<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Geopolitechs]]></title><description><![CDATA[a geopolitics and technology policy watcher]]></description><link>https://www.geopolitechs.org</link><image><url>https://substackcdn.com/image/fetch/$s_!aVc5!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2028e1d9-f1fb-49c7-a3d8-7db2ddc3e7dd_484x484.png</url><title>Geopolitechs</title><link>https://www.geopolitechs.org</link></image><generator>Substack</generator><lastBuildDate>Fri, 11 Sep 2026 23:44:29 GMT</lastBuildDate><atom:link href="https://www.geopolitechs.org/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Peng ZHANG]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[geotechnopolitic@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[geotechnopolitic@substack.com]]></itunes:email><itunes:name><![CDATA[Geopolitechs]]></itunes:name></itunes:owner><itunes:author><![CDATA[Geopolitechs]]></itunes:author><googleplay:owner><![CDATA[geotechnopolitic@substack.com]]></googleplay:owner><googleplay:email><![CDATA[geotechnopolitic@substack.com]]></googleplay:email><googleplay:author><![CDATA[Geopolitechs]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[DeepSeek V4.1 Flash: Stronger, Faster, More Accessible]]></title><description><![CDATA[Today, we are officially releasing DeepSeek V4.1 Flash. It is the smallest model in our new family of model architectures and features native multimodal visual understanding.]]></description><link>https://www.geopolitechs.org/p/deepseek-v41-flash-stronger-faster</link><guid isPermaLink="false">https://www.geopolitechs.org/p/deepseek-v41-flash-stronger-faster</guid><dc:creator><![CDATA[Geopolitechs]]></dc:creator><pubDate>Thu, 10 Sep 2026 08:56:34 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Rs-h!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffab12565-d449-4dc2-a290-25d023b60f46_1080x554.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Today, we are officially <a href="https://mp.weixin.qq.com/s/qg0NU3NNUbp1co2PdkAPAg">releasing</a> <strong>DeepSeek V4.1 Flash</strong>. It is the smallest model in our new family of model architectures and features native multimodal visual understanding.</p><p>The new architecture is designed to deliver <strong>higher capability ceilings, faster inference, greater throughput, and scalability to models with significantly larger parameter counts</strong>.</p><h2>Asymmetric architecture: big intelligence at lower cost</h2><p>DeepSeek V4.1 Flash is a 552B-parameter MoE model built on a new <strong>Causal-Encoder-Decoder</strong> architecture. It uses an asymmetric design between input and output: only <strong>8B activated parameters</strong> on the input side and <strong>16B activated parameters</strong> on the output side, resulting in significantly lower cost than other known models at a similar scale.</p><blockquote><p><em><strong>Editor&#8217;s note:</strong> The official release of V4 Flash on July 31 retained the same model architecture and size as the preview version, with the main changes coming from additional post-training. This design is closely aligned with how AI agents operate. When working with code repositories, long documents, or extensive conversation histories, models often need to process large volumes of input while generating relatively limited outputs, such as decisions, code, or action instructions. Reducing the computational cost of input processing could therefore significantly improve the overall efficiency of these agentic workloads.</em></p></blockquote><p>V4.1 Flash also adopts a new pre-training approach and undergoes larger-scale reinforcement learning (post-training). In benchmark evaluations, it surpasses the intelligence level of a number of flagship models, including DeepSeek V4 Pro.</p><blockquote><p><em><strong>Editor&#8217;s note:</strong>According to the official benchmark results, V4.1 Flash scored 90.9 on GPQA Diamond, a benchmark for graduate-level scientific reasoning, achieved a Codeforces competitive programming rating of 3,471, and scored 65.6 on MathArena Apex.</em></p><p><em>On Terminal-Bench 2.1, which evaluates models&#8217; ability to execute tasks in terminal environments, V4.1 Flash scored 90.6. It also achieved 88.1 on CyberGym, a cybersecurity benchmark. By comparison, the previously released V4 Pro scored 87.9 and 83.3, respectively, on these two benchmarks.</em></p></blockquote><p><strong>Figure 1. Performance comparison on Agentic Benchmark</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Rs-h!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffab12565-d449-4dc2-a290-25d023b60f46_1080x554.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Rs-h!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffab12565-d449-4dc2-a290-25d023b60f46_1080x554.png 424w, https://substackcdn.com/image/fetch/$s_!Rs-h!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffab12565-d449-4dc2-a290-25d023b60f46_1080x554.png 848w, https://substackcdn.com/image/fetch/$s_!Rs-h!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffab12565-d449-4dc2-a290-25d023b60f46_1080x554.png 1272w, https://substackcdn.com/image/fetch/$s_!Rs-h!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffab12565-d449-4dc2-a290-25d023b60f46_1080x554.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Rs-h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffab12565-d449-4dc2-a290-25d023b60f46_1080x554.png" width="1080" height="554" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fab12565-d449-4dc2-a290-25d023b60f46_1080x554.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:554,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:316027,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.geopolitechs.org/i/215013569?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffab12565-d449-4dc2-a290-25d023b60f46_1080x554.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Rs-h!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffab12565-d449-4dc2-a290-25d023b60f46_1080x554.png 424w, https://substackcdn.com/image/fetch/$s_!Rs-h!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffab12565-d449-4dc2-a290-25d023b60f46_1080x554.png 848w, https://substackcdn.com/image/fetch/$s_!Rs-h!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffab12565-d449-4dc2-a290-25d023b60f46_1080x554.png 1272w, https://substackcdn.com/image/fetch/$s_!Rs-h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffab12565-d449-4dc2-a290-25d023b60f46_1080x554.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!50mo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd498db35-503f-47f6-8755-d99726877097_1080x1110.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!50mo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd498db35-503f-47f6-8755-d99726877097_1080x1110.webp 424w, https://substackcdn.com/image/fetch/$s_!50mo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd498db35-503f-47f6-8755-d99726877097_1080x1110.webp 848w, https://substackcdn.com/image/fetch/$s_!50mo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd498db35-503f-47f6-8755-d99726877097_1080x1110.webp 1272w, https://substackcdn.com/image/fetch/$s_!50mo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd498db35-503f-47f6-8755-d99726877097_1080x1110.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!50mo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd498db35-503f-47f6-8755-d99726877097_1080x1110.webp" width="1080" height="1110" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d498db35-503f-47f6-8755-d99726877097_1080x1110.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1110,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:79960,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.geopolitechs.org/i/215013569?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd498db35-503f-47f6-8755-d99726877097_1080x1110.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!50mo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd498db35-503f-47f6-8755-d99726877097_1080x1110.webp 424w, https://substackcdn.com/image/fetch/$s_!50mo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd498db35-503f-47f6-8755-d99726877097_1080x1110.webp 848w, https://substackcdn.com/image/fetch/$s_!50mo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd498db35-503f-47f6-8755-d99726877097_1080x1110.webp 1272w, https://substackcdn.com/image/fetch/$s_!50mo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd498db35-503f-47f6-8755-d99726877097_1080x1110.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Smaller cache, lower cost</h2><p>The new-generation architecture substantially reduces the size of the KV cache. Compared with the previous generation, the demand for HBM is reduced to <strong>1/4</strong>, and the demand for SSD is reduced to <strong>1/8</strong>.</p><p>In agent-use scenarios, cache-hit fees often take a meaningful share of total cost. Compressing KV cache therefore significantly reduces the cost of agent-style tasks.</p><p><strong>[Missing image]</strong> (KV cache size reduction progress figure)</p><p>The original post notes that, compared with the first-generation model, the KV cache has already shrunk by <strong>437&#215;</strong>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Q_rW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72faca0d-0539-4db3-a6fc-9468c1cd7df0_1080x554.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Q_rW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72faca0d-0539-4db3-a6fc-9468c1cd7df0_1080x554.webp 424w, https://substackcdn.com/image/fetch/$s_!Q_rW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72faca0d-0539-4db3-a6fc-9468c1cd7df0_1080x554.webp 848w, https://substackcdn.com/image/fetch/$s_!Q_rW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72faca0d-0539-4db3-a6fc-9468c1cd7df0_1080x554.webp 1272w, https://substackcdn.com/image/fetch/$s_!Q_rW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72faca0d-0539-4db3-a6fc-9468c1cd7df0_1080x554.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Q_rW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72faca0d-0539-4db3-a6fc-9468c1cd7df0_1080x554.webp" width="1080" height="554" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/72faca0d-0539-4db3-a6fc-9468c1cd7df0_1080x554.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:554,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:22294,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.geopolitechs.org/i/215013569?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72faca0d-0539-4db3-a6fc-9468c1cd7df0_1080x554.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Q_rW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72faca0d-0539-4db3-a6fc-9468c1cd7df0_1080x554.webp 424w, https://substackcdn.com/image/fetch/$s_!Q_rW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72faca0d-0539-4db3-a6fc-9468c1cd7df0_1080x554.webp 848w, https://substackcdn.com/image/fetch/$s_!Q_rW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72faca0d-0539-4db3-a6fc-9468c1cd7df0_1080x554.webp 1272w, https://substackcdn.com/image/fetch/$s_!Q_rW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72faca0d-0539-4db3-a6fc-9468c1cd7df0_1080x554.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p><strong>Editor&#8217;s note:</strong> Compared with V4 Flash pricing during the same time window, cached input is 60% cheaper, uncached input about 33.3% cheaper, and output about 11.1% cheaper.</p><p>The savings are <a href="https://mp.weixin.qq.com/s/556H0Ug4KPpW8VtIIHX6C">more significant</a> for workloads that repeatedly process large amounts of context. Agents, for example, often need to re-read conversation history, tool instructions, and code across multiple steps. Lower cached-input pricing can substantially reduce these recurring costs. By contrast, workloads dominated by the generation of new output will see more limited savings.</p><p>For example, assuming fixed usage of 1 million cached input tokens, 100,000 uncached input tokens, and 10,000 output tokens, the cost of a single task during off-peak hours would fall from RMB 0.245 to RMB 0.16, a reduction of approximately 34.7%. Actual costs will still depend on factors such as reasoning length, the number of tool-call iterations, and failed attempts or retries.</p></blockquote><h2>API support</h2><p>DeepSeek V4.1 Flash is now available on the DeepSeek API, with native multimodal support. To use the latest V4.1 Flash, set the model name to <strong>deepseek-flash</strong>.</p><p>The older models <strong>V4 Flash</strong> and <strong>V4 Flash Vision Exp</strong> have been taken offline. For compatibility, requests to <strong>deepseek-v4-flash</strong> and <strong>deepseek-v4-flash-vision-exp</strong> will temporarily be routed to V4.1 Flash.</p><p>Based on extensive testing, V4.1 Flash outperforms V4 Pro across performance, cost, speed, and end-to-end latency. DeepSeek plans an orderly phase-out of <strong>V4 Pro</strong>. After <strong>12:00 (Beijing time), Sep 14, 2026</strong> and until V4.1 Pro is released, all requests to <strong>deepseek-v4-pro</strong> will be routed to V4.1 Flash and billed at the V4.1 Flash price.</p><p>Tencent (WorkBuddy, CodeBuddy) and OpenCode, as official partners, have fully integrated DeepSeek V4.1 Flash&#8212;welcome to try it.</p><blockquote><p><em><strong>Editor&#8217;s note:</strong></em>Previously, DeepSeek offered experimental vision capabilities through V4 Flash Vision Exp. With the new release, both the previous V4 Flash model and the experimental vision model have been retired. Requests using either of the two former model names are now handled by V4.1 Flash, bringing text and image processing together in a single flagship API model.</p><p>According to the latest image-understanding documentation, developers can use the model to describe images, extract text from screenshots, and analyze charts. Images can be provided through publicly accessible URLs, submitted directly in encoded form, or uploaded and referenced through the Files API.</p><p>This has practical implications for agents working with real-world materials. Business documents often require models to understand text alongside charts, while software-related tasks may require code to be interpreted together with interface screenshots. A unified model endpoint reduces the need for developers to route tasks between, and switch across, separate text and vision models.</p></blockquote><h2>API pricing adjustment</h2><p>Thanks to architectural innovation, DeepSeek V4.1 Flash can serve more users at lower cost, so its pricing is reduced accordingly. To allocate resources more reasonably, DeepSeek continues to use peak/off-peak pricing: <strong>off-peak price is half of peak price</strong>, encouraging users to schedule tasks based on their needs. The new pricing takes effect at <strong>12:00 (Beijing time), Sep 10, 2026</strong>.</p><p><strong>[Missing image]</strong> (pricing table/figure in the original post)</p><h2>Open-sourcing</h2><p>DeepSeek will fully support the open-source community in adapting inference for this new model architecture and will explore various ways to broaden the deployment footprint. If you have large-scale deployment needs and the required resources (e.g., 2,000 GPUs and a storage cluster), DeepSeek welcomes you to get in touch.</p><ul><li><p><strong>Model</strong>: <a href="https://huggingface.co/deepseek-ai/DeepSeek-V4.1-Flash">https://huggingface.co/deepseek-ai/DeepSeek-V4.1-Flash</a></p></li><li><p><strong>Technical report</strong>: <a href="https://huggingface.co/deepseek-ai/DeepSeek-V4.1-Flash/blob/main/DeepSeek_V41_Tech_Report.pdf">https://huggingface.co/deepseek-ai/DeepSeek-V4.1-Flash/blob/main/DeepSeek_V41_Tech_Report.pdf</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[China Fires Back at U.S. Security Agencies’ AI Model Distillation Allegations]]></title><description><![CDATA[On September 8, the U.S.]]></description><link>https://www.geopolitechs.org/p/china-fires-back-at-us-security-agencies</link><guid isPermaLink="false">https://www.geopolitechs.org/p/china-fires-back-at-us-security-agencies</guid><dc:creator><![CDATA[Geopolitechs]]></dc:creator><pubDate>Wed, 09 Sep 2026 13:59:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Yg-Z!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9f8f5a6-db33-4bc2-bf6c-50d7d2a93ad6_1593x1140.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>On September 8, the U.S. National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and Federal Bureau of Investigation (FBI) jointly issued an 18-page <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a">cybersecurity advisory </a>titled <em>China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Against U.S. AI Companies</em>. The advisory primarily sets out the U.S. government&#8217;s attribution of the activities, the techniques allegedly employed, and recommended defensive measures for U.S. companies.</p><p>Regarding the Chinese government&#8217;s relationship to these activities, the advisory stops short of alleging direct government involvement, instead stating that the activities were &#8220;likely with Chinese government awareness.&#8221;</p><blockquote><p><em>Likely with Chinese government awareness, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024.</em></p></blockquote><p>Today, spokespersons for China&#8217;s Ministry of Commerce and Ministry of Foreign Affairs separately responded to the U.S. allegations.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Yg-Z!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9f8f5a6-db33-4bc2-bf6c-50d7d2a93ad6_1593x1140.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Yg-Z!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9f8f5a6-db33-4bc2-bf6c-50d7d2a93ad6_1593x1140.png 424w, https://substackcdn.com/image/fetch/$s_!Yg-Z!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9f8f5a6-db33-4bc2-bf6c-50d7d2a93ad6_1593x1140.png 848w, https://substackcdn.com/image/fetch/$s_!Yg-Z!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9f8f5a6-db33-4bc2-bf6c-50d7d2a93ad6_1593x1140.png 1272w, https://substackcdn.com/image/fetch/$s_!Yg-Z!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9f8f5a6-db33-4bc2-bf6c-50d7d2a93ad6_1593x1140.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Yg-Z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9f8f5a6-db33-4bc2-bf6c-50d7d2a93ad6_1593x1140.png" width="1456" height="1042" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f9f8f5a6-db33-4bc2-bf6c-50d7d2a93ad6_1593x1140.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1042,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:627896,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.geopolitechs.org/i/214889977?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9f8f5a6-db33-4bc2-bf6c-50d7d2a93ad6_1593x1140.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!Yg-Z!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9f8f5a6-db33-4bc2-bf6c-50d7d2a93ad6_1593x1140.png 424w, https://substackcdn.com/image/fetch/$s_!Yg-Z!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9f8f5a6-db33-4bc2-bf6c-50d7d2a93ad6_1593x1140.png 848w, https://substackcdn.com/image/fetch/$s_!Yg-Z!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9f8f5a6-db33-4bc2-bf6c-50d7d2a93ad6_1593x1140.png 1272w, https://substackcdn.com/image/fetch/$s_!Yg-Z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9f8f5a6-db33-4bc2-bf6c-50d7d2a93ad6_1593x1140.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><a href="https://mp.weixin.qq.com/s/mAXvb8-QLl1pFGie_86ibA"><span>MOFCOM Spokesperson Responds to Questions on U.S. Cybersecurity Advisory Concerning Alleged Distillation Activities by Chinese AI Companies</span></a></strong></p><blockquote><p><strong><span>September 9, 2026</span></strong><span><br><br></span><strong><span>Q:</span></strong><span> On September 8 U.S. Eastern Time, the U.S. National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and Federal Bureau of Investigation (FBI) jointly issued an advisory accusing Chinese artificial intelligence companies of conducting &#8220;industrial-scale&#8221; distillation of U.S. models to acquire the capabilities of leading U.S. models, while recommending defensive measures for U.S. companies. What is China&#8217;s comment?<br><br></span><strong><span>A:</span></strong><span> We have taken note of the relevant developments. China believes that the U.S. allegations that Chinese AI companies are conducting &#8220;industrial-scale&#8221; distillation of U.S. models are unfounded both in fact and in law. The U.S. is politicizing and weaponizing distillation, which is a normal technical and commercial practice within the industry, while applying double standards in practice. The advisory is yet another example of the United States pursuing technological hegemony in the field of artificial intelligence, seeking to monopolize computing power, and suppressing competition. China firmly opposes such actions.<br><br>Distillation is a common practice through which AI models learn from one another and is, in essence, a technologically neutral technique. Model developers around the world, including U.S. companies, use distillation. It can improve the efficiency of model learning and enable more effective utilization of human knowledge. It therefore has positive implications for the development of AI industries around the world, for unlocking the potential of AI technologies, for narrowing development gaps, and for ensuring that developing countries and the broader public can benefit more widely from advances in AI.<br><br>The U.S. approach represents a typical case of double standards. China encourages open-source development, openness, cooperation and sharing in AI. Chinese open-source models are available to companies around the world, including U.S. companies, facilitating the development of their models. Reports published by U.S. companies on their model development have also disclosed extensive distillation of Chinese models. By contrast, the United States has repeatedly and unilaterally accused Chinese companies of engaging in &#8220;industrial-scale&#8221; distillation, portraying a common industry practice as a form of attack. This reflects both U.S. anxiety and its double standards.<br><br>The U.S. approach is also a typical example of using the fight against distillation as a pretext for pursuing industrial monopoly. Having national security agencies issue such an advisory ties the interests of individual companies and capital to national security and uses the coercive power of the state to interfere with normal commercial activities. We have also noted that certain U.S. AI companies have abused their competitive advantages by incorporating sweeping geographic restrictions and other unfair terms into their user agreements. The U.S. allegations concerning distillation appear to provide government backing for such unfair contractual terms.<br><br>The U.S. approach is a typical example of using state power to preserve technological hegemony and monopolies over computing power while suppressing competition. Since the beginning of this year, the U.S. executive and legislative branches have repeatedly threatened sanctions and other restrictive measures against Chinese companies over alleged distillation activities. Their objective is to suppress competition and preserve U.S. monopolies in computing power and data&#8212;seeking a situation in which only the United States wins rather than one in which humanity as a whole benefits. This would turn global AI resources, which should be accessible on an open and equitable basis, into resources monopolized by a small number of companies, while preventing other countries from participating in and broadly sharing the benefits of AI innovation.<br><br>The large-model industry is currently at a critical stage characterized by rapid technological iteration, emerging risks and continued development. As major countries, China and the United States should address the challenges and risks facing artificial intelligence in a positive and responsible manner. The two heads of state have agreed to establish an intergovernmental dialogue on artificial intelligence. China is willing to engage in constructive and professional discussions with the United States through dialogue on the basis of equality, mutual benefit and win-win cooperation.<br><br>However, if the United States uses combating distillation as a pretext to take actions aimed at containing and suppressing Chinese AI companies, China will resolutely take countermeasures. We hope the United States will work with China in the same direction, manage risks through dialogue and communication, and promote the development of an AI industry that benefits the world.</span></p></blockquote><p><strong><a href="https://www.fmprc.gov.cn/fyrbt_673021/202609/t20260909_12019125.shtml">China&#8217;s Foreign Ministry Responds to U.S. Allegations of AI Model Distillation</a></strong></p><blockquote><p><strong>AFP:</strong> Yesterday, the U.S. Cybersecurity and Infrastructure Security Agency accused leading Chinese artificial intelligence companies, including DeepSeek and Moonshot AI, of stealing technology from U.S. large models, describing this as a &#8220;core&#8221; strategy of Chinese AI companies. What is the Foreign Ministry&#8217;s comment?</p><p><strong>Mao Ning:</strong> The development of artificial intelligence in China is the result of the country&#8217;s pursuit of greater self-reliance and strength in science and technology. It has also benefited from China&#8217;s consistent commitment to the principles of extensive consultation, joint contribution and shared benefits, as well as openness and cooperation.</p><p>We have always maintained that countries should work together to promote the open, inclusive and responsible development of artificial intelligence, ensure that its benefits are broadly shared, and harness AI for the well-being of all humanity.</p><p>We hope the United States will earnestly implement the important common understandings reached by the two heads of state and refrain from making unfounded accusations against China or smearing the country. China and the United States are both major AI powers and should strengthen cooperation.</p></blockquote>]]></content:encoded></item><item><title><![CDATA[China’s Supreme Court Sets the Rules for AI Liability — but Sidesteps the Biggest Copyright Question]]></title><description><![CDATA[New judicial guidance clarifies fault, platform liability and evidentiary burdens, while deliberately avoiding a uniform rule on AI training and copyright.]]></description><link>https://www.geopolitechs.org/p/chinas-supreme-court-sets-the-rules</link><guid isPermaLink="false">https://www.geopolitechs.org/p/chinas-supreme-court-sets-the-rules</guid><dc:creator><![CDATA[Geopolitechs]]></dc:creator><pubDate>Tue, 08 Sep 2026 20:22:57 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!2Obu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30e24007-cce8-4a71-b504-4e8cb168632d_1074x696.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>On September 7, 2026, China&#8217;s Supreme People&#8217;s Court (SPC) issued the <em>O<a href="https://www.court.gov.cn/zixun/xiangqing/511101.html">pinions of the Supreme People&#8217;s Court on the Lawful Adjudication of Artificial Intelligence-Related Disputes</a></em> (the &#8220;Opinions&#8221;). </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2Obu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30e24007-cce8-4a71-b504-4e8cb168632d_1074x696.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2Obu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30e24007-cce8-4a71-b504-4e8cb168632d_1074x696.png 424w, https://substackcdn.com/image/fetch/$s_!2Obu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30e24007-cce8-4a71-b504-4e8cb168632d_1074x696.png 848w, https://substackcdn.com/image/fetch/$s_!2Obu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30e24007-cce8-4a71-b504-4e8cb168632d_1074x696.png 1272w, https://substackcdn.com/image/fetch/$s_!2Obu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30e24007-cce8-4a71-b504-4e8cb168632d_1074x696.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2Obu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30e24007-cce8-4a71-b504-4e8cb168632d_1074x696.png" width="1074" height="696" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/30e24007-cce8-4a71-b504-4e8cb168632d_1074x696.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:696,&quot;width&quot;:1074,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2Obu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30e24007-cce8-4a71-b504-4e8cb168632d_1074x696.png 424w, https://substackcdn.com/image/fetch/$s_!2Obu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30e24007-cce8-4a71-b504-4e8cb168632d_1074x696.png 848w, https://substackcdn.com/image/fetch/$s_!2Obu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30e24007-cce8-4a71-b504-4e8cb168632d_1074x696.png 1272w, https://substackcdn.com/image/fetch/$s_!2Obu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30e24007-cce8-4a71-b504-4e8cb168632d_1074x696.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The Opinions contain 24 provisions covering AI-enabled face swapping, voice cloning, virtual avatars, personal information, infringement involving AI-generated content, discriminatory pricing, autonomous driving, training data, open-source software, and AI-generated evidence.</p><p>The primary purpose of the Opinions is to provide courts with a more consistent framework for adjudicating AI-related disputes under China&#8217;s existing civil law regime. In particular, they address how liability should be allocated among developers, service providers and users, and how courts should assess duties of care, fault, causation and burdens of proof.</p><p>It is important to clarify at the outset that the Opinions do not constitute new AI legislation, nor are they a judicial interpretation. They are issued under the document designation &#8220;Fa Fa&#8221; (&#27861;&#21457;) and constitute judicial policy and adjudicatory guidance issued by the SPC. In its accompanying <a href="https://www.court.gov.cn/zixun/xiangqing/511111.html">Q&amp;A</a>, the SPC expressly noted that China has not yet enacted a dedicated AI law. AI-related disputes must therefore continue to be adjudicated under existing laws, including the Civil Code, Copyright Law, Personal Information Protection Law, Anti-Unfair Competition Law, Consumer Rights Protection Law, Product Quality Law and Civil Procedure Law. The Opinions themselves therefore cannot create new categories of civil rights or liabilities.</p><p>Nevertheless, their practical significance is considerable. The Opinions call for cases that may establish important rules or require greater consistency in the application of law to be heard at a higher level where appropriate, while promoting greater consistency through the People&#8217;s Courts Case Database and judicial supervision. Standards developed through future landmark AI cases may therefore have a broader impact on companies&#8217; product design, data governance and risk controls.</p><p><strong>On the allocation of liability, the Opinions generally retain a fault-based approach. They do not impose strict liability on model developers or service providers for all AI outputs, but nor do they allow companies to avoid liability simply by invoking &#8220;technology neutrality&#8221; or arguing that the content was generated automatically by a machine.</strong> Courts will assess liability in light of the particular use case, the degree of system autonomy, potential risks and their scope of impact, as well as each party&#8217;s ability to foresee and control those risks.</p><p>This approach both limits and potentially strengthens platform liability. On the one hand, the Opinions do not categorically treat purely online models or applications as &#8220;products&#8221; for purposes of the Product Quality Law. Strict product liability therefore remains primarily relevant to AI products with a physical form, such as robots and autonomous vehicles. On the other hand, a platform may still be found at fault if it could reasonably foresee a particular type of harm and had the ability to mitigate that risk but failed to take proportionate measures.</p><p>Infringement of personality rights illustrates this framework. The Opinions distinguish between infringing content generated by a model itself and content deliberately induced by users through malicious prompts. Users are responsible for their own intentional infringing conduct, while platform liability depends on factors including foreseeability, technical control and the measures already implemented. Where a rights holder provides verified identity information and prima facie evidence of infringement, a platform that fails to take necessary measures&#8212;such as preventing the relevant generation, restricting particular instructions or taking action against an account&#8212;may also bear liability for additional harm occurring after notification.</p><p>Unlike conventional online platforms, where an infringing article, image or hyperlink can simply be removed, a generative model may reproduce similar content following relatively minor changes to a prompt. An important issue for future cases will therefore be how courts determine whether filtering, prompt restrictions, account measures or model updates constitute reasonable and necessary responses. The Opinions do not prescribe a uniform technical standard, leaving this assessment to the circumstances of individual cases.</p><p><strong>The evidentiary rules may have the most immediate practical implications for AI companies.</strong> In cases involving copyright infringement by generated content, a rights holder generally remains responsible for producing prima facie evidence that the disputed content was generated by the model in question and is substantially similar to the protected work. Courts may then, where necessary, require the model developer or service provider to explain the sources of its training data, the training process, the operation of the model and the relevant scientific basis.</p><p>This does not amount to a wholesale reversal of the burden of proof. Rather, evidentiary burdens are allocated according to access to information: rights holders establish external facts reasonably accessible to them, while parties controlling the model, training materials and operational records may be required to provide reasonable explanations concerning internal facts. Where a party controlling documentary or electronic evidence refuses to produce it without justification, the court may draw adverse factual inferences.</p><p>As a result, information concerning training-data provenance, model versions, prompt records, retrieval-augmented generation (RAG) materials, filtering rules, risk testing and complaint handling may evolve from internal R&amp;D records into important litigation evidence for determining infringement, fault and causation. AI compliance is therefore increasingly moving from the question of <strong>whether an obligation was fulfilled to whether the company can demonstrate that it was fulfilled</strong>.</p><p>Companies will accordingly need more traceable data and model governance systems. This may include preserving key records concerning data provenance and licensing, model versions and testing, as well as necessary generation and complaint-handling logs. At the same time, evidence retention must continue to comply with requirements concerning personal information, trade secrets, data security and cross-border transfers. Potential litigation does not justify indefinite retention of all information.</p><p><strong>Compared with its relatively detailed rules on liability and evidence, the SPC has taken a notably cautious approach to copyright issues at the training stage. In its accompanying Q&amp;A, the SPC explained that significant disagreement arose during the drafting process over whether AI-generated content can qualify as a copyrighted work and how the unauthorized use of copyrighted works for model training should be characterized. The Opinions therefore do not establish uniform rules on either issue. This means that while the Opinions provide some guidance on liability arising from AI outputs, they do not resolve the more fundamental industry question of whether foundation-model training is lawful, when such use might constitute fair use, or when authorization from rights holders may be required.</strong></p><p>Previous Chinese cases have indicated that copyright protection for AI-generated content may depend on the extent of human intellectual contribution to the particular generation process and the evidence demonstrating that contribution. In the Beijing Internet Court&#8217;s 2023 &#8220;Spring Breeze Brings Tenderness&#8221; case, the court found that the user had demonstrated original intellectual input by designing prompts, setting parameters and making individualized choices concerning visual elements and composition. The resulting image was therefore eligible for copyright protection. By contrast, in the &#8220;Phantom Wings Transparent Art Chair&#8221; case, the court found that the plaintiff had entered relatively simple prompts and had failed to provide complete records of the generation process, making it difficult to establish a sufficient level of original intellectual contribution. The contrast between the two cases suggests that the central issue is not necessarily whether AI was used, but whether the human contribution satisfies the originality threshold under copyright law and whether that contribution can be demonstrated.</p><p>Existing cases concerning generative AI platform liability have also adopted different analytical approaches. Courts in Guangzhou and Hangzhou, in disputes involving AI-generated images of well-known film and television characters, have examined factors including the degree of platform control over the final output and whether conduct at different stages&#8212;including user uploads, training and generation&#8212;constituted direct or contributory infringement. The multi-factor approach adopted by the Opinions is broadly consistent with this emerging case law, but it does not elevate the approach taken in any individual case into an absolute rule applicable to all models and business models.</p><p>From a broader policy perspective, the SPC&#8217;s decision to address output liability first while postponing a uniform standard for training-related copyright avoids establishing a definitive rule while significant questions remain concerning technical mechanisms, market substitution and licensing arrangements. Whether an output is substantially similar to a pre-existing work, whether a user intended to infringe and whether a platform acted after receiving notice can generally be assessed by reference to specific content and conduct. By contrast, determining whether unauthorized use of copyrighted works for model training constitutes reproduction or qualifies as fair use implicates the technical operation of models, methods of data acquisition, potential market substitution, licensing transaction costs and the conditions necessary for the development of the foundation-model industry.</p><p>Any uniform rule in this area would directly affect the allocation of costs and benefits among model developers, content industries and rights holders. The SPC has not further explained the policy considerations behind its decision not to establish such a rule. The more cautious conclusion at this stage is therefore that these issues will continue to develop through individual cases, industry practice and future legislation.</p><p>Personal-information rules must also be distinguished from copyright rules governing training data. Article 6 of the Opinions leaves some room for using lawfully public personal information for model training within a reasonable scope. Where an individual has not expressly objected and the processing does not have a material impact on that person&#8217;s rights and interests, such processing will generally not be regarded as an infringement of personal-information rights.</p><p>However, permission to process publicly available personal information does not mean that copyrighted expression contained in the same material may automatically be used for training without authorization. A publicly accessible article, for example, may simultaneously contain personal information and copyright-protected expression. Compliance with personal-information rules does not eliminate copyright, contractual or unfair-competition risks. Conversely, obtaining copyright permission does not mean that sensitive personal information contained in the relevant material may be processed without restriction. Public accessibility does not itself amount to a copyright licence or authorization for other uses.</p><p>The Opinions take a comparatively innovation-friendly approach to open-source software. In assessing the liability of open-source software developers and providers, courts may consider licence terms, restrictions on rights, security measures and risk disclosures. Developers that provide certain code modules free of charge and adequately disclose their functions and risks may, depending on the circumstances, be found not liable for downstream infringement.</p><p>However, this provision concerns open-source software and code modules and <strong>should not be broadly interpreted as creating a safe harbour for all open-weight AI models</strong>. Model code, weights, training data and downstream applications may each be governed by different licences and legal rules. Making model weights openly available does not mean that the underlying training data may be freely used. Companies deploying open-weight models therefore still need to review separately the applicable conditions governing code, weights, training data and commercial applications.</p><p>Beyond intellectual property, the Opinions provide guidance on areas including discriminatory pricing and autonomous driving. &#8220;Big data price discrimination&#8221; continues to be assessed primarily through consumers&#8217; rights to information, choice and fair dealing. Liability for autonomous-driving accidents will depend on factors such as driver fault, vehicle defects, sales representations and the causal contribution of each factor. A party controlling autonomous-driving event data may also face adverse consequences if it refuses to produce relevant records.</p><p><strong>From a corporate compliance perspective, the most important implication of the Opinions is not the creation of a new AI compliance checklist, but the growing importance of &#8220;demonstrable compliance.&#8221;</strong> Companies need not only to conduct data-provenance reviews, risk testing, model-version management and rights-notification handling, but also to ensure that these measures can be demonstrated if a dispute subsequently arises.</p><p>At the model pre-training and fine-tuning stages, companies should prioritize records concerning data provenance, licensing status, supplier responsibilities and key cleaning and annotation processes. Significant model and product updates should be accompanied by records of material version changes, testing and risk assessments. Providers of public-facing generative AI services should establish effective rights-notification, internal escalation and remediation mechanisms, and should be able to reconstruct the relevant model version and response process when a dispute arises. When using open-source software or open-weight models, companies should separately review licence terms, model cards, redistribution restrictions, training-data disclosures and restrictions on commercial use.</p><p>Not all of these measures constitute new legal obligations created by the Opinions. Some derive from existing legislation and administrative regulation; others are risk-management measures that may help companies demonstrate that they exercised reasonable care within a fault-based liability framework. As case law develops, practices that currently remain partly voluntary&#8212;such as data traceability, model-version records, red-team testing, risk disclosure and complaint handling&#8212;may increasingly become relevant factual benchmarks for determining whether an AI company exercised reasonable care.</p><p>From an international comparative perspective, China is developing a dual-track AI governance framework combining administrative regulation with judicial liability. The EU AI Act primarily establishes ex ante obligations through risk classification. The United States still lacks an equivalent comprehensive federal AI statute, and many boundaries continue to develop through copyright, product-liability and consumer-protection litigation and administrative enforcement. In China, administrative authorities address matters such as filings, security assessments, content labelling, platform governance and personal-information protection, while courts apply existing civil, intellectual-property and procedural laws to actual harm and the allocation of liability.</p><p>Overall, the Opinions do not represent a wholesale expansion of liability for AI companies. Fault remains the basic liability framework, and purely digital model services are not categorically brought within strict product liability. The more significant development is that <strong>courts will increasingly focus on whether companies could foresee and control particular risks, what measures they actually took, and whether they can demonstrate that those measures were genuinely implemented.</strong></p><p>At the same time, the most consequential copyright questions remain unresolved. The Opinions do not establish a uniform standard for when AI-generated content qualifies as a copyrighted work, nor do they determine when the use of copyright-protected material to train foundation models requires authorization or may qualify as fair use. These questions will continue to evolve through future legislation, individual cases and industry practice.</p>]]></content:encoded></item><item><title><![CDATA[China Imposes Provisional Anti-Dumping Measures on a Key Specialty Gas Used in Chip Manufacturing Originating from Japan]]></title><description><![CDATA[On September 7, China&#8217;s Ministry of Commerce announced a preliminary determination and decided to impose provisional anti-dumping measures on dichlorosilane originating in Japan from September 8.]]></description><link>https://www.geopolitechs.org/p/china-imposes-provisional-anti-dumping</link><guid isPermaLink="false">https://www.geopolitechs.org/p/china-imposes-provisional-anti-dumping</guid><dc:creator><![CDATA[Geopolitechs]]></dc:creator><pubDate>Mon, 07 Sep 2026 22:31:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!8J8M!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d7fa64f-f939-4402-bc4d-07a15f7b5457_1178x876.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>On September 7, China&#8217;s Ministry of Commerce announced a p<a href="https://www.mofcom.gov.cn/zwgk/zcfb/art/2026/art_01c15948864a45d186abb146fe30a42b.html">reliminary determination</a> and decided to impose provisional anti-dumping measures on dichlorosilane originating in Japan from September 8. The security deposit rates are 99.2% for Shin-Etsu Chemical, 80.8% for DYNASILAN, and 99.2% for all other Japanese companies. For now, importers must pay security deposits to Chinese Customs; the final duty rates will be determined in the final ruling.</p><p>Dichlorosilane, abbreviated as DCS, has the chemical formula SiH&#8322;Cl&#8322; and is a silicon-containing gas used in chip manufacturing. Its main function can be understood as supplying the silicon feedstock needed to form films on wafer surfaces. Under specific reaction conditions, it is used to form epitaxial silicon, silicon nitride, silicon oxide, polysilicon, and other films. These films form part of chip structures or insulating layers, so DCS may be used in logic, memory, and analog chips.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8J8M!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d7fa64f-f939-4402-bc4d-07a15f7b5457_1178x876.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8J8M!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d7fa64f-f939-4402-bc4d-07a15f7b5457_1178x876.png 424w, https://substackcdn.com/image/fetch/$s_!8J8M!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d7fa64f-f939-4402-bc4d-07a15f7b5457_1178x876.png 848w, https://substackcdn.com/image/fetch/$s_!8J8M!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d7fa64f-f939-4402-bc4d-07a15f7b5457_1178x876.png 1272w, https://substackcdn.com/image/fetch/$s_!8J8M!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d7fa64f-f939-4402-bc4d-07a15f7b5457_1178x876.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8J8M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d7fa64f-f939-4402-bc4d-07a15f7b5457_1178x876.png" width="1178" height="876" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2d7fa64f-f939-4402-bc4d-07a15f7b5457_1178x876.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:876,&quot;width&quot;:1178,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:66834,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.geopolitechs.org/i/214646020?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d7fa64f-f939-4402-bc4d-07a15f7b5457_1178x876.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8J8M!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d7fa64f-f939-4402-bc4d-07a15f7b5457_1178x876.png 424w, https://substackcdn.com/image/fetch/$s_!8J8M!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d7fa64f-f939-4402-bc4d-07a15f7b5457_1178x876.png 848w, https://substackcdn.com/image/fetch/$s_!8J8M!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d7fa64f-f939-4402-bc4d-07a15f7b5457_1178x876.png 1272w, https://substackcdn.com/image/fetch/$s_!8J8M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d7fa64f-f939-4402-bc4d-07a15f7b5457_1178x876.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>DCS is an electronic specialty gas and a consumable used in semiconductor manufacturing. The challenge in this industry is not merely synthesizing a compound. Suppliers must also control impurities consistently, maintain batch-to-batch stability, and manage contamination risks associated with cylinders, filling, transportation, and gas delivery. Shin-Etsu&#8217;s own product materials identify high-purity refining, strict quality control, and container delivery management as competitive strengths.</p><p>Japanese suppliers&#8217; advantages therefore stem largely from their long record of stable supply and established customer relationships. A wafer fab must verify that changing materials will not affect film quality or production yield. Even when a domestic product is less expensive, price alone is not enough to justify an immediate switch. This explains why a relatively small materials market can still have high barriers to entry.</p><p>China&#8217;s action first reflects a clear request from a domestic producer. Tangshan Sunfar Electronic Materials Co., Ltd. filed an application on December 8, 2025, and the Ministry of Commerce opened the investigation on January 7, 2026. At initiation, the Ministry cited preliminary evidence showing that imports from Japan increased overall from 2022 to 2024, while prices fell by about 31% cumulatively and the domestic industry suffered injury.</p><p>Two details in the preliminary determination are important: Japanese products were still priced higher than domestic products in China, and their market share was declining. The Ministry&#8217;s main finding concerned price suppression. As Japanese suppliers continued to cut prices, downstream customers used those reductions to press domestic suppliers for further price cuts. Domestic producers increased sales but continued to incur losses.</p><p>Legally, &#8220;dumping&#8221; is not the same as cutting prices or selling below a competitor&#8217;s price. The key test compares the export price with the normal value determined under the applicable rules and then assesses whether the domestic industry has suffered injury. The 99.2% margin also reflects a procedural factor: the Ministry found that Shin-Etsu had not submitted complete documentation on domestic sales, costs, and transactions, so it based part of its determination on information supplied by the applicant. The calculation for DYNASILAN also relied in part on substitute information.</p><p>In industrial terms, I believe the measure will help Chinese producers move beyond the stage in which they can already manufacture DCS but still struggle with customer qualification and profitability. Sunfar&#8217;s first-half 2026 report states that its electronic specialty gases have gradually entered large-scale supply, while also noting that domestically produced DCS remains relatively scarce. Raising the cost of Japanese imports will give wafer fabs a stronger incentive to qualify domestic materials and expand domestic sourcing.</p><p><strong>China&#8217;s Imports of Japanese DCS and Market Indicators</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!a-5O!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08fe3b7c-074a-4b77-bd0a-9e79af6753bb_1800x560.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!a-5O!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08fe3b7c-074a-4b77-bd0a-9e79af6753bb_1800x560.png 424w, https://substackcdn.com/image/fetch/$s_!a-5O!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08fe3b7c-074a-4b77-bd0a-9e79af6753bb_1800x560.png 848w, https://substackcdn.com/image/fetch/$s_!a-5O!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08fe3b7c-074a-4b77-bd0a-9e79af6753bb_1800x560.png 1272w, https://substackcdn.com/image/fetch/$s_!a-5O!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08fe3b7c-074a-4b77-bd0a-9e79af6753bb_1800x560.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!a-5O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08fe3b7c-074a-4b77-bd0a-9e79af6753bb_1800x560.png" width="1456" height="453" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/08fe3b7c-074a-4b77-bd0a-9e79af6753bb_1800x560.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:453,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:103530,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.geopolitechs.org/i/214646020?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08fe3b7c-074a-4b77-bd0a-9e79af6753bb_1800x560.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!a-5O!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08fe3b7c-074a-4b77-bd0a-9e79af6753bb_1800x560.png 424w, https://substackcdn.com/image/fetch/$s_!a-5O!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08fe3b7c-074a-4b77-bd0a-9e79af6753bb_1800x560.png 848w, https://substackcdn.com/image/fetch/$s_!a-5O!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08fe3b7c-074a-4b77-bd0a-9e79af6753bb_1800x560.png 1272w, https://substackcdn.com/image/fetch/$s_!a-5O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08fe3b7c-074a-4b77-bd0a-9e79af6753bb_1800x560.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;">China&#8217;s imports of Japanese DCS and market indicators</p><p>These figures show that Japan remains an important source of supply for the Chinese market. They do not prove that more than 60% of Japanese DCS sales depend on China. The preliminary determination specifically notes that the relevant customs tariff code also covers other products. The quantities and prices in the table are based on third-party industry data provisionally accepted by the investigating authority, so the total trade value under the tariff code should not be treated as DCS trade value.</p><p>I did not find enough public information to calculate the Chinese-market dependence of Japan&#8217;s overall DCS sales. Shin-Etsu disclosed that the Chinese market accounted for about 10% of group revenue from April to June 2026, but that figure covers all products. It cannot be used as a proxy for the share of DCS revenue generated in China, much less for the share of revenue covered by these measures.</p><p>The preliminary data can nevertheless help estimate the order of magnitude. Multiplying 2024 import volume by that year&#8217;s average end-market price gives approximately RMB 65 million. This is only a rough estimate of the corresponding sales value: imports and end-market sales differ because of inventory and timing, and end-market prices include distribution margins. It is therefore neither an accurate measure of Japanese suppliers&#8217; export revenue nor an estimate of expected losses. Even so, the figure indicates that the case directly concerns a relatively small market for a specialized material.</p><p>The most immediate pressure on Japanese suppliers is the trade-off between orders and profit. Importers initially bear the cash burden of the security deposits and may then ask suppliers to cut prices or reduce their purchases. If Japanese companies lower prices to retain customers, their margins will shrink; if they hold prices, they may lose orders. How the burden is ultimately shared among Japanese suppliers, import distributors, and Chinese wafer fabs will depend on contract terms and the availability of alternative supply.</p><p>The more significant concern is the potential loss of customers over the medium to long term. Because electronic materials require customer qualification, once Chinese wafer fabs qualify domestic materials and establish stable procurement relationships, Japanese suppliers may not easily regain share even if they later recover their price competitiveness. They could lose not only current-year sales but also supply opportunities tied to future capacity expansion and new production lines.</p><p>The impact may also extend to customer collaboration. Long-term supply relationships help materials producers understand customers&#8217; requirements for new processes and conduct joint qualification work. If Chinese customers gradually shift to domestic suppliers, Japanese companies will have fewer opportunities to participate in such collaboration. This is a potential long-term competitive loss, but it cannot yet be quantified as a realized financial loss.</p><p>Chinese downstream manufacturers also face costs. For processes where alternative materials have not yet completed qualification, wafer fabs may still need to buy Japanese products and absorb part of the additional burden. Existing domestic production capacity does not mean that every customer and every process can switch immediately. Whether the measures achieve their intended industrial effect will ultimately depend on the stability of domestic products, the pace of qualification, and suppliers&#8217; ability to deliver.</p>]]></content:encoded></item><item><title><![CDATA[An Interview with Zhipu AI Co-founder Tang Jie by Qiushi Magazine]]></title><description><![CDATA[In an interview featured by Qiushi, Zhipu AI co-founder and Chief Scientist Tang Jie discussed the state and future of China&#8217;s large-model industry.]]></description><link>https://www.geopolitechs.org/p/an-interview-with-zhipu-ai-co-founder</link><guid isPermaLink="false">https://www.geopolitechs.org/p/an-interview-with-zhipu-ai-co-founder</guid><dc:creator><![CDATA[Geopolitechs]]></dc:creator><pubDate>Mon, 07 Sep 2026 15:57:35 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Z9nQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55ac655c-f22a-4219-bb2c-f50b563f1c1c_3729x2001.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p style="text-align: justify;">In an <a href="https://www.qstheory.cn/20260903/e1d43f221ac74d89901e33066d47d985/c.html">interview</a> featured by <em>Qiushi</em>, Zhipu AI co-founder and Chief Scientist Tang Jie discussed the state and future of China&#8217;s large-model industry. </p><p style="text-align: justify;">Tang argued that Chinese models are narrowing the gap with global leaders in areas such as question answering and search, while acknowledging that leading international models are moving rapidly into coding and long-horizon tasks. He identified open-source AI as an important source of competitive advantage for Chinese developers, citing Hugging Face&#8217;s use of Zhipu&#8217;s GLM-5.2 as an example of the value of locally deployable, auditable and controllable models, while cautioning that this does not mean GLM is superior to GPT. </p><p style="text-align: justify;">On longer-term AI development, Tang said he believes models surpassing individual human intelligence are inevitable, although whether AI can ultimately exceed the collective intelligence of humanity remains an open question. He also highlighted that insufficient access to high-quality data and China&#8217;s continued weakness in original breakthroughs in fundamental AI theory are major constraints on China&#8217;s AI development.</p><p style="text-align: justify;">Notably, Tang Jie published a commentary titled &#8220;Driving High-Quality Development of the Intelligent Economy with Tokens as the Engine,&#8221; on Qiushi Magazine, one of China&#8217;s most important political outlets.</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;307c1e81-ea4b-4b31-8136-971f382e95e4&quot;,&quot;caption&quot;:&quot;Today, Qiushi published an article titled &#8220;Driving High-Quality Development of the Intelligent Economy with Tokens as the Engine,&#8221; authored by Tang Jie, co-founder of Zhipu AI and professor in the Department of Computer Science and Technology at Tsinghua University.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Zhipu AI Co-Founder Tang Jie: Tokens as the Engine of the Intelligent Economy&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:179984675,&quot;name&quot;:&quot;Geopolitechs&quot;,&quot;bio&quot;:&quot;Former international lawyer, currently an analyst in private sector. explain China&#8217;s tech policy practices in plain language.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3499a9c5-0d81-451a-a8b0-1cdbf4231139_1024x1024.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-08-16T17:58:04.961Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!03Ri!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d2201e-bf4f-4483-ace6-095a52699ad7_1536x1024.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://www.geopolitechs.org/p/zhipu-ai-co-founder-tang-jie-tokens&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:211449225,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:10,&quot;comment_count&quot;:1,&quot;publication_id&quot;:2100547,&quot;publication_name&quot;:&quot;Geopolitechs&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!aVc5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2028e1d9-f1fb-49c7-a3d8-7db2ddc3e7dd_484x484.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Z9nQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55ac655c-f22a-4219-bb2c-f50b563f1c1c_3729x2001.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Z9nQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55ac655c-f22a-4219-bb2c-f50b563f1c1c_3729x2001.png 424w, https://substackcdn.com/image/fetch/$s_!Z9nQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55ac655c-f22a-4219-bb2c-f50b563f1c1c_3729x2001.png 848w, https://substackcdn.com/image/fetch/$s_!Z9nQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55ac655c-f22a-4219-bb2c-f50b563f1c1c_3729x2001.png 1272w, https://substackcdn.com/image/fetch/$s_!Z9nQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55ac655c-f22a-4219-bb2c-f50b563f1c1c_3729x2001.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Z9nQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55ac655c-f22a-4219-bb2c-f50b563f1c1c_3729x2001.png" width="1456" height="781" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/55ac655c-f22a-4219-bb2c-f50b563f1c1c_3729x2001.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:781,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Z9nQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55ac655c-f22a-4219-bb2c-f50b563f1c1c_3729x2001.png 424w, https://substackcdn.com/image/fetch/$s_!Z9nQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55ac655c-f22a-4219-bb2c-f50b563f1c1c_3729x2001.png 848w, https://substackcdn.com/image/fetch/$s_!Z9nQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55ac655c-f22a-4219-bb2c-f50b563f1c1c_3729x2001.png 1272w, https://substackcdn.com/image/fetch/$s_!Z9nQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55ac655c-f22a-4219-bb2c-f50b563f1c1c_3729x2001.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: justify;"><strong>Host(Qiu Shi)</strong></p><p style="text-align: justify;">From Doubao and DeepSeek to Zhipu Qingyan, how far are these hugely popular Chinese AI applications from the world&#8217;s leading technologies?</p><p style="text-align: justify;"><strong>Tang Jie</strong></p><p style="text-align: justify;">The gap between Chinese models and the world&#8217;s leading models is narrowing.</p><p style="text-align: justify;"><strong>Host</strong></p><p style="text-align: justify;">Will artificial intelligence surpass human intelligence?</p><p style="text-align: justify;"><strong>Tang Jie</strong></p><p style="text-align: justify;">I think it is perfectly normal for a model to surpass the intelligence of an individual human being.</p><p style="text-align: justify;"><strong>Host</strong></p><p style="text-align: justify;">Should AI education also start from an early age?</p><p style="text-align: justify;"><strong>Tang Jie</strong></p><p style="text-align: justify;">Once a new tool arrives, we have to learn to use it. That is why I encourage my students&#8212;and even my own children&#8212;to use large models.</p><p style="text-align: justify;"><strong>Host</strong></p><p style="text-align: justify;">In this episode of <em>Shidian Interview</em>, Tang Jie, Professor in the Department of Computer Science and Technology at Tsinghua University, continues to share his insights into the present and future of China&#8217;s homegrown large models.</p><p style="text-align: justify;"><strong>Host</strong></p><p style="text-align: justify;">Professor Tang, welcome to <em>Shidian Interview</em>. Today, generative AI applications such as Doubao, DeepSeek, Yuanbao, Kimi, Zhipu Qingyan and Tongyi Qianwen are rapidly becoming mainstream. Behind these consumer AI products are large models developed in China. How do you assess the current development of China&#8217;s homegrown large models?</p><p style="text-align: justify;"><strong>Tang Jie</strong></p><p style="text-align: justify;">The products you just mentioned&#8212;including Kimi, Doubao, Zhipu Qingyan and DeepSeek&#8212;are all very good products, and essentially all of them are powered by large models developed in China.