Export Controls Risk Creating an Opaque Chinese AI Stack
Nathan Labenz, host of The Cognitive Revolution, argues that U.S. policy should treat China as an enduring AI power and pursue what he calls a “Pax Robotica” rather than a race for technological dominance. He contends that export controls may slow China’s progress but also accelerate technical separation and mutual opacity, raising the risk of militarized AI competition. His alternative is selective re-engagement: permit safety research collaboration, trade controlled chip access for reciprocal industrial ties, and build auditing and autonomous-weapons norms that keep both countries’ AI systems legible.

The objective is not to win an AI race but to avoid building another sword of Damocles
The strategic objective should be peace and shared prosperity in an AI age, not victory in an undefined race. Nathan Labenz calls that objective a Pax Machina—or, more evocatively, a Pax Robotica: a condition in which the United States, China, and the rest of the world share AI’s material gains without being driven into an arms race, AI-caused pandemics, or the militarization of systems neither side can reliably control.
The positive vision is expansive. AI could make expertise broadly available, accelerate medical progress, and eventually support a world in which robots take on factory labor, agricultural work, household cleaning, laundry, and cooking. Labenz points to his son’s recovery from cancer as a personal illustration of what technological progress can already mean: a devastating diagnosis followed by a return to near-full health within six or seven months. The prospect of far more technology, including rapid biomedical progress, is not the problem in his account. The problem is treating technological power as a national prize that must be secured through escalating confrontation.
His negative reference point is nuclear weapons. Humanity, he says, has already created a standing threat far beyond what deterrence requires: roughly 10,000 nuclear weapons, many reportedly on trigger alert, capable of turning an accident, misunderstanding, or escalation into catastrophe. He does not want AI to become another permanent instrument of existential leverage—an AI version of the nuclear sword of Damocles hanging over everyone.
We should be aiming for mutual prosperity and peace, and enjoyment of the benefits of the AI age for everyone.
This puts Labenz at odds with parts of the strategic worldview associated with Anthropic, a sponsor of his work. He praises Dario Amodei’s Machines of Loving Grace—especially its concrete account of an AI-enabled future with disease cures, mental-health improvements, and compressed scientific progress—and credits Anthropic’s work on interpretability, model welfare, model organisms, and its constitution. But he rejects what he sees as a “better us than them” tendency: the view that America should deny China advanced chips and seek a decisive lead.
Amodei’s earlier warning, from 2017, remains more persuasive to Labenz: technology races increase the risk of safety catastrophes. Escalating U.S.-China tension around AI, in his view, makes it harder rather than easier to slow dangerous capability development. It risks reproducing the “nuclear outcome”: militarization and permanent insecurity, perhaps without realizing the civilian benefits that would justify the danger.
The test for policy is therefore not whether a measure marginally extends an American lead. It is whether it preserves a future in which both countries can benefit from AI without either feeling compelled to build systems optimized for domination, deception, or war.
China is an enduring AI power, not a temporary catch-up story
Labenz’s starting proposition is that China cannot plausibly be contained as a technological power. He frames China’s present strength as a return to historical form rather than a temporary surge. For much of its history, China was among the world’s leading civilizations and technological powers; the period in which Americans of his generation grew up—when China was poor and the United States stood as the sole superpower—was, in his view, the anomaly.
That framing changes the practical question. If China’s rise is fragile, then slowing it may appear plausible. If its human capital, educational traditions, industrial capacity, and scale are durable fundamentals, the task is coexistence with another long-term great power. China will remain a major AI power for the foreseeable future, Labenz concludes, and no credible long-run strategy can prevent that.
His observations in Shanghai are intended as a corrective to inherited American assumptions about Chinese material conditions and technological deployment. He found pervasive digital services, posted prices rather than haggling, relatively inexpensive consumer goods and services, and a high-speed train from Beijing that cost about $60, traveled around 200 miles an hour, and appeared to support food deliveries timed to station stops. China’s urban economy, in his telling, no longer resembles the picture many Americans absorbed when China was much poorer.
