U.S. AI Restrictions Face an Enforcement Problem as Open Weights Spread
Cheap, capable Chinese AI models have turned model access into a conflict over national security, intellectual property and the economics of U.S. frontier labs, John Coogan argues. He and Jordi Hays say Washington may be able to target companies over alleged IP theft or infrastructure access, but open weights, fine-tunes and synthetic training data make it difficult to define—or enforce—a ban on a model’s Chinese origins. The result is a more immediate business question for users: which models are affordable, capable and permissible to deploy.

Cheap Chinese models have made access a security and business conflict
John Coogan frames the immediate dispute as whether U.S. companies should be able to use Chinese AI models that have become both capable and inexpensive—and whether Washington could, or should, stop them. Chinese models have been available to American users for years, he says. What has changed is their perceived capability and cost.
The Wall Street Journal reported that OpenAI and Anthropic executives had warned that powerful Chinese models could create security risks and contribute to a “dystopian AI future.” Their critics see a more commercial calculation. Frontier labs have raised billions to fund the compute required to keep improving their systems; low-cost rivals could weaken the pricing power that helps finance that spending.
The immediate flashpoint is a group of Chinese systems including Moonshot AI’s Kimi K3 and Alibaba’s Qwen 3.8 Max. Coogan describes Alibaba as both a major investor in Moonshot and a company with its own large-model operation, comparing that position to Google’s place in the U.S. AI ecosystem. Kimi K3, he says, was competitive with U.S. models on some benchmarks. The important unresolved question was whether it would actually be released as open weights.
Open-weight distribution changes the economics as well as the geography of competition. A company can download a model, customize it with its own data, and adapt it to a particular task rather than pay a provider for each use. That can be highly useful for enterprises, Coogan says, but it also raises the prospect that capable intelligence becomes broadly available at little direct cost.
Dean Ball, OpenAI’s head of strategic futures, described one possible consequence as “full AI communism”: a world in which AI is treated not as a market product but as a public good or state-provided digital infrastructure. Ball later said he was not stating OpenAI policy or advocating a crackdown on Chinese AI; he said he was describing what he saw as a probable outcome.
Coogan interprets that argument more narrowly than a prediction that the state would nationalize data centers. Neo-clouds and compute providers could still be paid and still earn profits. The question is whether open access to strong models would compress margins for infrastructure providers and model developers alike.
It’s not that this automatically leads to nationalization of compute in any way. People would still be paid, but the margins might be lower.
That economic concern sits uneasily beside the national-security case. David Sacks, the White House AI adviser, read Ball’s argument as a potential case for regulatory capture: an attempt by incumbent labs to turn regulatory uncertainty into a weapon against competitors. Coogan says the administration appeared divided, with security-focused officials reportedly considering trade blacklists, security warnings about Chinese AI companies, and a possible executive order targeting open models.
Treasury Secretary Scott Bessent offered what Coogan sees as a possible basis for action: the administration supports open-source models, Bessent said, but not intellectual-property theft. If the government acts aggressively, Coogan expects alleged IP theft could be the rationale used to sanction companies behind Chinese models. That remains a prospective path, not an announced policy.
Open weights make a clean restriction hard to define
The policy problem is not simply whether a model is Chinese or American. It is what counts as the model once weights, research methods, synthetic data, fine-tunes, and downstream derivatives circulate through an ecosystem.
Jordi Hays and Coogan return repeatedly to that practical difficulty. A company might download a model’s weights. It might train a similar architecture from a published paper. It might fine-tune a prior model, use outputs from another model as training data, or build a successor several technical steps removed from the original system. Coogan asks how far that chain must extend before a system no longer counts as Chinese.
He compares the enforcement problem to piracy. In his account, piracy was not eliminated by banning the ability to torrent files; legal services such as Spotify, Netflix, and Apple’s media products made paid access sufficiently convenient that many users preferred them. The comparable response to Chinese AI, he suggests, may be to make U.S. alternatives trusted, accessible, and cheap enough that users do not need to seek out restricted models.
Cybersecurity makes the argument harder. Coogan says open systems with advanced cyber capabilities could enable more attacks and more spam. But he also argues that cyber capability is becoming a product category among closed-model providers, including lower-cost specialized offerings. That creates a practical choice for a midsize company: a costly, tightly controlled system for intensive security work, or a cheaper tuned model that can review code and flag obvious problems.
The distinction matters because the security argument is not only about whether advanced cyber capabilities exist. It is also about who can afford them, under what conditions, and whether a company can obtain defensive assistance without paying frontier-model prices for every task.
The competitive landscape is therefore not just Chinese open models against closed U.S. labs. Coogan points to Thinking Machines Lab’s first open-weight model and says Nvidia’s Nemotron 3 Ultra was beginning to gain traction. If sanctions or compliance restrictions limited U.S. infrastructure providers’ ability to serve Chinese open models, he argues, American open-source alternatives could benefit. But the same technical openness that creates that opportunity also makes a categorical ban difficult to administer.