</p><p style="text-align: justify;">On November 30, 2022, ChatGPT was launched by OpenAI and quickly took the world by storm. Then, in 2023, ERNIE Bot and Zhipu Qingyan were released in China, followed soon afterward by Doubao and other products. There were roughly eight companies among the earliest group of players in China. Today, I would say that large models have become widely used by consumers for question answering, search and other related applications.</p><p style="text-align: justify;">In question-answering and search-related applications, the gap between Chinese models and the world&#8217;s leading models is narrowing. That is the first basic reality.</p><p style="text-align: justify;">At the same time, however, we can see that the world&#8217;s leading large models are beginning to shift into new areas&#8212;for example, programming and long-horizon tasks. As large models begin to program and carry out these long-horizon tasks, we need to transfer our workplace experience and expertise to them. In this way, large models gradually acquire the ability to perform work across different industries and scenarios.</p><p style="text-align: justify;">These capabilities are being added step by step. Some leading international and Chinese developers started working on them relatively early, so they do have certain advantages today.</p><p style="text-align: justify;">The third point brings us back to open source and openness. Only through open source and openness can our models establish their own advantages&#8212;not only in model R&amp;D, but also in expanding their global reach and enabling the broader deployment of AI workflows.</p><p style="text-align: justify;"><strong>Host</strong></p><p style="text-align: justify;">Not long ago, Hugging Face, the U.S.-based open-source AI community, was affected by an intrusion involving an OpenAI model. Hugging Face initially tried to call leading proprietary U.S. models to help identify and fix the vulnerability, but those attempts were blocked. It then turned to GLM-5.2, a large model developed by China&#8217;s Zhipu AI, and reportedly resolved the problem within several hours.</p><p style="text-align: justify;">As the founder of Zhipu AI and now its Chief Scientist, how do you view this incident? Does it suggest that China&#8217;s open-source large models have greater advantages and stronger development prospects than proprietary U.S. models?</p><p style="text-align: justify;"><strong>Tang Jie</strong></p><p style="text-align: justify;">We have also been following this incident very closely. Let me first walk through what happened from beginning to end.</p><p style="text-align: justify;">During the week of July 13, Hugging Face&#8212;the world&#8217;s largest open-source AI community&#8212;was hit by an intrusion involving a large model.</p><p style="text-align: justify;">What caused it? OpenAI was conducting an experiment in a closed environment, using a large model to attack software. But the model unexpectedly escaped that closed environment and ended up attacking Hugging Face over the internet.</p><p style="text-align: justify;">Hugging Face then tried to use some of the most advanced proprietary models available. Initially, it turned to closed models such as those from OpenAI and Claude. But OpenAI&#8217;s and Claude&#8217;s models have extensive safeguards and guardrails, which meant Hugging Face could not actually use them for what it needed to do.</p><p style="text-align: justify;">So what did Hugging Face do? It installed our GLM-5.2 locally. After installation, it created an internally isolated environment and reproduced the entire attack process within that environment. By tracing the attack, it was ultimately able to identify the cause.</p><p style="text-align: justify;">There are several lessons we can draw from this.</p><p style="text-align: justify;">First is the importance of open source. Without an open-source model, Hugging Face would not have been able to construct that environment, reproduce the incident or identify the cause of the attack.</p><p style="text-align: justify;">Second, both offensive security capabilities and safety guardrails are extremely important. A model needs to have the ability to conduct security testing, but it also needs defensive capabilities.</p><p style="text-align: justify;">Does this mean that open-source models necessarily have an advantage over proprietary models? I think it is still too early to draw that conclusion. After all, in this particular incident, the attack itself was initiated by OpenAI&#8217;s model.</p><p style="text-align: justify;">Why did Hugging Face use our GLM-5.2? Because it could not use the proprietary models for this purpose, so it had to use our open-source model.</p><p style="text-align: justify;">We cannot say that GLM-5.2 is therefore better than GPT. What we can say is that, through its open-source approach, GLM-5.2 has successfully occupied this particular ecological niche.</p><p style="text-align: justify;">That is the first point. The second point worth reflecting on is the value of controllability. The large models of the future need to be models whose operation is visible and understandable, that users can actually deploy, and that are auditable and controllable. Those are the kinds of models that people will truly be willing and able to use in real-world applications.</p><p style="text-align: justify;"><strong>Host</strong></p><p style="text-align: justify;">You have mentioned that you encourage many of your students to use large models. Even primary and secondary school students may increasingly use them in the future. Could this lead to weaker foundations in basic knowledge, or even the deterioration of certain fundamental skills?</p><p style="text-align: justify;"><strong>Tang Jie</strong></p><p style="text-align: justify;">Yes. This is a question I am asked very often.</p><p style="text-align: justify;">I remember that many years ago, when large models were first beginning to take off, I was talking with several friends. I told them that large models would develop extremely rapidly in the future, that knowledge would become much more widely accessible, and that these technologies would become part of our everyday lives.</p><p style="text-align: justify;">Many of my friends then asked me: what should our children do in the future? What should they learn?</p><p style="text-align: justify;">I think we need to answer that question from two perspectives.</p><p style="text-align: justify;">The first is that technology has already developed to this point, so simply refusing to use it is not really an option.</p><p style="text-align: justify;">Think about when the steam engine emerged. Before that, people knew how to ride horses. So should we still need to master horse-riding skills today?</p><p style="text-align: justify;">As you can see, many people today no longer know how to ride a horse. And even when I ride a horse, I do not do it because I want to travel faster or because I need a horse for transportation. Horse riding has become more of a recreational activity.</p><p style="text-align: justify;">So the first point is that a new era has arrived. Once these new tools emerge, we have to use them. That is why I encourage my students&#8212;and even my own children&#8212;to use large models.</p><p style="text-align: justify;">There is, of course, another side to the question. What happens if people no longer have a solid grasp of basic knowledge, or eventually lose certain fundamental skills altogether?</p><p style="text-align: justify;">That is another dimension of the issue.</p><p style="text-align: justify;">Personally, I think our technology stack may indeed change in the future. We may no longer need to master some of the basic knowledge points that people were previously expected to learn.</p><p style="text-align: justify;">But there is another dimension as well: large models allow us to expand the scope of our knowledge.</p><p style="text-align: justify;">Why do I say that?</p><p style="text-align: justify;">In the past, if you relied primarily on reading books, perhaps you could study 1,000 individual pieces of knowledge. Being able to absorb and make notes on 1,000 such points would already be quite an achievement.</p><p style="text-align: justify;">With large models, however, you might develop a deep understanding of 100 core knowledge points while gaining some exposure to another 10,000. In that sense, the overall space of knowledge available to you becomes much larger.</p><p style="text-align: justify;"><strong>Host</strong></p><p style="text-align: justify;">There is a book called <em>The Singularity Is Near</em> by Ray Kurzweil. He later wrote another book, <em>The Singularity Is Nearer</em>. These books discuss the possibility that by 2045, artificial intelligence could surpass the intelligence of the human brain.</p><p style="text-align: justify;">How do you view the direction in which AI is developing? Will machines replace humans? Could machine intelligence ultimately surpass human intelligence&#8212;or even come to dominate humanity? Is that a real possibility?</p><p style="text-align: justify;"><strong>Tang Jie</strong></p><p style="text-align: justify;">Personally, I think artificial general intelligence represents, in a sense, the aggregate intelligence of people around the world.</p><p style="text-align: justify;">From that perspective, I think it is perfectly normal for a single model to surpass the intelligence of a single human being.</p><p style="text-align: justify;">A model brings together knowledge from across the world. We have also given these models our reasoning processes and ways of thinking. More recently, we have begun giving them behavioral data as well, including data about the workflows through which we perform our jobs.</p><p style="text-align: justify;">Think about what that means. Such a model can work, it possesses knowledge, it can have strong emotional intelligence, and it can reason logically. In that sense, it brings together the intellectual capabilities of people from around the world.</p><p style="text-align: justify;">Could there come a day when large models surpass humanity as a whole and generate theories and ideas that none of us have ever conceived of? That remains an open question.</p><p style="text-align: justify;">This is also an extremely hot topic right now in Silicon Valley, Europe and China. We call it ASI&#8212;Artificial Superintelligence. The question is whether AI could eventually develop superintelligence that surpasses human intelligence.</p><p style="text-align: justify;">There is another concept that has also become very popular recently: recursive superintelligence. The question here is whether a large model can correct and improve itself, continuously making itself more capable.</p><p style="text-align: justify;">If a model can continuously improve and repair itself, then surpassing humanity could eventually become a realistic prospect.</p><p style="text-align: justify;">It is possible that this development curve will eventually reach a critical point and plateau. It is also possible that it will rise until it reaches the aggregate intelligence of humanity as a whole.</p><p style="text-align: justify;">So whether large models will ultimately surpass the combined intelligence of all humanity remains an open question. But I believe surpassing the intellectual capabilities of an individual human being is inevitable.</p><p style="text-align: justify;"><strong>Host</strong></p><p style="text-align: justify;">China&#8217;s large-model industry has developed rapidly. In your view, what problems and challenges does China still face in developing large models, and how can these challenges be overcome?</p><p style="text-align: justify;"><strong>Tang Jie</strong></p><p style="text-align: justify;">I would highlight four challenges.</p><p style="text-align: justify;">The first is computing power. We still face major constraints in this area. U.S. restrictions on China&#8217;s access to high-end chips have resulted in genuine shortages of advanced chips in China.</p><p style="text-align: justify;">The second is data. You can never have too much data, and there is never really enough of it.</p><p style="text-align: justify;">For various reasons, many industries cannot share their data or make it available for model training. Yet as large models expand their knowledge structures and their ability to perform different tasks, they need precisely this kind of real-world contextual data. This creates a fundamental tension.</p><p style="text-align: justify;">At the same time, the shortage of data has created new industries. There are now many companies specializing in data annotation, data generation and data cleaning. These activities have also created significant employment opportunities.</p><p style="text-align: justify;">So data represents the second major challenge, but also the second major area of opportunity.</p><p style="text-align: justify;">The third issue brings us back to originality and fundamental innovation.</p><p style="text-align: justify;">China still has room for improvement when it comes to original theoretical breakthroughs. The Transformer architecture that underpins modern large models, for example, was not originally proposed by Chinese researchers. Nor did reinforcement learning and reasoning techniques originate in China.</p><p style="text-align: justify;">So we still need to strengthen our capacity for original innovation in fundamental theory.</p><p style="text-align: justify;">This was also one of the motivations behind our team&#8217;s commercialization of research from Tsinghua University and the establishment of Zhipu AI. We hoped to combine academia and industry&#8212;to pursue fundamental innovation in technological theory while also expanding those technologies into a much broader range of practical applications.</p><p style="text-align: justify;">And, of course, we hope that in the future we can make our own contributions to original innovation in fundamental AI theory.</p><p style="text-align: justify;"><strong>Host</strong></p><p style="text-align: justify;">Thank you, Professor Tang. We greatly appreciate your insights and explanations.</p>]]></content:encoded></item><item><title><![CDATA[Is Model Distillation Legal? A Chinese Scholar’s Perspective]]></title><description><![CDATA[Model distillation, and particularly its legal implications, has recently become a subject of growing interest among scholars in both China and the United States.]]></description><link>https://www.geopolitechs.org/p/is-model-distillation-legal-a-chinese</link><guid isPermaLink="false">https://www.geopolitechs.org/p/is-model-distillation-legal-a-chinese</guid><dc:creator><![CDATA[Geopolitechs]]></dc:creator><pubDate>Fri, 04 Sep 2026 14:14:26 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Lt7V!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe80e52b6-aa93-4838-ba57-2239c8fcd4df_497x309.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p style="text-align: justify;">Model distillation, and particularly its legal implications, has recently become a subject of growing interest among scholars in both China and the United States. Today, I would like to introduce a recent paper by a Chinese legal scholar that explores this issue.</p><p style="text-align: justify;">The paper is by Li Xinmeng, a doctoral candidate at the Law School of Renmin University of China. It is published in Issue No. 4, 2026, of Legal Science, which examines whether black-box knowledge distillation can qualify as lawful reverse engineering under trade secret law. </p><p style="text-align: justify;">According to Li,technical information inside a model may constitute a trade secret, and knowledge distillation satisfies the constituent elements of reverse engineering in trade secret law. Where the principles of fairness and reasonableness are not violated, restrictive clauses in user service agreements&#8212;such as &#8220;no distillation&#8221;&#8212;may be valid as a matter of contract law; however, breach of such clauses should not give rise to trade secret misappropriation liability. Knowledge distillation as reverse engineering has an economic justification, but it should be confined to legitimate purposes, reasonable conduct, and the absence of market harm. Li also argues that clarifying the reverse-engineering characterisation of knowledge distillation and delineating its legitimacy boundaries helps achieve a dynamic balance between trade secret protection in the artificial intelligence industry and technological innovation.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Lt7V!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe80e52b6-aa93-4838-ba57-2239c8fcd4df_497x309.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Lt7V!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe80e52b6-aa93-4838-ba57-2239c8fcd4df_497x309.png 424w, https://substackcdn.com/image/fetch/$s_!Lt7V!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe80e52b6-aa93-4838-ba57-2239c8fcd4df_497x309.png 848w, https://substackcdn.com/image/fetch/$s_!Lt7V!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe80e52b6-aa93-4838-ba57-2239c8fcd4df_497x309.png 1272w, https://substackcdn.com/image/fetch/$s_!Lt7V!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe80e52b6-aa93-4838-ba57-2239c8fcd4df_497x309.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Lt7V!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe80e52b6-aa93-4838-ba57-2239c8fcd4df_497x309.png" width="497" height="309" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e80e52b6-aa93-4838-ba57-2239c8fcd4df_497x309.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:309,&quot;width&quot;:497,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:14043,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.geopolitechs.org/i/214163095?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe80e52b6-aa93-4838-ba57-2239c8fcd4df_497x309.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Lt7V!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe80e52b6-aa93-4838-ba57-2239c8fcd4df_497x309.png 424w, https://substackcdn.com/image/fetch/$s_!Lt7V!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe80e52b6-aa93-4838-ba57-2239c8fcd4df_497x309.png 848w, https://substackcdn.com/image/fetch/$s_!Lt7V!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe80e52b6-aa93-4838-ba57-2239c8fcd4df_497x309.png 1272w, https://substackcdn.com/image/fetch/$s_!Lt7V!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe80e52b6-aa93-4838-ba57-2239c8fcd4df_497x309.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Below is the full translation of the <a href="https://mp.weixin.qq.com/s/Yk2RC99qI0N-Oz1mCv07vg">paper</a>:</p><h2>Introduction</h2><p style="text-align: justify;">In 2025, the *Opinions of the State Council on Deepening the Implementation of the &#8220;AI+&#8221; Action* expressly proposed, under the section on &#8220;strengthening foundational supporting capabilities,&#8221; that China should &#8220;enhance foundational model capabilities and accelerate research into more efficient model training and inference methods.&#8221; As a key technology for improving training efficiency, knowledge distillation can transfer the knowledge embedded in a highly complex model (hereinafter, the &#8220;teacher model&#8221;) to a lightweight model (hereinafter, the &#8220;student model&#8221;). After obtaining the transferred data, the student model can reduce computational resource demands while achieving inference effectiveness close to that of the teacher model.</p><p style="text-align: justify;">Although knowledge distillation shows substantial potential for improving model efficiency, it has generated extensive controversy in trade secret protection because it involves obtaining technical information inside a model. In February 2025, in *OpenEvidence Inc. v. Pathway Medical, Inc.*, the plaintiff alleged that the defendant used &#8220;prompt-injection attacks&#8221; to extract pre-configured system prompts embedded in the plaintiff&#8217;s model (i.e., the model&#8217;s operating logic and instructions), and then used those system prompts to train the defendant&#8217;s AI model&#8212;thereby constituting unlawful acquisition of trade secrets, violations of the Computer Fraud and Abuse Act (CFAA) and the Digital Millennium Copyright Act (DMCA), as well as breach of contract. In April of the same year, a U.S. special committee released an investigative report asserting that DeepSeek (&#28145;&#24230;&#27714;&#32034;) was highly likely to have used knowledge distillation to systematically extract and reproduce the core capabilities of leading U.S. models; the report further suggested that such distillation likely violated OpenAI&#8217;s usage terms prohibiting the use of its services to &#8220;develop competing models.&#8221; Against this background, the legality of knowledge distillation has become a focal issue of global concern.</p><p style="text-align: justify;">Although existing scholarship has extensively discussed the legal nature of knowledge distillation, it has largely focused on copyright and patent perspectives. Relatively few studies examine reverse engineering under the trade secret framework or analyze the legal effectiveness of restrictive contractual clauses such as &#8220;no distillation.&#8221; Discussing the legal nature of knowledge distillation requires answering several questions: Can knowledge distillation be characterized as reverse engineering, which operates as an exception to trade secret misappropriation? Can restrictive clauses in user agreements, such as &#8220;no distillation,&#8221; exclude such a legality characterization? Where do the legitimacy and boundaries of knowledge distillation as reverse engineering lie? Clarifying these issues not only delineates clearer behavioral boundaries for AI companies and users, but also helps strike an appropriate balance between protecting R&amp;D incentives and promoting technological innovation.</p><p style="text-align: justify;">Knowledge distillation can be divided into &#8220;white-box distillation,&#8221; conducted on the basis of known technical information such as model weight parameters, and &#8220;black-box distillation,&#8221; which infers internal technical information by reverse reasoning from model outputs. The legal controversy is more acute for the latter. Accordingly, this article focuses on &#8220;black-box distillation&#8221;: it examines whether the technical information inside a model satisfies the protection requirements for trade secrets; analyzes whether knowledge distillation meets the constituent elements of reverse engineering and the legal effectiveness of restrictive contractual clauses such as &#8220;no distillation&#8221;; and, through an economic-analytical framework, explores the legitimacy of knowledge distillation as reverse engineering and its boundaries, thereby laying a theoretical foundation for the lawful conduct of knowledge distillation.</p><h2>I. Determining Whether Technical Information Inside a Model Constitutes a Trade Secret</h2><p style="text-align: justify;">Compared with copyright and patent protection, the trade secret pathway is more flexible in protecting abstract knowledge representations. In the &#8220;first case nationwide on protecting AI model structure and parameters,&#8221; the Beijing Intellectual Property Court stated that &#8220;a model&#8217;s structure and parameters constitute competitive interests protected by the Anti-Unfair Competition Law.&#8221; Determining a trade secret requires satisfying three elements: secrecy, value, and confidentiality measures. The value of a trade secret mainly derives from the competitive advantage produced by information not being generally known.</p><p style="text-align: justify;">Developing AI models requires substantial computing investment and massive data resources. Accordingly, technical information inside a model typically confers significant competitive advantages, enabling the attraction of users and expansion of market influence. While academia generally recognizes that technical information inside a model has commercial value, significant disputes remain as to secrecy and confidentiality measures: (1) whether an AI model loses secrecy regarding its internal technical information by publicly offering services in the market, and how open-source disclosure of weight parameters affects this element; and (2) whether clauses such as &#8220;no distillation&#8221; in user service agreements constitute confidentiality measures in a legal sense. It is therefore necessary to focus on the secrecy and confidentiality-measures elements to analyze whether the internal technical information implicated by knowledge distillation satisfies the constituent elements of a trade secret.</p><h3>(1) Secrecy</h3><p style="text-align: justify;">The Provisions of the Supreme People&#8217;s Court on Several Issues Concerning the Application of Law in the Trial of Civil Cases Involving Infringement of Trade Secrets* (hereinafter, the *Provisions on Application of Law in Trade Secret Cases*) draw on the Agreement on Trade-Related Aspects of Intellectual Property Rights (TRIPS) and interpret the secrecy element as &#8220;not generally known to and not readily obtainable by relevant persons in the field.&#8221; The *Provisions on Trade Secret Protection*, issued by the State Administration for Market Regulation in February 2026, describe the secrecy element as &#8220;not known to the public.&#8221; The U.S. Supreme Court has held that so long as information does not lose its secrecy, trade secret protection may still be available even if related products enter sales or licensing channels. Conversely, where relevant information can be easily obtained through public channels, it is generally found to lack secrecy.</p><p style="text-align: justify;">Although Chinese laws and regulations do not separately define &#8220;not known to the public,&#8221; Article 4 of the *Provisions on Application of Law in Trade Secret Cases* and Article 6 of the *Provisions on Trade Secret Protection* both enumerate specific circumstances in which information is &#8220;known to the public.&#8221; In addition to &#8220;not generally known,&#8221; the secrecy element requires that the information is &#8220;not readily obtainable.&#8221; This requirement reflects the difficulty of obtaining the alleged trade secret: the cost incurred by a defendant in obtaining the plaintiff&#8217;s information often determines whether the information meets the &#8220;not readily obtainable&#8221; requirement and thus the secrecy element. Expanding trade secret protection to business information that can be obtained at low cost by unspecified persons would impede the public&#8217;s freedom of action in the public domain and increase transaction costs.</p><h4>1. Secrecy of technical information inside a model</h4><p style="text-align: justify;">Article 5(2) of the *Provisions on Trade Secret Protection* provides that &#8220;information such as data, algorithms, computer programs, and code related to technology constitutes the technical information referred to in the preceding paragraph.&#8221; Technical information inside an AI model includes weight parameters, model architecture, and operating logic. Because AI models deployed in the market typically provide only a user interaction interface rather than exposing internal operating mechanisms, the logical patterns behind model outputs are often non-public and thus possess the feature of &#8220;not known to the public.&#8221; Accordingly, the key to secrecy lies in whether the information is &#8220;not readily obtainable.&#8221;</p><p style="text-align: justify;">Such &#8220;not readily obtainable&#8221; should be assessed by reference to the substitute cost for the public to obtain the information through legitimate channels, rather than by reference to the right holder&#8217;s own R&amp;D or collection costs. If a party can obtain such information through routine technical means within a short period, it should be considered &#8220;readily obtainable.&#8221; Conversely, if the information can be obtained only through costly reverse engineering or long-term independent R&amp;D, it should be deemed to satisfy the &#8220;not readily obtainable&#8221; requirement.</p><p style="text-align: justify;">For AI products or services already deployed in the market, while model outputs&#8212;as external carriers of information&#8212;are publicly observable, in &#8220;black-box distillation&#8221; it remains difficult to obtain internal technical information from those outputs. In ordinary user interactions, users can access only semantic-level output content, but cannot directly obtain the embedded internal technical information. Even if one uses knowledge distillation to reverse-analyze massive volumes of model outputs, substantial computing resources and time costs are required to obtain internal technical information. Therefore, technical information inside a model is information that is &#8220;not readily obtainable.&#8221;</p><p style="text-align: justify;">Moreover, the data aggregation effect further demonstrates that internal technical information is &#8220;not readily obtainable.&#8221; Fragmented user interactions do not reveal the model&#8217;s operating logic; only by analyzing statistical correlations and probabilistic characteristics across massive data can one infer such internal technical information. Similarly, in software industry practice, although software products are distributed to the public, technical information such as source code underlying software&#8212;where not disclosed to the public&#8212;still possesses secrecy. Accordingly, the internal technical information of AI models can be regarded as satisfying the secrecy element.</p><h4>2. The impact of model openness on secrecy</h4><p style="text-align: justify;">Whether internal technical information is externally disclosed also affects secrecy. For closed-source models, developers typically keep key technical information such as algorithms, model architecture, and underlying source code strictly confidential in order to prevent competitors from obtaining internal technical information and developing competing products, thereby preserving secrecy. By contrast, open-source models are premised on knowledge sharing and collaborative innovation. Depending on the content and degree of openness, open-source models form an &#8220;openness spectrum,&#8221; disclosing to varying extents training code, training data, model architecture, model parameters, inference code, and evaluation cases. Different open-source models also impose restrictions on subsequent uses of derivative models through license agreements or commercial restrictive clauses.</p><p style="text-align: justify;">For open-source models that have disclosed technical information such as weight parameters and training code, the information can be directly accessed by the public and will typically fail to satisfy the secrecy element&#8217;s requirements of &#8220;not known to the public&#8221; and &#8220;not readily obtainable.&#8221; However, this does not mean that internal technical information in open-source models necessarily fails to satisfy secrecy. Undisclosed internal technical information in open-source models (e.g., training methods) often remains secret, and the substitute cost for the public to obtain it is relatively high.</p><p style="text-align: justify;">For example, to obtain undisclosed original training data for an open-source model, practice often uses &#8220;data-free distillation&#8221; methods that reverse-reconstruct the feature distribution of the original training data based on the open-source model&#8217;s weight parameters, synthesizing data extremely close to the original. Such methods rely on complex algorithms and substantial computing investment. The resulting information about the feature distribution of training data is &#8220;not known to the public&#8221; and &#8220;not readily obtainable,&#8221; and thus possesses secrecy. Accordingly, regardless of whether the model as a whole is open-source, so long as a particular technical information item has not been disclosed and the public faces high costs to obtain it through substitute means, that information can be regarded as secret.</p><h3>(2) Confidentiality measures</h3><p style="text-align: justify;">A trade secret is not the object of an exclusive right. It is difficult to notify the public of right boundaries through property-right publicity mechanisms; accordingly, the right holder must take reasonable confidentiality measures to prevent the public from inadvertently accessing the trade secret. Article 9(1) of the *Provisions on Trade Secret Protection* requires the right holder, prior to the occurrence of the infringing act, to adopt &#8220;reasonable confidentiality measures commensurate with factors such as the nature of the trade secret and its carrier, and the commercial value of the trade secret.&#8221; The normative purpose is to facilitate limited sharing of trade secrets. The determination of confidentiality measures follows a reasonableness standard: &#8220;reasonable&#8221; means that the measures objectively notify the public of the right boundary and function to prevent others from easily obtaining the trade secret under the right holder&#8217;s control.</p><p style="text-align: justify;">Confidentiality measures can be divided into &#8220;internal&#8221; and &#8220;external&#8221; measures. AI companies typically adopt both types of measures with respect to internal technical information of models in order to maintain secrecy.</p><p style="text-align: justify;">&#8220;External&#8221; confidentiality measures refer to physical or technical control measures through which the right holder restricts others&#8217; access to trade secrets. For internal technical information, closed-source models adopt confidentiality measures such as application programming interface (API) access restrictions, output filtering, and call-frequency controls. Security mechanisms configured within the model can review content before output generation, filter out internal technical information, and prevent disclosure. At the same time, the model&#8217;s computation process involves multi-layer algorithmic processing and information transformation, making it difficult for others to restore internal technical details from outputs at low cost. In practice, conducting knowledge distillation requires substantial computing resources to obtain massive model outputs and thereby infer internal technical information. In addition, because internal technical information is strongly interdependent, even partial access to weight parameters is insufficient to reproduce model functionality at an equivalent level. Therefore, based on the technical measures configured in the model, the right holder has adopted reasonable confidentiality measures with respect to internal technical information, effectively maintaining secrecy.</p><p style="text-align: justify;">&#8220;Internal&#8221; confidentiality measures refer to circumstances in which the right holder allows the counterparty to access or control trade secrets by agreeing on confidentiality obligations and reasonably indicating the scope of confidential information. Where enterprises sign confidentiality agreements with employees or third parties, such agreements may still be regarded as confidentiality measures even if there is a theoretical risk of leakage. In the software industry, end-user license agreements (EULAs) are important confidentiality tools: they not only evidence the right holder&#8217;s subjective intent to maintain secrecy, but also enhance trade secret protection by clarifying the user&#8217;s confidentiality obligations.</p><p style="text-align: justify;">In cases involving software products, U.S. courts have recognized that contractual clauses can serve as proof of reasonable confidentiality measures. Where a software product adopts access restrictions such as password protection while also requiring the user to promise by contract not to disclose, use, or share trade secrets, courts may find that the enterprise satisfies the requirement of reasonable confidentiality measures; the effectiveness of such contractual clauses as confidentiality measures may even extend to information that is readily knowable, such as basic design and functionality. Analogously, AI companies also set user service agreements for their products or services. Depending on the user group, such agreements can generally be divided into two categories: (i) Terms of Use for ordinary individual users, which are typically click-through standard-form contracts and generally do not impose confidentiality obligations on users; and (ii) enterprise license agreements (Enterprise Licenses) for commercial users, which are typically signed after full negotiation between parties of relatively equal bargaining power and contain express confidentiality clauses, thereby imposing corresponding confidentiality obligations on commercial users.</p><p style="text-align: justify;">Accordingly, confidentiality measures should be assessed differently depending on the user group. For commercial users, the express confidentiality clauses in their license agreements can constitute effective confidentiality measures for internal model information. For individual users, even where the service agreement lacks an express confidentiality obligation, the right holder may still effectively control internal technical information through technical measures such as closed-source configurations, access restrictions, and output filtering. The legal nature and scope of effectiveness of restrictive clauses such as &#8220;no distillation&#8221; in individual user service agreements will be further analyzed below.</p><h2>II. Determining the Legal Characterization of Knowledge Distillation as Reverse Engineering</h2><p style="text-align: justify;">The legal logic of trade secret protection is to maintain the relative competitive advantage that the right holder has established through confidentiality measures, rather than to achieve absolute exclusive control over trade secret information. Therefore, the law prohibits only improper acquisition of trade secrets and does not restrict acquisition through legitimate means such as reverse engineering or independent R&amp;D.</p><p style="text-align: justify;">Accordingly, it is necessary to clarify the meaning and implementation process of knowledge distillation and, on that basis, to focus on &#8220;black-box distillation&#8221; to analyze whether it satisfies the constituent elements of reverse engineering and to examine the effectiveness of restrictive clauses such as &#8220;no distillation&#8221; in user agreements.</p><h3>(1) The meaning and implementation process of knowledge distillation</h3><p style="text-align: justify;">To determine whether knowledge distillation constitutes &#8220;improper acquisition&#8221; of trade secrets, it is necessary to clarify its meaning and implementation process. As a model compression technique, knowledge distillation involves three core elements: the &#8220;knowledge&#8221; embedded in the teacher model as the source of knowledge; the distillation algorithm that transfers knowledge; and the &#8220;teacher&#8211;student architecture&#8221; consisting of the teacher model and the student model.</p><p style="text-align: justify;">The core logic of knowledge distillation is to achieve knowledge transfer through the teacher&#8211;student architecture, enabling the student model to learn the teacher model&#8217;s decision logic more effectively, so that the student model can approach the teacher model&#8217;s performance even when its parameter scale is significantly compressed.</p><p style="text-align: justify;">The &#8220;knowledge&#8221; that is the object of distillation refers to technical information embedded inside the teacher model that users cannot directly obtain through ordinary interaction, including information such as the probability distribution at the output layer, feature representations at intermediate layers, the model&#8217;s decision logic, and correlation structures across layers. More specifically, such knowledge can be divided into three categories.</p><p style="text-align: justify;">First, response-based knowledge: the probability distribution (soft labels) over categories at the teacher model&#8217;s output layer. Unlike hard labels that indicate only the correct answer, soft labels include not only the teacher model&#8217;s probability judgment for the correct class but also information about relative similarities among all classes, enabling the student model to learn the teacher model&#8217;s decision logic more effectively.</p><p style="text-align: justify;">Second, feature-based knowledge: feature representations at the teacher model&#8217;s intermediate layers, reflecting the model&#8217;s internal processing logic and abstract representation capability.</p><p style="text-align: justify;">Third, relation-based knowledge: correlation structure information among outputs across different layers of the model.</p><p style="text-align: justify;">These three categories collectively constitute the core object obtained through knowledge distillation.</p><p style="text-align: justify;">Traditional knowledge distillation often depends on direct access to the teacher model&#8217;s weight parameters, training data, and the output-layer probability distribution (soft labels). However, in practical application, closed-source models often provide only APIs: external parties cannot obtain weight parameters, cannot access original training data, and APIs often return only final class results (hard labels) rather than the full probability distribution.</p><p style="text-align: justify;">As a result, &#8220;black-box distillation,&#8221; which can be conducted without access to internal parameters and solely through outputs, has increasingly emerged. Where there is no training data, no access to weight parameters, or even only hard-label outputs are available, the student model can still gradually learn the teacher model&#8217;s decision logic by inputting prompts to the teacher model and analyzing its output characteristics. Through a &#8220;question&#8211;answer&#8221; interactive mode, the student model reconstructs a knowledge set and thereby achieves inter-model knowledge transfer. This process not only requires substantial computing resources but also relies on the data aggregation effect.</p><h3>(2) Knowledge distillation satisfies the constituent elements of reverse engineering</h3><p style="text-align: justify;">Reverse engineering operates as an exemption from trade secret misappropriation liability. Article 14(1) of the *Provisions on Application of Law in Trade Secret Cases* provides that acquiring the alleged infringing information through independent R&amp;D or reverse engineering does not constitute trade secret infringement. Article 15 of the *Provisions on Trade Secret Protection* further clarifies that obtaining relevant technical information by disassembling, surveying, or analyzing products obtained through public channels does not constitute trade secret infringement. The Uniform Trade Secrets Act (UTSA) in the United States and the U.S. Supreme Court&#8217;s decision in *Kewanee Oil Co. v. Bicron Corp.* establish analogous reverse engineering rules.</p><p style="text-align: justify;">The UTSA emphasizes that obtaining a product through the public market in a &#8220;fair and honest manner&#8221; and dismantling it to understand its manufacturing process does not constitute trade secret misappropriation. The EU Trade Secrets Directive likewise notes that observing, studying, disassembling, or testing a product that is available to the public or lawfully possessed by the acquirer constitutes a lawful means of acquiring trade secrets.</p><p style="text-align: justify;">Synthesizing these rules, reverse engineering generally requires: lawful acquisition of the product; legitimate implementation methods; and the absence of breach of confidentiality obligations. It is therefore necessary to analyze, element by element, whether knowledge distillation satisfies these requirements.</p><p style="text-align: justify;">First, reverse engineering can be applied to products or services based on AI models. The aim of knowledge distillation is to obtain internal technical information of a model, and such information is carried by AI products or services. Although reverse engineering traditionally applied to &#8220;products obtained through public channels,&#8221; this historical focus reflects the industrial-era reality that trade secrets were typically embedded in tangible goods, requiring physical disassembly to obtain know-how. With technological development, the distinction between products and services has increasingly blurred in the digital era. What is &#8220;provided on the market&#8221; is not limited to tangible products, but also includes non-tangible products or services such as software and AI models.</p><p style="text-align: justify;">China&#8217;s *Interim Measures for the Administration of Generative AI Services* define &#8220;services&#8221; as the provision of content to the public by using generative AI technologies. However, &#8220;product&#8221; versus &#8220;service&#8221; is merely a market-provision form of an AI model and does not affect whether the AI model can be an object of reverse engineering. The concept of &#8220;product&#8221; in the digital era should be interpreted with sufficient flexibility and inclusiveness. There is no legal obstacle to including software and AI systems within the scope of &#8220;products,&#8221; and even AI outputs may potentially qualify as products. For example, the EU&#8217;s *New Product Liability Directive* defines &#8220;products&#8221; to include tangible and intangible movable property, including software, expressly recognizing the multiplicity of product forms in the digital era. Accordingly, the &#8220;product&#8221; concept relevant to reverse engineering can be interpreted teleologically to include products or services provided based on AI models.</p><p style="text-align: justify;">Second, the source of the product analyzed by reverse engineering must be &#8220;lawfully acquired.&#8221; Lawful acquisition entails two layers: lawful source and legitimate means. As to the source, lawful acquisition includes obtaining a license to use the product through a user agreement. One key justification for allowing reverse engineering is that the implementer has a right of disposition over lawfully obtained products.</p><p style="text-align: justify;">Article 15 of the *Provisions on Trade Secret Protection* does not explicitly clarify whether &#8220;obtained through public channels&#8221; is limited to obtaining ownership of products carrying trade secrets, or whether it can include access acquired through a license. Similar to software products, in AI model services users typically must subscribe to obtain access, and service providers impose restrictions on user conduct through service agreements. If &#8220;transfer of ownership&#8221; is insisted upon as the sole criterion for lawful acquisition, this would fail to accommodate the characteristics of AI technology development and would further compress the space for applying reverse engineering.</p><p style="text-align: justify;">In addition, whether knowledge distillation constitutes lawful acquisition of internal technical information also requires examining the lawfulness of the source of teacher-model outputs used. Express authorization in user agreements can serve as a basis for lawful acquisition. Some AI providers have expressly granted users rights relating to model outputs in their license agreements. In such cases, users obtain model outputs pursuant to contractual authorization, thereby constituting lawful acquisition of the AI model outputs.</p><p style="text-align: justify;">As to means, lawful acquisition further requires obtaining model outputs through legitimate methods. Although theory and practice recognize reverse engineering as a defense in trade secret cases, the boundary between lawful reverse engineering and unlawful improper acquisition methods can be blurred. The determination of &#8220;improper&#8221; methods depends on the degree of social impropriety attributed to the conduct within a particular industry context, as well as the trade secret holder&#8217;s own fault.</p><p style="text-align: justify;">Knowledge distillation typically obtains model outputs through large-scale automated queries. With respect to the legitimacy of using automated means to obtain information, *Compulife Software Inc. v. Newman* established a &#8220;foreseeability of technological means&#8221; standard. In that case, the U.S. Court of Appeals for the Eleventh Circuit held that the defendant&#8217;s use of automated programs to scrape the plaintiff&#8217;s trade secret database constituted improper acquisition, reasoning that the plaintiff could not reasonably foresee the need to defend against non-human access.</p><p style="text-align: justify;">However, as AI technologies become widespread, and the use of non-human methods to obtain data becomes an industry-common approach, it is more reasonable to shift the legitimacy assessment toward a substantive evaluation of the propriety of the conduct itself, where right holders can reasonably foresee such means. In the context of knowledge distillation, where an actor has lawful access to the model and does not adopt technical means that are unlawful or potentially harmful to normal model operation or cybersecurity&#8212;such as illegal access, cracking technical protection measures, bypassing API rate limits, or generating adversarial-sample attacks&#8212;the acquisition method should be regarded as legitimate.</p><p style="text-align: justify;">Third, in terms of process, reverse engineering implementers do not possess the trade secret ex ante; they identify undisclosed information through analysis and testing. Reverse engineering typically begins with an observable product and uses observation and black-box testing to infer internal structure, operating mechanisms, or implementation pathways. Knowledge distillation is similar in behavioral mode to traditional reverse engineering: both use observation of external outputs to infer internal technical information.</p><p style="text-align: justify;">For example, the &#8220;black-box testing&#8221; logic in software reverse engineering is that even if software exposes only an API, an actor can infer internal operating logic by observing the &#8220;input&#8211;output&#8221; relationship of the computer system. &#8220;Black-box distillation&#8221; follows a similar logic: the implementer continuously inputs prompts to the teacher model, analyzes its output, and uses distillation algorithms to reverse-analyze the &#8220;input&#8211;output&#8221; mapping, thereby inferring internal technical information. This is essentially consistent with the traditional &#8220;disassemble&#8211;reconstruct&#8221; model of reverse engineering.</p><p style="text-align: justify;">Finally, reverse engineering implementers must not breach confidentiality obligations. Reverse engineering implementers are not internal technical personnel and cannot access or know internal technical information; therefore, they do not owe confidentiality obligations under trade secret law.</p><p style="text-align: justify;">For individual users, although their user agreements may contain technical confidentiality clauses prohibiting reverse engineering (hereinafter, &#8220;anti&#8211;reverse engineering clauses&#8221;), such as OpenAI&#8217;s service agreement that expressly prohibits competitors from using automated means to obtain data to train competing models, individual user agreements are typically standard-form contracts with unequal bargaining positions and lack meaningful negotiation; the legal effectiveness of such clauses is questionable, and they should not be used to infer that individual users owe confidentiality obligations to AI companies.</p><p style="text-align: justify;">For commercial users, by contrast, where parties of equal bargaining power expressly agree on confidentiality obligations in commercial authorization agreements, such obligations are legally binding on commercial users.</p><h3>(3) Legal effectiveness analysis of restrictive clauses relating to &#8220;no distillation&#8221;</h3><p style="text-align: justify;">Although knowledge distillation satisfies the constituent elements of reverse engineering, in commercial practice AI product or service providers often include restrictive clauses prohibiting knowledge distillation in user service agreements. One category consists of &#8220;anti&#8211;reverse engineering clauses,&#8221; which primarily restrict the conduct itself by prohibiting reverse engineering, extraction, or copying of internal technical information such as weight parameters, or prohibiting automated extraction of model outputs. Another category consists of &#8220;anti-competitive-use clauses,&#8221; which primarily restrict the purpose of conduct by prohibiting users from using model outputs to develop competing products.</p><p style="text-align: justify;">The legal effectiveness of these clauses has become a central dispute in assessing the legality of knowledge distillation. It is therefore necessary to conduct an in-depth analysis of the legal effectiveness of both anti&#8211;reverse engineering clauses and anti-competitive-use clauses.</p><h4>1. Breach of an anti&#8211;reverse engineering clause does not constitute an improper means of acquiring trade secrets</h4><p style="text-align: justify;">There is controversy in both theory and practice as to whether breaching an anti&#8211;reverse engineering clause can constitute an improper means of acquiring trade secrets. Some U.S. cases tend to recognize the effectiveness of such clauses in specific circumstances. For example, in *SoCal Diesel, Inc. v. Extrasensory Software, Inc.*, the California Court of Appeal, Second Appellate District, held that even absent a pre-existing confidentiality obligation between an individual user and a trade secret holder, intentionally or fraudulently breaching a license agreement that expressly prohibited reverse engineering might still be regarded as acquiring trade secrets by improper means.</p><p style="text-align: justify;">However, scholarship generally adopts a cautious stance, arguing that reverse engineering is a lawful pathway for acquiring trade secrets and courts should not treat breach of an anti&#8211;reverse engineering clause as an improper means of acquiring trade secrets. Recognizing such clauses as a basis for &#8220;improper means&#8221; would effectively grant trade secret holders perpetual protection, undermining the balance between trade secret holders and the public.</p><p style="text-align: justify;">U.S. judicial practice also commonly holds that even where a user service agreement is breached, reverse engineering may still be a lawful means of acquiring trade secrets. In *DVD Copy Control Ass&#8217;n v. Bunner*, the defendant conducted reverse engineering in breach of an anti&#8211;reverse engineering clause to obtain trade secrets. Although the California Supreme Court did not decide whether breach of such a clause constituted &#8220;improper acquisition,&#8221; Justice Moreno stated in a concurring opinion that no precedent had recognized that trade secret holders could use standard-form contracts to bring reverse engineering within the category of &#8220;improper means.&#8221;</p><p style="text-align: justify;">In *Aqua Connect, Inc. v. Code Rebel, LLC*, the defendant downloaded a trial version of the plaintiff&#8217;s software and reverse engineered it to develop a competing product, directly breaching the end-user license agreement. The U.S. District Court for the Central District of California likewise held that breach of an anti&#8211;reverse engineering clause should not be treated as an improper means of acquiring trade secrets.</p><p style="text-align: justify;">On this basis, it is further necessary to distinguish between commercial license agreements and ordinary standard-form user contracts. In a commercial negotiation context, reverse engineering undertaken in breach of a license agreement may violate the confidentiality obligations mutually assumed under the contract, thereby constituting improper acquisition of trade secrets, because the anti&#8211;reverse engineering clause in a commercial agreement may concretize mutually agreed confidentiality obligations. By contrast, individual user agreements typically take the form of standard-form contracts; the parties do not substantively negotiate the licensing terms and there is no foundational confidentiality obligation. Therefore, an anti&#8211;reverse engineering clause in such a standard-form contract should not be treated as part of a confidentiality obligation formed through equal negotiation, and breach of such a clause does not constitute an improper means of acquiring trade secrets.</p><p style="text-align: justify;">Regardless of whether an individual user agreement contains an anti&#8211;reverse engineering clause, individual users do not owe confidentiality obligations. Individual users who lawfully obtain access to a model may conduct knowledge distillation, which can be characterized as reverse engineering. However, trade secret law and contract law operate as distinct evaluative dimensions: breaching an anti&#8211;reverse engineering clause may give rise to contractual liability.</p><h4>2. Contract validity of anti&#8211;reverse engineering clauses and anti-competitive-use clauses</h4><p style="text-align: justify;">In judicial practice, the contractual validity of anti&#8211;reverse engineering clauses is often recognized, and U.S. courts rarely invalidate such clauses on the ground that they are standard-form terms. For example, in *Triage Logic Mgmt. &amp; Consulting, LLC v. Innovative Triage Servs., LLC*, the North Carolina Business Court recognized the validity of an anti&#8211;reverse engineering clause in a software license agreement, holding that the clause did not constitute an unlawful restraint of trade.</p><p style="text-align: justify;">The contractual validity of anti&#8211;reverse engineering clauses is not without limits. In general, the law does not interfere with freedom of contract. However, in IP markets, firms with strong market control can readily restrict user rights through contracts, and the law should intervene in a timely manner to limit the validity of such terms. The stronger the substantive restriction, the more closely fairness should be scrutinized.</p><p style="text-align: justify;">In the U.S. context, a finding of unconscionability requires proof of both lack of &#8220;meaningful choice&#8221; and that the term is &#8220;unreasonably favorable&#8221; to the other party. Articles 496 and 497 of the PRC Civil Code (&#12298;&#27665;&#27861;&#20856;&#12299;) establish analogous rules. Article 496 provides that where the provider of standard-form terms fails to perform its duty of reminder or explanation such that the other party did not notice or understand a term of material interest, the other party may claim that the term does not become part of the contract. Article 497 provides that standard-form terms that unreasonably restrict or exclude the other party&#8217;s principal rights are invalid.</p><p style="text-align: justify;">As standard-form terms unilaterally drafted by AI companies, anti&#8211;reverse engineering clauses in individual user agreements offer users no realistic space to negotiate. Where AI companies fail to fulfill the duty to highlight or explain such clauses, users may invoke Article 496 of the Civil Code to argue that the clause does not form part of the contract. Even where the duty is fulfilled, if an anti&#8211;reverse engineering clause imposes overly broad and generalized restrictions that exceed what is reasonably necessary to protect technical information of the AI product or service and unreasonably restrict users&#8217; legitimate use of model outputs lawfully obtained, the clause may be held invalid under Article 497.</p><p style="text-align: justify;">From a comparative perspective, the EU Trade Secrets Directive also states that &#8220;reverse engineering of a lawfully acquired product should be considered a lawful means of acquiring information unless otherwise agreed in a contract. However, the freedom to conclude such contractual arrangements may be limited by law.&#8221; This indicates that while trade secret holders may use contracts to restrict reverse engineering, the law should intervene and limit freedom of contract where anti&#8211;reverse engineering clauses impede innovation or restrict market competition.</p><p style="text-align: justify;">For example, the EU has treated contractual clauses prohibiting necessary decompilation for interoperability as invalid. Knowledge distillation implicates significant public interests in promoting market competition and technological progress. Where an anti&#8211;reverse engineering clause substantially impedes the realization of such public interests and exceeds the legitimate boundary of contractual freedom, its contractual effectiveness should be restricted.</p><p style="text-align: justify;">With respect to anti-competitive-use clauses, &#8220;reasonableness&#8221; is an important consideration in confirming contractual validity. Reasonableness assessments typically consider factors such as time, geographic scope, and the scope of restriction. The Restatement (Second) of Contracts identifies relevant factors for reasonableness: where the restriction exceeds what is necessary to protect the legitimate interests of the promisee (the licensor), an anti-competitive-use clause may be found unreasonable.</p><p style="text-align: justify;">While AI companies&#8217; massive investments in model development constitute protectable interests, overly broad competition restrictions may still be deemed unreasonable because they exceed what is necessary to protect those interests. For example, some user agreements do not clearly limit the type or temporal scope of outputs covered, potentially sweeping in any model outputs generated by users. Such a scope exceeds what is necessary to protect AI companies&#8217; legitimate interests, and the clause may be held invalid.</p><p style="text-align: justify;">U.S. courts, when scrutinizing such clauses, also consider whether users receive adequate notice, have an opportunity to read the contract, and whether the restriction scope exceeds users&#8217; reasonable expectations at the time of contracting. Under Article 497 of the Civil Code, standard-form terms that unreasonably restrict the other party&#8217;s principal rights should be deemed invalid. Accordingly, users have legitimate interests in model outputs lawfully obtained, and overly broad non-compete restrictions constitute unreasonable restrictions. For example, in the above-mentioned *Triage Logic* case, while the court upheld the validity of an anti-competitive-use clause, it also found that a non-compete clause in the software license agreement constituted an &#8220;unlawful restraint of trade,&#8221; because it permanently prohibited users from developing software, services, or products substantially similar to the software, exceeding the scope of a reasonable restriction and therefore lacking legal effect.</p><p style="text-align: justify;">Even where such anti&#8211;reverse engineering clauses and anti-competitive-use clauses may not necessarily be legally effective, the &#8220;chilling effect&#8221; they generate can still significantly weaken the public&#8217;s incentives to use AI tools, influence the characterization of reverse engineering, and thereby seriously harm the public interest. Out of risk-avoidance considerations, later entrants may abandon reasonable competitive R&amp;D, producing negative effects on industry innovation. Accordingly, restrictive clauses relating to knowledge distillation that do not satisfy fairness and reasonableness requirements should have their contractual effectiveness limited in accordance with law.</p><h2>III. Legitimacy Analysis of Knowledge Distillation as Reverse Engineering</h2><p style="text-align: justify;">Although knowledge distillation satisfies the constituent elements of reverse engineering, a legality characterization merely resolves whether the conduct constitutes trade secret misappropriation; it does not sufficiently answer under what conditions reverse engineering is legitimate. Accordingly, it is necessary to introduce legitimacy analysis as a more refined normative framework to construct substantive standards for allowing or restricting reverse engineering.</p><p style="text-align: justify;">Experience from traditional manufacturing, semiconductors, and software industries indicates that the core of assessing the legitimacy of reverse engineering lies in evaluating the conduct&#8217;s impact on subsequent innovation and overall social welfare. Whether knowledge distillation as reverse engineering is legitimate likewise depends on whether it can balance promoting innovation in the AI industry and maintaining fair competition.</p><p style="text-align: justify;">The following analysis draws on the economic analysis paradigm of reverse engineering proposed by Samuelson and Scotchmer, and examines the legitimacy of knowledge distillation as reverse engineering along four dimensions.</p><h3>(1) Knowledge distillation as reverse engineering has an economic justification</h3><h4>1. Impact on innovation incentives of prior developers</h4><p style="text-align: justify;">As a policy lever, reverse engineering can provide appropriate incentives for innovators across different technological and industrial contexts. Views advocating strict restrictions on reverse engineering argue that reverse engineering may harm the expected returns of prior developers, making it difficult for them to recoup high R&amp;D costs and thereby weakening overall innovation incentives.</p><p style="text-align: justify;">However, not all returns of prior developers should be protected by law. Where later entrants can reverse engineer and produce competing products at costs so much lower than prior developers&#8217; costs that prior developers cannot obtain expected returns through market competition, law should regulate such reverse engineering conduct. Knowledge distillation provides later entrants in the AI industry with a pathway for rapid training, but whether rapid training necessarily implies &#8220;low cost&#8221; remains debatable. It is therefore necessary to examine the economic impact of knowledge distillation from the perspectives of development costs and substitution effects.