← Front Page
AI Daily
A fire-engine-red padlock clamped over a plain doorway, while a stream of tiny figures walks past it through an open side door marked with a jade-green flag.
Geopolitics • Sunday, 13 September 2026

Washington Wants to Ban China's AI. The Bill Would Land at Home.

By AI Daily Editorial • Sunday, 13 September 2026

The National Security Agency, the Cybersecurity and Infrastructure Security Agency, and the FBI rarely put their names on the same page. On September 8 they did, jointly accusing six Chinese firms, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, of "industrial-scale distillation" of American models: quietly training their own systems on the outputs of Claude, GPT, Gemini, and Grok. Beijing rejected the charge within a day. Its commerce ministry offered the sharper reply, arguing that distillation is a neutral technique every lab uses, American labs included, and that Washington was prosecuting a pricing problem in the language of espionage.

That framing stings because it is hard to fully dismiss. Six days before the advisory, the Justice Department backed OpenAI in its fight with The New York Times, arguing that training on copyrighted material is generally fair use. So scraping a newspaper to build a model is fair use, but training on a model's outputs is theft. A standard that flexible tends to hand your opponent the argument, and Beijing built its rebuttal on exactly that gap.

Set the fairness question aside and try the practical one. Suppose the charges are right and the policy works: Chinese models are blocked, delisted, and off-limits to any federal contractor, which is roughly what a bill from Senators Bill Cassidy and Jacky Rosen would do. Then what? Removing the cheapest supplier of the decade's most important technology does not erase its cost. It moves the cost around. And developers have been voting with their traffic. Chinese-built models drew 46.4 percent of the tokens routed through the aggregator OpenRouter this summer, against 35.7 percent for American ones, up from about 11 percent a year earlier. That was not ideology; the models were cheaper and, for a widening set of jobs, good enough.

The price gap is stark. DeepSeek's V4 Flash billed around 14 cents per million input tokens where OpenAI's flagship charged five dollars, and this month the discounting turned into a rout. Zhipu floated an anonymous "Ox Alpha" model on OpenRouter, revealed it as its own GLM-5.3, then ran it at half price. DeepSeek answered with a V4.1 Flash priced under a cent per million tokens, a level the analytics firm Artificial Analysis has taken to calling the "death zone" for anyone trying to compete in the middle. One agent company, Lindy, said moving off Anthropic to a Chinese model cut its inference costs by 90 percent with no drop in quality.

The advisory's own remedy is stranger than the accusation. Alongside detection and intelligence sharing, it urges American providers to subtly degrade the answers they serve to suspected distillers, and to vary the degradation so it is hard to measure. In plain terms, three federal agencies are recommending that US companies quietly hand worse results to paying customers without telling them, and the document does not say what happens on a false positive. Small wonder that 179 startups, then Microsoft, Nvidia, Meta and two dozen others, wrote to the White House warning against blanket restrictions. Notably, Anthropic and OpenAI did not sign.

There is a defensible version of all this, and it is narrow: guard the model weights, guard the chip supply chain, prosecute genuine intrusion, and enforce the licensing terms the labs already write. None of that requires telling a startup in Austin which model it may rent on a cloud GPU. The quieter risk is the one diplomats should watch. American software has long enjoyed default status, used the world over without anyone asking permission. Condition that access on geography and compliance and American AI stops being infrastructure and starts being a license. Alibaba's open Qwen models logged three billion downloads in six months, more than Google and Meta combined, and for a developer in Lagos or Jakarta the weights are free and run on a laptop. Licenses, in the end, are what create markets for alternatives. Xi Jinping arrives at the White House on September 24, with AI safety talks already on the agenda.

Sources