Artificial intelligence has found a new way to make policymakers nervous. The latest fight concerns less what AI can do than who may build it, copy it, distribute it, and decide when those activities become a security threat. That fight will help define AI governance, the rules and institutions used to manage AI development, access, safety, competition, and misuse.
On July 16, Moonshot AI, a Chinese artificial-intelligence company, released Kimi K3. It is an open-weight model, meaning the numerical parameters that encode what the model learned are publicly available for others to download, modify, and run. Even skeptical observers rated K3 “pretty much on par” with the best publicly available models of early 2026.
Five days later, OpenAI disclosed a very different milestone. During an internal cybersecurity evaluation, its models chained together several zero-day exploits, escaped their test environment, and achieved remote-code execution on Hugging Face’s production servers. A zero-day exploit targets a software flaw unknown to the developer or not yet patched. Remote-code execution allows an attacker to run commands on another computer. Hugging Face is a widely used platform for hosting and distributing AI models, datasets, and development tools. OpenAI called the result “unprecedented.”
Then Washington entered the fray. On July 22, White House science adviser Michael Kratsios said the government had information that Moonshot built K3 by distilling Anthropic’s Fable model at industrial scale. Distillation is a technique for training a smaller or competing model on the outputs of another model. A distillation attack uses large volumes of unauthorized or deceptive queries to copy capabilities from a rival system.
According to Kratsios, Moonshot used a platform designed to evade detection and relied on export-controlled Nvidia servers accessed through Thailand. Within hours, Treasury Secretary Scott Bessent warned that “open source is not open season on American IP” and said distillation attacks that “cross the line into IP theft” could put “sanctions and Entity List designations . . . on the table.” An Entity List designation subjects a person or company to U.S. export restrictions, often requiring licenses before American firms may supply specified goods, software, or technology.
The three developments point in different directions. Kimi K3 suggests that the gap between leading proprietary and open-weight models may be measured in quarters rather than years. OpenAI’s disclosure shows that even one of the world’s best-funded laboratories struggled to keep its own model inside a sandbox, a controlled environment intended to prevent outside access or damage.
The White House response points somewhere else again. Washington reached for its strongest trade and sanctions tools to address conduct that, by the government’s own account, involved fraudulent application programming interface (API) access and smuggled chips rather than open weights themselves. An API allows one piece of software to send requests to another and receive its outputs.
These events identify the questions AI governance should confront. The policy debate nonetheless keeps looking elsewhere.
That debate came into focus last week in a widely shared response to Kimi from Dean Ball, a former White House AI-policy adviser and author of the Hyperdimensional newsletter. Two of his claims deserve scrutiny. The first is that open-weight models are “inherently decelerationist” because they discourage investment in frontier-model development. The second is that a world dominated by open weights ends in “full AI communism,” with the state providing AI as “digital public infrastructure.”
Both claims misunderstand how markets create value. They also direct policymakers toward the wrong tools for addressing AI misuse and security threats.
Policymakers should focus on three priorities. They should preserve a healthy mix of open and proprietary models so defensive AI tools can spread widely. They should abandon export controls that fail to achieve their aims while imposing serious unintended costs. And they should recognize that firms providing access to models are often best positioned to detect and stop abuse.
A Commodity Is Not Communism
The economics are straightforward. If an open model that trails the frontier can reach “pretty much on par” within a few quarters, parts of the model layer are becoming commodities. That is what happens when meaningful differences between competing products shrink.
Technology analyst Ben Thompson, founder of the Stratechery newsletter, offers a useful refinement. A token from one model is not interchangeable with a token from another, so whether a model behaves like a commodity depends on the task. The relevant question is how much it costs to complete that task and how much demand the task creates. On this account, the commodity is less the model itself than the useful intelligence assembled from its tokens.
That refinement cuts against Ball’s argument. U.S. firms can remain competitive even if rivals distill their models, provided they still offer better efficiency, lower costs, or a better fit for particular uses.
A commodity is not communism. Nor does a public good in the economic sense—something nonrival and nonexcludable—require state provision. Open-source software is the standard example of a privately supplied public good.
