The Summit and the Reckoning: Eighteen Months That Rewired the US-China AI Balance
*Eighteen months of export controls, model bans, and distillation accusations were supposed to slow China's AI industry. The data says they did something else entirely. (Image: Unsplash)*
The Present Moment
On September 20, 2026, at JPMorgan's Park Avenue headquarters, the American and Chinese economic delegations sat down for what the official readouts carefully called "consultations." China's Vice Premier He Lifeng led the Chinese side; Treasury Secretary Scott Bessent and Trade Representative Jamieson Greer led the American one. The meeting ran roughly eight hours, and buried inside the trade arithmetic — tariff truces expiring November 10, a $30 billion reciprocal-tariff framework — was a first: a formal, structured dialogue on artificial intelligence.
That evening, Bessent told reporters the United States had proposed creating a standing "US-China AI dialogue," a safety notification mechanism that would give each country a direct line to the other's frontier AI laboratories. The proposal, he said, would be put before both presidents at their summit in Washington on September 24 — today.
Strip away the choreography and something remarkable has happened. The world's two AI superpowers are building the diplomatic plumbing for managing frontier-model risk — joint monitoring of AI-driven cyberattacks, information-sharing between labs, notification procedures for dangerous capability jumps. The agenda items being negotiated in Washington were, almost to a line, the agenda items American officials spent eighteen months accusing Beijing of ignoring.
And here is the part almost nobody in Washington will say aloud: America did not arrive at this table from a position of strength. It arrived there because its containment strategy failed in public, on the leaderboard, in a way that no amount of lobbying can spin.
| Seat at the Table | Who | Position Coming In |
|---|---|---|
| US delegation lead | Treasury Secretary Scott Bessent | Proposed the standing AI dialogue + notification mechanism |
| US trade lead | USTR Jamieson Greer | Tariff truce (expires Nov 10) tied to broader tech détente |
| China delegation lead | Vice Premier He Lifeng | Accepted AI dialogue as extension of May 2026 consensus |
| The backdrop | Trump–Xi summit, Sept 24, Washington | Mechanism to be considered at leader level |
| US anxieties | Distillation, Mythos-class offensive models, agent swarms | July: ~700 malicious OpenAI-based agents infiltrated Hugging Face |
| China's leverage | 8 of top 10 models on OpenRouter are Chinese | Weekly token volume lead stretching past 30 weeks |
*The negotiating positions as the two delegations arrived in Washington — and the data asymmetry underneath them. (Sources: Caixin, Reuters, Phoenix TV, Sputnik)*
The road to Park Avenue ran through eighteen months of escalation that few in either capital planned. The arc, compressed:
| Date | Event | What It Changed |
|---|---|---|
| Sep 2025 | Anthropic bans Chinese firms from its models | First major private-sector decoupling move |
| Jan 2026 | DeepSeek V3.2 and Kimi K2.5 go viral globally | The "extraction" narrative meets open-source reality |
| Feb 2026 | China models first pass US on OpenRouter (4.12T vs 2.94T weekly tokens) | The usage crossover |
| Feb 2026 | Anthropic alleges distillation attacks (DeepSeek, MiniMax, Moonshot) | Accusations replace access denial as the weapon |
| Jun 2026 | Anthropic letter to Senate on Alibaba; US model share down to 33% | Escalation peaks as the data turns |
| Jul 2026 | Kimi K3 (2.8T, open) triggers reported US model-ban deliberations | Washington debates banning what it cannot outcompete |
| Sep 12, 2026 | Amodei essay urges slowing the race | American labs split in public |
| Sep 20, 2026 | NYC consultations: first formal bilateral AI dialogue proposed | The containment era formally ends at a negotiating table |
*Eighteen months, eight turning points, one reversal. (Sources: OpenRouter, Caixin, Axios, company statements)*
Phase 1: The Ban (September 2025)
The current arc began, fittingly, with a refusal to engage. In September 2025 — after DeepSeek's R1 had already detonated the assumption that American labs held a comfortable frontier lead — Anthropic became the first major American AI company to formally prohibit Chinese firms from using its models. The ban was unusually sweeping: it applied not just to companies headquartered in China, but to any entity with Chinese controlling ownership, regardless of where it was incorporated.
The logic was straightforward. Anthropic's leadership had concluded that Chinese laboratories were closing the capability gap in part by using American models as training signal, and that cutting off access would slow them. The ban was cheered in Washington as a model for how the private sector could enforce what export controls could not.
What happened next is the hinge on which the entire eighteen-month story turns. Deprived of the sanctioned path — API access to closed American models — Chinese laboratories did not slow down. They changed religions.
