Beijing Breaks Its Silence on U.S. Allegations of AI Model Distillation
Over the past few days, Washington has seen an unusually intense debate over Moonshot AI’s Kimi K3 and the broader issue of model distillation. More than 50 U.S. companies—including NVIDIA—have signed an open letter urging the Trump administration not to restrict open-weight AI models.
George Chen, Partner at The Asia Group, has spent the past few days attending the APEC Digital Ministers' High-Level Meeting in Chengdu. According to him, the U.S. delegation has already raised the issue of model distillation with the Chinese delegation during closed-door discussions.
In closed‑door meetings, the U.S. delegation pressed Chinese officials on “industrial‑level distillation”, citing the new release of Kimi K3 as an example. U.S. officials also claimed training new models on the outputs of existing ones could undermine intellectual property protections. CAC officials strongly pushed back, insisting distillation was legitimate and distinct from theft.
After largely remaining silent throughout the debate for several days, China offered its first comprehensive response today.
At a regular press briefing, a spokesperson for China’s Ministry of Commerce (MOFCOM) delivered a lengthy and carefully worded statement.
MOFCOM first framed the U.S. allegations as an attempt to politicize and weaponize technology and trade issues, “stigmatize Chinese companies,” and “label” China without evidence. It further described Washington’s approach as a form of “AI hegemonism.”
The ministry also questioned the factual basis of the U.S. accusations. It noted that the release of Kimi K3 (without naming the company directly, referring instead to “the relevant Chinese enterprise”) came very close to the release of comparable U.S. frontier models. It further argued that Chinese AI models have already reached—or in some areas surpassed—the global frontier, citing front-end coding capabilities as one example of China’s growing technological competitiveness.
MOFCOM then turned the argument around, stating that many American AI companies have themselves distilled Chinese models during research and training. It also pointed to recent statements by “some large U.S. multinational companies”—an apparent reference to firms such as NVIDIA—which have argued that model distillation is a widely used industry practice and that American companies should continue to have access to Chinese open-source AI models. In particular, MOFCOM cited the recent open letter signed by dozens of U.S. companies supporting open-weight models as evidence that significant parts of the American AI industry disagree with the current U.S. government’s approach.
Finally, MOFCOM urged Washington to “stop smearing Chinese companies and threatening sanctions.” It also warned that if U.S. actions were to “substantially harm” China’s legitimate interests, Beijing would take “all necessary measures” to safeguard its lawful rights and interests.
The statement was widely republished by Xinhua and other state media outlets, as well as by major Chinese online commentators, quickly becoming one of today’s biggest AI policy stories in China.
Almost simultaneously, Yuyuantantian, a semi-official media account affiliated with CCTV, published a feature commentary titled “Open Models Can Break Western Bias.” The commentary opened with the recent incident in which Hugging Face was autonomously compromised by OpenAI’s models and ultimately relied on Zhipu AI’s GLM-5.2 to resolve the problem. It argued that while the West has long attacked the security of open-weight models, the Hugging Face incident has forced people to reconsider who should define AI safety, risk, and the future of artificial intelligence.
The commentary argued that the United States and the West have been fixated on using “security” as the primary argument against open-weight models, mainly to create justification for future restrictions and sanctions.
Once a technology is labeled a “security threat,” virtually any form of government intervention can be presented as legitimate. Export controls, licensing regimes, and even excluding specific countries from global supply chains can all be framed as measures taken “for the benefit of humanity.”
The article also reviewed Western media coverage over the past several years regarding the safety of open and proprietary models, arguing that these narratives have followed a clear pattern. According to the commentary, they have consistently promoted the following storyline:
Open models mean uncontrolled capabilities and the uncontrolled spread of risk; proprietary models represent responsible governance and order; and when Chinese models enter the global open-source ecosystem, their progress is simply attributed to leveraging Western technology.
Yuyuantantian argued that this narrative is overly absolutist.
There is no such thing as a perfect technological pathway. The existence of problems should not automatically lead to the conclusion that a particular technological approach is destined to fail. More importantly, what matters is who can better identify problems and adapt under pressure.
According to Yuyuantantian, the open-weight ecosystem has already demonstrated significant advantages in at least three respects, and the world does not have to choose between open and proprietary models as if they were mutually exclusive. The recent collective opposition by American companies to banning open-weight models illustrates precisely this point.
