Wholestory

Last Updated: September 19, 2026

International Competition: The Compute Race

On September 8 the NSA, FBI and CISA jointly named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI, alleging they extracted billions of tokens from US frontier models through ‘aggressive, malicious and targeted distillation activities at industrial scale’ — DeepSeek from eleven named model versions, Moonshot from eighteen models to train Kimi K2 and K3. The agencies assess this ran ‘likely with Chinese government awareness’. It is an advisory: no charge, no sanction, no penalty. Beijing called it groundless. Eight days later the Treasury Secretary said the US is ‘open to discussions on avoiding shared risks and avoiding bifurcation of our two systems’, covering both open- and closed-weight models. He and the trade representative were due to meet Vice Premier He Lifeng in New York on September 19–21, with AI governance one of three agenda items alongside critical minerals and an expiring tariff truce, before Trump hosts Xi on the 24th. The high-level AI talks Trump and Xi agreed to in May still have not been confirmed.

The Whole Story

Since October 2022 the United States has tried to hold a lead in artificial intelligence by controlling the machines that make it. The rule the Bureau of Industry and Security issued that month created chip classifications aimed at China, set fabrication thresholds carrying a presumption of denial, and for the first time barred American citizens from supporting advanced chip production at Chinese plants. Everything since has been a variation on it: a 2023 rewrite that redefined the controlled chips after Nvidia engineered around the first set, a January 2025 framework that tiered the entire world, and that framework's rescission four months later in favour of case-by-case discretion.

The theory was denial, and it has not held cleanly. In September 2023 a teardown of a Huawei phone found a 7-nanometre chip made without the lithography the controls were meant to withhold. On inauguration day in 2025 the Chinese lab DeepSeek released R1, a reasoning model built despite the controls, which took more than $600 billion off Nvidia's market value in a single session and became the central exhibit for the argument that restrictions were spurring China rather than slowing it. By August 2025 the policy had inverted far enough that Nvidia and AMD agreed to hand the US government 15% of their China AI-chip revenue in exchange for export licences — a national-security control administered as a revenue share, without clear precedent. Stanford's 2026 index put the measured performance gap between the best American and Chinese models at 2.7%.

In 2026 the instruments multiplied and the target moved from chips to models, and then to the machines they run in. In June the government used export-control authority against a named frontier model for the first time, cutting off two Anthropic models for every foreign national including those inside the United States, then withdrew the order eighteen days later without publishing either decision. The Pentagon's annual list of Chinese military companies added Alibaba and Baidu, on indirect state and ministry affiliation and alleging nothing about their AI. In July the Federal Communications Commission barred new foreign-made humanoid robots from the American market, a category in which two Chinese firms each shipped more than 5,000 of the roughly 15,000 units sold worldwide in 2025. The argument turned personal in the same weeks: the White House science adviser accused a Chinese lab of distilling an American model to build Kimi K3 and published no evidence, the Treasury Secretary put sanctions on the table, and the two governments' own evaluators then measured that model and found it well below the frontier on cyber capability.

The competition now has two blocs, and they are drawn on opposite principles of disclosure. The United States launched Pax Silica in December 2025 and had 24 signatories to its declaration by the second summit in June 2026, alongside a separate statement on AI opportunity signed by 35 economies — text and roster published in full, commitments non-binding and unfunded until a $50 million customs-credentialing notice in August. Three weeks after that summit, states meeting in Shanghai founded a World Artificial Intelligence Cooperation Organization: the count given at the signing was 29, Beijing now says 38, no member list has been published at either figure, and the founding agreement has never been produced. Kazakhstan is so far the only country reported in both. Then in September 2026 the United States hosted a G20 innovation ministerial in North Carolina at which both China and Russia were listed among those present for a consensus statement on emerging technology — so the same year that produced two rival rosters also produced a table with everyone at it, and a text agreed there that binds none of them. What the American record does not have either is an instrument for its own model-level actions: the chip rules were published in full and can be read line by line, while the orders that reached a frontier model in 2026 arrived with no classification, no regulation cited and no notice — and the agency that administers all of it now reports licence processing running at 62 days against the 38 in its last published report. Whether the observable record supports the arms-race framing, or something more tangled, still turns on documents that have not been produced.

Continue Reading →

AI Governance Is One Item on a Three-Item Agenda

Scott Bessent and Jamieson Greer were due to meet Vice Premier He Lifeng in New York over the weekend of September 19–21 for multi-hour talks on AI governance, critical minerals and a tariff truce expiring November 10 — the last preparatory round before Trump hosts Xi at the White House on the 24th. What has not happened is the thing agreed: Trump and Xi undertook at their May summit to hold high-level AI talks, and four months later none had been confirmed. Meanwhile China barred some citizens whose work touches national technology security from leaving, and Anthropic reported Chinese labs secretly routing requests to its Claude models.

The United States remains the leader in AI. And we are open to discussions on avoiding shared risks and avoiding bifurcation of our two systems. We expect our discussions to cover both open and closed weight models.?

Context: A written statement to Axios, eight days after three of his own government’s agencies accused six Chinese companies of industrial-scale distillation. Trump and Xi agreed in May to hold high-level AI talks; as of September 15 none had been publicly confirmed.

Three US Agencies Name Six Chinese AI Companies. It Is an Advisory, Not a Case.

The NSA, FBI and CISA jointly named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI on September 8, alleging they extracted billions of tokens from American frontier models through ‘aggressive, malicious and targeted distillation activities at industrial scale’. DeepSeek is said to have used outputs from four versions of Claude, two of Gemini, five of ChatGPT and Grok 4; Moonshot to have distilled 18 US models to train Kimi K2 and K3. The agencies assess this ran ‘likely with Chinese government awareness’ — their own qualifier, not high confidence — and strengthened China’s military and cyber capabilities. No charge, sanction or penalty accompanies it. China’s commerce ministry called the allegations groundless.

China and Russia sit down at an American G20 table — and agree to a text that binds no one

G20 ministers meeting in Chapel Hill, North Carolina on September 1 and 2, hosted by the Commerce Department and the White House science office, closed with a consensus Innovation Ministerial Statement. The published list of those present runs to twenty nations and unions and includes the People's Republic of China and the Russian Federation — Washington's two named rivals inside the same AI document rather than across a line from it. What they met over is thin by design. Its six pillars call on members to 'preserve national sovereignty in the governance of emerging technologies', warn that 'outdated or inflexible regulatory approaches can unintentionally restrict innovation', and hold that 'consumers will determine which AI models best meet their needs through free market competition'. Every deliverable is voluntary, export controls go unmentioned, and neither the statement nor the White House release records which of those present actually joined the consensus.

America's national AI research resource stops being a pilot

The National Science Foundation set up an operations center for the National Artificial Intelligence Research Resource, the public-private program that gives American academic researchers compute, data and models they could not otherwise buy. The pilot launched in January 2024 and was due to expire in January 2026; the center makes it permanent national infrastructure, coordinating resource providers, running the portal and training users. It will be led by the San Diego Supercomputer Center at UC San Diego with the Texas Advanced Computing Center at UT Austin. The pilot has backed more than 800 research projects. No dollar figure was published.