Moonshot AI, DeepSeek, Zhipu, Alibaba, MiniMax and a half-dozen others spent the following year doing something no American frontier lab was willing to do: releasing their most capable models as open weights, free to download, modify, and self-host, at prices that made the closed American APIs look like a different product category entirely. The ban did not deny Chinese labs American intelligence. It denied American labs the Chinese market — and handed Beijing's open-source coalition a monopoly on the fastest-growing developer ecosystem in the world.
Phase 2: The Accusation (February – June 2026)
If Phase 1 was a wall, Phase 2 was a warrant. In February 2026, Anthropic escalated from access denial to public accusation, publishing claims that three Chinese companies had conducted systematic "distillation attacks" against Claude — using the model's outputs to train their own systems in violation of terms of service.
The cited numbers became among the most-quoted figures in the industry's geopolitical fight:
| Accused Company | Alleged Claude Queries | The Company's Response |
|---|---|---|
| DeepSeek | ~150,000 | Denied wrongdoing; noted open training methodology |
| MiniMax | ~13,000,000 | Called the claims "a misunderstanding of how open-source training works" |
| Moonshot AI (Kimi) | ~3,400,000 | Pointed to its published reinforcement-learning pipeline |
*Anthropic's February 2026 distillation allegations and the responses. Within weeks, all three companies' open models were outcompeting Claude on developer traffic. (Source: Caixin, company statements)*
Elon Musk's public reaction — "the thief crying thief" — captured developer-community skepticism, given that distillation-adjacent techniques are standard practice across the industry and that Anthropic itself had trained on swaths of publicly available human-generated text. The claims did not produce legal victories or enforcement actions. What they produced was attention.
In June, Anthropic went further, sending a letter to the US Senate accusing Alibaba of stealing its AI capabilities. OpenAI had already written to the House of Representatives making parallel claims about DeepSeek. The message from the American frontier labs was unified: Chinese progress was not legitimate progress; it was extracted progress.
But the extraction narrative had a timing problem. The models kept getting better on benchmarks that had nothing to do with Claude's outputs. And the traffic data kept getting worse for the accusers.
Phase 3: The Backfire (2026)
Here is what the eighteen-month containment campaign actually produced, measured in the only currency the industry ultimately respects: usage.
In February 2026, Chinese models' weekly token consumption on OpenRouter — the largest API aggregation platform, used overwhelmingly by developers outside China, with Americans making up 47% of its user base and Chinese developers just 6% — surpassed American models' for the first time. The crossover week: China at 4.12 trillion tokens versus the US at 2.94 trillion. The following week, China hit 5.16 trillion. By June, the American share of OpenRouter traffic had collapsed from 72% a year earlier to 33%. By August, Chinese models had led for fifteen consecutive weeks, and the lead was growing, not shrinking.
The snapshot from the week of September 7–13 — the same week the summit choreography was being finalized — tells you where the industry actually is:
| Rank | Model | Origin | Weekly Tokens | Note |
|---|---|---|---|---|
| 1 | GPT-5.6 Luna | OpenAI (US) | 15.8T | The lone American flagship holding the top |
| 2 | DeepSeek V4.1 Flash | DeepSeek (CN) | 11.8T | Open weights, self-hostable |
| 3 | Tencent Hy4 preview | Tencent (CN) | 11.6T | Powers Yuanbao; also on HarmonyOS NEXT |
| 4–10 | 5 more Chinese models incl. Zhipu GLM-5.3, Xiaomi MiMo | CN | — | 8 of the global top 10 are Chinese |
| — | Total platform | — | 127T (+10.4% w/w) | Record week |
*OpenRouter global model call rankings, week of September 7–13, 2026. Chinese laboratories hold eight of the top ten positions. (Source: OpenRouter via Caixin)*
The trend line underneath that single week is even less forgiving to the old narrative. China's lead did not appear in September; it compounded for seven months:
| Milestone Week | Total Platform Volume | China Share | US Share | Marker |
|---|---|---|---|---|
| Feb 9–15, 2026 | ~7T tokens | 4.12T (first place) | 2.94T | The crossover |
| Feb 16–22, 2026 | ~7.9T | 5.16T (+127% in 3 weeks) | 2.7T | Four of global top five |
| Jun 2026 | ~45T | 9+ consecutive weeks in front | Share down to 33% (from 72% YoY) | Lead institutionalized |
| Aug 3–9, 2026 | 69T (+21.5% w/w) | 34.25T | 9.17T | Week 15 of the streak |
| Sep 7–13, 2026 | 127T (+10.4% w/w) | 8 of top 10 models | GPT-5.6 Luna alone at #1 | Record volume, same hierarchy |
*Seven months of OpenRouter data. Note the platform's user base is 47% American and 6% Chinese — this is global developers voting, not domestic consumption. (Source: OpenRouter, NBD, STCN, Caixin)*
The platform data understates the shift, because it misses the self-hosting wave. Hugging Face's spring 2026 report found Chinese open-source models accounted for 41% of all model downloads on the platform — surpassing the United States for the first time. Andreessen Horowitz partner Martin Casado noted in March that roughly 80% of the AI startup pitch decks he saw in Silicon Valley had a Chinese open model at the core of the stack. The American labs had tried to wall off the Chinese models. Instead, the Chinese models ate the American developer market from the inside — legally, openly, and at a tenth of the price.