First, identifying problems and solving them. Research institutions, enterprise users, and independent developers can inspect model behavior, identify vulnerabilities, develop safeguards, and continuously improve models without waiting for a single vendor to issue updates.
Second, real-world deployment accelerates model improvement. Once open-weight models are deployed in practice, their performance across different scenarios is continuously tested. The more they are used, the clearer the direction for future technical improvements becomes.
Third, specialization is beginning to emerge within the ecosystem. Companies are increasingly deploying open and proprietary models for different categories of tasks. NVIDIA and others have begun offering dedicated large language model routing solutions that dynamically select different models depending on the task.
The commentary argues that the open-weight approach represents a viable path for the continuous evolution of AI and for benefiting users around the world. The future of artificial intelligence depends on whether it can accommodate more choices. Now that both open and proprietary models have become part of the AI industry, the question is no longer choosing one over the other, but rather establishing a set of rules that allows both approaches to maximize their respective strengths while respecting their respective boundaries.
The commentary presents this as an entry point for understanding China’s approach to AI governance. From the Global Development Initiative, the Global Security Initiative, the Global Civilization Initiative, to the Global AI Governance Initiative, China has consistently advocated respecting each country’s own choices, addressing shared challenges through cooperation, and promoting common development through the provision of global public goods. According to the article, this philosophy has now been extended to artificial intelligence.
At a forum organized by the Chinese People’s Association for Public Diplomacy, one expert put it quite directly: China has already provided many public goods to the international community. In the field of AI, countries should simply “use whichever models work best,” and China is willing to strengthen coordination with governments around the world.
According to the commentary, Yuyuantantian also spoke with “industry insiders” and put forward several proposals. Taken together, these proposals aim to shift AI governance away from the binary debate over open versus proprietary models toward a framework of capability- and risk-based governance: opening what should be open, restricting what should be restricted, determining infringement based on evidence rather than assumptions based on a model’s country of origin, and establishing mechanisms for model safety evaluation, vulnerability disclosure, major incident reporting, and international cooperation while preserving innovation and controlling high-risk capabilities.
First, define clear boundaries for openness.
The key question going forward is no longer whether to support open or proprietary models, but rather: Which capabilities should be openly released? Which capabilities should be released only under controlled conditions? Which capabilities require access controls? And after a model is released, who should be responsible for vulnerability disclosure, major incident reporting, and governance of downstream derivatives?
According to an individual who has long studied AI policy and was quoted by Yuyuantantian, basic capabilities can be openly released, some frontier capabilities can be released under controlled conditions, commercial services can remain proprietary, while high-risk capabilities should be subject to access controls and safety evaluations. Before release, dangerous capabilities should be assessed. After release, mechanisms should exist for vulnerability disclosure, major incident reporting, and governance of derivative models.
China supports openness, but this does not mean advocating the unconditional dissemination of every capability. AI governance should begin by assessing what capabilities a model possesses and what risks it may create, rather than focusing on which country developed the model.
Second, define clear boundaries for so-called “infringement.”
Whether infringement has occurred should be determined on the basis of verifiable evidence. One should not simply infer that a model must have “stolen” American technology merely because its capabilities have improved or because it was developed in China.
Third, establish security cooperation mechanisms for the open ecosystem.
AI risks can spread across platforms and across national borders. Countries should promote compatible evaluation standards and establish mechanisms for reporting major security incidents and coordinating vulnerability responses.
Ultimately, the goal is to leave room for innovation, establish clear boundaries for risk, and preserve choices for all countries.
The real dividing line in the next phase of AI governance will not be between open and proprietary models, but between indiscriminate restrictions and risk-based governance.
Whoever succeeds in making AI more broadly accessible while keeping high-risk capabilities under effective control is more likely to define the next stage of artificial intelligence.
The debate unfolding in the United States over open-weight models has also prompted some Chinese observers to reflect on a broader question: how should China manage the relationship between open and proprietary models going forward?
Some observers argue that the current U.S. debate offers valuable lessons for China as well. While China has consistently promoted openness, accessibility, and shared AI development internationally, open-weight models are not the entirety of China’s AI ecosystem. China also has a number of companies making serious long-term investments in proprietary frontier models.
