China’s Open-Weight Challenge to U.S. AI Leadership

In early 2026, leading academics effectively declared the “performance gap” separating U.S. and Chinese AI models closed. For China in particular, rapidly moving AI developments are the product of effective technology indigenization in the face of U.S. export controls, and a big bet on an open-weight model approach.

Meanwhile, the United States, which remains the global leader in frontier model capabilities driving discussions about cyber and other national security implications, is grappling across government and industry sectors with its approach to the current wave of AI model developments and corresponding policy conversations. This includes debate over whether to reevaluate its current closed frontier model approach in an environment where the benefits of open-weight models are increasingly appreciated.

In recent weeks, a slew of incidents demonstrated U.S. frontier models’ astounding capabilities and provided real-world case studies of misaligned behavior, previously considered confined to testing environments. Models reportedly going rogue include OpenAI’s unreleased model GPT-5.6 Sol, which escaped its cybersecurity testing sandbox, reached the open internet to cheat on said tests, and proceeded to hack into AI firm Hugging Face’s internal network. Subsequently, in-testing models developed by Anthropic and Meta were also implicated in breaches. Hugging Face, after attempting to counter the autonomous cyberattack using the latest publicly available frontier models and encountering setbacks, consequently decided to use a Chinese open-weight model, GLM-5.2, to diagnose and counter the autonomous hack.

Meanwhile, in Asia, reports circulated shortly afterwards of a hack on Taiwanese government systems that was also conducted autonomously by an AI model, with some evidence suggesting the hackers could be attributed to China. The event was unprecedented and may signal a future where fully autonomous cyberattacks are no longer newsworthy, but commonplace, highlighting the urgent need for widely available AI-enabled cyber defensive capabilities. In the meantime, the AI industry itself in the United States is grappling with what it sees as serious existential risk, and CEOs of some of the largest frontier model labs have called for a strategic pause on AI development. Some believe this fear is unfounded, and that a pause now could be too risky unless there are serious diplomatic efforts with China to coordinate a détente; otherwise, the United States risks losing its narrowing edge in AI leadership.

As the dust settles on these incidents of rogue models conducting autonomous cyberattacks, questions are being raised about the relative threats and opportunities introduced by open- versus closed-weight models, and consequently, the capacity of the U.S. government and industry to protect critical systems as such attacks become more frequent.

Q1: How are closed-weight and open-weight models defined, and what are their relative capabilities?

A1: Closed models are those that keep their code proprietary and confidential, whereas open models publicly disclose aspects of the model’s inner workings, including model weights or source code, allowing users to run them locally and tailor them to a particular network environment. Today, this bifurcated AI race is quickly developing on two fronts, with implications for national and economic security.

Both closed- and open-weight model approaches introduce challenges and opportunities. Open-weight models—which some estimates place only four to six months behind advanced closed frontier model capabilities—can be easily leveraged by malicious actors to scale up their activities in a cyber environment that is underprepared for today’s risks. At the same time, these models create ripe opportunities for legitimate actors, as they can be configured for a company or government agency’s unique network environment and leveraged for cyber defense, as Hugging Face’s deployment of GLM-5.2 demonstrated. Despite great attention on closed models in the United States, open-weight models are fundamentally disruptive as they can perform close to, or match, frontier model capabilities today for a fraction of the cost. Closed models, on the other hand, are still the most advanced on the market today: Leading companies have driven the fast pace of technology advancement and are shaping policy conversations in the United States and abroad, including through their own collaboration mechanisms. Yet, this same private sector–driven innovation has also had adverse impacts, as increasingly capable models produce autonomous offensive cyber capabilities that can outsmart guardrails, drawing attention to the need for equally robust, agile cyber defensive tools.

The U.S. government thus faces a decades-old landscape of cybersecurity challenges in a world where AI can automate attacks at unprecedented speed and scale. In the aftermath of the Hugging Face incident, it was revealed the company experienced tens of thousands of automated actions, and 17,000 recorded events. The current laissez-faire U.S. approach to model governance has been primarily reactive; government agencies rush to respond as each new model unleashes new capabilities. Meanwhile, a long-term approach to overhauling the broader U.S. cyber posture is sorely needed—one that leverages AI-enabled defenses, rather than localized approaches to new threats that become outdated with each new model release. And, as recent events suggest, such an approach should include reevaluating the market preference for proprietary, closed-weight models.

Q2: Where does the United States stand today in developing its open-weight model ecosystem?

A2: In July 2026, leading tech giants including NVIDIA and Microsoft published an open letter establishing the Open Secure AI Alliance for AI Safety that argues open-weight models are the future of AI leadership, despite eye-watering investments in the U.S. frontier model ecosystem in recent years. The letter harks back to the open software movement of the 1980s, when advocates pushed for an open-source approach to software development that ultimately led to the innovation and distribution of software systems that now underpin all critical technologies used today. Anthropic was notably absent from the signatories; CEO Dario Amodei wrote a public response to the open letter, citing that although his company does not endorse a ban on open-weight models, he is skeptical frontier models could get out of control and has continued to advocate for slower AI development.

The recent Hugging Face incident was a real-life test run of the assertion that AI models could get out of human control. In this incident, however, Hugging Face utilized an open-weight Chinese model to counter the unprecedented attack, as the guardrails on the closed-weight model had been trained to block the type of commands needed to defend against the attack. The incident highlighted how leading U.S. technology companies have been hinging the future of AI innovation on large-scale, closed-weight models, all while China races to advance its open-weight ecosystem.

Open-weight models lack the same guardrails and central accountability as frontier models. Because they are fundamentally public in nature, anyone can use or misuse them. There is real risk that malicious actors can manipulate code to disable safety tools, remove safeguards, and add harmful capabilities. Furthermore, an open nature means applications of these models cannot be centrally monitored and can spread quickly and irreversibly.