The economics explain why. A developer running serious volume on Claude Opus-class models in early 2026 paid around $5 per million input tokens. The comparable Chinese open-weight models cost roughly $0.30 — one-sixteenth the price — with no egress lock-in, full customization rights, and deployment on hardware the user controls. For agentic workloads, which consume tokens in the trillions, the choice stopped being a choice.
And the capability gap that was supposed to justify the premium kept narrowing. Moonshot's Kimi K3 — released as the world's first 2.8-trillion-parameter open model — triggered such alarm in Washington that Axios reported the Trump administration began actively weighing a ban on Chinese AI models. That was July. By September, StepFun's Step 5 Preview (600B parameters) matched Kimi K3's third-party benchmark score; Zhipu's GLM-5.3-FlashX hit 200 output tokens per second on inference clusters of 100,000 domestic Chinese chips; Alibaba's Qwen3.8-Omni-Flash processed text, image, audio, and video in a single 1-million-token context while cutting audio-input prices by 98%; and China Telecom's Xing4.0 became the first 10B+-parameter model trained entirely on domestic Ascend compute — a model the export controls were explicitly designed to prevent from existing.
*The assumption that AI gravity would stay in Palo Alto died in 2026, one trillion tokens at a time. (Image: Unsplash)*
Phase 4: The Reckoning (September 2026)
Which brings us to the strange, brittle month of September — the month in which the American AI establishment turned on itself even as it finally sat down with Beijing.
On September 12, Anthropic CEO Dario Amodei published an essay arguing that the AI race had become dangerous and should be deliberately slowed, with mandatory third-party evaluations and mechanisms to shut down frontier models if necessary. Within 48 hours, President Trump publicly rejected the framing, declaring that "whoever wins AI, wins the future" and darkly suggesting a "malicious conspiracy against AI and data centers" was afoot. Amodei's counterparts — Sam Altman, Elon Musk, Demis Hassabis — offered carefully worded support. And then the whole tableau was served with a subpoena: a class-action lawsuit filed in California's Northern District accuses Anthropic, OpenAI, SpaceXAI, and Google of illegally coordinating to restrain AI development, citing the executives' public statements as evidence.
The irony is architectural. The American lab that most aggressively accused China of extraction spent the autumn of 2026 publishing data showing that its own model, Claude, now autonomously conducts roughly 26% of AI research and development work inside Anthropic — a number under 1% in February. The lab that warned loudest about runaway AI automation became the first to publish a credible measurement of its own replacement. Meanwhile, a leaked OpenAI financial deck projected $278 billion in cumulative negative free cash flow between 2026 and 2030 against $856 billion in planned compute spending — a burn predicated on closed-model pricing power surviving the open-source tide.
| Metric | American Closed Labs | Chinese Open-Source Camp |
|---|---|---|
| Flagship API input price (per 1M tokens) | ~$5 (Opus class) | ~$0.30 |
| Top-model weights | Proprietary | Downloadable |
| Revenue trajectory | Anthropic: $9B ARR (end-2025) → $65B+ (Jul 2026) | Kimi K2.5 earned more in 20 days than all of 2025 |
| Control posture | Ban Chinese users; lobby for restrictions | Open weights, global developer capture |
| September 2026 headache | Class-action collusion suit; safety-slowdown rift | Summit optics; distillation allegations on record |
*Two business models, two risk profiles. One of them is compounding developer loyalty; the other is compounding legal bills. (Sources: company disclosures, OpenRouter, court filings)*
The reckoning is not that China "won" — frontier benchmarks still tilt American on the hardest reasoning tasks. The reckoning is that the containment strategy assumed a monopoly on excellence that no longer exists. When the only lever you have left is dialogue, you are, by definition, negotiating from a position you did not choose.
What Comes Next
The summit will not produce a treaty. AI arms-control frameworks take years, and verification of model-training runs is a problem nobody has solved. But the direction of travel is now visible, and it matters more than any communiqué.
