I spent about a year asking the wrong question about Chinese AI labs. If they give the weights away, where does the money come from?
I kept assuming a business model was hiding somewhere — a freemium tier, an enterprise upsell, a rug pull once adoption locked in. Open now, meter later. That’s what open source means where I come from: customer acquisition with a delayed invoice.
There is no invoice coming. Once you accept that, everything else follows, including why almost every American response to this has been aimed at the wrong target. Here’s the whole argument, in order.
American AI is a SaaS business wearing a lab coat. You meter consumption, you defend the price, you expand the account, you show net revenue retention to people who are deciding what your equity is worth.
Chinese labs are not running that business. Not badly — at all. Revenue from American enterprises appears on none of their ledgers, and there are four that matter.
The state’s ledger. DeepSeek’s R1 release erased roughly a trillion dollars of US market value in a day. Kimi K3’s launch week took multiples of that off chip stocks — TSMC down 7%, SoftBank down 9%, Nvidia briefly losing the most-valuable-company crown. Meanwhile the AI+ Initiative targets 70% agent adoption across the Chinese economy by 2027 and 90% by 2030, and explicitly calls for “a flourishing open-source AI ecosystem.” The model is free; the factory it optimizes is Chinese. The return arrives as domestic productivity plus margin destruction in a rival’s crown-jewel industry.
The cap-table ledger. Zhipu listed in Hong Kong in January and is up roughly 2,200% — on $105 million of revenue against $695 million of losses. MiniMax doubled on debut, on $53 million of nine-month revenue against $512 million of losses. Moonshot is converting K3’s global adoption into a Hong Kong listing north of $30 billion. Global adoption is the story that prices the stock. An American company running Chinese weights never pays the lab a cent, and it doesn’t matter, because that adoption is the evidence that prices the listing — and Western institutions buy the listing on HKEX.
Anyone who lived through crypto recognizes the shape instantly. It’s a token launch in equity form: distribution builds narrative, narrative converts to liquidity at listing. We learned reflexivity the hard way and then forgot it.
The code ledger. Qwen has over 100,000 derivatives on Hugging Face. Every fine-tune, optimization and RL recipe the world builds on a Chinese base flows back into the next training run — while China’s own data stays closed. The USCC calls it “two loops.” It’s compounding you don’t have to pay for.
And the ledger they don’t need: yours. Chinese models earn roughly 1% of US enterprise AI spend. Hold onto that number. It’s the load-bearing fact in the entire policy debate and almost nobody says it out loud.
Americans keep hunting for the Chinese labs’ moat as though it must be a technology or a network effect. It’s the state, and it’s visible on the balance sheet.
The National AI Industry Investment Fund runs $8.2 billion. The National VC Guidance Fund runs $138 billion. Bank of China committed a $138 billion five-year AI financing program. Provinces hand out computing vouchers. Electricity for datacenters in Gansu, Guizhou and Inner Mongolia has been cut by roughly half. There are demand-side subsidies on API consumption. China is the first country with formal data accounting standards, which means data can be booked as a balance-sheet asset — a quiet and enormous change in what a Chinese AI company is worth on paper.
Put that together and you get something no American company has: a cost floor set by policy rather than by markets. Cheap power, subsidized compute, subsidized demand, and capital that doesn’t need a return on the schedule a fund does.
You cannot out-compete a moat like that on price, because it isn’t a price. It’s a decision.
This is the part I’d put in front of any American executive modeling Chinese labs as competitors.
DeepSeek took its first outside capital in June — about $7.4 billion at over $50 billion, after two and a half years running on High-Flyer’s hedge fund balance sheet. Most investors received a limited partnership with five-year lockups and zero voting rights. The state’s National AI Industry Investment Fund was the sole investor granted direct equity and voting rights.
Read the structure again. Money buys exposure. The state buys control.
Zhipu is the same story with municipal characteristics: state funds from Chengdu, Hangzhou and Zhuhai, Shanghai state funds, direct Hangzhou government money. Moonshot has China Mobile — a state carrier — on the cap table.
So compare the scorecards. A public American AI company answers to gross margin, net revenue retention, burn multiple, and a quarterly call. A Chinese lab whose only voting shareholder is a state industrial fund answers to a five-year plan: adoption targets, domestic productivity, ecosystem share, national capability.
Exactly one of those two organizations can rationally price its flagship product at zero, forever, and feel good about the quarter. It isn’t the one with the earnings call.
