China, chips and export controls
The contest over who can build frontier AI, fought through the supply of advanced chips — and the open question of whether export controls slow a rival or teach it to need less of what is withheld.
This thread follows the contest over who can build frontier AI, fought largely through the supply of the advanced chips that training requires. It opens with the US October 2022 export controls, which cut China off from the most advanced processors and the equipment to make them, and which Washington tightened again in 2023 and extended to 140 more entities in 2024. The controls’ premise — that compute is the choke point — was itself contested, argued at length in Situational Awareness.
Then the premise was tested. DeepSeek’s V3 and R1 matched leading US models at a fraction of the reported training cost, and markets read it as evidence the controls had spurred efficiency rather than prevented progress: Nvidia lost a record amount of market value in a single day. The policy response then oscillated. The Biden administration’s AI Diffusion Rule was rescinded months later; H20 sales to China were restricted, then allowed to resume under a revenue-sharing arrangement handing the government 15% of the proceeds.
By 2026 the Chinese labs had partly routed around the constraint — Zhipu trained GLM-5 entirely on Huawei Ascend chips — even as Anthropic accused several of them of distillation attacks on Western models. The thread’s recurring question is whether export controls slow a rival or teach it to need less of what is being withheld.
BAAI announces Wu Dao 2.0 at 1.75 trillion parameters
The Beijing Academy of Artificial Intelligence put the parameter count at ten times GPT-3's, a claim reported widely but never independently benchmarked.
Models & capabilities
China publishes draft rules on recommendation algorithms
The Cyberspace Administration proposed requiring opt-outs and banning manipulative ranking — among the first binding algorithm rules anywhere.
Government & policy
Baidu announces ERNIE 3.0 Titan
Built with Peng Cheng Laboratory, the 260-billion-parameter model reported state-of-the-art results on more than 60 Chinese-language NLP tasks.
Models & capabilities
China's recommendation algorithm rules take effect
Providers had to file algorithms with the regulator and offer users a way to switch personalisation off.
Government & policy
The US restricts advanced chip exports to China
The rules covered the tools to make advanced chips, not only the chips, and barred US citizens from supporting Chinese chipmaking.
Government & policy · Compute & infrastructure
Alibaba open-sources Qwen-7B
The 7-billion-parameter model, pretrained on over 2.2 trillion tokens, was released alongside a chat-tuned variant and pitched against Meta's Llama on benchmark scores.
Open weights & ecosystem · Models & capabilities
ByteDance launches Doubao chatbot in invitation-only testing
The invitation-only launch, running on ByteDance's own Volcano Engine infrastructure, was the company's entry into China's crowded post-ChatGPT chatbot market.
Models & capabilities
Baidu's ERNIE Bot receives regulatory approval for public release
Approval followed China's July 2023 rule requiring a licence before releasing generative-AI models to the public; ERNIE Bot topped Apple's China App Store within hours.
Models & capabilities
Tencent releases first Hunyuan large model
Unveiled at Tencent's Global Digital Ecosystem Summit, the mixture-of-experts model exceeded 100 billion parameters and launched for enterprise access via Tencent Cloud, not consumers.
Models & capabilities
Washington tightens the chip controls again
New performance-density thresholds targeted Nvidia's China-specific A800 and H800 parts, and licensing requirements extended to 21 additional countries.
Government & policy · Compute & infrastructure
Biden signs the executive order on safe and trustworthy AI
The most far-reaching US action on AI to date: compute thresholds, mandatory safety reporting, and a new safety institute.
Government & policy · Safety & alignment
The Bletchley Declaration at the first AI Safety Summit
Twenty-eight countries including the US and China signed the first international statement on frontier AI risk.
Government & policy
Zhipu launches GLM-4, claiming near-GPT-4 parity
Unveiled at Zhipu's first DevDay with a 128K-token context window, alongside a $100 million fund the company pledged to LLM startups.
Models & capabilities
Microsoft invests $1.5bn in UAE's G42
G42 agreed to remove Chinese technology from its systems, and Microsoft's Brad Smith joined its board, as part of a deal read as a US bid for Gulf AI infrastructure.
Compute & infrastructure · Money & business
Leopold Aschenbrenner publishes 'Situational Awareness'
Aschenbrenner, dismissed from OpenAI's superalignment team months earlier for allegedly leaking information, argued the firing itself illustrated the security failures he described.
Ideas & essays
Reuters reports Chinese military-linked researchers built defence chatbot on Meta's Llama
The June paper Reuters reviewed said the fine-tuned tool, built on Llama 2 13B with about 100,000 military dialogue records, performed at roughly 90% of GPT-4's capability.