A Chinese memory-chip maker takes the Pentagon's military-companies list to court

ChangXin Memory Technologies sued the Department of Defense in Washington on August 28, asking a judge to set aside its designation as a Chinese Military Company under Section 1260H — the same annual list that added Alibaba and Baidu in June. CXMT makes DRAM, the ordinary memory chip in consumer electronics, and calls the listing arbitrary and capricious under the Administrative Procedure Act. Its complaint also says the Pentagon published a notice on February 13 removing CXMT, withdrew it the same day without explanation, then relisted the company on June 8 — an account sourced only to the plaintiff's filing.

Alibaba and Baidu join the Pentagon's Chinese-military-companies list — on ministerial affiliation, not AI

The Deputy Secretary of Defense signed the annual Section 1260H designation on June 5, 2026, filed it on June 8 and had it published in the Federal Register on June 10: 80 parent entities identified as Chinese military companies operating in the United States, with Alibaba Group Holding Limited and Baidu, Inc. added and 10 previously listed entities removed on the ground that they do not operate in the United States. The stated basis for the two additions is identical word for word but for the name — “Alibaba is indirectly affiliated with SASAC… Alibaba is a military-civil fusion contributor to the Chinese defense industrial base because it is affiliated with MIIT” — and neither entry alleges anything about the companies' AI models, their cloud businesses, or any contract with the People's Liberation Army. The consequence that reaches AI is not in this document at all but in Section 1532 of the FY2026 defense authorization act, in force since January 17, 2026, which bars contractors from using AI products developed by listed entities in the performance of a Department of War contract without a case-by-case waiver. CNBC's widely repeated procurement dates — direct contracting barred from later in June 2026, third-party procurement from June 2027 — appear in neither primary document, and it cites no statute for them. The list is also worth reading for who is not on it. A full-text search returns no occurrence of Moonshot AI, DeepSeek, Zhipu, Z.ai or ByteDance; Huawei, SMIC, Tencent, Unitree, SenseTime, CloudWalk, Yitu, Inspur, Sugon, DJI, CXMT and YMTC are all there. The Chinese frontier-model labs at the centre of Washington's arms-race argument are absent from the Pentagon's military-companies list, and the two consumer platforms newly added to it are there for ministerial affiliation.

The president showed an olive branch, and it hasn't been taken up. So I think we're just going to let it lie.?

At a G20 press conference on September 2, Commerce Secretary Howard Lutnick said Beijing has not taken up January's eased H200 licensing — "The Chinese haven't really taken it up" — because it is steering firms toward domestic chips, so "I don't think it accomplishes what it was intended to." He added that the coming Trump-Xi meeting will not cover export controls, and that Commerce is instead expediting AI-export licenses to spread "the American AI stack" to allies. On the remote-access loophole he promised "whack-a-mole" using AI detection tools, without saying when a rule lands. His account sits against the August 19 report that ByteDance and Tencent had each quietly taken about 10,000 H200s offshore in Hong Kong.

Context: A fresh characterization, not yet independently settled. It cuts against the August 19 Financial Times report that ByteDance and Tencent had each taken roughly 10,000 H200s — though those were held offshore in Hong Kong at Beijing's direction, consistent with minimal mainland uptake. Checkable against Chinese import records and Nvidia's China revenue.

Washington Starts Drafting the Rule That Would Follow the Compute, Not the Chip

The Commerce Department is working on an export control aimed at Chinese remote access to AI compute hosted in Thailand and Singapore, and could put it to trade groups as early as September. It would be the first instrument to attach to the use of compute rather than to who owns it. One driver, per The Information, is Moonshot's Kimi K3. The objection is now specific: BIS advisory opinions since 2009 hold that remote access to a chip is not an "export" under 15 CFR 734.2 and bind the agency, so closing the gap by rule rather than statute invites a major-questions challenge under West Virginia v. EPA. The durable fix is legislation — the Remote Access Security Act (H.R. 2683, passed the House 369-22; Senate companion stalled) and the Chip Security Act (H.R. 3447) — neither yet law. The likelier near-term route is know-your-customer rules, one of which already exists, unenforced, from January 2025.

A Draft Cable Tells Thirty-Five Countries to Pick a Side

A State Department letter in draft, reported by Reuters, would tell the 35 signatories of June's AI Opportunity Statement that they cannot belong to both the American and Chinese AI ecosystems. “To be part of everything is to be part of nothing,” it reads. Membership brings access to investment opportunities reserved for members; joining China's competing framework would mean exclusion. About two dozen countries have signed, among them Japan, Australia and South Korea. Kazakhstan is the only one inside both coalitions, and a significant source of the critical minerals Pax Silica exists to secure. A US official said it is hard to see how a country can credibly be a trusted partner in one ecosystem while joining an initiative China designed to advance a competing vision. The State Department declined to comment on “purportedly leaked internal documents”. It is a draft and may be softened.

“We have information that Moonshot AI distilled Anthropic’s Fable for the development of its K3 model.”?

The White House science and technology adviser, OSTP Director Michael Kratsios, posted the allegation on X, adding that Moonshot "developed a sophisticated internal platform to conduct large scale distillation against U.S. models, allowing them to quickly switch between multiple methods of access to avoid detection," and that the company "has also acquired GB300-equipped servers and has accessed GB300s in Thailand, likely to train its AI models" — chips whose export to Chinese entities is restricted. It is the most specific public accusation the U.S. government has made about how a Chinese frontier model was built.

Context: Still unverified. No evidence accompanied the accusation (Politico: Kratsios "did not provide evidence"); Moonshot denies it and MOFCOM called it evidence-free. The Information (Aug 28) confirms Moonshot has a Southeast-Asian channel for Blackwell chips but not whether it is a legal rental or an illicit purchase. No Entity List or sanctions action has followed, and Moonshot is absent from the Pentagon's Section 1260H list.

A Bill to Let Clouds Report Their Own Customers

H.R. 9546, the Cloud Security Act, introduced by Josh Gottheimer and John Moolenaar and referred to House Judiciary, would amend the Stored Communications Act so a cloud provider may hand the Commerce Secretary information about a customer it believes in good faith to be a specified foreign entity using a covered cloud product. It is worth being precise: it does not require reporting, does not bar those customers from US clouds, and is a bill in committee, not law. Its definitions reach cloud services used to build or run billion-parameter models.

The Chips Cannot Be Exported. The Compute Can Be Rented.

Chinese AI firms are reportedly reaching the compute of Nvidia's most advanced chips, GB300s among them, through data centres in Southeast Asia. Less than a week after Moonshot AI released Kimi K3 in July, White House official Michael Kratsios accused the company of using GB300s through a facility in Thailand. The important part is not that a rule was broken but that it was not: Cassia King of the Institute for AI Policy and Strategy says the arrangement is legal "so long as Moonshot isn't actually buying and owning the physical hardware directly", because the export-control regime attaches to ownership of physical chips, not to remote access to what they compute. Legislation to give the government authority over cloud access to controlled technology is under discussion, with hurdles before it could bite.

