OpenAI战略未来负责人Dean W. Ball预测特朗普政府将通过对中国开源权重模型制造监管不确定性(而非直接禁令)来引导企业自行退缩。 微软正评估将K3接入Azure并替换部分由OpenAI和Anthropic模型驱动的Copilot功能,潜在推理成本节省可达6亿美元。
中文正文 · AI 翻译
本月评估中国开源权重模型的企业面临一个与基准测试无关的问题:一年后使用这种模型是否仍然简单易行。Moonshot AI 的 Kimi K3 于 7 月 16 日发布,成为迄今为止最大的开源权重模型,仅数天后,它就在华盛顿重新引发了一场已经沉寂一年的政策讨论。
这一结果将影响美国以外的采购决策,因为讨论中的机制——联邦采购规则、出口黑名单、安全咨询——都会通过服务全球大多数地区的同一云服务提供商传播。直接触发因素是一篇帖子:https://x.com/deanwball/status/2078133895766114412,由 OpenAI 战略未来负责人 Dean W. Ball 发布,他此前曾是特朗普白宫的高级 AI 顾问。
商业动机并不意味着安全问题是假的,而其最严肃的版本值得指出。开源权重无法撤回。一旦模型被下载并在成千上万个组织中运行,没有任何供应商可以对其进行修补、撤销或推送修复,这与托管 API 的风险模型有实质性的不同。模型行为比模型代码更难审计:微调可能带有偏见或失败模式,而任何许可证检查都无法揭示这些问题。
反对意见关注的是比例原则,而不是完全否定。乔治城大学研究员 Sam Bresnick 认为,暂停向中国销售 Nvidia H200,将比禁止美国人希望使用的开放模型对北京的影响大得多,其目标是输入而非输出。Ball 自己在第二条观察中也承认了这一点,将中国的开放权重策略部分归因于国内缺乏用于服务客户的计算能力,这使其在最初是美国出口管制的无意后果。
Axios:https://www.axios.com/2026/07/20/ai-us-china-open-source-kimi 于7月20日报道,援引接近政府人士称,商务部去年曾考虑将中国 AI 实验室列入实体清单,国家安全局(NSA)和国家网络主任办公室考虑发布关于中国 AI 实验室威胁的咨询,白宫曾考虑一项行政命令,使美国公司在使用中国模型时若发生数据泄露需承担责任。担心扼杀创新的官员最终否决了所有这些计划。
查看更多信息:Kimi K3 开放权重模型:中国最大的 AI 是对内存而非计算的赌注:https://www.artificialintelligence-news.com/news/kimi-k3-open-weight-model-memory-compute-china/
想了解更多来自行业领导者的 AI 和大数据信息吗?请查看 AI & Big Data Expo:https://www.ai-expo.net/?utm_source=AI-News&utm_medium=Footer-banner&utm_campaign=world-series,该活动将在阿姆斯特丹、加利福尼亚和伦敦举行。该综合性活动是 TechEx 的一部分:https://techexevent.com/?utm_source=AI-News&utm_medium=Footer-banner&utm_campaign=world-series,并与其他领先的技术活动共同举办,包括 Cyber Security & Cloud Expo:https://cybersecuritycloudexpo.com/?utm_source=CloudTech-News&utm_medium=Footer-banner&utm_campaign=world-series。更多信息请点击这里:https://techexevent.com/?utm_source=AI-News&utm_medium=Footer-banner&utm_campaign=world-series。
AI 新闻由 TechForge Media 提供:https://techforge.pub/?utm_source=AI-News&utm_medium=Footer-banner&utm_campaign=world-series。 在此探索其他即将到来的企业技术活动和网络研讨会:https://techforge.pub/events/?utm_source=AI-News&utm_medium=Footer-banner&utm_campaign=world-series。
AI 商业策略:https://www.artificialintelligence-news.com/categories/inside-ai/ai-business-strategy/,人工智能:https://www.artificialintelligence-news.com/categories/artificial-intelligence/,专题:https://www.artificialintelligence-news.com/categories/features/,金融 AI:https://www.artificialintelligence-news.com/categories/ai-in-action/finance-ai/,工作世界:https://www.artificialintelligence-news.com/categories/ai-and-us/world-of-work/
AI 应用:https://www.artificialintelligence-news.com/categories/ai-in-action/
将我们所有的优质内容和最新技术新闻直接发送到您的邮箱
AI 新闻是 TechForge 的一部分:https://techforge.pub/
Enterprises evaluating Chinese open-weight models this month face a question that has nothing to do with benchmarks: whether using one will still be straightforward in a year. Moonshot AI’s Kimi K3 arrived on July 16 as the largest open-weight model yet released, and within days it had reopened a policy argument in Washington that had been dormant for a year.
