Selective, targeted ban: the White House picks its shots at Chinese open-weight models
The New York Times reports that the White House is leaning toward selective bans on individual Chinese open-weight models, rather than a blanket ban on all open weights from China. National security concerns remain the justification, but the approach is shifting: models are targeted case by case, leaving room for the rest.
For those building systems on open models, the difference between a total ban and a targeted one is concrete. A blanket prohibition would have cut off access to Qwen, DeepSeek, Kimi and the entire Chinese supply chain that now powers much of local and self-hosted stacks. A selective ban lets the ecosystem survive, but introduces a regulatory risk criterion that didn’t exist before: a model available today may not be tomorrow if it lands on the list.
Meanwhile, OpenAI and Google DeepMind signed an open letter against open-weight model regulation, alongside many companies with commercial interests in open source (Microsoft and Google sell access to Chinese models through their services). The contradiction is what we flagged on July 23: OpenAI and Anthropic lobby privately to limit Chinese models, even though OpenAI signed the letter against regulation. Pressure on open weights doesn’t come only from politics, but from proprietary labs facing price competition.
For now, even the most recent Chinese models like Kimi K3 lag on cybersecurity benchmarks. The window to decide your strategy on open models is open, but closing.
In detail
What came before.
As early as July 20, Nathan Lambert described regulatory pressure on open models as Anthropic’s regulatory capture, and on July 23 we reported the common front between OpenAI and Anthropic in lobbying against open weights. This story confirms that pressure is translating into concrete policy: the New York Times documents that the Trump administration is building what The Decoder calls a «slow-motion ban», through sanctions and soft pressure.
What really changes.
The point is that the dynamic has structured itself at three levels, regardless of whether Chinese models get banned today:
- The White House is evaluating targeted, specific bans. This means the availability of an open-weight model becomes a variable that can change with an administrative decision, rather than the vendor’s release cycle.
- Proprietary labs (OpenAI, Anthropic) push privately to limit Chinese competitors, while signing public letters against open source regulation. OpenAI faces price pressure from cheaper Chinese models; Anthropic shares the same exposure.
- Companies with open source interests (Microsoft, Google, but also Hugging Face and the entire self-hosted supply chain) oppose regulation because Chinese open models have become infrastructure for their services.
Technical details for those not building models.
Open-weight models are those whose parameters (neural network weights) are published freely. Anyone can download and use them locally, without going through a commercial API. Models like Qwen (Alibaba), DeepSeek and Kimi K3 (Moonshot AI) have become the backbone of many local stacks and self-hosted agents. If a model lands on a ban list, users stop receiving updates and support, and in some cases may need to remove it from production environments.
How much to trust the security concerns.
The Times writes that national security concerns “could prove valid over time.” For now, cybersecurity benchmarks show that even the most recent Chinese models (like Kimi K3) lag behind frontier Western ones on offensive capabilities. The risk exists in potential, but hasn’t been demonstrated in practice yet. This makes the selective ban a cautious political move, but also one that could expand the list as Chinese models improve.
What remains open.
There’s no public list of banned models yet, nor formal criteria for deciding which ones end up in the crosshairs. Timing is uncertain. And the contradiction between OpenAI’s public letter and its private lobbying suggests that pressure on open weights will follow market dynamics, not just security ones.