Washington's China Commission Says the Contested Resource Is Now Data That Cannot Be Scraped

The US-China Economic and Security Review Commission published a report on China's data economy, and its most consequential claim is about scarcity rather than scale. China designated data a factor of production in 2020 and has since built exchanges, accounting rules and industrial data programmes to commercialise it — aimed, the Commission argues, at exactly the enterprise, operational and physical-world data that cannot be scraped, now that the open web is largely exhausted as a training resource. The Commission exists by statute to report risks arising from China, so this is its assessment rather than a neutral finding; it also records low data quality and private-firm reluctance as continuing obstacles.

The H200 finally reaches China — and Beijing keeps it just offshore

After eight months in which export licences moved almost nothing, Nvidia's H200 accelerators have begun arriving at Chinese technology companies: ByteDance and Tencent have each taken about 10,000 in recent weeks, the Financial Times reports, with others expected. It is the first real movement in a stop-start year — China blocked H200s at customs in January, cleared ByteDance, Alibaba and Tencent for more than 400,000 units a fortnight later, and Washington narrowed the field again in May. What makes the flow strange is where the chips sit: Beijing has told firms to keep the hardware off the mainland to protect its own chipmakers, routing the processors to Hong Kong, outside the mainland customs border, where mainland engineering teams reach the compute over cross-border links — a mirror of the Southeast-Asia remote-access loophole Washington is separately trying to close. One figure is unsettled: the FT puts the US per-company ceiling at 100,000 chips where earlier reporting had 75,000, with no revision documented, so the higher number rests on the FT alone.

Observation

BIS reports a 62-day licence average to Congress, and benchmarks it against the one year it has not published

The Bureau of Industry and Security — the agency that writes and enforces every chip control on this record — filed its FY2025 annual report to Congress, and three of its own documents can be read side by side. The new report says: "BIS also processed export licenses expeditiously. In calendar year 2025, BIS processed approximately 30,500 license applications. The average processing time for these licenses was 62 days – significantly less than the 90-day statutory benchmark, and approximately the same as in calendar year 2024 (60 days). This is despite the 43-day government shutdown in Q4 2025." The bureau's FY2023 report says it "processed 37,943 license applications" with an "average license application processing time in FY 2023 [of] 38 days." Its FY2022 report says it processed 40,765 with an average of 37 days. On the bureau's annual-reports page, those are the only other reports published: FY2025, FY2023 and FY2022. There is no FY2024 report there, and calendar year 2024 — the one year the new report compares itself to — appears in no published report on that page. Two caveats belong in the same breath, and readers can check both against the documents. The FY2025 report states its licensing figures by calendar year while the two earlier reports state theirs by fiscal year, so the comparison is not unit-identical. And the FY2025 report volunteers the 43-day shutdown as a drag on its own number. What the three published figures say together is that average processing time is 62 days against 38 two years earlier, and that volume fell from roughly 38,000 applications to roughly 30,500. Industry reports the same direction independently: the US-China Business Council's July survey found 66% of respondents with licences pending past the 90-day statutory benchmark.

The first money behind Pax Silica: $50 million for a supply-chain credentialing platform in Panama

The State Department published a competitive Notice of Funding Opportunity for the Pax Silica AI Assistance Project, announced at June's summit and now open to bidders until August 20. "Working with Congress," the department says, it "seeks to commit up to $50 million in foreign assistance funding" to build an AI supply-chain credentialing and provenance platform that speeds semiconductors, AI infrastructure, critical minerals and related goods through customs. It begins as a pilot with Panama's ports and customs authorities, integrating with existing customs, port-operator and shipper tracking systems, and would expand to other Pax Silica economies only if the pilot works. It is the first disclosed money behind an initiative that had until now consisted of a declaration and a signatory list — and it is aimed at logistics rather than at capability: the American bloc's opening expenditure is on knowing which containers to wave through.

Thirty-eight countries have become founding members of the World Artificial Intelligence Cooperation Organization.?

Chinese Foreign Minister Wang Yi gave the figure in a signed article in the People's Daily, relayed in English by China Daily, crediting China with having put forward the Global AI Governance Initiative and initiated the organization's establishment. The article restates that the founding agreement was signed in Shanghai on July 16. The count has moved: every account of the signing itself — The Diplomat, Al Jazeera, The Straits Times and China Daily alike — reported 29 signatories.

Context: Unverified: no membership list has been published at either count, and the founding agreement itself has never been published or quoted by any account of it. The four accounts of the signing that named individual founding members disagreed with each other, with only Russia, Brazil and Pakistan common to all four. This is an absence in the published record rather than proof the members do not exist; the checkable milestone is publication of the agreement or a member roster.

Most pending export licenses are for items that are already available in China from Chinese or international suppliers — effectively sidelining American companies for no strategic gain.±

The US-China Business Council, the trade association of American companies operating in China, published the results of a July flash survey of 31 member firms in technology, industrial manufacturing, energy and healthcare. Its reported findings: 95% cite long licence review times; 66% have had licences pending for at least three months, past the Commerce Department's 90-day statutory benchmark, and 31% for one to two years; 82% say their pending licences cover items with comparable alternatives from non-US suppliers; 36% put their losses from delay at tens of millions of dollars or more, with some naming hundreds of millions or billions; 73% report sales lost to Chinese competitors. Half cite the absence of Technical Advisory Committee meetings, the standing industry-feedback channel, which the council says has been cut back since 2025 except for the Emerging Technology committee. The council is the interested party in this argument — its members' business is the trade the controls restrict — and several of the percentages rest on 20 or 21 answers rather than all 31.

Context: The delay half is corroborated by the government's own published record: BIS's FY2025 annual report gives a 62-day average for 2025 against the 38 and 37 days its FY2023 and FY2022 reports gave. The conclusion — that the delays buy "no strategic gain" — is the council's own inference from members' self-reported view of foreign availability, on a sample of 21 for that question, and is not independently established.

The American bloc has a name, a text and a published membership: Pax Silica reaches 24 signatories

Three weeks before 29 states signed China's AI organization into being in Shanghai, the United States held the second summit of its own AI-and-supply-chain bloc in Washington. Pax Silica — launched in December 2025 by Under Secretary of State for Economic Affairs Jacob Helberg and described by the State Department as its "flagship effort on AI and supply chain security" — took ten new signatories over June 25-26, and the same summit produced a separate Joint Statement on AI Opportunity signed by 35 economies including the United States. The declaration itself is short and non-binding, and it reaches further up the stack than the chip rules do: signatories "encourage efforts to partner on strategic stacks of the global technology supply chain, including, but not limited to, software applications and platforms, frontier foundation models, information connectivity and network infrastructure, compute and semiconductors, advanced manufacturing, transportation logistics, minerals refining and processing, and energy." It commits no money and creates no institution, and its operative verbs are the diplomatic ones — encourage, seek, intend, endeavor. What it does do is name a roster. The signatory page lists all 24 by name: Argentina, Australia, Chile, Costa Rica, El Salvador, the European Union, Finland, Germany, Greece, India, Israel, Italy, Japan, Kazakhstan, the Netherlands, Norway, Panama, the Philippines, Qatar, the Republic of Korea, Singapore, Sweden, the United Arab Emirates and the United Kingdom. Taiwan endorsed the declaration's principles as a "non-signatory participant" through a separate January 2026 joint statement. Italy joined on July 31. The two State Department documents both give the total as 24 while listing different sets — the summit fact sheet counts the United States and not Italy, the standing signatory page counts Italy and not the United States. One name on that roster explains the argument that followed. Kazakhstan, admitted in June as the first Central Asian member and a significant source of the critical minerals the initiative is built around, is also reported to have joined the Chinese organization founded three weeks later.