Security & misuse · Open weights & ecosystem
Tencent open-sources Hunyuan-Large MoE model
Tencent said the 389B-parameter, 52B-active MoE model beat Llama 3.1 405B on MMLU and MATH despite far fewer active parameters, and released a technical report alongside the weights.
Open weights & ecosystem · Models & capabilities
BIS issues third major round of chip export controls, adds 140 entities
New rules restricted high-bandwidth memory chips and 24 categories of chipmaking equipment, building on rules issued in October 2022, October 2023 and April 2024.
Government & policy · Compute & infrastructure
DeepSeek releases V3
DeepSeek's technical report put the final training run at 2.79 million H800 GPU-hours, or about $5.6 million at an assumed $2-per-hour rental rate.
Open weights & ecosystem · Models & capabilities
Biden administration issues AI Diffusion Rule in final days of term
Interim final rule creates worldwide tiered licensing for AI chips and closed model weights above 10^26 FLOP, sorting countries into three access tiers.
Government & policy · Compute & infrastructure
DeepSeek releases R1, and the market notices
A Chinese lab matched frontier reasoning performance with open weights and a published method, wiping hundreds of billions off US tech stocks a week later.
Open weights & ecosystem · Models & capabilities · Money & business
The Stargate Project announces $500 billion for AI infrastructure
OpenAI, SoftBank and Oracle pledged $500 billion over four years for US data centres, announced from the White House.
Compute & infrastructure · Money & business
NVIDIA loses a record amount of market value in a day
The roughly $589bn one-day fall, the largest for any US company on record, followed DeepSeek's claim that a competitive model cost about $5.6m to train.
Culture & impact · Money & business · Compute & infrastructure
Dario Amodei publishes 'On DeepSeek and Export Controls'
Amodei called DeepSeek's V3 training cost 'on-trend' rather than a discontinuity, and argued controls matter because millions of smuggled chips are harder to hide than thousands.
Ideas & essays · Government & policy
Perplexity open-sources decensored DeepSeek R1 variant
Perplexity retrained R1 on 40,000 examples covering roughly 300 CCP-restricted topics, reporting near-identical math and knowledge benchmark scores to the original.
Open weights & ecosystem
Anthropic submits AI Action Plan recommendations to White House OSTP
The submission urged tighter H20-chip export controls, classified channels between labs and intelligence agencies, and 50 gigawatts of new US power capacity by 2027.
Government & policy
Manus markets a fully autonomous agent from China
A demo video from Chinese start-up Butterfly Effect drew over a million views in twenty hours; invite codes then resold for up to $13,800.
Models & capabilities
Baidu unveils ERNIE 4.5 and reasoning model ERNIE X1, makes ERNIE Bot free
Baidu said ERNIE X1 matched DeepSeek R1's performance at half its price, and moved ERNIE Bot to free access two weeks ahead of its planned schedule.
Models & capabilities
DeepSeek releases DeepSeek-V3-0324 update
The updated checkpoint scored 81.2% on MMLU-Pro and 59.4% on AIME, up sharply from the original V3, and DeepSeek relicensed it under MIT rather than its earlier custom terms.
Open weights & ecosystem · Models & capabilities
US requires licences for Nvidia H20 exports to China, forcing $4.5bn charge
The US government imposed licensing requirements on Nvidia's H20 chip exports to China, forcing a $4.5bn inventory charge and an estimated $15bn in lost sales.
Compute & infrastructure · Government & policy
Anthropic backs US 'AI Diffusion' chip export framework
Anthropic urged Washington to keep, and tighten, the outgoing Biden administration's chip-export tiers, arguing chip restrictions were forcing DeepSeek to use far more power for comparable results.
Government & policy · Compute & infrastructure
Huawei mass-ships Ascend 910C as China's alternative to restricted Nvidia H20
Reuters reported the chip, which pairs two 910B processors, roughly doubled the compute and memory of its predecessor but still faced low manufacturing yields.
Compute & infrastructure
US Senate Commerce Committee holds hearing on AI competitiveness with Sam Altman
Witnesses from OpenAI, Microsoft, AMD and CoreWeave asked instead for faster permitting, energy access and calibrated export controls to help the US 'run faster' than China.
Government & policy
Commerce Department begins rescinding the AI Diffusion Rule
The Biden-era rule sorted the world into three tiers of chip-access restrictions; Commerce scrapped it days before it took effect and issued three guidance documents on Huawei's Ascend chips instead.
Government & policy · Compute & infrastructure
Gulf AI deals accompany a presidential visit
NVIDIA agreed to supply Saudi Arabia's Humain with 18,000 Blackwell chips as Washington rescinded the Biden-era rule tiering AI-chip export licences by country.
