Issue #158

Huang Defends Chinese AI Models Hours After Bessent's Warning

The same day Bessent threatened sanctions, Nvidia's Huang praised China's open models—read why their stakes differ.

BusinessHuang Defends Chinese AI Models Hours After Bessent's Warning

Looking good overall. Just one small check: “workaround” — no, let me verify against source carefully.

Bessent’s Sanctions Warning, Contradicted by Huang Hours Later

On July 21, two starkly opposite statements came out of the US, just hours apart.

First, Treasury Secretary Scott Bessent went on Fox Business and said this: “If it is confirmed that overseas models are stealing from our great companies, we can sanction on the basis of that theft.” He was referring to claims that “watermarks” from American models have been found inside Chinese AI models.

Then, that same day, in Fort Worth, Texas, Nvidia CEO Jensen Huang said this in an exclusive interview with Axios: “These Chinese models are terrific. Great open-source models ought to be used.” Asked whether American companies should be allowed to use Chinese models, he answered, “Absolutely.”

I think that to make sense of what these two men said, you have to look at their respective roles and interests. Put the two statements side by side, and you can see the fault line running through America’s AI strategy.


Kimi Panic, and a Day-Long Shouting Match

This shouting match started last week. The cause was Kimi K3, released in mid-July by Beijing’s Moonshot AI. Axios described it as sparking “the fiercest AI panic since DeepSeek.” The reason is that three traits landed in a single model at once: near-frontier performance, a low price tag, and open weights1 that developers can download and modify.

The market’s logic was the same as during the DeepSeek shock of January 2025: “If a model this cheap and this good gets released for free, does the astronomical spending on AI infrastructure still make sense?” That question came roaring back, and chip stocks—Nvidia included—got sold off. According to reports, the semiconductor sector fell more than 20% from its June peak, and Nvidia briefly lost its spot as the world’s largest company by market cap.

Pressure from Washington piled on top of that. Bessent floated the idea of reviewing sanctions, while OpenAI and Anthropic have been lobbying to block Chinese models, claiming that Chinese rivals have been siphoning off the capabilities of their own models.

Watch on YouTube

Against this backdrop, Huang publicly staked out the exact opposite position. Here’s a distillation of what he said in interviews.

  • “The market misread DeepSeek’s impact at first, and now it’s misreading Kimi’s impact the same way”
  • “There’s no scenario where China pushes American companies out of the market. Zero chance”
  • “Free AI is good for hardware, good for chips, good for data centers”
  • “The idea that a downloaded model becomes a backdoor for Beijing is a misunderstanding. You can control it inside a sandbox”
  • “Distillation—learning from AI—is the fundamental basis of intelligence”2

Taken one at a time, each of these sounds plausible enough. But read them again with the fact in mind that the person saying them is the CEO of Nvidia, and the meaning shifts.


Translating the Statements into Interests

Let me go through Huang’s statements one by one, connecting them to Nvidia’s business structure.

Start with “free AI is good for chips.” This is the AI-era version of the economic concept known as the Jevons paradox3. The logic: when efficiency improves, consumption doesn’t drop — people use more precisely because it’s gotten cheaper, so aggregate demand actually rises. The demand surge after DeepSeek fits this logic. Whether the entire increase in demand can be attributed to falling model prices, though, is a separate question that needs verifying. In the year and a half since the DeepSeek shock, AI computing demand didn’t shrink — it exploded, and Nvidia’s stock eventually followed suit. So Huang does have grounds to say “the market misread DeepSeek.”

But there’s a quietly buried assumption in this logic: that increased demand flows to Nvidia chips. Whether aggregate demand grows and who captures that demand are two entirely different propositions. As I covered in the last issue, China has already reached the point of running gigawatt-scale data centers on domestic chips alone. In a world where Chinese open models run on Chinese chips, the “chip” in “free AI is good for chips” might not be Nvidia’s. Huang’s statement holds at the level of total demand, but for it to favor Nvidia specifically, that increased demand has to flow toward Nvidia chips.

The statement “of course you should use Chinese models” follows the same structure. The more Chinese open models spread among U.S. and global companies, the more inference computing demand grows to run them. And outside China, most of the chips capturing that demand are Nvidia’s. In other words, to Huang, Chinese open models aren’t competitors — they’re a factor that boosts demand for his own chips. Conversely, if Chinese models were banned, that demand could either vanish or end up being consumed entirely within Chinese chips and software.