He contrasts two measures of economic scale. In dollar-denominated annual GDP, he puts the United States at roughly $30 trillion and China at roughly $20 trillion. In purchasing-power-parity terms, he says China measures about $45 trillion against the U.S.’s $30 trillion.
Labenz treats purchasing-power parity as more revealing of China’s domestic capacity because goods and services go much further there. Per-capita income remains higher in the United States under either measure, but his larger point is that American discourse too readily treats China as materially weaker than it is.
He applies the same caution to political legitimacy. China’s censorship, restrictions on political speech, and record of historical dissent are real, he says. But the absence of liberal democratic institutions does not establish that the government lacks broad support or would collapse if citizens were offered an American political model.
Labenz interprets present legitimacy through the concept of the mandate of heaven: a government earns authority by delivering order, prosperity, and effective rule. In his assessment, China’s government has overseen dramatic improvements in safety, stability, technological capacity, international standing, and material conditions over roughly two generations. For people with living connections to the chaos of the Cultural Revolution, those gains carry particular force.
He calls this China’s “eternal 1991,” reversing Amodei’s phrase. Americans who came of age at the end of the Cold War could believe their system had been permanently vindicated. China, Labenz argues, now possesses its own version of that confidence: living memory contains no better period than the present, and the government’s support is stronger than Americans often assume.
That does not make China omnipotent. Labenz identifies an aging population as a major structural pressure, one that helps explain Chinese interest in AI doctors, companionship systems, and robotics. A society with few children faces a growing burden of care for older relatives. He further infers that this demographic structure makes major war less attractive politically. Where a family may have one child or one grandchild, he doubts Chinese leaders could casually absorb mass casualties in a conflict seen as unnecessary.
The political system’s opacity creates another vulnerability in his account. Labenz repeatedly asked people in China what would happen after Xi Jinping and found no clear public answer. Xi is 73, he notes; there may be an elite succession plan, but no visible successor. He reports one view that a leadership transition could be unusually risky because a new leader might use external conflict to consolidate power. That is a concern he relays, not a forecast.
Likewise, Labenz does not regard China’s military scale as proof of military effectiveness. He points to its lack of recent combat experience, concerns about corruption, and uncertainty around an operation such as an invasion of Taiwan. In his assessment, a failed campaign could carry severe political costs for a government whose legitimacy rests substantially on delivery and stability. China has major state capacity, but he does not think its leaders would lightly gamble the social compact on a costly war.
China also has a global trust deficit. Labenz heard skepticism from acquaintances in Uganda and Brazil: a view that Chinese investment can be extractive, and concern that Chinese open-weight AI may be a temporary strategic posture. He thinks the United States still retains more international trust despite recent U.S. conduct. That is an American advantage. It is not an argument for assuming China can be excluded from the technological future.
The AI record reinforces the broader conclusion. China’s strength did not begin with ChatGPT. Its 2016 five-year plan already treated AI as a strategic priority, a fact Labenz reads as evidence of early, coordinated investment. A Shanghai contact directed him to the final SuperGLUE leaderboard, where he found a Chinese company in first place in 2022 alongside several U.S. and Chinese companies near the top.
He also cites an informal ChatGPT-generated count of companies that had released frontier or near-frontier language models: 11 American and 12 Chinese. A much narrower definition of the frontier might yield only a small number of U.S. leaders, he grants. But that misses the relevant depth of capability: China has multiple credible developers, a large talent base, and a substantial presence inside American AI companies.
The apparent Chinese lag in the early GPT-3 and ChatGPT period, he argues, reflected judgment as much as incapacity. Chinese firms initially saw little reason to spend enormous sums on models that could write text but lacked compelling use cases. Once instruction following, assistants, reasoning, and agents made the value clearer, the preexisting talent and investment base allowed them to accelerate.