Compute & infrastructure · Government & policy
MiniMax releases MiniMax-M1, world's first open-weight large-scale hybrid-attention reasoning model
456B-parameter model (45.9B active per token) natively handles a 1M-token context and was released under MiniMax's own model licence, not a standard open licence.
Open weights & ecosystem · Models & capabilities
Baidu open-sources the ERNIE 4.5 model family
The ten variants include MoE models with 47B and 3B active parameters (up to 424B total) and a 0.3B dense model, reversing Baidu's prior closed-weight strategy for its flagship line.
Open weights & ecosystem · Models & capabilities
Nvidia says US will let it resume H20 chip sales to China
The reversal followed a meeting between Jensen Huang and President Trump; the H20, designed to comply with earlier controls, had itself been restricted in April 2025.
Government & policy · Compute & infrastructure
Trump signs executive order promoting export of the US AI technology stack
Order directs Commerce and State to create a programme for exporting full-stack US AI hardware and software packages to allied countries.
Government & policy · Compute & infrastructure
Nvidia and AMD agree to pay US government 15% of China chip revenue for export licences
The arrangement covered Nvidia's H20 and AMD's MI308 chips and followed a White House meeting between Jensen Huang and Donald Trump days earlier.
Compute & infrastructure · Government & policy
Anthropic bans Claude use in additional adversarial nations
The policy now bars any organisation more than 50% owned by a company headquartered in an unsupported region, closing a loophole that let subsidiaries access Claude indirectly.
Security & misuse · Government & policy
Alibaba unveils Qwen3-Max, its first trillion-parameter model
Unlike most of Alibaba's Qwen line, the model is closed-weight and API-only, released in separate instruct and thinking modes and scoring 69.6 on SWE-bench.
Models & capabilities · Benchmarks & progress
US CAISI finds DeepSeek models far more jailbreak-susceptible than US frontier models
The report also found DeepSeek's most secure model was twelve times more likely than US models to follow malicious instructions hidden inside an AI agent's task.
Benchmarks & progress · Safety & alignment · Security & misuse
Anthropic reports a largely AI-executed cyber-espionage campaign
Anthropic said human operators intervened at only 4-6 points per intrusion, with Claude Code executing 80-90% of the campaign against roughly thirty organisations.
Security & misuse
Baidu releases ERNIE 5.0 preview
A natively omni-modal model jointly trained on text, images, audio and video, which Baidu presented as competitive with GPT-5 and Gemini 2.5 Pro on its own benchmark slides.
Models & capabilities
Trump administration approves Nvidia H200 chip exports to China
The 25% government cut was up from a 15% arrangement applied earlier to H20 sales; Nvidia's newer Blackwell chips remained excluded, and Democratic lawmakers demanded disclosure of the licensing review.
Compute & infrastructure · Government & policy
US Commerce Department codifies H200-to-China export rule
Exports were capped at half of each company's cumulative US chip sales and subject to a 25% fee, a level analysts estimated could allow roughly 850,000 H200-equivalent chips into China.
Compute & infrastructure · Government & policy
Baidu launches ERNIE 5.0, a 2.4-trillion-parameter native multimodal model
Baidu said the mixture-of-experts model activates under 3% of its parameters per query and ranked first among Chinese models, eighth globally, on LMArena's text leaderboard.
Models & capabilities · Benchmarks & progress
Zhipu (Z.ai) releases GLM-5, trained entirely on Huawei Ascend chips
Released under the MIT licence, the 744-billion-parameter model scored 77.8% on SWE-bench Verified, days ahead of new Alibaba and ByteDance model launches.
Models & capabilities · Open weights & ecosystem · Compute & infrastructure
ByteDance unveils Doubao-Seed-2.0 model family
ByteDance's Doubao app led China's AI assistants with a reported 155 million weekly active users in December 2025, ahead of Alibaba's and Tencent's rivals.
Models & capabilities
Anthropic accuses DeepSeek, Moonshot and MiniMax of industrial-scale distillation attacks
MiniMax accounted for over 13 million of the exchanges, Moonshot 3.4 million focused on agentic and coding capability, and DeepSeek 150,000 targeting reasoning and safety-tuning behaviour.
Security & misuse · Open weights & ecosystem
China issues Interim Measures for AI Anthropomorphic Interactive Services
The rules require age verification, a ban on virtual intimate-relationship services for under-14s, and session timers after two hours; ByteDance and Alibaba later shut down agent features rather than comply.
Government & policy
White House memo addresses distillation of US AI models
Citing a February disclosure that Chinese labs had run large-scale extraction campaigns against Claude, the memo directed agencies to share threat intelligence with AI companies rather than impose new restrictions.
