How America Wins the AI Race With Open Source

42 minutes ago 4
Chattythat Icon

Speaking in Shanghai on July 17, Xi Jinping offered the world a vision of AI “for the positive, for good and for humanity.” He called for open source, openness, and sharing. He cautioned against stretching national security to cover the field. And he announced that over the next five years China will train 5,000 people from developing countries, build AI application cooperation centers with ASEAN, the Arab League, the African Union, CELAC, the Shanghai Cooperation Organization, and BRICS, and extend its MAZU meteorological warning system to 30 countries. The World Artificial Intelligence Cooperation Organization now exists in Shanghai with 37 member states.

This reasonable sounding offer is aimed squarely at the governments the United States most needs: countries that want AI capacity, local control, and a voice in setting the rules. For these governments sovereignty means control rather than independence, and a system they can operate locally is an easier sell than a remotely controlled API. Beijing pairs capable open weight models and inexpensive inference with training, institutions, and public goods, then wraps the package in the vocabulary of multilateralism and the United Nations.


The results are already visible. CNAS counted sovereign AI initiatives in 67 countries and the European Union by mid-2026, up from 16 governments in 2023, and most model projects with disclosed foundations adapt a foreign open weight model rather than train one. Increasingly that foundation is Chinese. Spain’s Quasar 438B, billed as Europe’s strongest reasoning model, is built on Z.ai’s GLM-5.2. Japan’s Rakuten AI 3.0 uses the DeepSeek-V3 architecture. AI Singapore built its latest regional model on Alibaba’s Qwen rather than Meta’s Llama, and Saudi Arabia’s HUMAIN commissioned its Arabic model from MiniMax. Chinese open-weight models passed the American share of global downloads for the first time in 2025, and on OpenRouter, a marketplace that routes developer traffic to models, their share of usage climbed from under 15 percent to more than half within a year, with businesses in the Global South the heaviest users.

The United States can win this competition, but not just by publishing the most advanced models and declaring victory. It must make American technology the preferred foundation for other countries’ AI systems, as American software and protocols became the foundation of the modern internet. That requires capable models, affordable hardware, financing, training, and dependable support, assembled into an offer that can stand beside a cheaper Chinese full-stack bid.

What America Must Do to Win

Washington should compete throughout hardware, models, software, and services. Retreating to frontier models and advanced chips while China supplies the open models, inexpensive inference, and industrial applications through which most of the world will actually use AI would surrender the contest at the layers where adoption happens.

Openness alone wins nothing. It gives a country seeking local control a reason to consider a model, not a reason to prefer an American one over a Chinese one. The American model must win on performance, total cost, local-language capability, reliable supply, and support, and it must leave room for domestic firms to build businesses around it. Partners deserve honest terms about licenses, updates, and what happens when a supplier relationship ends, and they have reason to ask. When U.S. controls forced Anthropic to suspend access to its newest models from June 12 to June 30, governments learned that even allies can lose access to American systems on a decision made in Washington. Autonomy has to be part of the product, because autonomy is what Beijing is selling.

The model is not hypothetical. An Indian financial firm runs DeepSeek on rented GPUs in India; the weights reside locally, inference never leaves the country, and there is no API for a foreign developer to revoke. Partners want the same from America, with the hardware, financing, and support that make it work. The developers now building on Qwen and DeepSeek show the cost of ceding that ground: expertise accumulates around particular models, models are tuned for particular hardware, and both pull future purchasing with them.

What China Is Doing

Xi’s language of openness should be read alongside that of Chen Yixin, China’s Minister of State Security. Writing in the Cyberspace Administration’s magazine in September, Chen describes AI as a primary battleground of great-power competition. He links political security, espionage, cyber capability, and military transformation to technological independence and control over international governance. An intelligence chief is explaining how AI alters the conditions under which his state exercises power. The two speeches are not in tension. One describes the offer; the other describes the objective.

The institutions Xi announced serve both. A cooperation center with each major regional bloc is a venue where Chinese models, hardware, and standards become the default for an entire region’s developers. A meteorological warning system deployed in 30 countries is a public good that also installs Chinese infrastructure and data flows in 30 capitals; an Egypt-specific version with aviation weather and sandstorm warnings is already in development, while Huawei courts Cairo for its Ascend chips and Malaysia weighs the same hardware. This is the softer sell: adapt the technology to the customer’s existing systems rather than demand reorganization around the supplier, as 01.AI did in building Kazakhstan’s national model. The World Artificial Intelligence Cooperation Organization is a bid to set governance terms in a body Beijing convened, and Xi’s warning against an expansive national security concept is a preemptive argument against the export controls Washington relies on. Washington should engage on international standards, but only where the decision rules leave Beijing no approval power over American development or release, at home or abroad.

Beijing’s openness may not last. Reuters reported in July that Chinese authorities were weighing restrictions on their own frontier models, and the TC260 AI Safety Governance Framework 3.0, released September 14 under CAC guidance, points the same way. Alongside provisions on loss of control and autonomous cyberattacks, its treatment of capability diffusion and removable safeguards suggests China may grow more selective about open releases. If so, its position as the default supplier of capable open models may not endure, and the window for an American alternative is open now.

The Tradeoff America Should Accept

Open models cannot be recalled once distributed. That is their appeal to partners, and it means adversaries will use them. The presumption should nonetheless favor open release. Any exception should identify the capability at issue, the security benefit of withholding it, the cost to American adoption, and whether adversaries can obtain comparable capability elsewhere. With a near-peer challenger offering alternatives, withholding American models may merely divert adoption without diminishing adversary capability. Washington can still restrict advanced chip exports for defined security reasons; a partner’s choice of competing hardware is a reason to improve the offer, not to penalize the partner.

Partner autonomy does not require surrendering American authority over domestic release decisions, export licensing, or the integrity of U.S. networks. It requires accepting that American benefits need not depend on a remote veto over systems partners already operate. Government and military users at home should continue to choose systems, closed or open, on performance and security.

What Washington Should Do

The July 2025 AI Action Plan endorses open-source and open-weight AI, and Executive Order 14320 on exporting the American AI stack supplies a framework for coordinated technology packages, diplomacy, and financing. The task is to convert those commitments into an offer that wins.

Fund what the market will undersupply: sustained open releases, smaller-language capability, independent evaluation, and affordable local deployment. Make the complete package competitive, with financing, predictable hardware access, workforce training, and genuine roles for local firms, and resource it as the national security priority it is. The Export-Import Bank’s $66.1 million guarantee for Côte d’Ivoire’s national data center shows the tools exist; it needs to operate at the scale of China’s regional cooperation centers. Demonstrate the bargain with willing partners through a sovereign AI pilot, potentially building on Pax Silica, that discloses remaining dependencies and compares cost, delivery time, and power requirements against the alternatives. Each regional cooperation center Beijing opens should have an American counterpart that partners can judge on results. Then measure the results: which models partners choose, whose hardware serves them, and who earns the integration revenue. A lost American sale does not always deepen dependence on China, and a won one does not always reduce it.

American leadership will prove most durable when partners have their own reasons to sustain it. The test is what countries choose to build, and whether building with America remains worth it to them.

The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.

Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

Read Entire Article