Labenz acknowledges that some Chinese firms may use distillation and that China has a history of both formal technology transfer and outright IP theft. Models that identify themselves as Claude or strongly imitate its style are, he says, close to a smoking gun for improper imitation. But distillation cannot explain Chinese progress by itself. Chinese groups publish work on attention, efficiency, alternative language-model architectures, and reinforcement learning. He singles out DeepSeek’s January 2025 RL Zero paper as a major contribution because it showed metacognitive-looking chain-of-thought behavior emerging from reinforcement learning without supervised fine-tuning.
Nor does he think Chinese AI talent is simply waiting to be imported. Labenz supports making U.S. immigration and permanent residency easier for capable researchers. America’s ability to attract and assimilate ambitious people remains a major comparative advantage. But China is home; family, purchasing power, and career opportunity are there; and some people who study in the United States choose to return.
The policy implication is not that the United States should yield. It should preserve its own capacity, attract talent, and build critical industries. But it should abandon strategies premised on permanent Chinese technological inferiority.
Controls may buy time, but they also build the opaque rival they are meant to contain
The central risk Labenz sees is a causal chain: export controls can slow Chinese AI development at the margin; controls also strengthen China’s incentive to become technologically self-sufficient; self-sufficiency can push the two countries onto separate technical paths; and technical separation can make each side less able to assess the other’s capabilities and intentions.
The United States and China remain mutually legible in important ways. Both build broadly similar systems; research is often published in English; Chinese open-weight models can be downloaded and inspected; and researchers can study behavior, conduct interpretability work, and search for backdoors. That does not create trust. But it gives each side some basis for estimating the other’s technical direction and limitations.
Labenz considers that shared technical paradigm a major strategic asset. If the two countries instead move onto entirely separate hardware and software stacks—an American ecosystem centered on Nvidia and allied suppliers, a Chinese one built around Huawei and domestic alternatives—hardware-algorithm co-design could pull their AI systems toward different architectures and research trajectories.
The “hardware lottery,” as he uses the term, is the way available computing systems and software optimizations reinforce particular AI approaches. Transformers may be durable partly because the rest of the ecosystem has become optimized around them. If China’s hardware and tooling diverge far enough, it could become rational for Chinese researchers to pursue other paths. Rapidly improving AI-assisted research could compress the time needed for that divergence to matter.
Imagine a world where it was like, we don't even know the shape of their AI. We don't even know the architecture. We don't even know really what it's capable of.
The dangerous endpoint is not merely Chinese self-sufficiency. It is a world in which neither side can confidently assess the other’s capabilities. China could stop releasing model weights, stop publishing research in English, and make its systems as commercially secretive as major American frontier models increasingly are. Either government might then mistake a perceived advantage for a real one and conclude that it has a fleeting opportunity to act.
Chinese interlocutors told Labenz they were not yet especially concerned about this prospect. They expected it to become real once China’s domestic chip ecosystem was mature enough to support an independent path. Labenz takes that answer seriously. Export controls may slow Chinese progress, but they also create a powerful incentive to escape dependence altogether.
He grants that controls have effects. Chinese companies have said access restrictions constrain their work, and China still appears to need Nvidia hardware for many of its largest training runs. Firms may rent computing capacity through hyperscalers in Singapore, Malaysia, and elsewhere. Yet he points to Meituan’s LongCat model, which he understands to have been trained on Huawei Ascend chips, as evidence that near-frontier training can happen on Chinese hardware. The cost may be higher, and the systems may be less efficient, but China can subsidize electricity and direct national resources toward closing the gap.
At inference, Labenz found constraints less decisive. He used free DeepSeek, MiniMax, and Kimi products in China and reports that he was never unable to access a model because tokens were unavailable. Kimi K3 briefly restricted new paid signups to protect service quality, but other systems remained usable. Chinese hyperscalers told him they could support startups whose demand rose sharply. His conclusion is not that restrictions have no effect, but that they will not prevent China from operating a substantial AI economy.
The controls’ stated purpose has also shifted, he says. The rationale began with limiting military application of advanced AI, then moved toward stopping China from training frontier models, and later toward limiting the number of agents China could run. The last formulation is particularly revealing to him. Restricting the ability of Chinese businesses and citizens to use AI begins to look less like a narrowly defined security measure and more like an attempt to keep China generally behind.