No AI-chip export policy to China can be “permissive, implementable, enforceable, and protective of US national security” at once.?

Writing for the Council on Foreign Relations, former NSC technology official Chris McGuire argued the January 2026 case-by-case rule proved that a permissive chip-export policy cannot simultaneously be enforceable and protect national security — and warned the same logic could be stretched to license far more capable Blackwell/GB300 chips. A direct rebuttal to the dependency theory, casting the loosening as strategically incoherent.

Context: Enforceability claim still open before the 2027-12-31 horizon, but the agency itself has now recorded a gap: BIS's FY2025 annual report to Congress says that "in certain areas, there remains a lack of alignment between U.S. controls and those of partners and allies," naming semiconductor manufacturing equipment as a particular concern. The August compute-rental review — into conduct the rules may not reach at all — is the next milestone.

Israel launches a National AI Program, bidding to be a ‘global AI superpower’

Prime Minister Benjamin Netanyahu and the head of the Prime Minister's Office National AI Directorate, Brig.-Gen. (res.) Erez Eskel, launched Israel's National AI Program at a government conference, moving Government Decision #4255 into an operational phase after several months of inter-ministerial drafting. The published strategic plan (National AI Directorate, August 2026) sets two declared goals — securing Israel as a "global superpower" in AI and lifting the wider economy — and names the country's chosen fields of differentiation: cyber, "physical AI" (robotics and embodied systems), compute and "powerhouse" computing infrastructure, a national quantum computer, and human capital. Notably, the plan states it will be financed "through investment rather than full state budgeting" and carries no single headline appropriation, relying instead on blended public-private funding and shared infrastructure. It positions Israel explicitly against a global field it describes as shaped by "export controls, concentrated supply chains, corporate allocation decisions and strategic alliances" — a new national entrant alongside the U.S. (Stargate, NSF), the EU (InvestAI) and China already on this record, and the first sovereign AI strategy this page has tracked from a mid-sized state defining its bid around cyber and embodied AI rather than frontier chips.

Washington opens a review of the chip-rental loophole — and finds it may be legal

The enforcement arm of the Bureau of Industry and Security launched a formal review of how Chinese AI firms reach controlled Nvidia chips they cannot buy: not by importing them, but by renting the computing power in third countries. According to Bloomberg (relayed here by The Next Web and ROIC, the primary report being paywalled by DataDome), the review is building two lists — countries hosting black markets that move restricted chips physically into China, and countries where Chinese firms tap the chips remotely. The second list is the unusual one, because remote access is not, at present, illegal: BIS built its powers around the movement of physical goods, and it is unclear whether it can police a cloud-computing arrangement at all. The structure at issue is deliberately hard to trace — Alibaba, for one, reaches Nvidia chips in Malaysia through Megaspeed, a Singaporean firm already under U.S. diversion investigation, via a Singapore shell owned by a Cayman entity Alibaba controls; the chips never move, only the workloads do. The legislation that would grant BIS explicit remote-access authority, the Remote Access Security Act, passed the House in January 2026 and has sat in the Senate since. So the week's action is an investigation into conduct the rules currently permit — the export-control regime discovering that its central 2026 evasion may be one it has no authority to stop.

China's air force reveals an AI system that plans mass air strikes

A state-television documentary broadcast for the 99th anniversary of the People's Liberation Army disclosed that the PLA Air Force has used an "intelligent strike planning system" to draw up battle plans for operations involving more than a hundred units — prioritising targets, sequencing attack waves and allocating tasks to individual formations. The system, developed by a team led by Senior Colonel Deng Jianping, was described as having been used "multiple" times in training exercises whose scale, the programme said, had outrun what commanders could plan by hand. The account is Chinese state media (CCTV, relayed by the South China Morning Post and Global Times), which the record treats as partisan: it establishes what Beijing is willing to claim about fielding decision-support AI, not an independently verified operational capability. It is the clearest Chinese-side counterpart to date of the American military-AI programs already on this record — the Pentagon's Replicator and its 2026 supply-chain order.

Kimi K3 was trained on 20,000 Nvidia chips — leased through Alibaba's cloud

A Bloomberg investigation, relayed by Tech Times, reported that Moonshot AI trained Kimi K3 on roughly 20,000 Nvidia Hopper-generation chips leased through Alibaba's cloud infrastructure — and that the Bureau of Industry and Security is examining the arrangement's compliance as part of a broader look at Chinese cloud access to controlled silicon, in light of BIS's May guidance that data centers already deploying controlled items need licenses for Chinese-party access. The finding reframes July's marquee capability story: the Chinese model graded frontier-class by independent indices was built on American accelerators reached through a rental arrangement, which makes K3 evidence for both sides of the export-control argument — Chinese labs can reach the frontier despite the controls, and they still need American silicon to do it.

Observation

A 29-state AI organization has been founded, and the record of its founding is missing its own documents

Four things about the World Artificial Intelligence Cooperation Organization can be checked against documents that exist, and each comes back short. The agreement said to have been signed in Shanghai on July 16 is neither published nor linked by any account of it, Chinese, analyst or Western. Xi Jinping's own address, published in full in English by China's foreign ministry, gives no signatory count and no signing date, and does not say the body is headquartered in Shanghai. A search of the full text returns no “29”, no “16 July”, and none of “sign”, “signed”, “signatory”, “charter” or “agreement”. Xi says only that the organization “has come into being in Shanghai.” The four accounts that name founding members do not agree on who they are, and no two lists match. Forbes prints Russia, Belarus, Serbia, Cuba, Brazil, Venezuela and Pakistan; The Diplomat prints Russia, Pakistan, Indonesia, Brazil, Kazakhstan, Cambodia, Laos, Malaysia and Myanmar; Al Jazeera prints Indonesia, Brazil, Malaysia, South Africa, Senegal, Russia and Pakistan; The Straits Times prints Brazil, Kazakhstan, Pakistan, Russia, Laos and Indonesia. Only Russia, Brazil and Pakistan appear on all four, against a claimed membership of 29. Forbes is the only source for Belarus, Serbia, Cuba and Venezuela, and cites Wikipedia for its central facts. And the accounts disagree about what kind of body it is. The Straits Times describes it as a non-governmental organisation; The Diplomat, Al Jazeera and China Daily all describe it as intergovernmental. On July 31 China's UN ambassador briefed member-state representatives on the organization, presenting it as the first intergovernmental body dedicated to AI cooperation — the diplomatic rollout moving from founding announcement to recruitment inside a week.

