A Ban on Chinese Open Models Would Fail, and Kimi K3 Just Proved It
I’m a hawk on this. I think the export controls on advanced chips are correct, I think Beijing’s technology apparatus serves an authoritarian state that will use every capability it acquires against people who can’t vote it out, and I’ve never found the argument that engagement moderates that state persuasive on any evidence I’ve seen. If you’re looking for someone to tell you the controls were a mistake, keep looking.
Which is why I want to be precise about the thing I think is wrong, because it isn’t the controls. It’s the proposal to extend them to open model weights.
That proposal is unenforceable. Not marginally unenforceable. Not unenforceable at the edges. Unenforceable in the way that a law against remembering something is unenforceable.
We got the demonstration this week. Moonshot AI released the weights for Kimi K3 under its own license, on the same day Beijing warned it would take all necessary measures if Washington sanctioned Chinese AI companies, and on the same day two long essays argued in opposite directions about whether America should ban Chinese models. Four position papers and one shipped artifact. The artifact settles it.
Ask who the ban actually stops
Here’s the test. A ban on Chinese open-weight models is a restriction on somebody. Who?
Not Moonshot, which is outside the jurisdiction and has already published. Not a Chinese lab downstream of it. Not a foreign adversary intelligence service, which faces no meaningful barrier to downloading a file. Not any sophisticated actor anywhere, because a set of weights is a few hundred gigabytes of numbers that copies perfectly, propagates through mirrors and torrents within hours, and can’t be recalled by anyone including the people who released it.
The people it stops are a machine shop in Michigan running a quantized model on a workstation because it can’t afford API costs, a hospital system in Kentucky that wants inference inside its own firewall for patient data, a two-person startup in Tel Aviv testing whether its product works at all before it commits to a vendor. Those are the actors within reach of American law. They’re the only ones.
A control regime that binds exclusively on the compliant is not a control regime. It’s a tax on being law-abiding.
The chip controls work for a reason that doesn’t transfer
The reason I support the chip restrictions is specific and it’s worth saying out loud, because the case for extending them collapses the moment you state it.
A lithography scanner weighs many tons, requires installation teams, needs continuous service contracts, consumes a supply chain of resists and pellicles and masks, and cannot be smuggled in a suitcase or reconstructed from a description. It’s physical, it’s traceable, and its supply is concentrated in a handful of firms in allied countries. That’s what makes it controllable. The control works because of the physics, not because of the statute.
Weights have none of those properties. They’re information. Every property that makes a scanner controllable is absent, and every property that makes information uncontrollable is present. Applying the same policy instrument to both isn’t consistency. It’s a category error wearing consistency’s clothes.
And here’s the part that should give the ban’s advocates pause: this week a Chinese state-backed firm reportedly began manufacturing DUV lithography machines. That’s the hardest case for control, the one with the physics on our side, and even there the substitution clock is running. Controls buy time. They don’t buy permanence, and they buy the least time in the domain where copying is free.
Even Dario Amodei isn’t asking for this
The strongest authority against the ban is the person its advocates most often invoke. Dario Amodei spent the week clarifying that Anthropic has never backed an open-weights model ban, while in the same set of remarks laying out why top-end chips shouldn’t be sold to China and calling for global model testing.
Read that carefully, because it’s the whole argument in one person’s position. The most prominent voice for taking AI risk seriously, running a lab that doesn’t publish its own weights, distinguishes between restricting compute and restricting information, and comes down for the first and against the second. He’s not soft on China. He’s making a distinction about which instruments actually bite.
When a company with every commercial incentive to see open models restricted declines to ask for it, the policy has a problem that isn’t ideological.
What I still won’t concede
I’m not signing on to the broader case, and I want to be clear about where I get off.
I don’t accept that open weights are a neutral substrate where innovation compounds for everyone equally. That framing launders a real asymmetry: a closed authoritarian system that publishes weights gets the diffusion benefits of openness while giving up none of its own opacity, and calling the result neutral flatters it. I don’t accept that adopting Chinese open models is costless — dependency on an upstream you can’t audit and can’t influence is a real strategic exposure, whoever’s running it. I don’t accept that the choice is between banning models and welcoming them. Procurement rules for federal systems, security auditing requirements, provenance standards, restrictions on critical infrastructure: those are all available, they’re all enforceable, and none of them require pretending you can un-publish a file.
Build the rules that bind on the people you can actually reach. Skip the ones that only announce a preference.
The weights are already out. Legislate accordingly.