Cybersecurity & Tech Foreign Relations & International Law

Open-Weight Diplomacy: How China’s AI Models Are Rerunning the Digital Silk Road

Chinmayi Sharma
Thursday, September 3, 2026, 1:00 PM

China's “free” AI models are rerunning Huawei’s telecom playbook: Give the weights away, sell the stack around it, own the dependency.

An ad for Alibaba Cloud in Hong Kong (Fooksou Lamimo, https://tinyurl.com/9m522m5u, CC BY-SA 4.0, https://creativecommons.org/licenses/by-sa/4.0/deed.en)

On July 16, the Chinese artificial intelligence (AI) company Moonshot AI announced Kimi K3—a model that independent measures place within one generation of U.S. frontier models. On July 27, Moonshot AI released the weights—the numerical parameters that encode what a trained model has learned—in files anyone can download, run, and build on.

Washington responded to the news by retreating to familiar corners. The Trump administration is reportedly weighing Entity List designations, which would categorize Moonshot AI as a risk to national security and impose license restrictions on its imports, as well as an executive order making U.S. companies liable for hosting Chinese models. Treasury Secretary Scott Bessent says sanctions are “on the table.” Nvidia, Microsoft, and Meta, plus over 230 other tech companies and organizations, have meanwhile answered with an industry letter warning the U.S. against imposing broad restrictions on open models. Contraband or free competition: The fight, as waged, resorts to absolutes once again.

But the absolutes answer the wrong question, and so deliver, at best, unhelpful, and, at worst, counterproductive answers. The open-weight debate has been conducted largely in the register of both existential risk and near-term misuse: bioweapons proliferation, cyber capability, censorship, and sensitive data flowing to Beijing.

Those risks are real, and they deserve the component-by-component scrutiny this author, among others, has urged. But they are not the largest thing at stake. The more consequential contest is over which countries’ models will end up as the base layers of everyone else’s work and what that position confers. No one model—or country—will win that contest outright; adopters hedge too deliberately for that. But position, held long enough, compounds.

In fairness, Washington senses deja vu; the crescendoing open-weight AI power struggle parallels the U.S.’s earlier rounds with China in the telecom arena. Seven senators urged the Commerce Department to scrutinize Chinese models by invoking the multibillion-dollar program that removed Huawei equipment from American networks; December’s annual defense budget bill ordered DeepSeek’s models purged from Pentagon systems within 30 days. Chinese models are being seen as the new Huawei gear. The telecom analogy is already writing U.S. policy. Whether it is being read correctly is another matter.

The United States has run this experiment before—confronting a subsidized Chinese technology in earnest only after much of the world had adopted it. The technology was network equipment: the base stations and routers a country’s communications run on. Huawei, China’s telecom giant, won that race.

China spent two decades making that expensive, essential equipment accessible to those who could not otherwise afford it. To do this, China created state credit lines financing Huawei’s customers at prices a Samsung executive told U.K. lawmakers that no profit-seeking company could match.

In underwriting so much of the world’s networks, what China bought was not merely market share, though Huawei remains the world’s largest telecom equipment vendor despite U.S. efforts to undercut its position. It bought China structural leverage, including leadership in declared 5G standard-essential patents, the standing to propose rewriting the internet’s architecture at the International Telecommunication Union, and networks too embedded to remove. That is path dependency, purchased outright.

The U.S. feared espionage—Huawei’s gear as Beijing’s listening post—and, darker still, a wartime kill switch. Yet there is no publicly confirmed case of a Huawei backdoor exploited for state espionage. The dependency was the power. And the United States knows what it costs to correct a dependency late—to let the equipment in first and legislate it out later. Congress first appropriated $1.9 billion to remove Chinese equipment from rural U.S. networks, but as approved costs swelled to $4.98 billion, Congress had to find another $3 billion. Six years on, the work remains unfinished. Turns out, “rip and replace” racks up quite the tab. And even after the bill is finally paid, the work itself remains harder than anticipated.

That is the view from Washington: Subsidies bought adoption, adoption became dependency, and dependency has proved brutally expensive to unwind. The view from the receiving end of that buildout—the developing countries whose networks China helped finance and build—is even more telling. In 2006, ZTE—China’s other telecom giant, this one state-controlled—offered Ethiopia something no Western lender would: the same state credit that financed Huawei’s customers, this time providing $1.5 billion to build out a national telecom network, with no conditions attached about liberalizing its economy. Ethiopia took the deal precisely because it preserved control: The state got connectivity on its own terms, and mobile subscriptions grew more than tenfold in five years. In many ways, Ethiopia was negotiating for its autonomy from Western influence.