Similarity can raise questions without proving distillation
A heatmap shown on screen compared semantic similarity among model families from Anthropic, OpenAI, Google, DeepSeek, Moonshot, and Zhipu. It placed Moonshot’s Kimi K3 comparatively close to Anthropic’s Fable 5, Opus 4.7 and 4.8, and Sonnet 5, according to the discussion around the graphic.
The unnamed speaker who explained the analysis described its method as prompting models repeatedly and looking for similarities in diction, phrasing, and other semantic patterns. But the speaker also stressed that only a few prompts were used and that the result was “very much just correlation,” not proof that Kimi K3 had been distilled from Anthropic models. Similar post-training techniques or other shared product choices could generate comparable outputs.
Coogan emphasizes that the same heatmap displayed ordinary family resemblance. OpenAI’s GPT 5.4, 5.5, and 5.6 appeared more similar to one another than to Anthropic models, while Anthropic systems appeared closer to other Anthropic systems. That is unsurprising, he says, if organizations build successive releases on their prior work.
There are also indirect routes by which a smaller model could acquire the textual flavor of a larger one. Coogan imagines users generating code with Opus, providing feedback on whether the result succeeded or failed, and then producing training material that helps another model learn related patterns. In that scenario, resemblance could emerge through user-generated rollouts and feedback rather than a straightforward copy of a model’s underlying weights.
The uncertainty has direct consequences for enforcement. Distillation may violate a provider’s terms of service, Hays says, but he considers suing Chinese companies a “complete and total waste of time.” Coogan agrees that tracing the conduct and enforcing a claim would be hard.
With an open-source model, how do you even define it?
Jim Cramer argued in a displayed X post that U.S. companies should not use Chinese models merely to save money, calling the issue vital to national security and asserting that the companies were run by the PLA. A reply displayed beneath the post made the opposing technical point: a model can be run entirely in America, with none of a user’s data leaving the country.
George Hotz’s response, as read by Coogan, was more commercial. If American model companies want developers to choose them over Chinese open-weight alternatives, Hotz argued, they should put their weights on Hugging Face rather than rely on what he called rent extraction.
China may be considering its own restrictions. Hays cited Financial Times reporting displayed on screen that China’s Ministry of Commerce had discussed limiting overseas transfers of key training data and foreign downloads of model weights by companies including Alibaba, ByteDance, and Zhipu. According to that reporting as described by Hays, overseas customers could still access models and related services. The direction under discussion, however, appeared to be less openness around weights rather than more.
That possibility supported Ball’s narrower prediction that geopolitical pressure could move both countries away from broadly downloadable frontier models. Coogan says Ball’s point was descriptive rather than prescriptive: he was forecasting how governments might respond, not necessarily endorsing that response.
AI provenance is becoming a product and disclosure question
Substack’s Pangram integration moves the provenance debate from model training to published writing. Jordi Hays says the feature lets users scan posts, replies, and comments in the Substack app for an estimate of how much was written by a human and how much involved AI assistance. Substack said the feature served its mission of building an economic engine for culture.
Coogan’s view is that audience response may be less absolute than the debate implies: if work is good and enjoyable, many readers may not care much whether AI helped create it. He does not argue that creators need to put a production disclosure at the top of every post. His standard is that authorship arrangements should be possible to discover for a reader who wants to know.
He compares that to a publication brand such as Bloomberg. Not every article is written by Michael Bloomberg, Coogan says, but readers can see who wrote a given article. Hays describes a similar pre-AI arrangement from his YouTube work: he would write material, a writer on his team would make a draft, and they would iterate. The writer appeared in the credits, though Hays did not begin each video by announcing the collaboration.
For Substack authors and other individual creators, Hays’s proposed disclosure is simple: say somewhere that a team helps create the work. Coogan says ghostwriting already makes authorship more complicated than a single byline suggests. Some book authors acknowledge collaborators; many do not. He mentions the continuation of books under established author brands after the original author has died as an example of a name becoming a larger commercial identity.
Coogan also pushes back on writer Dave Eggers’s reported claim that nobody will read AI novels. People are likely already reading AI-generated or AI-assisted work, he says, whether or not they know it. The practical issue is whether a reader who cares about provenance can learn how the work was produced.
Model routing turns abundance into an operating-cost decision
The expanding model market is also producing a more prosaic enterprise problem: deciding which model should handle which task. Coogan says Ramp has launched a model router in alpha with some customers and that he believes it is also available to non-Ramp customers as a standalone product.
The rationale, in his account, is cost control. Companies should not use their most expensive frontier model for every request. Coogan describes the waste case as burning millions of tokens from a top-tier system to answer something as routine as a weather question.
Ramp’s promise to save companies time and money fits that use case, he says: route work to a model appropriate to the task rather than defaulting to the most capable and costly available option. The point is connected to the broader contest over Chinese models but is not identical to it. More open-weight systems, low-cost providers, specialized cyber models, and frontier offerings mean the choice of model is increasingly an operational purchasing decision—not just a judgment about the maximum capability a company can access.



