AI Policy16 min

The Month China Almost Locked Down Its AI Models — and Then Didn't

September 29, 2026·AI in China
The Month China Almost Locked Down Its AI Models — and Then Didn't

The Deadline That Wasn't

On the last working day of September 2026, nothing happened.

No press release. No amendment to the Catalogue of Technologies Prohibited from Export. No joint announcement from the Ministry of Commerce and the Ministry of Science and Technology. No statement from the State Council. Not even a carefully worded denial.

The silence was, in its own way, a decision.

For three months, China's Ministry of Commerce (MOFCOM) and the National Development and Reform Commission (NDRC) had been holding closed-door consultations with the country's most important AI companies — Alibaba, ByteDance, Zhipu AI, and others — about a policy that would have fundamentally altered the global AI landscape: restricting overseas access to China's most advanced artificial intelligence models, including the open-weight systems that have powered the country's extraordinary global expansion.

The September decision window — the period analysts had circled for a formal amendment to the export catalogue — closed without a single public word. As of September 24, 2026, no formal announcement had been made. No new timeline was issued.

MOFCOM did release one statement in late September. It was not about export controls. It was about the United States: the ministry called Washington's allegations of industrial-scale distillation by Chinese AI labs a case of "technological hegemony," signaling that bilateral talks on the issue had stalled.

So the question hangs in the air, unanswered: did Beijing blink? Or is it simply reloading?

The answer matters enormously — not just for the future of Chinese AI, but for the structure of the global technology order. Because what Beijing was considering was not a minor regulatory adjustment. It was the AI equivalent of what the United States did with advanced semiconductors: declare a layer of the technology stack a strategic asset, and place it under state control.

What Was on the Table

The proposal under discussion, first reported by Reuters in July 2026 and subsequently confirmed by multiple outlets, was architecturally sophisticated. It was not a blanket ban. It was a tiered regime — the same regulatory architecture Beijing has applied to drones, rare earths, and outbound investment.

TierModel CategoryProposed Treatment
Tier 1Basic open-source modelsSimple filing requirements for overseas release
Tier 2Advanced open-weight modelsSecurity review before foreign distribution
Tier 3Frontier / most capable modelsPossible ban on public overseas release; domestic use only

The consultations went further than models. Regulators also discussed whether theft or unauthorized disclosure of proprietary AI technology should be classified as a violation of China's national security law — elevating what in the corporate world would be a trade-secret dispute into a matter of state security. Additional scrutiny of foreign investment into Chinese AI startups was floated as a parallel track.

The institutional machinery for implementation already existed. MOFCOM had quietly amended the Catalogue of Technologies Prohibited and Restricted from Export three times since 2020 — most recently in 2025, when it added battery cathode preparation technology. Adding "advanced large language models" to that list requires only a joint MOFCOM–MOST announcement and State Council sign-off. The legal pathway was clear, short, and well-traveled.

What was unusual was that Beijing didn't take it.

The Reason in the Numbers

To understand why the decision window closed empty, look at the financial data that was accumulating on the other side of the ledger.

China's frontier AI labs have been quietly building something unprecedented: a business model that depends on foreign demand. Not as a luxury. As a lifeline.

LabOverseas Revenue ShareSource Period
Moonshot AI (Kimi)Over 50%Since end of 2025
Kuaishou (Kling AI)75% of ARRThrough March 2026
MiniMax61% of total revenueH1 2026

These are not marginal exports. For Kling, the AI video generator that competes with Runway and Google Veo, three-quarters of annual recurring revenue comes from customers outside China. Moonshot, the maker of the Kimi model family, crossed 50% overseas revenue late last year and has been negotiating revenue-sharing agreements with Microsoft, Amazon, and Google — deals in which Moonshot's share could reach 30% of the revenue generated by its open-weight models on Western cloud platforms.