</p><p style="text-align: justify;">From the perspective of implementation costs, knowledge distillation improves the efficiency of student models through interactive training, reducing training complexity and computational costs, but it still requires substantial computing resources and R&amp;D investment. If the cost of competitive copying becomes so low that innovators cannot recoup R&amp;D investments, incentives to develop innovative products will be undermined. U.S. judicial regulation of &#8220;plug molding&#8221; behavior reflects this logic. &#8220;Plug molding&#8221; is a manufacturing technique in traditional industries that uses an original product as a mold to cast duplicates directly. Although the U.S. Supreme Court in *Bonito Boats, Inc. v. Thunder Craft Boats, Inc.* confirmed that plug molding is one method of reverse engineering, because its essence is low-cost copying of original innovation&#8212;without advancing subsequent innovation and without benefiting overall social welfare&#8212;such conduct lacks the legitimacy of reverse engineering.</p><p style="text-align: justify;">By contrast, in the software industry, disassembly and decompilation of computer programs require significant time and economic costs. Such reverse engineering can facilitate the development of interoperable products and can diminish industry monopolies in a constructive manner. This indicates that the legitimacy of reverse engineering is closely related to its cost inputs.</p><p style="text-align: justify;">In the AI industry, knowledge distillation obtains internal technical information derived from analyzing and processing teacher-model outputs. Yet student-model performance depends not only on distillation features but also on the training corpus, training and fine-tuning methods, and other factors. The complete model development process involves data collection, cleaning, pre-training, and fine-tuning. Knowledge distillation likewise requires organizing and cleaning teacher-model output data and independently designing the student model&#8217;s system architecture and learning process. In addition, distillation effectiveness depends on the intrinsic structure and distributional characteristics of training data and on continuous optimization of distillation algorithms.</p><p style="text-align: justify;">Accordingly, although knowledge distillation can save certain R&amp;D costs, developing a student model still requires substantial training costs. It is therefore inappropriate to treat knowledge distillation as low-cost copying of a teacher model.</p><p style="text-align: justify;">From the perspective of substitution effects, skepticism about the legitimacy of knowledge distillation is based on the concern that student models will rapidly eliminate the teacher model&#8217;s leading advantage, capturing market share at lower prices and thereby undermining innovators&#8217; incentives. This view, however, overlooks inherent technical limitations of knowledge distillation.</p><p style="text-align: justify;">First, a &#8220;scale gap&#8221; makes it difficult for student models to achieve the same performance as teacher models. Knowledge distillation does not directly use information such as the teacher model&#8217;s structure, parameters, or code. Rather, it analyzes teacher-model outputs to obtain internal technical information such as probability distributions and uses that information to optimize student-model training. The capacity gap between large deep neural networks and small student networks reduces knowledge transfer effectiveness. The &#8220;small-model learnability gap&#8221; phenomenon in fact indicates that small language models cannot stably benefit from distillation from large teacher models. From the perspective of transfer effectiveness, data obtained from learning a teacher model with a similar parameter scale better matches the student model&#8217;s own capability level.</p><p style="text-align: justify;">Nevertheless, industry practice commonly adopts teacher&#8211;student architectures with large scale differences. This is not because they pursue optimal transfer effectiveness, but because they trade off some performance in exchange for lightweight and efficient models, improving inference efficiency and reducing memory usage. Accordingly, the aim of knowledge distillation is to achieve lightweight and efficient student models, rather than to fully replicate teacher-model capabilities. A substantial performance gap between student and teacher models remains.</p><p style="text-align: justify;">Second, student models trained on distillation data have limitations in performance. Pre-training is the primary source of model capabilities. While student models may reach levels comparable to teacher models in specific tasks, their adaptability to new scenarios or tasks often falls below teacher models when tasks lack sufficient training data support, and they still require massive data for fine-tuning to narrow capability gaps.</p><p style="text-align: justify;">In addition, student models trained solely on teacher-model output data face the risk of performance degradation. Research indicates that teacher-model output data only partially represents the patterns embedded in the original training data; it cannot reflect all characteristics of the training data, and the student model introduces errors in learning. If training uses only teacher-model outputs, these two categories of errors will continuously accumulate. Student models will gradually lose low-frequency but important data features in the true data distribution. Such error accumulation can cause irreversible &#8220;model collapse,&#8221; namely performance degradation. Although introducing real human data into training can slow this process, declines in student-model performance are difficult to avoid. Therefore, to maintain long-term market competitiveness, significant costs are still required to obtain and use real human data for training, so as to offset error accumulation and performance degradation brought about by distillation.</p><p style="text-align: justify;">Third, market demand for AI models is differentiated. Student models and teacher models serve different market demands. Student models obtained through knowledge distillation typically have smaller parameter scales, lower computational requirements, and are mainly oriented toward niche markets with higher requirements for privacy protection and localized deployment. Teacher models, by contrast, have larger parameter scales and mainly serve cloud application scenarios requiring high-precision inference and complex computation. The two types of models have significantly different market positioning, and student models are difficult to serve as direct market substitutes for teacher models.</p><p style="text-align: justify;">Although student models may compete with teacher models in specific tasks, knowledge distillation itself requires substantial time and economic inputs. During this period, prior developers can maintain a sufficient lead, recoup R&amp;D costs, and obtain innovation returns.</p><h4>2. Impact on competitive order and market prices</h4><p style="text-align: justify;">Although products obtained through reverse engineering may enter the market and compete with prior products, causing the market price of prior products to decline, such competition can still be regarded as constructive within a certain range. This is because such competition motivates developers to improve product quality, enhance management, and reduce costs and prices.</p><p style="text-align: justify;">After student-model products or services enter the market&#8212;whether released in open-source or closed-source form&#8212;knowledge distillation can effectively reduce overall price levels for AI products and services, increase market supply, and help maintain a sound competitive order.</p><p style="text-align: justify;">On the one hand, knowledge distillation as reverse engineering can prevent prior developers from setting excessively high license fees for AI products or services. The pricing strategy of distillation implementers is cost-dependent. Once student-model products or services enter the market, they exert downward pricing pressure on teacher-model products or services. At the same time, prior developers have incentives to set license fees at reasonable levels to attract licensees and to prevent later entrants from entering the market through reverse engineering as a lawful means. Regardless of motivation, knowledge distillation as reverse engineering can objectively promote reasonable pricing by prior developers.</p><p style="text-align: justify;">Taking OpenAI as an example, its official distillation tools allow users to store model responses free of charge and charge subsequent evaluation and fine-tuning at the standard fine-tuning fee rates. Although this license price is relatively low, licensees obtain only usage rights to customized student models based on API calls. Because the student model is hosted in the cloud, licensees cannot access underlying files such as core weight parameters and must pay subsequent fees higher than standard API calls. Some studies suggest that prior developers&#8217; motivations for granting technical licenses often stem from concerns about reverse engineering.</p><p style="text-align: justify;">Accordingly, knowledge distillation as reverse engineering can incentivize prior developers to adjust license-fee pricing and reduce market prices for related products or services, thereby promoting constructive competition and broader adoption of AI technologies.</p><p style="text-align: justify;">If knowledge distillation were not characterized as reverse engineering, prior developers would no longer face competitive pressure from distillation implementers. In that scenario, prior developers may reduce prices in the short term to expand market share. However, once monopoly power is formed, prior developers may charge higher prices to users dependent on the product or service, increasing overall service prices.</p><p style="text-align: justify;">Where knowledge distillation can be characterized as reverse engineering, competition between closed-source student models and teacher models manifests as price competition; both sides may adjust pricing strategies in response to the other&#8217;s market price. Yet because student models and teacher models maintain performance gaps and student models likewise must recover development costs through pricing, student-model products or services may reduce teacher-model market prices but will not trigger destructive price competition.</p><p style="text-align: justify;">On the other hand, if student models obtained through knowledge distillation are released as open-source, they can also compete with teacher models through differentiation. Compared with price competition among closed-source models, competition between open-source and closed-source models takes a different form. Closed-source developers are often more vigilant regarding the effects of open-source models on pricing strategies and market share.</p><p style="text-align: justify;">Some argue that knowledge distillation can enable open-source models to rapidly narrow gaps with closed-source models, thereby exposing closed-source models to risks of losing competitive advantages. For example, a Stanford University study found that the open-source model &#8220;Alpaca&#8221; distilled from OpenAI&#8217;s base model (approximately 175 billion parameters) could, with only 7 billion parameters, exhibit performance similar to the latter in specific tasks. Nevertheless, the two still have substantial capability gaps in long-tail knowledge handling and complex reasoning logic. Closing these gaps requires high R&amp;D costs and reliance on massive generated data or stronger base models; in complex application scenarios, student models are therefore unlikely to directly substitute for teacher models in the short term.</p><p style="text-align: justify;">Open-source models exert some competitive pressure on closed-source models in terms of user costs and market choice. Open-sourcing as a market strategy aims to establish technical standards and expand ecosystem influence, thereby competing with closed-source models through differentiation.</p><p style="text-align: justify;">At the cost level, open-source student models provide lower-priced substitutes in scenarios where users have higher data-security requirements or specific vertical-domain needs, leading to some decline in market prices of closed-source teacher models. Yet this impact mainly manifests in particular niche markets and is unlikely to constitute comprehensive substitution.</p><p style="text-align: justify;">With respect to user choice, scholarship distinguishes between two competitive strategies for open-source models. Where open-source models adopt a &#8220;reactive strategy,&#8221; namely always following closed-source models&#8217; performance improvements at a fixed ratio, closed-source models can always induce users to choose closed-source models through price reductions or performance adjustments. Only where open-source models adopt a &#8220;proactive strategy,&#8221; namely independently developing high-performance models rather than merely following closed-source development, will users tend to choose open-source models, thereby weakening closed-source competitive advantages. Accordingly, knowledge distillation, as a typical &#8220;reactive strategy,&#8221; will not directly substitute teacher models in the market. Rather, the existence of open-source alternatives can incentivize closed-source providers to lower prices for related products or services, thereby promoting a fair competitive environment.</p><h4>3. Impact on subsequent innovation in the AI industry</h4><p style="text-align: justify;">This factor assesses whether reverse engineering enables later entrants, after obtaining technical information, to develop improved, compatible, or more advanced new products, thereby advancing technological innovation and progress. Knowledge distillation obtains internal technical information by learning from teacher-model outputs; its essence is not direct copying of teacher-model performance, but innovation built on that basis.</p><p style="text-align: justify;">In the semiconductor chip industry, the U.S. Semiconductor Chip Protection Act of 1984 (SCPA) clarified the legitimacy of reverse engineering: it allows copying of chip layouts for purposes of learning and analysis, but requires later entrants to engage in &#8220;forward engineering,&#8221; namely using acquired knowledge to develop original chip designs. This institutional design ensures that prior developers can recoup costs while compelling later competitors to improve upon the original product, thereby encouraging competition and preventing technological monopolies.</p><p style="text-align: justify;">Analogously, valuable knowledge distillation is often accompanied by substantial subsequent innovation. Implementers must invest significant R&amp;D costs in fine-tuning and optimizing student models before bringing them to market.</p><p style="text-align: justify;">In terms of specific paths for subsequent innovation, knowledge distillation can enable at least the following.</p><p style="text-align: justify;">First, student models obtained via knowledge distillation can expand the scope of AI applications and be applied across computer vision, speech recognition, and natural language processing. By adding vertical-domain data for training, student models can achieve&#8212;in specific professional scenarios such as medicine and law&#8212;capabilities comparable to or even exceeding those of general-purpose large models serving as teacher models.</p><p style="text-align: justify;">Second, knowledge distillation can break technological monopolies by a small number of leading industry models and reduce entry barriers for subsequent developers. Specifically, distillation can transfer advanced capabilities of base models such as GPT-4 to accessible open-source models such as LLaMA and Mistral, enabling secondary innovation by developers.</p><p style="text-align: justify;">Third, knowledge distillation can convert ultra-large-parameter models into lightweight models deployable on mobile devices or IoT endpoints, allowing high-performance models that previously could run only in the cloud to run on end-user devices, thereby supporting differentiated new AI products or services.</p><p style="text-align: justify;">In addition, knowledge distillation can promote interoperability among AI applications and reduce developers&#8217; dependence on a single closed-source model. Just as reverse engineering in software can achieve interoperability between platforms and applications&#8212;reducing monopolies formed by non-interoperable systems and incentivizing platform licensing and application development&#8212;knowledge distillation in AI enables developers, when faced with monopolistic pricing by model vendors, to reduce model migration costs, achieve low-cost switching among models, reduce dependence on a single closed-source model, provide more diverse market choices, and promote a sound competitive order.</p><h4>4. Impact on waste of social R&amp;D resources</h4><p style="text-align: justify;">Legitimate reverse engineering can reduce repetitive and ineffective R&amp;D inputs, enabling more efficient use of social innovation resources. With respect to knowledge distillation, its effects on R&amp;D investment can be analyzed in two respects.</p><p style="text-align: justify;">On the one hand, knowledge distillation can reduce repetitive and ineffective exploratory R&amp;D investment. Model training is highly dependent on computing resources. According to industry reports, by 2024 the training costs of the most advanced base large models (such as GPT-4 and Gemini Ultra) had reached USD 78 million and USD 191 million, respectively. Given the extremely high training costs of such ultra-large models, R&amp;D is currently mainly conducted by a small number of cash-rich technology giants.</p><p style="text-align: justify;">Knowledge distillation enables later developers to directly benefit from prior models&#8217; development experience and reduces large amounts of ineffective investment in prior R&amp;D. If the legitimacy of knowledge distillation as reverse engineering is not recognized, later developers would have to independently complete the model training process, producing large amounts of duplicative R&amp;D investment.</p><p style="text-align: justify;">Although implementing knowledge distillation requires collecting and analyzing teacher-model outputs and continuously debugging distillation algorithms to train student models, these costs are far lower than the R&amp;D investment required to independently repeat training. Where legal risks, compliance barriers, or difficulties in fully eliminating potential infringement risks associated with training data make re-training necessary, independent training may indeed be justified. Outside such circumstances, however, repeatedly conducting pre-training will waste social resources, and allowing knowledge distillation helps achieve efficient allocation of social innovation resources.</p><p style="text-align: justify;">On the other hand, as a widely adopted technology in the AI industry, knowledge distillation can help direct limited R&amp;D resources toward more valuable frontier technological innovations. Resources saved through distillation can be reinvested into independent R&amp;D such as training data collection, algorithm debugging, and model optimization, thereby producing higher-quality model products. This differs fundamentally from &#8220;free-riding&#8221; conduct that directly copies others&#8217; achievements. If knowledge distillation is not recognized as legitimate reverse engineering, the AI industry will be unable to reasonably draw on prior R&amp;D results, markets will generate extensive duplicative R&amp;D, and overall social R&amp;D efficiency will significantly decline.</p><p style="text-align: justify;">The above four dimensions indicate that knowledge distillation as reverse engineering can effectively promote constructive market competition. The basic function of competition is to incentivize producers to continuously develop and adopt new technologies, improve management to reduce costs, and thereby increase public welfare. Knowledge distillation, as a reverse engineering method, can promote technological progress while maintaining innovation incentives, maximizing overall social welfare.</p><h3>(2) The legitimacy boundaries of knowledge distillation as reverse engineering</h3><p style="text-align: justify;">Although knowledge distillation as reverse engineering has an economic justification, it should, like reverse engineering in traditional industries, be subject to legitimacy boundaries. The legitimacy boundaries should be argued in light of the market characteristics of the relevant industry, the specific threats faced, and the economic impact of restrictions. A legitimacy assessment framework based on three dimensions&#8212;&#8220;purpose&#8211;conduct&#8211;result&#8221;&#8212;can be constructed around the characteristics of knowledge distillation.</p><p style="text-align: justify;">First, as to purpose legitimacy, one should examine whether the distillation implementer has an intent to innovate. Where an actor conducts knowledge distillation to improve student-model performance based on obtaining internal technical information, or to create complementary innovation vis-&#224;-vis teacher-model products, the purpose should be regarded as legitimate. By contrast, knowledge distillation aimed at purely copying teacher-model functionality rather than pursuing innovative development lacks legitimacy.</p><p style="text-align: justify;">Because purpose legitimacy is a subjective element and difficult to directly prove in practice, it can be inferred from objective conduct. Where an actor continuously invests R&amp;D resources to optimize the student model during the distillation process and further fine-tunes and optimizes the student model with real data after distillation, one may infer an intent to innovate. Conversely, where an actor brings a student-model-based product or service to market immediately after completing basic distillation steps, with no subsequent R&amp;D investment, one may infer that the purpose is copying rather than innovation.</p><p style="text-align: justify;">Second, as to conduct reasonableness, one should assess the necessity and innovativeness of knowledge distillation conduct.</p><p style="text-align: justify;">At the necessity level, it should be analyzed whether knowledge distillation is a necessary pathway for obtaining internal technical information and improving student-model performance. Where there is a reasonably priced alternative pathway capable of achieving the same effect&#8212;for example, obtaining a distillation license at a reasonable price&#8212;the necessity of conducting knowledge distillation is weakened. However, the necessity requirement should not be overly stringent; otherwise, later developers may abandon knowledge distillation out of risk avoidance, thereby unduly narrowing the scope of reverse engineering.</p><p style="text-align: justify;">At the innovativeness level, it is necessary to examine whether the implementer, on the basis of knowledge distillation, has invested a substantial degree of R&amp;D costs. Such costs include not only economic inputs such as computing resources necessary to conduct distillation, but also subsequent innovation inputs such as further fine-tuning and optimization of the model using real human data.</p><p style="text-align: justify;">One may draw on the SCPA&#8217;s &#8220;forward engineering&#8221; institutional design and require distillation implementers to produce results with a certain degree of originality: the student model should form performance advantages different from those of the teacher model. In *Sega Enterprises Ltd. v. Accolade, Inc.*, one of the reasons the court found the defendant&#8217;s reverse engineering legitimate was that the defendant developed a new non-infringing program, thereby promoting the creativity incentives intended by copyright law. The innovativeness requirement objectively extends the student model development cycle, enabling prior developers to maintain a lead during that period and recoup R&amp;D costs.</p><p style="text-align: justify;">Finally, as to market harm, one should examine whether the student model, after entering the market, directly substitutes for the teacher model, substantially affects the prior developer&#8217;s ability to recoup R&amp;D costs, and weakens its incentives for subsequent innovation. Where student-model products or services target different market segments and user groups and compete with teacher models through differentiation rather than direct substitution, market harm is absent.</p><p style="text-align: justify;">In determining direct market substitution, the following factors may be considered: (i) whether student and teacher models have significant differences in market positioning and target different user groups; and (ii) whether the student model forms differentiated functionality in specific vertical domains distinct from the teacher model. If either condition is satisfied, direct market substitution will generally not be found, and market harm will be absent.</p><p style="text-align: justify;">It should be noted that implementation costs of knowledge distillation may continue to decline with technological iteration. If the technology develops to a point where it can replicate teacher models at extremely low cost, the risk of direct market substitution will substantially increase.</p><p style="text-align: justify;">In applying these standards, the three factors form a progressive logic. Purpose legitimacy is the prerequisite, examining whether the actor has a subjective intent of substantive innovation. Conduct reasonableness is the key: on the basis of legitimate purpose, it further examines whether the distillation method is necessary and whether the implementer has invested substantive R&amp;D costs and produced innovative results. Market harm is the final step: on the basis of legitimate purpose and reasonable conduct, it examines whether the student model directly substitutes for the teacher model and weakens prior developers&#8217; innovation incentives.</p><p style="text-align: justify;">Accordingly, distillation conducted for the purpose of copying teacher-model functionality, without subsequent innovation inputs, and resulting in direct market substitution lacks legitimacy and should not be characterized as reverse engineering. Conversely, where knowledge distillation, with certain subsequent R&amp;D inputs, enhances differentiated performance of student models and constitutes complementary innovation rather than direct market substitution, it should be regarded as legitimate reverse engineering.</p><h2>Conclusion</h2><p style="text-align: justify;">Technological innovation in the intelligent era has brought new needs and opportunities for the development of intellectual property law. The Central Economic Work Conference in 2025 for the first time proposed &#8220;improving the intellectual property protection system in emerging fields,&#8221; signaling that IP protection in emerging technology fields has risen to the level of national strategy.</p><p style="text-align: justify;">The controversy over the legality of knowledge distillation is, in essence, a conflict between protecting R&amp;D incentives and enabling subsequent technological innovation. Legal protection of technological innovation should not come at the expense of subsequent innovation. Knowledge distillation conduct that satisfies purpose legitimacy, conduct reasonableness, and the absence of market harm should constitute reverse engineering.</p><p style="text-align: justify;">Clarifying the legality of knowledge distillation as reverse engineering helps form a dynamic balance between trade secret protection and industrial innovation incentives. In the AI era, technology evolves rapidly; only by actively responding to technological transformation can law promote high-quality and sustainable development of the AI industry in open competition.</p>]]></content:encoded></item><item><title><![CDATA[The Five Biggest AI Risks, According to China’s CAC]]></title><description><![CDATA[Artificial intelligence is advancing at a rapid pace and is being deployed across an ever-wider range of industries and sectors.]]></description><link>https://www.geopolitechs.org/p/the-five-biggest-ai-risks-according</link><guid isPermaLink="false">https://www.geopolitechs.org/p/the-five-biggest-ai-risks-according</guid><dc:creator><![CDATA[Geopolitechs]]></dc:creator><pubDate>Thu, 03 Sep 2026 14:13:38 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Jv8G!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F899bffa0-1b97-406c-ac5f-6a045ea52434_516x387.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p style="text-align: justify;">Artificial intelligence is advancing at a rapid pace and is being deployed across an ever-wider range of industries and sectors. At the same time, the security risks associated with AI have attracted growing attention. At a press conference held on September 1 for the 2026 National Cybersecurity Awareness Week, Wang Lihong, Deputy Director-General and First-Level Inspector of the Cybersecurity Coordination Bureau of the Cyberspace Administration of China, <a href="https://www.cernet.edu.cn/info/focus/rd_xin_wen/202609/t20260902_2769888.shtml">told </a>China Media Group&#8217;s CCTV that the AI sector currently faces five major categories of security risks and challenges.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Jv8G!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F899bffa0-1b97-406c-ac5f-6a045ea52434_516x387.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Jv8G!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F899bffa0-1b97-406c-ac5f-6a045ea52434_516x387.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Jv8G!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F899bffa0-1b97-406c-ac5f-6a045ea52434_516x387.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Jv8G!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F899bffa0-1b97-406c-ac5f-6a045ea52434_516x387.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Jv8G!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F899bffa0-1b97-406c-ac5f-6a045ea52434_516x387.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Jv8G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F899bffa0-1b97-406c-ac5f-6a045ea52434_516x387.jpeg" width="516" height="387" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/899bffa0-1b97-406c-ac5f-6a045ea52434_516x387.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:387,&quot;width&quot;:516,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:45407,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.geopolitechs.org/i/214014237?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F899bffa0-1b97-406c-ac5f-6a045ea52434_516x387.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Jv8G!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F899bffa0-1b97-406c-ac5f-6a045ea52434_516x387.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Jv8G!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F899bffa0-1b97-406c-ac5f-6a045ea52434_516x387.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Jv8G!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F899bffa0-1b97-406c-ac5f-6a045ea52434_516x387.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Jv8G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F899bffa0-1b97-406c-ac5f-6a045ea52434_516x387.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: justify;"><strong>First, inherent technological vulnerabilities remain difficult to eliminate, undermining the stability and reliability of AI outputs.</strong> AI algorithms such as deep learning are inherently complex and often lack interpretability. Their reasoning processes are opaque, making it difficult to quickly identify and correct anomalies or failures. Even minor perturbations to inputs can lead to erroneous reasoning or outputs. Meanwhile, the data used in model development and training come from complex and diverse sources, creating the possibility that biases, discrimination, and other problems may be introduced, intentionally or unintentionally, causing models to learn from flawed patterns and generate discriminatory content. These inherent technical limitations significantly increase the difficulty of diagnosing system failures and make it harder to effectively verify whether AI-generated decisions are sound and reasonable. This severely constrains the large-scale deployment of AI in environments with stringent security requirements, low tolerance for error, and complex operating conditions.</p><p style="text-align: justify;"><strong>Second, rapid advances in model capabilities are disrupting traditional security paradigms and giving rise to risks of extreme loss of control.</strong> Some frontier models have seen dramatic improvements in their ability to discover vulnerabilities, substantially lowering the barriers to launching cyberattacks while making systems more difficult to defend. This is challenging the traditional cybersecurity model, which relies primarily on patching vulnerabilities and static, rule-based defenses, and is forcing a fundamental rethink of the cybersecurity paradigm. Recently, a number of major technology companies have reported incidents involving large AI models exhibiting behavior beyond intended controls. During safety evaluations, frontier models have demonstrated behaviors such as agents circumventing sandboxes, evading security boundaries, gaining unauthorized access, and attacking external real-world production systems. The risk of AI systems becoming severely uncontrollable therefore warrants close attention.</p><p style="text-align: justify;"><strong>Third, as AI applications evolve rapidly, the nature of security risks is also changing at an accelerating pace.</strong> Since 2025, AI agents have proliferated rapidly, with AI shifting from simply &#8220;answering questions&#8221; toward &#8220;executing tasks.&#8221; Correspondingly, security risks are evolving from the &#8220;generation of harmful content&#8221; toward the &#8220;autonomous execution of actions.&#8221; Highly privileged endpoint agents such as OpenClaw, which surged in popularity earlier this year, possess system-level permissions and can directly execute terminal commands and access files and tools across networks, creating significant security risks. At the same time, numerous agent &#8220;skills&#8221; and plugins have been found to contain security vulnerabilities. Once exploited by attackers, these highly privileged agents could become &#8220;springboards&#8221; for breaching network boundaries, compromised machines used to carry out attacks, or &#8220;Trojan horses&#8221; for surveillance and data theft&#8212;turning from capable assistants into unwitting accomplices operating from within.</p><p style="text-align: justify;"><strong>Fourth, the risks of AI misuse, abuse, and malicious use are becoming increasingly prominent, posing challenges to social order and ethical boundaries.</strong> In information services, AI can be used to generate illegal or harmful information, blur the distinction between fact and falsehood, mislead users, and degrade the online information ecosystem. In scientific research, AI is lowering barriers to entry in ethically sensitive fields such as biology and genetics, potentially increasing the risk of research crossing established ethical boundaries. In the labor market, AI is accelerating the restructuring of traditional economic structures and contributing to declining demand for certain forms of conventional labor.</p><p style="text-align: justify;"><strong>Fifth, the global AI sector faces risks arising from technological hegemony.</strong> The AI industry is characterized by a highly globalized division of labor and extensive cross-border collaboration. However, certain countries are pursuing &#8220;technological hegemony&#8221; by using unilateral measures such as export controls to create barriers across global supply chains. They are also leveraging their influence over public discourse to produce misleading evaluation reports on large AI models and maliciously discredit the technological development of other countries. In addition, they are taking advantage of their dominance in training-data resources to promote particular values through AI systems, further widening the global governance divide.</p>]]></content:encoded></item><item><title><![CDATA[Yuyuan Tantian: Anthropic Has Caught America’s Disease]]></title><description><![CDATA[A commentary published today by Yuyuan Tantian, a self-media outlet regarded as close to the Chinese official line, was titled &#8220;Anthropic Has Caught the American Disease.&#8221;]]></description><link>https://www.geopolitechs.org/p/yuyuan-tantian-anthropic-has-caught</link><guid isPermaLink="false">https://www.geopolitechs.org/p/yuyuan-tantian-anthropic-has-caught</guid><dc:creator><![CDATA[Geopolitechs]]></dc:creator><pubDate>Sun, 30 Aug 2026 12:49:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!xtk3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1224dbd9-c538-48bb-a3ae-a88786e2752c_750x455.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p style="text-align: justify;">A commentary published today by Yuyuan Tantian, a self-media outlet regarded as close to the Chinese official line, was titled &#8220;Anthropic Has Caught the American Disease.&#8221; </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xtk3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1224dbd9-c538-48bb-a3ae-a88786e2752c_750x455.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xtk3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1224dbd9-c538-48bb-a3ae-a88786e2752c_750x455.webp 424w, https://substackcdn.com/image/fetch/$s_!xtk3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1224dbd9-c538-48bb-a3ae-a88786e2752c_750x455.webp 848w, https://substackcdn.com/image/fetch/$s_!xtk3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1224dbd9-c538-48bb-a3ae-a88786e2752c_750x455.webp 1272w, https://substackcdn.com/image/fetch/$s_!xtk3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1224dbd9-c538-48bb-a3ae-a88786e2752c_750x455.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xtk3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1224dbd9-c538-48bb-a3ae-a88786e2752c_750x455.webp" width="750" height="455" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1224dbd9-c538-48bb-a3ae-a88786e2752c_750x455.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:455,&quot;width&quot;:750,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:19182,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.geopolitechs.org/i/213393321?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1224dbd9-c538-48bb-a3ae-a88786e2752c_750x455.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xtk3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1224dbd9-c538-48bb-a3ae-a88786e2752c_750x455.webp 424w, https://substackcdn.com/image/fetch/$s_!xtk3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1224dbd9-c538-48bb-a3ae-a88786e2752c_750x455.webp 848w, https://substackcdn.com/image/fetch/$s_!xtk3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1224dbd9-c538-48bb-a3ae-a88786e2752c_750x455.webp 1272w, https://substackcdn.com/image/fetch/$s_!xtk3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1224dbd9-c538-48bb-a3ae-a88786e2752c_750x455.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: justify;">Its central argument is that if the authority to define model safety rests with a single U.S. company such as Anthropic, then its competitors will inevitably be placed on the &#8220;unsafe&#8221; side of the divide. What is needed instead is a scientific definition acceptable to both sides, not one unilaterally imposed by a single country or company.<br><br>According to the commentary, capabilities that could genuinely cause severe harm, the commentary says, can be jointly tested and jointly constrained. Ordinary model development and commercial use, however, should not be subject to covert interference. The line between the two must be drawn collectively by all relevant parties.<br><br>The commentary argues that U.S. figures are already discussing how to persuade China to accept limits on &#8220;AI models with dangerous capabilities.&#8221; The question, however, is whether, in the presence of companies such as Anthropic, Washington should first examine its own firms before asking China to restrict model releases or disclose risks. That would mean publicly clarifying the purpose, scope, and rules of such companies&#8217; identification mechanisms and subjecting them to independent third-party audits.<br><br>The commentary further pointed out that if U.S. companies are permitted to transmit user data back without informed consent, bypass permission checks, and enable automated decision-making by default, while the U.S. government remains silent, then American talk of &#8220;safety boundaries&#8221; amounts to little more than rhetoric.<br><br>Only if the United States can first show that its safety rules apply equally to its own model companies, the piece suggests, can China and the United States move into substantive discussions.<br><br>Reuters reported on July 21, citing five sources familiar with the matter, that the two sides were planning to hold the first formal AI dialogue of the Trump administration in September, tentatively under the lead of U.S. Treasury Secretary Scott Bessent and ahead of President Xi Jinping&#8217;s visit to the United States. At that point, however, the date, venue, agenda, and composition of the delegations had yet to be settled. By August 19, the South China Morning Post was still reporting that no venue had been fixed, no decision had been made on whether companies and technical experts would participate, and the U.S. side itself had not fully settled which department would take the lead.<br><br>At the same time, peripheral channels of communication appear to be accelerating. On August 24, Wang Huning met the U.S. delegation to the third China-U.S. Track 1.5 Dialogue, and the American side, in its public remarks, made specific reference to the need to &#8220;prevent risks such as those posed by artificial intelligence.&#8221;<br><br>Against that backdrop, and on the eve of what could become intergovernmental China-U.S. talks on AI safety, the Yuyuan Tantian commentary merits attention.<br><br>To understand the piece, it is also useful to note several developments in the days immediately preceding its publication. </p><p style="text-align: justify;">On August 26, Bill Gates told Reuters that if the United States were to move first in constraining dangerous models, China might be willing to restrict the release of such models as well, and he raised the idea of some form of international governance body. </p><p style="text-align: justify;">On August 28, a U.S. court overturned the Pentagon&#8217;s supply-chain risk designation concerning Anthropic. </p><p style="text-align: justify;">Two days later, Yuyuan Tantian published its article. In that context, the line stating that &#8220;relevant figures on the U.S. side are discussing how to get China to limit models with dangerous capabilities&#8221; most plausibly refers not only to statements by officials such as Bessent, but also to arguments advanced by Gates and broader circles in the U.S. policy community.<br><br>One line in particular stands out: &#8220;Capabilities that could truly cause serious harm can be jointly tested and jointly restricted.&#8221; That wording suggests China may not be rejecting frontier-model controls in principle. Rather, it appears to be setting out three conditions: first, that dangerous capabilities must be defined in technical terms that are repeatable and verifiable; second, that the standards must apply equally to Chinese and U.S. firms; and third, that the mechanisms for testing and restriction cannot be secretly controlled by American companies.<br><br>Taken together, the commentary appears to send a fairly clear signal. China may be willing to engage the United States on AI safety, but only in relation to a narrow category of clearly defined and verifiable catastrophic capabilities. Any rules would need to be reciprocal, rather than leaving companies such as Anthropic with effective interpretive authority. Normal research and development, open-source ecosystems, and commercial applications, meanwhile, should not be subjected to covert monitoring or blocked in the name of safety.</p><p style="text-align: justify;">Below is my full English translation of the article. As always, any errors or omissions are entirely my own.</p><p>But before getting to the translation, I&#8217;d like to make a brief personal note.</p><blockquote><p style="text-align: justify;">AI policy and geopolitics are increasingly sensitive and sometimes highly politicized subject. For that reason, I would like to reiterate that all views, commentary, and translations published on this Substack are entirely my own and should not be understood as representing the position or interests of any organization.</p><p style="text-align: justify;">This Substack is a personal, non-commercial project that I maintain in my spare time, simply because I enjoy following these issues and believe that serious ideas and debates are worth sharing with a wider audience. I receive no payment for this work, and my decisions about what to translate, what to write about, and what views to express are entirely my own.</p><p style="text-align: justify;">I very much welcome disagreement, criticism, and debate on the substance. Readers are, of course, equally free to follow or not follow this work. My only request is that the discussion remain focused on the ideas themselves, rather than speculation about personal identities, affiliations, or presumed interests.</p><p style="text-align: justify;">I hope this small independent project can remain what it was intended to be: a space for sharing information, exchanging ideas, and encouraging serious discussion of technology and public policy. I would be grateful for everyone&#8217;s understanding and respect for that purpose.</p></blockquote><h4 style="text-align: justify;"><a href="https://mp.weixin.qq.com/s/iHEghBZ8VnPFxR5zUr9qwQ">Anthropic Has Caught America&#8217;s Disease</a></h4><blockquote><p style="text-align: justify;">Anthropic CEO Dario Amodei once said that if powerful artificial intelligence develops in the right direction, the world could become &#8220;stunningly beautiful.&#8221;</p><p style="text-align: justify;">He sketched out a future thoroughly rewritten by technology: most diseases would be cured, human life expectancy could double, poverty would disappear, and many people who lived to see it would be &#8220;moved to tears.&#8221;</p><p style="text-align: justify;">To support that vision, Anthropic has demonstrated striking technical strength and unusually fast industrial penetration. On major international rankings, the company&#8217;s Claude model family currently occupies the top three spots. On the application side, data from May to July this year show that 39% of developers globally and 47% of developers in the United States were using its core AI coding tool, Claude Code, in their work.</p><p style="text-align: justify;">Anthropic is now sprinting toward what could become the largest IPO in history. According to foreign media disclosures, it plans to tell investors that its potential addressable market could exceed US$30 trillion, selling the story of how AI will restructure global productivity. The grand vision in Amodei&#8217;s writing appears, on the surface, to be moving step by step toward reality.</p><p style="text-align: justify;">Yet the social reaction he has received looks very different.</p><p style="text-align: justify;">In the United States, public anxiety over AI squeezing human space for survival is turning into a wave of opposition directed at Anthropic, while intellectual criticism of monopoly power among technology giants is growing louder.</p><p style="text-align: justify;">More than a month ago, China&#8217;s Ministry of Industry and Information Technology directly named Claude Code and said it carried serious backdoor security risks, including the ability to send users&#8217; geographic location, identity markers, and other sensitive information back to remote servers without user consent.</p><p style="text-align: justify;">The contrast is deeply ironic. How did a company that believes it is saving humanity become, in the eyes of so many people, a byword for overreach, surveillance, and hegemony?</p><p style="text-align: justify;">In 2020, a group of core OpenAI employees chose to leave the company and start their own venture. They were convinced that they understood better than their predecessors how AI should develop, and that they had seen the future of AI earlier than the rest of the world.</p><p style="text-align: justify;">Dario Amodei was one of the central figures in that group. He carries the typical traits of a Silicon Valley elite: educated at top universities, formed inside major technology companies, convinced that technology can solve humanity&#8217;s most fundamental problems, and convinced that engineers are not only building products but also designing the future of society.</p><p style="text-align: justify;">Anthropic was born in that context.</p><p style="text-align: justify;">Idealism, though, never comes free. To realize the utopia he talks about, Anthropic needs enormous investment to build the world&#8217;s most advanced models and reach users across the whole of society.</p><p style="text-align: justify;">Every interaction and every line of code are treated by Anthropic as part of the capability base for training its models. If the destination is humanity&#8217;s ultimate ideal, then along the way, what does it matter to collect a bit of user data, take over a bit of terminal authority, or bypass a bit of user consent?</p><p style="text-align: justify;">The backdoor issue is a concentrated expression of that worldview.</p><p style="text-align: justify;">In discussions on GitHub about Claude Code, the author found that one of the major flashpoints was covert monitoring activity.</p><p style="text-align: justify;">A typical case appeared in January this year, when an overseas developer checking proxy logs discovered that Claude Code was sending requests to a website every few seconds in the background, at a frequency that looked like real-time monitoring. At the time, Anthropic did not explain what the website was collecting or what it was for. The feedback that developer posted on GitHub also received no substantive response.</p><p style="text-align: justify;">More developers reported similar anomalies.</p><p style="text-align: justify;">Some noticed that Claude Code would send the domain name of a website the user was preparing to access to Claude&#8217;s own interface before formal authorization had even been given. Others found that Claude Code could sometimes bypass certain interception mechanisms.</p><p style="text-align: justify;">Taken together, these phenomena point to one issue: Anthropic wants its model to monitor and see everything.</p><p style="text-align: justify;">During use, Claude Code also exposed another, more serious problem: allowing AI to make decisions in place of the user.</p><p style="text-align: justify;">Anthropic officially provides a parameter called <code>dangerously-skip-permissions</code>. Once enabled, Claude Code skips permission confirmation and executes operations directly.</p><p style="text-align: justify;">In March this year, Claude Code went further and introduced an &#8220;auto mode,&#8221; relying on a built-in risk-classification model to decide operational permissions by itself. Starting on August 14, that mode was enabled by default.</p><p style="text-align: justify;">Anthropic&#8217;s official documentation states clearly that permission rules are enforced at the tool layer, and prompts cannot alter what the tool is allowed or forbidden to do.</p><p style="text-align: justify;">From monitoring, to skipping confirmation, to automated decision-making, the pattern is the same: the user steps back, and the system steps forward.</p><p style="text-align: justify;">That is exactly how Amodei&#8217;s worldview shows up inside the product. If AI carries the mission of leading humanity into the future, then by definition it must know more than users, judge faster than users, and possess broader authority to act.</p><p style="text-align: justify;">What is even more troubling is that none of Anthropic&#8217;s steps across the line has been effectively stopped.</p><p style="text-align: justify;">In theory, the U.S. government should be the firmest defender of security boundaries. In practice, it has yielded repeatedly.</p><p style="text-align: justify;">In the first half of this year, the U.S. government prepared an executive order titled &#8220;Promoting Advanced Artificial Intelligence Innovation and Safety,&#8221; under which the government would review the safety of frontier AI models before release.</p><p style="text-align: justify;">Compared with the earlier draft, the final executive order steadily lowered the regulatory bar. The pre-release access period was cut from 90 days to 30 days, and the text repeatedly emphasized voluntary participation.</p><p style="text-align: justify;">When the U.S. government loosens rules and retreats in order to preserve technological hegemony, and when capital markets provide a kind of moral exemption in pursuit of returns, the desire for control that originally sat inside one person&#8217;s savior complex gains fertile nourishment from the institutions of American society. That is also the root of what the article calls &#8220;closed-source America.&#8221;</p><p style="text-align: justify;">A backdoor can be deleted. Permission settings can be changed. But the real problem lies far beyond the technical layer.</p><p style="text-align: justify;">Recent developments have pushed the contest over artificial intelligence toward a deeper question: who gets to define the security boundaries of frontier models?</p><p style="text-align: justify;">The way Anthropic is competing for power and advantage shows that it is no longer just a technology company.</p><p style="text-align: justify;">Earlier, when Anthropic&#8217;s annualized revenue reached the one-billion-dollar threshold and it was preparing to accelerate commercialization, Amodei published a long essay of roughly ten thousand words that already showed an ambition to intervene in global order.</p><p style="text-align: justify;">One full section of that essay was devoted to international governance, and the language was highly controlling and openly aggressive.</p><p style="text-align: justify;">He argued that an alliance of &#8220;democratic countries&#8221; should firmly control the AI supply chain and restrict adversaries&#8217; access to chips and semiconductor equipment. At the same time, those countries should use AI to build military superiority while also using incentives to draw more countries into the alliance. He stated explicitly that this would require &#8220;extremely close cooperation&#8221; between private AI companies and governments.</p><p style="text-align: justify;">That does not sound like an entrepreneur discussing a product roadmap. It sounds like someone planning a global AI order and reserving for his own company a dominant seat at the very center.</p><p style="text-align: justify;">Silicon Valley has heard this kind of argument before.</p><p style="text-align: justify;">Alexander Karp, the CEO of Palantir, published a book titled <em>The Technological Republic</em>, arguing that Silicon Valley should reengage with national defense and state governance and use technological capability to help the United States and its allies manage security and geopolitical competition. Amodei&#8217;s vision follows the same logic.</p><p style="text-align: justify;">Very quickly, that ambition moved into practice.</p><p style="text-align: justify;">Claude Code was brought into the U.S. Department of Defense for intelligence analysis, modeling and simulation, operational planning, and cyber operations.</p><p style="text-align: justify;">But the cooperation was not smooth. The Pentagon believed that once the system entered the government&#8217;s door, it should obey government direction. Anthropic believed that control over the model&#8217;s core capabilities and safety criteria remained in its own hands, and that the government could not simply decide how those capabilities would be used.</p><p style="text-align: justify;">When the two sides could not agree, Anthropic did not withdraw. It changed course, shifting from direct service provision to participation in rule-making.</p><p style="text-align: justify;">In the first half of 2026, Anthropic increased its federal lobbying spending to a level above its total for all of 2025. In addition, it put US$40 million into an organization focused on AI risk regulation.</p><p style="text-align: justify;">Its IPO can also be understood in that context. The money raised from going public will not be used only to build stronger models. It will also be used to keep buying something else: the power to define.</p><p style="text-align: justify;">Put these facts together and the path becomes clear. Anthropic first enters government systems through the banner of safety capability, then uses lobbying and capital to help shape industry rules. It is both a regulated object and a participant in defining what kinds of models are dangerous and at what point the government should stop them from entering the market.</p><p style="text-align: justify;">By this point, Amodei&#8217;s logic has gone through two enlargements: from &#8220;I am doing good&#8221; to &#8220;I will decide for you,&#8221; and from &#8220;my country is doing good&#8221; to &#8220;anyone who does not cooperate should be restricted.&#8221;</p><p style="text-align: justify;">This is a creature produced entirely by the American path. It sincerely believes that it is right. It sincerely believes that its models are &#8220;democratic models,&#8221; and that its own safety standards are the world&#8217;s safety standards. It does not seem to realize that this very inability to doubt itself is the greatest danger of all.</p><p style="text-align: justify;">And the reason it is now so urgent is that time is not on its side. More and more people are beginning to see that clearly.</p><p style="text-align: justify;">Stanford University&#8217;s <em>AI Index Report 2026</em> shows that the performance gap between the top Chinese and American models has narrowed to about 2.7%. Separate disclosures indicate that Microsoft, Amazon, and Google are in talks with the Chinese company Moonshot AI about connecting its Kimi K3 model to U.S. cloud service platforms.</p><p style="text-align: justify;">That piece of news carries a great deal of information.</p><p style="text-align: justify;">The open-source character and low-cost profile of Chinese models are making advanced models more substitutable. That also means barriers built purely on model performance are beginning to loosen.</p><p style="text-align: justify;">Today, when the United States and China discuss cooperation on artificial intelligence, control over frontier models is one of the key issues.</p><p style="text-align: justify;">The problem is that America&#8217;s own frontier models have already developed in a distorted way. That means the negotiation is not, from the outset, a purely technical dialogue. It is a continuation of all the earlier problems: the United States is trying to turn the &#8220;security boundaries&#8221; it has drawn for itself into the default rules of the world. The &#8220;controls&#8221; proposed by the United States are, in substance, an attempt to have China accept an order partly defined by American companies.</p><p style="text-align: justify;">So the real issue is not whether there should be controls. The real issue is who should define the security boundaries of frontier models. Who has the authority to say which models are dangerous and which kinds of behavior should be restricted?</p><p style="text-align: justify;">If these questions are not resolved in a reasonable way, the later stages of negotiation have no real meaning.</p><p style="text-align: justify;">The principles have to be clarified first.</p><p style="text-align: justify;">First, there must be a distinction between genuine security threats and straightforward technological competition.</p><p style="text-align: justify;">The United States has taken Chinese models that are cheaper and more open and directly labeled them as &#8220;security threats.&#8221; That has already moved beyond technological competition and into blockade.</p><p style="text-align: justify;">Anthropic&#8217;s differentiated treatment of users in different regions, and its packaging of commercial competition as a security problem, is one expression of that logic. The problem is simple: if definitional authority sits in the hands of one American company, then its competitors will always be placed on the &#8220;unsafe&#8221; side. What is needed now is a scientific definition that both sides can accept, not a unilateral declaration by a single country or a single company.</p><p style="text-align: justify;">Capabilities that could truly cause severe harm can be jointly tested and jointly restricted. Ordinary model research and ordinary commercial use should not be subject to secret interference. That line must be drawn collectively by the parties involved.</p><p style="text-align: justify;">Second, if the United States wants to talk about rules, it must first prove that the rules are equally effective against its own companies.</p><p style="text-align: justify;">Relevant figures on the American side are already discussing how to get China to agree to restrict &#8220;AI models with dangerous capabilities.&#8221; The question is this: with companies like Anthropic in existence, before the United States asks China to restrict model releases and disclose risks, should it not first investigate its own companies, make public the purposes, scope, and rules of their identification mechanisms, and subject them to third-party audits?</p><p style="text-align: justify;">If American companies can return data without users knowing, skip permission confirmation, and enable automated decision-making by default, while the U.S. government says nothing, then American talk about &#8220;security boundaries&#8221; is empty.</p><p style="text-align: justify;">Only after the United States proves that its safety rules are equally binding on its own model companies can China and the United States move into substantive discussion.</p></blockquote>]]></content:encoded></item><item><title><![CDATA[JD.com and China’s Second EU FSR Blocking Order]]></title><description><![CDATA[On August 19, China&#8217;s Ministry of Justice issued Announcement No.]]></description><link>https://www.geopolitechs.org/p/jdcom-and-chinas-second-eu-fsr-blocking</link><guid isPermaLink="false">https://www.geopolitechs.org/p/jdcom-and-chinas-second-eu-fsr-blocking</guid><dc:creator><![CDATA[Geopolitechs]]></dc:creator><pubDate>Wed, 19 Aug 2026 12:31:18 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!r9cj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ce65d5d-f1be-47b0-b1d3-1fa8572c9666_750x396.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p style="text-align: justify;">On August 19, China&#8217;s Ministry of Justice issued Announcement No. 8 of 2026, declaring that certain investigative measures taken by the European Union in its Foreign Subsidies Regulation (FSR) investigation into JD.com constitute &#8220;improper extraterritorial jurisdiction,&#8221; and prohibiting any organization or individual from implementing or assisting in the implementation of those measures.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!r9cj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ce65d5d-f1be-47b0-b1d3-1fa8572c9666_750x396.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!r9cj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ce65d5d-f1be-47b0-b1d3-1fa8572c9666_750x396.webp 424w, https://substackcdn.com/image/fetch/$s_!r9cj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ce65d5d-f1be-47b0-b1d3-1fa8572c9666_750x396.webp 848w, https://substackcdn.com/image/fetch/$s_!r9cj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ce65d5d-f1be-47b0-b1d3-1fa8572c9666_750x396.webp 1272w, https://substackcdn.com/image/fetch/$s_!r9cj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ce65d5d-f1be-47b0-b1d3-1fa8572c9666_750x396.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!r9cj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ce65d5d-f1be-47b0-b1d3-1fa8572c9666_750x396.webp" width="750" height="396" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8ce65d5d-f1be-47b0-b1d3-1fa8572c9666_750x396.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:396,&quot;width&quot;:750,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:13988,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.geopolitechs.org/i/211848439?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ce65d5d-f1be-47b0-b1d3-1fa8572c9666_750x396.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!r9cj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ce65d5d-f1be-47b0-b1d3-1fa8572c9666_750x396.webp 424w, https://substackcdn.com/image/fetch/$s_!r9cj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ce65d5d-f1be-47b0-b1d3-1fa8572c9666_750x396.webp 848w, https://substackcdn.com/image/fetch/$s_!r9cj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ce65d5d-f1be-47b0-b1d3-1fa8572c9666_750x396.webp 1272w, https://substackcdn.com/image/fetch/$s_!r9cj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ce65d5d-f1be-47b0-b1d3-1fa8572c9666_750x396.