As the capabilities and adoption of Chinese open-weight AI models continue their ascent, the discourse surrounding their implications has once again reached a critical juncture.
Whispers of a potential ban by the Trump administration circulate, though no official action has yet materialized. Concurrently, developers of proprietary models, notably OpenAI and Anthropic, are expressing growing apprehension regarding these advancements.
Open-weight models, such as Moonshot AI’s Kimi K3 or Alibaba’s Qwen, deliver inference at a significantly lower token cost compared to the closed-source offerings from major U.S. laboratories. This cost efficiency, however, fuels concerns that they may pose other threats, particularly to the profit margins of established proprietary AI firms.
But should enterprises deploying these models within their own data centers succumb to fears that they could serve as a conduit for Chinese cyberattacks?
“No,” asserts Lucas Atkins, CTO of Arcee, a company actively developing open models to provide U.S. businesses with a homegrown alternative to Chinese solutions.
While Arcee stands to gain from any restriction on Chinese models, Atkins contends that China’s open models pose no greater risk than any other open-source software a company might utilize. In fact, he highlights their inherent benefits, even for his own organization.
“A lot of people view this as similar to a Chinese software program. Like, it was coded with these x, y, z intentions” that a malicious actor could simply command, he explained.
Atkins clarified, “That is fundamentally not how these models are trained. There is really not any way for an Arcee, or an Alibaba, to make a model, have someone run it in their own environment and for us have any access to it whatsoever.”
While most of these models are categorized as “open weight” rather than fully open-source software, their source code—the executable component—is largely visible and reviewable when downloaded from platforms like Hugging Face. The proprietary aspects typically encompass the training methodologies and datasets.
Large organizations are advised to subject any model's core components to their established security testing and inspection protocols. They also frequently fine-tune these models for specific applications, thus working with, optimizing, and thoroughly understanding them before user prompts are introduced.
Could a model designed for coding potentially inject malicious backdoors into the code it generates? While theoretically possible, achieving such a feat would demand extraordinary technical dexterity.
“There’s no reason that a sophisticated enough actor couldn’t train a model to be a completely amazing coding model in every circumstance, but when presented with a certain type of code base … some hidden training would kick in,” postulated Atkins, whose daily work involves model training. Yet, he immediately added, “I don’t know how you would do this.”
Given the inherently creative nature of large language models, the probability of a contemporary model generating malware in response to a meticulously planned, perfect storm of context and prompt is exceedingly low. Even more improbable is the scenario where an enterprise would then implement such code.
Could such an event transpire in the future? That remains speculative. However, enterprises are increasingly designing their AI applications to be model-agnostic, enabling them to leverage multiple models. This approach ensures that even if Chinese models offer the best value today, companies will not be permanently tied to them.
“I think instead of the conversation being about how to ban Chinese models, it should be about how do we foster a good, open ecosystem here in the U.S.,” Atkins advocates.
Arcee itself derives advantages from Chinese open models. Atkins explains that the startup “benefits from those models being good because we can learn what they did. We can build on top of them. Then they can learn what we do.” He further expresses, “We have tremendous respect for the people building those models, the individual researchers.”
Ultimately, Atkins concludes that the most effective strategy to compete with Chinese models “is to release a model that is better.” He adds, “We need to give them something to talk about.”
The Editorial Staff at AIChief is a team of professional content writers with extensive experience in AI and marketing. Founded in 2025, AIChief has quickly grown into the largest free AI resource hub in the industry.
