Issue #146

Same Frontier Model, Different China Sales Rules

OpenAI, Google, and Anthropic draw different lines on serving Chinese firms' overseas units with AI.

SocietySame Frontier Model, Different China Sales Rules

Same Frontier Model, Different China Sales Rules

On July 9, OpenAI unveiled GPT-5.6. It comes in three variants — Sol, Terra, and Luna — and the most powerful of them, Sol, was released only after the US government reviewed its safety first. The reason was that its capabilities were considered too potent for potential use in cyberattacks. Most coverage has focused on benchmark scores and pricing.

But I was drawn to another story that broke the same week: reporting on how Chinese-linked firms are using AI. On July 10, the Financial Times reported that OpenAI and Google had been providing AI services to overseas subsidiaries of Chinese companies that appear on the US Department of Defense’s list.

Pre-release safety review and company-by-company decisions about who gets access are two separate processes. Government regulation applies across the board, but beyond that, how far a company extends its services to other customers comes down to each AI firm’s own policy.

Model Safety Review and Customer Access Policy

Let’s start with how GPT-5.6 was rolled out. OpenAI first deployed the model to a small group of trusted partners at the request of the US government. That’s because Sol, its most powerful capability, far outpaced the previous generation in cyber operations—finding vulnerabilities and writing exploit code. Before the model went public, it went through a rigorous process in which the government reviewed its dangerous capabilities first.

Where companies diverge is in their customer access policies. According to the Financial Times, OpenAI and Google have been supplying AI services to the Singapore subsidiaries of Alibaba, Baidu, and Tencent—all three of which the US government has flagged as companies “linked to the Chinese military.” After the FT’s reporting began, OpenAI disclosed that it had cut off API access for Alibaba-affiliated users last month, citing signs of “distillation.”1

Per the FT, OpenAI said it doesn’t allow access from within China, but does permit use by some Chinese-linked firms in countries where it can apply safeguards and monitor for distillation. The company also stated its position that it’s better for AI reflecting democratic values to be widely used than AI controlled by authoritarian governments. Google said it offers in-policy services in Hong Kong and Singapore, and explained that regional restrictions alone aren’t enough to prevent distillation.

Anthropic applies broader restrictions. Its policy, announced in September 2025, covers not only companies headquartered in unsupported regions like China, but also any overseas entity that such companies own—directly or indirectly—by more than 50%. In other words, the three companies providing frontier models2 each apply different standards for how Chinese-linked overseas entities can use their services.

Why This Gap Exists

America’s export controls don’t apply to every kind of AI use in the same way.

The US has controlled “chips” for a long time. “Models” are a different story. In January 2025, the Biden administration created the AI Diffusion Rule3, which for the first time tried to bring model weights under export control—but the Trump administration rescinded the rule that same May. Chip exports have since actually loosened further: starting in January 2026, some chips bound for China are being approved on a case-by-case basis.

The upshot is that the US currently manages individual models like Fable, Mythos, and GPT-5.6 through government review, but doesn’t broadly prohibit China-headquartered companies from using frontier AI itself—even companies listed on the Department of Defense’s 1260H list4. That list grew to 188 entities in June 2026 when Alibaba and Baidu were added, but being on the list doesn’t mean a company is barred from using American software. Chris McGuire, who handled export controls at the Biden White House, put it to the FT this way: “The administration always says ‘we have to beat China in AI,’ but when it comes to export controls—the actual tool for slowing China down—they’ve done nothing.”

Distillation is one of the central flashpoints in access policy. Distillation means taking the outputs of a strong model and using them to train another model—meaning that a single instance of access can amount to a transfer of capability. Anthropic said earlier this year that Chinese AI labs DeepSeek, Moonshot, and MiniMax had distilled Claude, and it’s been reported that Anthropic recently told Congress it suspects an Alibaba-affiliated entity used roughly 25,000 fake accounts to generate 28.8 million conversations for distillation purposes. This should be understood as Anthropic’s allegation, not established fact. The real issue at stake is the practice of using mass volumes of output to train other models.

In the words of AI policy and security expert Joe Kawam, this amounts to a structure where Chinese labs “systematically extract frontier capability without paying the compute, engineering, and safety costs American companies bore.” The moment you sell API access, you may effectively be exporting capability. Even so, there’s a reason Washington hasn’t clamped down on models as hard as it has on chips. Chips are physical objects that customs can intercept at the border, but a model’s outputs can be received via remote API calls from any number of countries. What’s more, there’s still no consensus on how far to control open-weight5 models, or where to draw the line on free software distribution. Enforcement here requires a different playbook than the one built for physical exports.

Redefining “Sovereign AI”

These days, countries everywhere are talking about “sovereign AI.” France is grooming Mistral as its national champion model, and Saudi Arabia has launched HUMAIN through its sovereign wealth fund, announcing a plan with Nvidia to bring in hundreds of thousands of GPUs over the next five years. The first phase was pitched at a scale of 18,000 units — which doesn’t mean the full announced volume has already been secured. The UK, meanwhile, has stood up a £500 million sovereign AI unit of its own. When people say “sovereign AI,” they usually picture something like this: a country owning its entire stack — chips, data, models — end to end.

