How Banning Chinese AI Could Hurt American Innovation

NSA, the Cybersecurity and Infrastructure Security Agency, and the FBI rarely sign the same document. On September 8 they jointly named six Chinese firms for industrial-scale distillation of American models.

The National Security Agency, the Cybersecurity and Infrastructure Security Agency, and the FBI rarely sign the same document. On September 8 they jointly named six Chinese firms, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, for industrial-scale distillation of American models. The extraction ran against Claude, GPT, Gemini and Grok, and happened likely with Chinese government awareness.

Mao Ning called the accusations unfounded within a day. The commerce ministry followed with the sharper line: distillation is a neutral technique every lab uses, American labs included, and Washington is prosecuting a pricing problem in the vocabulary of espionage. Xi Jinping arrives at the White House on September 24, with AI safety talks already being prepared.

The coverage wrote itself. America catches the AI thieves.

Try the other question. Suppose every charge is correct and the policy works as designed: Chinese models are, and Grok blocked, delisted, and off-limits to anyone holding a federal contract. Then what?

Stay ahead of the geopolitical week.

MD Briefing delivers expert analysis across five global fronts — the Indo-Pacific, energy, geoeconomics, European security, and the Middle East — every Monday morning. Free.

Remove the cheapest supplier of the decade’s most consequential technology, and the cost does not disappear. It moves. Washington would not be taking a market from China so much as a discount from itself.

The discipline shows up in published prices, and it runs in both directions. DeepSeek’s V4 Flash billed 14 cents per million input tokens in June against five dollars for OpenAI’s GPT-5.5. On July 30 OpenAI cut its Luna tier by 80 percent, to twenty cents in and $1.20 out. DeepSeek raised its own rates roughly fourfold on August 16 and added peak pricing, which pushed Luna below V4 Flash at busy hours. Two labs, six weeks, competing on price. That is a market working.

Watch the premium end, where nothing is pressing. OpenAI launched GPT-6 Astra on September 3 at $10 per million input tokens and $50 out, with fast and long-context tiers running to $150. Five days later, three federal agencies proposed a policy whose success condition is that the cheap alternative goes away.

Developers have been voting. Chinese-built models took 46.4 percent of tokens routed through OpenRouter this summer against 35.7 percent for American ones, up from 11 percent a year earlier. Not ideology. They were cheaper and, for a widening set of tasks, good enough.

Part of the security case is sound. The gray market selling Claude access through proxy networks and pooled accounts breaks the terms every American lab writes, and the Wall Street Journal reported this week that queries reached Claude through transfer stations outside China. That argues for enforcement and procurement rules, not for telling a startup in Austin what it may run on a rented GPU. Senators Bill Cassidy and Jacky Rosen would extend a DeepSeek ban to every federal contractor. The distance between the two is a markup.

The advisory’s own remedy is stranger than the accusation. Alongside detection and intelligence sharing, it urges providers to subtly alter responses for suspected distillers so the payoff degrades and to vary those alterations so the degradation is hard to measure. Three federal agencies are recommending that American companies quietly serve worse answers to paying customers without telling them. What happens on a false positive is a question the document does not raise.

The theory points inward too. Six days before the advisory, the Justice Department backed OpenAI against the New York Times, arguing that training on copyrighted material is generally fair use. Distillation is theft when a Chinese lab does it to an American model. Scraping is fair use when an American lab does it to a newspaper. Beijing built its statement around that gap, which is what a flexible standard does: it hands your opponent the argument.

Americans made this case to the White House before the advisory and not as lobbyists for Beijing. 179 startups wrote to the administration on July 22 asking it not to cut off Chinese open-weight models. Days later, Microsoft, Nvidia, Meta, and two dozen others warned against premature restrictions. Anthropic and OpenAI did not sign. Dario Amodei has argued that open weights carry military and repression risk because guardrails do not travel with them. Anthropic also appears on every row of the advisory’s target list and sells at the premium end. Only part of that is being weighed.

Once training on another model’s outputs is a security offense rather than a contract dispute, every American startup inherits provenance paperwork and the risk that a routine engineering step gets recharacterized later. OpenAI and Anthropic can absorb that. Six people in a rented office cannot.

The cost diplomats should watch is quieter. American power in software has rested on default status: the world builds atop American platforms and absorbs American rules without negotiating them. That requires using the thing without asking permission. Condition access on export compliance, geography, and acceptable use, and American AI stops being infrastructure and becomes a license. Licenses create markets for alternatives.

Alibaba’s Qwen family logged three billion downloads in six months, passing Google and Meta combined. For a developer in Lagos or Jakarta, the weights are free and run on a laptop.

Then there is the standard the advisory settled on. Not directed by its government. Likely with its awareness. Ask what that license is on its third outing, against a French lab or an Emirati one. Allied capitals watched the Huawei exclusions widen and learned to translate. When Washington says security, more of them now hear competition.

The defensible version of this policy is narrow. Guard the weights. Guard the chip supply chain. Prosecute intrusion. Enforce the contracts the labs already write. None of that requires telling American developers which models they are permitted to find useful. The version on offer is the seductive one: protect the incumbents, call it security, send the bill elsewhere.

Scott Bessent told an audience at Southern Methodist University that the Chinese distill American models and can never get ahead of us. He may be right. What the summit will not settle is who pays for the arrangement that keeps him right. Americans will, at a price their own government will have set for them.

Imran Khalid
Imran Khalid
Geostrategic analyst and columnist on international affairs.