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><h4 style="text-align: justify;"><strong><a href="https://www.moj.gov.cn/pub/sfbgw/zwxxgk/fdzdgknr/fdzdgknrtzwj/202608/t20260819_538688.html">Announcement No.8 of the Ministry of Justice of the People&#8217;s Republic of China</a></strong></h4><p style="text-align: justify;">Pursuant to Articles 3 and 6 of the <em>Regulations of the People&#8217;s Republic of China on Countering Improper Extraterritorial Jurisdiction by Foreign States</em>, the Ministry of Justice, together with the Ministry of Commerce and other relevant authorities, has conducted an investigation and determined that certain cross-border investigative practices adopted by the European Union against Chinese entities in its investigation into JD.com under the <em>Foreign Subsidies Regulation</em> constitute measures involving improper extraterritorial jurisdiction.</p><p style="text-align: justify;">No organization or individual shall implement or assist in the implementation of such improper extraterritorial jurisdiction measures.</p><p style="text-align: justify;">This Announcement shall take effect as of the date of publication.</p></blockquote><p style="text-align: justify;">The Ministry of Justice spokesperson also responded to questions from the press, calling on the EU to immediately stop abusing its foreign subsidies investigation tool and warning that, should the EU persist in its course, China will resolutely take countermeasures in accordance with the law.</p><blockquote><h4 style="text-align: justify;"><a href="https://www.moj.gov.cn/pub/sfbgw/gwxw/xwyw/202608/t20260819_538687.html">Ministry of Justice Spokesperson Responds to Questions on the EU&#8217;s Foreign Subsidies Investigation Practices Constituting Improper Extraterritorial Jurisdiction</a></h4><p style="text-align: justify;"><strong>Q: On August 19, 2026, the Ministry of Justice issued an announcement determining that certain cross-border investigative practices adopted by the European Union against Chinese entities in its investigation into JD.com under the Foreign Subsidies Regulation constitute improper extraterritorial jurisdiction. What considerations led to this decision?</strong></p><p style="text-align: justify;"><strong>A:</strong> Recently, in its investigation into JD.com under the Foreign Subsidies Regulation, the European Union has arbitrarily demanded from Chinese entities, on a cross-border basis, extensive and unnecessary information located within China. These are improper demands imposed on the entities concerned and constitute a serious violation of the international rule of law.</p><p style="text-align: justify;">In order to safeguard China&#8217;s sovereignty, security and development interests, and to protect the lawful rights and interests of Chinese citizens, legal persons and other organizations, the Ministry of Justice, pursuant to the <em>Regulations of the People&#8217;s Republic of China on Countering Improper Extraterritorial Jurisdiction</em>, worked together with the Ministry of Commerce and other relevant authorities to identify and assess the EU practices in accordance with the law. It has determined that the aforementioned EU practices constitute measures involving improper extraterritorial jurisdiction, and has required that no organization or individual implement or assist in the implementation of such measures.</p><p style="text-align: justify;">We urge the EU to immediately correct its wrongful practices, stop abusing the foreign subsidies investigation tool, and create a fair, equitable and predictable market environment for companies investing and operating in Europe. Should the EU persist in pursuing this course, China will resolutely take countermeasures in accordance with the law.</p></blockquote><p style="text-align: justify;">Importantly, China has not declared that the EU lacks jurisdiction to review JD.com&#8217;s proposed acquisition, nor has it directly demanded that the European Commission terminate its investigation. What China is objecting to is the Commission extending its investigative powers into Chinese territory by requiring Chinese companies, banks and other institutions to cooperate and provide information that Beijing considers excessively broad in scope. The measure gives JD.com a basis under Chinese law for refusing certain information requests, but it also places the company in a much clearer conflict of laws: providing information to the Commission could violate the Chinese prohibition, while refusing to provide it could lead the Commission to conclude that JD.com has failed to cooperate and draw adverse inferences.</p><p style="text-align: justify;">The investigation stems from JD.com&#8217;s proposed acquisition of German consumer-electronics retailer CECONOMY for approximately &#8364;2.2 billion. CECONOMY owns brands including MediaMarkt and Saturn and operates extensive online platforms and physical retail stores across Europe. The transaction represents an important step in JD.com&#8217;s expansion into the European retail market.</p><p style="text-align: justify;">JD.com notified the transaction to the European Commission on April 17, 2026. On May 28, the Commission <a href="https://germany.representation.ec.europa.eu/nachrichten-und-veranstaltungen/pressemitteilungen/drittstaatliche-subventionen-kommission-leitet-eingehende-untersuchung-zur-geplanten-ubernahme-von-2026-05-28_de?utm_source=chatgpt.com">opened an in-depth investigation</a> under the FSR. The Commission suspects that JD.com may have benefited from preferential financing, tax advantages and grants attributable to the Chinese government. Such support may have enabled JD.com to offer a higher price for CECONOMY and thereby distort the normal competitive process for the acquisition. Following completion of the transaction, JD.com might also use such support, together with its technological and logistics capabilities, to rapidly expand CECONOMY&#8217;s European operations and affect competition in local markets.</p><p style="text-align: justify;">On July 22, the Commission issued JD.com a Statement of Reasons formally setting out its concerns, indicating that the investigation had entered a critical stage. The Commission had originally been expected to decide by October 2 whether to approve the transaction, approve it subject to conditions, or prohibit it.</p><p style="text-align: justify;">JD.com&#8217;s <a href="https://www.reuters.com/world/asia-pacific/no-chinese-subsidies-involved-ceconomy-deal-jdcom-says-2026-05-28/?utm_source=chatgpt.com">response</a> has been that the acquisition will be financed through commercial bank loans and cash generated from ordinary business operations, without subsidies from the Chinese government or any other non-EU government. JD.com has also stated that it has not received any foreign subsidies related to the transaction that could distort competition in the EU market.</p><p style="text-align: justify;">However, JD.com and the Commission are not entirely answering the same question. JD.com is emphasizing that the acquisition financing itself does not involve government subsidies. The Commission&#8217;s inquiry is broader. It is examining not only where the money for the acquisition comes from, but also whether the JD.com group has received preferential loans, tax reductions, government grants or other forms of &#8220;foreign financial contribution&#8221; over the previous three years, and whether such support may have indirectly strengthened JD.com&#8217;s ability to bid for CECONOMY and expand in Europe. Demonstrating that the purchase price will be funded by commercial loans and JD.com&#8217;s own cash therefore does not, by itself, fully address the Commission&#8217;s concerns.</p><p style="text-align: justify;">China&#8217;s latest response did not emerge suddenly. It is the latest step in a gradual escalation of Beijing&#8217;s response to the EU&#8217;s implementation of the FSR. In July 2024, the Ministry of Commerce launched a trade and investment barriers investigation into whether the EU&#8217;s application of the FSR discriminated against Chinese companies. In January 2025, the Ministry reached a final <a href="https://trb.mofcom.gov.cn/mybldc/art/2025/art_4585ba645ce84e12bbf0db43515673f8.html?utm_source=chatgpt.com">determination</a> that the relevant EU practices constituted trade and investment barriers. Among the problems it identified were the disproportionate concentration of investigations on Chinese companies, an excessively broad definition of &#8220;foreign financial contributions,&#8221; heavy evidentiary burdens on companies, and demands for large amounts of information located within China. </p><p style="text-align: justify;">In April 2026, China promulgated the <em>Regulations on Countering Improper Extraterritorial Jurisdiction by Foreign States</em>, establishing a comprehensive framework covering investigation and identification, public announcements, blocking measures and further countermeasures. Under the Regulations, the Ministry of Justice may investigate, together with the Ministry of Commerce and other authorities, whether a foreign measure constitutes improper extraterritorial jurisdiction. Once such a determination is made, organizations and individuals are, in principle, prohibited from implementing or assisting in the implementation of the measure. Chinese citizens and organizations with special needs may apply to the Ministry of Justice for exemptions within a specified scope. </p><p style="text-align: justify;">On May 15, 2026, the Ministry of Justice exercised this authority for the first time. <a href="https://www.moj.gov.cn/pub/sfbgw/gwxw/xwyw/202605/t20260515_535047.html">Announcement No. 5</a> determined that certain cross-border investigative demands made by the EU against Chinese entities in its investigation into Nuctech constituted improper extraterritorial jurisdiction. The Ministry of Commerce subsequently went further, stating that the Commission had not only required the company concerned to provide information, but had also compelled Chinese banking institutions to cooperate with the investigation and demanded substantial amounts of information located in China, some of which had no direct connection to the case.</p><p style="text-align: justify;">I previously <a href="https://www.geopolitechs.org/p/nuctech-case-and-a-clash-between">analysed</a> in detail the measures taken by China&#8217;s MOJ and MOFCOM in response to the EU&#8217;s FSR investigation into Nuctech.</p><p style="text-align: justify;">Announcement No. 8 concerning JD.com uses almost exactly the same language as the announcement concerning the FSR investigation into Nuctech. This suggests that the Chinese government may be developing a repeatable enforcement model. Under the boundary China appears to be drawing, the EU may investigate transactions and business activities occurring in Europe. But when the Commission requires companies, banks, government authorities or other institutions located in China to submit to investigation or provide broad categories of information located in China, Beijing may characterize those demands as improper extraterritorial jurisdiction and prohibit Chinese parties from complying.</p><p style="text-align: justify;">The Announcement does not specify which particular questions, documents or information requests are covered by the prohibition. JD.com therefore cannot simply interpret it as meaning that none of the information requested by the Commission may be provided. It will still need to distinguish among materials generated within the EU, ordinary commercial information already held by the group, information involving third parties in China, and information that requires assistance from Chinese banks, government authorities, suppliers or other companies. The measures most directly affected by the prohibition are more likely to be compulsory investigative demands extending into Chinese territory, rather than the entirety of the EU investigative process.</p><p style="text-align: justify;">China&#8217;s legal position on improper extraterritorial jurisdiction has itself developed gradually. Initially, the position was expressed primarily through diplomacy and international law. China has long argued that a state&#8217;s exercise of extraterritorial jurisdiction must be based on a genuine and reasonable connection with the conduct concerned, and that, without the consent of another state, it cannot directly conduct investigations, collect evidence, freeze assets or compel local companies and institutions to enforce its laws within that state&#8217;s territory. This position is principally grounded in sovereign equality, non-interference and territorial jurisdiction.</p><p style="text-align: justify;">China subsequently began developing domestic blocking instruments. The <em>Provisions on the Unreliable Entity List</em> adopted in 2020 and the <em>Rules on Counteracting Unjustified Extra-territorial Application of Foreign Legislation and Other Measures</em> adopted in 2021 began providing Chinese companies with domestic legal tools for responding to foreign long-arm jurisdiction. At that stage, the principal concern was U.S. secondary sanctions&#8212;in particular, the use of U.S. law to pressure Chinese companies to terminate otherwise lawful transactions with third countries such as Iran and Russia.</p><p style="text-align: justify;">The <em>Anti-Foreign Sanctions Law</em>, adopted in 2021, elevated China&#8217;s countermeasure authority to the level of national legislation and expressly prohibited organizations and individuals from implementing or assisting in the implementation of discriminatory restrictive measures imposed by foreign states against Chinese entities. Article 33 of the <em>Foreign Relations Law</em>, adopted in 2023, then provided a more general authorization for China to take corresponding countermeasures and restrictive measures against conduct that violates international law and basic norms governing international relations and harms China&#8217;s sovereignty, security or development interests.</p><p style="text-align: justify;">By 2026, the <em>Regulations on Countering Improper Extraterritorial Jurisdiction by Foreign States</em> had further institutionalized these principles. For the first time, the Regulations expressly require consideration of whether there is an &#8220;appropriate connection&#8221; between the foreign state and the conduct it seeks to regulate, while establishing mechanisms for investigations, announcements, prohibitions on compliance, case-specific exemptions, countermeasure lists and judicial remedies. The Nuctech and JD.com announcements have now translated those abstract principles into prohibitions directed at specific foreign investigations. China&#8217;s response has therefore evolved from diplomatic protests and statements of principle into a domestic legal regime capable of directly regulating the conduct of companies and other entities.</p><p style="text-align: justify;">The EU, however, is likely to respond that JD.com is seeking to acquire a European company and that the transaction will directly affect the EU market. On that basis, the EU can argue that its review of the transaction has a clear territorial nexus. From the EU perspective, this is therefore not an exercise of long-arm jurisdiction over a Chinese company with no meaningful connection to Europe, but a review necessary to determine whether a transaction taking place in the European market should be permitted.</p><p style="text-align: justify;">The stronger part of China&#8217;s position concerns compulsory demands directed, without China&#8217;s consent, at third parties, banks and other institutions located within Chinese territory for broad categories of domestic information. The EU considers such information requests part of the conditions that companies must accept if they wish to access or complete transactions in the European market. China, by contrast, considers at least some of these demands to amount to compulsory investigative activity conducted within Chinese territory. The two sides therefore have fundamentally different understandings of where the jurisdictional boundary lies. No international court has issued a binding ruling resolving this dispute, but this increasingly appears to be the central point of disagreement between China and the EU.</p><p style="text-align: justify;">For JD.com, the Announcement provides both protection and risk. JD.com can now invoke the Chinese prohibition to refuse at least some information requests involving China, and it may use the Announcement to press the Commission to narrow its requests or accept alternatives such as aggregated data, anonymized information, independent audit reports or materials already available within the EU. But none of this requires the Commission to terminate its investigation.</p><p style="text-align: justify;">Article 16 of the EU <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?qid=1673254237527&amp;uri=CELEX%3A32022R2560&amp;utm_source=chatgpt.com">Foreign Subsidies Regulation</a> allows the Commission, where an undertaking fails to provide requested information, provides incomplete information or otherwise obstructs an investigation, to reach a decision on the basis of &#8220;facts available.&#8221; The outcome may therefore be less favorable than if the company had fully cooperated. The Commission may also suspend the review timetable or draw adverse conclusions from JD.com&#8217;s failure to cooperate.</p><p style="text-align: justify;">The best-case outcome would be for JD.com and the Commission to renegotiate the scope of the information requests, with the Chinese authorities granting specific exemptions for materials that genuinely need to be submitted, or for the parties to agree on alternatives such as aggregated data and third-party audits. JD.com could also offer financing, operational or governance commitments in exchange for conditional approval. If the conflict over information and evidence cannot be resolved, however, the Commission could rely on the facts available and draw adverse inferences, potentially resulting in a lengthy delay or even prohibition of the transaction.</p><p style="text-align: justify;">The JD.com case is in fact more difficult than the Nuctech case. Nuctech was responding to an investigation initiated by the Commission into its market activities. JD.com, by contrast, needs affirmative Commission approval before it can complete the acquisition of CECONOMY. The Commission therefore has direct power to block the transaction, making the commercial cost of refusing to provide information considerably higher for JD.com.</p><p style="text-align: justify;">For other Chinese companies, the two Ministry of Justice announcements mean that responding to FSR investigations can no longer simply be treated as a process in which European counsel coordinates the collection and submission of information from across a global corporate group. Companies will first need to conduct a Chinese-law review: where the requested information is located; whether it involves Chinese banks, government authorities, suppliers or other independent third parties; whether data security, personal information, state secrets or commercial secrets are implicated; and whether the request falls within the &#8220;improper extraterritorial jurisdiction measures&#8221; identified in a Ministry of Justice announcement. Where necessary, companies may also need to consider applying to the Ministry for a specific exemption.</p><p style="text-align: justify;">These requirements will increase the time, cost and uncertainty associated with European acquisitions, public procurement and major investments by Chinese companies. Transaction agreements will increasingly need to allocate FSR-related risks, conflicts over information disclosure, regulatory delays and potential transaction failure through conditions precedent, long-stop dates, regulatory cooperation obligations and termination arrangements.</p><p style="text-align: justify;">The Commission is highly unlikely to accept that a Chinese announcement can restrict the application of EU law. The more interesting question is how its investigative practice may evolve in response. Could the Commission increasingly seek information already held by Chinese companies&#8217; European subsidiaries, rely more heavily on public sources and information from EU-based banks, customers and competitors, accept independent audits or legal opinions, or simply draw conclusions from the facts available when Chinese information cannot lawfully be obtained? Could more cases ultimately be resolved through commitments rather than insisting on access to all underlying materials? Over the longer term, these conflicts may also create pressure for China and the EU to establish more formal arrangements governing the scope of FSR information requests, cross-border evidence gathering and cooperation between their respective authorities.</p>]]></content:encoded></item><item><title><![CDATA[Zhipu AI Co-Founder Tang Jie: Tokens as the Engine of the Intelligent Economy]]></title><description><![CDATA[Today, Qiushi published an article titled &#8220;Driving High-Quality Development of the Intelligent Economy with Tokens as the Engine,&#8221; authored by Tang Jie, co-founder of Zhipu AI and professor in the Department of Computer Science and Technology at Tsinghua University.]]></description><link>https://www.geopolitechs.org/p/zhipu-ai-co-founder-tang-jie-tokens</link><guid isPermaLink="false">https://www.geopolitechs.org/p/zhipu-ai-co-founder-tang-jie-tokens</guid><dc:creator><![CDATA[Geopolitechs]]></dc:creator><pubDate>Sun, 16 Aug 2026 17:58:04 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!03Ri!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d2201e-bf4f-4483-ace6-095a52699ad7_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Today, <em>Qiushi</em> published an article titled &#8220;Driving High-Quality Development of the Intelligent Economy with Tokens as the Engine,&#8221; authored by Tang Jie, co-founder of Zhipu AI and professor in the Department of Computer Science and Technology at Tsinghua University.</p><p><span>The article&#8217;s core argument is that tokens should not be treated merely as a technical unit through which large models process information, but should become the foundational unit for measuring the production, exchange, and value creation of intelligent services. The development of the intelligent economy depends on three factors: model intelligence level, which determines the intrinsic worth of each individual token; API call volume, which determines the market scale of intelligent services; and intelligent conversion efficiency, which determines whether tokens can actually translate into productivity gains, enterprise revenue, and economic growth.<br><br>The author argues that China has built meaningful advantages through domestically developed open-source models, low-cost services, and sheer volume of API calls, but that a large proportion of token consumption remains concentrated in low-value scenarios such as chat and image generation, while fundamental model innovation and application in high-value domains like industrial manufacturing and scientific research remain insufficient. The next step should not be to pursue call volume growth alone, but to simultaneously raise model capability and the rate of conversion into the real economy, while working to establish measurement, pricing, trading, and governance rules for tokens. That said, tokens from different models are not fully comparable, and growth in call volume does not necessarily represent growth in economic value &#8212; which is precisely why intelligent conversion efficiency matters more than raw token counts.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!03Ri!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d2201e-bf4f-4483-ace6-095a52699ad7_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!03Ri!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d2201e-bf4f-4483-ace6-095a52699ad7_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!03Ri!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d2201e-bf4f-4483-ace6-095a52699ad7_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!03Ri!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d2201e-bf4f-4483-ace6-095a52699ad7_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!03Ri!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d2201e-bf4f-4483-ace6-095a52699ad7_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!03Ri!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d2201e-bf4f-4483-ace6-095a52699ad7_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/24d2201e-bf4f-4483-ace6-095a52699ad7_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2372462,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.geopolitechs.org/i/211449225?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d2201e-bf4f-4483-ace6-095a52699ad7_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!03Ri!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d2201e-bf4f-4483-ace6-095a52699ad7_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!03Ri!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d2201e-bf4f-4483-ace6-095a52699ad7_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!03Ri!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d2201e-bf4f-4483-ace6-095a52699ad7_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!03Ri!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d2201e-bf4f-4483-ace6-095a52699ad7_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><span>Full translation of the article is available:</span></strong></p><p><strong><a href="https://www.qstheory.cn/20260815/c5e9a814270d4d30ba6ec17c7d5c05eb/c.html">Qiushi | Tang Jie: Driving High-Quality Development of the Intelligent Economy with Tokens as the Engine</a></strong></p><p>Recently, Qiushi published an article by Tang Jie, professor in the Department of Computer Science and Technology at Tsinghua University, titled &#8220;Driving High-Quality Development of the Intelligent Economy with Tokens as the Engine.&#8221; &#8220;Tsinghua Humanities and Social Sciences&#8221; hereby reposts the article for readers.<br><br><strong>Driving High-Quality Development of the Intelligent Economy with Tokens as the Engine<br><br>Tang Jie</strong><br><br>On July 17, General Secretary Xi Jinping delivered a keynote speech at the opening ceremony of the 2026 World Artificial Intelligence Conference and High-Level Meeting on Global AI Governance. He stressed the need to &#8220;comprehensively promote scientific and technological innovation, industrial development, and scenario-based application of artificial intelligence,&#8221; and to &#8220;empower all industries with artificial intelligence.&#8221; At present, the intelligent economy, mainly supported by large models and agents, is rapidly reshaping the global economic structure. Tokens, as the basic unit of AI-generated content, have gone beyond being a purely technical concept and are becoming a new type of data element that promotes the development of China&#8217;s intelligent economy. They are not only bringing changes to the business model of the AI industry, but also opening up new growth space for future industries characterized by intelligence. We should uphold innovative thinking and a systems perspective, better leverage the multiplier effects of model intelligence level, application programming interface (API) call volume, and intelligent conversion efficiency, allow tokens to generate richer economic value, and better promote the high-quality development of China&#8217;s intelligent economy.<br><br>I. What Are Tokens?<br><br>Tokens originate from natural language processing and are currently the smallest unit through which large models process information. As a bridge connecting human natural language with machine intelligence computation, tokens are becoming a core indicator for measuring the transaction volume of intelligent services and a micro-level carrier for value creation in the intelligent economy. They have clear attributes of productivity.<br><br>First, tokens are measurable, priceable, and tradable, thereby restructuring the mechanism that connects technology supply with business demand. As the statistical unit for the scale of large model calls, tokens precisely quantify the consumption of intelligent services. As a billing unit, they push the software business model to shift from traditional licensing and subscription toward on-demand calling, making intelligent services available like water and electricity, and providing a clear quantitative basis and transaction possibility for the large-scale implementation of the AI industry.<br><br>Second, tokens are dynamically generated, high-density data elements. Unlike traditional data, which serve as static records and production factors, tokens represent knowledge that is being generated and activated by models. They include not only textual semantic slices, but also vectorized expressions of multimodal information such as images, audio, and video. They contain the model&#8217;s reasoning, generation, and decision-making processes in specific tasks, and are an intelligent form created after data elements are processed by large models, which can directly serve production and daily life.<br><br>Third, tokens have long-term stability and technological neutrality, and possess the attributes of a value anchor and measurement language in the intelligent era. Tokens are not tied to a specific technological route or a single vendor, and are highly universal. Just as the &#8220;barrel&#8221; in the oil era and the &#8220;kilowatt-hour&#8221; in the electricity era served as key units, mastering the token as a unit of measurement is essentially equivalent to mastering the right to define and measure the infrastructure of the intelligent economy. Establishing a digital economy foundation based on tokens is of great significance for China to gain standard-setting power and pricing leadership in global intelligent economy competition.<br><br>II. Three Dimensions of Tokens as an Engine for Intelligent Economy Development<br><br>Tokens promote the vigorous development of the intelligent economy through their full penetration into production, life, industry, and commerce. They not only give rise to AI-native new business forms such as agent services and &#8220;one-person companies,&#8221; but also create tokenized value increments as AI empowers existing industries, and restructure the value chains and collaboration-distribution methods of existing industries. The effectiveness of tokens&#8217; contribution to the development of the intelligent economy is mainly determined by three factors: model intelligence level, API call volume, and intelligent conversion efficiency.<br><br>The model intelligence level determines the intelligence density and value content carried by a single token. The higher the model intelligence level, the stronger the logic, accuracy, and creativity of the generated tokens, the more significant their ability to solve complex problems and assist scientific decision-making, and the higher the use value of the generated content. Model intelligence level can be measured by performance in benchmarks covering comprehensive knowledge, complex reasoning, code engineering, multimodal processing, and autonomous execution by agents. Since last year, the iteration speed of mainstream large models worldwide has accelerated, continuously refreshing benchmark scores. These test results provide an important reference for observing the relative intelligence levels of different models.<br><br>API call volume is the scale foundation of the intelligent economy. It measures model computing power consumption and data throughput, and reflects the popularity of large models and the activity level of the AI industry. At present, major model vendors around the world all provide API services billed by call volume and actively open them to industry. Through APIs, tokens flow across different industries, regions, and organizations, becoming the main way for intelligent elements to be allocated across scenarios. Overseas users can also remotely call models and computing power within China through APIs to obtain inference services and pay according to token consumption, thereby realizing the &#8220;export of tokens.&#8221;<br><br>Intelligent conversion efficiency reflects the rate of value realization in the intelligent economy. It measures the conversion effectiveness between token generation and economic value creation, and is closely related to factors such as the penetration rate of model applications in industries and their adaptability in scenarios. The higher a model&#8217;s intelligence level, the deeper its integration with industries, and the stronger users&#8217; human-machine collaboration capabilities, the more economic value can be produced with less token consumption, achieving higher intelligent conversion efficiency. Higher intelligent conversion efficiency means that tokens can more accurately match industrial needs, deeply integrate with a wide range of industries, promote expansion, cost reduction, and efficiency improvement, more fully drive productivity enhancement and economic benefit growth, and complete the value loop of the intelligent economy.<br><br>The three factors above &#8212; model intelligence level, API call volume, and intelligent conversion efficiency &#8212; shape the activity characteristics of workers using AI for production and economic value creation from three dimensions: tool quality, behavioral scale, and output effectiveness. When large models are deeply integrated with industrial scenarios, tokens can transform from digital costs into intelligent assets. Their growth-driving effect will be reflected in the intelligent economy through improved production efficiency, better service quality, and the emergence of new business forms, opening broader, more practical, and more sustainable growth space for future industries.<br><br>III. New Characteristics of China&#8217;s Intelligent Economy Development Driven by Tokens<br><br>At present, the token-driven development of China&#8217;s intelligent economy already has notable advantages such as leading overall scale and rich application scenarios. It is showing clear characteristics including volume explosion, deeper application, structural optimization, and model innovation, driving China&#8217;s intelligent economy to accelerate from a stage of concept popularization into a stage of large-scale value creation.<br><br>The comprehensive competitiveness of domestic open-source models continues to make new breakthroughs, and their ability to serve the intelligent economy through token supply has significantly strengthened. In April this year, a domestic large model ranked first globally in a professional software engineering benchmark, surpassing U.S. closed-source flagship models from the same period. In June, on a front-end development evaluation system involving blind testing by one million users worldwide, a domestic large model again ranked first among globally available models. Unlike the U.S. government&#8217;s ban on foreign entities accessing its leading closed-source models, domestic large models have firmly upheld openness and open source, providing high-quality, accessible, and trustworthy large model services to global users. At the same time, the service prices of domestic open-source models also have cross-order-of-magnitude advantages compared with the flagship versions of U.S. closed-source models. The narrowing technological gap, extreme cost-performance advantage, and stable openness together form the core support for the comprehensive competitiveness of domestic models.<br><br>API call volume has exploded exponentially, making China the world&#8217;s largest token consumption market. Over the past two years, China&#8217;s large model applications have rapidly become widespread, the agent ecosystem has accelerated in development, and token call volume has grown explosively. This is a direct reflection of China&#8217;s ultra-large-scale market advantage in the intelligent economy. At the beginning of 2024, China&#8217;s average daily token call volume was 100 billion; by the end of 2025, it had jumped to 100 trillion; and in March 2026, it exceeded 140 trillion, representing growth of more than a thousandfold in two years. According to statistics from OpenRouter, a global large model aggregation platform, since late April 2026, the weekly token call volume of Chinese large models has exceeded that of the United States for three consecutive months and remained first globally. This explosive growth marks the formation of a massive intelligent consumption market in China, making China one of the most active and promising token consumption centers in the global intelligent economy.<br><br>Application scenarios are moving from conversational interaction into production processes, and the path of intelligent conversion is becoming increasingly clear. By being embedded into specific production, service, and trade processes, tokens are converted into visible and real economic increments. This reflects the evolution of the intelligent economy from being pushed unidirectionally by the technology supply side toward being pulled by value validation on the demand side. In enterprise-level applications, new application forms such as intelligent R&amp;D assistants and intelligent operations hubs continue to emerge, and token consumption is accelerating its embedding into core business processes and high-value links. Some analysis reports show that in the second half of 2025, China&#8217;s average daily token call volume for enterprise-level large models rose to 3.6 times the level of the first half of the year. Since 2025, the revenue of China&#8217;s major model companies has increased substantially, also showing that model-as-a-service platforms can directly convert token consumption into measurable business revenue through API call pricing, and leading models are achieving both volume and price growth.<br><br>At present, although China&#8217;s intelligent economy is developing rapidly, using tokens as the engine to promote high-quality development of the intelligent economy still faces some constraints. First, improvement in model intelligence level faces bottlenecks, with an emphasis on engineering optimization but insufficient breakthroughs in principles. There remain gaps with international leading levels in autonomous reasoning, long-range planning, multimodal integration, safety alignment, and other areas, while innovation in basic theories, underlying technologies, and core algorithms remains insufficient. Second, token calls face structural contradictions. Consumer-level applications such as chat and text-to-image generation have large call volumes but low commercial returns. Although the market for small and medium-sized enterprise-level applications is growing rapidly, its overall penetration rate still needs improvement. A large amount of high-value calls remains inside closed enterprise systems and has not been converted into dividends for the open platform API ecosystem. Third, the conversion rate from token output to real-economy value is not high, especially in high-value-added fields such as industrial manufacturing and scientific research innovation, where penetration remains low. Only by properly solving these problems can tokens further play their role as an engine and inject stronger driving force into the development of China&#8217;s intelligent economy.<br><br>IV. Fully Leveraging the Role of Tokens as an Engine for Driving High-Quality Development of the Intelligent Economy<br><br>The &#8220;15th Five-Year Plan&#8221; period is an important strategic window for China&#8217;s AI development to shift from technological explosion to mature application. The endogenous growth momentum of the intelligent economy comes from the positive feedback loop of &#8220;intelligence level &#8212; API call volume &#8212; intelligent conversion efficiency.&#8221; We should closely follow the engine function of tokens, raise the intelligence ceiling for token value release, expand the usage scale of generated token content, improve the integration level between tokens and the real economy, and build a governance system suited to this process, so as to promote the transformation and upgrading of China&#8217;s intelligent economy from scale leadership to quality leadership.<br><br>Raise the intelligence ceiling and improve the model intelligence level. Intelligence level is essentially a reflection of the accumulation of general-purpose technological capital. Investment in intelligence level is the accumulation of intelligent capital stock, and its returns have the characteristic of long-term increase. More attention should be paid to the leap from perceptual intelligence to cognitive intelligence, vigorously promoting original innovation in model architectures and algorithms, and seeking breakthroughs in long-range task capabilities of large models, autonomous agent systems, self-evolution, and autonomous training. We should accelerate the construction of high-quality, multimodal Chinese corpora and knowledge bases covering key industries, and explore safe and compliant data sharing and &#8220;data elements &#215;&#8221; models. Policy guidance and institutional supply should be strengthened, universities, research institutes, and leading enterprises should be supported in jointly carrying out frontier basic research, funding support for large model R&amp;D, computing power construction, and data element markets should be increased, the intellectual property system should be improved, and innovation vitality should be stimulated.<br><br>Innovate service models and expand API call volume. API call volume is essentially the demand scale for the new consumer good of &#8220;intelligence as a service.&#8221; An increase in user numbers will accelerate model improvement, and model improvement will in turn attract more users, forming demand-side economies of scale. The cost of model access and switching should be reduced, differentiated pricing should be implemented, and a more mature API market should be cultivated. An independently controllable &#8220;model-chip-energy integrated&#8221; AI infrastructure should be built, and the construction and intensive, efficient use of a nationwide integrated computing power network should be advanced. An open-source and open high-performance computing power service platform should be built, the API service ecosystem should be continuously optimized, and inclusive computing power support should be provided to a wide range of small and medium-sized enterprises. Agents should be vigorously developed, and large-scale application of agents in various vertical fields should be encouraged, so that agent clusters capable of autonomous driving, collaborative operations, and round-the-clock functioning become a new industrial form, truly moving from &#8220;intelligent assistants&#8221; to &#8220;digital employees.&#8221; Token measurement and trading markets should be improved, unified token measurement standards and trading rules should be established more quickly, and the production, circulation, and consumption of tokens should be further activated.<br><br>Strengthen scenario guidance and improve intelligent conversion efficiency. As tokens penetrate from the consumer side into the production side, they are concentrated in the early stage in standardized tasks that are easy to mass-produce, such as copywriting generation and code completion. In the later stage, they need to solve &#8220;last-mile&#8221; adaptability problems involving industry knowledge, business processes, and regulatory constraints. The key to improving intelligent conversion efficiency lies in designing a &#8220;token-task&#8221; matching mechanism, so that token production is as close as possible to value creation scenarios. With advanced manufacturing clusters, national-level economic and technological development zones, and pilot free trade zones as key areas, and modern agricultural industrial parks and modern service industry clusters as broader extensions, industrial and enterprise business processes should be systematically reviewed. Token-driven solutions should be developed for pain points and bottlenecks, a number of benchmark scenarios for the intelligent economy should be created, and intelligent conversion efficiency should be improved. An evaluation system for intelligent economy conversion efficiency should be built, and efforts should be made to explore incorporating new indicators such as the GDP-driving effect per unit of token consumption and AI penetration rates in key industries into the national statistical system.<br><br>Strengthen governance support and build an ecosystem for the sustained and healthy development of the intelligent economy. Focusing on property rights, transactions, and risks, a token governance system that is incentive-compatible, balances public and private interests, and has clear rights and responsibilities should be built more quickly. Alignment capabilities suited to model intelligence levels should be built in parallel. National laws and regulations, social norms, morality, and ethics should be written into models&#8217; value functions as underlying axioms, ensuring that AI technology promotes the intelligent economy toward good. A sound algorithm security regulatory system should be established to prevent risks such as algorithmic discrimination, privacy leaks, and the spread of false information. Openness and cooperation should be upheld, active participation in the formulation of global AI governance rules should be pursued, and an open, fair, and non-discriminatory international environment for intelligent economy development should be promoted.</p>]]></content:encoded></item><item><title><![CDATA[How (some) Chinese AI Practitioners View Model Distillation]]></title><description><![CDATA[A LatePost piece: The Distillation Storm: The Technical Race AI Companies Don&#8217;t Want to Discuss in Public]]></description><link>https://www.geopolitechs.org/p/how-some-chinese-ai-practitioners</link><guid isPermaLink="false">https://www.geopolitechs.org/p/how-some-chinese-ai-practitioners</guid><dc:creator><![CDATA[Geopolitechs]]></dc:creator><pubDate>Thu, 13 Aug 2026 22:27:04 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!JJPm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1889b7e4-753c-4094-8a29-5d98239650a6_702x437.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em><strong>This is a translation of a piece by LatePost (&#26202;&#28857;), a Chinese tech media outlet known for its close sourcing within China&#8217;s internet and AI industry. The article draws on interviews with nearly ten researchers and practitioners at various Chinese AI companies, combined with public research and technical reports, to reconstruct the history and current state of model distillation &#8212; what it actually is, how industrial-scale distillation works, and whether it can be a lasting competitive advantage.</strong></em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JJPm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1889b7e4-753c-4094-8a29-5d98239650a6_702x437.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JJPm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1889b7e4-753c-4094-8a29-5d98239650a6_702x437.png 424w, https://substackcdn.com/image/fetch/$s_!JJPm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1889b7e4-753c-4094-8a29-5d98239650a6_702x437.png 848w, https://substackcdn.com/image/fetch/$s_!JJPm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1889b7e4-753c-4094-8a29-5d98239650a6_702x437.png 1272w, https://substackcdn.com/image/fetch/$s_!JJPm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1889b7e4-753c-4094-8a29-5d98239650a6_702x437.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JJPm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1889b7e4-753c-4094-8a29-5d98239650a6_702x437.png" width="702" height="437" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1889b7e4-753c-4094-8a29-5d98239650a6_702x437.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:437,&quot;width&quot;:702,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:26329,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.geopolitechs.org/i/211103252?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1889b7e4-753c-4094-8a29-5d98239650a6_702x437.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!JJPm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1889b7e4-753c-4094-8a29-5d98239650a6_702x437.png 424w, https://substackcdn.com/image/fetch/$s_!JJPm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1889b7e4-753c-4094-8a29-5d98239650a6_702x437.png 848w, https://substackcdn.com/image/fetch/$s_!JJPm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1889b7e4-753c-4094-8a29-5d98239650a6_702x437.png 1272w, https://substackcdn.com/image/fetch/$s_!JJPm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1889b7e4-753c-4094-8a29-5d98239650a6_702x437.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong><a href="https://mp.weixin.qq.com/s/m9Q_YMwX_TNbs2KvxFWO8g">The Distillation Storm: The Technical Race AI Companies Don&#8217;t Want to Discuss in Public</a></strong></h3><p>Original by the LatePost Team (&#26202;&#28857;&#22242;&#38431;)<br>August 13, 2026<br><br>By Cheng Manqi (&#31243;&#26364;&#31098;) | Edited by Song Wei (&#23435;&#29614;)<br><br>No one wants to talk about it publicly, but everyone is quietly watching it.<br><br>Some see it as an unseemly act of theft. Others believe it has been stigmatized by a small number of leading companies for their own benefit, and that in itself it is merely an optimization method.<br><br>Over the past several months, many loose threads in the AI field have pointed to the same node: distillation.<br><br>The changes and events connected to it include open-source models closing in on the strongest closed-source models; 77 U.S. companies signing an open letter opposing rushed restrictions on open-source models; Anthropic twice accusing Chinese companies of using large numbers of fraudulent accounts to extract data; a $1.5 billion copyright settlement; and ByteDance&#8217;s founder&#8217;s direct response at a ByteDance Seed all-hands meeting about &#8220;not distilling.&#8221;<br><br>This technology, which has existed for many years, has been repeatedly mentioned, discussed, misunderstood, and distorted in 2026. What exactly is distillation? How is large-scale distillation carried out? Can distillation become a moat for a model development team? And what is its cost?<br><br>We interviewed nearly ten researchers and practitioners in the model field from different companies, and combined those interviews with public research and technical reports, to reconstruct the past and present of distillation, as well as the further changes it is bringing.</p><p>The starting point of distillation: compression, not getting stronger<br><br>Distillation is not plagiarism. It is not stealing software code, and it cannot directly obtain another model&#8217;s weights or its complete training data.<br><br>The kind of distillation now at the center of controversy &#8212; that is, distillation that makes a model stronger &#8212; is technically a way to obtain high-quality data: repeatedly ask a stronger &#8220;teacher model&#8221; questions, get answers, and then use these question-answer data pairs to train another &#8220;student model,&#8221; so that the latter reaches similar performance.<br><br>The idea of distillation has been around for a long time. In 2015, Geoffrey Hinton, who had recently joined Google Brain, published &#8220;Distilling the Knowledge in a Neural Network&#8221; together with Jeff Dean, then head of Google Brain, and the young researcher Oriol Vinyals. It was the first time earlier ideas such as model compression, which had appeared in 2006, were summarized under the term &#8220;distillation.&#8221;<br><br>At that time, Google was still nearly two and a half years away from proposing the Transformer architecture, which is now the foundation of large language models. Hinton and his co-authors applied the idea of distillation to image recognition models. Their method was to have the student model learn the probability distribution output by the teacher model. For example, recognizing that a cat is a cat is, for deep learning, a statistical process: 0.7 cat, 0.2 fox, 0.1 dog &#8594; cat.<br><br>The student model can see this set of probability distributions output by the teacher. This is learning the &#8220;logits,&#8221; in what is called &#8220;soft distillation.&#8221; Logits are a set of raw scores; after Softmax conversion, they become a probability distribution.<br><br>Soft distillation is usually &#8220;white-box distillation,&#8221; because it requires the teacher model&#8217;s output probabilities to be fully open to the student model.<br><br>This kind of distillation usually happens within the same organization. Its purpose is not to make a model stronger, but to &#8220;compress&#8221; it &#8212; to use a smaller-parameter model to approximate the capabilities of a larger-parameter model. Some performance is lost, but inference becomes faster and cheaper.<br><br>Even today, &#8220;compression&#8221; remains one of the most typical uses of distillation. In autonomous driving, for example, companies first build a stronger cloud-based large model, and then use methods such as distillation and pruning to turn it into a smaller model that can run on in-car chips. Companies including Li Auto (&#29702;&#24819;) and XPeng (&#23567;&#40527;) have such practices.<br><br>A more recent example is DeepSeek-R1 in early 2025. At that time, DeepSeek also released six small distilled models. Their teacher model was R1 itself, with 671 billion total parameters. Among the student models, four used Alibaba&#8217;s Qwen2.5 as the base, and two used Meta&#8217;s Llama 3 as the base. The smallest had 1.5 billion parameters, and the largest had 70 billion.<br><br>DeepSeek first had R1 generate about 600,000 pieces of reasoning data in the format of &#8220;question&#8211;reasoning process&#8211;answer,&#8221; along with about 200,000 pieces of non-reasoning data. It then used these data in the post-training stage to supervised fine-tune six small base models. All of these models gained stronger reasoning abilities.<br><br>LatePost previously reported that after the 2026 Spring Festival, Guo Daya (&#37101;&#36798;&#38597;), one of the core authors of R1, joined ByteDance Seed.</p><p>&#8220;Industrial-scale distillation attacks&#8221;<br><br>When used for compression, distillation is a neutral technical method. But by February 2026, Google and Anthropic had both published articles that used &#8220;distillation&#8221; together with &#8220;attack,&#8221; directly accusing some companies of using distillation for unfair competition.<br><br>Google viewed this as a form of IP theft:</p><p>Over the past year, &#8220;distillation attacks&#8221; have increasingly been used as a means of intellectual property theft.<br>&#8212; GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use</p><p>Anthropic said in February and June that DeepSeek, Moonshot AI (&#26376;&#20043;&#26263;&#38754;, Kimi), MiniMax, and Alibaba Qwen (&#38463;&#37324;&#21315;&#38382;) had used roughly 50,000 fraudulent accounts to conduct more than 44.8 million interactions with Claude, attempting to extract Claude&#8217;s capabilities. The February document was titled &#8220;Detecting and preventing distillation attacks&#8221;; the June claim appeared in Anthropic&#8217;s letter to the U.S. Senate. The companies mentioned did not respond directly.<br><br>How did distillation of leading closed-source models come to be carried out at large scale? The source of the change is still technical. There are three lines of development.</p><p>From soft distillation to hard distillation, from white-box to black-box<br><br>In 2016, Yoon Kim, then a PhD student at Harvard, and his adviser Sasha Rush proposed sequence-level knowledge distillation, applying the method that had first been used in image recognition to the language task of translation.<br><br>Sequence-level distillation no longer learns the probability distribution output by the model at each step. Instead, the teacher model first generates high-quality translations, and then the student model learns the complete &#8220;source text&#8211;translation&#8221; sequence pairs.<br><br>This technique was originally proposed to compress large translation models and improve decoding speed. But it also had another effect: distillation no longer needed to know the teacher model&#8217;s step-by-step probability distribution. It could be done by looking only at the &#8220;final answer.&#8221;<br><br>This is &#8220;hard distillation.&#8221; It can be done in a black-box way, meaning that one only needs to call an API and directly obtain the teacher model&#8217;s answer.<br><br>Sasha Rush later joined the AI programming company Cursor in March 2025. In June this year, Cursor was acquired by SpaceXAI &#8212; the new name after the merger of SpaceX and xAI &#8212; for $60 billion, and the team has already been integrated.</p><p>The rise of reasoning models<br><br>In September 2024, just as discussion was spreading about the Scaling Law hitting a wall, OpenAI released the o1 reasoning model. o1 brought two changes.<br><br>Large-scale reinforcement learning in the post-training stage could teach a model to form reasoning strategies. And at the inference stage &#8212; that is, the stage when the model is being used &#8212; more test-time compute could allow the model to generate longer chains of thought when answering complex questions, and thus continue improving performance.<br><br>Both changes amplify the effect of distillation. Large-scale distillation is a method mainly used in the post-training stage; as the importance of post-training rises, the return on investment from distillation also rises. At the same time, test-time compute allows the model, in addition to producing a final answer, to also produce long reasoning processes &#8212; chains of thought, tool calls, search processes, correction processes. These outputs can be used as raw material for distillation data.<br><br>Four months later, the distillation process disclosed by DeepSeek in the R1 technical report showed in more detail the mechanism by which distillation makes models stronger. R1 had several specific practices and findings.<br><br>The distillation process mainly used &#8220;question&#8211;reasoning process&#8211;answer&#8221; data pairs generated by R1. This is currently the ideal state for distillation, and it works better than data pairs that contain only question and answer.<br><br>When releasing R1, the highly open DeepSeek directly displayed the full chain of thought, saying it &#8220;hoped to help the community distill better small models.&#8221;<br><br>By contrast, leading closed-source model companies, including OpenAI, Anthropic, and Google DeepMind, have always hidden full chains of thought and reasoning traces from users. That is why practitioners often say, when talking about distillation, that &#8220;so-and-so cracked so-and-so&#8217;s chain of thought.&#8221;<br><br>This Monday, August 10, researchers from the University of T&#252;bingen in Germany and other institutions released a paper titled &#8220;Stealing Reasoning Traces from Proprietary LLM APIs,&#8221; showing some methods they had found for reconstructing reasoning traces. The research website is stolen-thoughts.com.<br><br>In fact, this has not been a secret for a long time. Even if closed-source model companies deliberately hide them, chains of thought and reasoning traces can still be reconstructed through technical means. The essential reason is that they are all part of model output &#8212; products of the model usage stage. As long as you use a model, chains of thought and reasoning processes are generated and leave traces. This still belongs to black-box distillation and hard distillation.<br><br>Another finding from R1 about distillation is that in the post-training stage, direct distillation brings greater improvement than having the model do reinforcement learning on its own.<br><br>At the time, DeepSeek ran a controlled experiment using Qwen2.5-32B. After more than 10,000 steps of large-scale reinforcement learning on Qwen-32B-Base, the resulting model scored 47.0% on AIME 2024, a benchmark that evaluates mathematical problem-solving ability. After supervised fine-tuning Qwen-32B-Base with 800,000 pieces of data generated by R1, the resulting model scored 72.6% on AIME 2024, more than 25 percentage points higher than the RL method.</p><p>&#8220;We demonstrate that the reasoning patterns of larger models can be distilled into smaller models, resulting in better performance compared to the reasoning patterns discovered through RL on small models.&#8221;<br>&#8212; R1 technical report</p><p>Although this was the result of a specific experiment and may not generalize to all situations, it is still an attractive finding. Long-step reinforcement learning is inherently more difficult than supervised fine-tuning. It places more demands on infrastructure, is often slower, and has higher compute costs.<br><br>DeepSeek made public a relatively economical, efficient, and deterministic way to improve the reasoning ability of smaller or weaker models.<br><br>Several practitioners said that some recent practices mainly use supervised fine-tuning in the post-training stage, with little or almost no reinforcement learning, and can still achieve very good results.<br><br>It was also after DeepSeek-R1, throughout 2025 and up to now, that Anthropic, OpenAI, Google, and other companies said the &#8220;distillation attacks&#8221; they had detected were increasing.<br><br>During the same period, more exploration of post-training also promoted another form of distillation that is not controversial: on-policy distillation, currently mainly used for merging post-training capabilities.<br><br>The difference between on-policy and off-policy distillation lies in who generates the data. The distillation mentioned earlier, in which a model learns from another closed-source model, is mostly off-policy distillation: the data is generated by the teacher model. On-policy distillation, by contrast, has the student model generate reasoning and answers, while the teacher model provides feedback. The feedback can be the distribution probabilities generated token by token (white-box), or it can be a judgment of the reasoning trace and answer (black-box).<br><br>Since the second half of 2025, Alibaba Qwen, Thinking Machines Lab, and Xiaomi MiMo have all contributed practices and improvements in on-policy distillation.<br><br>In the technical report for MiMo V2-Flash early this year, Xiaomi introduced MOPD, or multi-teacher on-policy distillation. In June, it published a separate paper titled &#8220;Multi-Teacher On-Policy Distillation for Capability Integration in LLM Post-Training.&#8221; The method first trains teacher models in different directions &#8212; math, coding, tool use &#8212; and then has the student model generate its own trajectories and receive feedback from different teachers according to the task. It aims to solve a new post-training problem: if capabilities in multiple directions are directly mixed together for reinforcement learning, they often interfere with each other, with gains in one area coming at the expense of another.<br><br>The technical reports for DeepSeek-V4 and Kimi K3 both said that in the post-training stage, they used MOPD-like ideas to merge multiple expert models.</p><p>Using AI to accelerate AI<br><br>The third line of development in the scaling of distillation is that distillation itself is becoming more automated as AI capabilities grow stronger.<br><br>Return to the key of distillation: &#8220;question&#8211;reasoning process&#8211;answer&#8221; data pairs. The question-asking step can shift from humans to AI. Since 2022, studies such as Self-Instruct have tried to solve the problem that high-quality questions are scarce and expensive.<br><br>In practice, companies can first screen high-quality real questions from authorized user behavior, then expand from these real questions to generate more AI-created questions, which can be used to ask the teacher model more frequently and obtain more answers. It is like starting with some yeast &#8212; real data &#8212; and using it to ferment a larger dough.<br><br>The complete &#8220;question&#8211;reasoning process&#8211;answer&#8221; data pairs can also be rewritten and expanded in this way. This is essentially a basic way of thinking in today&#8217;s AI field: using AI and models to automate and accelerate AI itself.<br><br>Many specific steps in the distillation process can also use AI. These include selecting high-quality questions from massive amounts of real questions, evaluating what counts as high-quality data, and improving the diversity of synthetic data. Some steps can be handled by models. Others can be accelerated and optimized by increasingly powerful AI programming capabilities, which make it faster to build and improve various systems.<br><br>Since 2025, the various methods and practices of large-scale distillation have gradually matured. Its effects and necessity have also become more apparent as the importance of post-training has increased. Discussion around &#8220;distillation&#8221; has also gradually moved beyond the AI technical community. In the process of communication, it has been simplified, misunderstood, and even distorted. Distillation is no longer a purely technical issue. It has moved to the center of the storm.</p><p>Misunderstandings about distillation: it is neither a silver bullet nor a secret<br><br>As mentioned repeatedly above, distillation that makes large language models stronger mainly happens in the post-training stage, and also includes the mid-training stage. But a model&#8217;s overall effectiveness comes from the complete training process, from pre-training to post-training. Pre-training is generally believed to be more important. Distillation is not the most important factor determining a model&#8217;s performance.<br><br>In the DeepSeek-R1 technical report, the same 800,000 pieces of R1 data were used for distillation. After distillation, the Qwen2.5-32B base model scored 72.6% on AIME 2024, higher than the 70.0% scored by the distilled Llama-3.3-70B-Instruct, even though the latter had more than twice as many parameters.<br><br>After K3 was released, Ai2 researcher Nathan Lambert replied to a tweet about K3 topping the Frontend Code Arena ranking, which evaluates front-end coding ability. He said that by this point, the whole &#8220;distillation&#8221; narrative should stop; people should recognize that China is also very good at building models.<br><br>A certain level of pre-training is the foundation that allows Chinese open-source models such as K3, GLM-5.2, and DeepSeek-V4 to achieve their current performance.