Commoditization also does not necessarily deter investment. Linux replicates many functions of Windows and macOS, yet it became the foundation for Android and much of the world’s cloud-computing business. Value moved to other parts of the technology stack, including data, distribution, applications, and integration. This is the familiar strategy of commoditizing a complement so that demand grows for the product you sell.
If customers continue paying for frontier capabilities, free substitutes pose little threat. If customers switch, the market has decided that the frontier premium is not worth the price. That is competition, not communism. Ball cannot plausibly claim both that the frontier remains steep and valuable and that open weights will eliminate the investment needed to reach it.
There is a more plausible version of the case against open weights, though it is a trade argument. Ball attributes China’s open-weight strategy partly to “the normal Chinese strategy of aggressive exports.” The White House now uses similar language. Secretary Bessent’s warning that “open source is not open season on American IP” frames Chinese models as a problem of dumping and theft, with trade sanctions as the answer.
If a state-backed rival distributes a product below cost to damage a domestic industry, trade law calls that dumping. The claim is familiar, heavily contested, and subject to established remedies. It should be evaluated as an economic and national-security question, with evidence of underpricing, injury, and likely effects. There is no need to dress it up as a broader question about whether AI may be sold through ordinary markets.
Even then, a dumping claim based on free models nearly defeats itself. Predatory pricing usually requires some plausible path to recouping the initial losses once competitors have been weakened. It is hard to see how a laboratory giving away open-weight models later raises prices enough to recover that investment.
Ball predicts that the administration may instead manufacture diffuse “regulatory risk” around Chinese models. That would amount to protectionism without the usual burden of proving underpricing, injury, or any long-term theory of how Chinese laboratories expect to profit from open-weight releases.
The economics matter most for what they imply about policy. If parts of the model layer are becoming commodities, banning open-weight models or stretching export controls to cover them will miss both the source of the alleged harm and the conduct causing it.
The plausible complaint is about trade practices. The plausible control point is neither the model weights nor the hardware that runs them.
Export Controls Meet the Copy Button
The “AI communism” argument is one front in the broader fight over export controls, which remain a form of economic policy. Consider an extreme example. In September 2024, the U.S. Department of Commerce extended export controls to quantum computing, a technology so immature that no one can yet identify its main commercial uses, forecast its cost curve, or say which hardware design will prevail. Scholars have aptly described the exercise as regulation under deep uncertainty.
Export controls, assuming they work at all, have the best chance of success when they target physical technology that governments can identify and isolate. Quantum computing therefore presents a relatively favorable case. Quantum machines require dilution refrigerators, cryogenic systems, vibration isolation, and electromagnetic shielding. That bulky, traceable infrastructure creates natural enforcement chokepoints.
Even there, the evidence calls for humility. Studying the 2007 U.S. “China Rule,” Ernest Liu, Yingyi Liu, Alexey Makarin, and Xuan Wen find that export controls reduced targeted imports in the short term. They also pushed affected Chinese firms and their suppliers to spend more on research and development and file more patents in the controlled technologies. China’s cryogenics industry may already be innovating around current restrictions.
At best, export controls buy time. They do not guarantee permanent denial. Their value depends on how the United States uses that time, which is why the debate over chip controls ultimately turns on competing forecasts about AI development and China’s ability to produce substitutes.
Model weights present a far harder target than quantum equipment. They are weightless, infinitely replicable at nearly zero marginal cost, and already distributed around the world. Open-weight models also generate no revenue stream to embargo. Trying to “starve” China of them would deny Chinese laboratories little while burdening global experimentation, safety research, and low-cost defensive uses.
A ban would still create one clear beneficiary. It would give a small group of U.S. firms a legally protected moat, along with the rent seeking and regulatory capture that such protection invites. Restrictions on exporting or importing Chinese models would function chiefly as industrial protection.
The irony is that Ball attributes China’s open-weight strategy partly to “an unintended byproduct of US export controls.” The controls helped produce the workaround innovation that policymakers now cite as a reason for more controls.
Even the chip restrictions appear to function mainly as expensive speed bumps. U.S. policy has pushed Chinese firms to replace American suppliers. Chinese chip stocks have rallied on expectations for Huawei accelerators, while surveys show Chinese companies shifting away from Nvidia toward domestic alternatives.