This is why “they’ll have to monetize eventually” is the most comfortable and least supported thing Americans say about this. They will monetize domestically, and they already are — Moonshot went from $200 million to $300 million ARR in two months, Zhipu bills the state-owned enterprises, Qwen sells Alibaba Cloud. Abroad, they may never need to, because diffusion itself is the payoff.
Here’s the detail that convinced me this is an industrial program rather than an industry.
Since roughly December 2025, and formally expanded in May 2026, senior AI researchers and founders at Chinese labs — Alibaba, DeepSeek and Manus among the named firms — require government approval before traveling internationally. The policy began with state-owned enterprises and now covers private companies and startup founders. People are added to the list based on their assessed impact on China’s AI ambitions rather than their title or employer. Neither Alibaba nor DeepSeek has commented publicly.
Two things follow from that, and both matter.
Analytically, nearly everything the West believes about these labs is inferred from published papers, released weights, benchmark results and a handful of curated interviews. That’s not nothing — weights are the most honest artifact any lab produces — but we’re reading a system through its outputs while it reads us through an open press, a leaky venture ecosystem, and executives who post their roadmaps. The information asymmetry runs one direction and it isn’t ours.
Strategically, you don’t restrict the movement of people whose work you intend to sell. You restrict people whose work you intend to deploy. Governments control the movement of nuclear physicists and rocket engineers. They don’t control the movement of SaaS founders. The travel policy tells you which category Beijing thinks these people are in, and it isn’t the one where you’re optimizing net revenue retention.
Now the part Americans find genuinely unreadable, and which explains more Chinese strategy than any policy document I’ve read.
Shanzhai — 山寨, “mountain stronghold,” carrying a connotation of bandits operating outside official authority — started as a word for knockoff electronics. Nakia phones. Samsong. The ai-phone. Western coverage stopped there, filed it under counterfeiting, and missed what it turned into: the entire open manufacturing system Shenzhen built over thirty years.
The mechanics matter. Shanzhai runs on open access to components and on gongban — shared reference boards and bills of materials circulating freely between manufacturers, with total disregard for IP. A design that works becomes common property within weeks. Iteration cycles run in weeks where Western consumer electronics runs in quarters.
And here’s the sentence that unlocked it for me, from the V&A’s research on Shenzhen: the concept of branding, which attracts most of the attention in the Western world, is almost irrelevant in the shanzhai world, where what really counts is to make and sell things in the most efficient way.
That’s not a moral position about intellectual property. It’s a different theory of where value lives.
The American mind locates value in the brand, the IP, the design language, the margin — the story around the object. The shanzhai mind locates it in throughput: cost of goods, speed to market, units reaching someone who needs one.
So when that mind encounters a product selling for two thousand dollars, it does not see a premium brand. It sees thirty dollars of components, a factory that could be running by Thursday, and roughly nineteen hundred and seventy dollars of marketing, retail markup and waste that somebody convinced a customer to pay for.
And it feels none of the things an American product manager would feel about that. Not envy. Not guilt. Not a competitive urge to build a better brand. It feels the way you would feel about an obvious arbitrage that nobody had bothered to take.
The output was never only copies, either — that’s the second thing the Western coverage got wrong. Shanzhai produced phones with oversized fonts for elderly users, multiple SIM slots for migrant workers, solar chargers for places with unreliable power, and a built-in compass oriented to Mecca. Those aren’t counterfeits. They’re products for customers a global brand had decided weren’t worth a line item.
Now apply that instinct to today’s market. Frontier intelligence sells for something like $56 per million tokens. Equivalent open-weight capability runs closer to fifty cents. The thing being sold is a file. The marginal cost of distributing it is zero.
An American executive looks at that gap and sees a defensible premium justified by reliability, support, safety and brand. A shanzhai-trained instinct looks at the same gap and sees the largest arbitrage in the history of manufactured goods, and reaches for it without one thought about whose logo is on it.
That psychology isn’t inscrutable. It’s orthogonal, which is worse — because orthogonal strategies don’t show up in your competitive analysis at all until they’ve already taken the market.
It’s also worth remembering how this pattern plays out over time, because we have the tape — and I was standing in it.
