China Considers AI Model Export Controls
Beijing may restrict foreign access to top AI models.
Model Diplomat8 min readAsia

China Weighs AI Model Export Controls on Alibaba, ByteDance, Z.ai
Beijing is considering restricting foreign access to its top AI models — a mirror of US export controls that would reshape open-weight adoption worldwide.
Beijing's Ministry of Commerce has spent the past month sounding out Alibaba, ByteDance and Z.ai on restricting overseas access to China's most advanced AI models, Reuters reported on July 7 — a move that, if enacted, would end the single most consequential asymmetry in the US–China tech contest: China's willingness to ship its best models to the world for free while Washington locks its own down. The angle that matters is not that China is imitating US export controls; it is that Beijing is now prepared to trade its global open-weight market share — more than 540 million cumulative Hugging Face downloads by October 2025 — for state control over frontier AI as a national-security asset. That trade-off, and the timing of it, tells you the AI race has entered a new phase.
What Beijing is actually contemplating
According to the Reuters exclusive by Fanny Potkin, the meetings — led by the Ministry of Commerce with National Development and Reform Commission officials in the room — discussed limits on "the most advanced AI models, both closed-source and more open versions," treating any leak or theft of proprietary model weights as a national-security offence, and new restrictions on who may fund Chinese AI startups. Two sources told Reuters the rules may apply only to future models; nothing has been decided.
The regulatory scaffolding is already in place. On October 28, 2025, China's National People's Congress Standing Committee passed a revised Cybersecurity Law that, per the State Council Information Office, "added an article on the safe and sound development of AI" and took effect on January 1, 2026. On September 30, 2024, the State Council's
Network Data Security Regulations (Decree 790) — also in force since January 1, 2026 — added Article 19 requiring generative-AI providers to strengthen training-data security, and Article 45 imposing cross-border transfer duties on "large network platform service providers." Together, they hand the Cyberspace Administration of China and MOFCOM the statutory hooks to gate model exports without new primary legislation.
A May 2026 roundtable summary published in a Supreme People's Court journal, cited by Reuters, sketches the likely architecture: a tiered regime in which "basic open-source tools" require simple filing, more capable systems face security reviews, and the most sensitive frontier models are barred from public release or restricted to domestic use. That is, functionally, the Biden-era "AI Diffusion Rule" — but pointed inward.
What Beijing is trading away
To grasp why this is a real strategic choice and not a reflex, look at what China would give up. The Economist reported in January 2026 that downloads of Chinese open-weight models on Hugging Face had overtaken American ones. By October 2025, cumulative Chinese open-weight downloads exceeded 540 million, per an Atom Project analysis cited by
Al Jazeera. A December 2025 arXiv preprint by Longpre et al.,
Economies of Open Intelligence, documents a "fundamental rebalancing of economic power" on Hugging Face away from Google, Meta and OpenAI toward Chinese industry — "with DeepSeek and Qwen models potentially heralding a new consolidation of market power."
The commercial logic is well-established. MERICS analyst Wendy Chang wrote in June 2026 that Chinese firms are pursuing "a strategy of wide diffusion and cheap tokens to gain market share across the world," noting that of the top ten open-weight models by performance, seven are Chinese. The Council on Foreign Relations' analysis of
DeepSeek V4 put the pricing edge bluntly: V4 Pro is "at least four times cheaper than American competitors," and while the US still leads on capability by roughly seven months, China is winning the adoption race, "particularly in the Global South."
Airbnb CEO Brian Chesky's admission in October 2025 that the platform now runs on Alibaba's Qwen rather than OpenAI, and Chamath Palihapitiya's disclosure that Social Capital migrated to Moonshot's Kimi K2, were canaries. Nathan Lambert, co-author of the ATOM Report, told Al Jazeera that "Chinese open models have become a de facto standard among startups in the US." If Beijing throttles overseas access, that de facto standard becomes politically radioactive overnight — and every US developer on Qwen or GLM has to decide whether to migrate or be caught on the wrong side of a future ban.
Why Beijing is willing to trade — the Mythos shock
The proximate cause is the June 12, 2026 letter from US Commerce Secretary Howard Lutnick to Anthropic. As CSIS documented, the Bureau of Industry and Security invoked interim controls under the Export Control Reform Act to suspend all foreign access — including foreign nationals inside the United States — to Anthropic's Fable 5 and Mythos 5. Anthropic disabled the models globally, unable to verify user citizenship in real time, per
BBC News. The Peterson Institute's Martin Chorzempa
called it "the first time" Washington has "imposed controls on the model weights of certain advanced closed AI models."
For Beijing, Mythos is the horror scenario in reverse. Two of Reuters' sources said Chinese authorities are "deeply worried" that Mythos — designed for cybersecurity professionals and, per Anthropic, capable enough at finding software vulnerabilities that even the White House judged it too dangerous for open release — could be turned against Chinese critical infrastructure. Zhou Hongyi, founder of Chinese cybersecurity firm 360, has publicly argued that China needs its own Mythos. The June 30 Commerce lifting of the general Fable 5 restrictions, per the BBC, did not lift the Mythos gating.
The distillation fight sharpens the trigger. In a June 10 letter to Senators Tim Scott and Elizabeth Warren, Anthropic accused Alibaba of running "the largest campaign to illicitly extract Claude's capabilities" — roughly 29 million exchanges through thousands of fraudulent accounts. Anthropic's language was extraordinary: distillation attacks, it wrote, "turn hundreds of billions of dollars in American investment and R&D into a massive subsidy for our geopolitical competitors." That framing gives Chinese hawks their symmetrical argument at home: if American labs treat weight extraction as national-security theft, Chinese labs must too.
