China’s ‘open source’ AI isn’t a gift — it’s a Trojan horse

Published July 22, 2026 7:00am ET



Chinese artificial intelligence company Moonshot AI recently released its latest model, Kimi K3, triggering fresh alarm in the United States that China may be erasing America’s AI lead.

In April, the Center for AI Standards and Innovation estimated that China’s leading model at that time, DeepSeek’s V4, was approximately eight months behind top American systems. However, less than three months later, benchmarking firm Arena.ai ranked Kimi K3 as the best in six out of seven key categories, including data analytics and content creation, surpassing Anthropic’s Claude and OpenAI’s GPT-5.6 Sol. The Kimi K3 also climbed 17 places compared with its predecessor, Kimi K2.6, demonstrating the rapid pace of progress in Chinese AI development

Yet, it would be premature to conclude that China has eliminated America’s advantage in the AI field. Much of what China has achieved still relies on foundational technologies pioneered in the United States. Notably, Chinese AI companies continue to depend on cutting-edge Nvidia Blackwell chips. They have resorted to tactics like third-country routing, shell companies, and even smuggling to navigate around U.S. export restrictions, as reported by the Wall Street Journal.

American AI companies have also raised serious concerns about Chinese competitors engaging in unauthorized “distillation.” This practice involves training smaller “student” models on outputs generated by powerful “teacher” models (like Claude or GPT), enabling them to replicate advanced capabilities at a significantly reduced time and cost. 

In February, Anthropic disclosed that it had discovered three Chinese AI companies — DeepSeek, Moonshot, and MiniMax — using fraudulent accounts and proxy services to generate over 16 million interactions with Claude, thereby violating the terms of service. OpenAI raised similar concerns shortly after DeepSeek’s R1 launch in early 2025.

While closing performance gaps on many benchmarks, most leading Chinese models, including Kimi K3, are released as open source. This allows users worldwide to download, customize, and run them locally at 60%-90% lower costs (sometimes 95%+ on output-heavy tasks) than premium U.S. models from OpenAI, Anthropic, or Google. This cost-effectiveness has enticed prominent U.S. companies, including Airbnb, Coinbase, and DoorDash, to move non-sensitive workloads to Chinese models. Notably, even Microsoft has explored making DeepSeek’s R1 model available on Azure AI Foundry and testing it for Copilot Cowork as a lower-cost option.

At the 2026 World AI Conference in Shanghai, President Xi Jinping portrayed China’s focus on open source as a dedication to openness, collaboration, and fair global access. Do not be fooled by the rhetoric. This ostensibly “open” strategy serves as a Trojan horse, aiming to foster rapid global adoption and technological dependence while positioning Beijing to exert control and gain concessions when necessary.

China is following a familiar playbook it has used in other strategic sectors. Just as it leveraged its dominance in rare-earth minerals to punish Japan during a territorial dispute and restricted exports to the United States to counter President Donald Trump’s tariffs, Beijing is likely to weaponize AI supremacy for geopolitical leverage in the future.

We must not lose sight of the true nature of the regime behind these models. Freedom House’s 2026 report ranks China near the bottom in political rights and civil liberties, with severe restrictions on speech, assembly, religion, and the internet. The country has neither an independent judiciary nor free elections. The CCP maintains absolute control through the world’s most extensive surveillance apparatus to monitor and punish dissent. Only a handful of regimes, such as North Korea, Eritrea, and Syria, score worse.

The Chinese government mandates that AI systems serve the Chinese Communist Party. Thus, relying on Chinese models carries a hidden cost: potentially yielding influence to a regime determined to shape the future of AI to its advantage.

A major report by the Australian Strategic Policy Institute shows how the CCP is already using large language models and other AI systems to automate and scale censorship, surveillance, and preemptive suppression of dissent. Chinese AI companies are making government censorship faster, cheaper, and more pervasive. As a leading exporter of surveillance technology, Beijing is poised to export these upgraded tools to other authoritarian states, helping them tighten control over their populations.

A U.S. House select committee on the CCP report found that up to 85% of responses from DeepSeek are altered or suppressed to align with party narratives, such as insisting Taiwan is part of China and denying events such as the Tiananmen Square massacre. These content controls extend into applications built on the models. The popularity of Chinese AI models abroad means millions of foreign users are unwittingly helping propagate CCP propaganda.

Trump’s recent primetime address on election integrity further underscored the threat, with declassified intelligence revealing China’s alleged compromise of 220 million U.S. voter files — the largest such breach in history. Sophisticated Chinese AI models could powerfully advance the CCP’s goal of undermining democratic processes by amplifying disinformation, targeting voters with tailored propaganda, and enabling large-scale influence operations at minimal cost. 

There is already credible evidence that China is among the foreign actors using AI-generated content to push anti-data-center messaging, hoping to slow America’s technological advancement. New York recently became the first U.S. state to pass a statewide data center moratorium. 

Even users of Western AI models are not fully insulated. Research shows that U.S. systems generate more positive portrayals of Chinese institutions and leaders when queried in Chinese, largely because their training data includes Chinese state-sponsored news and information sources.

THE TIKTOK PLAYBOOK IS NOW CHINA’S AI STRATEGY

It has become clear that the U.S. and China now lead global AI development, leaving much of the world forced to choose between American innovation and Chinese infrastructure. Beijing’s open-source push, marketed as benevolent, is in reality a strategic Trojan horse. By flooding the market with capable, low-cost models aligned with CCP priorities, China is fostering dependencies that can later be weaponized for censorship, surveillance, data extraction, and geopolitical leverage.

The United States must respond with far stronger measures: rigorous scrutiny of Chinese AI adoption, sustained investment in secure domestic alternatives, and export controls that actually work. Policymakers and the public alike should recognize that self-defeating steps such as data-center moratoriums only hand China a competitive advantage by slowing American innovation while Beijing races ahead. Complacency is not an option. In the AI era, the choice before us is stark: Either we maintain technological leadership and defend an open, free digital future — or we cede the 21st century to digital authoritarianism.

Helen Raleigh is a senior contributor at the Federalist.