The outcome will affect procurement decisions well outside the United States, because the mechanisms under discussion–federal procurement rules, export blacklists, security advisories–travel through the same cloud providers that serve most of the world. The immediate trigger was a post:https://x.com/deanwball/status/2078133895766114412 by Dean W. Ball, OpenAI’s head of strategic futures and until recently a senior AI adviser in the Trump White House.
His assessment of the model was largely positive: a very good model, he wrote, whose performance he did not think could be explained away by distillation. He also observed that it seemed “very token hungry,” and that it was not obvious to him that it is actually cheap to run, a useful caution, given K3 launches with maximum reasoning effort as its only setting and bills output at $15 per million tokens.
Then he predicted that the Trump administration would eventually decide its best strategy was to create regulatory risk around Chinese open-weight models. Not a ban, which he called one of the dumber motifs in AI policy, but soft guidance from agencies suggesting such models may contain backdoors. “It needn’t be that well justified,” he wrote. Enough uncertainty, and regulated enterprises retreat on their own.
The reaction was fierce, and it came from Americans rather than from Beijing. David Sacks, co-chair of the President’s Council of Advisors on Science and Technology, said he could not tell whether Ball was confessing to a regulatory capture strategy or predicting one, and that either way, weaponising regulatory uncertainty as a competitive tool should be unacceptable.
He added that the leading closed labs, already a duopoly in model revenue, want the government to remove their open-source competition. Yann LeCun and Martin Casado argued that open and proprietary development can coexist. Ball later clarified that he had been forecasting rather than recommending, and walked back the claim that open weights necessarily slow the field down.
Underneath the personalities is an arithmetic problem. Closed labs need revenue per token to justify the capital they are raising for data centres, and cheaper open-weight models compress that revenue without reducing how much AI gets used, the point Snorkel AI co-founder Braden Hancock put to TechCrunch:https://techcrunch.com/2026/07/20/openai-is-scared-of-open-weight-models-should-the-us-be/ . The routing data already shows the shift: open-weight models handled 29% of tokens through Vercel’s production gateway in June, up from roughly a ninth in April, while accounting for under 4% of spending.
That pressure is arriving from inside the American stack. GitHub made Moonshot’s Kimi K2.7 Code generally available:https://github.blog/changelog/2026-07-01-kimi-k2-7-is-now-available-in-github-copilot/in the Copilot model picker on July 1, hosted on Microsoft Azure. The Information reports Microsoft is now adding K3 to Azure and evaluating whether it can run Copilot features currently handled by OpenAI and Anthropic models, with potential inference savings of up to $600 million.
Microsoft has confirmed neither the figure nor which features. It is an evaluation, not a deployment, but it is the largest customer of both American frontier labs, pricing the alternative.
Commercial motive does not make the security concern fake, and the strongest version of it deserves stating. Open weights cannot be recalled. Once a model is downloaded and running inside thousands of organisations, no vendor can patch it, revoke it, or push a fix, which is a materially different risk profile from a hosted API. Model behaviour is harder to audit than model code: a fine-tune can carry biases or failure modes that no licence inspection would reveal.
NIST has previously found:https://www.nist.gov/news-events/news/2025/09/caisi-evaluation-deepseek-ai-models-finds-shortcomings-and-risks security vulnerabilities in DeepSeek’s open models, and for regulated industries, questions about training data provenance and content handling are live regardless of where a model was built.
