
As the capabilities and appeal of Chinese open-weight AI models escalate, discussions regarding the appropriate responses to them have surged once more.
There’s speculation that the Trump administration may attempt to impose a ban (although no actions have been taken yet). In the meantime, creators of proprietary models, particularly OpenAI and Anthropic, seem increasingly apprehensive about these developments.
Open-weight models like Moonshot AI’s Kimi K3 or Alibaba’s Qwen provide inference at a fraction of the cost per token compared to the closed source models produced by these major U.S. labs. The concern is that they might represent a form of threat. Undoubtedly, they jeopardize the profit margins of the large proprietary AI laboratories.
But should companies utilizing these models in their own data centers give in to the anxiety that they could become a conduit for Chinese hackers?
No, asserts Lucas Atkins, the Chief Technology Officer of Arcee, which is developing open models to provide U.S. firms with a domestically produced alternative to Chinese variants.
If any startup would benefit from a prohibition on Chinese models, it would be Arcee. However, Atkins claims that China’s open models are not any more perilous than any other open source software a company might employ. In fact, he mentions, they even offer advantages to his own enterprise.
“Many perceive this as akin to a Chinese software application. Like, it was developed with these x, y, z objectives” that a malicious actor could potentially manipulate, he remarked.
“That is fundamentally not how these models undergo training. There is essentially no way for an Arcee, or an Alibaba, to create a model, have it executed in someone’s setting and have us gain any access to it at all,” he clarified.
Although most of these models are referred to as “open weight” and aren’t entirely open source software, the source code (the portion that will actually operate on servers), if acquired from open source platforms like Hugging Face, is predominantly transparent and subject to scrutiny. (What remains inaccessible is the methodologies and data utilized to train the models.)
Large organizations ought to subject any model core to their security evaluations and inspection protocols, and they often retrain the models for their specific applications, examining factors such as bias, toxicity, hallucinations, and sensitivity to particular subjects. Thus, they analyze, optimize, and comprehend the models before users commence submitting prompts.
Could a model designed for coding potentially insert harmful backdoors into the code it generates? While that is theoretically feasible, it would necessitate intricate maneuvers to achieve.
“There’s no reason a sufficiently skilled actor couldn’t train a model to be an outstanding coding resource in every situation, but when faced with a specific type of codebase… some concealed training would be triggered,” speculated Atkins, who dedicates his time to training models. However, he adds: “I’m not sure how one would accomplish this.”
Given that large language models are inherently creative, the likelihood of eliciting a contemporary model to produce malware in reaction to a meticulously planned perfect storm of context and prompt is minimal. Even more unlikely is that any organization would opt to use that code.
Could such an event occur in the future? That remains uncertain. However, organizations are also constructing their AI applications to be model-agnostic and to integrate multiple models. Thus, even if Chinese models are the most cost-effective today, firms won’t be confined to using them indefinitely.
“I believe rather than the dialogue focusing on how to ban Chinese models, it should shift to how we can cultivate a robust, open ecosystem here in the U.S.,” remarks Atkins.
Arcee also receives benefits from Chinese models. Their openness allows the startup to “gain from those models being effective because we can learn from what they have accomplished. We can build upon them. Then they can learn from our advancements,” he states. “We hold immense respect for the individuals developing those models, the individual researchers.”
Ultimately, the approach to compete with Chinese models “is to release a model that surpasses theirs,” asserts Atkins. “We need to provide them with something worth discussing.”
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