Washington moves the UAE into its trusted tier for advanced chips

The Commerce Department upgraded the United Arab Emirates to Export Administration Regulations Country Group A:5, giving the UAE government and approved commercial parties access to advanced computing items under the licensing posture reserved for close partners. It formalizes the Gulf corridor this record traced from the November 2025 export approvals: the UAE is no longer a case-by-case exception but a categorized ally in the chip-control architecture, at the moment Gulf sovereign capital is financing a growing share of the datacenter buildout.

Observation

The June order disclaims any licensing requirement for releasing a model; ten days later, export-control authority reached one

Executive Order 14409 of June 2, 2026 says, in Section 3(c): “Nothing in this section shall be construed to authorize the creation of a mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of new AI models, including frontier models.” A case-insensitive search of the full text of the order returns no occurrence of “export control”, “Bureau of Industry and Security” or “Export Administration Regulations”; “licensing” and “preclearance” each appear once, in the sentence quoted, and the disclaimer is scoped to Section 3 by its own terms. Ten days after the order was signed, export-control authority did reach a particular frontier model: on June 12 the government required Anthropic to cut off access to Claude Fable 5 and Mythos 5 for every foreign national, including those inside the United States. Eighteen days after that it was withdrawn. Neither decision was published, and no account of either names the classification, regulation or notice it was made under — where BIS restrictions, as the Atlantic Council notes, ordinarily carry a public explanation in the Federal Register. The two documents do not contradict each other on their face: an export control is not a licensing regime for release, and the disclaimer covers only Section 3. The observable point is narrower. The authority that reached a frontier model in June appears nowhere in the order that addresses frontier models, and it operated without a published instrument at either end.

The FCC bars new foreign-made humanoid robots from the American market

On July 28, 2026 the Federal Communications Commission added two categories to its Covered List: “advanced robotic devices” — defined as mobile robots such as humanoids and quadrupeds — and connected power inverters, in each case those produced in foreign countries. Equipment on the Covered List cannot obtain the equipment authorisation a device needs before it may be imported, marketed or sold in the United States. The Commission can add to that list only at the direction of national security authorities, under the Secure and Trusted Communications Networks Act, and its fact sheet records the trigger: determinations by a White House-convened Executive Branch interagency body that these foreign-made products, “regardless of the nationality of origin,” pose “unacceptable risks to the national security of the United States or the safety and security of United States persons.” Three limits sit on the face of the document and are absent from the coverage of it. The bar applies only to new device models, not to models already authorised or devices already bought. It “does not impact purchase or use by the federal government at all.” And producers may apply to the Department of War or the Department of Homeland Security for what the Commission calls Conditional Approval. The FCC has made comparable Covered List additions in recent months for uncrewed aircraft systems and consumer-grade routers. The market at stake is lopsided. Of roughly 15,000 humanoid robots shipped worldwide in 2025, the Chinese firms Unitree and AGIBOT each shipped more than 5,000, while Tesla and Figure AI each shipped a few hundred or fewer — figures the research group Omdia supplied to the Associated Press. Neither determination names China, or any other country; the AP account of the action was headlined “U.S. bans foreign-made humanoid robots, targeting China over national security.” China's foreign ministry answered on July 29, spokesperson Mao Ning saying that “protectionism does not make the U.S. more competitive, and it will only hurt the interests of U.S. companies and consumers,” and that China would take all measures necessary to defend its firms.

Twenty-one economies, the United States among them, sign a statement encouraging support for open-source AI

The 21 APEC member economies adopted the 2026 APEC Digital and AI Ministerial Statement — the Chengdu Statement — in Chengdu on July 23, 2026, at a meeting chaired by China's Minister of Industry and Information Technology Li Lecheng and opened by Vice Premier Zhang Guoqing. Its paragraph 15 is the one that bears on the competition: “While respecting security, data protection and intellectual property rights, we encourage member economies to support open-source models and projects that employ strong security assurance through development and deployment. We also encourage member economies to engage in cooperation with open-source communities.” The instrument is non-binding and reads that way throughout. It encourages, notes, welcomes and reaffirms; it imposes no obligation and names no enforcement; and its third paragraph expressly acknowledges “member economies' different approaches to their respective digital and AI policies.” What gives it weight is the signatory list and the date. The United States is one of the 21, and the statement was adopted the day after the White House science adviser publicly accused Moonshot AI of distilling a US frontier model. China chairs APEC in 2026; the ministerial goes to Viet Nam in 2027.

“We are finding watermarks of our US large language models on many Chinese models, and that’s unacceptable.”?

Treasury Secretary Scott Bessent, in a Fox Business interview on July 21, said the administration was examining whether Chinese open-source models were built on stolen U.S. intellectual property — "a very technical AI word for it called distillation, but you and I would call it theft" — and named no company. The next evening he set out the policy consequence on X: "We support open-source AI and the innovation it unlocks. But open source is not open season on American IP. When PRC firms conduct covert, industrial-scale distillation attacks that cross the line into IP theft, sanctions and Entity List designations will be on the table." The watermark assertion is the only evidentiary claim either official offered this week.

Context: Unverified: no supporting evidence was published — neither Treasury nor Commerce released watermark findings, sample models, methodology, or named a company, and the July UK AISI/CAISI Kimi K3 assessment tested cyber capability, not provenance. The threatened consequences remain unexecuted: no Entity List addition or sanctions against any Chinese AI firm, and Moonshot is absent from the Pentagon's June Section 1260H list. This is an absence in the published record, not proof no evidence exists.

The leading closed labs, already a duopoly in terms of AI model revenue, want the government to eliminate their open-source competition.?

David Sacks, an outside adviser to the White House on AI, wrote on X on Sunday, July 19, 2026: “We are at a critical inflection point in AI policy. The leading closed labs, already a duopoly in terms of AI model revenue, want the government to eliminate their open-source competition.” He added: “They have laid their cards on the table. It is time for the rest of Silicon Valley — the vast majority that still values open competition — to do the same.” The posts name no company. It is an attribution of motive to unnamed firms made from inside the US policy process, three days before the White House science adviser publicly accused a Chinese lab of distilling an American frontier model.

Context: An assertion about other companies’ intentions, published without evidence and naming no company, so there is no specific claim to test. It is recorded as a position taken inside the US policy process during the July argument over whether to restrict American access to Chinese open-weight models. It would become checkable if any of the firms it describes filed a submission asking for restrictions on open-weight releases; none has been produced.

I hereby announce that in the next five years, China will provide developing countries with 5,000 opportunities in AI training and seminar programs; develop international AI application cooperation centers with the Association of Southeast Asian Nations, the League of Arab States, the African Union, the Community of Latin American and Caribbean States, the Shanghai Cooperation Organization, and BRICS; and enable 30 countries to use the AI-powered meteorological warning system, or MAZU, to safeguard homes around the world.?

Xi Jinping's address to the World AI Conference in Shanghai on July 17, published in English by China's foreign ministry, attaches numbers to one thing and to nothing else. The three deliverables are Chinese bilateral commitments announced alongside the new organization rather than commitments of it: no source says the World Artificial Intelligence Cooperation Organization funds or administers any of them. The address states no monetary figure, no budget, no start date and no delivery mechanism, and does not say who selects the 30 countries that are to receive MAZU.