The aggregate picture is striking. Total ARR for all of China's AI models stood at approximately $10.7 billion as of the latest available data — roughly 10% of the combined revenue of OpenAI and Anthropic. Small in absolute terms, but growing fast. Zhipu's model-as-a-service ARR surged twenty-fold from $74 million in January to $1.6 billion in August 2026. MiniMax's ARR quadrupled in the same period.

The equity markets have noticed. PE/VC investment, IPO inflows, and private placements into Zhipu, MiniMax, DeepSeek, and Moonshot totaled 179 billion yuan in the first eight months of 2026 — twenty times the 9 billion yuan invested in all of 2025. Moonshot's reported valuation soared from $4 billion at the end of 2025 to $50 billion by August.

Two hands in a business handshake — the financial stakes in China's AI export deliberations involve billions in overseas revenue and hundreds of billions in market value

Now consider what export controls would do to that trajectory. If downloading Chinese model weights from Hugging Face required a MOFCOM security review, every enterprise customer in San Francisco, London, and Tokyo would face a choice: navigate an opaque Chinese regulatory process, or switch to an American model. The switching cost might be tolerable for a startup. For a Fortune 500 company building production systems on Qwen, it would be a compliance nightmare.

The labs understood this. They were, by all accounts, not enthusiastic participants in the consultations.

The Contradiction at the Heart of Chinese AI

There is a deeper tension that the export control deliberations forced into the open — one that goes to the identity of Chinese AI itself.

At the World AI Conference in Shanghai in July 2026, China positioned itself as the global champion of open-source AI. President Xi Jinping personally promoted China's open-weight AI leadership. The World AI Cooperation Organization (WAICO) was founded as China's institutional vehicle for promoting open AI access globally. The narrative was clear: while America hoards its frontier models behind APIs and export controls, China shares its intelligence with the world.

Simultaneously, Beijing was meeting with Alibaba and ByteDance to discuss restricting overseas access to those same models.

The Openness NarrativeThe Control Reality
Xi promotes open-weight AI leadership at WAIC 2026MOFCOM/NDRC consultations on restricting model exports since July
WAICO founded to promote global open AI accessTiered regime would require security reviews for advanced open models
Qwen surpasses 1 billion Hugging Face downloadsQwen derivatives (113,000+) could face foreign distribution restrictions
Chinese models hold 5 of top 10 open model slotsFrontier models (Tier 3) could be banned from overseas release entirely
OpenRouter: 61% of token consumption is Chinese modelsAPI access preserved, but weight downloads potentially controlled

This is not hypocrisy, exactly. It is something more interesting: the institutional contradiction of a great power trying to be both the world's AI supplier and its own AI sovereign. The openness generates influence, adoption, and developer loyalty — a soft-power empire built on free weights. The control instinct reflects a legitimate strategic concern: if your most capable models are available for download by any adversary, have you given away your edge?

Washington faced the mirror-image dilemma in June 2026, when it ordered Anthropic to suspend global access to its Fable 5 and Mythos 5 models for 19 days before partially restoring availability. The world's two largest AI powers are discovering the same uncomfortable truth: models are simultaneously commercial products and strategic assets, and treating them as both at once may be impossible.

The Labs in the Middle

For the companies caught in these consultations, the stakes are existential in a very literal sense.

Alibaba's Qwen is the most important open-model franchise in the world. It has surpassed 1 billion cumulative downloads on Hugging Face, overtaking Meta's Llama as the most-downloaded open model family. More than 200,000 Qwen-tagged models and over 113,000 derivatives populate the hub — more than Google and Meta's base families combined. Roughly 40% of all new LLM derivatives created on Hugging Face are Qwen-based. China accounted for approximately 41% of all Hugging Face downloads over the trailing year.

An export control regime that restricted Qwen's foreign distribution would not just hurt Alibaba's cloud business. It would fragment the global open-source AI ecosystem overnight — forcing developers, startups, and enterprises across every continent to either find alternatives or navigate Chinese export licensing.