I spent time in China when WeChat was crossing 96% penetration in the major cities, and I wrote about what that actually felt like on the ground: renting a power bank in a metro station by scanning a QR code, $1.72 for 24.7 kilometers on a Mobike, a $300 billion sharing economy running through one app because there was no friction left to remove. I also wrote at the time about why WeChat was beating Messenger and WhatsApp at their own game, which was not a feature argument — Western messengers had the features. It was that WeChat had stopped being an app and become the layer everything else ran on.
The sequence never varied: win presence first, monetize nothing for years, then fold in payments via the 2014 red-envelope masterstroke, then every vertical — shopping, city services, mini-programs, eventually a national electronic ID — once switching costs were absolute.
Saturation first, extraction later. The exact inverse of the American instinct to meter from day one. I watched that movie for years before it occurred to me that the open-weights strategy is the same film with the infrastructure layer as the protagonist.
Follow the incentives of the people who actually funded this, and the strategy stops looking like generosity.
State industrial funds, provincial governments, Chinese PE, and Hong Kong public markets hold the equity. That equity appreciates when Chinese models are adopted globally — because adoption is the story that prices an HKEX listing that has essentially no revenue behind it. Zhipu at 2,200% on $105 million of revenue is not a company being valued on cash flows. It’s a company being valued on evidence of diffusion.
Now look at what those same stakeholders are positioned against. American AI value is concentrated, private today, and about to become public, liquid and marked daily. Ninety percent of US venture funding is going to AI. OpenAI and Anthropic alone took 74% of those dollars. AI capex is carrying US equity performance outright.
So one side holds assets that appreciate when the price of intelligence goes to zero. The other side holds assets that are priced on the assumption it doesn’t.
I want to make the structural argument here rather than the conspiratorial one, because the structural one is both more defensible and more alarming.
DeepSeek is owned by a quantitative hedge fund. High-Flyer isn’t an incidental backer — the company is a release pipeline and a trading desk under one founder. Bill Ackman asked the obvious question in January 2025 about short-dated Nvidia puts around the R1 drop, and no evidence ever surfaced. What is documented is that short sellers made over $6 billion on Nvidia alone during that week. And trading ahead of your own release isn’t even classic insider trading when there’s no listed security in the entity doing the releasing.
Nobody has to allege anything. The org charts are public, the incentives point one direction, and the release calendar is free.
This is the thing I’d most want an American AI executive to internalize: you cannot kamikaze their business by open-sourcing your own technology, and you cannot starve them by refusing to buy.
They don’t need the revenue. What they need is distribution, and giving it away is the most efficient distribution mechanism ever devised. It costs them almost nothing, it makes them look like the good guys, and it drops adoption straight into the story that prices their listings.
Meanwhile the demand side is real and it’s already moving. OpenRouter’s weekly token share by model author, second week of June, one year apart: US models fell from 72% to 33%; Chinese models rose from 17.4% to 46.8%. A 13.8-point lead, in twelve months.
Coinbase routed over 1,200 agents to GLM and Kimi and cut AI spend roughly in half — Brian Armstrong said so publicly. Cursor built Composer 2 on Kimi. Airbnb runs Qwen for customer service because it’s fast and cheap. Uber burned its annual AI budget in four months on premium tokens and went shopping.
Now the honest counter, because the argument is stronger for it: closed APIs still take roughly 89% of enterprise AI spend, and a16z’s CIO survey shows open-source share of enterprise LLM spend actually falling, from 19% to 11%. Usage flipped. Dollars haven’t. That’s the crossover in progress, moving workload by workload from the cost-sensitive end upward — volume is the leading indicator, spend is the lagging one — but anyone telling you the enterprise has already switched is selling something.
And the switch isn’t free for the buyer, which is the other thing that gets glossed. Running open weights yourself means inference cost, infrastructure, MLOps, evals, security review, and owning the model risk that a vendor used to absorb. The Mozilla data says it plainly: the blocker is operational tooling and trust, not model capability. Infra cost, security and compliance, and maintenance are the top three.
That gap between “free model” and “working deployment” is not a footnote. It’s where the entire American opportunity lives.
Here’s the sequence, and we’re already three beats into it.
Beat one: “Chinese models are dangerous.” Now playing. Cramer’s “Finsuicide” segment. State Department statements about embedded censorship. Congressional letters to Cursor and Airbnb. Booz Allen finding three of four Chinese code models produced more vulnerable code for self-identified US government users — with the caveat, in their own report, that they have no proof the flaws were intentional.