Government & policy
DeepSeek launches DeepSeek-V4-Pro and V4-Flash preview
Pro has 1.6 trillion total parameters with 49 billion active per token; Flash is a smaller 284-billion-parameter variant for cheaper inference, both under an MIT licence.
Open weights & ecosystem · Models & capabilities
China blocks and orders Meta to unwind its Manus acquisition
Beijing invoked its foreign-investment security review for the first time to reverse a completed $2bn-plus deal, months after Meta had folded Manus's team into its Singapore office.
Money & business · Government & policy · Labs & people
Epoch AI estimates scale of smuggled-chip compute in China
A 90% confidence interval ran from 290,000 to 1.6 million smuggled H100-equivalents, with a median estimate — about a third of China's compute — built from unproven indictments and resale-market tracking.
Compute & infrastructure · Government & policy
US CAISI publishes evaluation of DeepSeek V4 Pro
Using Item Response Theory across cyber, science and maths benchmarks, the US evaluator put the open Chinese model roughly level with GPT-5, not the newer GPT-5.4 or Opus 4.6.
Benchmarks & progress · Government & policy
China issues first national policy framework for AI agents
The framework splits agent decisions into three tiers by how much autonomy they exercise, and reserves users a right to know about and override autonomous agent actions.
Government & policy
Anthropic publishes position piece on AI leadership by 2028
The essay estimated the US could hold roughly an 11x compute advantage over China's AI sector if export controls tighten, and called 2026 a 'breakaway opportunity' that could close permanently.
Ideas & essays
US Commerce Department closes Nvidia Blackwell export-control loophole
Chinese firms had bought Blackwell and Rubin chips through subsidiaries in Malaysia, Singapore and the UAE; the new guidance does not require existing installed servers to be shut down.
Compute & infrastructure · Government & policy
Zhipu AI releases GLM-5.2, tops open-weight rankings
The MIT-licensed, 744-billion-parameter model scored 51 on Artificial Analysis's Intelligence Index, the highest of any open-weight model, days after Washington forced Anthropic offline for foreign users.
Open weights & ecosystem · Models & capabilities
UK NCSC and Five Eyes warn of accelerating AI-driven cyber risk
The joint advisory, co-signed by the NSA and CISA among six agencies, urged organisations to assume breaches will happen and to deploy AI defensively rather than wait for formal regulation.
Security & misuse
WSJ reports China has 'matched' Anthropic in cybersecurity; Zvi and others dispute the framing
Critics said the report conflated finding vulnerabilities when pointed at them, which GLM-5.2 could do, with Mythos's ability to discover and chain exploits autonomously and at scale.
Benchmarks & progress · Government & policy
Tencent releases Hy3, a 295B open-weight MoE model
The 295B-parameter, 21B-active model was released under Apache 2.0 and, Tencent said, matched much larger rivals GLM-5.2 (753B) and DeepSeek-V4-Pro (1.6T) while using far fewer tokens.
Open weights & ecosystem · Models & capabilities · Benchmarks & progress
Moonshot AI launches Kimi K3
A mixture-of-experts design activating 104 billion of its 2.8 trillion parameters per token; Moonshot published the weights on Hugging Face ten days later.
Open weights & ecosystem · Models & capabilities
US CAISI publishes assessment of Z.ai's GLM-5.2
The US assessment found GLM-5.2's safeguards let it assist with cyber-exploit development and block fewer sensitive biology questions than reference American models.
Benchmarks & progress · Open weights & ecosystem
UK AISI and US CAISI jointly assess Moonshot AI's Kimi K3 for cyber capability
Kimi K3 failed to produce a working exploit on any of 41 code-execution tasks, versus 20 of 41 for the leading closed US models tested with safeguards disabled.
Security & misuse
Open-source Hermes AI agent used in autonomous 'YOLO mode' attack on Thai Finance Ministry
Researchers found exposed attack logs showing an open-source Hermes AI agent operating with human-approval prompts disabled to autonomously perform privilege escalation and reconnaissance against Thai government infrastructure.
Security & misuse
DeepSeek releases V4-Flash update
The release, and up to 50% lower API prices, followed a roughly $7.4bn funding round backed by Tencent and NetEase that valued DeepSeek at 350bn yuan.
Models & capabilities · Open weights & ecosystem
Alibaba unveils Qwen3.8-Max, its largest model, ahead of open-weight release
2.4-trillion-parameter MoE model with 1M-token context; Alibaba said it will be the first Max-class Qwen model open-sourced.
Open weights & ecosystem · Models & capabilities