But Ethiopia’s telecom deal had fine print, and the fine print is the lesson for AI. The rollout involved enormous contracts awarded to suppliers without a competitive process (or a justification for skipping one), repayment stretching over a decade, and enough leverage lost that Addis Ababa eventually had to split its follow-on contract between two Chinese vendors (the other, Huawei) to restore its own bargaining power. Ethiopia deserves credit for navigating the urgent need for connectivity and a lack of options. However, Ethiopia still needed years, and a rival—also Chinese—supplier to claw back position in a network it could no longer do without.

Twenty years later, China’s open-weight AI models are sparking debates that echo the concerns the telecom buildout raised: How does the majority world access an indispensable technology without surrendering sovereignty, or in other words, without trading access today for dependency tomorrow?

China’s playbook appears virtually identical to its telecom strategy. Its AI buildout involves many of the same companies, the same countries, and the same vocabulary as its broadband strategy. And open weights play the role subsidized equipment once did: They are the keystone to an indispensable new technology that one country can provide to another virtually for free to get a foot in the door, but they are also useless without the intricate, interconnected stack of other components that, conveniently, are far more expensive.

Just as countries like Ethiopia once saw Chinese telecom as connectivity without geopolitical strings attached, countries like Malaysia now describe Chinese open-weight models as “something you can control.” When the AI option promising the most control also seems to come at the lowest cost, developing countries can hardly be faulted if they “always pick the cheapest one.” These judgment calls—control and cost—are not irrational; they simply have a shelf life. The promise of “no strings attached” elapses once the welcome phase does. But misreadings of majority world motivations and their historical context are tainting the entire debate over Chinese AI.

Restriction hawks never stop to ask why countries adopt. Openness advocates treat the answer as a point on their side (though a few skeptics have noted, in passing, that adopting a model aligns you with the architecture beneath it). Both camps stop at the weight file: One to ban it, one to bless it. But weights are not the whole story: Open-weight models are not inherently sovereignty-enhancing. And the models are only one front in a wider war clashing over compute, cloud, data, and applications. But the open-weight front is where the misreading is doing the most damage, at least right now.

To be sure, the weight file itself—the downloadable file that contains the distributed open weights—has earned some of its sovereignty appeal. Once downloaded, a weight file is genuinely unlike a Huawei switch: It can be copied, run on your own machines, and kept forever; vendors surrender their leashes once the weights ship. And countries act on that appeal: Southeast Asia’s flagship regional models have deliberately mixed U.S. and Chinese bases—a sophisticated hedge against dependency on either patron.

If the story ended at the weights, the telecom analogy would fail. But a hedge is only as durable as the cost of switching, and China’s playbook ups that ante at every stage: Make a Chinese base the obvious first choice, reward staying inside the family, and let the price of leaving climb on its own. China is not selling weights; it is assembling the same structure it once assembled around network gear. Adopting an open-weight model confers real control over one layer of the stack; China’s strategy is to slowly entrench dependencies through other components in the stack to build gates and moats around the weights and then charge tolls to gain or maintain access to them.

Look at what actually surrounds a “sovereign” deployment of a Chinese model. When Malaysia launched what it called sovereign AI in 2025, the sovereignty was DeepSeek running on Huawei chips—a bundle so plainly Chinese that the government retracted the announcement within a day amid U.S. pressure (an episode that, it should be said, displayed Washington’s own leverage over a sovereign government’s choices).

Huawei—no longer just an infrastructure vendor, but a company whose software already reaches from network cores into phones, wearables, and cars—opened a cloud region in Egypt and launched an Arabic large language model with it. It has pledged to train 150,000 people in sub-Saharan Africa and 300,000 in Pakistan—skilling programs of the kind U.S. firms run too.

The difference is which stack the skills attach to. Zhipu, one of China’s leading labs—state backed, and newly flush from a multibillion-dollar share sale—pitches “sovereign AI agents” directly to Belt and Road governments. And Beijing has built the diplomatic scaffolding to match: a Global AI Governance Action Plan offering AI capacity-building to the developing world, and now a world AI cooperation organization headquartered in Shanghai. And there are no efforts to hide the playbook. It is the digital Silk Road, running a new workload.

The models themselves are being positioned to pull the rest of the stack along—a coupling that is still very much in flux today, but whose stage is being set. In August 2025, DeepSeek released a model using a data format almost no one had heard of, and said the quiet part out loud: The format “is designed for the next generation of domestically produced chips.” The ambition is to make the model a software-led road map for Chinese hardware: Build chips that run what everyone already uses, and the hardware follows the model.

When DeepSeek’s latest model shipped this past spring, eight Chinese chipmakers had it running on their silicon on day one. The picture painted is not quite a wildfire yet: Porting a Chinese model to U.S. chips still takes days, not years, so no model is a standard yet. But the stack integration is the kindling and the match—something a CUDA-style ecosystem (the software necessary to harness compute) could grow around, kernel by kernel, engineer by engineer—and the environment is dry enough to catch. The day-one coordination suggests the approach is deliberate.