<br><br>Distillation is often compared to a shortcut. A shortcut usually implies ease and less effort. But in reality, carrying out distillation at large scale today is a relatively complex systems-engineering project.<br><br>Based on descriptions from several practitioners, large-scale distillation has several difficult parts.<br><br>First, a team must be able to call leading models stably, frequently, and at large volume, while also doing user operations. One practice mentioned is to build many relay sites and attract a group of specific users with real usage behavior through discounts or other methods. These users might be advanced programmers, or science and engineering students and researchers who need to handle a large number of research questions. In daily use, they naturally generate high-quality multi-turn questions from real scenarios and real tasks, and then receive model answers. After being screened and processed in certain ways, the data from these questions and answers can serve as the source for fermenting and expanding more data.<br><br>This tests a team&#8217;s operations capabilities, including whether it knows where high-quality users are and how to reach them. It also tests the engineering capability to build such a system. It also requires some ecosystem capabilities, because the whole process may require cooperation with third-party companies or institutions.<br><br>Second is the team&#8217;s own ability to construct high-quality questions and tasks. This requires deep understanding of the tasks, the data, and the performance boundaries of current leading models. It overlaps with some of the capabilities needed for large-model training itself.<br><br>Third is how to use the data well. This requires building a data pipeline: whether the task distribution is reasonable; how to sample, screen, filter, deduplicate, expand, and correct; and how to determine formats and ratios. This pipeline has some measurable optimization indicators, such as what proportion of the raw data obtained can ultimately be used in post-training, and how efficient and high-quality the expansion is. The quality of the data pipeline affects effectiveness, efficiency, and cost.<br><br>Continuous distillation is also very expensive. There are some circulating claims about what companies in the industry are spending and budgeting for distillation this year, ranging from more than $100 million to $1 billion.<br><br>One AI investor said: distillation is not a simple button. It is not that you click once and model performance suddenly leaps forward. There are many implementation problems involved. Distillation also requires calculating return on investment.</p><p>Is distillation a moat for a model team?<br><br>Most of the practitioners we spoke with, whether they came from companies rumored to be doing distillation or from companies that do not distill, held relatively consistent views: for first-tier companies, distillation does not constitute a long-term moat.<br><br>Like many technologies in large models, the ideas and practices of distillation will gradually spread. Personnel movement, open-source sharing, conference exchanges, and third-party service providers looking for more customers all contribute to this. People and information in the AI circle are constantly moving. Researchers repeatedly expressed a similar sentiment: there are no real secrets in the large-model field.<br><br>The competitive advantage brought by a technical method itself is mostly first-mover advantage. Those who do it first will have more experience, but it is not an insurmountable, winner-takes-all moat like a network effect.<br><br>The phenomenon truly seen as having a stronger competitive moat is the &#8220;data flywheel&#8221;: if one company&#8217;s model is strong enough and can reach large numbers of users who use it for difficult tasks, it will receive more high-quality data flowing back. These data are unique, non-public, and unavailable to others. After certain processing, these data can again be used to help train stronger models, which then attract more users to handle harder tasks.<br><br>In this flywheel logic, applications that directly contact users are highly valuable. For example, depending on user agreements and permission settings, applications such as Cursor, Devin, and Manus may be able to obtain more complete data and user behavior than the models they call.<br><br>Yesterday, August 12, after Grok 4.6 was released, Elon Musk (&#39532;&#26031;&#20811;) replied to a tweet saying Devin had integrated Grok 4.6. He said: &#8220;Grok 4.7 will be better than all current models.&#8221; &#8220;The training corpus of SpaceX is so awesome and unique.&#8221; A $60 billion acquisition of Cursor seems to have been worth it.<br><br>The data flywheel also has its own controversies. Model and application companies can obtain data, but can they use those data for training? The more difficult the task and the higher-value the scenario, the more likely customers and users may be to prefer controlling those data themselves. At the same time, as the number of model users continues to expand, user types and scenarios become more diverse. Is it still worth searching for gold in the sand?<br><br>One practitioner believes that in some AI applications that lean toward life assistants, entertainment, and leisure, the vast majority of user-generated data are garbage for training stronger models.</p><p>The internal line of judgment: black box or white box<br><br>The most interesting phenomenon about distillation is this: no one wants to talk about it publicly, but most of the practitioners we spoke with do not believe deep down that it is a shameful practice or one that violates their technical convictions.<br><br>The dividing line in this internal judgment lies between black box and white box.<br><br>The distillation currently being done on closed-source models is all black-box distillation. The data it obtains are data generated during use after these models are released. They are products of the model as a product. Then why can&#8217;t other companies ask this model questions and obtain answers as users? Besides, everyone has paid real money for these questions and answers. Of course, in practice, various methods are used to &#8220;take advantage&#8221; and lower costs.<br><br>The more controversial part here is reasoning traces. Most models hide the full reasoning traces, and the distilling party needs to use some technical means to infer and reconstruct them. But reasoning traces are still products of the model usage stage.<br><br>Anthropic, Google, and OpenAI would say: my user agreement clearly states that other competitors cannot use my model to train and improve their own models.<br><br>But who was sued by The New York Times, accused of copying and using without permission the newspaper&#8217;s archive of journalism accumulated over more than 170 years by generations of reporters, commentators, and authors? OpenAI. Who downloaded huge numbers of books from pirate platforms, was unwilling to pay for any of them, was sued in a class action by several American authors, and just reached a $1.5 billion settlement? Anthropic.<br><br>Even some American AI practitioners believe companies such as Anthropic are being highly hypocritical. It is a bit like the situation in Christopher Nolan&#8217;s new film The Odyssey: you sent the Trojan Horse into Troy, and now your own homeland is being invaded by those who come from the sea.<br><br>Large-scale distillation is a new issue that has emerged after the development of new technology. It is hard to make most people sincerely accept that this is undesirable, unethical, or even shameful and evil just because several companies say it violates their user agreements. Moreover, violating a user agreement does not necessarily constitute legal infringement. This also involves other legal rules, jurisdictional questions, and more.<br><br>In the broadest sense, distillation &#8212; that is, using data to improve a model &#8212; has become ubiquitous.<br><br>A widely circulated way to verify distillation is actually invalid: when you ask a model &#8220;Who are you?&#8221; and Model A says it is Model B, this is not ironclad proof that A distilled B. In the pre-training stage, everyone uses large amounts of public internet data, and much of that data already includes content generated by various models themselves.<br><br>In July this year, Nvidia founder Jensen Huang (&#40644;&#20161;&#21195;) was asked about distillation in an interview with Axios. He said: &#8220;Distillation, learning from AI and learning from other sources of knowledge, is the fundamental principle of intelligence.&#8221;<br><br>For most model companies, including some American model companies, the accelerator on distillation has already been pressed. Few will voluntarily give up distillation in the short term.</p><p>Is it really impossible for distillation to surpass the teacher model?<br><br>We also asked several practitioners this question. Their answers were similar: technically it is not impossible, but there are potential organizational risks.<br><br>Distillation has some inherent technical problems. For example, it may cause the student model to learn some of the teacher model&#8217;s errors, biases, refusal habits, and expression patterns.<br><br>But distillation is only one part of model training. There are many other parts of the complete model training process that can be improved: pre-training data, architecture, algorithms, infrastructure. If multiple optimizations are stacked together, is it possible for a student model to become better than a given teacher model?<br><br>Some studies have shown that on certain specific tasks, student models can surpass teacher models. In December 2024, for example, Microsoft released Phi-4, a 14-billion-parameter model. A large amount of its training data was synthesized by teacher models such as GPT-4o. Phi-4 surpassed GPT-4o on two benchmarks:<br></p><ul><li><p>GPQA, which evaluates graduate- and PhD-level scientific knowledge and reasoning ability: Phi-4 scored 56.1%, while GPT-4o scored 50.6%.</p></li></ul><ul><li><p>MATH, which evaluates mathematical problem-solving and reasoning ability: Phi-4 scored 80.4%, while GPT-4o scored 74.6%.</p></li></ul><p>What is special is that as a small-parameter model, Phi-4 also directly used data generated by teacher models in pre-training. But when training truly large-scale models with trillions of parameters, the pre-training stage requires enormous amounts of data, and it is difficult to use data obtained through distillation. Compared with directly processing web pages, code, and books, calling teacher models one by one to generate data is slow and expensive.<br><br>But this also raises a possibility: when model inference speed increases greatly and prices fall sharply, can distillation &#8212; or data constructed with the help of stronger models &#8212; enter pre-training more often?<br><br>At the same time, can ideas such as multi-teacher distillation also be used to make models stronger? In theory, a student model can learn from different strongest models such as Claude and GPT at the same time. This may bring new technical problems, such as training instability and interference between different capabilities when distilling from different base models.<br><br>More aggressive possibilities include whether the most leading companies can distill their own models to achieve a kind of &#8220;lifting themselves by stepping on their own foot.&#8221;<br><br>From a pure research perspective, &#8220;whether a model using distillation can surpass the teacher model&#8221; is at least a question that remains to be tested and explored.<br><br>Distillation is a relatively economical method that produces results quickly. An athlete can certainly both take stimulants and train diligently. But in reality, the two are often hard to balance, because luck and inertia set in.<br><br>When a team, during a certain stage, puts a relatively large share of its attention and resources into distillation, projects and individuals exploring more uncertain and longer-term directions may not receive enough resources or recognition.<br><br>When someone accuses you of doing something wrong, responding with &#8220;didn&#8217;t you do the same?&#8221; does not resolve the conflict.<br><br>At this moment, open-source models are increasingly approaching the leading closed-source models in performance. It is also an objective fact that the strongest open-source models come from China, while the strongest closed-source models come from the United States.<br><br>Earlier, Zhipu had already been placed on the U.S. Commerce Department&#8217;s Entity List in January 2025. The Intelligence Authorization Act for Fiscal Year 2026, which took effect at the end of the same year, requires DeepSeek to be removed from U.S. intelligence systems, national security systems, and related suppliers.<br><br>By April this year, the U.S. House Committee on Homeland Security and the Select Committee on the Strategic Competition Between the United States and the Chinese Communist Party had begun investigating American companies&#8217; use of Chinese models. They asked Cursor why it used Kimi K2.5 as the base for Composer, and asked Airbnb why it used Alibaba Qwen in its customer service business.<br><br>After Kimi K3 was released on July 16, the U.S. government was reportedly considering restricting or even banning some Chinese open-source models. On July 24, 77 companies and organizations, including Microsoft, Nvidia, Meta, and Fireworks AI, successively signed the open letter &#8220;Open Weights and American AI Leadership,&#8221; opposing rushed restrictions on open-source models.<br><br>Jensen Huang&#8217;s first post on Twitter was sharing this open letter.<br><br>New restrictive measures in recent months are still under discussion and have not yet been implemented.<br><br>Companies including Anthropic, OpenAI, and Google are also taking stricter technical measures to identify and ban accounts suspected of being used for distillation. Anthropic, for example, said it had built classifiers and behavioral fingerprinting systems to identify distillation traffic, detecting cross-account coordination, repeated questioning, and attempts to extract chains of thought. It will also strengthen identity verification for education, research, and startup accounts.<br><br>In the University of T&#252;bingen &#8220;stealing reasoning traces&#8221; study mentioned earlier, the methods used to reconstruct reasoning traces had already been reported by the research team to the relevant closed-source model companies. By the time the researchers uploaded the paper, some of those methods had already stopped working.<br><br>All parties involved are making their own choices and preparations. The changes that follow will affect the entire industrial chain, from compute, cloud services, and infrastructure to models, applications, and customer deployment.<br><br>The storm is still continuing. The next eye of the storm may not necessarily be distillation. Distillation itself is only one method for optimizing models.<br><br>So many companies are investing so many resources and rushing into this intelligence race. What are they doing it for? In the first half of this year, explosive growth in coding and agents reversed market expectations. Further ahead, if the scale and speed of large-model application adoption cannot continue, how will the future of the model R&amp;D race fluctuate? That is a question some others are already watching.</p>]]></content:encoded></item><item><title><![CDATA[Manus Unacquired]]></title><description><![CDATA[On August 11, Manus issued a letter to users stating that it will soon resume operations as an independent company.]]></description><link>https://www.geopolitechs.org/p/manus-unaccquired</link><guid isPermaLink="false">https://www.geopolitechs.org/p/manus-unaccquired</guid><dc:creator><![CDATA[Geopolitechs]]></dc:creator><pubDate>Tue, 11 Aug 2026 18:19:15 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!T6uO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00de52f9-15ec-4dcc-9352-cad194c21376_1080x691.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>On August 11, Manus issued a letter to users stating that it will soon resume operations as an independent company. Some users will need to back up their data before 7:59 a.m. on August 23, 2026, and restore it after 8:00 a.m. on August 25. Jiemian News, citing Manus, provided further details on the scope of the data handling: for some users, data generated on or after December 29, 2025 will be deleted between 8:00 a.m. on August 23 and August 24.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!T6uO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00de52f9-15ec-4dcc-9352-cad194c21376_1080x691.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!T6uO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00de52f9-15ec-4dcc-9352-cad194c21376_1080x691.png 424w, https://substackcdn.com/image/fetch/$s_!T6uO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00de52f9-15ec-4dcc-9352-cad194c21376_1080x691.png 848w, https://substackcdn.com/image/fetch/$s_!T6uO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00de52f9-15ec-4dcc-9352-cad194c21376_1080x691.png 1272w, https://substackcdn.com/image/fetch/$s_!T6uO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00de52f9-15ec-4dcc-9352-cad194c21376_1080x691.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!T6uO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00de52f9-15ec-4dcc-9352-cad194c21376_1080x691.png" width="1080" height="691" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/00de52f9-15ec-4dcc-9352-cad194c21376_1080x691.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:691,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:0,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!T6uO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00de52f9-15ec-4dcc-9352-cad194c21376_1080x691.png 424w, https://substackcdn.com/image/fetch/$s_!T6uO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00de52f9-15ec-4dcc-9352-cad194c21376_1080x691.png 848w, https://substackcdn.com/image/fetch/$s_!T6uO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00de52f9-15ec-4dcc-9352-cad194c21376_1080x691.png 1272w, https://substackcdn.com/image/fetch/$s_!T6uO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00de52f9-15ec-4dcc-9352-cad194c21376_1080x691.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Meta announced its acquisition of Manus on December 29, 2025, in a deal reportedly worth more than $2 billion. In January 2026, China&#8217;s Ministry of Commerce began looking into whether the transaction complied with relevant Chinese laws and regulations. Against this backdrop, Manus&#8217;s announcement that it will &#8220;resume independent operations&#8221; appears to suggest that the transaction or subsequent integration is now entering a separation phase. What users see is a backup-and-restore process; what the company is dealing with behind the scenes is the data and operational relationships established following the transaction.</p><p>This is not a routine product upgrade. Ordinary upgrades typically do not require users to first back up and then restore their data, nor do they usually divide user data based on a specific historical cutoff date. Manus attributed the changes to the &#8220;resumption of independent operations&#8221; and the need to &#8220;comply with regulatory requirements in certain jurisdictions.&#8221; This suggests that the adjustment is more akin to a reset of the company&#8217;s operating structure, data ownership arrangements, or compliance boundaries.</p><p>The December 29, 2025 cutoff is particularly significant. Manus did not explain in its user letter why this date serves as the dividing line. However, the fact that only certain data generated on or after that date needs to be deleted suggests that the regulatory or compliance measures apply specifically to data created during a particular period or under a particular operating structure. What can be said with greater confidence is that Manus appears to have determined that some data generated after that date cannot simply remain in the existing system and must instead be reconnected through a user-initiated backup and restoration process.</p><p>In the short term, the main impact on Manus is likely to be on user trust and experience. AI agent products differ from ordinary chat tools: users may store not only conversation histories, but also task histories, files, project context, and workflows. Even if Manus provides backup and restoration tools, some heavy users are likely to have concerns about data integrity, continuity of historical tasks, and the stability of the service going forward.</p><p><strong>A letter to our users</strong></p><p>Manus will soon resume operations as an independent company.</p><p>As part of this transition, and to comply with regulatory requirements in certain jurisdictions, some users will need to back up their data before 7:59 AM (Singapore time) on August 23, 2026, and then restore starting 8:00 AM (Singapore time) on August 25, 2026, to ensure continued access.</p><p>More information is available in our blog post. We have also provided detailed guidance in the Help Center, including how to check whether you are affected.</p><p>For affected users, here are the key details:</p><p>We will notify you via email and in-app notification. If you registered with an Apple ID or Facebook account, please check your in-app notifications.</p><p>Back up your data anytime between now and 7:59 AM on August 23 (Singapore time). You can back up more than once &#8212; after backing up, you can continue creating new data and simply run the backup again.</p><p>Starting 8:00 AM on August 25 (Singapore time), the restoration portal will open. Restore your data and pick up right where you left off.</p><p>Affected users will not be charged during the transition period, and we will provide a welcome-back bonus.</p><p>If your account is not affected, you don't need to do anything &#8212; just keep using Manus as usual. You will receive an in-app notification confirming this.</p><p>For those who are affected, we understand this is disruptive and we apologize for the inconvenience. Supporting you through this process is our top priority. In addition to the full guide in the Help Center, our support team is available 24/7 to answer any questions.</p><p>Looking ahead, we are incredibly excited about what's coming. We are preparing a range of new features that will once again push the boundaries of what general-purpose AI agents can do.</p><p>Thank you for being with us through this. The best is yet to come.</p>]]></content:encoded></item><item><title><![CDATA[China Issues Preliminary Anti-Dumping Ruling on U.S. and Mexican Pecans ]]></title><description><![CDATA[Setting a 54.3% Rate for U.S. Exporters]]></description><link>https://www.geopolitechs.org/p/china-issues-preliminary-anti-dumping</link><guid isPermaLink="false">https://www.geopolitechs.org/p/china-issues-preliminary-anti-dumping</guid><dc:creator><![CDATA[Geopolitechs]]></dc:creator><pubDate>Mon, 10 Aug 2026 13:35:12 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!3ySV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9843fcb-9d50-4936-ba9f-ffddd099133f_1272x807.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p style="text-align: justify;">On August 10, China&#8217;s Ministry of Commerce (MOFCOM) issued <a href="https://www.mofcom.gov.cn/zwgk/zcfb/art/2026/art_7d3cfb2920ed43f69e56ab0fccbef027.html">Announcement No. 32 of 2026</a>, publishing its preliminary determination in the anti-dumping investigation into pecans imported from Mexico and the United States. MOFCOM preliminarily determined that imports of the products under investigation from both countries were being dumped, that China&#8217;s domestic pecan industry had suffered material injury, and that there was a causal link between the dumping and the injury. </p><p style="text-align: justify;">Pursuant to Articles 28 and 29 of China&#8217;s Anti-Dumping Regulations, MOFCOM decided to impose provisional anti-dumping measures in the form of cash deposits. Beginning August 11, 2026, importers of the products under investigation are required to provide deposits to Chinese Customs based on the deposit rates assigned to the relevant companies in the preliminary determination.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3ySV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9843fcb-9d50-4936-ba9f-ffddd099133f_1272x807.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3ySV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9843fcb-9d50-4936-ba9f-ffddd099133f_1272x807.png 424w, https://substackcdn.com/image/fetch/$s_!3ySV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9843fcb-9d50-4936-ba9f-ffddd099133f_1272x807.png 848w, https://substackcdn.com/image/fetch/$s_!3ySV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9843fcb-9d50-4936-ba9f-ffddd099133f_1272x807.png 1272w, https://substackcdn.com/image/fetch/$s_!3ySV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9843fcb-9d50-4936-ba9f-ffddd099133f_1272x807.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3ySV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9843fcb-9d50-4936-ba9f-ffddd099133f_1272x807.png" width="1272" height="807" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a9843fcb-9d50-4936-ba9f-ffddd099133f_1272x807.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:807,&quot;width&quot;:1272,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:461190,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.geopolitechs.org/i/210602344?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9843fcb-9d50-4936-ba9f-ffddd099133f_1272x807.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3ySV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9843fcb-9d50-4936-ba9f-ffddd099133f_1272x807.png 424w, https://substackcdn.com/image/fetch/$s_!3ySV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9843fcb-9d50-4936-ba9f-ffddd099133f_1272x807.png 848w, https://substackcdn.com/image/fetch/$s_!3ySV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9843fcb-9d50-4936-ba9f-ffddd099133f_1272x807.png 1272w, https://substackcdn.com/image/fetch/$s_!3ySV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9843fcb-9d50-4936-ba9f-ffddd099133f_1272x807.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: justify;">Notably, the case was initiated by MOFCOM on its own initiative rather than in response to a written petition from Chinese domestic producers. MOFCOM relied on the &#8220;special circumstances&#8221; provision under Article 18 of the Anti-Dumping Regulations. Its explanation was that China&#8217;s domestic pecan-growing industry is highly fragmented, has a low level of concentration, and involves a large number of growers, making it costly and difficult for the industry to organize and file an anti-dumping petition itself. The investigating authority therefore initiated the case on its own initiative. The dumping investigation period covered the full year of 2024, while the injury investigation period extended from 2022 through 2024. Separately, on September 25, 2025, China also launched a trade and investment barrier investigation into Mexico&#8217;s restrictive measures targeting China.</p><p style="text-align: justify;">Following the outbreak of U.S.-China trade tensions in 2018, U.S. pecan exports to China were hit hard by retaliatory tariffs and fell sharply from their peak around 2017. In recent years, the U.S. pecan industry has been hoping to regain access to the Chinese market, while Mexico has emerged as an important source of incremental supply. China&#8217;s decision to investigate both countries at the same time therefore carries a clear message that circumvention will not be tolerated: it restricts direct U.S. exports while also putting pressure on Mexico and discouraging attempts to route U.S. products through Mexican processing and supply chains.</p><p style="text-align: justify;">There is also a domestic industrial-policy rationale. China&#8217;s pecan-growing industry remains in the early stages of scaling up. Competition from low-priced imports does not merely put direct downward pressure on domestic prices; it may also discourage new planting and reduce growers&#8217; incentives to make subsequent investments in orchard management. This is an important part of the industry-protection rationale disclosed by MOFCOM.</p><p style="text-align: justify;">One particularly noteworthy detail concerns MOFCOM&#8217;s injury analysis. The investigating authority did not use the aggregated data submitted by the six sampled domestic producers. Instead, it relied on nationwide industry statistics provided by the Research Institute of Non-Timber Forestry under the Chinese Academy of Forestry. MOFCOM explained that the questionnaire responses from the sampled companies contained missing and inconsistent data and therefore could not reasonably reflect the overall condition of the domestic industry. This suggests that the statistical system for China&#8217;s pecan industry remains relatively underdeveloped, and the investigating authority&#8217;s methodology could consequently face questions over procedural compliance.</p><p style="text-align: justify;">No U.S. producer or trader registered to participate in the investigation within the prescribed period. The U.S. Embassy in China registered as an interested party, but no U.S. company participated at the corporate level. As a result, all U.S. companies are subject to a uniform 54.3% cash deposit rate, with no differentiation among companies and no company-specific exceptions. This is the highest rate imposed in the preliminary determination. Once combined with existing tariffs and value-added tax, the resulting import cost will leave Chinese importers with very little economic incentive to continue purchasing U.S. pecans.</p><p style="text-align: justify;">A further consequence is that U.S. companies lost the procedural opportunity to seek lower company-specific rates at the preliminary stage. If U.S. companies participate in the investigation during the subsequent final-determination stage, they could in theory seek review or differentiated rates. However, the across-the-board rate imposed at the preliminary stage has already caused a de facto disruption of trade, and the commercial losses during this interim period are real.</p><p style="text-align: justify;">The situation for Mexico is more complicated because Mexican companies participated in the investigation and therefore received differentiated deposit rates. The two sampled companies&#8212;San Enrique Agricultural Enterprises and Alta Vineyards&#8212;are subject to rates of 23.0% and 17.8%, respectively. Four other cooperating Mexican companies are subject to a 22.2% rate, while other non-cooperating Mexican companies face a 51.6% rate, broadly comparable to the rate imposed on U.S. companies.</p><p style="text-align: justify;">From an industry-incentive perspective, the leading and cooperating Mexican companies secured significantly more favorable treatment by participating in the investigation and therefore retain some possibility of preserving their Chinese orders. Nevertheless, even a 17.8% deposit represents a substantial additional cost and is likely to prompt Chinese importers to put pressure on Mexican suppliers during price negotiations to share part of that burden. For non-cooperating Mexican companies, the 51.6% rate effectively amounts to being priced out of the Chinese market.</p><p style="text-align: justify;">Mexico&#8217;s pecan industry is sizable. Industry estimates put its 2024 production at approximately 129,000 metric tons, broadly comparable to U.S. production. These figures should not be treated as precise customs statistics, as estimates vary depending on whether they are measured on an in-shell or kernel basis and on differences in crop-year definitions. The industry estimate cited here comes from Mundus Agri. Mexico&#8217;s pecan industry has traditionally been deeply integrated with U.S. processing and consumer markets, while China has become an important source of incremental demand in recent years. If Chinese orders contract, Mexican growers could simultaneously face greater competition in the U.S. market and fluctuations in domestic production, with pressure transmitting upstream from exporters to growers and harvesting operations.</p><p style="text-align: justify;">Overall, China&#8217;s approach toward the United States looks more like closing the door, while its approach toward Mexico is more akin to screening: cooperating companies are allowed to retain some market access, while non-cooperating companies are effectively pushed out. </p><p style="text-align: justify;">At the same time, the measure sends a broader signal to the Mexican government: if Mexico unilaterally absorbs the costs of restrictions targeting China as U.S.-China supply chains are reconfigured, Beijing has trade-policy tools with which to respond.</p><div><hr></div><p style="text-align: justify;"><strong>Full translation of the announcement:</strong></p><p style="text-align: justify;"><strong>MOFCOM Announcement No. 32 of 2026<br>Preliminary Determination in the Anti-Dumping Investigation into Imports of Pecans Originating in Mexico and the United States</strong></p><p><strong>Issuing Department:</strong> Trade Remedy and Investigation Bureau<br><strong>Document No.:</strong> MOFCOM Announcement No. 32 of 2026<br><strong>Date of Issuance:</strong> August 10, 2026</p><p>In accordance with the provisions of the <em>Anti-Dumping Regulations of the People&#8217;s Republic of China</em> (the &#8220;Anti-Dumping Regulations&#8221;), on September 25, 2025, the Ministry of Commerce of the People&#8217;s Republic of China (&#8220;MOFCOM&#8221; or the &#8220;Investigating Authority&#8221;) issued Announcement No. 52 of 2025, deciding to initiate an anti-dumping investigation into imports of pecans originating in Mexico and the United States (the &#8220;product under investigation&#8221;).</p><p>The Investigating Authority conducted an investigation into whether dumping existed and the margin of dumping, whether the product under investigation had caused injury to the domestic industry in China and the extent of such injury, as well as the causal relationship between the dumping and the injury. Based on the findings of the investigation and pursuant to Article 24 of the Anti-Dumping Regulations, the Investigating Authority has made a preliminary determination (see Annex 1). The relevant matters are hereby announced as follows:</p><h3>I. Preliminary Determination</h3><p>The Investigating Authority has preliminarily determined that imports of pecans originating in Mexico and the United States are being dumped, that China&#8217;s domestic pecan industry has suffered material injury, and that there is a causal relationship between the dumping and the material injury.</p><h3>II. Collection of Cash Deposits</h3><p>Pursuant to Articles 28 and 29 of the Anti-Dumping Regulations, the Investigating Authority has decided to impose provisional anti-dumping measures in the form of cash deposits.</p><p>Beginning on August 11, 2026, importers of the product under investigation shall, when importing such product, provide corresponding cash deposits to the Customs of the People&#8217;s Republic of China based on the cash deposit rates applicable to the respective companies as determined in this preliminary determination.</p><p>The product under investigation is specifically described as follows:</p><p>Scope of investigation: Imports of fresh or dried pecans originating in Mexico and the United States.</p><p>Name of the product under investigation: Fresh or dried pecans (American pecans; thin-shelled hickory nuts).</p><p>Foreign-language/scientific name: <em>Carya illinoensis</em>.</p><p>Product description: Seeds of the thin-shelled hickory, genus <em>Carya</em>, family Juglandaceae; fresh pecans, or nuts produced from pecan fruits through processes including sorting and drying, whether or not shelled or peeled, principally intended for human consumption.</p><p>Principal uses: Pecans may be consumed raw or roasted, used in the preparation of various pastries and other foods, or processed for oil extraction.</p><p>The product is classified under tariff heading 08029990 of the <em>Import and Export Tariff of the People&#8217;s Republic of China</em>. Other products classified under this tariff heading are not covered by this investigation.</p><p>The cash deposit rates applicable to the respective companies are set forth in Annex 2 to this Announcement.</p><h3>III. Method for Collection of Cash Deposits</h3><p>Beginning on August 11, 2026, when importing pecans originating in Mexico and the United States, importers shall provide corresponding cash deposits to the Customs of the People&#8217;s Republic of China based on the cash deposit rates applicable to the respective companies as determined in this preliminary determination.</p><p>The cash deposit shall be calculated on an ad valorem basis using the customs-determined dutiable value of the imported goods. The formula is as follows:</p><p>Cash Deposit Amount = (Customs-determined dutiable value of the imported goods &#215; applicable cash deposit rate) &#215; (1 + import VAT rate)</p><h3>IV. Comments</h3><p>Interested parties may submit written comments to the Investigating Authority within 10 days from the date of publication of this Announcement.</p><p>Annexes:</p><ol><li><p><em>Preliminary Determination of the Ministry of Commerce of the People&#8217;s Republic of China on the Anti-Dumping Investigation into Imports of Pecans Originating in Mexico and the United States</em></p></li><li><p><em>List of Cash Deposit Rates Applicable to Individual Companies</em></p></li></ol><p>Ministry of Commerce of the People&#8217;s Republic of China<br>August 10, 2026</p>]]></content:encoded></item><item><title><![CDATA[Caught in the Crossfire: Palo Alto Networks Under China's Cybersecurity Review]]></title><description><![CDATA[China announced cybersecurity review of Palo Alto Networks]]></description><link>https://www.geopolitechs.org/p/caught-in-the-crossfire-how-palo</link><guid isPermaLink="false">https://www.geopolitechs.org/p/caught-in-the-crossfire-how-palo</guid><dc:creator><![CDATA[Geopolitechs]]></dc:creator><pubDate>Thu, 06 Aug 2026 12:16:49 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!quWQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8989a929-3472-46f9-99a2-1f367111b5e5_1000x528.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p style="text-align: justify;">On August 6, the Cyberspace Administration of China&#8217;s Office of Cybersecurity Review <a href="https://mp.weixin.qq.com/s?__biz=MzAwMjU0MjIyNw==&amp;mid=2651540255&amp;idx=1&amp;sn=9dfdd957b7aaac1d3fbe93ec0c39fce5&amp;chksm=80b44cf7ea0d9d95ec0d7890673690f8cb1eee091c14e53401fe8f3615e4568028262bd24142&amp;scene=126&amp;sessionid=0&amp;clicktime=1786007882&amp;enterid=1786007882#rd">announced</a> that, in accordance with the National Security Law, the Cybersecurity Law, and the Measures for Cybersecurity Review, it would conduct a cybersecurity review of products sold in China by the U.S. cybersecurity company Palo Alto Networks.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!quWQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8989a929-3472-46f9-99a2-1f367111b5e5_1000x528.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!quWQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8989a929-3472-46f9-99a2-1f367111b5e5_1000x528.webp 424w, https://substackcdn.com/image/fetch/$s_!quWQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8989a929-3472-46f9-99a2-1f367111b5e5_1000x528.webp 848w, https://substackcdn.com/image/fetch/$s_!quWQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8989a929-3472-46f9-99a2-1f367111b5e5_1000x528.webp 1272w, https://substackcdn.com/image/fetch/$s_!quWQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8989a929-3472-46f9-99a2-1f367111b5e5_1000x528.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!quWQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8989a929-3472-46f9-99a2-1f367111b5e5_1000x528.webp" width="1000" height="528" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8989a929-3472-46f9-99a2-1f367111b5e5_1000x528.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:528,&quot;width&quot;:1000,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:29192,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.geopolitechs.org/i/210065006?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8989a929-3472-46f9-99a2-1f367111b5e5_1000x528.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!quWQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8989a929-3472-46f9-99a2-1f367111b5e5_1000x528.webp 424w, https://substackcdn.com/image/fetch/$s_!quWQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8989a929-3472-46f9-99a2-1f367111b5e5_1000x528.webp 848w, https://substackcdn.com/image/fetch/$s_!quWQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8989a929-3472-46f9-99a2-1f367111b5e5_1000x528.webp 1272w, https://substackcdn.com/image/fetch/$s_!quWQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8989a929-3472-46f9-99a2-1f367111b5e5_1000x528.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: justify;">At present, the CAC has not determined that the company&#8217;s products pose a national security risk, nor has it announced a blanket sales ban. However, given that the review targets cybersecurity products and that the notice specifically emphasizes &#8220;ensuring the safe and stable operation of critical information infrastructure,&#8221; government agencies, central state-owned enterprises, and operators of critical information infrastructure in sectors such as finance, energy, telecommunications, and transportation will very likely immediately suspend new purchases pending the review outcome. In commercial terms, this is already close to a de facto temporary restriction.<br><br>Palo Alto Networks is headquartered in Santa Clara, California, and is one of the world&#8217;s largest specialist cybersecurity companies. Its best-known product is the next-generation firewall. It also offers the GlobalProtect enterprise VPN, the Prisma cloud security platform, the Cortex endpoint detection and security operations platform, the WildFire malware analysis service, and Unit 42 threat intelligence and cyber incident response services. The company reported about $9.22 billion in revenue for fiscal year 2025, making it one of the representative firms in the U.S. cybersecurity industry.<br><br>What distinguishes Palo Alto from an ordinary software company is that its products are typically deployed at critical nodes such as enterprise network gateways, data centers, and cloud platforms. Firewalls can identify the applications, users, devices, and communication traffic operating within an enterprise network. VPNs control how employees access internal systems from outside. Security detection platforms, meanwhile, need to continuously collect domain names, IP addresses, attack logs, device status, and even submit suspicious files to the cloud for analysis. These products are not only the &#8220;guards&#8221; of a company&#8217;s network, but also sit at the network&#8217;s main gate. If they are secure and reliable, they can block attacks; if they are remotely controlled, stop receiving updates, or are used to collect information, they can also become a channel into the entire network.<br><br>Palo Alto&#8217;s public documents show that its firewalls can send the company telemetry data on applications, threats, and device operations. WildFire can also upload suspicious files to regional cloud infrastructure for analysis. Palo Alto&#8217;s WildFire cloud for the Asia-Pacific region is located in Singapore, and the company has not publicly listed any regional cloud located in mainland China. Although customers can disable some telemetry functions or use localized private cloud appliances, Chinese regulators still need to determine exactly what data products sold in China collect by default, whether such data and file samples are transferred abroad, whether overseas headquarters can remotely access them, and whether the U.S. government could require the company under U.S. law to provide relevant information. Palo Alto products can also be deployed locally, so not all data is automatically sent to the United States. For that reason, these questions require technical review before any conclusion can be reached, and cannot simply be equated with the discovery of a &#8220;backdoor.&#8221;<br><br>Palo Alto does have business operations in China. The company has had offices in Beijing, Shanghai, Guangzhou, and other cities. Public information indicates that it has more than 70 employees in China and has provided firewalls, VPN, and cloud security services to some multinational corporations and large enterprises. For example, Thoughtworks China once deployed Palo Alto firewalls, GlobalProtect, and WildFire for 2,817 employees. Even so, Palo Alto is not a mainstream vendor in China&#8217;s cybersecurity market. According to IDC data, China&#8217;s cybersecurity hardware market was worth about RMB 21 billion in 2024, and the top five vendors were Sangfor, Venustech, H3C, Huawei, and Topsec, each with a market share above 9 percent. Palo Alto did not rank among the top five. Because the company does not separately disclose its China revenue, the only safe conclusion is that its overall share of the Chinese market is below 9.3 percent, and more likely in the low single digits. It has relatively stronger influence among multinational companies, high-end manufacturers, and customers that require a globally unified network architecture, but in the government, central SOE, and critical information infrastructure markets, it has long been squeezed by indigenous innovation policies and domestic substitution.<br><br>In fact, this review did not come out of nowhere. As early as January this year, China had already instructed some domestic institutions to stop using U.S. and Israeli cybersecurity products from Palo Alto, Fortinet, VMware, Check Point, and others. According to reporting at the time, Chinese authorities were concerned that these products might collect sensitive information and transmit it overseas. The formal launch of a review into Palo Alto products by the Office of Cybersecurity Review means that restrictions that had previously been advanced mainly through procurement guidance and domestic substitution are now being converted into a national security review with a clear legal procedure.<br><br>As for what specific &#8220;bad record&#8221; or unfriendly conduct by Palo Alto may have drawn China&#8217;s attention, the official notice does not list any concrete facts, so it would be wrong to say that the company was punished because of one particular report or one particular action. Still, public records show at least several areas likely to have raised concern in Beijing.<br><br>The most sensitive issue is that Palo Alto&#8217;s Unit 42 threat intelligence team has long maintained cooperation with the U.S. government and intelligence community. The company has publicly stated that Unit 42 has established threat intelligence sharing mechanisms with the U.S. Department of Homeland Security, the U.S. intelligence community, and international law enforcement agencies. In 2025, when the U.S. Department of Justice indicted several Chinese citizens and personnel from i-Soon, it specifically thanked Unit 42 for assisting the investigation. From the perspective of a U.S. company, this is a common form of public-private cooperation in cybersecurity. From the perspective of Chinese regulators, however, a U.S. company that may have access to the network traffic, attack logs, and suspicious files of Chinese clients, while also sharing threat intelligence with U.S. homeland security, law enforcement, and intelligence agencies, clearly carries a high degree of national security sensitivity.<br><br>Unit 42 has also for years published reports about what it describes as &#8220;China-linked hackers&#8221; and &#8220;Chinese state-backed cyber operations,&#8221; attributing multiple campaigns targeting diplomatic entities, telecommunications, government bodies, and critical infrastructure to Chinese-related groups. In 2025, Unit 42 also named a group that had long targeted government and telecom organizations &#8220;Phantom Taurus,&#8221; and assessed it as having a &#8220;China nexus.&#8221; China has consistently opposed politicized attribution based solely on attack tools, language traces, working hours, IP addresses, and target selection. It argues that research by U.S. security firms is often used by the U.S. government to prosecute Chinese individuals, sanction Chinese companies, and amplify the narrative of a &#8220;China cyber threat.&#8221; From Beijing&#8217;s point of view, Palo Alto may be seen not merely as a commercial security vendor, but also as an intelligence provider within the broader U.S. cyber policy and law-enforcement system directed at China.<br><br>One episode in February this year is especially revealing. Reuters reported that Unit 42 had originally planned to directly attribute a cyber espionage campaign affecting 37 countries to Beijing, but Palo Alto management worried about triggering further Chinese retaliation and ultimately described the actor in the final report only as a &#8220;state-linked group active in Asia.&#8221;<br><br>In addition, Palo Alto products have in recent years suffered several serious vulnerabilities that were actively exploited in the wild. CVE-2024-3400 allowed an unauthenticated attacker to execute code with the highest privileges on certain firewalls. CVE-2024-3393 could cause firewalls to reboot repeatedly. After that, the PAN-OS management interface and GlobalProtect also saw a string of problems including authentication bypass. Several of these were added by the U.S. Cybersecurity and Infrastructure Security Agency to its Known Exploited Vulnerabilities catalog. These vulnerabilities do not prove that Palo Alto intentionally planted backdoors; any large cybersecurity product can have vulnerabilities. But because firewalls sit at the network perimeter, once compromised they pose risks far beyond those of ordinary application software, so they naturally become a focus of Chinese review.<br><br>The most relevant precedent for this review is Micron. In March 2023, China announced a cybersecurity review of Micron products sold in China. About seven weeks later, regulators concluded that the products posed relatively serious cybersecurity risks and required operators of critical information infrastructure in China to stop purchasing them. Whether Palo Alto will face the same outcome remains unclear. Under the Measures for Cybersecurity Review, regulators will focus on whether its products could lead to illegal control of, interference with, or damage to critical information infrastructure; whether supply could be interrupted for political or diplomatic reasons; and whether important data could be stolen, leaked, or unlawfully transferred abroad. If Palo Alto can demonstrate that data flows are controllable, that products can be fully deployed locally, that overseas headquarters cannot remotely interfere, and that the company will ensure continued supply and comply with Chinese law, it is still possible that the review could be cleared subject to remedial conditions. Even so, given that notices to stop using its products had already appeared in January, the probability of eventual restrictions on procurement by critical information infrastructure operators is not low.<br><br>Politically, this cybersecurity review is closely aligned with the logic behind China&#8217;s recent retaliation against FCC-related restrictions. In recent years, the United States has repeatedly invoked &#8220;national security&#8221; to restrict Chinese telecom equipment, routers, inverters, robots, testing laboratories, and cybersecurity firms from entering the U.S. market. China is now also beginning to use its own tools of cybersecurity review, certification, entity lists, and export controls to impose more concrete reciprocal restrictions on U.S. companies. The Compliance Testing case was a named retaliation against a promoter of FCC policy. The CCC measure was a reciprocal response within the certification system. The Palo Alto review goes one step further, extending scrutiny to U.S. cybersecurity products and their ability to control data.<br><br>For Palo Alto, the direct economic loss may not be very large. Its Asia-Pacific and Japan business accounts for only about 12 percent of global revenue, and China is just a relatively small part of that. When the January stop-use news emerged, Palo Alto&#8217;s share price barely moved, which also suggests that investors do not see China as central to the company&#8217;s growth story. But the symbolic significance of this case is much larger than the short-term revenue impact: an American security company whose business is to protect networks has now itself become the object of a Chinese cybersecurity review. Taken together, these signs suggest that China is carrying out a cross-departmental, layered, &#8220;portfolio-style&#8221; retaliation strategy: naming and punishing U.S. firms involved in designing and promoting restrictive policies, creating reciprocal barriers for U.S. certification bodies, and formally reviewing U.S. security products that can enter China&#8217;s critical networks and access sensitive data.<br><br>Given Palo Alto Networks&#8217; overall market share in China is not high, the company could financially exit the China market, but that would be the worst way to resolve the situation &#8212; though under today&#8217;s geopolitical realities, it may also be an unfortunate option.</p>]]></content:encoded></item><item><title><![CDATA[China Hits Back at FCC's Escalating Restrictions]]></title><description><![CDATA[On August 5, after a few quiet days, the Chinese government moved again, taking countermeasures against the United States&#8217; recent &#8220;economic and trade restrictive measures.&#8221;]]></description><link>https://www.geopolitechs.org/p/chinas-response-to-the-fccs-escalating</link><guid isPermaLink="false">https://www.geopolitechs.org/p/chinas-response-to-the-fccs-escalating</guid><dc:creator><![CDATA[Geopolitechs]]></dc:creator><pubDate>Wed, 05 Aug 2026 11:08:07 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!de3q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48ad5e15-66b3-44e5-bc8b-ab515c96b818_2752x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><span>On August 5, after a few quiet days, the Chinese government moved again, taking countermeasures against the United States&#8217; recent &#8220;economic and trade restrictive measures.&#8221;</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!de3q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48ad5e15-66b3-44e5-bc8b-ab515c96b818_2752x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!de3q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48ad5e15-66b3-44e5-bc8b-ab515c96b818_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!de3q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48ad5e15-66b3-44e5-bc8b-ab515c96b818_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!de3q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48ad5e15-66b3-44e5-bc8b-ab515c96b818_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!de3q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48ad5e15-66b3-44e5-bc8b-ab515c96b818_2752x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!de3q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48ad5e15-66b3-44e5-bc8b-ab515c96b818_2752x1536.png" width="1456" height="813" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/48ad5e15-66b3-44e5-bc8b-ab515c96b818_2752x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:813,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3882673,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.geopolitechs.org/i/209908029?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48ad5e15-66b3-44e5-bc8b-ab515c96b818_2752x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!de3q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48ad5e15-66b3-44e5-bc8b-ab515c96b818_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!de3q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48ad5e15-66b3-44e5-bc8b-ab515c96b818_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!de3q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48ad5e15-66b3-44e5-bc8b-ab515c96b818_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!de3q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48ad5e15-66b3-44e5-bc8b-ab515c96b818_2752x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span><br>The countermeasures announced this time mainly include several items.<br><br>First, China will </span><a href="https://www.mofcom.gov.cn/zwgk/zcfb/art/2026/art_74835ca289b5463f9c36cb983b689dba.html"><span>strengthen export controls on drones</span></a><span>, their key components, and related technologies to the United States.<br><br>From now on, drones, key components, and technologies that have already been included in China&#8217;s export control list of dual-use items will be subject to strict case-by-case review if exported to the United States, and exporters will no longer be allowed to use license facilitation measures.<br><br>Second, China will </span><a href="https://www.mofcom.gov.cn/zwgk/zcfb/art/2026/art_5536d924b28442f3ad90db8d764bab0d.html"><span>suspend</span></a><span> part of China-U.S. product certification cooperation.<br><br>Designated bodies for China Compulsory Certification will suspend entrusting U.S. certification bodies with follow-up inspections of U.S. factories.<br><br>Third, China will add </span><a href="https://www.mofcom.gov.cn/zwgk/zcfb/art/2026/art_bd62c275eb144ba7bc6a50716ab823b6.html"><span>seven U.S. entities </span></a><span>to its countermeasure list.<br><br>Six of them are accused of assisting and supporting the United States in imposing Xinjiang-related sanctions. The other, a U.S. compliance testing company, is accused of assisting the FCC in introducing restrictive measures against Chinese companies and testing laboratories. Organizations and individuals within China will no longer be allowed to conduct relevant transactions, cooperation, and other activities with these seven entities.<br><br>Fourth, China will launch a </span><a href="https://www.mofcom.gov.cn/zwgk/zcfb/art/2026/art_0e46c09f491a4881bae53c168c365361.html"><span>national security investigation</span></a><span> into imported printing and copying office equipment installed with foreign system software.<br><br>The investigation covers imported office equipment that is installed with foreign driver software and embedded software and has both printing and copying functions.</span></p><p><span>For the detailed content of these announcements,</span><a href="https://www.fredgao.com/"><span>Inside China</span></a><span> has published a </span><a href="https://www.fredgao.com/p/chinas-mofcom-fires-back-over-us"><span>full English translation</span></a><span>.<br><br>Taken together, this is indeed a carefully designed package of countermeasures. The FCC restricted Chinese testing laboratories, drones, routers, submarine cables, robots, and power inverters; China is responding item by item from several directions, including certification, components, software security, and supply chain compliance.</span></p><p>In an accompanying <a href="https://www.mofcom.gov.cn/syxwfb/art/2026/art_7d99f063f3a64ab1a874497ed9fc70d7.html">press briefing</a>, China&#8217;s Ministry of Commerce (MOFCOM) made no attempt to downplay the rationale behind the latest measures.</p><p>According to the spokesperson, since the Trump&#8211;Xi summit in Busan, the U.S. Federal Communications Commission (FCC) has repeatedly ignored China&#8217;s strong objections as well as calls from industry in both countries, while continuously expanding the concept of national security to justify a growing number of restrictive measures against China. These measures have covered a wide range of sectors, including telecommunications operators, testing laboratories, drones, consumer routers, submarine cables, and, most recently, advanced robotics and power inverters.</p><p>The spokesperson also highlighted that, despite repeated diplomatic representations from China, the United States added more than 40 Chinese entities to the Uyghur Forced Labor Prevention Act (UFLPA) Entity List on July 31, just one day after the July 30 video call between the Chinese and U.S. lead officials on economic and trade affairs. China said it was &#8220;strongly dissatisfied with and firmly opposed&#8221; to this decision.</p><p>According to MOFCOM, these U.S. actions seriously violate the important consensus reached by the two heads of state and undermine China&#8217;s legitimate rights and interests, leaving China no choice but to adopt necessary countermeasures.</p><p>At the same time, the spokesperson stressed that China&#8217;s response remains restrained. China values the hard-won stability in bilateral economic and trade relations and hopes the United States will work with China in the same direction. China urged Washington to immediately revoke the relevant measures, abandon what it described as its &#8220;erroneous practices,&#8221; and return to resolving differences through dialogue and cooperation in order to preserve constructive strategic stability between the two countries.</p><p>The spokesperson added that if the United States proceeds with additional restrictive measures against China, China will take further countermeasures in response.<span><br><br>The actual force of these measures is not exactly the same. Some have already taken effect immediately and will directly cut off relevant companies&#8217; business with China. These include strengthening export controls on drones, their key components, and related technologies to the United States; suspending part of China-U.S. product certification cooperation; and adding seven U.S. entities to the countermeasure list. Others are only investigations for now and remain some distance away from actual import restrictions. One example is the national security investigation into imported printing and copying office equipment installed with foreign system software. This is also the first time China has launched a foreign trade national security investigation under Article 41 of the Foreign Trade Law.<br><br>Among all these measures, inclusion on the countermeasure list carries the most serious consequences. Most of the U.S. entities listed this time are not household-name large companies, but they share one feature: they are all located in the implementation layer of U.S. Xinjiang-related supply chain enforcement and product safety regulation.<br><br>For example, Applied DNA Sciences and Stratum Reservoir mainly provide services such as DNA tagging and stable isotope analysis, which can be used to determine the origin of cotton, agricultural products, and other raw materials. After the United States implemented the Uyghur Forced Labor Prevention Act, importers needed to prove that their products and raw materials had no connection to Xinjiang. Traditional contracts, invoices, and supplier declarations were sometimes not enough to satisfy U.S. Customs, so DNA and isotope testing came to be used as supporting evidence.<br><br>Applied DNA Sciences is a listed company. In 2025, it changed its name to BNB Plus Corp., and its stock ticker changed from APDN to BNBX. The company previously operated cotton DNA tagging and origin tracing businesses, and it once publicly stated that U.S. implementation of the UFLPA helped drive demand for its business. Since then, however, the company has undergone major business changes. Its main strategy has now shifted to holding BNB digital assets and generating returns through the Binance ecosystem. Its original DNA supply chain tagging and security business is being exited, and its molecular diagnostics business has also been discontinued. The remaining industrial business is mainly nucleic acid production technology for the biopharmaceutical and diagnostics industries. The Ministry of Commerce&#8217;s move this time is more about the company&#8217;s past participation in UFLPA supply chain tracing than its current core business.<br><br>Altana Technologies operates a supply chain data platform. It uses customs, shipping, corporate, and trade data to map supply chain networks from raw materials to final products. In 2025, U.S. Customs and Border Protection selected Altana&#8217;s &#8220;product passport&#8221; system, allowing importers to prove product origin and supply chain compliance to customs in advance. Altana&#8217;s core strength is mapping global supply chain networks, and China is one of the most important nodes in global manufacturing and trade networks. If Chinese companies cannot directly provide data to Altana, purchase its services, or participate in product passport cooperation, Altana can still rely on U.S. customs data, shipping data, and overseas customers to continue analyzing Chinese supply chains, but the completeness of its data and its verification capacity will clearly be affected. For a company whose core selling point is end-to-end supply chain visibility, this impact may be greater than the direct loss of China revenue.<br><br>The Responsible Business Alliance, or RBA, is a very important industry organization in global electronics, automotive, and consumer goods supply chains. It develops supply chain codes of conduct and provides factory audits, forced labor-specific assessments, risk questionnaires, training, and corrective action tools. Many multinational companies require suppliers to accept RBA standards or audits. Many of RBA&#8217;s activities take place at the level of Chinese factories and suppliers. Now that it has been placed on the list, organizations and individuals within China, in principle, can no longer conduct relevant transactions and cooperation with it. This may affect its membership fees, factory audits, training, data submissions, and supplier assessments. In reality, however, many RBA services are purchased centrally by multinational headquarters, which then require their Chinese subsidiaries and suppliers to implement them. How regulators will define such intra-group arrangements in the future, and whether contracts signed overseas will be treated as extending to audit activities inside China, remains to be seen.