Context: A five-year delivery commitment made on July 17, 2026; none of the three deliverables is checkable yet. The address supplies no budget, start date or delivery mechanism and names no body responsible for any of them, so the count has to be checked against Chinese ministry records and recipient governments rather than against the pledge itself. The earliest checkable milestones are the establishment of any of the six named cooperation centres and the first MAZU deployments outside China.

Twenty-nine states found a world AI organization in Shanghai, and no Western government is among them

Representatives of 29 countries signed an agreement in Shanghai on July 16, 2026 establishing the World Artificial Intelligence Cooperation Organization, the day before the 2026 World AI Conference opened in the same city. Chinese Foreign Minister Wang Yi signed for China, and UN Secretary-General António Guterres attended. China first proposed the body at the 2025 edition of the same conference, where Premier Li Qiang unveiled it and named Shanghai as its intended seat. The count of 29 and the July 16 date are carried alike by The Diplomat, Al Jazeera, The Straits Times and China Daily; the details about Wang Yi and Guterres rest on The Diplomat alone, which attributes them to Xinhua and to China's foreign ministry. What the founding does not have is a published text: no account of it, Chinese or Western, links or quotes the agreement.

The first model-level export control is lifted after eighteen days, and neither the order nor its withdrawal was published

The export controls applied to Claude Fable 5 and Claude Mythos 5 on June 12, 2026 were lifted on June 30, eighteen days after they took effect. Anthropic's own filing records the moment — “As of today, June 30, the export controls on Fable 5 and Mythos 5 have been lifted” — and hyperlinks those words to a post by Commerce Secretary Howard Lutnick on X. Fable 5 was restored globally on July 1; Mythos 5 came back only to a set of US organisations, after government approval on June 26. What is missing is the instrument, at both ends. Bureau of Industry and Security restrictions ordinarily arrive with a public explanation in the Federal Register; the Atlantic Council records that this one “was negotiated privately, leaving no clear guidance for the next company,” and no account of the episode — the vendor's own filing included — names an export-control classification, a section of the Export Administration Regulations, or a Federal Register notice for the June order. The first known use of export-control authority against a named frontier model was imposed and withdrawn without either decision being published. In between, around a hundred named cybersecurity practitioners — the count differs across accounts, from “roughly 100” to “one hundred and fifty” — wrote to Lutnick and to National Cyber Director Sean Cairncross demanding the restriction be reversed, arguing that it “has taken the best models away from defenders, created market uncertainty, and risked America's AI leadership without any real risk to justify it.” Signatories named in the coverage include Alex Stamos, Katie Moussouris, Rachel Tobac, Chris Wysopal and Joe Levy.

Export control reaches inside the United States: a frontier model cut off from foreign nationals

Citing national security authorities, the U.S. government issued an export-control directive requiring Anthropic to suspend all access to its Claude Fable 5 and Mythos 5 models by any foreign national — not only abroad, but inside the United States, including the company's own foreign-national employees. Unable to verify nationality in-product, Anthropic disabled both models for every customer. What is new here is the instrument, not the outage: the export-controls practice at Greenberg Traurig called it "the first known U.S. use of export control authorities to regulate a particular AI frontier model on a national security basis," and noted that because it bit on deemed exports it reached API calls, embedded agents and internal tooling wherever a foreign national could reach them. Anthropic's contemporaneous filing records that the directive "did not provide specific details of its national security concern"; access was restored at the end of June. The chip-control regime this page has tracked since 2022 now has a model-level counterpart.

Sell China the fourth-best chip so “their developers get addicted to the American technology stack.”?

Explaining why the administration reversed course and let Nvidia resume H20 sales, Commerce Secretary Howard Lutnick said the U.S. does not sell China its best, second-, or third-best chips — and that the point of selling the ‘fourth one down’ is to keep Chinese developers reliant on U.S. technology: ‘You want to sell the Chinese enough that their developers get addicted to the American technology stack.’ A rare on-record statement of the dependency theory behind the policy — the opposite of the denial logic the controls were built on.

Context: Forecast still open before the 2027-12-31 horizon, but the early evidence cuts against it: by mid-2026 the reported dependency ran partly the other way, with nearly 200 U.S. startup founders and 20-plus firms (Nvidia, Microsoft, Meta, Palantir) urging the administration not to cut off the Chinese open-weight models smaller American firms rely on (Politico 2026-07-23; CNBC 2026-07-25). Revisit against adoption data on both sides.

The U.S. accusations "lack any actual evidence, have no legal backing, and effectively amount to a double standard. It is a classic case of hegemonic behavior in the AI sphere."±

China's Ministry of Commerce issued the first direct government response to the distillation accusations on July 27, rejecting them outright while arguing that distillation is widespread on both sides — "many U.S. AI companies have distilled from China's models for their own R&D and training" — and that Washington had ignored "the extremely short interval between the release of Chinese enterprises' AI models and U.S. frontier models." It said China "will take all measures necessary to staunchly defend its legitimate and legal rights and interests," and urged the U.S. to honour the consensus reached between the two heads of state. Quoted from CSET's English translation of the Chinese original.

Context: Mixed: the checkable sub-claim holds — MOFCOM’s “nearly 200 U.S. startups” figure matches Politico’s reporting, and 20-plus firms (Nvidia, Microsoft, Meta, Palantir) opposed “premature restrictions” on open-weight models on July 24. But the central charge that the U.S. accusations lack evidence describes what has been disclosed, not proof none exists — and MOFCOM published none for its own counter-claim either.

Two governments measure Kimi K3 — and get an answer the week’s rhetoric did not

The UK AI Security Institute and the U.S. Center for AI Standards and Innovation, a Commerce Department body, published a joint preliminary assessment of Moonshot AI's Kimi K3 on July 23, the first bilateral state evaluation of a Chinese frontier model. On ExploitBench — a 41-task Carnegie Mellon benchmark over post-2023 vulnerabilities in Chrome's V8 engine — K3 scored 32% against 24% for GLM-5.2, then the most cyber-capable open-weight model; but it achieved arbitrary code execution, the benchmark's highest-severity outcome, on 0 of 41 tasks, where the most cyber-capable models averaged 20 of 41. On "The Last Ones," a 32-step simulated corporate-network attack, K3 reached step 17 on average against 28.5 for the most cyber-capable U.S. models, and completed the range in 1 of 10 attempts against 6/10 and 7/10 for the leaders. The institutes state their own limits: preliminary results, K3's aggregate score estimated from a single benchmark and so carrying a wider confidence interval, a selective task set because of K3's hosting, and — importantly — U.S. closed-weight models evaluated with system-level safeguards disabled to measure maximal capability, which shipping versions do not permit. They also found K3's own safeguards did not stop it attempting exploit development. Set beside the week's other U.S. government artifact, the picture is discordant: on July 22 the OSTP director said Moonshot had run "large scale distillation against U.S. models" to build K3; on July 23 two governments jointly reported that "Kimi K3 performs significantly below the most recent frontier cyber-capable models." The two address different questions — where capability came from, and how much of it there is — and neither resolves the other.