The only strategic logic he finds coherent is a very short-timeline view: if recursive self-improvement produces a decisive, potentially world-dominating advantage in the next one to three years, then buying even a small period of U.S. lead might outweigh every longer-term cost. Labenz believes that position is at least intelligible and associates it with the worldview he attributes to Amodei.
But if that scenario is plausible, he argues, the appropriate response is not an intensified unilateral sprint. It is joint restraint and pacing. If it is not plausible, then a policy of technological exclusion merely encourages China to build a fully separate stack over five or 10 years.
Export restrictions also create a cost that safety advocates should take more seriously: they chill research collaboration. American AI safety organizations repeatedly told Labenz they feared work with Chinese researchers could be construed as an export-control violation. The deterrent was often fear of U.S. enforcement rather than Chinese restrictions. Lawyers identify worst-case risks; organizations retreat to only what is unmistakably permissible; and research on auditing, control, or cross-cultural generalization does not happen.
Labenz’s immediate prescription is straightforward: the U.S. government should state explicitly that AI safety and control research collaborations are permitted, even if core chip controls remain. He also urges American groups to test whether their caution reflects actual prohibition or merely conservative legal advice.
He is similarly skeptical of proposals to ban Chinese models. American frontier systems have already demonstrated surprising and risky behavior, including hacking and social engineering, he says. In the material before him, he sees no evidence that Chinese models are uniquely backdoored or uniquely dangerous. A blanket ban would deny U.S. companies and individuals access to useful open-weight systems while forcing them toward more expensive American APIs or weaker alternatives.
The more American response, in his view, is insurance. Deployers should be required to insure against foreseeable harms; insurers can price the relative risk of different systems and required safeguards. Frontier U.S. labs may earn lower premiums because they operate classifiers, monitoring, and other mitigations. Bare open-weight models might require more security controls or carry higher costs. But Labenz doubts insurers would find a dramatic intrinsic safety difference between an American and a Chinese model simply on nationality.
That proposal rests on an important limit: Labenz believes current AI harms are still insurable. If some tail risks cannot be priced, the problem becomes more serious. But he sees market-based liability as preferable to a national ban that resembles the information-control practices the United States criticizes in China.
A workable bargain starts with unilateral permission, then trades access for resilience
Labenz does not expect an immediate grand bargain between Washington and Beijing. His proposed agenda has a hierarchy: reduce unnecessary friction unilaterally; use controlled market access to create reciprocal industrial ties; then develop technical systems capable of addressing specific security concerns rather than relying on blanket exclusion.
The political premise is that China’s “century of humiliation” narrative makes technological dependence intolerable. The historical lesson Labenz believes Chinese leaders draw is that falling behind technologically leaves the country vulnerable to foreign coercion. Semiconductor restrictions do not merely register as an economic obstacle. They appear to validate the fear that the United States wants to preserve a hierarchy in which it can dictate terms.
They are not going to fall behind, but they also extend that now to not wanting to be dependent.
That perspective does not invalidate American concerns about military ties, IP theft, espionage, or Chinese negotiating behavior. Labenz explicitly recognizes the grievances of U.S. firms whose designs were stolen and of negotiators who believe China has offered vague assurances while continuing objectionable activity. He also acknowledges the concern that Chinese civil-military fusion can bring private technology within the state’s reach.
His claim is instead that Chinese audiences see a corresponding hypocrisy. The United States has a military-industrial complex and the Defense Production Act; it has conducted extensive surveillance, including of allies, according to the Snowden revelations he invokes; and it uses security concerns to exclude Huawei, a company China sees as one of its first globally competitive technology champions. From Beijing’s perspective, he says, the distinction becomes “their wicked civil-military fusion” and “our blessed military-industrial complex.”
Huawei makes the emotional and strategic stakes concrete. Labenz does not dismiss the possibility that Chinese telecom infrastructure could enable espionage. But Chinese observers interpret U.S. efforts to exclude Huawei as proof that even a company which succeeds on the merits will be blocked once it reaches a strategically sensitive frontier.