</span></p><p>It is worth noting that the RBA is one of the world&#8217;s most widely adopted supply chain compliance frameworks. Many multinational companies&#8212;including Apple, Dell, HP, Intel, Tesla, and Bosch&#8212;are RBA members and require their suppliers to comply with its standards. If RBA is no longer able to conduct audits in China as a result of its designation on China&#8217;s countermeasures list, many Chinese suppliers may be unable to obtain new RBA certifications or renew existing ones. Overseas customers may then require Chinese companies to adopt alternative certification schemes or conduct supplier audits themselves. This could have a meaningful impact on sectors such as electronics, automotive, new energy, semiconductors, and EMS manufacturing. Much will depend on how the countermeasures are implemented in practice. If the restrictions were to materially affect Chinese companies&#8217; ability to meet supply chain compliance requirements, the exemption mechanism under China&#8217;s Anti-Foreign Sanctions Law could potentially be used to waive the relevant restrictions.<span><br><br>Verit&#233; has long worked on labor rights, forced labor, and supply chain due diligence, providing research, training, and consulting to governments, companies, and international organizations. Being placed on the countermeasure list may cause it to lose some China-related projects, clients, and sample sources, but these organizations have not publicly disclosed their China revenue, so it is difficult to judge the actual amount involved.<br><br>Human Rights in China mainly engages in human rights research and policy advocacy. Its commercial attributes are relatively weak, and it has no obvious commercial activities inside China. Its inclusion on the countermeasure list is therefore more political and symbolic.<br><br>For UFLPA listings, the Department of Homeland Security&#8217;s publication of a list is only the first step. Actual enforcement still requires origin testing, supply chain data, factory audits, labor investigations, and policy research. The Chinese side is targeting precisely the technology and service providers behind this enforcement system. The signal is already very clear: if foreign organizations help the U.S. government investigate, identify, and sanction Chinese companies, they may face risks under Chinese law even if they are not government agencies themselves.<br><br>The other company separately added to the countermeasure list is Compliance Testing LLC, based in Arizona. It is an FCC-recognized U.S. testing laboratory and telecommunications certification body that can help electronic products complete FCC testing, obtain FCC IDs, and enter the U.S. market. On the one hand, the company has long provided FCC certification services to Chinese manufacturers, and its website clearly states that it &#8220;frequently works with Chinese clients.&#8221; On the other hand, its executives have long lobbied the FCC to prohibit Chinese laboratories from testing products exported to the United States, arguing that this business should be moved back to the United States. So its inclusion on the list is not exactly undeserved. After being placed on the countermeasure list, Chinese manufacturers, in principle, can no longer directly entrust this company with testing and certification. Ongoing projects may also need to be transferred to other FCC-recognized bodies, which may bring Compliance Testing relatively direct losses of Chinese clients. However, after the United States restricts Chinese laboratories, some testing that was previously conducted in China may flow to U.S. laboratories. Compliance Testing may lose Chinese clients, but it may also benefit from the return of testing business to the United States. The final net impact is therefore hard to judge.<br><br>The drone-related countermeasure is to apply strict case-by-case review to exports to the United States of drones, key components, and related technologies included in the dual-use item list, while canceling license facilitation. It does not prohibit all drones and components from being exported to the United States. The existing list mainly covers drones with certain technical parameters and military uses, as well as aircraft engines, communications equipment, infrared imaging equipment, synthetic aperture radar, lasers, high-precision inertial measurement equipment, and counter-drone systems. Ordinary consumer-grade products and general components, if they do not meet the parameters in the list, should not be automatically banned from export because of this announcement.<br><br>Major U.S. military drone companies were already reducing their use of key Chinese components. Companies such as AeroVironment, Red Cat, and Skydio serve the U.S. defense and public safety markets and usually need to meet NDAA or Blue UAS supply chain requirements. U.S. law has already restricted the Department of Defense from procuring drones that use key components produced in China, such as flight control systems, communications equipment, cameras, gimbals, operating software, and other parts. As a result, large U.S. military drone companies are already less directly dependent on key Chinese components than ordinary commercial drone companies. Compared with drone companies themselves, this measure is more likely to affect two types of companies. One group consists of small and medium-sized drone companies that still procure motors, batteries, magnets, sensors, and general electronic components from China. The other consists of companies that need high-performance thermal imaging, inertial measurement, lasers, communications equipment, or counter-drone components.<br><br>One new tool that has attracted attention this time is China&#8217;s first use of the foreign trade national security investigation authority under Article 41 of the Foreign Trade Law to launch a national security investigation into imported printing and copying office equipment. The investigation targets imported printing and copying equipment installed with foreign driver software or embedded software. The Ministry of Commerce will assess the impact of these devices on national security, domestic industries, import dependence, and domestic supply capacity.<br><br>But it should be emphasized that this is currently only an investigation, not a ban. The Ministry of Commerce has not prohibited the import of any brand, has not imposed additional tariffs, and has not named HP, Xerox, Canon, Ricoh, or any other company. Judging from the market structure, the U.S. companies that may be affected are mainly HP and Xerox. But China&#8217;s office printing market also includes many Japanese brands, such as Canon, Ricoh, Konica Minolta, Kyocera, Brother, and Epson. Therefore, if the investigation eventually turns into substantive restrictions, the companies most affected may not necessarily be American; they could instead be Japanese manufacturers.<br><br>Another key issue is that the investigation targets only &#8220;imported equipment.&#8221; If the relevant printers are produced inside China, then even if the brand and software are controlled by a foreign company, they may not fall within the scope of this investigation. Therefore, to assess a company&#8217;s risk, it is not enough to look only at whether it is a foreign brand. One also needs to look at where the specific product is manufactured and how it enters China.<br><br>The investigation may eventually lead to several possible outcomes: foreign companies may be required to provide more detailed explanations of software and data security; restrictions may be imposed on remote updates, telemetry, cloud printing, and device management functions; companies may be required to establish software maintenance and vulnerability response capabilities inside China; government departments, state-owned enterprises, or critical infrastructure operators may be restricted from procuring certain imported devices; some products may face import restrictions.<br><br>HP&#8217;s printing business remains an important source of profit, but the company does not separately disclose revenue from its China printing business, so outsiders cannot accurately calculate its dependence on the Chinese market. If the final result is only a requirement to submit security materials or adjust some software functions, the impact on HP&#8217;s overall revenue would be very small. Only if China restricts imported equipment or government procurement would there be a more visible financial impact.</span></p><p><span>Xerox&#8217;s situation is somewhat different. In 2025, the company acquired Lexmark. Lexmark had previously been controlled by investors including China&#8217;s Ninestar and has some manufacturing and supply chain foundations in China. Some products, if manufactured inside China, may not themselves qualify as &#8220;imported equipment.&#8221; But if the investigation is further extended to foreign-controlled embedded software, cloud printing, and remote management services, Xerox and Lexmark may still be affected. Considering that Xerox is currently also facing high debt, declining demand for traditional printing, and acquisition integration issues, the Chinese investigation is not yet its most important fundamental variable.</span></p><p>The China Chamber of Commerce for Import and Export of Machinery and Electronic Products (CCCME) quickly issued a <a href="https://mp.weixin.qq.com/s/OscFwxo_ziD2KwwKect5TQ">statement</a> backing the government&#8217;s actions on printing devices.</p><blockquote><p>The chamber said it &#8220;firmly supports&#8221; the Ministry of Commerce&#8217;s decision to launch the investigation in accordance with the law, assess the impact of the relevant imports on China&#8217;s national security interests in foreign trade, and adopt further measures where necessary.</p><p>CCCME also criticized a series of recent China-related measures introduced by the U.S. Federal Communications Commission (FCC) and the U.S. Department of Homeland Security, including multiple restrictions on market access. It further argued that the U.S. government has continuously expanded the concept of national security, even extending Section 232 investigations and tariffs to ordinary products such as timber, and expressed its firm opposition to these actions.</p><p>The chamber noted that printing and photocopying equipment, as critical information input and output devices, forms part of the essential infrastructure supporting economic and social activities. It argued that ensuring the security of the domestic printing and copying equipment industry is important for safeguarding China&#8217;s national security interests and promoting the healthy development of the industry.</p><p>CCCME added that it will actively organize relevant companies to cooperate with the Ministry of Commerce&#8217;s investigation and support efforts to safeguard China&#8217;s industrial development and national security interests.</p></blockquote><p>The measure suspends China&#8217;s designated CCC certification bodies from commissioning U.S. certification bodies to carry out post-certification follow-up factory inspections of U.S. manufacturers. Previously, China generally allowed qualified overseas certification bodies to participate in CCC factory inspections to facilitate international trade. Suspending this arrangement does not ban U.S. products from entering the Chinese market or automatically invalidate existing CCC certificates. However, it will increase the time and cost for U.S. companies to maintain their CCC certification, creating a new procedural barrier for U.S. exports to China. The move is widely seen as a reciprocal response to the United States&#8217; use of mechanisms such as the FCC equipment authorization regime to steadily raise regulatory barriers for Chinese products entering the U.S. market in recent years.</p>]]></content:encoded></item><item><title><![CDATA[China's New Exit Regulations Reinforce Export Controls and Anti-Sanctions Enforcement]]></title><description><![CDATA[On July 31, China&#8217;s State Council released the Regulations on Exit and Entry Administration, which will take effect on September 15, 2026.]]></description><link>https://www.geopolitechs.org/p/chinas-new-exit-regulations-reinforce</link><guid isPermaLink="false">https://www.geopolitechs.org/p/chinas-new-exit-regulations-reinforce</guid><dc:creator><![CDATA[Geopolitechs]]></dc:creator><pubDate>Fri, 31 Jul 2026 21:22:55 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!R7WE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bde22d9-4518-4ffd-86c3-868b84866085_2200x1607.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>On July 31, China&#8217;s State Council released <a href="https://www.xinhuanet.com/20260731/08228229f320402fb3a97a095abfd1ad/c.html">the Regulations on Exit and Entry Administration</a>, which will take effect on September 15, 2026. The Regulations establish a new framework covering a wide range of issues, including the departure of Chinese citizens, the entry of foreign nationals, travel document administration, and exit-entry services.</p><p>Prior to the issuance of these Regulations, China&#8217;s legal framework governing restrictions on the departure of Chinese citizens was primarily based on the Exit and Entry Administration Law, the Passport Law, the Supervision Law, the Counter-Espionage Law, the Tax Collection and Administration Law, and other relevant legislation. Most of these statutes, however, are laws enacted by the National People&#8217;s Congress with relatively high-level provisions. They generally lack detailed implementing rules and typically apply only to specific categories of persons or particular circumstances.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!R7WE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bde22d9-4518-4ffd-86c3-868b84866085_2200x1607.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!R7WE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bde22d9-4518-4ffd-86c3-868b84866085_2200x1607.png 424w, https://substackcdn.com/image/fetch/$s_!R7WE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bde22d9-4518-4ffd-86c3-868b84866085_2200x1607.png 848w, https://substackcdn.com/image/fetch/$s_!R7WE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bde22d9-4518-4ffd-86c3-868b84866085_2200x1607.png 1272w, https://substackcdn.com/image/fetch/$s_!R7WE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bde22d9-4518-4ffd-86c3-868b84866085_2200x1607.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!R7WE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bde22d9-4518-4ffd-86c3-868b84866085_2200x1607.png" width="1456" height="1064" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2bde22d9-4518-4ffd-86c3-868b84866085_2200x1607.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1064,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1212084,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.geopolitechs.org/i/209309589?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bde22d9-4518-4ffd-86c3-868b84866085_2200x1607.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!R7WE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bde22d9-4518-4ffd-86c3-868b84866085_2200x1607.png 424w, https://substackcdn.com/image/fetch/$s_!R7WE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bde22d9-4518-4ffd-86c3-868b84866085_2200x1607.png 848w, https://substackcdn.com/image/fetch/$s_!R7WE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bde22d9-4518-4ffd-86c3-868b84866085_2200x1607.png 1272w, https://substackcdn.com/image/fetch/$s_!R7WE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bde22d9-4518-4ffd-86c3-868b84866085_2200x1607.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p><strong>Exit and Entry Administration Law (Article 12)</strong></p><p>Chinese citizens may be prohibited from leaving China under any of the following circumstances:</p><ul><li><p>They do not possess valid travel documents or refuse to undergo, or evade, border inspection;</p></li><li><p>Their criminal sentence has not yet been fully served;</p></li><li><p>They are defendants or criminal suspects in a criminal case;</p></li><li><p>They are involved in unresolved civil litigation where a people&#8217;s court has ordered an exit ban;</p></li><li><p>They have been penalized for disrupting border administration or have previously been repatriated for illegal exit, illegal residence, or unauthorized employment and remain within the applicable restriction period;</p></li><li><p>Their departure is likely to endanger national security or cause significant harm to national interests;</p></li><li><p>Other circumstances prescribed by laws or administrative regulations.</p></li></ul></blockquote><blockquote><p><strong>Supervision Law (Article 33)</strong></p><p>To prevent persons under investigation or other relevant individuals from fleeing abroad, supervisory authorities may, with the approval of a supervisory authority at or above the provincial level, impose exit restrictions, which are enforced by the public security authorities.</p></blockquote><blockquote><p><strong>Counter-Espionage Law (Article 33)</strong></p><p>The Ministry of State Security may:</p><ul><li><p>prohibit Chinese citizens from leaving China for a specified period if their departure is likely to endanger national security or cause significant harm to national interests; and</p></li><li><p>notify immigration authorities to prevent individuals suspected of espionage activities from leaving the country.</p></li></ul></blockquote><blockquote><p><strong>Tax Collection and Administration Law (Article 44)</strong></p><p>Taxpayers with outstanding tax liabilities, or the legal representatives of enterprises that owe taxes, must settle the outstanding taxes and late-payment surcharges, or provide an acceptable guarantee, before leaving China. Otherwise, the tax authorities may notify the immigration authorities to prevent them from departing the country.</p></blockquote><p>In the accompanying<a href="https://www.moj.gov.cn/pub/sfbgw/zcjd/202607/t20260731_538117.html"> Q&amp;A</a>, the Ministry of Justice, the Ministry of Public Security, and the National Immigration Administration explained the background to the issuance of the Regulations. They noted that, as China continues to advance high-level opening-up, a number of new challenges and issues have emerged in exit and entry administration. It has therefore become urgently necessary to promulgate the Regulations, following the principle of addressing the most pressing needs first, in order to improve and refine the relevant legal framework.</p><p>One noteworthy change is that <strong>violations of China&#8217;s export control regime have, for the first time, been expressly included within the scope of the exit-ban system.</strong></p><p><strong>Article 4</strong> provides:</p><blockquote><p>Where a Chinese citizen violates export control regulations, technology import and export administration regulations, or other relevant rules, and such conduct may endanger China&#8217;s industrial security or technological security, the competent departments of the State Council, including the Ministry of Commerce, may decide to prohibit that person from leaving China.</p></blockquote><p>The accompanying Q&amp;A further explains that this provision is mainly intended to address situations that have arisen in practice where individuals leave China and subsequently transfer technology overseas illegally, thereby endangering China&#8217;s industrial security and technological security. According to the authorities, the provision further refines and improves the existing circumstances under which exit bans may be imposed, pursuant to the authorization provided by the Exit and Entry Administration Law.</p><blockquote><p><strong>Question:</strong> What provisions does the Regulations make with respect to the administration of Chinese citizens&#8217; departure from China?</p><p><strong>Answer:</strong> In recent years, as the number of Chinese citizens travelling abroad has continued to increase, new issues have emerged in practice, including the illegal transfer of technology overseas after individuals leave China, thereby endangering China&#8217;s industrial security and technological security. To address these issues, the Regulations provide that where a person violates export control regulations or technology import and export administration regulations, and such conduct may endanger China&#8217;s industrial security or technological security, that person may, in accordance with the law, be prohibited from leaving China.</p></blockquote><p>This may indicate that the practical reach of China&#8217;s export control enforcement is no longer limited to licensing requirements, controlled items, and cross-border transactions, but may also extend to the exit administration of individuals responsible for export control violations. For companies engaged in sensitive technology research and development, technology cooperation, exports of controlled items, and cross-border technology transfers, greater attention may need to be paid to the personal compliance responsibilities of individuals involved in technology transfer activities, with personnel compliance becoming an integral part of export control compliance programs.</p><p>Foreign media have repeatedly reported allegations that China has restricted the overseas travel of individuals involved in sensitive technologies. </p><p>For example, the <em><a href="https://www.ft.com/content/d9123d9d-c807-41d6-8a17-80ff1111834a">Financial Times</a></em> reported in March 2026 that two executives from Manus were summoned to Beijing to meet with officials from the National Development and Reform Commission (NDRC), after which they were reportedly informed that they could not leave China while regulatory review of Meta&#8217;s proposed acquisition of Manus was ongoing, although they remained free to travel within the country. </p><p>On June 25, 2025, <em><a href="https://www.wsj.com/world/china-to-block-its-rare-earth-experts-from-spilling-their-secrets-8d69b75f">The Wall Street Journal</a></em> reported that China&#8217;s Ministry of Commerce had asked certain rare earth companies to submit lists of technical personnel, including information on their areas of expertise, educational background, and research experience. According to the report, some technical staff were also required to hand over their passports to their employers or local authorities in order to prevent unauthorized overseas travel and the disclosure of rare earth processing technology. </p><p><a href="https://www.bloomberg.com/news/articles/2026-05-26/china-expands-travel-curbs-to-top-ai-talent-at-private-firms">Bloomberg</a> further reported in May 2026 that China had required certain senior researchers and professionals working on strategic AI projects at companies including Alibaba and DeepSeek to obtain government approval before traveling abroad.</p><p>None of these reports has ever been officially confirmed or denied, and they are better understood as unverified media allegations. Moreover, much of the reporting sought to portray such restrictions as arbitrary exercises of unchecked government authority, implying that the Chinese government could prohibit individuals from leaving the country simply because they possessed important technologies, without any legal basis for doing so. The issuance of the new Regulations by the State Council provides an important clarification in response to such interpretations and misunderstandings.</p><p>In addition, the new Regulations also provide that Chinese citizens who engage in illegal or criminal activities overseas may be prohibited from leaving China again, provided that such activities endanger China&#8217;s national security or national interests.</p><p>Article 4 provides:</p><blockquote><p>Where a Chinese citizen engages in illegal or criminal activities outside China that endanger China&#8217;s national security or national interests, the relevant competent departments under the State Council, or the people&#8217;s government at the provincial level of the individual&#8217;s place of residence within China, upon verification by Chinese diplomatic missions or other relevant authorities abroad, may decide to prohibit that person from leaving China for a period of six months to three years from the date of his or her return to China.</p></blockquote><p>In addition to strengthening national security-related measures, the Regulations also improve procedural safeguards.</p><p>Under<strong> Article 6,</strong> where a decision has been made in accordance with the law to prohibit a person from leaving China, the authority making the decision shall, in principle, notify the individual in writing of the facts, reasons, legal basis, and available avenues for relief.</p><p>Article 6 provides:</p><blockquote><p>Where a decision is made in accordance with the law to prohibit a person from leaving China, the authority making the decision shall promptly notify the immigration authorities for implementation in accordance with the relevant provisions, and shall notify the individual in writing of the facts, reasons, legal basis, and available avenues for relief. Where notification to the individual may affect national security, the investigation of criminal cases, or other similar circumstances, the individual may not be notified.</p><p>When implementing an exit ban decision, the immigration authorities shall notify the individual in accordance with the contents of the notice received from the authority making the decision.</p></blockquote><p>At the same time, in the accompanying Q&amp;A, the Ministry of Justice, the Ministry of Public Security, and the National Immigration Administration specifically emphasized that, in implementing the Regulations, commercial secrets, personal privacy, and personal information shall be protected in accordance with the law, while balancing the needs of national security with the protection of the lawful rights and interests of the individuals concerned.</p><p>Another important feature of the Regulations is that they further clarify the implementation of China&#8217;s countermeasures regime in the context of visa issuance and the entry administration of foreign nationals.</p><p>Article 5 provides that where a foreign national has been included on a countermeasure list, the Unreliable Entity List, the Malicious Entity List, or has otherwise been made subject to countermeasures or restrictive measures in accordance with the law, and relevant legal measures such as refusing to issue exit-entry documents or denying entry are required, such measures shall be implemented by the visa authorities and immigration authorities in accordance with their respective responsibilities.</p><blockquote><p>Article 5</p><p>Where a foreign national, when applying for a Chinese visa outside China or applying for entry at a port of entry, submits false materials or makes false statements, the immigration authorities or visa authorities may decide to prohibit that person from entering China for a period of one to five years.</p><p>Where a foreign national has received criminal punishment for disrupting border administration, or administrative penalties for fraudulently obtaining exit-entry documents or for illegal exit or entry, the immigration authorities may, based on the nature of the violation and the need to prevent future violations or crimes, decide to prohibit that person from entering China for a period of one to five years from the date the penalty has been fully served. Where other laws provide otherwise, those provisions shall apply.</p><p>Where a foreign national has been included on a countermeasure list, the Unreliable Entity List, the Malicious Entity List, or has otherwise been made subject to countermeasures or restrictive measures, and it is necessary under the law to refuse the issuance of exit-entry documents or deny entry, such measures shall be implemented by the immigration authorities and visa authorities in accordance with their respective responsibilities.</p></blockquote><p>In the accompanying policy interpretation, the Ministry of Justice, the Ministry of Public Security, and the National Immigration Administration explicitly stated that the purpose of these provisions is to &#8220;strengthen the implementation of entry-related countermeasures&#8221; and to further improve China&#8217;s legal framework for countering sanctions, foreign interference, and &#8220;long-arm jurisdiction.&#8221; </p><p>From the perspective of institutional coordination, this means that restrictive measures previously established under the Anti-Foreign Sanctions Law, the Unreliable Entity List regime, and the legal framework for countering the extraterritorial application of foreign laws have now been more clearly integrated with China&#8217;s visa administration, border inspection, and entry management systems, providing a clearer implementation pathway for these measures.</p><p><strong>Below is the full translation (unofficial) of the regulation and the Q&amp;A:</strong></p><blockquote><p style="text-align: justify;"><strong>Provisions of the State Council on the Administration of Exit and Entry</strong><br><br>Article 1&#12288;These Provisions are formulated in accordance with the Exit and Entry Administration Law of the People&#8217;s Republic of China and other laws, for the purposes of regulating exit and entry administration, protecting the lawful rights and interests of persons exiting or entering the country, and safeguarding national sovereignty, security, and development interests.<br><br>Article 2&#12288;The State shall establish and improve a system for preventing safety and security risks relating to the exit of Chinese citizens from the country.<br><br>The competent departments of the State Council for foreign affairs, culture and tourism, and diplomatic missions abroad shall, in light of the security conditions in relevant countries and regions, including wars or armed conflicts, public security conditions, natural disasters, accidents and disasters, and outbreaks of infectious diseases, promptly publish overseas security alerts and safety risk advisories for travel destinations.<br><br>Chinese citizens shall pay attention to overseas security alerts and safety risk advisories for travel destinations, and avoid travelling to or staying in high-risk countries or regions.<br><br>When accepting and examining applications by Chinese citizens for exit and entry documents and conducting exit border inspection, immigration administration authorities shall, on the basis of notifications from the relevant competent departments of the State Council, remind Chinese citizens who intend to travel to high-risk countries or regions to travel with caution or to closely monitor the local security situation, heighten vigilance, strengthen precautions, and pay attention to safety. Where Chinese citizens intend to travel to countries or regions with the highest risk rating or where cases seriously endangering personal safety occur suddenly and frequently, such citizens shall, where necessary, be dissuaded from travelling there.<br><br>Article 3&#12288;The grounds on which persons exiting or entering the country apply for exit or entry, or for stay or residence, shall be truthful and lawful.<br><br>When verifying the identity of persons exiting or entering the country and the grounds for their applications, immigration administration authorities and visa authorities may inquire into relevant circumstances and require such persons to present or provide relevant documents, materials, electronic data and other information; persons exiting or entering the country shall cooperate accordingly.<br><br>Where any entity or individual issues invitation letters or other application materials for persons exiting or entering the country, such entity or individual shall be responsible for the authenticity of the matters invited and the matters certified, and shall cooperate with immigration administration authorities and visa authorities in verifying relevant information.<br><br>Where persons exiting or entering the country provide false materials or make false statements, immigration administration authorities and visa authorities shall have the authority to decide not to issue exit or entry documents or not to permit such persons to exit or enter the country.<br><br>Article 4&#12288;Where a Chinese citizen is subject to an administrative detention penalty for fraudulently obtaining exit or entry documents or for illegally exiting or entering the country, immigration administration authorities may, in light of the circumstances of the violation and the need to prevent violations and crimes, decide not to permit such citizen to exit the country for a period of not less than six months and not more than three years from the date on which execution of the penalty is completed.<br><br>Where a Chinese citizen engages in illegal or criminal activities abroad and thereby endangers national security and interests, the relevant competent departments of the State Council may decide, or the provincial people&#8217;s government at the place of domicile of such citizen within the territory of China may, after verification by a diplomatic mission abroad or other authority, decide not to permit such citizen to exit the country for a period of not less than six months and not more than three years from the date of return to China.<br><br>Where a Chinese citizen violates provisions on export control, technology import and export administration or other provisions, and may endanger national industrial security or technological security, the competent departments of the State Council for commerce and other relevant matters may decide not to permit such citizen to exit the country.<br><br>Article 5&#12288;Where a foreign national provides false materials or makes false statements when applying for a Chinese visa abroad or applying for entry at a port, immigration administration authorities and visa authorities may decide not to permit such foreign national to enter the country for a period of not less than one year and not more than five years.<br><br>Where a foreign national is subject to a criminal penalty for obstructing the administration of national borders, or is subject to an administrative penalty for fraudulently obtaining exit or entry documents or for illegally exiting or entering the country, immigration administration authorities may, in light of the circumstances of the violation and the need to prevent violations and crimes, decide not to permit such foreign national to enter the country for a period of not less than one year and not more than five years from the date on which execution of the penalty is completed. Where laws provide otherwise, such provisions shall prevail.<br><br>Where a foreign national is included on a countermeasure list, unreliable entity list, malicious entity list, or is subject to countermeasures, restrictive measures or other measures, and it is necessary to take relevant measures in accordance with law, including refusing to issue exit or entry documents or denying entry, immigration administration authorities and visa authorities shall implement such measures in accordance with their respective functions.<br><br>Article 6&#12288;With respect to persons against whom a decision not to permit exit from the country has been made in accordance with law, the deciding authority shall, in accordance with provisions, promptly notify immigration administration authorities for enforcement, and shall inform the party concerned in writing of the facts, reasons and basis for the decision not to permit exit, as well as the channels for seeking remedies; where circumstances exist in which such notification may affect national security, criminal case investigations or other matters, the party concerned may not be informed.<br><br>When enforcing a decision not to permit exit from the country, immigration administration authorities shall inform the party concerned of the contents notified by the deciding authority.<br><br>Article 7&#12288;The State shall implement record-filing administration with respect to institutions and personnel that, upon entrustment by persons exiting or entering the country, engage in intermediary services such as consulting on exit and entry policies, agency services for documents, and handling of procedures.<br><br>An institution engaging in exit and entry intermediary services shall, within 15 days from the date of its establishment, complete record-filing with the immigration administration authority at the place where it is located. Personnel engaging in exit and entry intermediary services shall have record-filing formalities handled by the institution to which they belong. Those that have already engaged in exit and entry intermediary services before the implementation of these Provisions shall complete record-filing formalities within 90 days from the date on which these Provisions come into force.<br><br>Specific measures for the record-filing administration of institutions and personnel engaging in exit and entry intermediary services shall be formulated by the national immigration administration department in conjunction with the competent departments of the State Council for market regulation and other matters.<br><br>Article 8&#12288;An institution engaging in exit and entry intermediary services shall meet the following conditions:<br><br>(1) it is established in accordance with law;<br>(2) its legal representative or person in charge has not been subject to a criminal penalty for an intentional crime;<br>(3) it has staff with professional knowledge of laws, regulations, policies and other matters relating to exit and entry, and has funds and premises commensurate with the intermediary service activities in which it engages;<br>(4) staff who directly provide intermediary services to persons exiting or entering the country have not been subject to a criminal penalty for an intentional crime endangering national security or public security or obstructing the administration of national borders;<br>(5) it has sound management systems, including systems for personnel management, education and training, retention of materials, data security, and compliance management.<br><br>An institution engaging in outbound intermediary services shall also have established cooperative relations with relevant overseas service institutions or signed valid letters of intent for cooperation.<br><br>Overseas enterprises and institutions shall not provide exit and entry intermediary services within the territory of China.<br><br>Article 9&#12288;Immigration administration authorities shall, in conjunction with competent departments at the same level for foreign affairs, education, judicial administration, human resources and social security, commerce, culture and tourism, market regulation and other relevant matters, establish and improve regulatory systems, strengthen supervision and administration of the satisfaction of conditions and business activities of institutions engaging in exit and entry intermediary services in accordance with the division of functions, and publish relevant information on violations of law and adverse records in accordance with law.<br><br>Relevant competent departments and their staff shall, in accordance with law, keep confidential any state secrets, work secrets, trade secrets, personal privacy and personal information that they become aware of in the course of performing their duties.<br><br>Article 10&#12288;An institution engaging in exit and entry intermediary services shall not commit any of the following acts:<br><br>(1) publishing false information, or soliciting service recipients by exaggerated publicity, misleading publicity or other means;<br>(2) providing or assisting in providing false materials, or assisting others in handling visas, stay or residence documents, passports or other exit and entry documents or formalities in violation of provisions;<br>(3) disclosing, selling or illegally providing trade secrets, personal privacy or personal information learned in the course of intermediary service activities;<br>(4) engaging in exit and entry intermediary services beyond the scope of record-filing;<br>(5) organizing or assisting others in engaging in cross-border illegal or criminal activities;<br>(6) other acts that endanger national security or interests or disrupt the order of exit and entry administration.<br><br>Where public officials, military personnel or other persons entrust an institution engaging in exit and entry intermediary services to handle foreign nationality, overseas permanent residence qualifications, overseas residence documents, or other exit and entry documents or formalities in violation of provisions, the institution engaging in exit and entry intermediary services shall not handle such matters, and shall promptly report the matter to the supervisory organs and other authorities.<br><br>Article 11&#12288;Where any person obtains a visa, stay or residence document, passport or other exit or entry document by fraud through providing false materials, making false statements or other falsification, immigration administration authorities shall impose penalties in accordance with the Exit and Entry Administration Law of the People&#8217;s Republic of China and the Passport Law of the People&#8217;s Republic of China.<br><br>Where an individual issues a false invitation letter or other application materials for another person&#8217;s application for exit or entry, or for stay or residence, immigration administration authorities shall impose a fine of not less than RMB 5,000 and not more than RMB 10,000; where there are illegal gains, the illegal gains shall be confiscated. Where an entity commits the aforesaid act, a fine of not less than RMB 10,000 and not more than RMB 50,000 shall be imposed; where there are illegal gains, the illegal gains shall be confiscated; and the directly responsible person in charge and other directly responsible persons shall be fined not less than RMB 5,000 and not more than RMB 10,000. Where laws provide otherwise, such provisions shall prevail.<br><br>Article 12&#12288;Where an institution engaging in exit and entry intermediary services violates Article 7 or Article 8 of these Provisions, immigration administration authorities shall order it to make corrections within a prescribed time limit; where it refuses to make corrections, a fine of not less than RMB 5,000 and not more than RMB 10,000 shall be imposed, and the relevant competent departments shall be notified to order suspension of relevant business or suspension of business for rectification; where the circumstances are serious, a fine of not less than RMB 10,000 and not more than RMB 50,000 shall be imposed, and the relevant competent departments shall be notified to revoke the relevant business licence or revoke the business licence.<br><br>Where an individual engages in exit and entry intermediary services in violation of these Provisions, immigration administration authorities shall order the cessation of the illegal act; where there are illegal gains, the illegal gains shall be confiscated; where the circumstances are serious, a fine of not more than RMB 5,000 may also be imposed.<br><br>Article 13&#12288;Where an institution engaging in exit and entry intermediary services violates Article 10 of these Provisions and disrupts the order of exit and entry administration, immigration administration authorities shall order it to make corrections within a prescribed time limit; where there are illegal gains, the illegal gains shall be confiscated; where the illegal gains are RMB 20,000 or more, a fine of not less than one time and not more than five times the illegal gains shall also be imposed; where there are no illegal gains or the illegal gains are less than RMB 20,000, a fine of not less than RMB 20,000 and not more than RMB 50,000 shall also be imposed; where it refuses to make corrections or the circumstances are serious, the relevant competent departments shall be notified to order suspension of relevant business, suspension of business for rectification, revocation of the relevant business licence, or revocation of the business licence; and the directly responsible person in charge and other directly responsible persons shall be fined not less than RMB 10,000 and not more than RMB 50,000. Where laws provide otherwise, such provisions shall prevail.<br><br>Article 14&#12288;Where an exit and entry administration authority of the public security organ of a local people&#8217;s government at or above the county level imposes an administrative penalty of a fine exceeding RMB 5,000 or confiscation of illegal gains in accordance with these Provisions, the decision shall be made by the public security organ to which it belongs.<br><br>Article 15&#12288;The relevant competent departments of the State Council shall strengthen coordination in work relating to the protection of the lawful rights and interests of persons exiting or entering the country, the prevention of safety and security risks relating to the exit of Chinese citizens from the country, and the administration of exit and entry intermediary services.<br><br>Article 16&#12288;Immigration administration authorities shall maintain unobstructed channels for reporting acts violating exit and entry administration, and shall handle relevant reports promptly in accordance with law. Reports that do not fall within the functions of the authority shall be promptly transferred to the relevant entity for handling in accordance with law.<br><br>Article 17&#12288;Where any violation of these Provisions constitutes a crime, criminal liability shall be pursued in accordance with law.<br><br>Article 18&#12288;For the purposes of these Provisions, &#8220;immigration administration authorities&#8221; means the national immigration administration department, exit and entry border inspection authorities, and exit and entry administration authorities of public security organs of local people&#8217;s governments at or above the county level.<br><br>For the purposes of these Provisions, &#8220;visa authorities&#8221; means overseas visa authorities and port visa authorities.<br><br>Article 19&#12288;These Provisions shall come into force on September 15, 2026.</p></blockquote><blockquote><p style="text-align: justify;"><strong>Officials from the Ministry of Justice, the Ministry of Public Security, and the National Immigration Administration Answer Reporters&#8217; Questions on the State Council Provisions on Exit and Entry Administration</strong><br><br>On July 22, 2026, Premier Li Qiang of the State Council signed State Council Decree No. 841, promulgating the State Council Provisions on Exit and Entry Administration (hereinafter referred to as the &#8220;Provisions&#8221;), which will come into force on September 15, 2026. Officials from the Ministry of Justice, the Ministry of Public Security, and the National Immigration Administration answered reporters&#8217; questions on issues related to the Provisions.</p><p>Q: Please briefly introduce the background to the formulation of the Provisions.<br><br>A: Exit and entry administration concerns the safety and lawful rights and interests of Chinese nationals traveling abroad, as well as China&#8217;s sovereignty, security, and development interests. Since the Exit and Entry Administration Law came into force in 2013, it has played an important role in regulating exit and entry administration, safeguarding national sovereignty, security, and social order, and promoting opening-up and exchanges with other countries.<br><br>As China continues to advance high-standard opening-up across the board, new challenges and issues have emerged in exit and entry administration. It is therefore urgent to promulgate the Provisions in accordance with the principle of addressing urgent needs first, so as to improve relevant systems.<br><br>First, it is necessary to strengthen the prevention of safety risks for Chinese citizens traveling abroad. As China&#8217;s international exchanges continue to expand, more and more Chinese citizens travel overseas for tourism, family visits, business, study, and other purposes. In recent years, major emergencies such as wars or armed conflicts, public security incidents, natural disasters, accidents, and infectious disease outbreaks have occurred from time to time in some countries and regions, posing threats to the personal safety of Chinese citizens abroad. It is therefore necessary to promptly improve the system for preventing safety risks faced by citizens traveling overseas.<br><br>Second, it is necessary to regulate the entry administration of foreigners. As China continues to deepen its opening-up, the number of foreign nationals entering China has continued to grow. In practice, there have also been cases in which a small number of individuals provided false materials or fraudulently obtained exit and entry documents when applying for entry. It is therefore necessary to improve measures such as entry examination and denial of entry.<br><br>Third, it is necessary to regulate exit and entry intermediary services. After the access licensing requirement for private exit and entry intermediary service agencies was abolished in 2018, the number of such agencies grew rapidly. While they have provided convenience for exit and entry personnel, problems have also emerged, including unclear overall information about intermediary agencies, unlawful or non-compliant business practices by some agencies, and harm to the lawful rights and interests of exit and entry personnel. It is therefore necessary to improve the management system for intermediary service agencies.</p><p>Q: What provisions does the Provisions contain regarding the prevention of safety risks for Chinese citizens traveling abroad and the protection of their personal safety?<br><br>A: In order to more effectively prevent safety risks faced by Chinese citizens after they travel abroad and to protect their personal safety, the Provisions adhere to the principle of prioritizing prevention and adopting comprehensive measures. The main provisions are as follows.<br><br>On the one hand, overseas safety risk alerts and reminders must be issued in a timely manner. The foreign affairs, culture, and tourism departments of the State Council, as well as diplomatic missions abroad, are required to promptly publish overseas safety alerts and safety risk reminders for tourist destinations based on the security situation in relevant countries and regions, including wars or armed conflicts, public security conditions, natural disasters, accidents, infectious disease outbreaks, and other factors.<br><br>On the other hand, the safety risk prevention system at the exit stage is improved. Immigration administration authorities are required, when accepting and approving applications for exit and entry documents and conducting exit border inspections, to remind citizens to exercise caution when traveling to high-risk countries or regions. For those who indeed need to travel to such destinations, the authorities should remind them to pay attention to the local security situation and strengthen safety precautions. When necessary, the authorities should dissuade them from traveling to countries or regions with the highest risk level or where incidents seriously endangering personal safety are occurring suddenly or frequently.</p><p>Q: What provisions does the Provisions contain regarding the regulation of exit administration for Chinese citizens?<br><br>A: In recent years, as the number of Chinese citizens traveling abroad has continued to increase, some problems have arisen in practice. These include individuals being deceived into leaving the country, or fabricating reasons to illegally exit the country to engage in illegal activities such as cross-border gambling and telecom and online fraud, seriously endangering the lives and property of the public. There have also been cases in which individuals illegally transferred technology abroad after leaving the country in violation of regulations, endangering national industrial security and technological security.<br><br>In response to these issues, the Provisions strengthen exit administration on the one hand. They require that the reasons given by exit applicants must be truthful and lawful, and that applicants cooperate with immigration administration authorities in verifying their identity and the reasons for their application. They also provide that entities and individuals issuing invitation letters shall be responsible for the truthfulness of the invitation content. Where false materials are provided or false statements are made, immigration administration authorities have the right to decide not to issue exit and entry documents or not to permit the applicant to leave the country.<br><br>On the other hand, pursuant to the authorization under the Exit and Entry Administration Law, the Provisions improve the circumstances under which exit may be denied. In accordance with the law, exit shall be denied to persons who have been subject to administrative detention for fraudulently obtaining exit and entry documents or for illegally exiting or entering the country; persons who engage in illegal or criminal activities abroad that endanger national security and interests; and persons who may endanger national industrial security or technological security by violating regulations on export control, technology import and export administration, and other related rules.</p><p>Q: What provisions does the Provisions contain regarding the regulation of entry administration for foreigners?<br><br>A: To further regulate the entry administration of foreigners, the Provisions mainly contain the following provisions.<br><br>First, entry administration is strengthened. The Provisions require that the reasons given by entry applicants for entry, stay, or residence must be truthful and lawful, and that applicants cooperate with immigration administration authorities and visa authorities in verifying their identity and the reasons for their application. They also provide that entities and individuals issuing invitation letters shall be responsible for the truthfulness of the invitation content.<br><br>Second, the circumstances under which entry may be denied are improved. Pursuant to the authorization under the Exit and Entry Administration Law, the Provisions specify that foreign nationals who provide false materials or make false statements when applying for a Chinese visa abroad or applying for entry at a port, who have been subject to criminal punishment for obstructing the administration of national border control, or who have been subject to administrative penalties for fraudulently obtaining exit and entry documents or for illegally exiting or entering the country, shall be denied entry in accordance with the law.<br><br>Third, the implementation of entry-related countermeasures is strengthened. To strengthen the rule-of-law response to counter-sanctions, anti-interference, and opposition to &#8220;long-arm jurisdiction,&#8221; the Provisions stipulate that where foreign nationals are included on a countermeasure list, the unreliable entity list, or the malicious entity list, or are subject to countermeasures and restrictive measures, and where relevant measures such as refusing to issue exit and entry documents or denying entry need to be taken in accordance with the law, immigration administration authorities and visa authorities shall implement such measures according to their respective duties.</p><p>Q: Please briefly introduce the main considerations behind the establishment of the filing-based management system for exit and entry intermediary service agencies under the Provisions.<br><br>A: In recent years, the number of agencies in China engaged in exit and entry intermediary services has grown rapidly. While they have provided convenience for exit and entry personnel, problems have also emerged, including unclear overall information about such agencies, unlawful or non-compliant business practices by some agencies, and harm to the lawful rights and interests of exit and entry personnel. These issues affect the standardized and healthy development of the industry and endanger the national order of exit and entry administration. It is therefore urgent to improve relevant systems and rules.<br><br>The Provisions adopt a problem-oriented approach and improve the management system for intermediary service agencies in a targeted manner.<br><br>First, a filing-based management system is established. The Provisions specify that agencies and personnel entrusted by exit and entry personnel to provide intermediary services such as exit and entry policy consultation, document application agency services, and procedure handling shall be subject to filing-based management. Intermediary service agencies are required to file with the local immigration administration authority within 15 days from the date of establishment. Personnel engaged in exit and entry intermediary services shall complete filing procedures through their agencies. Agencies that were already engaged in intermediary services before the Provisions come into force shall complete filing procedures within 90 days from the date on which the Provisions come into force. Non-profit activities such as policy consultation and information inquiries do not fall within the scope of &#8220;exit and entry intermediary services&#8221; as referred to in the Provisions.<br><br>Second, the conditions that intermediary service agencies must meet are clarified. To ensure the quality of intermediary services and improve service standards, agencies engaged in exit and entry intermediary services are required to have staff with relevant professional knowledge, as well as premises and financial support commensurate with the intermediary service activities they conduct. At the same time, the Provisions clarify that overseas enterprises and institutions may not provide exit and entry intermediary services within China. Foreign-invested enterprises and institutions, as well as enterprises and institutions funded by investors from Hong Kong, Macao, or Taiwan, that are lawfully established within China may engage in exit and entry intermediary services in accordance with the law.<br><br>Third, intermediary service practices are regulated. To effectively protect the lawful rights and interests of exit and entry personnel and promote the standardized and healthy development of the industry, the Provisions stipulate that agencies engaged in exit and entry intermediary services shall not publish false information, solicit clients through exaggerated or misleading publicity, provide or assist in providing false materials, or assist others in improperly handling visas, stay or residence permits, passports, or other exit and entry documents or procedures.</p><p>Q: What provisions does the Provisions contain regarding the strengthening of protection for the lawful rights and interests of exit and entry personnel?<br><br>A: To better protect the lawful rights and interests of exit and entry personnel, the Provisions, while strengthening the protection of the personal safety of outbound travelers, also strengthen protection in the following respects.<br><br>On the one hand, protection of personal privacy and personal information is strengthened. The Provisions emphasize that relevant competent departments and their staff shall keep confidential, in accordance with the law, any trade secrets, personal privacy, and personal information that they become aware of in the course of performing their duties. They also provide that exit and entry intermediary service agencies shall not disclose, sell, or illegally provide trade secrets, personal privacy, or personal information.<br><br>On the other hand, the Provisions clarify that authorities making decisions to deny exit shall, in accordance with the law, inform the parties concerned in writing of the facts, reasons, legal basis, and remedies relating to the denial of exit. When immigration administration authorities enforce a decision to deny exit, they shall notify the parties concerned in accordance with the notice from the decision-making authority, so as to effectively strengthen protection of the parties&#8217; lawful rights and interests regarding exit.</p></blockquote>]]></content:encoded></item><item><title><![CDATA[China expressed serious concerns over the recent U.S. restrictive economic and trade measures in the latest high level meeting]]></title><description><![CDATA[On July 30, Chinese Vice Premier He Lifeng held a video call with U.S.]]></description><link>https://www.geopolitechs.org/p/china-expressed-serious-concerns</link><guid isPermaLink="false">https://www.geopolitechs.org/p/china-expressed-serious-concerns</guid><dc:creator><![CDATA[Geopolitechs]]></dc:creator><pubDate>Thu, 30 Jul 2026 21:51:24 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!wZa_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7df1ae2b-bd79-4f02-90be-c9029aebf548_1080x322.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>On July 30, Chinese Vice Premier He Lifeng held a video call with U.S. Treasury Secretary Scott Bessent and U.S. Trade Representative Jamieson Greer.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wZa_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7df1ae2b-bd79-4f02-90be-c9029aebf548_1080x322.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wZa_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7df1ae2b-bd79-4f02-90be-c9029aebf548_1080x322.webp 424w, https://substackcdn.com/image/fetch/$s_!wZa_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7df1ae2b-bd79-4f02-90be-c9029aebf548_1080x322.webp 848w, https://substackcdn.com/image/fetch/$s_!wZa_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7df1ae2b-bd79-4f02-90be-c9029aebf548_1080x322.webp 1272w, https://substackcdn.com/image/fetch/$s_!wZa_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7df1ae2b-bd79-4f02-90be-c9029aebf548_1080x322.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wZa_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7df1ae2b-bd79-4f02-90be-c9029aebf548_1080x322.webp" width="1080" height="322" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7df1ae2b-bd79-4f02-90be-c9029aebf548_1080x322.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:322,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:21258,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.geopolitechs.org/i/209179001?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7df1ae2b-bd79-4f02-90be-c9029aebf548_1080x322.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wZa_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7df1ae2b-bd79-4f02-90be-c9029aebf548_1080x322.webp 424w, https://substackcdn.com/image/fetch/$s_!wZa_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7df1ae2b-bd79-4f02-90be-c9029aebf548_1080x322.webp 848w, https://substackcdn.com/image/fetch/$s_!wZa_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7df1ae2b-bd79-4f02-90be-c9029aebf548_1080x322.webp 1272w, https://substackcdn.com/image/fetch/$s_!wZa_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7df1ae2b-bd79-4f02-90be-c9029aebf548_1080x322.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>According to the Chinese <a href="https://mp.weixin.qq.com/s/uOVCZLbPZ9eDTUhNWOgMSA">readout</a>, the two sides discussed implementing the consensus reached by the two heads of state at their Beijing meeting, maintaining stable economic and trade relations, expanding practical cooperation, and properly addressing each other&#8217;s concerns. </p><blockquote><p><em>On July 30, Chinese Vice Premier He Lifeng, China's lead official for China-U.S. economic and trade affairs, held a video call with his U.S. counterparts, Treasury Secretary Scott Bessent and U.S. Trade Representative Jamieson Greer. The two sides held candid, in-depth, and constructive discussions on implementing the important consensus reached by the two heads of state during their meeting in Beijing, maintaining stable China-U.S. economic and trade relations in the next stage, expanding practical cooperation, and properly addressing each other's concerns. The Chinese side expressed serious concerns over the recent U.S. restrictive economic and trade measures against China. The two sides agreed that, under the strategic guidance of the two heads of state, they will further make full use of the China-U.S. economic and trade consultation mechanism, strengthen communication, enhance mutual trust, address each other's concerns, expand cooperation, promote the stable and positive development of bilateral economic and trade relations, and contribute to building a constructive and strategically stable China-U.S. relationship.</em></p></blockquote><p>One sentence in the Chinese statement deserves particular attention: <strong>&#8220;The Chinese side expressed serious concerns over the recent U.S. restrictive economic and trade measures against China.&#8221;</strong></p><p>It is worth reviewing what these &#8220;restrictive measures&#8221; refer to. In the week leading up to the call, the United States either introduced or signaled new restrictions across tariffs, robotics, energy equipment, telecommunications components, and artificial intelligence.</p><p>On July 23, the United States announced a new round of Section 301 tariffs targeting products associated with forced labor. Citing the failure of other economies to take sufficient measures to prevent goods produced with forced labor from entering global supply chains, the White House imposed an additional 12.5% tariff on products from China and around 60 other economies. Unlike the broader tariffs previously challenged in U.S. courts under the International Emergency Economic Powers Act (IEEPA), this action relies on Section 301 of the Trade Act of 1974. Beijing is likely concerned that Washington is repackaging broad-based tariffs into a series of legally distinct Section 301 actions based on different policy justifications, making them more difficult to reverse in the future.</p><p>On July 28, the Federal Communications Commission (FCC) announced restrictions on new foreign-manufactured advanced mobile robots and grid-connected power inverters entering the U.S. market. The policy covers humanoid robots, quadruped robots, and other devices that rely on wireless connectivity to navigate or perform autonomous functions. Although the rule is technology-neutral on its face, its practical target is widely understood to be Chinese manufacturers. Rather than banning existing products, the FCC is restricting new models from obtaining equipment authorization. Products that have already received authorization will not automatically lose their approvals, although the FCC retains the authority to revoke them in the future.