China remains undecided on whether to curb open-weight AI models after Xi Jinping used a July 17 speech at Shanghai’s World AI Conference to endorse both “open source and openness, cooperation and sharing” and the need to “strengthen risk awareness, and ensure security and controllability.” Graham Webster argues this pairing is an unresolved tension rather than a blessing for the country’s open-weight labs. Three AI experts in our Who’s Who directory shared the piece.
Open-weight AI models: unresolved threshold
Xi’s approach echoes an older formulation from 2014: “development is the foundation of security, and security is a precondition of development.” China’s current generative AI regulation similarly instructs the state to “maintain equal emphasis on development and security.” Webster’s reading is that Beijing has not yet decided where the security threshold sits for models such as DeepSeek V4, GLM 5.2, Kimi K3, and Alibaba’s Qwen line, which he places roughly six months behind U.S. frontier systems.
Four triggers that could shift policy
Webster walks through four hypothetical triggers that could push Chinese authorities to tighten controls. First, he regards political dissent as unlikely to be the trigger because, in his words, “getting online in China and communicating over the platforms that reach large numbers of Chinese citizens entails multiple layers of identity verification and surveillance.”
Second, cyber risk is active but bounded: a U.S.-U.K. analysis found that Kimi K3’s “safeguards did not prevent it from attempting cyber exploit development or offensive cyber operations,” though Webster notes Chinese models currently trail their U.S. counterparts in capability.
Third, a biological or chemical proof of concept could move policy quickly — “hopefully in a lab and not in the wild,” he writes.
Fourth, Beijing may prefer to be a fast follower, expecting Chinese officials can “see what kind of trouble awaits and swerve before they get there.”
Webster closes with a caution for outside observers: betting on an imminent Chinese crackdown, he argues, “may say more about the observer than about Beijing.”