A statutory demand tests whether the 2025 rescission left a foundry loophole open

Senator Elizabeth Warren, ranking member of the Senate Banking Committee, invoked the Export Control Reform Act of 2018 — which obliges Commerce to produce "any information obtained at any time" under the export regulations on a ranking member's request — to compel the Bureau of Industry and Security to hand over documents by August 7, 2026. Her argument runs on the machinery this page has tracked: the January 2025 Foundry Due Diligence rule makes foundries such as TSMC presume that advanced chips need a licence unless due-diligence obligations are met, but it works only on top of the AI Diffusion Rule's worldwide licence requirement. Rescinding the latter in May 2025, she writes, "created a foundry loophole that brings the United States back to the very circumstances that allowed Huawei to divert millions of AI chips in the first place." The release also states that the promised AI Diffusion replacement, "more than a year later, still has not been issued" — the narrower January 2026 case-by-case rule for H200-class chips is not a replacement framework. This is a minority-party document: primary as to the demand and its deadline, contested as to BIS's conduct.

An executive order lets the Pentagon point AI at its own supply chain — and the headline outruns the text

Executive Order 14415, "Securing America's Defense Supply Chains and Ensuring Domestic Acquisition of Critical Materials," orders the Department of War to require prime contractors and subcontractors to trace every component back to raw-material origin, and to vet suppliers for foreign ownership, control or influence. Its artificial-intelligence content is one permissive clause in Section 3(d): the department shall map national-security vulnerabilities "using any tools and technologies to include artificial intelligence to assist in doing so." DefenseScoop headlined the order "Trump authorizes use of AI for defense supply chain mapping"; its own body text is more careful, noting the edict "noted that the Pentagon may use AI." Readers can check both: the order neither mandates AI nor funds it, and the deadlines it sets — 180 days for implementation guidance, 90 days for a testing-and-qualification strategy — attach to the sourcing requirements, not to the AI clause.

Stanford’s 2026 AI Index: the U.S.–China frontier gap narrows to 2.7%

Stanford HAI’s 2026 AI Index reported that the measured performance gap between the top U.S. and Chinese models had effectively closed — the two traded the lead repeatedly through 2025, and by March 2026 the leading U.S. model led by just 2.7% on the Index’s benchmark composite. The U.S. still produced more top-tier models, hosted 5,427 data centers (more than ten times any other country), and drew $285.9 billion in private AI investment (over 23 times China’s), while China led in publication volume, patents, and industrial-robot installations — a split scorecard, each half tied to a named metric rather than a single ‘who’s winning’ rank.

The controls loosen: BIS moves H200-class chips from denial to case-by-case review

On January 13, 2026, BIS published a final rule shifting the license-review policy for advanced chips bound for China and Macau from a presumption of denial to case-by-case review for parts below a set ceiling (Total Processing Performance under 21,000 and DRAM bandwidth under 6,500 GB/s) — a band that includes Nvidia’s H200 and AMD’s MI325X. Approval carries conditions: China-bound shipments capped at 50% of a firm’s U.S. volume, end-use and physical-security certifications, no model-weight transfer, and third-party lab review of every shipment. It codified the Trump-era turn from tiered denial toward conditioned access.

The Gulf corridor opens: U.S. approves advanced-chip exports to the UAE’s G42

On November 20, 2025 the White House authorized exports of advanced AI chips to the UAE’s G42, governed by a G42-built ‘Regulated Technology Environment’ compliance framework vetted by Commerce and BIS. The approval unlocked Stargate UAE — a 1-gigawatt cluster G42 is building for OpenAI with Oracle, Cisco, Nvidia, and SoftBank — within a larger planned 5-gigawatt U.S.–UAE campus, extending U.S.-controlled compute into the Gulf under a matched-buildout model.

An unprecedented cut: Nvidia and AMD to hand the U.S. 15% of their China AI-chip revenue

On August 11, 2025, Nvidia and AMD agreed to remit 15% of their revenue from AI-chip sales to China — Nvidia’s H20 and AMD’s MI308 — to the U.S. government in exchange for export licenses. President Trump confirmed the terms, saying he had wanted 20% before Huang negotiated him to 15%. Framing a national-security export control as a revenue share for the Treasury was without clear precedent, and drew objections from China-hawks in both parties who called it a tax on selling China the very chips the controls were meant to deny.

Reversal: the U.S. clears Nvidia to resume H20 sales to China

Nvidia said on July 14–15, 2025 that Washington would let it resume H20 shipments to China after CEO Jensen Huang met President Trump, with export licenses to follow. Nvidia had said it could have sold roughly $8 billion of H20s in the quarter before the April halt. The whiplash — restrict in April, permit in July — set up the revenue-sharing arrangement that followed. Commerce Secretary Lutnick’s stated rationale is recorded, and tagged as a prediction, as a separate statement.

Frontier labs enlist: the Pentagon awards up to $200M each to Anthropic, Google, OpenAI, and xAI

On July 14, 2025 the DoD’s Chief Digital and Artificial Intelligence Office awarded contracts worth up to $200 million each to Anthropic, Google, and xAI — joining OpenAI, which had received the first such award on June 17 — to develop ‘frontier AI’ and agentic workflows for national-security use. The awards followed the labs’ June rollouts of government-tailored models (Anthropic’s ‘Claude Gov,’ ‘OpenAI for Government’), formalizing the frontier labs as national-security contractors.

Trump’s Commerce Department rescinds the AI Diffusion Rule

On May 13, 2025 — two days before it would have taken effect — the Trump Commerce Department announced it was rescinding Biden’s AI Diffusion Framework, with Under Secretary Jeffery Kessler ordering enforcement staff to stand down while a replacement was drafted. In its place BIS issued guidance warning industry against using Huawei Ascend chips, cautioning that letting U.S. chips train Chinese models ‘may’ carry consequences, and advising firms to guard supply chains against diversion — a shift from a rules-based tiering system toward case-by-case discretion.

Even the compliance chip gets caught: U.S. requires a license for Nvidia’s H20

Nvidia disclosed on April 15, 2025 that the U.S. government would require an indefinite license to export its H20 — the chip Nvidia had designed specifically to stay under the 2023 thresholds — citing the risk it could be used in a Chinese supercomputer. Nvidia booked a $5.5 billion charge. The move showed how far the goalposts had shifted: a chip built expressly to be exportable was no longer exportable.

DeepSeek’s models are “broadly comparable to the best U.S.-developed AI models introduced in mid-2024.”

CSIS assessed that DeepSeek’s V3/R1 were broadly comparable to leading mid-2024 U.S. models, naming OpenAI’s o1 and Anthropic’s Claude 3.5 Sonnet as the reference points — a bounded, model-to-model comparison rather than a single-axis ranking. It implied a capability lag of months, not years, and became a touchstone for arguing the frontier gap had narrowed.

Context: Corroborated by later independent measurement: Stanford HAI’s 2026 AI Index found the top U.S. and Chinese models traded the lead through 2025 and sat within 2.7% by March 2026. The mid-2024-comparability assessment held up as the gap continued to close.

Europe’s answer: InvestAI mobilizes €200 billion and four ‘gigafactories’

At the Paris AI Action Summit on February 11, 2025, Commission President Ursula von der Leyen launched InvestAI, an initiative to mobilize €200 billion for AI investment across the EU, including a €20 billion fund for four AI ‘gigafactories’ — each envisioned with around 100,000 latest-generation chips, roughly four times the scale of the AI factories already being stood up on €10 billion of existing public support. Europe’s bid to avoid dependence on U.S. and Chinese compute.