</p><p>During the same week, the FCC also adopted rules preventing products containing specified logic components from companies on the FCC&#8217;s Covered List, including Huawei and ZTE, from obtaining equipment authorization. As a result, the scope of U.S. restrictions has expanded beyond complete telecommunications equipment to include internal chips, modules, and control components incorporated into a wide range of products.</p><p>Meanwhile, U.S. government officials and members of Congress have increasingly accused certain Chinese AI companies of acquiring the capabilities of leading U.S. models through model distillation, account circumvention, or access to export-controlled computing resources. Moonshot AI and its Kimi models have received particular attention. The U.S. government is reportedly evaluating whether to respond through export controls, Entity List designations, or other sanctions tools.</p><p>The U.S. Department of War has also recently expanded its Section 1286 list to include several Chinese universities under the &#8220;problematic activities&#8221; framework established by the National Defense Authorization Act. The practical consequences extend well beyond symbolic designation, affecting eligibility for U.S. federal research funding, university partnerships, academic exchanges, laboratory procurement, and participation in advanced research networks.</p><p>On July 29, the Treasury Department&#8217;s Office of Foreign Assets Control (OFAC) announced new Iran-related sanctions targeting entities registered in Hong Kong or linked to offices in Shenzhen as part of Iran&#8217;s oil transportation and &#8220;shadow fleet&#8221; network. Designation on the SDN List typically cuts designated entities off from the U.S. dollar financial system, transactions involving U.S. persons, and compliance channels used by major international banks, with broader spillover effects on shipping, insurance, trade finance, and energy supply chains.</p><p>The U.S. <a href="https://x.com/SecScottBessent/status/2082897984425955774">readout</a> framed the call primarily around implementation and institutional mechanisms, with particular emphasis on China&#8217;s commitments regarding rare earth exports and agricultural trade. Washington appears focused on ensuring that Beijing follows through on the commitments made during the leaders&#8217; meeting, while Beijing is seeking to discourage the United States from introducing additional restrictive measures after the meeting.</p><blockquote><p><em><span>Today,US Trade Representative Greer and I spoke with Chinese Vice Premier He Lifeng ahead of President Trump and President Xi&#8217;s meeting in September.<br><br>In our discussion, I emphasized that we expect Beijing to fully meet its commitments on rare earths and U.S. agricultural products. We also discussed implementation of the Trade and Investment Boards as a mechanism to secure concrete progress toward a more balanced, fair, and constructive U.S.-China economic relationship.</span></em></p></blockquote><p>In the near term, both sides are likely to continue managing frictions through the bilateral economic and trade consultation mechanism. However, the recent series of U.S. restrictive measures may already represent an important test of whether China and the United States can maintain constructive strategic stability despite intensifying competition.</p>]]></content:encoded></item><item><title><![CDATA[China's Proposal on Security Requirements for AI Agent Interactions]]></title><description><![CDATA[Cybersecurity Standards Practice Guide &#8212; Security Requirements for Agent Interactions (Draft for Public Consultation)]]></description><link>https://www.geopolitechs.org/p/cybersecurity-standards-practice</link><guid isPermaLink="false">https://www.geopolitechs.org/p/cybersecurity-standards-practice</guid><dc:creator><![CDATA[Geopolitechs]]></dc:creator><pubDate>Wed, 29 Jul 2026 16:07:50 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!G1vA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F734d8789-fa48-4d29-9644-52a8b7fde4c5_1800x1050.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>This is an unofficial English translation of a Chinese cybersecurity standards document, <em>&#8220;Cybersecurity Standards Practice Guide &#8212; Security Requirements for AI Agent Interaction&#8221;</em> (TC260-PG-2026NA). </p><p>It was released in July 2026 (Draft for Public Comment, v0.23) by the Secretariat of the National Information Security Standardization Technical Committee (TC260) &#8212; the body that steers China&#8217;s national cybersecurity standards. </p><p>As a &#8220;practice guide,&#8221; it is not a mandatory national standard but an authoritative reference that signals the direction of forthcoming regulation and industry practice.</p><p>The guide sets out security requirements for how AI agents interact &#8212; both agent-to-agent and agent-to-tool &#8212; with the aim of preventing risks such as identity forgery, unauthorized (privilege) access, and the cascading spread of hallucinations across multiple agents. </p><p>It is organized around three areas: </p><p>(1) general interaction security (identity, access control, communication security, and risk management); </p><p>(2) agent-to-agent interaction security (registration, discovery, and mutual invocation); and </p><p>(3) agent-to-tool interaction security (tool discovery and tool invocation). An informative appendix maps a catalog of concrete interaction risks (e.g., information tampering, information leakage, privilege loss of control, tool abuse, intent hijacking) to the specific clauses that mitigate them. </p><p>It is aimed at AI agent service providers and tool providers, and can also serve as a reference for third-party assessors.</p><p><em>(The full translation follows. In case of any discrepancy, the original Chinese document prevails.&#65289;</em></p><p><strong>Foreword</strong></p><p>The <em>Cybersecurity Standards Practice Guide</em> (hereinafter the &#8220;Practice Guide&#8221;) is a standards-related technical document organized, developed, and published by the Secretariat of the National Information Security Standardization Technical Committee (hereinafter the &#8220;Cybersecurity Standardization Committee&#8221; or &#8220;TC260&#8221;). It aims to promote cybersecurity-related standards and knowledge and to provide standardization practice guidance around such themes as cybersecurity laws, regulations and policies, standards, and cybersecurity hot topics and incidents.</p><p><strong>Drafting organizations of this document:</strong> China Mobile Communications Group Co., Ltd.; China Electronics Standardization Institute; Beijing Zhongguancun Laboratory; National Computer Network Emergency Response Technical Team/Coordination Center of China (CNCERT/CC); ZTE Corporation; Beijing Kuaishou Technology Co., Ltd.; Fudan University; Alibaba Cloud Computing Co., Ltd.; Strategic Research Center of Qiyuan Laboratory; Ant Technology Group Co., Ltd.; Harbin Institute of Technology.</p><p><strong>Drafters of this document:</strong> Qiu Qin, Su Li, Yang Kai, Li Ziwei, He Min, Cui Yong, Chen Jia, Zhao Yuhang, Ran Peng, Sun Yang, Li Bangling, Lu Dongjie, Xu Sijia, Zhang Yanting, Zhang Lei, Chao Yihan, Du Chenguang, Shi Guixin, Li Ye, Wang Kun, Wang Bo, Zhou Jihua, Mei Aoting, Cao Xiaoqi, Shao Meng, Wang Jian, Gu Chen, Yang Min, Hong Geng, Chen Pei, Peng Juntao, Xu Yuan, Li Yunjia, Lin Guanchen, Yang Xiaofang, Peng Jin, Jiang Wei, Ye Lin.</p><p><strong>Statement</strong></p><p>The copyright of this Practice Guide belongs to the Secretariat of the Cybersecurity Standardization Committee. Without the written authorization of the Secretariat, no part of this Practice Guide may be copied or translated in any manner. When reprinting or citing the views or data of this Practice Guide, please indicate: &#8220;Source: Secretariat of the National Information Security Standardization Technical Committee.&#8221;</p><p><strong>Abstract</strong></p><p>This document is developed to guide the interaction security of AI agents and to prevent security risks such as identity forgery, unauthorized access, and cascading hallucination propagation across multiple agents during agent interaction, in accordance with the <em>Cybersecurity Law of the People&#8217;s Republic of China</em>, the <em>Data Security Law of the People&#8217;s Republic of China</em>, and relevant national standards.</p><p>To this end, this Guide specifies general security requirements for agent interaction, as well as security requirements for agent-to-agent interaction and agent-to-tool interaction. It is intended to provide security practice guidance on the interaction process for AI agent service providers and tool providers, and may also serve as a reference for third-party assessment organizations and other bodies.</p><p><strong>Table of Contents</strong></p><ol><li><p>Scope</p></li></ol><ol start="2"><li><p>Normative References</p></li></ol><ol start="3"><li><p>Terms and Definitions</p></li></ol><ol start="4"><li><p>Abbreviations</p></li></ol><ol start="5"><li><p>Overview</p></li></ol><ol start="6"><li><p>General Security Requirements for AI Agent Interaction</p></li></ol><ol start="7"><li><p>Security Requirements for Agent-to-Agent Interaction</p></li></ol><ol start="8"><li><p>Security Requirements for Agent-to-Tool Interaction</p></li></ol><ul><li><p>Appendix A (Informative) &#8212; List of AI Agent Interaction Security Risks</p></li></ul><ul><li><p>References</p></li></ul><p><strong>1 Scope</strong></p><p>This document specifies the interaction security requirements for agent-to-agent and agent-to-tool interactions, including general security requirements for agent interaction, security requirements for agent-to-agent interaction, and security requirements for agent-to-tool interaction.</p><p>This document is applicable to guiding AI agent service providers and tool providers in safeguarding the security of the agent interaction process. It is also applicable to third-party assessment organizations and other bodies in assessing the security of agent interaction.</p><p><strong>2 Normative References</strong></p><p>The contents of the following documents, through normative reference in this text, constitute indispensable provisions of this document. For dated references, only the version corresponding to that date applies to this document. For undated references, the latest version (including all amendments) applies to this document.</p><ul><li><p>GB/T 25069 &#8212; Information security techniques &#8212; Terminology</p></li></ul><ul><li><p>GB 45438&#8212;2025 &#8212; Cybersecurity technology &#8212; Labeling method for content generated and synthesized by artificial intelligence</p></li></ul><ul><li><p>GB/T 45574&#8212;2025 &#8212; Data security technology &#8212; Security requirements for the processing of sensitive personal information</p></li></ul><ul><li><p>GB/T 45654&#8212;2025 &#8212; Cybersecurity technology &#8212; Basic security requirements for generative artificial intelligence services</p></li></ul><ul><li><p>GB/Z 185.1&#8212;2026 &#8212; Artificial intelligence &#8212; Agent interconnection &#8212; Part 1: General architecture</p></li></ul><ul><li><p>GB/Z 185.3&#8212;2026 &#8212; Artificial intelligence &#8212; Agent interconnection &#8212; Part 3: Identity management</p></li></ul><ul><li><p>GB/Z 185.4&#8212;2026 &#8212; Artificial intelligence &#8212; Agent interconnection &#8212; Part 4: Agent description</p></li></ul><ul><li><p>GB/Z 185.5&#8212;2026 &#8212; Artificial intelligence &#8212; Agent interconnection &#8212; Part 5: Agent discovery</p></li></ul><ul><li><p>ISO/IEC 22989:2022 &#8212; Information technology &#8212; Artificial intelligence &#8212; Artificial intelligence concepts and terminology</p></li></ul><p><strong>3 Terms and Definitions</strong></p><p><strong>3.1 AI agent</strong></p><p>A general term for an automated entity &#8212; that is, a process or system that can operate under specified conditions without human intervention or with controlled human intervention, that can perceive and respond to its environment, and that takes actions to achieve its goals.</p><p>[Source: ISO/IEC 22989:2022, 3.1.1, modified]</p><p><strong>3.2 AI agent service provider</strong></p><p>An organization or individual that provides AI agent services.</p><p><strong>3.3 AI agent description</strong></p><p>Machine- and human-understandable information used to describe an agent&#8217;s name, functions, and so forth.</p><p>[Source: GB/Z 185.4&#8212;2026, 3.1]</p><p>NOTE: In a specific system, the agent description generally follows a specific form of expression.</p><p><strong>3.4 AI agent credential</strong></p><p>A tamper-resistant collection of data that contains claims about an agent&#8217;s identity attributes and is used for identity authentication.</p><p>[Source: GB/Z 185.1&#8212;2026, 3.4]</p><p><strong>3.5 AI agent discovery</strong></p><p>The process of matching and obtaining one or more agent descriptions that meet business requirements.</p><p>[Source: GB/Z 185.5&#8212;2026, 3.1]</p><p><strong>3.6 Agent discovery service</strong></p><p>A process that implements or provides the agent discovery function.</p><p>[Source: GB/Z 185.5&#8212;2026, 3.2]</p><p><strong>3.7 Agent identity registration service</strong></p><p>A service that processes agent identity registration requests, performs agent identity verification, and manages agent identity accounts.</p><p>[Source: GB/Z 185.3&#8212;2026, 3.4, modified]</p><p><strong>3.8 Critical information infrastructure</strong></p><p>Important network facilities, information systems, and the like in important industries and fields such as public communications and information services, energy, transportation, water conservancy, finance, public services, e-government, and the national defense science, technology, and industry sector, as well as others that, once damaged, disabled, or subject to data breach, may seriously endanger national security, the national economy and people&#8217;s livelihood, or the public interest.</p><p>[Source: GB/T 39204&#8212;2022, 3.1]</p><p><strong>3.9 Tool</strong></p><p>A functional entity that can be invoked by an agent application.</p><p>NOTE: Examples of tools include cloud services, applications, agents, external devices, and so forth.</p><p><strong>3.10 Minimum privilege</strong></p><p>For a given subject, its access rights are limited to only those privileges necessary to perform the authorized tasks.</p><p>[Source: GB/T 5271.8&#8212;2001, 08.04.15, modified]</p><p><strong>3.11 Identity (identifier)</strong></p><p>Information that can uniquely determine the identity of an entity.</p><p>[Source: GM/T 0090&#8212;2020, 3.1]</p><p>NOTE: An identifier consists of information that the entity cannot repudiate, such as the entity&#8217;s identifiable name, email address, ID card number, telephone number, street address, and so forth.</p><p><strong>4 Abbreviations</strong></p><p>The following abbreviations apply to this document.</p><ul><li><p><strong>AI</strong>: Artificial Intelligence</p></li></ul><ul><li><p><strong>TLS</strong>: Transport Layer Security</p></li></ul><ul><li><p><strong>IP</strong>: Internet Protocol</p></li></ul><p><strong>5 Overview</strong></p><p>The security requirements for agent interaction include general security requirements for agent interaction, security requirements for agent-to-agent interaction, and security requirements for agent-to-tool interaction, as shown in Figure 1:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!G1vA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F734d8789-fa48-4d29-9644-52a8b7fde4c5_1800x1050.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!G1vA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F734d8789-fa48-4d29-9644-52a8b7fde4c5_1800x1050.png 424w, https://substackcdn.com/image/fetch/$s_!G1vA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F734d8789-fa48-4d29-9644-52a8b7fde4c5_1800x1050.png 848w, https://substackcdn.com/image/fetch/$s_!G1vA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F734d8789-fa48-4d29-9644-52a8b7fde4c5_1800x1050.png 1272w, https://substackcdn.com/image/fetch/$s_!G1vA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F734d8789-fa48-4d29-9644-52a8b7fde4c5_1800x1050.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!G1vA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F734d8789-fa48-4d29-9644-52a8b7fde4c5_1800x1050.png" width="1456" height="849" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/734d8789-fa48-4d29-9644-52a8b7fde4c5_1800x1050.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:849,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:55972,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.geopolitechs.org/i/208994629?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F734d8789-fa48-4d29-9644-52a8b7fde4c5_1800x1050.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!G1vA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F734d8789-fa48-4d29-9644-52a8b7fde4c5_1800x1050.png 424w, https://substackcdn.com/image/fetch/$s_!G1vA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F734d8789-fa48-4d29-9644-52a8b7fde4c5_1800x1050.png 848w, https://substackcdn.com/image/fetch/$s_!G1vA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F734d8789-fa48-4d29-9644-52a8b7fde4c5_1800x1050.png 1272w, https://substackcdn.com/image/fetch/$s_!G1vA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F734d8789-fa48-4d29-9644-52a8b7fde4c5_1800x1050.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Figure 1 &#8212; AI Agent Interaction Security Architecture</strong></p><p><em>Description of Figure 1 (original labels are in Chinese):</em> The architecture consists of two top-level blocks &#8212; <strong>Security Requirements for Agent-to-Agent Interaction</strong> (&#26234;&#33021;&#20307;&#38388;&#20132;&#20114;&#23433;&#20840;&#35201;&#27714;) and <strong>Security Requirements for Agent-to-Tool Interaction</strong> (&#26234;&#33021;&#20307;&#19982;&#24037;&#20855;&#20132;&#20114;&#23433;&#20840;&#35201;&#27714;) &#8212; which are both <strong>supported</strong> (&#25903;&#25745;) by a foundational layer, <strong>General Security Requirements for Agent Interaction</strong> (&#26234;&#33021;&#20307;&#20132;&#20114;&#36890;&#29992;&#23433;&#20840;&#35201;&#27714;). This foundational layer comprises four components: <strong>Identity</strong> (&#36523;&#20221;&#26631;&#35782;), <strong>Access Control</strong> (&#35775;&#38382;&#25511;&#21046;), <strong>Communication Security</strong> (&#36890;&#20449;&#23433;&#20840;), and <strong>Risk Management</strong> (&#39118;&#38505;&#31649;&#25511;).</p><p><strong>6 General Security Requirements for AI Agent Interaction</strong></p><p><strong>6.1 Identity</strong></p><p>An agent shall have an identifier that can uniquely identify the agent. An agent shall have an agent credential corresponding to that identifier.</p><p><strong>6.2 Access Control</strong></p><p>Both parties to an agent interaction shall support an access control mechanism to decide whether to permit access and to interrupt access.</p><p><strong>6.3 Communication Security</strong></p><p>The communication security requirements for agent interaction are as follows:</p><p>a) An agent shall use a secure communication channel that supports identity authentication of the access object and provides non-repudiation of both parties&#8217; behaviors.</p><p>b) An agent shall adopt encryption and integrity-verification strategies, and should use a transport-layer protocol of TLS 1.2 or above.</p><p>c) An agent that processes critical business carried by critical information infrastructure shall, during communication with an interaction counterpart, use cryptographic algorithms for identity authentication, data encryption, and integrity verification in accordance with the requirements of the national cryptography administration authority and relevant industry requirements.</p><p>d) An agent service provider shall support traffic monitoring and cleaning mechanisms, identify and rate-limit/block abnormally high-frequency requests, and prevent resource-exhaustion attacks.</p><p>e) An agent service provider should support a transmission-path redundancy mechanism that automatically switches to a backup path when the primary path is impaired.</p><p><strong>6.4 Risk Management</strong></p><p><strong>6.4.1 Proactive Prevention</strong></p><p>The proactive-prevention security requirements for agent interaction are as follows:</p><p>a) An agent service provider shall establish an interaction rate-limiting mechanism for agents, controlling the number of interaction counterparts and the interaction frequency of a single agent per unit of time.</p><p>b) An agent service provider should support making advance judgments about potential abnormal interaction behaviors based on historical interaction logs and behavior-feature libraries, and should intercept high-risk interaction requests or subject them to manual review.</p><p><strong>6.4.2 Anomaly Detection</strong></p><p>The anomaly-detection security requirements for agent interaction are as follows:</p><p>a) An agent service provider shall, on the condition that user authorization has been obtained, support a monitoring function for the agent interaction status, tracking in real time such information as communication time, interaction counterparts, interaction status, and interaction behaviors, and shall promptly discover and issue early warnings of abnormal behaviors.</p><p>b) When a non-convergent interaction or communication anomaly is detected, the agent service provider shall forcibly terminate the interaction and record the anomaly information.</p><p>NOTE: A non-convergent interaction refers to a situation in which the dialogue or operation sequence between agents falls into repetition, looping, or contradiction and cannot advance the task, or an interconnection interruption caused by a network fault, a crash of the counterpart agent, or non-responsiveness.</p><p>c) When the agent service provider detects abnormal behavior by either party to the interaction, it shall record the details of the abnormal event.</p><p><strong>6.4.3 Attack Analysis</strong></p><p>The attack-analysis security requirements for agent interaction are as follows:</p><p>a) For discovered attack activities, an agent service provider shall analyze the attack target and the attack route.</p><p>b) An agent service provider shall have a mechanism to protect against identified attack behaviors.</p><p>c) An agent service provider should establish a mechanism for collaborative anomaly detection across multiple agents.</p><p><strong>6.4.4 Emergency Response and Handling</strong></p><p>The emergency-response and handling security requirements for agent interaction are as follows:</p><p>a) An agent service provider shall formulate a graded response plan for agent interaction security incidents, clearly defining the handling procedures for general, relatively major, major, and especially major incidents.</p><p>b) An agent service provider shall formulate an emergency strategy for agent interaction. When an agent interaction security incident occurs, the provider shall immediately activate emergency response and handling measures, and &#8212; in light of the actual situation &#8212; rapidly implement measures such as severing communication connections, blocking interactions, isolation handling, and vulnerability remediation, and initiate secondary verification for objects that repeatedly exhibit anomalies. The provider shall produce an incident report and handling record, retain complete interaction logs and a chain of evidence, and prevent security risks from spreading along the interaction chain.</p><p>c) After a relatively major or higher-level security incident occurs, the agent service provider shall promptly report it to the competent authority.</p><p><strong>6.4.5 Traceability</strong></p><p>An agent service provider shall have an attack-traceability mechanism and should, based on the analysis results, build a profile of the attacker.</p><p><strong>7 Security Requirements for Agent-to-Agent Interaction</strong></p><p><strong>7.1 Agent Registration Security</strong></p><p>An agent service provider shall select an agent identity registration service. The service shall support the following security mechanisms for the registration process. At the time of registration:</p><p>a) The service shall authenticate the agent&#8217;s identity.</p><p>b) The service shall implement a registration monitoring mechanism that supports monitoring, alerting on, and deregistering agents with abnormal registrations.</p><p>c) The service shall conduct a compliance review of agent service providers, allowing only providers that pass the review to register their agents.</p><p>d) The service shall support an agent identity lifecycle management mechanism.</p><p>e) The service shall, based on the agent description, detect the authenticity of capabilities and the compliance of behaviors &#8212; including but not limited to detecting the capability scope, input/output types, the provider, and obvious false/malicious injection &#8212; and it is recommended that a third-party assessment organization be engaged to carry out testing.</p><p><strong>7.2 Agent Discovery Security</strong></p><p>The discovery-security requirements for agent interaction are as follows:</p><p>a) An agent service provider shall disclose agent descriptions based on a standardized agent discovery mechanism.</p><p>b) The agent service provider of the discovering party shall verify the integrity and source of the list information returned by discovery.</p><p>c) When an agent service provider chooses a service-based agent discovery mechanism, it shall select an agent discovery service that supports the following security mechanisms:</p><ol><li><p>It shall have an anti-interference agent recommendation/ranking mechanism;</p></li></ol><ol start="2"><li><p>It shall support an anti-tampering mechanism for the agent list;</p></li></ol><ol start="3"><li><p>It shall support a mechanism for identifying and blocking malicious queries.</p></li></ol><p><strong>7.3 Agent-to-Agent Invocation Security</strong></p><p>The invocation-security requirements for agent interaction are as follows:</p><p>a) Both parties to an agent invocation shall perform mutual identity authentication.</p><p>b) Both parties to an agent invocation shall, through a standard interface or other form, exchange each other&#8217;s agent descriptions, security policies, data requirements, and potential risks, and shall reach an invocation agreement on the basis that both parties fully understand the potential impacts.</p><p>c) Both parties to an agent invocation shall follow the principle of minimum privilege, shall support a privilege-negotiation mechanism, and the validity of privileges shall be verifiable.</p><p>d) An agent shall ensure decision-making autonomy during collaboration, preventing unauthorized parties from tampering with its decision logic or goals.</p><p>e) During the interaction, both parties to an agent invocation should support lifecycle management of the invocation session and a mechanism to prevent session hijacking.</p><p>NOTE: A session corresponds to one multi-agent interaction process. It is created by the requesting agent and has a numbered identifier, used to manage the service agents, messages, and tasks involved in that process.</p><p>f) Both parties to an agent invocation shall have a security-protection mechanism against attack behaviors and content in inputs and outputs, and &#8212; for critical information &#8212; shall have the ability to verify its authenticity and integrity.</p><p>g) Both parties to an agent invocation shall support a mechanism to identify abnormal behaviors that exceed the scope of the agent description.</p><p>h) During the interaction, the called-party agent shall be prohibited from enabling high-risk system privileges without user authorization.</p><p>i) The calling-party agent service provider shall grant only the minimum privileges consented to by the user; the called-party agent shall verify that such privileges are consistent with the user&#8217;s original authorization, and shall save the invocation logs.</p><p><strong>8 Security Requirements for Agent-to-Tool Interaction</strong></p><p><strong>8.1 Tool Discovery Security</strong></p><p>The tool-discovery security requirements for agent interaction are as follows:</p><p>a) During tool discovery, the agent service provider shall ensure that the source and integrity of the tool list are verifiable.</p><p>b) A tool provider shall disclose to the calling party complete tool attribute information whose integrity and source can be verified, containing at least the tool identifier, tool name, tool description, and tool input/output parameters.</p><p><strong>8.2 Tool Invocation Security</strong></p><p>The tool-invocation security requirements for agent interaction are as follows:</p><p>a) An agent shall obtain user authorization when invoking a tool.</p><p>b) When an agent invokes a tool, identity authentication shall be performed based on an identity-authentication mode supported by both parties.</p><p>NOTE: The identity-authentication mode may be any of the following: mutual identity authentication; the agent unilaterally authenticating the tool; the tool unilaterally authenticating the agent; or no identity authentication.</p><p>c) A tool provider shall implement the principle of minimum interface exposure, exposing to the agent only the minimum necessary functional interfaces.</p><p>d) When an agent invokes a tool, it shall follow the principle of minimum privilege.</p><p>e) When an agent invokes a tool by means of a protocol, it shall be based on a standardized protocol recognized by both parties.</p><p>f) An agent shall, on the basis of clear business necessity and risk-assessment results, strictly limit the application for and use of high-risk system privileges.</p><p>g) For tool invocations involving high-risk system privileges, the agent service provider shall fully inform the user of the security risks and obtain the user&#8217;s express consent.</p><p>h) An agent shall support a malicious-tool identification mechanism; when it identifies the tool to be invoked as a malicious tool, it shall not initiate the invocation.</p><p>i) An agent shall inspect the feedback information from tools; when it identifies malicious content or malicious behavior, it shall stop the invocation.</p><p><strong>Appendix A (Informative) &#8212; List of AI Agent Interaction Security Risks</strong></p><p><strong>Table 1 &#8212; List of AI Agent Interaction Security Risks</strong></p><p>T01 Information Tampering</p><p><strong>Risk description:</strong> Tampering with input instructions, tampering with tool lists, tampering with invocation parameters/return results.</p><p><strong>Covered clauses:</strong> 6.3 Communication Security; 7.3 Agent-to-Agent Invocation Security (f); 8.1 Tool Discovery Security (b); 8.2 Tool Invocation Security (i).</p><p><strong>Solution:</strong></p><ol><li><p>Use a communication channel with encryption and integrity verification (6.3 b).</p></li></ol><ol start="2"><li><p>For agent-to-agent invocation, verify the authenticity and integrity of critical information (7.3 f).</p></li></ol><ol start="3"><li><p>During tool discovery, verify the integrity of the tool list and tool attribute information (8.1 a, b).</p></li></ol><ol start="4"><li><p>During tool invocation, inspect the tool&#8217;s feedback information and identify malicious content or behavior (8.2 i).</p></li></ol><p>T02 Information Leakage</p><p><strong>Risk description:</strong> Leakage of invocation-parameter/return-result information, output of sensitive information, memory theft.</p><p><strong>Covered clauses:</strong> 6.3 Communication Security; 7.3 Agent-to-Agent Invocation Security (b, f); 8.2 Tool Invocation Security (g).</p><p><strong>Solution:</strong></p><ol><li><p>Use an encrypted communication channel (6.3 b).</p></li></ol><ol start="2"><li><p>Exchange data requirements and security policies before agent-to-agent invocation (7.3 b), and apply security protection to output content (7.3 f).</p></li></ol><ol start="3"><li><p>Strictly limit the application for and use of high-risk system privileges, invoking them only in a controlled environment (8.2 g).</p></li></ol><ol start="4"><li><p>Follow the principle of minimum privilege (6.2, 7.3 c, 8.2 d).</p></li></ol><p>T03 Information Missing</p><p><strong>Risk description:</strong> Incomplete logs, difficulty in tracing accountability.</p><p><strong>Covered clauses:</strong> 6.4.5 Traceability; 7.3 Agent-to-Agent Invocation Security (i).</p><p><strong>Solution:</strong></p><ol><li><p>The agent service provider shall have an attack-traceability mechanism (6.4.5).</p></li></ol><ol start="2"><li><p>Agent-to-agent invocation shall save the invocation logs (7.3 i).</p></li></ol><p>T04 Harmful Information</p><p><strong>Risk description:</strong> Injection of harmful instructions, indirect injection, business-logic bypass, tool-description poisoning, malicious content in invocation parameters/return results, output of harmful/malicious content, propagation of false information.</p><p><strong>Covered clauses:</strong> 6.4.2 Anomaly Detection; 7.3 Agent-to-Agent Invocation Security (f, g); 8.2 Tool Invocation Security (h, i).</p><p><strong>Solution:</strong></p><ol><li><p>Monitor the interaction status, and detect and terminate non-convergent or abnormal interactions (6.4.2).</p></li></ol><ol start="2"><li><p>For agent-to-agent invocation, apply security protection to inputs and outputs and identify abnormal behaviors (7.3 f, g).</p></li></ol><ol start="3"><li><p>During tool invocation, support a malicious-tool identification mechanism (8.2 h) and detect malicious content fed back by tools (8.2 i).</p></li></ol><p>T05 Identity Error</p><p><strong>Risk description:</strong> Identity impersonation, agent identity forgery, forgery of the caller&#8217;s identity, confusion of user identity, unclear identity of the recipient, session hijacking.</p><p><strong>Covered clauses:</strong> 6.1 Identity; 7.1 Agent Registration Security (a); 7.3 Agent-to-Agent Invocation Security (a, e); 8.2 Tool Invocation Security (b).</p><p><strong>Solution:</strong></p><ol><li><p>An agent shall have a unique identifier and a corresponding credential (6.1).</p></li></ol><ol start="2"><li><p>Agent identity shall be authenticated at registration (7.1 a).</p></li></ol><ol start="3"><li><p>Agent-to-agent invocation must implement mutual identity authentication (7.3 a).</p></li></ol><ol start="4"><li><p>When an agent invokes a tool, identity authentication shall be performed based on a mode supported by both parties (8.2 b).</p></li></ol><ol start="5"><li><p>Support lifecycle management of invocation sessions and a session-hijacking prevention mechanism (7.3 (e)).</p></li></ol><p>T06 Privilege Loss of Control</p><p><strong>Risk description:</strong> Unauthorized access, unauthorized execution, environment jailbreak, runtime-environment escape, privilege overreach, system-privilege escalation, excessive privilege application.</p><p><strong>Covered clauses:</strong> 6.2 Access Control; 7.3 Agent-to-Agent Invocation Security (c, h, i); 8.2 Tool Invocation Security (a, d, g).</p><p><strong>Solution:</strong></p><ol><li><p>Both parties to the interaction shall support an access control mechanism (6.2).</p></li></ol><ol start="2"><li><p>Agent-to-agent invocation shall follow the principle of minimum privilege and support privilege negotiation and verification (7.3 c), shall prohibit enabling high-risk privileges without user authorization (7.3 h), and shall verify that privileges are consistent with the user&#8217;s original authorization (7.3 i).</p></li></ol><ol start="3"><li><p>Tool invocation shall obtain user authorization (8.2 a), follow minimum privilege (8.2 d), and strictly limit the use of high-risk privileges to controlled environments (8.2 g).</p></li></ol><p>T07 Resource Occupation</p><p><strong>Risk description:</strong> DoS attacks, planning confusion, resource overload, abuse of system functions.</p><p><strong>Covered clauses:</strong> 6.3 Communication Security (d); 6.4.1 Proactive Prevention (a); 6.4.2 Anomaly Detection (a).</p><p><strong>Solution:</strong></p><ol><li><p>Support traffic monitoring and cleaning, and identify and rate-limit/block abnormally high-frequency requests (6.3 d).</p></li></ol><ol start="2"><li><p>Establish an interaction rate-limiting mechanism to control the number and frequency of interaction counterparts per unit of time (6.4.1 a).</p></li></ol><ol start="3"><li><p>Monitor the interaction status and promptly discover and issue early warnings of abnormal behaviors (6.4.2 a).</p></li></ol><p>T08 Attack Behavior</p><p><strong>Risk description:</strong> DoS attack tools, output of attack behaviors, output of malicious code/scripts, multi-agent collaborative attacks, spread of attacks caused by the absence of an emergency-response and handling mechanism for security incidents.</p><p><strong>Covered clauses:</strong> 6.4.3 Attack Analysis; 7.3 Agent-to-Agent Invocation Security (f); 8.2 Tool Invocation Security (i); 6.4.4 Emergency Response and Handling.</p><p><strong>Solution:</strong></p><ol><li><p>Analyze and protect against discovered attack activities, and should establish a mechanism for collaborative anomaly detection across multiple agents (6.4.3).</p></li></ol><ol start="2"><li><p>For agent-to-agent invocation, have a security-protection mechanism against attack behaviors in inputs and outputs (7.3 f).</p></li></ol><ol start="3"><li><p>During tool invocation, inspect the tool&#8217;s feedback information and stop the invocation upon identifying malicious behavior (8.2 i).</p></li></ol><ol start="4"><li><p>For emergency response and handling, implement graded plans, severing/isolation/remediation, secondary verification, retention of the chain of evidence, reporting, and other handling measures (6.4.4).</p></li></ol><p>T09 Component Risk</p><p><strong>Risk description:</strong> Malicious materials, materials with vulnerabilities, malicious extensions.</p><p><strong>Covered clauses:</strong> 7.1 Agent Registration Security (e) (indirectly, through referencing GB/T 43698 and GB/T 44111).</p><p><strong>Solution:</strong></p><ol><li><p>At registration, detect the authenticity of capabilities and the compliance of behaviors based on the agent description, and it is recommended to engage a third-party assessment (7.1 e).</p></li></ol><ol start="2"><li><p>The normative references include software-supply-chain security standards (GB/T 43698, GB/T 44111), which provide a standards basis for preventing component risks.</p></li></ol><p>T10 Intent Hijacking</p><p><strong>Risk description:</strong> Infringement of the right to choose tools, manipulation of tool ranking, mismatch during the discovery stage or invocation of the wrong object caused by non-standard or tampered agent descriptions.</p><p><strong>Covered clauses:</strong> 7.2 Agent Discovery Security (c, a); 8.1 Tool Discovery Security (b).</p><p><strong>Solution:</strong></p><ol><li><p>When choosing a service-based discovery mechanism, select a service that has an anti-interference agent recommendation/ranking mechanism (7.2 c 1)).</p></li></ol><ol start="2"><li><p>Disclose agent descriptions based on a standardized agent discovery mechanism (7.2 (a)).</p></li></ol><ol start="3"><li><p>Tool attribute information shall be disclosed completely and with verifiable integrity (8.1 (b)).</p></li></ol><p>T11 Tool Abuse</p><p><strong>Risk description:</strong> Malicious tools, tool-combination attacks, tool downgrading, illegal operations, tool abuse, tool poisoning, unauthorized execution by tools.</p><p><strong>Covered clauses:</strong> 7.1 Agent Registration Security (e); 8.1 Tool Discovery Security (a); 8.2 Tool Invocation Security (g, h, i).</p><p><strong>Solution:</strong></p><ol><li><p>At registration, detect the authenticity of the agent&#8217;s capabilities and the compliance of its behaviors (7.1 e).</p></li></ol><ol start="2"><li><p>During tool discovery, ensure the source and integrity of the tool list are verifiable (8.1 a).</p></li></ol><ol start="3"><li><p>Limit high-risk tool invocation to controlled environments and explicitly obtain user authorization (8.2 g).</p></li></ol><ol start="4"><li><p>Support a malicious-tool identification mechanism (8.2 h), and stop the invocation upon detecting malicious content or behavior (8.2 i).</p></li></ol><p>T14 Intent Deviation</p><p><strong>Risk description:</strong> Reasoning hijacking, goal hijacking, hallucination amplification, cumulative intent drift, long-context attacks, entropy increase in tool selection, abnormal task execution.</p><p><strong>Covered clauses:</strong> 6.4.2 Anomaly Detection; 7.3 Agent-to-Agent Invocation Security (d, g).</p><p><strong>Solution:</strong></p><ol><li><p>Monitor the interaction status, and forcibly terminate and record when a non-convergent interaction (falling into a loop or contradiction) is detected (6.4.2).</p></li></ol><ol start="2"><li><p>An agent shall ensure decision-making autonomy during collaboration, preventing unauthorized parties from tampering with its decision logic or goals (7.3 d).</p></li></ol><ol start="3"><li><p>Support a mechanism to identify abnormal behaviors that exceed the scope of the agent description (7.3 g).</p></li></ol><div><hr></div><p>References</p><p>[1] GB 45438&#8212;2025 &#8212; Cybersecurity technology &#8212; Labeling method for content generated and synthesized by artificial intelligence</p><p>[2] GB/T 34975&#8212;2017 &#8212; Information security technology &#8212; Security technical requirements and testing and evaluation methods for application software of mobile intelligent terminals</p><p>[3] GB/T 35273 &#8212; Information security technology &#8212; Personal information security specification</p><p>[4] GB/T 39720&#8212;2020 &#8212; Information security technology &#8212; Security technical requirements and testing and evaluation methods for mobile intelligent terminals</p><p>[5] GB/T 39276&#8212;2020 &#8212; Information security technology &#8212; General security requirements for network products and services</p><p>[6] GB/T 45574&#8212;2025 &#8212; Data security technology &#8212; Security requirements for the processing of sensitive personal information</p><p>[7] GB/T 45652&#8212;2025 &#8212; Cybersecurity technology &#8212; Data security specification for generative artificial intelligence pre-training and optimization-training</p><p>[8] GB/T 45654&#8212;2025 &#8212; Cybersecurity technology &#8212; Basic security requirements for generative artificial intelligence services</p><p>[9] GB/T 45674&#8212;2025 &#8212; Cybersecurity technology &#8212; Data-annotation security specification for generative artificial intelligence</p><p>[10] HarmonyOS AI Agent Framework White Paper</p><p>[11] YD/T 3973&#8212;2021 &#8212; General technical requirements for end-to-end 5G network slicing</p><p>[12] YD/T 6095&#8212;2024 &#8212; General technical requirements for fixed-mobile convergence dedicated-line services based on the SDN/NFV new-generation network architecture</p><div><hr></div><p><em>This is an unofficial English translation prepared for reference only. In case of any discrepancy, the original Chinese document (&#8221;&#32593;&#32476;&#23433;&#20840;&#26631;&#20934;&#23454;&#36341;&#25351;&#21335;&#8212;&#8212;&#26234;&#33021;&#20307;&#20132;&#20114;&#23433;&#20840;&#35201;&#27714;&#65288;&#24449;&#27714;&#24847;&#35265;&#31295;&#65289;&#8221;, TC260-PG-2026NA) prevails. Source: Secretariat of the National Information Security Standardization Technical Committee.</em></p>]]></content:encoded></item><item><title><![CDATA[China's First Comprehensive Response to Western Overcapacity Allegations]]></title><description><![CDATA[Today, the Chinese government held a press briefing to present its official position on the overcapacity issue by releasing a position paper titled &#8220;China&#8217;s Position on the So-called Excess Capacity Issue&#8221;]]></description><link>https://www.geopolitechs.org/p/chinas-first-comprehensive-response</link><guid isPermaLink="false">https://www.geopolitechs.org/p/chinas-first-comprehensive-response</guid><dc:creator><![CDATA[Geopolitechs]]></dc:creator><pubDate>Tue, 28 Jul 2026 09:53:53 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Ysqd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa82718a9-5427-489b-b57f-7ac24f8900c5_750x333.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Today, the Chinese government held a press briefing to present its official position on the overcapacity issue by releasing a position paper titled &#8220;<a href="https://www.news.cn/20260728/558861063fe74feb974b683dd8447a41/c.html">China&#8217;s Position on the So-called Excess Capacity Issue</a>&#8221;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ysqd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa82718a9-5427-489b-b57f-7ac24f8900c5_750x333.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ysqd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa82718a9-5427-489b-b57f-7ac24f8900c5_750x333.webp 424w, https://substackcdn.com/image/fetch/$s_!Ysqd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa82718a9-5427-489b-b57f-7ac24f8900c5_750x333.webp 848w, https://substackcdn.com/image/fetch/$s_!Ysqd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa82718a9-5427-489b-b57f-7ac24f8900c5_750x333.webp 1272w, https://substackcdn.com/image/fetch/$s_!Ysqd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa82718a9-5427-489b-b57f-7ac24f8900c5_750x333.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ysqd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa82718a9-5427-489b-b57f-7ac24f8900c5_750x333.webp" width="750" height="333" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a82718a9-5427-489b-b57f-7ac24f8900c5_750x333.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:333,&quot;width&quot;:750,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:14884,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.geopolitechs.org/i/208807761?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa82718a9-5427-489b-b57f-7ac24f8900c5_750x333.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Ysqd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa82718a9-5427-489b-b57f-7ac24f8900c5_750x333.webp 424w, https://substackcdn.com/image/fetch/$s_!Ysqd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa82718a9-5427-489b-b57f-7ac24f8900c5_750x333.webp 848w, https://substackcdn.com/image/fetch/$s_!Ysqd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa82718a9-5427-489b-b57f-7ac24f8900c5_750x333.webp 1272w, https://substackcdn.com/image/fetch/$s_!Ysqd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa82718a9-5427-489b-b57f-7ac24f8900c5_750x333.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Overcapacity has long been one of the most contentious issues in China&#8217;s trade relations with both the European Union and the United States. In Washington and Brussels, the prevailing view is that China has continuously directed large amounts of capital into strategic manufacturing sectors through subsidies, policy lending, low-cost land and energy, government procurement, and local industrial policies. Because domestic demand is seen as insufficient to absorb the resulting output, the surplus is ultimately exported at low prices, putting pressure on manufacturing industries in other countries.</p><p>That said, the United States and the European Union do not frame the issue in exactly the same way. The United States primarily views it through the lens of macroeconomic imbalances, industrial security, and strategic competition with China. The European Union, by contrast, focuses more on demonstrating the existence of specific subsidies, import injury, and the legal basis for trade remedy measures.</p><p>I have participated in several discussions on China-Europe economic relations, involving both think tanks and industry representatives, and one thing has become increasingly clear to me: there remains a significant gap between Chinese and European perspectives on this issue.</p><p>European experts generally argue that the challenge has evolved beyond isolated trade disputes or individual industries into a structural conflict between two different economic models. In their view, China relies on exports and industrial upgrading to sustain economic growth, while Europe sees its own manufacturing base coming under sustained pressure, with implications for employment, industrial capacity, and political stability. As a result, Europe&#8217;s &#8220;de-risking&#8221; agenda is driven as much by domestic economic and political considerations as by geopolitics. </p><p>Many also argue that years of dialogue have failed to change the underlying dynamics, prompting the EU to rely increasingly on legal and industrial policy tools in an effort to encourage adjustments by China. With China&#8217;s technological upgrading accelerating, many in Europe believe that waiting longer would only further erode Europe&#8217;s industrial competitiveness.</p><p>China apparently has a very different view, as indicated by the word &#8220;so-called&#8221; being used in the title of the official position paper. Chinese experts generally argue that the China-EU trade imbalance is primarily the result of macroeconomic structures rather than unfair competition driven by subsidies. China has maintained a high savings rate for decades, while domestic investment has slowed in recent years, naturally producing current account surpluses and capital outflows. </p><p>They contend that China&#8217;s manufacturing competitiveness is rooted in its enormous domestic market, highly integrated supply chains, and industrial clusters&#8212;not simply in government support. In this view, attributing trade imbalances entirely to industrial policy misdiagnoses the problem and risks turning what should be addressed through macroeconomic adjustment into a trade conflict. </p><p>Some Chinese experts also question the methodologies used in Western studies on China&#8217;s overcapacity and subsidy levels, arguing that they rely on strong assumptions and that policies built on those estimates could face challenges both economically and under international trade rules.</p><p>I am not a trade economist, and it will be too difficult to take a position on this debate. My impression is that this is an extraordinarily complex issue that deserves much more research and discussion by international experts.</p><p>The position paper released by the Chinese government today is, from my personal view, a detailed response to many of the criticisms that the United States and Europe have made against China on this issue over the past several years. I would recommend that anyone following China trade policy&#8212;including policy watchers and trade lawyers&#8212;read it carefully.</p><p>One small but telling detail is the title of the position paper. The official English version is "China's Position on the So-called <strong>Excess Capacity</strong> Issue," rather than using the much more common Western term "<strong>overcapacity</strong>." This is unlikely to be accidental. </p><p>In U.S. and European policy discussions, &#8220;overcapacity&#8221; has become a loaded political term, implicitly accepting the premise that China suffers from a structural overcapacity problem. By choosing the more neutral phrase &#8220;excess capacity&#8221; and prefacing it with &#8220;<strong>so-called</strong>&#8221;, China seems to signal that it does not accept the Western framing of the debate. </p><p>You can download the full English text of China&#8217;s position paper here:</p><p><strong><a href="https://english.news.cn/20260728/d954bc12e2af498d8301f3922f4dbe68/c.html">China&#8217;s Position on the So-called Excess Capacity Issue</a></strong></p><p>The full English transcript (my own translation) of today&#8217;s press briefing is available here:</p><h2>Opening Remarks</h2><p><strong>Jia Huili, Deputy Director-General of the News Bureau of the State Council Information Office and Spokesperson:</strong></p><p>Good afternoon, ladies and gentlemen. Welcome to this press conference of the State Council Information Office.</p><p>Today, the Ministry of Commerce released the document <strong>China&#8217;s Position on the So-Called &#8220;Overcapacity&#8221; Issue</strong>. We are joined by Mr. Yan Dong, Vice Minister of Commerce, who will brief us on the document and answer questions of concern. Also attending today&#8217;s press conference are Mr. Lin Weilong, Director-General of the Policy Research Department of the Ministry of Commerce; Mr. Han Yong, Director-General of the Department of World Trade Organization Affairs; and Mr. He Shaojun, head of the Department of Foreign Trade.</p><p>First, I will give the floor to Mr. Yan Dong.</p><h2>Introductory Statement</h2><p><strong>Yan Dong, Vice Minister of Commerce:</strong></p><p>Thank you, Madam Moderator. Friends from the media, good afternoon.</p><p>As just mentioned, the Ministry of Commerce today released the document <strong>China&#8217;s Position on the So-Called &#8220;Overcapacity&#8221; Issue</strong>. I would like to take this opportunity to briefly introduce the background to its release and its main contents.</p><p>In recent years, global economic growth has lacked momentum. The international community has paid broad attention to global supply-demand balance and capacity issues, and there has been much discussion. In particular, some economies, out of concern over their own industrial competitiveness and market position, have politicized economic and trade issues, hyped up the so-called issue of Chinese &#8220;overcapacity,&#8221; and even deliberately confused concepts by linking industrial subsidies, trade surpluses, economic imbalances, and market competition with &#8220;overcapacity.&#8221; They have pushed narratives such as &#8220;China Shock 2.0&#8221; and used the so-called &#8220;overcapacity&#8221; issue as a pretext to implement all kinds of protectionist measures.</p><p>President Xi Jinping has pointed out that blowing out others&#8217; lamps will not make oneself brighter, and blocking others&#8217; paths will ultimately block one&#8217;s own. China believes that capacity issues should be viewed in a comprehensive, objective, and fair manner, and must not be used as a pretext for protectionism. Doing so will only disrupt the global economic and trade order and the stability of industrial and supply chains, aggravate contradictions and divisions, and create long-term risks for global economic growth. To clarify the facts and explain China&#8217;s views and position on issues related to the so-called &#8220;overcapacity,&#8221; we prepared this position paper.</p><p>The Chinese version of the document contains more than 10,000 Chinese characters, and an English version has also been released simultaneously on the website of the Ministry of Commerce. The full text consists of three parts: a preface, the main body, and a conclusion. The main body has four chapters.</p><p>Chapter One is <strong>A Comprehensive and Objective View of Global Capacity and the So-Called &#8220;Overcapacity.&#8221;</strong> This chapter reviews, from a historical perspective, the evolution of the global capacity landscape and explains that the gradual shift of the global industrial pattern from a single center to multiple centers is the result of international industrial division of labor. &#8220;Overcapacity&#8221; is a dynamic phenomenon in a market economy. Different parties understand the concept differently, and the situation in different economies and industries should be measured according to their stages and levels of development.</p><p>Chapter Two is <strong>China&#8217;s Position on Four Relationships Related to &#8220;Overcapacity.&#8221;</strong> It objectively analyzes the relationship between industrial subsidies, trade surpluses, economic imbalances, market competition, and &#8220;overcapacity,&#8221; emphasizing that there is no necessary connection between industrial subsidies and overcapacity, that more exports and larger surpluses do not equal overcapacity, that global economic imbalance is a historical norm with complex roots, and that market competition is an important safeguard for the optimization and adjustment of capacity.</p><p>Chapter Three is <strong>China&#8217;s Commitment to Building a Modern Industrial System Through Openness and Cooperation.</strong> This chapter focuses on China&#8217;s policy practices and future direction. It explains that the rapid development of China&#8217;s modern industries is driven by innovation, and that the steady and healthy operation of industry depends on deepening reform. It also makes clear that the development of China&#8217;s modern industries is not the so-called &#8220;China Shock 2.0,&#8221; but rather &#8220;China Opportunity 2.0.&#8221;</p><p>Chapter Four is <strong>Jointly Promoting an Open and Inclusive Global Industrial and Supply Chain Cooperation Landscape.</strong> This chapter presents China&#8217;s vision and proposals. It calls on the international community to shoulder responsibilities together and move toward one another, advocate mutual benefit and win-win outcomes, respect market rules, strengthen coordination of industrial policies, expand market openness, create cooperation opportunities, uphold multilateralism, and build a fairer and more equitable international economic order.</p><p>That is all for my introduction. My colleagues and I are now ready to take your questions. Thank you.</p><p><strong>Jia Huili:</strong></p><p>Thank you, Mr. Yan Dong, for the introduction. We will now move to questions. Please identify your media outlet before asking your question.</p><h2>Questions and Answers</h2><p><strong>Reporter from The Beijing News, Shell Finance:</strong></p><p>At present, countries hold different views on the issue of &#8220;overcapacity,&#8221; and international institutions also lack a unified definition. Evaluation criteria vary significantly and there are major differences of opinion. How should we understand this issue? Thank you.</p><p><strong>Yan Dong:</strong></p><p>I will invite Director-General Lin Weilong of the Policy Research Department to answer this question.</p><p><strong>Lin Weilong, Director-General of the Policy Research Department, Ministry of Commerce:</strong></p><p>Thank you for your question. As you just mentioned, the concept of &#8220;overcapacity&#8221; and related issues have long been disputed in the international community, and no broad consensus has been reached. I would like to explain this from three dimensions so that the issue can be understood in a more comprehensive, objective, and systematic way.</p><p>The first is the theoretical dimension. &#8220;Overcapacity&#8221; is a complex concept that needs to be understood in a specific economic context. Most economists explain it from both macro and micro perspectives. At the macro level, it refers to supply exceeding demand, with total production capacity clearly surpassing total demand. At the micro level, it refers to idle enterprise capacity, with factors such as monopolistic competition preventing the clearing of capacity and keeping output below its optimal state. &#8220;Overcapacity&#8221; is a dynamic phenomenon in a market economy. It is related both to changes in supply and demand and to the industrial life cycle, and it always exists in a dynamic cycle of balance, imbalance, and rebalancing. Balance is relative; imbalance is common.</p><p>The second is the historical dimension. The global center of capacity has undergone several major shifts along with industrial relocation. Since the First Industrial Revolution, factors of production around the world have accelerated their movement, and the United Kingdom and the United States successively became world industrial centers. In 1880, the United Kingdom&#8217;s share of global industrial output reached a peak of 22.9 percent; in 1953, the United States&#8217; share reached as high as 44.7 percent. After World War II, the world experienced multiple waves of industrial transfer: from the United States to Europe, from Europe and the United States to Japan, then to East Asia and China, and now from parts of China to Southeast Asia and other regions. This has formed three major regional manufacturing centers in North America, Europe, and East Asia. China&#8217;s emergence as the &#8220;world&#8217;s factory&#8221; is the result of actively integrating into economic globalization and participating in international industrial division of labor, and it is an important component of the global manufacturing network.</p><p>The third is the practical dimension. Capacity utilization needs to be assessed in light of the realities of different countries and industries. Internationally, capacity utilization is commonly used to measure &#8220;overcapacity.&#8221; This indicator is the ratio of actual output to potential output. Reasonable ranges differ across economies, and there is no universally applicable global standard. The median capacity utilization rate in developed and fast-growing economies is usually between 75 percent and 80 percent, while in less developed countries it is generally between 50 percent and 64 percent. At the same time, capacity utilization differs greatly across industries. In some traditional industries, capacity utilization is clearly below the average level. In some countries, utilization in industries such as beverages and furniture is around 65 percent, while in rubber, chemicals, and plastics it is only 40 to 50 percent. Emerging industries tend to have relatively higher rates. In some countries, capacity utilization in computers and peripheral equipment reaches 83 percent, and in electrical equipment and components it reaches 86 percent. Looking at countries&#8217; economic practice, capacity utilization is somewhat objective as a measure of the state of capacity use, but it should not be absolutized as a standard for judging whether different economies or industries have overcapacity.</p><p>In light of China&#8217;s actual development, industrial capacity utilization as a whole remains within a reasonable range. In 2025, the capacity utilization rate of above-designated-size industry was 74.4 percent. In fields such as high-tech manufacturing, high-end equipment manufacturing, and strategic emerging industries, capacity was used more fully. In some traditional industries, such as raw materials, utilization was temporarily lower, mainly because of adaptive adjustments brought about by structural transformation and green transition. This is a normal phenomenon in the process of industrial upgrading and quality improvement. Overall, China&#8217;s industry remains basically balanced in supply and demand and operates steadily.</p><p>Thank you.</p><p><strong>Reporter from China News Service:</strong></p><p>In recent years, there has been an international narrative that subsidies cause overcapacity. How does China view such statements? Also, what is the relationship between industrial subsidies and &#8220;overcapacity&#8221;? Thank you.</p><p><strong>Yan Dong:</strong></p><p>Thank you for your question. I will ask Director-General Han Yong of the WTO Affairs Department to answer.</p><p><strong>Han Yong, Director-General of the Department of World Trade Organization Affairs, Ministry of Commerce:</strong></p><p>Thank you for the question. At present, many countries formulate industrial policies tailored to their national conditions and industrial development needs. For example, they provide research and development subsidies for emerging industries and risk subsidies for agriculture. These are WTO-consistent industrial and trade policy tools available to members. Multiple reports by UNCTAD show that the number of industrial policies worldwide has been on the rise over the past five years, and that R&amp;D subsidies, tax incentives, and low-interest loans have become internationally common approaches to supporting emerging industries. What needs to be emphasized here is that industrial subsidies are not a problem in themselves, nor is there any necessary connection between industrial subsidies and overcapacity. Reasonable and compliant subsidy policies can help correct market failures, advance technological innovation, protect the ecological environment, reduce poverty, and promote balanced development. They do not create the so-called &#8220;overcapacity.&#8221;</p><p>On the other hand, if protectionist measures are adopted and non-compliant industrial policies are introduced to shift burdens onto others and restrict competition, they will disrupt the global economic and trade order. The U.S. Inflation Reduction Act plans to provide $750 billion in various subsidies from 2022 to 2031, and subsidized electric vehicles must meet conditions such as being produced and sold locally or in North America, thereby excluding other countries and regions. In addition, according to incomplete statistics, the European Commission will provide more than 1.44 trillion euros in various subsidies between 2021 and 2030. The EU&#8217;s Industrial Accelerator Act proposes to directly link local content with fiscal support through an &#8220;EU-origin&#8221; requirement, creating serious investment barriers and institutional discrimination. Major powers are the leaders of global industrial development and should set an example by using subsidies reasonably on the basis of openness, fairness, and compliance, avoiding discriminatory subsidy policies and avoiding artificial interference in the global layout of industrial and supply chains.</p><p>China has always strictly observed WTO rules and is committed to building and improving a fiscal subsidy system consistent with international practices. Over the years, China has taken multiple measures to continuously improve the compliance, scientific basis, and transparency of subsidies, and has constantly standardized and refined related policies. It has cleaned up and regulated some improper local subsidies and is studying the establishment of a unified negative list management mechanism for local fiscal subsidies. China fulfills its WTO transparency obligations in a timely and comprehensive manner, and its subsidy notifications cover the entire country. Chinese subsidies are mainly directed to areas such as scientific research and development, commercialization of technology, and market consumption. More often, China uses market-based and guiding means such as public services, technical standards, and skills training, with&#37325;&#28857; support for technological innovation, small and medium-sized enterprises, green development, and energy conservation. China&#8217;s subsidies apply equally to all kinds of market entities. Foreign-invested enterprises actively participate and benefit on an equal footing.