What caught my attention in this FT report was something different: the conditions under which countries keep using foreign models. Even as a nation scales up its own compute, if a given workload depends on a specific overseas API, that provider’s access policy has to be examined just as closely.

The problem is that companies don’t agree on what those policies should be. Anthropic treats model access as an “export control” issue. It blocks companies headquartered in China on the basis of nationality, and says it has forfeited hundreds of millions of dollars in revenue as a result. OpenAI sees it differently — as a matter of “values and markets.” It draws the line not by nationality but by whether behavior can be monitored, arguing that spreading AI built on democratic values more widely is the better strategy. Neither position is straightforwardly wrong. What is clear, though, is that in the space governments haven’t regulated, individual companies’ own standards end up carrying enormous weight over what services actually get delivered.

Consider a company that already runs its own data center. It might still rely on a specific foreign model for certain tasks. If that API gets cut off, those particular workflows suffer, and switching to another model isn’t free. That doesn’t mean the company’s own GPUs become useless for every hard problem — but it does mean someone has to map out, concretely, which tasks depend on which supplier.

That’s why I think a real discussion of sovereign AI can’t stop at domestic models and infrastructure. It has to also account for the terms under which foreign models are used, and how replaceable they actually are. The real test is whether critical operations can keep running if access is cut off.

Oswarld’s Lens

There’s one thing I keep confirming as I build GTM strategies. Alongside feature strength, the power to decide “who you sell to, under what conditions” matters just as much. Features can be copied, but distribution channels and access controls are much harder to replicate.

The same dynamic is playing out in frontier AI. Protecting a model’s technical edge and determining which countries benefit from that model both come down to a single decision: who gets API access. Once distillation means that a sale can effectively become a transfer of capability, it’s each company’s trust-and-safety team—enforcing its own terms of service—that ends up policing access restrictions in practice. That’s not the same as holding legal authority the way a government agency would. I think this shift is the real core of this news.

Before taking a side, though, let me lay out the limits of both approaches. Anthropic’s blanket-block model looks clean in principle, but in reality it’s hard to fully enforce because of workaround accounts and overseas subsidiaries, and the revenue losses are substantial. OpenAI’s “sell while monitoring” approach isn’t baseless either—the logic that if you can’t stop it anyway, you’re better off funneling users toward a monitorable channel to catch distillation, actually worked once, with last month’s block on Alibaba. My conclusion is this: in a world where distillation lets you copy capability at low cost, it’s getting harder and harder to defend a nationality-blind access policy—but that doesn’t mean “blocking is automatically the right answer” either. This isn’t just a technical question. It’s also a question of how you set the criteria for restriction and who bears responsibility for enforcing them.

Closing

American companies differ in how they treat AI use by China-linked overseas subsidiaries. It’s worth separating three distinct things: government model reviews, export controls, and companies’ own customer vetting. If you’re on the receiving end of these services, you need to weigh both the possibility that access conditions will change and what alternatives you’d have if they do.

What do you think should matter most when setting access restrictions on AI services? Nationality and ownership structure, actual intended use, or the feasibility of monitoring — I’d love to hear which of these you think deserves the closest scrutiny.


📨 If you know a colleague curious about where AI and geopolitics intersect, please pass this along.


This fragment matches the Korean source accurately in structure, numbers, links, and glossary terms. No corrections needed.

Your take shapes the next issue

What resonated most in this issue, or where has your experience been different?

Any registered reader can comment for free.

References & Further Reading

Primary sources

Background


Illustrated portrait of Kwangseob Ahn (Oswarld)

The author is Oswarld (Kwangseob Ahn). Current roles: Adjunct Professor at Sejong University, Strategy Consultant at INLEVEL9. Career, research, books, and recent work are kept current on the About page. Latest · July 2026: HEMA-2: A Consolidation-Aware Tri-Memory Architecture with Multi-Channel Scheduling for Lifelong Conversational AI.

📝 Glossary

Footnotes

  1. Distillation: A method of training one model by feeding it the mass-collected outputs (answers) of a stronger model as its textbook. It becomes a problem when the outputs are used in violation of licensing terms — though distillation itself is also just a common model-training technique.

  2. Frontier model: The most advanced AI model available at a given point in time. Models like GPT-5.6 and Fable fall into this category.

  3. AI Diffusion Rule: A rule the U.S. attempted to introduce in 2025 that, for the first time, would have brought “model weights” (a model’s core parameters) under export control. The rule was withdrawn just before taking effect. Whether other export controls or sanctions apply must still be checked separately.

  4. 1260H list: An annual list of “Chinese military-linked companies” compiled by the U.S. Department of Defense under Section 1260H of the National Defense Authorization Act. It blocks contracts with the Department of Defense, but does not automatically ban private-sector sales.

  5. Open weight: A model whose core numerical values — its weights — are made public, letting anyone download and run it on their own machine. Once released, it’s effectively impossible to claw back, which makes export control especially tricky.