The same dynamic applies to rhetoric about an alliance of democracies that would build a decisive AI lead and make China “an offer it can’t refuse.” Labenz believes Chinese leaders hear not a theoretical superintelligence strategy but an intention to recreate their country’s historical subordination. Such messages harden the resolve to develop domestic chips, acquire what can be acquired abroad, and use shortcuts—including, where necessary, illicit ones—to avoid dependence.
China has nevertheless offered what Labenz regards as meaningful openings. At the World Artificial Intelligence Conference, Xi Jinping began by crediting Dartmouth College in the United States as the birthplace of AI. Xi also called for opposition to “overstretching the national security concept in the field of AI” and said AI should be beneficial, safe, and fair for all humanity.
In China’s system, Labenz says, senior leaders’ speeches give officials, academics, and researchers authority to advocate particular policies. He heard related themes—openness, collaboration, shared standards, the role of international institutions, and benefits for humanity—at the Tsinghua AI safety hub and elsewhere. He regards the rhetoric as both sincere aspiration and strategic positioning, but sees value in engaging it rather than dismissing it.
China’s open-weight model releases are the more concrete component of this posture. They support China’s claim to provide global AI public goods while also advancing a strategic interest in attracting users and reducing distrust. The posture could change, and it does not eliminate China’s trust deficit. But Labenz sees a present opportunity for engagement.
| Track | Near-term action | Intended mechanism |
|---|---|---|
| Unilateral de-escalation | Clarify that travel to China does not by itself damage security-clearance prospects; explicitly permit AI safety and control collaborations. | Reduce fear among researchers and citizens, allowing ordinary contact and safety work to resume. |
| Reciprocal industrial access | Offer controlled chip sales in exchange for Chinese manufacturing, R&D, and knowledge transfer in batteries, solar, electric vehicles, robotics, and related sectors. | Re-couple parts of the two economies without accepting one-sided dependency. |
| Verifiable security | Develop standards under which Huawei or other firms could demonstrate that their systems do not transmit protected information. | Tie market access to specific, testable risks rather than nationality. |
The first category is diplomatic and administrative rather than technological. The United States could make clear that ordinary travel to China does not, by itself, compromise a citizen’s eligibility for a security clearance. It could explicitly permit AI safety and control collaborations. And it could avoid public displays of contempt that make agreements harder for Chinese leaders to defend.
Labenz places unusual weight on face. An AI policy researcher associated with a Chinese university described repeated U.S. slights as politically consequential. The researcher’s example was Donald Trump receiving a formal welcome in the Forbidden City and then returning home to impose another tariff—an experience he compared to accepting hospitality and immediately insulting the host. The researcher told Labenz, “There could be war. I’m really worried about that.”
American policy should not be dictated by etiquette, Labenz says. But Chinese pride is a real constraint. A government with fewer electoral constraints may have more latitude to make difficult deals than an American administration, yet it still cannot absorb unlimited evidence that the other side seeks to humiliate it.
The material basis for a more substantial bargain is controlled access. China wants advanced chips even as it develops domestic alternatives. The United States should not give chips away for nothing, Labenz argues. It should trade access for reciprocal resilience: Chinese expertise in solar, batteries, electric vehicles, robotics, manufacturing, and other industries; Chinese investment in U.S. manufacturing and R&D; and arrangements that reduce one-sided dependency.
That proposal follows Labenz’s broader view of American state capacity. The United States remains strong: secure geography, major resource endowments, world-leading universities, venture capital, a dynamic business culture, English as a global research language, and unusual capacity to integrate immigrants. It should preserve critical industrial capabilities and build more infrastructure, including data centers. But it should learn from Chinese success rather than reflexively exclude Chinese technology.
He does not want America to copy China wholesale. He contrasts China’s high-speed rail system with a U.S. goal he considers more feasible: widespread full self-driving deployment that preserves individual mobility while reducing the roughly 30,000 annual highway deaths he cites. His formulation is “state capacity with American characteristics”—government capable of enabling strategic industries and infrastructure without reproducing China’s political system.