Stargate: a pledged $500 billion for U.S. AI infrastructure

A day after the inauguration, OpenAI announced the Stargate Project — a new company intending to invest up to $500 billion over four years in U.S. AI data centers, with $100 billion pledged ‘immediately.’ SoftBank, OpenAI, Oracle, and MGX are the initial equity backers, with SoftBank chair Masayoshi Son as chairman and buildout beginning in Texas. It is the private-capital counterpart to the public compute race — the amounts are commitments, not deployed spending. (Tracked in depth on The Money and Infrastructure.)

DeepSeek-R1: a Chinese model at the frontier, and a $600 billion jolt to the arms-race story

On January 20, 2025 — inauguration day — the Chinese lab DeepSeek released its R1 reasoning model, days after its V3 base model. Built despite export controls, R1 performed comparably to leading U.S. reasoning models and, within a week, DeepSeek’s app had overtaken ChatGPT atop the U.S. App Store while Nvidia shed more than $600 billion of market value in a single session. Widely dubbed a ‘Sputnik moment,’ R1 became the central exhibit in the debate over whether controls were slowing China or spurring it to do more with less. (DeepSeek’s own claim that its final training run cost only ~$5.6M is recorded, and fact-checked, as a separate statement.)

The Biden endgame: an ‘AI Diffusion’ framework and a foundry crackdown

In its final days the Biden administration published two rules. The ‘Framework for Artificial Intelligence Diffusion’ (effective January 13, 2025) established a global three-tier system of country caps and license exceptions governing exports of advanced chips and, for the first time, closed-weight AI model weights. A companion rule (January 15) tightened foundry and packaging controls — requiring an approved-designer attestation or verified transistor count to ship advanced chips — and added 16 PRC and Singapore entities, including AI firm Sophgo, to the Entity List. Most compliance provisions were set to bite May 15, 2025.

DeepSeek says its V3 model’s final training run used 2,788,000 H800 GPU-hours — about $5.6 million.±

DeepSeek’s own V3 technical report stated the model’s final pretraining run consumed 2.788 million Nvidia H800 GPU-hours, which at an assumed $2/GPU-hour it valued at roughly $5.576 million — a figure widely repeated as evidence that frontier models could be trained cheaply despite export controls. The number describes only the last successful run, not the total cost of building the model.

Context: The $5.6M figure is DeepSeek’s own and, per CSIS, covers only the final successful pretraining run — excluding prior experiments, post-training, staff, and the underlying hardware. SemiAnalysis estimated DeepSeek/High-Flyer operates ~50,000 Hopper-class GPUs and spent ~$1.6 billion on GPU-server capex. So the marginal-run figure may be accurate while the ‘trained for $5.6M’ framing understates true cost by orders of magnitude.

The October 2023 update: closing the workaround chips and going worldwide by headquarters

On October 17, 2023, BIS overhauled the 2022 rule. It redefined controlled chips by Total Processing Performance and Performance Density (dropping the interconnect-speed parameter Nvidia had engineered its China-specific A800/H800 chips around), created a ‘Notified Advanced Computing’ license exception for less-capable datacenter chips, extended controls to 43 more countries, and — for the first time — imposed a worldwide license requirement keyed to an end user’s headquarters location. A new ‘red flag’ obliged foundries such as TSMC to scrutinize orders combining 50-billion-plus-transistor designs with high-bandwidth memory.

The United States has seen “no evidence” that China can produce advanced 7nm chips at scale.±

Commerce Secretary Gina Raimondo said in September 2023 that the U.S. had no evidence China could manufacture advanced 7nm chips in large volumes — a remark that landed just after TechInsights confirmed SMIC 7nm silicon in the Huawei Mate 60 Pro. The narrow claim (‘at scale’) proved more durable than the broad reading: SMIC did field 7nm parts, but independent analysts reported the process ran at limited yield without EUV, so high-volume leading-edge production remained constrained.

Context: SMIC demonstrably produced 7nm chips (TechInsights teardown, Sep 2023), so the existence of the capability was already contradicted. But Raimondo’s specific claim was about volume — producing at scale — and reporting through 2024–2025 indicated SMIC’s 7nm yields remained low without EUV, limiting high-volume output. True on capability existing, defensible on scale.

A 7nm chip in the Huawei Mate 60 Pro: proof China cleared a barrier the controls aimed to hold

A TechInsights teardown of Huawei’s Mate 60 Pro found its Kirin 9000S processor fabricated by SMIC on a 7nm (N+2) process — physical evidence that China had reached 7nm without extreme-ultraviolet (EUV) lithography, using multi-patterned deep-ultraviolet tools. TechInsights vice chair Dan Hutcheson called it a demonstration of ‘the technical progress China’s semiconductor industry has been able to make without EUV,’ and predicted ‘even greater restrictions than what exist today’ — a forecast the following years bore out. Independent analysts noted the achievement came at limited yield and did not resolve China’s dependence on imported lithography.

Pentagon launches ‘Replicator’ to counter China’s mass with attritable autonomy

Deputy Defense Secretary Kathleen Hicks unveiled the Replicator initiative on August 28, 2023, at the NDIA Emerging Technologies for Defense Conference, setting a goal to field thousands of attritable, autonomous systems across multiple domains within roughly 18–24 months to offset the numerical advantage of China’s military buildup. It marked the U.S. defense establishment’s move to translate AI and autonomy into fielded capability at scale.

The October 7 controls: the U.S. moves to choke off China’s access to AI compute

On October 7, 2022, BIS issued the interim final rule that became the foundation of the AI chip-control regime. It created new control classifications (ECCNs 3A090/4A090) for high-performance chips headed to China and two new Foreign Direct Product rules; it set fab-level thresholds (logic at 16/14nm FinFET or below, DRAM at 18nm half-pitch, NAND at 128 layers or more) with a presumption of denial for PRC-owned facilities; and, for the first time, it barred ‘U.S. persons’ from supporting advanced-chip production at Chinese fabs. The rule took effect in phases through October 21, 2022.

CHIPS and Science Act becomes law: $52B to reshore semiconductor manufacturing

President Biden signed the CHIPS and Science Act on August 9, 2022, authorizing roughly $52 billion in subsidies and tax credits for domestic semiconductor manufacturing and about $200 billion in research authorizations across AI, quantum, and robotics — an industrial-policy bet, framed explicitly against China, to keep leading-edge chip fabrication (and the compute AI runs on) inside the United States.

U.S. tightens the Huawei net: Entity List additions and a broadened Foreign Direct Product Rule

Effective August 17, 2020, the Commerce Department's Bureau of Industry and Security added 38 more non-U.S. Huawei affiliates to the Entity List, ended the Temporary General License, and amended the Foreign Direct Product Rule so that any foreign-made item produced with U.S. technology or software requires a license when a listed Huawei entity is a party. It was the template — controlling foreign production through U.S. tooling — that the later chip-wide controls would scale up.