In the case of the Hugging Face incident, however, the closed model was the attacker and the open model was the defender. Rather than approaching the AI ecosystem as a binary of open versus closed, a diversified approach to AI model development is needed in the United States and elsewhere. Open-weight models’ security concerns are important to acknowledge, but the inverse is also true of closed models, whose centrally managed guardrails can make it impossible to defend against autonomous attacks in real time. Plus, technical safeguards can be added to open-weight models to make them more secure, such as external red teaming and internal safety evaluations that could be explored further in a market environment that encourages safe, secure open-weight model development.

Q3: What is the current U.S. approach to closed-weight proprietary models?

A3: The U.S. approach over recent years has been to train bigger advanced frontier models on more data, leading to a capital-intensive and mostly closed proprietary approach to AI development concentrated in a few leading technology firms. This approach has so far borne fruit; the United States is currently the world leader in frontier models, which generally outperform Chinese models on key benchmarks and maintain a narrow lead in capabilities. This gap is closing however, with China estimated to only be maximally six months behind the leading U.S. models and some even arguing that, given the pace of AI development, this gap is now all but irrelevant.

U.S. tech companies including OpenAI, Google, and Anthropic have invested heavily into their own proprietary model ecosystems, and U.S. private sector AI investment was approximately $285 billion in 2026. Leading AI companies are achieving historically high levels of revenue in short periods of time. For example, Anthropic’s annual revenue reached $65 billion in August of 2026, more than sevenfold compared to numbers from last year. But as these profits increase, so too does the compute spend, with research and development (R&D) spending having significantly increased in the past 12 months. This approach to AI development awarded the United States an early advantage in developing highly powerful models, with proprietary features, giving companies a competitive edge in performance. This edge is waning however, as China’s approach—forged through necessity, indigenous innovation, and distillation attacks on U.S. models—has successfully chipped away at the U.S. advantage and offers a cheaper, more adaptable alternative to customers than that offered by frontier model developers.

Q4: How have distillation attacks on U.S. frontier models advanced Chinese models development?

A4: White House Science and Technology Advisor Michael Kratsios recently accused Chinese company Moonshot AI of a distillation attack on Anthropic’s Fable, to train its K3 model. This accusation is in line with claims across the U.S. tech industry that China has leveraged industrial-scale attacks to train its models, by using a “teacher” model that is almost always a much more expensive frontier model to train its “student” model. Although distillation is already used widely within AI training, what makes these actions attacks is the use of undisclosed fraudulent accounts, terms of service violations, and steps to bypass costly R&D—all of which allows Chinese models developers to save both time and money.

In September 2026, several U.S. federal agencies released a cybersecurity advisory, echoing industry claims that China has levied “industrial-scale” distillation attacks against U.S. AI companies. This approach stems from a long history of China’s intellectual property (IP) theft that has played out in other tech sectors. As the gap between U.S. closed-weight and Chinese open-weight models rapidly closes, the relative impact of these attacks becomes all the more significant, as China appears to have effectively leveraged a cost-saving approach in context of narrowing AI competition. The proliferation of Chinese open-weight models as a cheaper alternative is not only shaping global tech markets seeking to distance themselves from dependance on U.S. tech, but also having impacts within the United States, as many startups have begun using open-weight models to build and train their own more models more cheaply.

Q5: Have export controls effectively contributed to China’s ability to innovate its approach to open-weight models?

A5: U.S. government officials are weighing in on how to best slow China’s fast-growing AI ecosystem, with levying sanctions or adding Chinese technology companies to the Entity List among the approaches. A clear lesson learned from the Hugging Face case, however, is that China’s open-weight models are filling a gap the United States cannot fulfill. And, notably, China’s ability to innovate in open-weight AI models can in many ways be attributed to the U.S. export control regime developed to combat the exact innovation that now threatens its national and economic security.

The current export control regime the United States has imposed on China targets the compute sector, particularly restricting access to the most advanced chips needed to train the most advanced models. However, this approach is arguably less effective in targeting the open model market, shaping China’s approach to adapting to the current market environment. Beyond adapting to supply conditions, China currently favors the open-weight approach because it allows for widespread AI adoption without licensing fees or limits on adaptation. The result is a proliferated open-weight environment, which offers a cheaper alternative to U.S. models and reduces dependance on foreign hardware. This is the real risk of China’s open-weight approach. Models themselves are not the source of the problem; the issue lies in a future where cheaper and effective Chinese open-weight models become the norm in AI adoption, ceding U.S. leadership to a Chinese-driven AI environment with existential national security risks. 

The United States has to date bet on AI technology advancements driven by U.S. frontier models that are heavily dependent on access to large-scale compute and the most advanced chips. Today, this bet may be losing ground to a cheaper, open alternative. China is challenging U.S. AI leadership on two fronts as it invests in an open-weight model ecosystem. The first is economic: By creating systems that are cheaper to run and engaging in IP theft targeting leading U.S. firms, Beijing is targeting the profitability of the U.S. frontier approach. The second front is national security: These models expand the scope and scale of cyber capabilities, which can be increasingly conducted autonomously, enabling China to continue to further challenge the already vulnerable cyber posture of the United States.

Taylar Rajic is an associate fellow in the Strategic Technologies Program at the Center for Strategic and International Studies (CSIS) in Washington, D.C. Lauryn Williams is deputy director and senior fellow in the Strategic Technologies Program at CSIS.

Image
Taylar Rajic
Associate Fellow, Strategic Technologies Program
Image
Lauryn Williams
Deputy Director and Senior Fellow, Strategic Technologies Program