The counterargument is about proportionality rather than dismissal. Georgetown research fellow Sam Bresnick has argued that halting Nvidia H200 sales to China would slow Beijing considerably more than banning open models Americans want to use, targeting the input rather than the output. And Ball himself conceded a version of this in his second observation, attributing China’s open-weight strategy partly to a lack of domestic compute for serving customers, which would make it an unintended byproduct of US export controls in the first place.
Axios:https://www.axios.com/2026/07/20/ai-us-china-open-source-kimi reported on July 20, citing people close to the administration, that Commerce last year weighed adding Chinese AI labs to the Entity List, that the NSA and the Office of the National Cyber Director considered issuing an advisory on Chinese AI lab threats, and that the White House considered an executive order making US companies liable for breaches if they used Chinese models. Officials concerned about stifling innovation killed all of it.
With adviser Sriram Krishnan gone and security hawks louder, the effort has revived, but the described approach is procurement rules, Entity List threats and public pressure rather than prohibition. “What’s actually happening is slower and more durable,” one source told Axios . Neither the White House nor Commerce responded to Axios’s requests for comment, and Politico reports Commerce will not move imminently.
For buyers outside the US, the exposure is indirect but real. A rule written for American regulated industries and federal procurement does not bind a Malaysian bank or an Indonesian telco. The hyperscalers are the transmission line.
Most enterprises in this region reach Kimi K3 through Azure, AWS or Google Cloud rather than Moonshot’s own API, and if Washington makes hosting Chinese open-weight models uncomfortable enough for those providers, the model quietly leaves the catalogue in Kuala Lumpur at the same time it leaves it in Virginia.
Ball anticipated this in his own post, noting that regulators would not want to push so hard that hyperscalers stop serving Chinese models altogether, since that would only drive startups toward less reputable providers. The obvious hedge is to hold your own copy. Moonshot publishes K3’s weights on July 27, and from that point the model cannot be withdrawn from anyone who has downloaded it.
But as covered previously, K3 is a difficult model to self-host: Moonshot recommends serving it across 64 or more accelerators, and the weights alone come to roughly 1.4TB. For most companies, the fallback is theoretical.
That leaves a narrower question than the headlines imply. Not whether Chinese open-weight models are safe or permitted, but whether the specific model you build on will still be in your cloud provider’s catalogue in twelve months, and what it would cost you to move if it isn’t. That is a due-diligence question, and it is answerable today.
See more: Kimi K3 open-weight model: China’s biggest AI is a bet on memory, not compute:https://www.artificialintelligence-news.com/news/kimi-k3-open-weight-model-memory-compute-china/
Want to learn more about AI and big data from industry leaders? Check out AI & Big Data Expo:https://www.ai-expo.net/?utm_source=AI-News&utm_medium=Footer-banner&utm_campaign=world-series taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx:https://techexevent.com/?utm_source=AI-News&utm_medium=Footer-banner&utm_campaign=world-series and is co-located with other leading technology events including the Cyber Security & Cloud Expo:https://cybersecuritycloudexpo.com/?utm_source=CloudTech-News&utm_medium=Footer-banner&utm_campaign=world-series. Click here:https://techexevent.com/?utm_source=AI-News&utm_medium=Footer-banner&utm_campaign=world-series for more information.
AI News is powered by TechForge Media:https://techforge.pub/?utm_source=AI-News&utm_medium=Footer-banner&utm_campaign=world-series. Explore other upcoming enterprise technology events and webinars here:https://techforge.pub/events/?utm_source=AI-News&utm_medium=Footer-banner&utm_campaign=world-series.
AI Business Strategy:https://www.artificialintelligence-news.com/categories/inside-ai/ai-business-strategy/, Artificial Intelligence:https://www.artificialintelligence-news.com/categories/artificial-intelligence/, Features:https://www.artificialintelligence-news.com/categories/features/, Finance AI:https://www.artificialintelligence-news.com/categories/ai-in-action/finance-ai/, World of Work:https://www.artificialintelligence-news.com/categories/ai-and-us/world-of-work/