The precedent Beijing has already built
The Meta–Manus case is the template. On April 27, 2026, the NDRC ordered Meta to unwind its $2 billion acquisition of the Singapore-domiciled, Chinese-founded AI-agent startup — a firm that had reincorporated abroad specifically to escape US restrictions on Chinese AI. Beijing asserted jurisdiction anyway. On June 1, 2026, the State Council issued its
Outward Investment Regulations (Decree 837), which the Asia Pacific Foundation of Canada describes as imposing "sweeping scrutiny on outbound investment — broadly defined to capture any company dealing in Chinese-linked assets, goods, technology, personnel, or training."
Read together, Manus + Decree 837 + the July 7 MOFCOM meetings amount to the closing of a loop. Beijing has moved, in eight weeks, from blocking foreign acquisition of Chinese AI, to policing the outbound flow of Chinese AI capital and personnel, to now contemplating export controls on the models themselves. The Cambridge Forum on AI: Law and Governance framing of China's approach as "vertical and adaptive" is being tested in real time: content control has always been the CAC's brief; national-security-grade export control is a new muscle for a bureaucracy that until 2024 was more permissive on outbound models than on inbound ones.
Who wins and who loses
The bureaucratic winner in Beijing is MOFCOM, which absorbs a new competency that had drifted toward the CAC and the NDRC. The commercial winners are Huawei and the domestic-chip stack: as RAND argued in August 2025, if Alibaba, Tencent and ByteDance are pushed to keep their frontier training and deployment inside China, the "positive feedback loop" for Huawei's Ascend ecosystem accelerates. That is precisely the tipping point RAND warned Washington to avoid.
The commercial losers are Alibaba, ByteDance and Z.ai themselves — the very firms in the room. MERICS' analysis notes Chinese labs "often can't benefit directly from their overseas traffic" because hosting platforms capture the margin, but overseas adoption still delivered brand, talent-pull and de facto standard-setting. Restrictions would surrender all three. Z.ai's GLM-5.2, which Reuters says has "set Silicon Valley abuzz" for approaching US frontier performance at a fraction of the cost, is the model most exposed.
The geopolitical winners are European sovereign-AI advocates. The Royal United Services Institute argued after the Mythos restrictions that Europe's "feeling of being left out and overly reliant on the ebbs and flows of companies headquartered in the US" is now compounded by symmetrical risk from China. If both superpowers gate frontier models, the European Commission's Technological Sovereignty Package, the UK's BAE-Thales sovereign-model coalition, and Mistral's investor pitch all improve overnight. Global-South governments that had quietly standardised on Qwen and DeepSeek face the harder choice.
What to watch
Three catalysts will decide whether this becomes policy or stays a trial balloon.
- A published draft from MOFCOM or the CAC by end-Q3 2026, translating the May Supreme People's Court roundtable tiering into a filing/security-review/prohibition trichotomy. Absent a text, this is still a signalling exercise.
- The next Z.ai or Alibaba frontier release — GLM-6 or Qwen-4 — and whether it launches with open weights on Hugging Face or with a geo-gated API. Deployment behaviour will front-run the regulation.
- The US Commerce Department's Mythos posture and whether Congress passes the pending bill giving BIS clear jurisdiction over remote model access — the gap
PIIE flagged as the current legal weakness. Symmetric US formalisation would give Beijing political cover to move.
Diplomat View
The forecast: Beijing will implement a tiered export-control regime on frontier AI models within nine to twelve months, but grandfather in the currently released open-weight models — Qwen 3, DeepSeek V4, GLM-5.2 — and apply the restrictions primarily to next-generation systems. That structure lets China preserve its Hugging Face dominance and Global-South standard-setting while sealing off the frontier, mirroring what Washington did with Mythos. The likeliest first target is agentic and cyber-capable models in the Mythos class, not general-purpose chatbots.
What would change this forecast: an intra-Party push from the "diffusion" camp — Alibaba, ByteDance and the Ministry of Industry and Information Technology — that successfully argues Chinese soft power in AI depends on the open-weight strategy and cannot be sacrificed. Watch for MIIT statements defending open-source; watch for Alibaba lobbying visible in state media. If those signals dominate through the fall, the regime shrinks to a filing system with no real teeth. If they are silent, the Mythos-symmetric hawks have won the internal argument, and the July 7 meetings become the founding document of Chinese AI export control.
The bottom line: China is preparing to give up its greatest AI soft-power weapon — the free, cheap, globally downloadable model — because Beijing has concluded that frontier AI is now a strategic asset that must be nationalised in the same way Washington has already nationalised Anthropic's Mythos. The rest of the world will not get to choose between US and Chinese frontier AI for much longer. It will have to build its own, or borrow within limits set in Washington and Beijing.
Discover more

US Politics
House Ethics Committee Pushes Sexual Miscond.
The House Ethics Committee has shifted responsibility for sexual harassment settlement records to the Office of Congressional Workplace Rights, complicating disclosure efforts.

India
Congress Accuses Modi of Stalling Women's Law
Congress accuses Modi of stalling women's reservation law by linking it to delimitation, revealing a deeper electoral strategy.

India
BJP's Misunderstanding of Women's Quota Needs
The BJP's linking of the Women Reservation Bill to delimitation risks delaying women's empowerment in India, misreading the aspirations of female voters.

Economics
US Tariffs on Brazil: A Political Play
US imposes 25% tariff on Brazil but exempts 66% of exports, targeting manufactured goods ahead of Brazil's October election. Analysis of the political calculus, exemptions, and Brazil's response options.