, but no law prevents Indian developers from downloading Chinese open weights, and the Indian government has no ready means to stop them. India now has begun to build rather than to choose – under the IndiaAI Mission, it now funds about 20 indigenous models. It is also exploring distinct approaches towards openness with BharatGen releasing training workflows while Sarvam has published weights alone. Yet India’s dependence runs deeper than China’s. Its sovereign-AI effort relies on roughly 34,000 imported Nvidia accelerators, with practically no domestic fabrication as of now. The realistic ambition is, therefore, two-fold, to champion for standards that keep open models auditable and replaceable on national terms, and to loosen the compute dependence that caps that very leverage. For, in a contest that is not theirs, the states in the middle have reason to shape its terms rather than inherit them.
About the Author: Sruthi Kalyani is a Policy Fellow at the Centre for Society and Policy, Indian Institute of Science (IISc), Bengaluru. The views expressed are personal and do not reflect those of the organisation.