According to them, for large Chinese technology companies, the commercial logic behind open-weight models has become increasingly clear. The strategy is to offer models for free or at very low cost, expand adoption among developers and enterprises, and monetize downstream through cloud computing, inference services, enterprise deployment, applications, developer tools, and hardware. Many industry observers, for example, view Qwen primarily as a customer acquisition channel for Alibaba Cloud. According to Alibaba, by early 2026 the Qwen family had surpassed one billion cumulative downloads on Hugging Face. During the same period, Alibaba Cloud’s external revenue grew by 40% year over year, while AI-related products continued to post triple-digit growth.
They also argued that the picture is very different for AI startups that have models but lack their own cloud platform, application layer, or customer distribution channels. For these companies, a purely open-weight business model may prove difficult to sustain over the long term. Training a frontier model can require investments of billions of dollars. Yet once the model weights are released, competitors can download them, build their own APIs, quantize and fine-tune the models, integrate them into their own cloud platforms, and serve customers at lower prices—all without paying anything to the original model developer. The result is that the model company bears the overwhelming R&D costs, while much of the commercial value accrues to cloud providers, application developers, and distribution channels.
This is not a major problem for Alibaba. Alibaba owns not only the model, but also the cloud platform, enterprise customer relationships, and an integrated commercial ecosystem. The model itself drives demand for higher-value cloud and enterprise services. For startups whose only asset is the model, however, this could become a fundamental commercial dilemma.
As more Chinese models are released as open weights or offered at extremely low prices, enterprises may become increasingly unwilling to pay several times more for a proprietary API that is only marginally better. Model capabilities are likely to become commoditized much more rapidly. API prices may continue to fall, the pricing power of standalone model developers may weaken, and value creation may gradually shift toward cloud platforms, data, applications, enterprise services, and customer relationships.
This suggests that the business models of Chinese AI companies may also evolve over time. Open-weight development is likely to continue because it is no longer merely a technical philosophy. It has become an important competitive strategy for attracting global developers, challenging the platform advantages of U.S. firms, and expanding the adoption of China’s AI technology stack. At the same time, however, the most expensive, most advanced, most commercially valuable, and most sensitive capabilities may no longer be fully open. Instead, they may increasingly remain proprietary and be monetized through APIs, cloud services, enterprise solutions, and vertical applications.
If this trajectory continues, China and the United States may ultimately converge toward a remarkably similar industrial structure: open foundation models competing for developers, ecosystem adoption, and market share, while proprietary frontier models maintain a performance lead and generate revenue through cloud services, computing infrastructure, enterprise offerings, and applications. This is, in fact, remarkably close to the long-term vision Jensen Huang has described.
If the industry evolves in this direction, the Chinese government will face not only industrial policy questions but also regulatory ones.
Some observers therefore argue that China needs to think carefully, sooner rather than later, about how to regulate the relationship between open and proprietary models, including policy guidance, industrial support, and technology export controls.
For example, global media have recently reported that China is considering export controls on advanced domestic AI models in order to prevent cutting-edge AI technologies from flowing overseas. If those reports prove accurate, policymakers would at least face two possible approaches.
The first would be to subject both open and proprietary models to the same export control regime. This would provide regulatory consistency. However, because open-weight models are inherently designed to be copied and distributed, whether such controls could be effectively enforced in practice is another question. More importantly, countries across the Global South might begin to question whether China’s long-standing commitment to openness, accessibility, and shared technological development is changing, making them less willing to adopt China’s AI technology stack.
The second approach would be to focus export controls primarily on proprietary models while allowing open-weight models to remain relatively unrestricted. Under this approach, a model such as Kimi K3, because it is released with open weights, could continue to publish its weights on major international open-source platforms and be freely deployed overseas without requiring export approval. By contrast, a proprietary model—even one that is somewhat less capable than K3—might be required to obtain government approval before its weights could be transferred abroad or deployed internationally.
Such a regulatory framework would give open-weight models a natural competitive advantage in perhaps the most important aspect of global expansion: cross-border weight distribution and overseas deployment. That advantage would not arise from superior technology, but rather from differences in government regulatory treatment.