MetricScale
Qwen cumulative Hugging Face downloads1 billion+
Qwen-tagged models on Hugging Face200,000+
Qwen derivatives113,000+
Share of all new HF LLM derivatives that are Qwen-based~40%
Chinese models in June 2026 HF trending top 105 of 10
Chinese share of OpenRouter token consumption61%
Chinese models in OpenRouter top 6 usage spotsAll 6

ByteDance faces a different calculus. It keeps its best models proprietary and behind APIs, monetizing attention and cloud rather than weights. For ByteDance, export controls on weights are less immediately threatening — but restrictions on API access or data transfer would strike at the core of its Volcano Engine cloud business, which has set a model-as-a-service revenue target of ¥15 billion (~$2.2 billion).

Zhipu AI, fresh from a Hong Kong IPO and a 27 billion yuan private placement, has bet its growth on enterprise API services. It also acquired AI infrastructure firm Xcore Sigma for a 1GW data center project using domestic chips — a move to improve margins while hedging against geopolitical supply-chain risk.

The labs have been hedging in other ways, too. Moonshot is reportedly in discussions with Microsoft, Amazon, and Google about revenue-sharing for its open-weight models — agreements that would formalize its overseas commercial relationships in ways that could become either protective armor or compliance liabilities, depending on what Beijing eventually decides.

The Precedent That Worries Everyone

If there is a template for what aggressive enforcement looks like, it already exists.

On April 27, 2026, the NDRC blocked Meta's acquisition of the Chinese AI startup Manus, whose parent had reincorporated in Singapore in what Beijing viewed as an attempt to bypass restrictions. A week later, the State Council issued Decree No. 837 on Outward Investment, establishing sweeping scrutiny of any outbound investment touching "Chinese-linked assets, goods, technology, personnel, or training." Penalties reach 10% of deal value, with personal criminal liability for executives.

The architecture of the proposed AI model controls — filing at tier one, security review at tier two, domestic-only at tier three — is the same architecture applied one level up the stack. The legal precedent is set. The machinery is tested. What is missing is only the trigger.

Washington's own behavior has provided additional ammunition. In 50 days spanning June and July 2026, the US suspended and restored Claude Fable 5, accused Alibaba of running a 25,000-account distillation ring, and watched as China's labs shipped GLM-5.2 and Kimi K3 open weights into the gap. US companies including Cursor and Cognition reportedly trained on Qwen and DeepSeek — a practice that MOFCOM's September statement on "technological hegemony" explicitly referenced as a grievance.

Three Scenarios for What Comes Next

The empty September window does not mean the question is dead. Analysts tracking the deliberations have mapped three plausible paths.

ScenarioProbabilityWhat It Looks Like
Status quo hold40%Beijing maintains ambiguity indefinitely. No formal rule, but tacit pressure on labs to coordinate major releases. The threat itself becomes the enforcement mechanism.
Quiet implementation35%MOFCOM amends the export catalogue in Q4 2026 or Q1 2027 — plausibly timed to the January anniversary of DeepSeek R1 — with a tiered regime that exempts most current models but restricts future frontier systems.
Escalation25%A triggering event — another US distillation accusation, a major model leak, or a security incident — prompts rapid imposition of strict controls, including possible restrictions on API access from foreign IP addresses.

The watchpoints are clear. Q4 2026 model releases will be the single most revealing signal: whether DeepSeek's V5, Alibaba's next Qwen iteration, and Zhipu's GLM-6 launch with unrestricted Hugging Face weights, geofenced weights, or domestic-only APIs will tell the world everything about whether the tiered regime is live in practice, regardless of what appears on paper.

The CAC's TC260 committee is expected to release the next iteration of its AI Safety Governance Framework in the coming months, possibly including a technical standard for the tiered risk-categorization system. And the falsifiable test, as one analyst put it: if by end-March 2027 Beijing has issued no export-catalogue amendment and no CAC standard on cross-border model access, the initiative has genuinely stalled.

Financial charts and data visualizations — the collision between AI sovereignty and AI economics will be decided not in summit rooms but in spreadsheet models tracking overseas revenue

The Deeper Signal

Strip away the procedural detail and the September silence points to something larger: the AI model layer of the technology stack has joined chips, cloud, and data as an instrument of state power.