Three scenarios are live:
| Scenario | What It Looks Like | Probability Signal |
|---|---|---|
| Managed rivalry | Standing AI dialogue launches; notification channel for frontier model incidents; quiet US softening on open-model restrictions in exchange for safety commitments | The Sept 20 proposal already drafted in this direction |
| Creeping decoupling | Talks continue but US moves to restrict Chinese model distribution anyway; China doubles down on open weights as state policy | Axios-reported model-ban deliberations resurface |
| Race acceleration | Safety dialogue collapses under the collusion suit and election pressure; both sides sprint; agent-safety incidents (Hugging Face swarm, German site hijackings) multiply | Trump rhetoric stays maximalist |
*The most likely outcome is the first — not because either side trusts the other, but because both sides now have something the other wants: America has the frontier capability edge, and China has the deployment-scale ecosystem that determines whose standards become global.*
*Diplomacy moves slower than token volume — which is precisely why the summit matters more than the communiqué. (Image: Unsplash)*
The milestones to watch through the end of 2026 are concrete: whether the "US-China AI dialogue" mechanism appears in the summit readout; whether the November 10 tariff truce renewal carries AI provisions attached; whether Washington formally moves to restrict Chinese open models or quietly drops the idea; and whether Anthropic's safety-slowdown gambit survives its collision with the administration's industrial policy. On the Chinese side, watch whether the open-source all-in continues past the point of commercial logic — because at this point, open weights are not just a business strategy for Beijing's labs. They are the most effective geopolitical weapon China has ever built, and it cost nothing to deploy.
Eighteen months ago, an American AI company banned Chinese firms from its API and expected deference. Today, eight of the ten most-used AI models on Earth are Chinese, the American president is proposing an AI hotline to Beijing, and the architects of the containment strategy are being sued for conspiring to slow down their own industry. The summit in Washington is being billed as the beginning of a new era of AI diplomacy. It is actually something more honest: the first diplomatic negotiation in history in which one side arrived having already lost the argument that its technology was irreplaceable.
Voices From the Debate
Zhihu — @算力观察员 (29k upvotes):
"封禁芯片,中国造出了自己的超节点;封禁模型,中国开源拿下了全球开发者。历史没有偏见,只有因果。"
*"Ban the chips, China builds its own supernodes. Ban the models, China's open source captures the world's developers. History has no bias — only cause and effect."*
X (Twitter) — @AISupplyChain, quoted by 340 users:
"Washington spent 18 months trying to keep Chinese labs out of the frontier. OpenRouter says the frontier now speaks Chinese eight days a week. The summit is a concession wearing a tie."
*"Washington spent 18 months trying to keep Chinese labs out of the frontier. OpenRouter says the frontier now speaks Chinese eight days a week. The summit is a concession wearing a tie."*
Weibo — @科技老兵张明 (18k reposts):
"贝森特 proposing a dialogue mechanism 之前,先想想是谁先把模型政治化的。谈判桌不是恩赐,是我们用 token 堆出来的。"
*"Before Bessent proposes a dialogue mechanism, he should remember who politicized the models first. A seat at the table isn't a gift — we stacked it with tokens."*
Hacker News — throwaway-ai (top-thread comment, 512 points):
"I work at a US startup. Our stack is DeepSeek V4.1 Flash self-hosted plus a Claude wrapper for the hard 2%. The distillation accusations are irrelevant to every purchasing decision we make. Price and latency won. The summit won't change that."
*"I work at a US startup. Our stack is DeepSeek V4.1 Flash self-hosted plus a Claude wrapper for the hard 2%. The distillation accusations are irrelevant to every purchasing decision we make. Price and latency won. The summit won't change that."*
Douban — 阿北与AI (featured in 科技瓜组):
"挺讽刺的:喊暂停的那个公司,自己的数据说模型已经干了26%的研发。要我说这不是中美博弈,这是所有闭源公司跟开源未来的博弈。"
*"The irony: the company shouting 'pause' published data saying its model now does 26% of R&D. If you ask me, this isn't US vs China — it's every closed company versus an open-source future."*
GitHub — issue comment on vllm/vllm #44712 (1.2k reactions):
"Every week another GLM/DeepSeek/Qwen drop lands and our inference costs drop another notch. Whatever happens in Washington, the weights are already out here. You can't sanction a magnet link."
*"Every week another GLM/DeepSeek/Qwen drop lands and our inference costs drop another notch. Whatever happens in Washington, the weights are already out here. You can't sanction a magnet link."*
*Related coverage: China's Open-Source AI Empire and the BRICS Playbook · China's Compute Empire: How Sanctions Boomeranged · The US-China AI Safety Dialogue: DeepSeek, Huawei, and Compute Independence · China's AI IPO Gold Rush*
Editor at AI in China. Tracking Chinese AI companies, funding rounds, and the technologies reshaping global tech. More about me.