Some of this is real. Chinese-hosted APIs are a genuine data problem: your prompts land on servers under PRC jurisdiction. That distinction — Chinese-hosted API versus self-hosted weights — is the entire policy question, and the loudest voices in this debate consistently don’t know it exists. A self-hosted open weight collects nothing. No prompt retention, no training on your data, no lock-in. It is the privacy-maximal deployment, and it’s the one a ban would discourage.
Beat two: “We need to change American business models.” The quiet panic as IPO paperwork meets open-weight pricing. The CEO of Writer already said the quiet part: “These LLM companies are going to go public and they’re going to raise prices because they have to.” Raise prices — into a market where equivalent intelligence costs a fiftieth as much.
Beat three: restriction, scoped and timed. Not a weights ban, which is unenforceable and everyone technical knows it. The Axios-reported draft executive order points at security requirements plus legal liability for US companies hosting foreign models. That targets intermediaries, because you can’t ban math but you can regulate chokepoints. My call is OpenRouter and Hugging Face get pressured first.
Beat four: the loophole becomes the market. None of that touches self-hosted open weights running on American silicon in American datacenters, phoning home to nobody. Adoption doesn’t stop. It goes infrastructure — quieter, deeper, permanent.
And now the consequence, which is the actual weapon. American businesses get told to use more expensive models for security reasons. Businesses want freedom and cheaper inputs. US labs, now public and margin-constrained, respond the only way a public company can: move up the stack, charge more, lock in harder, demand more of the customer’s economics — because the model layer alone no longer supports the valuation.
The chaos isn’t the model release. The chaos is what we do to ourselves in response to it.
Play that out and the optics are almost too good to have designed.
China is the champion of open access. America is the party defending a price. And that framing isn’t rhetorical — twenty-nine countries have joined Xi’s World AI Cooperation Organization, positioned explicitly around open access. A US restriction makes that claim more credible, not less, and it lands hardest in exactly the markets where WeChat won: places that would rather have working infrastructure than a principled dependency.
Then comes the Red Hat move, outside the US. Free weights don’t monetize themselves, but support, hosting, integration and compliance do — and Huawei is the distribution channel already in place. Ascend edge boxes, NPU phones, a HarmonyOS fleet approaching a billion devices, Belt-and-Road datacenter-plus-power packages. Notice the design convergence too: Chinese labs build sparse mixture-of-experts models — K3 activates 16 of 896 experts — that run beautifully on exactly that class of constrained domestic silicon. The architecture and the channel were built for each other.
WeChat won diaspora rails across Africa and much of Southeast Asia, got blocked in India, never cracked the West. Watch Chinese models run the same map, with a services business layered on top in every region where the US isn’t setting the rules.
And underneath all of it, the trade. American AI value is about to consolidate into public markets — the IPO wave, the index inclusion, the pensions, the liquid options chains. Every one of those listings is priced on token margins. Every one of them reprices when a free comparable model drops. The parties with the best knowledge of release timing are on the other side of the ocean, and after the listings there will be direct tickers to express a view on.
You don’t need a conspiracy for that to be dangerous. You need a calendar.
Watch for it in the S-1 risk factors, incidentally. SEC-mandated disclosure will force the sentence into the filings: a foreign competitor may release comparable technology at no cost. The prospectus will concede the thesis in writing, on the day of the roadshow.
The wedge is open source, and it keeps working. What I can’t see is the end.
Here’s what makes me think we haven’t seen their best work, stated carefully, because this is exactly the claim that turns an argument into a conspiracy theory if you’re sloppy.
Beijing’s Ministry of Commerce is consulting domestic AI and chip firms on a licensing regime for advanced AI systems — reviewing export lists, tightening end-user checks, raising barriers to transferring technology abroad. Reuters reported the discussions covered flagship systems by name: Alibaba’s Qwen, ByteDance’s Doubao, Z.ai’s GLM-5.2 — both closed and open-weight. And officials are weighing a tiered review under which frontier systems might be kept at home entirely. The stated rationale is to stop China’s most advanced systems from being scooped up by the West.
Nothing is decided, and officials stress the curbs might apply only to future models. But you don’t build a licensing regime for something you intend to give away.
The behavior already supports it. The operating pattern this past year has been: open the prestige flagship, close the monetized turbo variant, raise the API price on the closed one. Alibaba tried taking Qwen3.6-Max API-only before reversing with an open 2.4-trillion-parameter release. Baidu and Tencent took their flagships back to closed. And Huawei training Pangu 718B on 6,000-plus Ascends means what gets released is a policy decision now, not a capability ceiling.