</p><p>Development is an eternal theme of human society. All countries should focus on making the global development pie bigger and introduce industrial policies in a reasonable and compliant manner, rather than using them as tools to restrain other countries&#8217; development. China is willing to hold discussions with all parties under the WTO framework on relevant industrial policies, jointly regulate related practices, and promote the updating of multilateral rules.</p><p>Thank you.</p><p><strong>Reporter from Bloomberg News:</strong></p><p>Does China plan to address trade partners&#8217; concerns about &#8220;overcapacity&#8221; and the displacement of domestic industries by low-cost Chinese exports? If so, what specific measures will it take? And do you expect the trade surplus to reach another record high this year? Thank you.</p><p><strong>Yan Dong:</strong></p><p>This question concerns trade, so I will ask Mr. He Shaojun from the Department of Foreign Trade to answer.</p><p><strong>He Shaojun, head of the Department of Foreign Trade, Ministry of Commerce:</strong></p><p>Thank you for your question. Trade surplus is a topic of broad concern, and I would like to take this opportunity to share some views from several angles.</p><p>First, a surplus reflects profound changes in the international division of labor. Looking back at the history of global economic development, countries generally went through stages of trade surplus during industrialization. Manufacturing powers such as the United Kingdom, the United States, Japan, and Germany all maintained trade surpluses for long periods. At the product level, 80 percent of U.S. chips are exported, and about two-thirds of commercial aircraft delivered by Boeing are sold to customers outside North America. In 2025, the European Union recorded surpluses of $92.2 billion in automobiles, $214.6 billion in pharmaceuticals, and $11.6 billion in cosmetics. More exports and larger surpluses do not equal overcapacity. China&#8217;s trade surplus reflects the completeness and efficiency of its industrial system and is an objective result of changes in the global division of labor and trade patterns.</p><p>Second, Chinese products meet the production and daily-life needs of countries around the world. Consumer goods produced in China, such as computers, mobile phones, furniture, clothing, and toys, provide consumers in various countries with more choices, lower consumption costs, and help buffer inflation risks. China&#8217;s exports of production equipment and intermediate goods strongly support the industrialization of its trade partners. For example, China supplies more than 80 percent of the world&#8217;s photovoltaic modules and 70 percent of wind power equipment, providing important support for the green transition of its trade partners. Foreign-invested enterprises contribute 16 percent of China&#8217;s surplus and have also earned substantial returns on their investment. This vividly shows that while the surplus is recorded in China, the benefits are shared by all parties.</p><p>Third, from the perspective of the overall balance of payments, although China runs a sizeable surplus in trade in goods, it has deficits in trade in services and in the capital and financial account. The current account surplus accounts for about 3.7 percent of GDP, which is within the internationally recognized reasonable range, and there is no significant external imbalance.</p><p>I would like to stress that China never deliberately pursues a trade surplus. We will continue to actively promote balanced development of imports and exports, continue opening our market to the world, and firmly expand imports. In the first half of this year, China&#8217;s import growth in goods trade was 22.1 percent, significantly faster than export growth. China remains the world&#8217;s second-largest import market, and its enormous market demand provides strong momentum for the development of its trading partners. Since last year in particular, we have built the &#8220;Export to China&#8221; brand and plan to hold more than 100 import promotion activities every year, with the aim of sharing China&#8217;s new development opportunities with the world. At many overseas &#8220;Export to China&#8221; events, Chinese enterprises have signed letters of intent with local companies, broadened sourcing channels for imports, and created more convenient pathways for companies from various countries to enter the Chinese market. These efforts have received positive responses and have generated mutually beneficial cooperation.</p><p>Going forward, we will take more practical measures to expand imports and share with countries around the world the new opportunities created by China&#8217;s large market.</p><p>First, we will continue to expand the influence of the &#8220;Export to China&#8221; brand. Through a series of matchmaking events, exhibition linkages, and targeted procurement, we will further increase imports.</p><p>Second, we will continue to strengthen policy support. We will improve the facilitation of import trade, optimize the sources and structure of imported goods, and better meet the needs of industrial development and people&#8217;s aspirations for a better life.</p><p>Third, we will make full use of various promotion platforms. We will continue to host major exhibitions such as the China International Import Expo and the China International Consumer Products Expo, regularly organize import-trade fairs for featured CIIE products, and better leverage national demonstration zones for import trade promotion and innovation, so as to actively drive the import of high-quality goods and services from around the world.</p><p>Thank you.</p><p><strong>Reporter from International Market News, United States:</strong></p><p>Recently, some leaders from EU countries and institutions have expressed concerns that China&#8217;s currency is undervalued and gives Chinese exporters an unfair advantage. What is the Ministry of Commerce&#8217;s response? Looking ahead to the second half of this year, especially amid continued trade tensions and the broader economic backdrop, how does the Ministry view the outlook for China-EU trade? Thank you.</p><p><strong>Yan Dong:</strong></p><p>Director-General Lin Weilong from the Policy Research Department will answer this question.</p><p><strong>Lin Weilong:</strong></p><p>Thank you for your question. We have taken note of the relevant developments. In recent years, under the strategic guidance of the leaders of China and the EU, China-EU economic and trade relations have developed generally well. In the first half of this year, trade in goods between China and the EU increased by 14.2 percent year on year, reaching $447.88 billion. The two sides have huge potential for cooperation in services trade, scientific and technological innovation, and the green economy. This is both the result of deep interconnection and complementarity in China-EU industrial and supply chains, and a reflection of the broader trend of global digital and green transformation and the future development of China and Europe.</p><p>At the same time, the EU has recently continued to roll out trade restriction measures against China and to hype the so-called issue of the renminbi exchange rate. This lacks a factual basis and is not conducive to the stable development of China-EU economic and trade relations. China adheres to giving the market a decisive role in exchange-rate formation and maintains the renminbi exchange rate basically stable at an adaptive and equilibrium level. As a responsible major country, China does not seek competitive advantage through currency depreciation. Chinese manufacturing is internationally competitive, and there is no need to promote exports through an undervalued exchange rate.</p><p>China is not the source of the EU&#8217;s economic and trade problems, but a partner in solving them. Protectionism leads nowhere; cooperation for mutual benefit is the right path. At the end of last month, Minister of Commerce Wang Wentao and European Commissioner for Trade and Economic Security Maros Sefcovic jointly chaired the first meeting of the China-EU trade and investment consultation mechanism, and reached consensus on the new positioning of the relationship as one of &#8220;stable and balanced key trade partners.&#8221; China is willing to use this mechanism to strengthen dialogue and consultation with the EU, properly handle differences and frictions, promote practical cooperation, advance trade toward a more balanced direction, and foster the steady and sound development of China-EU economic and trade relations, thereby injecting more certainty and positive energy into the global economy.</p><p>Thank you.</p><p><strong>Reporter from National Business Daily:</strong></p><p>There are currently two narratives in the international community regarding China&#8217;s industrial development and technological innovation: one is &#8220;China Shock 2.0&#8221; and the other is &#8220;China Opportunity 2.0.&#8221; How should we view these two narratives? Is China&#8217;s industrial development ultimately a shock or an opportunity for the world? Thank you.</p><p><strong>Yan Dong:</strong></p><p>Thank you for your question. I will answer this one myself.</p><p>This is indeed a topic that has attracted a great deal of attention and discussion. Some countries have put forward the so-called &#8220;China Shock 2.0&#8221; narrative, slandering China&#8217;s industrial development as a threat to the monopoly position of Western countries and as squeezing the development space of countries in the Global South. This narrative does not conform to the facts and cannot stand up to scrutiny.</p><p>For more than a decade, China has been an important engine of world economic growth, contributing about 30 percent. By leveraging its market strengths, industrial development, and technological progress, China has provided the world with growing &#8220;market dividends,&#8221; &#8220;development dividends,&#8221; and &#8220;innovation dividends.&#8221; These dividends overlap and reinforce one another, bringing the world more development opportunities and broader room for growth, which is what more rational and objective voices in the international community call &#8220;China Opportunity 2.0.&#8221; This can be understood from four aspects.</p><p>First, China&#8217;s industrial development is a ballast stone for the stability of global industrial and supply chains. China has the world&#8217;s largest industrial manufacturing system, with the most complete range of categories and the most integrated system. It continues to provide all kinds of industrial manufactured products in an efficient manner, strongly supporting stable global supply and effectively offsetting localized supply gaps caused by protectionism, geopolitical conflicts, and other factors. This has demonstrated China&#8217;s strong resilience and sense of responsibility, enabling it to play the role of a stabilizing anchor and major hub in global industrial cooperation. China&#8217;s exports of high-quality and cost-effective production equipment and components have lowered entry barriers for developing countries&#8217; manufacturing sectors. From 2012 to 2024, China exported more than $30 billion in textile machinery to developing countries, helping some countries in Southeast Asia and South Asia become important textile producers and exporters.</p><p>Second, China&#8217;s industrial development is a new engine for global innovation cooperation. China adheres to innovation-driven development and has forged an effective path in which technological innovation leads industrial innovation and industrial upgrading in turn accelerates technological iteration. With the support of Chinese manufacturing, any valuable technological achievement can quickly be transformed into a real product, making China an ideal testing ground for both &#8220;0-to-1&#8221; validation and &#8220;1-to-N&#8221; scaling of new products and services. China remains open in innovation, and its rapidly growing innovative companies have delivered several-fold, and in some cases several-dozen-fold, returns to investors from around the world. Many of China&#8217;s innovations, including large AI models, follow an open-source path and are widely welcomed by countries everywhere. Global cumulative downloads of open-source large models have surpassed 10 billion, enabling more countries, especially developing countries, to access and afford new technologies.</p><p>Third, China&#8217;s industrial development is a driving force for the global green transition. China is accelerating a comprehensive green transition and promoting green, low-carbon industrial development. By the end of the 15th Five-Year Plan period, the scale of China&#8217;s green industries is expected to exceed 20 trillion yuan. The rapid development of China&#8217;s green industries and the growing supply of new energy products have enriched global supply and strongly advanced the global low-carbon transition. According to a report by the International Renewable Energy Agency, over the past decade, the global levelized cost of electricity for wind and solar projects has fallen by more than 60 percent and 80 percent, respectively, and a large part of that is attributable to Chinese manufacturing and Chinese capacity. At present, with global energy tensions and artificial intelligence driving up electricity demand, the International Energy Agency predicts that by 2030 global electricity consumption by data centers will approach 1 trillion kilowatt-hours, of which 40 percent of the additional electricity demand will rely on renewable energy. China has clear scale and technological advantages in solar energy, energy storage, and electrification, and will be better positioned to meet future global demand for green energy and industrial development.</p><p>Fourth, China&#8217;s industrial development helps improve people&#8217;s well-being around the world. The rapid development of Chinese industry has provided the world with a rich supply of high-quality, highly efficient, and cost-effective products, offering consumers in all countries more stable and more diversified choices. Chinese manufacturing has improved living standards, reduced the cost of living, and eased global inflationary pressure. For example, Chinese air conditioners have recently sold well in Europe, helping local people stay cool during heat waves. A report by the European Central Bank estimates that if EU imports from China increase by 10 percent in 2026, the EU&#8217;s overall import prices would fall by 1.6 percent. China&#8217;s trade and investment have also had a stronger enabling effect on industrialization in developing countries. China has established more than 50,000 enterprises overseas, with outward investment stock exceeding $3 trillion, nearly 90 percent of which is located in developing economies. Through local production, local procurement, local hiring, supporting upstream and downstream industries, and connecting regional supply chains, Chinese-invested enterprises have brought a large number of projects in light industry, textiles, home appliances, and other sectors to fruition, while also driving the development of digital and green sectors. This has strengthened the contribution of exports to local value added in host countries. According to estimates by the Chinese Academy of Sciences, the value added in local exports driven by Chinese-invested enterprises in 24 developing economies increased from $24.4 billion in 2012 to $142.4 billion in 2025, nearly a fivefold increase. The so-called theory that China is squeezing others out is simply a new version of the &#8220;China threat&#8221; narrative. It is intended to undermine China&#8217;s cooperation with countries of the Global South and to shift historical and present responsibilities, rather than to genuinely help developing countries. Facts and data show clearly that China&#8217;s industrial development brings the world opportunities, not shocks; empowerment, not threats. It helps developing countries modernize and helps pave the way for their development.</p><p>Thank you.</p><p><strong>Reporter from Yangguangwang, China National Radio, CMG:</strong></p><p>In recent years, unilateralism and protectionism have been on the rise. Some economies have adopted discriminatory measures that undermine fair competition and disrupt global industrial division of labor and cooperation. How do you view the role of market competition in adjusting the global distribution of capacity, and how can the WTO play a better role in maintaining a fair international competitive environment? Thank you.</p><p><strong>Yan Dong:</strong></p><p>Thank you for your question. I will ask Director-General Han Yong to answer it.</p><p><strong>Han Yong:</strong></p><p>Thank you for the question. Market competition is an important safeguard for optimizing and adjusting capacity and for promoting healthy industrial development. Historically, every industrial revolution and technological transformation has been accompanied by a rise in capacity in related industries and even, in the short term, situations in which supply exceeded demand. In this process, enterprises invest and expand production in pursuit of profits and market share, while market competition drives them to reduce costs and improve efficiency, bringing technological progress and productivity gains. In that sense, market competition is the most effective mechanism for preventing disorderly expansion of capacity. The role of government should be to maintain competitive order and a fair environment, allowing the market to function more fully so that outdated capacity exits naturally through competition and dynamic balance between supply and demand is ultimately achieved. The WTO&#8217;s principle of fair competition and related rules have become widely accepted norms of behavior globally. All parties should uphold fair competition and reduce improper interference with global cooperation in capacity allocation.</p><p>China is actively fostering a first-class business environment characterized by fair competition. China has the largest number of market entities in the world. This huge number creates a fully competitive environment in which enterprises face direct challenges and compete on real strength, refining products and services in the survival-of-the-fittest process. McKinsey once described China as &#8220;the world&#8217;s toughest gym,&#8221; a place that has forged highly competitive companies. China&#8217;s 15th Five-Year Plan outline makes clear that it will deepen the development of a unified national market, remove barriers in factor acquisition, qualification recognition, tendering and bidding, and government procurement, fully implement national treatment for foreign-invested enterprises, and actively foster a first-class business environment that is market-oriented, law-based, and internationalized.</p><p>The multilateral trading system with the WTO at its core and rules at its foundation has played an important role in maintaining the stability of the global economic and trade order. Principles such as free trade, non-discrimination, and fair competition are deeply rooted and together form the underlying logic that keeps the global economic and trade order stable and predictable. At present, the multilateral trading system is under severe impact from unilateralism and protectionism, but multilateralism remains the first choice of the overwhelming majority of WTO members. According to WTO statistics, 72 percent of global trade is still conducted under the most-favored-nation principle. This fully demonstrates the value and resilience of the multilateral trading system&#8217;s basic principles, including fair competition. No one wants to return to a jungle world where the strong prey on the weak. In difficult times, international fairness and justice become all the more precious. China will work with all parties to firmly support the multilateral trading system, advance WTO reform, resolutely uphold the WTO&#8217;s basic principles and rules, and maintain a transparent, fair, and inclusive global economic and trade environment.</p><p>Thank you.</p><p><strong>Reporter from the South China Morning Post:</strong></p><p>The EU has recently proposed related trade defense instruments, and the United States has launched a Section 301 investigation targeting the capacity issue. How does the Ministry of Commerce comment on this? Given that domestic supply in related areas continues to exceed domestic demand, what measures is the Ministry taking to prevent export spillover effects from triggering more trade restrictions? Thank you.</p><p><strong>Yan Dong:</strong></p><p>Thank you for your question. Director-General Lin Weilong of the Policy Research Department will answer.</p><p><strong>Lin Weilong:</strong></p><p>Thank you for your question. As I understand it, your question actually contains three issues: trade measures by Europe and the United States, China&#8217;s domestic demand, and the export spillover effect and the resulting global economic imbalance.</p><p>Let me first address the question of the EU&#8217;s trade defense instruments and the U.S. Section 301 investigation into the capacity issue. China has repeatedly stated its position on both matters. The EU has continued to introduce protectionist measures against China, seriously undermining the confidence of Chinese enterprises in cooperating with Europe. Given the enormous scale of China-EU cooperation, it is inevitable that differences and frictions will arise, but such differences should not become a pretext for fabricating accusations, still less an excuse for setting restrictions, increasing pressure, and affecting practical cooperation. China is willing to properly handle differences and frictions with the EU through dialogue and consultation. As for the U.S. Section 301 investigation on the capacity issue, this is a typical act of unilateralism that seriously undermines the international economic order. The U.S. side cannot narrowly define production capacity exceeding domestic demand as &#8220;overcapacity&#8221; and attach the label of &#8220;excess.&#8221; Nor does it have the right, through a Section 301 investigation, to unilaterally determine whether a trading partner has &#8220;overcapacity&#8221; and to adopt unilateral restrictive measures. China urges the U.S. side to correct its wrong approach and return to the right track of resolving issues through dialogue and consultation. China will closely follow developments, reserve the right to take necessary measures, and firmly safeguard its legitimate rights and interests.</p><p>Second, on China&#8217;s domestic demand. As our position paper points out, some people claim that &#8220;insufficient domestic demand in China has led to overcapacity,&#8221; but this does not conform to the facts. China is not only a manufacturing powerhouse, but also a major consumer market. Domestic demand has long been the main engine of China&#8217;s economy. From 2013 to 2024, domestic demand contributed an average of 93 percent to China&#8217;s economic growth, with consumption and investment contributing 55 percent and 38 percent, respectively, on average. China&#8217;s total retail sales of consumer goods rose from 23.8 trillion yuan in 2013 to 50.1 trillion yuan in 2025, more than doubling. Based on World Bank purchasing power parity calculations, China&#8217;s retail sales in 2025 were about 1.7 times those of the United States, meaning China is already the world&#8217;s largest commodity consumption market in practical terms. For example, in food consumption, China&#8217;s Engel coefficient has fallen to 29.8 percent, and per capita protein supply has exceeded 130 grams per day, higher than in many developed countries. In terms of industrial goods consumption, annual per capita purchases of air conditioners, refrigerators, mobile phones, and automobiles have already approached OECD-country levels.</p><p>At present, insufficient effective demand in China is a stage-specific phenomenon in the transition from high-speed growth to high-quality development. Over the long term, however, China&#8217;s consumption space remains vast and full of potential, and its role as the main engine will become even more prominent. Over the next decade, China&#8217;s middle-income group is expected to exceed 800 million people, and per capita GDP will reach the level of moderately developed countries. Structurally, China is accelerating the shift from goods-led consumption toward a pattern in which goods and services are equally important. Service consumption is developing rapidly, and by 2030 it is expected to account for more than half of total consumption. China&#8217;s 15th Five-Year Plan contains a dedicated chapter on domestic demand, emphasizing the need to treat demand expansion as a strategic priority, expand effective investment, vigorously boost consumption, implement special initiatives to stimulate consumption, upgrade goods consumption, unlock service-consumption potential, foster new forms of consumption, guide new supply through new demand, create new demand through new supply, promote positive interaction among consumption, investment, supply, and demand, and strive to achieve a higher-level balance between supply and demand.</p><p>Third, on global economic imbalance. Global economic imbalances have always existed and are a historical norm. Under the global economic structure and international economic governance system formed after World War II, the world economy has experienced a major imbalance roughly every decade or so, and some of these episodes have even triggered international economic and financial crises. Each new round of imbalance prompts wide international discussion, though the focus has kept changing. Some discussions emphasize market factors such as the savings-investment structure and industrial and supply-chain division of labor; others focus on institutional factors such as the international financial system and macroeconomic policy. The roots of economic imbalance are extremely complex.</p><p>In recent years, global economic imbalance has taken on new features. Institutions such as the International Monetary Fund believe that the macroeconomic policies of countries, especially fiscal policy, are a key factor behind current global imbalances. The United States has accumulated a huge debt imbalance and needs to improve its fiscal position; Europe suffers from insufficient investment and needs to raise productivity; China needs to expand domestic demand. That view is only one school of thought, but it does reflect the systemic and complex nature of global economic imbalance. Some people seek to link global economic imbalance with the so-called &#8220;overcapacity.&#8221; This is simplistic attribution, a deliberate attempt to confuse the issue, and motivated by ulterior motives. By contrast, China&#8217;s high-quality capacity has not only met domestic demand but has also made important contributions to global development and played a significant role in promoting global economic balance.</p><p>Thank you.</p><p><strong>Reporter from Elephant News:</strong></p><p>China&#8217;s emerging industries such as artificial intelligence, new-energy vehicles, and lithium batteries have developed rapidly, and their export performance has also been strong. What are the sources of China&#8217;s industrial strengths and momentum? Thank you.</p><p><strong>Yan Dong:</strong></p><p>Thank you for your question. I will ask Mr. He Shaojun from the Department of Foreign Trade to answer.</p><p><strong>He Shaojun:</strong></p><p>Thank you. We have also noted that in recent years China&#8217;s electric vehicles, lithium batteries, and artificial intelligence industries have developed rapidly and posted strong export growth. According to customs statistics, in the first half of this year, China&#8217;s exports of electric vehicles and lithium batteries increased by 68.7 percent and 37.6 percent, respectively. AI-related products such as industrial robots and 3D printers also performed strongly, rising by 18.6 percent and 109.3 percent, and have become new calling cards for China&#8217;s foreign trade. Overall, this is the result of multiple factors, including a solid industrial foundation, market-driven iteration, enterprise innovation, and international openness and cooperation. These can be summarized as four major strengths.</p><p>First is the strength of a complete industrial system. China has now established a comprehensive and efficient new-energy vehicle industrial chain covering basic materials, components, complete vehicles, and manufacturing equipment. Its supply-chain responsiveness, cost control, and delivery speed are globally leading. In the Yangtze River Delta, through coordinated industrial-cluster development, a new-energy vehicle manufacturer can obtain needed supporting components within a four-hour drive.</p><p>Second is the strength of a super-sized market. China has the world&#8217;s largest consumer market, which provides a proving ground and training ground for new technologies, products, and services. New-energy vehicle sales have ranked first in the world for 11 consecutive years, and fierce domestic competition has greatly improved product technology. Massive user demand and diverse application scenarios have accelerated AI technology iteration, enabling rapid verification of technical feasibility and spreading R&amp;D costs across a larger base.</p><p>Third is the strength of innovation-driven development. China has firmly pursued innovation-driven development, using scientific and technological innovation to lead industrial development and continuously enhance industrial competitiveness. National R&amp;D intensity rose from 1.91 percent in 2012 to 2.8 percent in 2025. International patent applications have ranked first in the world for seven consecutive years, and China accounts for 60 percent of global AI patents. Technological breakthroughs have been achieved in areas such as power batteries and general-purpose large models. By 2025, the energy density of power batteries had increased by more than 50 percent compared with 2018, while production costs had fallen by more than 60 percent. Domestic large models such as DeepSeek and Qwen have risen collectively.</p><p>Fourth is the strength of openness and cooperation. At present, the global energy system is undergoing deep transformation, and artificial intelligence is developing rapidly. Economic and trade cooperation in related fields has enormous potential. According to institutional estimates, by 2030 the global market size for products and technologies such as electric vehicles, solar energy, and wind power will reach $2.1 trillion, while the AI data-center market is expected to grow by 45 percent annually over the next five years. The market outlook is broad. Guided by the principle of mutual benefit and win-win cooperation, China advances international cooperation and supports capable electric-vehicle and lithium-battery enterprises in making rational and orderly cross-border arrangements for industrial and supply chains, thereby empowering green transition and industrial upgrading in other countries.</p><p>The development of China&#8217;s modern industries and the enhancement of its foreign-trade competitiveness are driven by innovation and by the continuous deepening of reform. Going forward, we will continue to advance high-quality trade development, further support enterprises in related industries in integrating more deeply into global industrial and supply-chain systems, and inject more vitality into global digital, intelligent, and green transformation.</p><p>Thank you.</p><p><strong>Jia Huili:</strong></p><p>Thank you. We now have time for one last question.</p><p><strong>Reporter from CCTV, China Media Group:</strong></p><p>Under the current volatile international situation, maintaining stable and smooth global industrial and supply chains faces many challenges and requires the joint efforts of all countries moving in the same direction. What suggestions does the Ministry of Commerce have for better promoting an open and inclusive global industrial and supply chain cooperation landscape? Thank you.</p><p><strong>Yan Dong:</strong></p><p>Thank you for your question. I will answer this one.</p><p>At present, with the international situation turbulent and protectionism on the rise, safeguarding the stability and smooth functioning of global industrial and supply chains is in the interests of all parties and is also an urgent expectation of the international community. President Xi Jinping has pointed out that economies advance together when connected and all fall behind when closed off. China is willing to work with all parties to uphold the global free-trade system, preserve an international environment of openness and cooperation, and jointly promote the building of an open and inclusive global industrial and supply chain cooperation landscape.</p><p>We must uphold mutual benefit and win-win outcomes and make the global development pie bigger. When the pie grows larger, conflicts over distribution become smaller. All parties should jointly seize the opportunities created by a new round of industrial revolution and technological transformation, strengthen international cooperation in areas such as green and low-carbon development, artificial intelligence, and bio-manufacturing, and use shared technological dividends to break through growth bottlenecks and continuously inject new momentum into the global economy. All parties should also pay greater attention to the &#8220;real imbalances&#8221; between developed and developing economies, strengthen industrial cooperation as well as trade and investment cooperation, help more developing countries and regions integrate into the international division of labor, accelerate industrialization and modernization, and open up a new blue ocean for global industrial cooperation.</p><p>We must uphold openness and connectivity and promote sound circulation in global industrial and supply chains. The division of labor and cooperation in global industrial and supply chains did not take shape overnight, and forced intervention by human hands will only backfire. All parties should continue expanding market openness, promote trade and investment liberalization and facilitation, improve the efficiency of allocating factors and resources, and jointly create and maintain an open global innovation ecosystem so that international industrial cooperation can deliver greater benefits. All parties should oppose the politicization and over-securitization of economic issues, respect market rules, reduce barriers to trade, lower obstacles to investment cooperation, promote full market competition, stimulate business vitality, and make the flow of factors and resources and the distribution of industrial division of labor more rational and orderly.</p><p>We must uphold policy coordination and foster a stable and predictable environment for cooperation. The world economy is highly interconnected, and national industrial policies have obvious spillover effects, so communication and coordination should be strengthened, especially among major powers, which should set an example. All parties should adhere to consultation on an equal footing and properly manage differences, abandon unilateralism and protectionism, and oppose discriminatory and exclusionary practices. All parties should strengthen bilateral and multilateral dialogue on industrial policies, uphold openness and transparency, and deepen exchanges and discussions on industrial policy under the WTO framework, taking more coordinated and effective measures to better pool the combined forces of global economic growth.</p><p>We must uphold multilateralism and build a fairer and more equitable international economic order. The multilateral trading system with the WTO at its core is the cornerstone of economic globalization and international trade. In economic and trade exchanges, all parties should uphold equality and mutual benefit, respect each other&#8217;s stage of development and national conditions, and strive through fair competition to run faster themselves rather than trip others up, while jointly resisting bullying by the strong against the weak. All parties should adhere to genuine multilateralism, uphold the WTO&#8217;s basic principles and rules, advance WTO reform in step with the times, safeguard the WTO&#8217;s authority and effectiveness, and make better use of multilateral and regional cooperation mechanisms such as the G20, BRICS, and APEC, so as to jointly defend fairness and justice and make the global economic governance system more just and equitable.</p><p>Thank you.</p><h2>Closing</h2><p><strong>Jia Huili:</strong></p><p>That concludes today&#8217;s press conference. Thank you to all the speakers and to all the journalists for participating. Goodbye.</p>]]></content:encoded></item><item><title><![CDATA[Moonshot released Kimi K3 model weights and technical report]]></title><description><![CDATA[Source:https://mp.weixin.qq.com/s/tryHe81IyM6nr0fBPDz72g]]></description><link>https://www.geopolitechs.org/p/moonshot-released-kimi-k3-model-weights</link><guid isPermaLink="false">https://www.geopolitechs.org/p/moonshot-released-kimi-k3-model-weights</guid><dc:creator><![CDATA[Geopolitechs]]></dc:creator><pubDate>Mon, 27 Jul 2026 16:09:51 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!qNyz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b57d447-3056-4e62-8e24-c5de9ddb911a_1097x400.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Source:https://mp.weixin.qq.com/s/tryHe81IyM6nr0fBPDz72g</strong></p><h3>Kimi K3 Open Day</h3><p>Thank you for your patience.</p><p>Today is Kimi K3 Open Day. We are releasing the Kimi K3 <a href="https://huggingface.co/moonshotai">model weights</a>, the <a href="https://github.com/MoonshotAI/Kimi-K3">technical report</a>, and the key infrastructure technologies that support Kimi K3 model training: <a href="https://github.com/moonshotAI/moonep">MoonEP</a>, <a href="https://github.com/MoonshotAI/FlashKDA/">FlashKDA</a>, and <a href="https://github.com/kvcache-ai/AgentEnv">AgentEnv</a>. We hope this will accelerate the deployment and adoption of frontier intelligence and advance AGI research.</p><h3>Kimi K3 Weights Released</h3><p><a href="https://mp.weixin.qq.com/s?__biz=Mzk0NDU1MDkyNg==&amp;mid=2247488658&amp;idx=1&amp;sn=a4fd7ead31c1b49357b29535c0dea4fe&amp;scene=21#wechat_redirect">Kimi K3</a> is our most capable model. It is a 2.8-trillion-parameter Mixture-of-Experts model with native visual understanding and support for a 1-million-token context window.</p><p>Kimi K3 has roughly three times as many parameters as Kimi K2.5. Scaling, however, is not merely the accumulation of parameters. Under constrained compute conditions, we achieved a 2.5&#215; improvement in scaling efficiency through a set of technical innovations, including <a href="https://github.com/MoonshotAI/Kimi-K3">Kimi Delta Attention</a>, <a href="https://github.com/MoonshotAI/Kimi-K3">Attention Residuals</a>, and <a href="https://github.com/MoonshotAI/MoonEP">MoonEP</a>. In compute-optimal terms, each unit of compute now produces roughly 2.5 times as much intelligence as before.</p><p>Everyone can now download and deploy the Kimi K3 model, whether for internal research and development or for integration into end-user products. For other use cases, please see the <a href="https://huggingface.co/moonshotai/Kimi-K3/blob/main/LICENSE">Kimi K3 License</a>.</p><p><a href="https://huggingface.co/moonshotai">Download Kimi K3 model weights</a></p><h3>Kimi K3 Technical Report Published</h3><p>Alongside the Kimi K3 model weights, we are also making public our model training methods. The <a href="https://github.com/MoonshotAI/Kimi-K3">Kimi K3 technical report</a> is now available.</p><p>The technical report covers the following details:</p><ul><li><p>KDA + AttnRes: KDA and Gated MLA are mixed at a 3:1 ratio to enable efficient long-context modeling, while block-level attention residuals improve cross-layer information flow.</p></li><li><p>Stable LatentMoE: Each token activates 16 out of 896 routed experts. SiTU-GLU and Quantile Balancing maintain training stability under extremely high sparsity.</p></li><li><p>MoonViT-V2: The visual encoder is trained from scratch using next-token prediction, without contrastive pretraining. It reaches the baseline performance of SigLIP initialization while providing a more stable optimization process.</p></li><li><p>Post-training and evaluation: The report covers large-scale task synthesis across general reasoning, general agents, and coding agents; reinforcement learning infrastructure for million-token contexts; and full evaluation results from nearly 20 internal benchmarks.</p></li></ul><p>These points are only an overview. Detailed discussions and ablation experiments are included in the technical report.</p><p><a href="https://github.com/MoonshotAI/Kimi-K3">Download the Kimi K3 technical report</a></p><h3>Key Kimi K3 Infrastructure Technologies Open-Sourced</h3><p>Model capability depends on stable training systems at the infrastructure layer. Today, we introduce three infrastructure technologies that support Kimi K3 training: MoonEP, FlashKDA, and AgentEnv. They cover key links from high-performance communication and high-performance kernels to distributed RL environments. FlashKDA had already been open-sourced; MoonEP and AgentEnv are being officially open-sourced with this release.</p><ul><li><p>MoonEP: MoonEP is a high-performance communication library designed for extremely large, fine-grained MoE models. It enables expert-parallel communication to maintain high efficiency even under imbalance.</p></li><li><p>FlashKDA: FlashKDA is our high-performance kernel implementation of Kimi Delta Attention. On NVIDIA H20, compared with the flash-linear-attention baseline, its prefill speed is 1.72&#8211;2.22&#215; faster, and it can be used directly as a replacement backend for flash-linear-attention.</p></li><li><p>AgentEnv: AgentEnv is a sandbox system developed jointly with KVCache.ai for running agent environments at scale. It provides high-fidelity, strongly isolated sandboxes for Kimi K3 post-training, with flexible support for fast snapshotting, restoration, and forking. It is designed for massively parallel agent workflows and training tasks.</p></li></ul><p>These three technologies are key to Kimi K3&#8217;s training efficiency and stability. We are opening them up in the hope that they can also help you train next-generation models.</p><p><a href="https://github.com/moonshotAI/moonep">MoonEP GitHub repository</a></p><p><a href="https://github.com/MoonshotAI/FlashKDA/">FlashKDA GitHub repository</a></p><p><a href="https://github.com/kvcache-ai/AgentEnv">AgentEnv GitHub repository</a></p><h3>Why We Choose Openness</h3><p>We firmly believe in the value of open-weight models. They lower the barrier to accessing intelligence, promote innovation, and give users greater control over their data, privacy protection, and ownership. Over the past few weeks, we have been pleased to hear support from many members of the AI community and from technology leaders who share our vision.</p><p>We believe that for a technology with far-reaching impact like AGI, a broad and open ecosystem is the most suitable foundation. We will continue to contribute to that ecosystem.</p><h3>Quick Start</h3><ul><li><p><a href="https://huggingface.co/moonshotai">Download Kimi K3 model weights</a></p></li><li><p><a href="https://github.com/MoonshotAI/Kimi-K3">Read the Kimi K3 technical report</a></p></li><li><p><a href="https://github.com/MoonshotAI/MoonEP">Learn about MoonEP</a></p></li><li><p><a href="https://github.com/MoonshotAI/FlashKDA/">Learn about FlashKDA</a></p></li><li><p><a href="https://github.com/kvcache-ai/AgentEnv">Learn about AgentEnv</a></p></li><li><p><a href="https://mp.weixin.qq.com/s?__biz=Mzk0NDU1MDkyNg==&amp;mid=2247488658&amp;idx=1&amp;sn=a4fd7ead31c1b49357b29535c0dea4fe&amp;scene=21#wechat_redirect">Learn about the Kimi K3 model</a></p></li></ul><p></p><p><strong>GitHub Repository Content</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qNyz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b57d447-3056-4e62-8e24-c5de9ddb911a_1097x400.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qNyz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b57d447-3056-4e62-8e24-c5de9ddb911a_1097x400.png 424w, https://substackcdn.com/image/fetch/$s_!qNyz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b57d447-3056-4e62-8e24-c5de9ddb911a_1097x400.png 848w, https://substackcdn.com/image/fetch/$s_!qNyz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b57d447-3056-4e62-8e24-c5de9ddb911a_1097x400.png 1272w, https://substackcdn.com/image/fetch/$s_!qNyz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b57d447-3056-4e62-8e24-c5de9ddb911a_1097x400.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qNyz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b57d447-3056-4e62-8e24-c5de9ddb911a_1097x400.png" width="1097" height="400" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4b57d447-3056-4e62-8e24-c5de9ddb911a_1097x400.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:400,&quot;width&quot;:1097,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:116200,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.geopolitechs.org/i/208707061?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b57d447-3056-4e62-8e24-c5de9ddb911a_1097x400.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qNyz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b57d447-3056-4e62-8e24-c5de9ddb911a_1097x400.png 424w, https://substackcdn.com/image/fetch/$s_!qNyz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b57d447-3056-4e62-8e24-c5de9ddb911a_1097x400.png 848w, https://substackcdn.com/image/fetch/$s_!qNyz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b57d447-3056-4e62-8e24-c5de9ddb911a_1097x400.png 1272w, https://substackcdn.com/image/fetch/$s_!qNyz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b57d447-3056-4e62-8e24-c5de9ddb911a_1097x400.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Repository Overview</h3><p>MoonshotAI/Kimi-K3 is titled &#8220;Open Frontier Intelligence.&#8221; The repository is public and includes an <code>assets</code> directory, <code>LICENSE</code>, <code>README.md</code>, and <code>k3_tech_report.pdf</code>. The repository page links to the Kimi chat site, Moonshot AI homepage, Hugging Face organization, Twitter/X account, Discord, ModelScope organization, the Kimi K3 license, the technical blog, and the full report.</p><h3>1. Model Introduction</h3><p>Kimi K3 is an open-weight, native multimodal agentic model and Moonshot AI&#8217;s most capable model to date. It is a 2.8T-parameter model built on Kimi Delta Attention (KDA) and Attention Residuals (AttnRes), with native vision capabilities and a 1-million-token context window. It is described by the repository as the world&#8217;s first open 3T-class model, designed for frontier intelligence across long-horizon coding, knowledge work, and reasoning.</p><h3>Key Features</h3><ul><li><p>New Architecture: Kimi K3 is built on Kimi Delta Attention (KDA) and Attention Residuals (AttnRes), and scales up MoE sparsity with a Stable LatentMoE framework that activates 16 out of 896 experts, yielding an approximate 2.5&#215; improvement in overall scaling efficiency over Kimi K2.</p></li><li><p>Long-Horizon Coding: Operating with minimal human oversight, Kimi K3 sustains long engineering sessions, navigates massive repositories, and orchestrates terminal tools, from GPU kernel optimization and compiler development to vision-in-the-loop game development, CAD, and chip design.</p></li><li><p>Agentic Knowledge Work: Kimi K3 advances end-to-end knowledge work, producing deep research with interactive visualizations, widgets and dashboards, motion design, and video editing, powered by its native multimodal architecture.</p></li><li><p>Native Multimodality &amp; Long Context: Kimi K3 understands text, images, and video within the same model, and supports a 1-million-token context window.</p></li><li><p>Open Frontier Weights: Moonshot AI releases the full Kimi K3 model weights under the Kimi K3 License, making frontier intelligence openly available for research, deployment, and further innovation.</p></li></ul><h3>2. Model Summary</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LvJX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9902883c-916d-4978-8853-768e2d181322_1120x1682.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LvJX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9902883c-916d-4978-8853-768e2d181322_1120x1682.png 424w, https://substackcdn.com/image/fetch/$s_!LvJX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9902883c-916d-4978-8853-768e2d181322_1120x1682.png 848w, https://substackcdn.com/image/fetch/$s_!LvJX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9902883c-916d-4978-8853-768e2d181322_1120x1682.png 1272w, https://substackcdn.com/image/fetch/$s_!LvJX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9902883c-916d-4978-8853-768e2d181322_1120x1682.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LvJX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9902883c-916d-4978-8853-768e2d181322_1120x1682.png" width="1120" height="1682" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9902883c-916d-4978-8853-768e2d181322_1120x1682.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1682,&quot;width&quot;:1120,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:320752,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.geopolitechs.org/i/208707061?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9902883c-916d-4978-8853-768e2d181322_1120x1682.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LvJX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9902883c-916d-4978-8853-768e2d181322_1120x1682.png 424w, https://substackcdn.com/image/fetch/$s_!LvJX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9902883c-916d-4978-8853-768e2d181322_1120x1682.png 848w, https://substackcdn.com/image/fetch/$s_!LvJX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9902883c-916d-4978-8853-768e2d181322_1120x1682.png 1272w, https://substackcdn.com/image/fetch/$s_!LvJX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9902883c-916d-4978-8853-768e2d181322_1120x1682.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>3. Evaluation Results</h3><ol start="3"><li><p></p><pre><code><code>Benchmark | Kimi K3 | Claude Fable 5 | GPT-5.6 Sol | Claude Opus 4.8 | GPT-5.5 | GLM-5.2
  &lt;tr&gt;&lt;td&gt;GPQA Diamond&lt;/td&gt;&lt;td&gt;93.5&lt;/td&gt;&lt;td&gt;92.6&lt;/td&gt;&lt;td&gt;94.1&lt;/td&gt;&lt;td&gt;91.0&lt;/td&gt;&lt;td&gt;93.5&lt;/td&gt;&lt;td&gt;91.2&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;CritPt&lt;/td&gt;&lt;td&gt;23.4&lt;/td&gt;&lt;td&gt;28.6&lt;/td&gt;&lt;td&gt;32.3&lt;/td&gt;&lt;td&gt;20.9&lt;/td&gt;&lt;td&gt;27.1&lt;/td&gt;&lt;td&gt;20.9&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;AA-LCR&lt;/td&gt;&lt;td&gt;74.7&lt;/td&gt;&lt;td&gt;70.0&lt;/td&gt;&lt;td&gt;73.7&lt;/td&gt;&lt;td&gt;67.7&lt;/td&gt;&lt;td&gt;74.3&lt;/td&gt;&lt;td&gt;71.3&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;HLE-Full&lt;/td&gt;&lt;td&gt;43.5 / 56.0&lt;/td&gt;&lt;td&gt;53.3 / 63.0&lt;/td&gt;&lt;td&gt;44.5 / 58.0&lt;/td&gt;&lt;td&gt;49.8 / 57.9&lt;/td&gt;&lt;td&gt;41.4 / 52.2&lt;/td&gt;&lt;td&gt;&#8212;&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;DeepSWE&lt;/td&gt;&lt;td&gt;67.5&lt;/td&gt;&lt;td&gt;70.0&lt;/td&gt;&lt;td&gt;73.0&lt;/td&gt;&lt;td&gt;59.0&lt;/td&gt;&lt;td&gt;67.0&lt;/td&gt;&lt;td&gt;46.2&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;ProgramBench&lt;/td&gt;&lt;td&gt;77.8&lt;/td&gt;&lt;td&gt;76.8&lt;/td&gt;&lt;td&gt;77.6&lt;/td&gt;&lt;td&gt;71.9&lt;/td&gt;&lt;td&gt;70.8&lt;/td&gt;&lt;td&gt;63.7&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;Terminal-Bench 2.1&lt;/td&gt;&lt;td&gt;88.3&lt;/td&gt;&lt;td&gt;88.0&lt;/td&gt;&lt;td&gt;88.8&lt;/td&gt;&lt;td&gt;84.6&lt;/td&gt;&lt;td&gt;83.4&lt;/td&gt;&lt;td&gt;82.7&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;FrontierSWE&lt;/td&gt;&lt;td&gt;81.2&lt;/td&gt;&lt;td&gt;86.6&lt;/td&gt;&lt;td&gt;71.3&lt;/td&gt;&lt;td&gt;66.7&lt;/td&gt;&lt;td&gt;64.9&lt;/td&gt;&lt;td&gt;67.3&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;SWE-Marathon&lt;/td&gt;&lt;td&gt;42.0&lt;/td&gt;&lt;td&gt;35.0&lt;/td&gt;&lt;td&gt;39.0&lt;/td&gt;&lt;td&gt;40.0&lt;/td&gt;&lt;td&gt;14.0&lt;/td&gt;&lt;td&gt;13.0&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;PostTrainBench&lt;/td&gt;&lt;td&gt;36.6&lt;/td&gt;&lt;td&gt;41.4&lt;/td&gt;&lt;td&gt;34.6&lt;/td&gt;&lt;td&gt;34.1&lt;/td&gt;&lt;td&gt;28.4&lt;/td&gt;&lt;td&gt;34.3&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;MLS-Bench-Lite&lt;/td&gt;&lt;td&gt;48.3&lt;/td&gt;&lt;td&gt;49.9&lt;/td&gt;&lt;td&gt;46.2&lt;/td&gt;&lt;td&gt;42.8&lt;/td&gt;&lt;td&gt;35.5&lt;/td&gt;&lt;td&gt;40.4&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;SciCode&lt;/td&gt;&lt;td&gt;58.7&lt;/td&gt;&lt;td&gt;60.2&lt;/td&gt;&lt;td&gt;56.1&lt;/td&gt;&lt;td&gt;53.5&lt;/td&gt;&lt;td&gt;56.1&lt;/td&gt;&lt;td&gt;50.5&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;Kimi Code Bench 2.0&lt;/td&gt;&lt;td&gt;72.9&lt;/td&gt;&lt;td&gt;76.9&lt;/td&gt;&lt;td&gt;64.8&lt;/td&gt;&lt;td&gt;71.7&lt;/td&gt;&lt;td&gt;69.0&lt;/td&gt;&lt;td&gt;64.2&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;BrowseComp&lt;/td&gt;&lt;td&gt;91.2&lt;/td&gt;&lt;td&gt;88.0&lt;/td&gt;&lt;td&gt;90.4&lt;/td&gt;&lt;td&gt;84.3&lt;/td&gt;&lt;td&gt;84.4&lt;/td&gt;&lt;td&gt;&#8212;&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;DeepSearchQA F1&lt;/td&gt;&lt;td&gt;95.0&lt;/td&gt;&lt;td&gt;94.2&lt;/td&gt;&lt;td&gt;&#8212;&lt;/td&gt;&lt;td&gt;93.1&lt;/td&gt;&lt;td&gt;&#8212;&lt;/td&gt;&lt;td&gt;&#8212;&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;ResearchRubrics&lt;/td&gt;&lt;td&gt;76.2&lt;/td&gt;&lt;td&gt;&#8212;&lt;/td&gt;&lt;td&gt;73.8&lt;/td&gt;&lt;td&gt;73.5&lt;/td&gt;&lt;td&gt;64.0&lt;/td&gt;&lt;td&gt;71.1&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;GDPval-AA v2 Elo&lt;/td&gt;&lt;td&gt;1686&lt;/td&gt;&lt;td&gt;1747&lt;/td&gt;&lt;td&gt;1736&lt;/td&gt;&lt;td&gt;1593&lt;/td&gt;&lt;td&gt;1491&lt;/td&gt;&lt;td&gt;1510&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;Toolathlon-Verified&lt;/td&gt;&lt;td&gt;76.5&lt;/td&gt;&lt;td&gt;77.9&lt;/td&gt;&lt;td&gt;74.9&lt;/td&gt;&lt;td&gt;76.2&lt;/td&gt;&lt;td&gt;73.5&lt;/td&gt;&lt;td&gt;59.9&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;MCPMark-Verified&lt;/td&gt;&lt;td&gt;94.5&lt;/td&gt;&lt;td&gt;87.4&lt;/td&gt;&lt;td&gt;92.9&lt;/td&gt;&lt;td&gt;76.4&lt;/td&gt;&lt;td&gt;92.9&lt;/td&gt;&lt;td&gt;&#8212;&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;MCP-Atlas&lt;/td&gt;&lt;td&gt;84.2&lt;/td&gt;&lt;td&gt;84.7&lt;/td&gt;&lt;td&gt;83.6&lt;/td&gt;&lt;td&gt;83.6&lt;/td&gt;&lt;td&gt;82.8&lt;/td&gt;&lt;td&gt;82.6&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;AutomationBench&lt;/td&gt;&lt;td&gt;30.8&lt;/td&gt;&lt;td&gt;29.1&lt;/td&gt;&lt;td&gt;29.7&lt;/td&gt;&lt;td&gt;27.2&lt;/td&gt;&lt;td&gt;22.7&lt;/td&gt;&lt;td&gt;12.9&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;JobBench&lt;/td&gt;&lt;td&gt;54.3&lt;/td&gt;&lt;td&gt;57.4&lt;/td&gt;&lt;td&gt;45.4&lt;/td&gt;&lt;td&gt;48.4&lt;/td&gt;&lt;td&gt;38.3&lt;/td&gt;&lt;td&gt;43.4&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;AA-Briefcase Elo&lt;/td&gt;&lt;td&gt;1548&lt;/td&gt;&lt;td&gt;1583&lt;/td&gt;&lt;td&gt;1495&lt;/td&gt;&lt;td&gt;1354&lt;/td&gt;&lt;td&gt;1158&lt;/td&gt;&lt;td&gt;1260&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;Agents' Last Exam&lt;/td&gt;&lt;td&gt;28.3&lt;/td&gt;&lt;td&gt;25.7&#8224;&lt;/td&gt;&lt;td&gt;29.6&lt;/td&gt;&lt;td&gt;27.0&lt;/td&gt;&lt;td&gt;26.6&lt;/td&gt;&lt;td&gt;20.4&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;APEX-Agents&lt;/td&gt;&lt;td&gt;41.0&lt;/td&gt;&lt;td&gt;43.3&lt;/td&gt;&lt;td&gt;39.9&lt;/td&gt;&lt;td&gt;39.4&lt;/td&gt;&lt;td&gt;38.5&lt;/td&gt;&lt;td&gt;35.6&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;OfficeQA Pro&lt;/td&gt;&lt;td&gt;63.3&lt;/td&gt;&lt;td&gt;69.9&lt;/td&gt;&lt;td&gt;63.2&lt;/td&gt;&lt;td&gt;63.9&lt;/td&gt;&lt;td&gt;60.9&lt;/td&gt;&lt;td&gt;41.4&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;SpreadsheetBench 2&lt;/td&gt;&lt;td&gt;34.8&lt;/td&gt;&lt;td&gt;34.7&lt;/td&gt;&lt;td&gt;32.4&lt;/td&gt;&lt;td&gt;31.6&lt;/td&gt;&lt;td&gt;29.1&lt;/td&gt;&lt;td&gt;28.1&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;OSWorld-Verified&lt;/td&gt;&lt;td&gt;84.8&lt;/td&gt;&lt;td&gt;85.0&lt;/td&gt;&lt;td&gt;83.0&lt;/td&gt;&lt;td&gt;83.4&lt;/td&gt;&lt;td&gt;79.0&lt;/td&gt;&lt;td&gt;&#8212;&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;OSWorld 2.0&lt;/td&gt;&lt;td&gt;58.3&lt;/td&gt;&lt;td&gt;66.1&lt;/td&gt;&lt;td&gt;62.6&lt;/td&gt;&lt;td&gt;55.7&lt;/td&gt;&lt;td&gt;49.5&lt;/td&gt;&lt;td&gt;&#8212;&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;SaaS-Bench&lt;/td&gt;&lt;td&gt;60.1&lt;/td&gt;&lt;td&gt;&#8212;&lt;/td&gt;&lt;td&gt;61.4&lt;/td&gt;&lt;td&gt;56.1&lt;/td&gt;&lt;td&gt;43.8&lt;/td&gt;&lt;td&gt;&#8212;&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;&#964;&#179;-Banking&lt;/td&gt;&lt;td&gt;33.4&lt;/td&gt;&lt;td&gt;26.8&lt;/td&gt;&lt;td&gt;33.0&lt;/td&gt;&lt;td&gt;27.6&lt;/td&gt;&lt;td&gt;31.3&lt;/td&gt;&lt;td&gt;26.8&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;Harvey Lab-AA&lt;/td&gt;&lt;td&gt;94.6&lt;/td&gt;&lt;td&gt;93.6&lt;/td&gt;&lt;td&gt;87.2&lt;/td&gt;&lt;td&gt;91.1&lt;/td&gt;&lt;td&gt;86.3&lt;/td&gt;&lt;td&gt;91.0&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;CorpFin v2&lt;/td&gt;&lt;td&gt;71.6&lt;/td&gt;&lt;td&gt;71.8&lt;/td&gt;&lt;td&gt;64.4&lt;/td&gt;&lt;td&gt;66.7&lt;/td&gt;&lt;td&gt;68.4&lt;/td&gt;&lt;td&gt;66.1&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;Finance Agent v2&lt;/td&gt;&lt;td&gt;54.4&lt;/td&gt;&lt;td&gt;56.3&lt;/td&gt;&lt;td&gt;53.8&lt;/td&gt;&lt;td&gt;53.9&lt;/td&gt;&lt;td&gt;51.8&lt;/td&gt;&lt;td&gt;49.7&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;Legal Research Bench&lt;/td&gt;&lt;td&gt;44.2&lt;/td&gt;&lt;td&gt;49.5&lt;/td&gt;&lt;td&gt;48.1&lt;/td&gt;&lt;td&gt;43.8&lt;/td&gt;&lt;td&gt;40.4&lt;/td&gt;&lt;td&gt;31.3&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;WorldVQA ForceAnswer&lt;/td&gt;&lt;td&gt;51.0&lt;/td&gt;&lt;td&gt;56.7&lt;/td&gt;&lt;td&gt;41.8&lt;/td&gt;&lt;td&gt;39.1&lt;/td&gt;&lt;td&gt;38.5&lt;/td&gt;&lt;td&gt;&#8212;&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;OmniDocBench&lt;/td&gt;&lt;td&gt;91.1&lt;/td&gt;&lt;td&gt;89.8&lt;/td&gt;&lt;td&gt;85.8&lt;/td&gt;&lt;td&gt;87.9&lt;/td&gt;&lt;td&gt;89.4&lt;/td&gt;&lt;td&gt;&#8212;&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;PerceptionBench&lt;/td&gt;&lt;td&gt;58.5&lt;/td&gt;&lt;td&gt;57.2&lt;/td&gt;&lt;td&gt;59.7&lt;/td&gt;&lt;td&gt;47.2&lt;/td&gt;&lt;td&gt;55.8&lt;/td&gt;&lt;td&gt;&#8212;&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;Video-MME w. sub&lt;/td&gt;&lt;td&gt;90.0&lt;/td&gt;&lt;td&gt;&#8212;&lt;/td&gt;&lt;td&gt;89.5&lt;/td&gt;&lt;td&gt;86.0&lt;/td&gt;&lt;td&gt;89.3&lt;/td&gt;&lt;td&gt;&#8212;&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;MMVU&lt;/td&gt;&lt;td&gt;82.1&lt;/td&gt;&lt;td&gt;&#8212;&lt;/td&gt;&lt;td&gt;81.2&lt;/td&gt;&lt;td&gt;79.2&lt;/td&gt;&lt;td&gt;81.7&lt;/td&gt;&lt;td&gt;&#8212;&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;BabyVision w/ python&lt;/td&gt;&lt;td&gt;85.7&lt;/td&gt;&lt;td&gt;90.5&lt;/td&gt;&lt;td&gt;88.9&lt;/td&gt;&lt;td&gt;81.2&lt;/td&gt;&lt;td&gt;83.6&lt;/td&gt;&lt;td&gt;&#8212;&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;MMMU-Pro&lt;/td&gt;&lt;td&gt;81.6 / 83.4&lt;/td&gt;&lt;td&gt;81.2 / 86.5&lt;/td&gt;&lt;td&gt;83.0 / 84.6&lt;/td&gt;&lt;td&gt;78.9 / 82.7&lt;/td&gt;&lt;td&gt;81.2 / 83.2&lt;/td&gt;&lt;td&gt;&#8212;&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;CharXiv RQ&lt;/td&gt;&lt;td&gt;84.8 / 91.3&lt;/td&gt;&lt;td&gt;88.9 / 93.5&lt;/td&gt;&lt;td&gt;84.6 / 89.1&lt;/td&gt;&lt;td&gt;80.5 / 89.9&lt;/td&gt;&lt;td&gt;84.1 / 89.0&lt;/td&gt;&lt;td&gt;&#8212;&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;MathVision&lt;/td&gt;&lt;td&gt;94.3 / 97.8&lt;/td&gt;&lt;td&gt;94.8 / 98.6&lt;/td&gt;&lt;td&gt;95.8 / 97.8&lt;/td&gt;&lt;td&gt;86.7 / 97.1&lt;/td&gt;&lt;td&gt;92.2 / 96.8&lt;/td&gt;&lt;td&gt;&#8212;&lt;/td&gt;&lt;/tr&gt;  
  &lt;tr&gt;&lt;td&gt;ZeroBench pass@5&lt;/td&gt;&lt;td&gt;23.0 / 41.0&lt;/td&gt;&lt;td&gt;23.0 / 46.0&lt;/td&gt;&lt;td&gt;17.0 / 35.0&lt;/td&gt;&lt;td&gt;17.0 / 34.0&lt;/td&gt;&lt;td&gt;22.0 / 41.0&lt;/td&gt;&lt;td&gt;&#8212;&lt;/td&gt;&lt;/tr&gt;  
</code></code></pre></li></ol><p>The repository footnotes state that all Kimi K3 results are obtained with reasoning effort set to <code>max</code> and temperature set to 1.0. For single-step tasks such as GPQA Diamond, HLE-Full, and vision benchmarks without tools, top-p is set to 0.95. For agentic tasks, top-p is set to 1.0. For HLE-Full, MMMU-Pro, CharXiv (RQ), MathVision, and ZeroBench, each cell reports scores without and with tool augmentation in that order.</p><h3>Evaluation Footnotes</h3><p>Reasoning and knowledge benchmark scores for CritPt and AA-LCR are cited from Artificial Analysis as of July 23, 2026.</p><p>For coding benchmarks, DeepSWE is evaluated with the Kimi Code harness. GLM-5.2 is taken from the GLM-5.2 release blog, while remaining DeepSWE scores are from the official DeepSWE leaderboard; Kimi K3 attains 67.3 with the mini-SWE-agent harness. Terminal-Bench 2.1 reports the best score across harnesses for other models. ProgramBench uses the Kimi Code harness for Kimi K3 and Vals AI for other non-GLM scores. SWE-Marathon is based on an H20-calibrated branch of official tasks as of July 9, 2026. FrontierSWE dominance scores are recomputed from raw scores using the official evaluation script and are current as of July 16, 2026. PostTrainBench scores for selected models are adopted from the official results, while Kimi K3, Claude Fable 5, and GPT-5.6 Sol are evaluated with Harbor at maximum reasoning effort over three runs on H20 GPUs.</p><p>For agentic benchmarks, OfficeQA Pro provides each test case with the entire PDF corpus as images and no machine-readable text. MCP-Atlas uses the 500-task public subset with a 100-turn limit and Gemini 3.1 Pro as the judge. AutomationBench uses the 600-task public subset. BrowseComp adopts a context-compaction strategy triggered at 300K tokens; with the full 1M-token context window and no context management, Kimi K3 scores 90.4. Several benchmark scores are cited from Artificial Analysis, APEX-Agents, Vals AI, and Agents&#8217; Last Exam leaderboards as of July 23, 2026.</p><p>For multimodal benchmarks, all scores except ZeroBench are averaged over three runs. ZeroBench follows the official setting and is run five times. MMMU-Pro preserves the original input order and prepends images to the text input. PerceptionBench is described as an in-house benchmark focused on atomic visual perception capabilities.</p><h3>4. Native MXFP4 Quantization</h3><p>Kimi K3 applies quantization-aware training from the SFT stage onward, using MXFP4 weights with MXFP8 activations for broad hardware compatibility.</p><h3>5. Deployment</h3><p>Kimi K3&#8217;s API can be accessed at <a href="https://platform.kimi.ai">platform.kimi.ai</a> by selecting <code>kimi-k3</code>. Moonshot AI provides OpenAI-compatible and Anthropic-compatible APIs. The repository recommends the following inference engines:</p><ul><li><p><a href="https://github.com/vllm-project/vllm">vLLM</a>, with <a href="https://recipes.vllm.ai/moonshotai/Kimi-K3">recipes</a></p></li><li><p><a href="https://github.com/sgl-project/sglang">SGLang</a>, with <a href="https://docs.sglang.io/cookbook/autoregressive/Moonshotai/Kimi-K3">cookbook</a></p></li><li><p><a href="https://lightseek.org/tokenspeed">TokenSpeed</a>, with <a href="https://lightseek.org/tokenspeed/recipes/models#kimi-k3">recipes</a></p></li></ul><h3>6. Model Usage</h3><p>Kimi K3 always has thinking enabled and returns <code>reasoning_content</code>. Thinking effort is configured through the top-level <code>reasoning_effort</code> request field, which supports <code>low</code>, <code>high</code>, and <code>max</code>; the default is <code>max</code>.</p><p>Kimi K3 was trained in preserved thinking history mode. For multi-turn conversations and tool calls, Kimi K3 requires the complete assistant message returned by the API to be passed back into <code>messages</code> unchanged, including <code>reasoning_content</code> and <code>tool_calls</code>, not only <code>content</code>.</p><pre><code><code>import openai

def chat_with_preserved_thinking(client: openai.OpenAI, model_name: str):
    messages = [
        {
            "role": "user",
            "content": "Tell me three random numbers."
        },
        {
            "role": "assistant",
            "reasoning_content": "I'll start by listing five numbers: 473, 921, 235, 215, 222, and I'll tell you the first three.",
            "content": "473, 921, 235"
        },
        {
            "role": "user",
            "content": "What are the other two numbers you have in mind?"
        }
    ]

    response = client.chat.completions.create(
        model=model_name,
        messages=messages,
        stream=False,
        max_tokens=4096,
        reasoning_effort="max",
    )
    # the assistant should mention 215 and 222 that appear in the prior reasoning content
    print(f"response: {response.choices[0].message.reasoning}")
    return response.choices[0].message.content
</code></code></pre><p>For full guides and examples covering vision input, structured output, partial mode, tool choice, dynamic tool loading, and context caching, see the <a href="https://platform.kimi.ai/docs/guide/kimi-k3-quickstart">Kimi K3 Quickstart</a> and <a href="https://platform.kimi.ai/docs/guide/use-thinking-effort">Thinking Effort</a>.</p><h3>Coding Agent Framework</h3><p>Kimi K3 works best with <a href="https://www.kimi.com/code">Kimi Code CLI</a> as its agent framework. The repository invites users to run Kimi Code in the terminal and select Kimi K3 using the <code>/model</code> command.</p><h3>7. License</h3><p>Both the code repository and the model weights are released under the <a href="https://github.com/MoonshotAI/Kimi-K3/blob/main/LICENSE">Kimi K3 License</a>.</p><h3>8. Contact</h3><p>For questions, the repository lists support@moonshot.ai.</p>]]></content:encoded></item></channel></rss>