China’s open-source AI models gain ground as U.S. frontier AI faces new rollout restrictions
Just a day after Western companies began shifting AI workloads to cheaper Chinese models to cut costs, a new challenge has emerged for America’s frontier AI developers. Fresh rollout restrictions on leading U.S. models are giving Chinese open-source rivals another opportunity to win enterprise customers.
The timing is difficult to ignore. Chinese open-weight models are improving on performance, price, and availability just as America’s top AI labs are facing new limits tied to national security concerns.
Anthropic was cleared by the White House on Friday to release its powerful Mythos 5 model to some companies and federal agencies after a two-week shutdown tied to an export control directive. Its Fable 5 model remains off the market. OpenAI said the same day that it would limit the rollout of its GPT 5.6 models following a government request.
The restrictions land at a sensitive moment for the U.S. AI race. Anthropic and OpenAI are locked in a high-stakes competition with each other and tech giants such as Google to build the most capable AI systems. For much of the past year, U.S. policymakers have argued that fewer domestic restrictions would help American companies maintain their edge over China.
Now the opposite risk is coming into view. If U.S. frontier models become harder to access, cheaper Chinese models may gain an opening.
Chinese models are closing the performance gap
Chinese AI labs are no longer trailing far behind in every category. Zhipu’s GLM 5.2, released earlier this month, is drawing attention from researchers and investors for its performance on cyber benchmarks. Some researchers say it can match top U.S. labs in selected capabilities, including areas where Anthropic has been seen as a leader.
“Many smart people/AI insiders are saying GLM-5.2 is the first Chinese AI model to match and often beat the American big lab public AI models with no compromises,” venture capitalist Marc Andreessen wrote in a post on X over the weekend. “Incredible timing given current events.”
Sam Bresnick, a research fellow at Georgetown’s Center for Security and Emerging Technology, called the recent developments “a pretty good wake-up call,” CNBC reported.
Jefferies strategist Christopher Wood cited industry sources in a client report, saying GLM 5.2 “is almost equal to Anthropic as a competitor for the corporate market and is just one quarter of the cost in terms of cost per token.”
David Sacks, the former White House crypto and AI czar and a frequent critic of Anthropic’s AI safety stance, posted a screenshot of a Wall Street Journal headline saying China had matched Anthropic in cybersecurity.
“A year ago, President Trump declared that America was in a global AI race and that the way to win it was to be pro-innovation, pro-infrastructure, pro-energy, and pro-export,” Sacks wrote. “President Trump was exactly right; we deviate from that strategy at our peril.”
Representatives for Anthropic, OpenAI, and the White House did not respond to requests for comment.
Cost pressure is pushing companies toward Chinese AI
The shift is not limited to benchmarks. Corporate buyers are increasingly prioritizing cost, latency, control, and return on investment over raw model prestige.
That change favors Chinese open-weight models.
Earlier this month, Flo Crivello, CEO of AI startup Lindy, moved his company off Anthropic’s Claude models and shifted all traffic to DeepSeek, the Chinese AI company known for cheaper open-weight models.
“We did it, and you could see that cost curve go down, like, crash to the ground,” Crivello told CNBC in a story published last week.
For companies burning through tokens, that math can be hard to ignore. Open-weight models let teams download software, run it on their own servers, and avoid relying fully on a third-party cloud provider. That gives businesses more control over cost and deployment.
“With the open-weight models, it’s kind of the Wild West,” said Travis Lanham, co-founder of AI security startup Armadin, which is testing GLM 5.2 and Kimi K2.7 from Moonshoot AI.
Lanham said the models are improving in cybersecurity use cases such as analyzing reconnaissance data and creating customer exploit code.
The security question is getting harder
That is where the story gets more complicated.
The same qualities that make open-weight models attractive to startups and enterprises also make them harder to control. Once a model is released, companies can run it anywhere. Bad actors can do the same.
Cybersecurity experts are paying close attention. Some open-weight models can already automate parts of a cyberattack. Hed Kovetz, CEO of Silverfort, said he worries these systems may soon be able to run entire operations from start to finish.
“If the U.S. government does not let the industry take advantage of this opportunity to get ready, then when the Chinese models reach a similar level, no one will be prepared,” he said.
The concern cuts both ways. U.S. officials have spent years trying to limit China’s access to advanced AI hardware by imposing export controls on chips from Nvidia and AMD. Washington has also restricted U.S. companies from using Huawei equipment due to national security concerns.
Last year, the U.S. cleared Nvidia’s H200 chip for export to China. Nvidia later said it had not generated revenue from those chips and did not know if China would allow imports of its products.
Now policymakers face a tougher question. If Chinese AI models become widely used within U.S. companies, especially in security-sensitive workflows, should access to those models be restricted as well?
U.S. companies are already testing the alternatives
Chinese models are no longer a niche experiment. Major companies have started talking openly about using them.
Shopify and Airbnb have highlighted Alibaba’s Qwen 3 as a platform for scaling AI features. Coinbase CEO Brian Armstrong wrote on X last week that the company is using open-weight models such as GLM 5.2 and Kimi 2.7, helping Coinbase cut nearly half its AI spending even as token use increased.
That tells a larger story about where the AI market may be heading. The first phase of enterprise AI was about access to the most powerful models. The next phase may be about matching the right model to the right task at the lowest sustainable cost.
Chinese labs are taking advantage of that shift.
Elon Musk, who founded Tesla and SpaceX, wrote on X that GLM 5.2 would likely reach Fable-level capabilities by the first quarter, in response to a user asking when that milestone might arrive.
Zhipu founder Jie Tang replied, “won’t take that long.”
That short exchange captured the mood across the AI industry. The gap between U.S. frontier labs and Chinese challengers is narrowing in public view. U.S. restrictions may slow the rollout of American models in the name of national security, yet market demand is moving in the opposite direction.
Companies want cheaper models. Developers want models they can run themselves. Security teams want to test what adversaries may soon use.
That leaves the U.S. AI sector in a difficult spot. Slowing access to frontier models may reduce some risks in the near term. It may also push more users toward Chinese open-weight alternatives that are cheaper, easier to deploy, and improving faster than many expected.