Honesty requires the caveat: there’s no public evidence of a stockpile of superior unreleased models, and capability trackers put the leading Chinese lab three to six months behind the US frontier. I’m inferring from structure and policy, not reporting a source.
But it doesn’t actually matter whether they’re sitting on something better. What they hold is the option — the ability to release something competitive at zero, at a moment of their choosing, at trivial cost, with no position that gets damaged when the market reprices. That option is valuable whether or not anything remarkable sits behind it. And a state that formally reviews which models may leave the country has decided that release timing is a policy lever rather than a company decision.
So where does it go?
The ban doesn’t work. We’ve run the experiment three times. Linux: open source won the server, America didn’t prosecute the engineers or ban the kernel because Linus was Finnish, IBM put in a billion twice, Microsoft went from “Linux is a cancer” to top kernel contributor, Red Hat built the toll booth and sold for $34 billion, and cloud and Android and the modern internet got built on that commons. Tornado Cash: OFAC sanctioned open-source contracts, the Fifth Circuit ruled immutable code isn’t sanctionable property, Treasury delisted — but they got the engineer anyway, chilled a generation of American developers, and stopped nothing. Open weights is run three, and there’s no third path where prohibition works; the weights are on the internet and Bernstein v. DOJ sits right there as code-as-speech precedent.
And the punchline: the same administration drafting restriction orders put “encourage open-source and open-weight AI” in its own July 2025 AI Action Plan, funds open ecosystems through NSF POSE, and co-signed a $152 million check with NVIDIA for Ai2’s open models. David Sacks said it out loud: “The leading closed labs, already a duopoly in terms of AI model revenue, want the government to eliminate their open-source competition. They have laid their cards on the table.” This isn’t America versus China. It’s American policy versus American policy, with the closed labs lobbying one wing of the White House against the other.
The realistic endgame is a toll booth. TikTok didn’t end in prohibition — it ended in three non-enforcement orders in defiance of the statute, then a negotiated joint venture with Oracle, Silver Lake and MGX at 15% each and ByteDance engineered to 19.9%, just under the statutory line, at $14 billion against prior estimates of $40–60 billion. Public support for the ban decayed from 50% to about 32% as usage entrenched. Someone becomes the Oracle of AI: the trusted American runtime certifying that foreign-origin intelligence runs clean on American infrastructure. That seat is worth more than the model layer it certifies.
And the only real defense is to stop selling the thing that reprices. You cannot out-free a country that has decided pricing its flagship at zero is a good trade for the state. So change what’s being sold. Revenue priced on verified delivered outcomes doesn’t reprice when a free model drops; token-metered revenue does. That’s the whole hedge, and it’s available now.
It also happens to be what the market is asking for. Ninety-seven percent of enterprises have deployed something and roughly 11% have anything in production at scale. That gap doesn’t close with cheaper tokens — it closes with accountability. And the token is already failing as a unit of account even in court: Kahn v. Anthropic, filed June 10 in the Northern District of California, alleges paid plans deliver allowances far below what was advertised, with pricing that obscures consumption. What’s being litigated isn’t a wrong answer. It’s the illegibility of the token as a commercial unit.
The winners of this round are already visible and they aren’t the most decentralized — they’re the most portable. Fireworks at $17.5 billion, Baseten at $13 billion, Together at $8.3 billion are centralized businesses selling decentralizability: your weights, your data, your VPC, credible exit from any vendor and any jurisdiction. Fireworks’ most telling number isn’t the valuation — it’s that 95% of its tokens come from specialized models trained on customers’ proprietary data. Enterprises are already paying for their own intelligence rather than renting someone else’s.
There’s a wildcard that could invert all of it: if Beijing actually restricts its own labs’ overseas releases while Washington restricts access from this side, both governments squeeze at once, and the premium on already-downloaded weights, neutral runtimes and portable infrastructure goes up sharply inside a quarter.
What I’m confident about is narrower. They aren’t running our playbook badly. They’re running a different one, on purpose, funded by people with different scorecards, executed by an instinct that sees our margins as waste rather than as value. And the most dangerous thing about a business model that was never designed to take your money is that there’s nothing you can take away from it.
Where we go after the wedge becomes unbearable, I genuinely don’t know. But I’d rather we spent the next year building a business model that can’t be shorted by a file than another year arguing about whether the file should be legal.