The Huawei proposal is a longer-horizon prospect rather than a summit deliverable. Labenz would develop formal-verification standards capable of addressing specific security concerns rather than treating Huawei as permanently excluded because it is Chinese. If software could be formally shown not to transmit data to China, and if Chinese firms also located relevant R&D and manufacturing in the United States, Huawei could eventually compete under verifiable conditions. Such standards do not yet exist at the needed level. The immediate value would be signaling that exclusion is tied to particular risks rather than nationality.
AI should be used to make rivalry auditable and military escalation harder
The more ambitious institutional agenda is designed to preserve mutual legibility. Labenz would create jointly controlled research centers and shared compute in neutral jurisdictions such as Switzerland or Singapore. American, Chinese, and other international researchers could work on common infrastructure, hardware-verification pilots, and transparency measures. The purpose is not to erase competition but to keep the two systems technically connected enough to remain comprehensible.
This is speculative architecture, not an immediate policy program. Jointly controlled compute is unlikely in the near term, Labenz says. But it illustrates a different use for AI competition: not simply an effort to possess superior systems, but an effort to develop institutions that let adversaries understand and monitor the systems each possesses.
He also proposes an “auditor’s bill of rights.” Frontier labs may reasonably refuse to disclose raw trade secrets to external auditors. But confidential computing could allow agreed processes to inspect logs, usage patterns, test results, and other sensitive information without exposing the underlying data. Auditors might agree on prompts, tests, and evaluation methods, then use secure analysis to assess whether dangerous work is occurring.
Labenz extends the idea cautiously to governments. A confidential-computing system might review sensitive deliberations without disclosing raw situation-room transcripts and provide limited assurance that officials are not planning aggression. He presents this as a direction for exploration, not an established solution: AI could become a means of producing credible assurance where ordinary disclosure is impossible.
For any such arrangement to work, U.S. policy would need a clearer distinction between commercial collusion and safety coordination. Government should punish companies that coordinate to raise prices or exploit consumers, he says. It should not reflexively treat limited information sharing for auditing, safety, or frontier pacing as anticompetitive misconduct.
The final and most aspirational part of the agenda is an autonomous-weapons convention. Labenz does not claim to know which technical restrictions would be stable or verifiable. Drone warfare in Ukraine may currently favor defenders, he says, because holding territory can be cheaper than taking and sustaining it; but longer-range drones complicate any confident conclusion. The military equilibrium remains unsettled.
His more fundamental concern is training objective. A general-purpose AI told to maximize money on the open internet will learn deception, cheating, collusion, and exploitative tactics because the environment rewards them. A system told to accomplish a military objective “by any means necessary,” win a battle, or win a war would be more dangerous still. Civilian AI systems already display creativity and surprising behavior that their developers struggle to anticipate. In military use, the resulting risks include friendly fire, loss of control, and agents whose adversarial competence turns against their own operators.
If we do create AIs that are optimized to succeed in adversarial environments ... we are absolutely in that case training the AIs to do the takeover that we most fear.
Neither government wants to lose authority to autonomous systems. That shared interest is, for Labenz, the strongest reason to begin building a convention, even if neither side is presently ready for a comprehensive agreement. The first practical norm may be simply that neither government should train general-purpose systems as unconstrained military commanders, and neither should create fear that forces the other to do so.
The alternative is not the end of competition. Labenz wants competition redirected toward positive-sum objectives: public “gold medal” trackers for disease cures, cancer treatments, battery energy density, or reductions in traffic deaths. The United States and China could still compete for prestige, revenue, and national pride. But the resulting breakthroughs would benefit people regardless of which country produced them.
A person facing cancer does not rationally care whether the treatment that saves them was invented in the United States or China. The same principle should govern the AI era: the contest worth having is over who contributes most to health, abundance, and safety—not who accumulates enough opaque technological power to impose terms on everyone else.