And the giveaway of open-weight models is not charity. Alibaba gives Qwen, its open-weight model, away as a funnel into Alibaba Cloud, whose AI revenue now helps justify roughly $17 billion a year in new infrastructure spending. Moonshot’s “free” Kimi K3 carries a license clause requiring large hosting businesses to negotiate a separate agreement with Moonshot—and its paid API revenue has reportedly tripled since its release. U.S. firms run versions of this circuit too; Meta’s Llama license has a restrictive commercial clause of its own.

The difference is what sits at the bottom of the circuit. Meta’s ends in a private advertising business. China’s ends in state-championed chips, state-financed data centers, and a national strategy: free at the front, monetized in the middle, reinvested in the stack underneath. Telecom ran the same relationship with the economics reversed—there the equipment was expensive, and the credit was nearly free. Either way, the leverage lived in the relationship, the cultivated dependencies, not in the price tag.

There is one more echo, and it reverberates the loudest. The countries adopting Chinese models are not growing dependent because of the model weights they have; it is because of the next release they don’t have—the new and improved weights the lab generated. Because if a country cannot keep up in the AI race, they drop out. This is the Huawei lesson relearned in software: The power was never in the backdoor. It was in being the supplier everyone must return to. Beijing has at least considered closing that tap: It is reportedly weighing export controls on the weight files for its own labs’ most advanced models.

Today, the dependency is shallow—a ministry that can retrain on a U.S. model next quarter is a shopper, not a loyalty-card-carrying customer. The thing to watch is whether that stays true. If the fine-tunes, the toolchains, and the trained engineers stack up on Chinese model families faster than adopters can migrate—if the base-mixing that Southeast Asia practices today quietly stops—Chinese labs begin to rack up true customers. Telecommunications is a teaser to that story’s ending.

So the telecom analogy, read at the software artifact layer—where Washington keeps reading it—genuinely fails: Model weights cannot be embargoed like equipment or ripped out like radios. A true download ban may not even be lawful, which is why every restriction Congress has actually enacted runs through the government’s own purchasing—Pentagon systems, federal contracts, state devices. What the precedent licenses at home is narrower: covered lists in which the government controls the purchase, and inspection applied to open and closed models alike.

But read at the buildout layer, it is barely an analogy at all: the same financiers, the same bundles, the same training academies, the same institutions, welcomed in the same places for the same reasons. Analysts have begun to see the resemblance, arguing that the contest over AI stacks “increasingly resembles” the telecom competition Huawei won on financing and distribution rather than technical merit.

What the analogy still misses is the clock and the other side of the table. The adopting countries are not passive terrain awaiting a buildout. They are shrewd players with their own histories, politics, and balance sheets, hedging between two patrons whose reliability they have each had reason to doubt: Washington capped the developing world’s compute with one rule in January and rescinded it by May. With Beijing now debating its own weight controls, both taps have visibly trembled. Which is why the U.S. answer cannot be a fence—and cannot be mere presence, either. U.S. clouds are already there: African sovereign-AI projects lean heavily on U.S. clouds and grants.

But right now, the U.S. is selling exactly the closed dependence these sovereign initiatives are trying to escape. What wins a buildout’s second phase is the structurally less extractive bid: open U.S. models worth adopting, with genuinely accessible compute and financing attached, offered on terms a sovereign state can justify accepting. Right now, almost no one is making that bid: U.S. labs treat open models as a side project, and Washington’s export programs remain closer to paper than practice.

The revealing exception is Nvidia. Because it simply wants to sell chips, it is out striking “sovereign AI” deals, partnerships and subsidized government buildouts, that its U.S. peers, with different incentives, will not touch. Nvidia's become the next closest thing the United States has to a welcome-phase opponent, even if what its bid builds is dependence on Nvidia rather than openness.

The lesson is that the buildout playbook borrowed from telecom follows incentives, not flags—and that a U.S. version of it is possible when the incentives point the right way. That is not a reason to abandon the recommendation. It is the measure of how far there is to go. The United States lost the telecom buildout with the wrong offer at the wrong moment, while its champions died at home. The question now is not whether open-weight Chinese models can hurt Americans. It is who will be standing beside the half of the world that is building right now—and on what terms.


Chinmayi Sharma is an associate professor at Fordham Law School. Her research and teaching focus on internet governance, platform accountability, cybersecurity, and computer crime/criminal procedure. Before joining academia, Chinmayi worked at Harris, Wiltshire & Grannis LLP, a telecommunications law firm in Washington, D.C., clerked for Chief Judge Michael F. Urbanski of the Western District of Virginia, and co-founded a software development company.
}

Subscribe to Lawfare