Two years ago, that sentence would have read as speculation. In September 2026, it reads as the base case. The United States has already acted on this logic — restricting chip exports, suspending model access, investigating distillation. China's deliberations, whether or not they produce formal rules, represent an acknowledgment that the game has changed. Models are not just products. They are leverage.

But the economics push in the opposite direction, and the economics are formidable. China's frontier labs are generating real revenue from overseas customers for the first time. Their valuations — DeepSeek at ~$50 billion, Moonshot at $50 billion, the four pure-play labs combined at roughly $159 billion — depend on continued global expansion. Killing that growth to prevent a hypothetical adversary from downloading a model that is already freely available on Hugging Face would be an extraordinary act of economic self-harm.

Beijing appears to have noticed. The empty decision window suggests that, for now, the sovereignty argument has not overwhelmed the commercial one. But the consultations continue. The legal machinery remains in place. And MOFCOM's September statement — accusing the United States of "technological hegemony" — suggests that the political appetite for confrontation has not diminished.

The Silence Is the Strategy

There is one more interpretation of the empty September window, and it may be the most accurate one: the ambiguity is deliberate.

By maintaining the threat of export controls without implementing them, Beijing achieves several objectives simultaneously. The labs stay cautious about what they release and where. Foreign customers are reminded of their dependency on Chinese models — and of the political risk embedded in that dependency. Washington is denied the clean narrative of a China that has "gone closed." And Beijing retains maximum flexibility: it can implement controls at any moment, in response to any trigger, without needing new legislative action.

The silence is not indecision. It is a policy instrument in its own right — the regulatory equivalent of a loaded weapon placed visibly on the table.

The AI model layer of the stack has joined chips, cloud, and data as an instrument of state power. The only question now is when — not whether — someone pulls the trigger.


What They're Saying

**"我们终于走到了这一天——模型权重成为国家战略资产。问题是,我们的商业模式建立在把它们免费送给全世界的基础上。"

"We've finally arrived at the day when model weights become national strategic assets. The problem is, our business model is built on giving them away for free to the entire world."**

— 陈默 (Chen Mo), AI infrastructure engineer at a Beijing frontier lab, posting on Zhihu (知乎)

"If Beijing actually restricts Qwen downloads, half the AI startups in America have a supply-chain emergency they didn't know they had. This is a bigger deal than the chip ban."

— @dylanfernandez, ML engineer, on X

**"出口管制的讨论本身就是管制。你不需要真的禁止什么——你只需要让每个人在发布之前三思。"

"The discussion of export controls is itself a form of control. You don't actually need to ban anything — you just need everyone to think twice before releasing."**

— 一只鹿鸣 (A Deer Calls), tech policy commentator on WeChat

"The irony is painful. Washington accuses China of stealing American models while American companies quietly train on Qwen. And Beijing considers locking down its models while lecturing the world about openness. Both governments are writing the same playbook from opposite ends."

— @sarahchen_ai, AI policy researcher, on X

**"灵境外收入占比超过50%的公司,不可能支持出口管制。这不是政治问题,这是数学问题。

A company with over 50% of revenue from overseas cannot support export controls. This isn't a political question. It's a math problem."**

— 量子位观察 (QbitAI Observer), AI industry newsletter, on WeChat

"Everyone is watching Q4 model releases. If DeepSeek V5 drops with unrestricted weights, the window was theater. If it launches domestic-only, the silence was a warning."

— @markus_rehm, semiconductor analyst, on X


Key Events Timeline

M

By Meeeeed

Editor at AI in China. Tracking Chinese AI companies, funding rounds, and the technologies reshaping global tech. More about me.

← Previous

The Enterprise Pivot: How China's AI Giants Just Killed the Consumer Playbook

Next →

The Great AI Export: How China's Intelligence Industry Is Rewiring the Global Tech Map