Chinese chips may remain a generation behind, but the gap is narrowing. China also has access to far more abundant energy. At sufficient scale, weaker chips paired with more electricity can still power highly capable systems.
The greater long-term risk is that firms around the world adopt a Chinese-centered hardware and software stack. That would matter far more than modest pressure on the profit margins of U.S. chipmakers.
Remote access makes the controls still less effective. Even if chip restrictions worked exactly as intended, illicit access to U.S. models is already widespread. Laboratories use fraudulent accounts both to distill models and for ordinary daily access. Anthropic disclosed that three Chinese laboratories, including Moonshot AI, had harvested more than 16 million Claude exchanges through roughly 24,000 fraudulent accounts.
The United States has badly miscalculated its AI export controls. Policymakers should focus instead on AI governance, and governance must extend beyond model alignment. Firms that provide access to models may be the least-cost avoiders, meaning the parties able to prevent or limit misuse at the lowest cost.
The legal tools available to carry out Secretary Bessent’s threat point in the same direction. Procurement bans, information and communications technology and services orders modeled on the restrictions against Kaspersky, and Entity List designations all target transactions, services, or distribution channels.
An Entity List designation restricts exports to a listed party. It does not prevent a U.S. user from downloading a publicly available model. Freely published software also generally falls outside the Export Administration Regulations.
An attempt to ban a free model file under the International Emergency Economic Powers Act (IEEPA) would face the statute’s exemption for informational materials. Courts relied on the same provision when they blocked parts of the 2020 TikTok restrictions.
Whatever the merits of those measures, restrictions aimed at services and transactions have the strongest chance of surviving judicial review. Both the law and the economics point toward the capability layer, where firms provide model access and can observe how customers use it.
Police the API, Not the Model
Export controls and bans on open-source models will create more problems than they solve. That does not mean policymakers should do nothing. It means policy should prepare for the likeliest future, one in which defensive AI must be widely available to firms and individuals.
Governance should therefore focus on the capability layer, where model outputs become action. Consider distillation, in which an adversary harvests API outputs to train a substitute model. Security researchers have documented this attack method since at least 2016.
The API owner is best positioned to detect industrial-scale extraction. It can see account creation, payment signals, proxy use, and query patterns long before any regulator can. The government’s own allegations against Moonshot describe precisely that route. Moonshot allegedly used fraudulent, detection-evading access to a U.S. laboratory’s API to conduct distillation at industrial scale. That would be a failure of API security, not a leak caused by open weights.
The laboratory also has access, at least in theory, to the most advanced AI-security tools available. Restricting open models while tolerating weak API security would create moral hazard. It would shield incumbents from the competitive consequences of their own security failures, weaken their incentives to fix those failures, and leave the public bearing the remaining risk.
The Hugging Face incident makes the problem hard to ignore. Before frontier laboratories ask policymakers to cordon off the world’s open models, they should show that they can keep their own agents inside their own evaluation sandboxes. Stronger laboratories, tighter APIs, and better security monitoring will move faster than legislation and target the actual vulnerability more precisely than a ban. They will also improve through repeated use.
The framing of the news reveals another blind spot. OpenAI made headlines because its model escaped a sandbox and exploited outside systems. The public heard far less about whether the same model could build a system secure enough to resist that attack. The industry devotes enormous attention to demonstrating offensive capability and far too little to the defensive capabilities AI should provide.
Open weights should therefore be treated as part of the defense, not merely as a source of risk. Distributed threats require distributed protection. A $200-a-month frontier subscription cannot serve as the security layer for billions of devices.
Local, auditable, open models may offer the only economical way to provide phishing detection, log review, and endpoint triage on that scale. That is one reason the Defense Advanced Research Projects Agency (DARPA) released the cyber-reasoning systems developed through its AI Cyber Challenge as open source. Regulators should preserve a healthy mix of open and proprietary models so defensive tools can spread as widely as the threats they address.
Open-weight competition constrains prices, shifts value across the technology stack, and broadens access to defensive tools. The governance agenda is less dramatic than a sweeping ban. Harden the laboratories. Police the APIs. Monitor the physical infrastructure. Litigate trade grievances as trade grievances. Then let competition do the rest.
The first rule of AI governance should be simple. Secure the door before banning the key.