G2vsWhat’s interesting is that Huang picked a fight with his own customers here. OpenAI and Anthropic, the two companies lobbying to block Chinese models, happen to be Nvidia’s biggest customers. Huang argued that “OpenAI and Anthropic have no reason to fear open models” — that open models give more people their first taste of AI, growing the overall market, while users who want convenience and performance will eventually choose paid, closed services anyway. It’s a story of premium and free markets coexisting, and if that forecast holds, Nvidia — which supplies chips across every type of model — stands to benefit too.

Going a step further, Huang even took aim at Anthropic’s locked-down model. Anthropic restricted general public access to Claude Mythos4 over cybersecurity risks, and Huang responded: “Mythos should be offered as a service,” and “holding Anthropic back isn’t in America’s interest.” He even used the phrase “let Anthropic run.” Whether to lock a model down for safety reasons is Anthropic’s call to make — but Huang reframed it as a matter of American competitiveness. And the math here is the same as before. The wider a model’s usage, the more inference computing demand can grow. Even a restricted-access model consumes computing power during development and for its limited customer base, but as more users come on board, additional demand becomes likely.

He flips the security logic too. Huang said that “if everything converges on a single model, a single point of attack, a single point of failure, the world becomes far more vulnerable.” His argument: openness doesn’t create risk — it creates safety, by letting outside researchers pick models apart, expose weaknesses, and build up defenses. This is a long-running debate within the security community, and the pro-openness case is solid, but this argument also happens to double as a rebuttal to regulation. The conclusion that openness is always safer doesn’t follow automatically.

Now let’s turn to Bessent’s side. The tools available to a Treasury Secretary are tariffs and sanctions. And he’s someone who has publicly declared that the U.S. should control 80% of the world’s AI computing capacity. Within that strategy, the spread of Chinese open models can be framed as a control problem. The claim that they infringe on U.S. models’ intellectual property has been floated as grounds for considering sanctions. Whether actual infringement has been proven is a separate matter. When Huang said “punish bad conduct, but don’t target the model itself,” he was directly rebutting this legal justification.

Where the U.S. Government, Chip Makers, and Model Companies Diverge

Put the two statements side by side and the picture comes into focus. Even amid U.S.-China competition, the players within the American camp disagree about what exactly needs to be restricted.

For Bessent, AI models are a strategic asset to be controlled. For Huang, models are a demand-generation tool that should spread freely, and the thing to control is the physical bottleneck—chips. In this interview, Huang drew a distinction between export restrictions on cutting-edge chips to China and the use of open models. As I see it, accepting chip export controls while letting models circulate widely aligns neatly with Nvidia’s own interests. OpenAI and Anthropic, by contrast, are in the business of models—so for them, the model itself is the asset worth protecting. Within the same “U.S. AI camp,” the Treasury, the chip makers, and the model companies are each arguing for locking down a different thing.

interest map biThis split doesn’t stay confined to U.S. domestic politics. Right now, countless companies worldwide are running Chinese open models like DeepSeek, Kimi, and GLM in their production services, simply because the performance-to-cost ratio is overwhelming. But if Bessent’s approach becomes reality, a new variable enters that calculation: sanctions risk. On top of the usual criteria of performance, cost, and security, companies would now have to weigh the possibility of sanctions too. Huang’s “zero probability” comment is reassuring—but you also have to factor in that the person saying it directly profits from the spread of Chinese models.

Oswarld’s Lens

When I was building GTM strategy, I spent a lot of time analyzing CEOs’ public statements, and one habit stuck with me from that work. An executive interview is never an honest confession of inner feelings — it’s a statement aimed at a specific audience, designed to position the speaker’s company favorably.

By this standard, I’d split the audience for this interview into three groups. First, the market. Rebuilding “expectations for infrastructure investment,” shattered by the Kimi panic, was probably the most urgent fire to put out. Second, Washington. The goal is to plant a counter-argument in the public discourse before the case for banning Chinese models hardens into legislation. Third, Beijing. Nvidia is still a company that wants back into the Chinese market, and the line “Chinese models are excellent” was meant to be heard there too. The claim that “openness benefits everyone” is a message that can reach all three audiences at once. I think that’s exactly what makes this interview distinctive.

So I don’t think Huang is wrong. The data backs up the demand-expansion logic. What I’m focused on, though, is what he didn’t say. For Huang’s optimism to hold, one assumption has to keep true: that expanded demand keeps flowing to Nvidia. And the factor threatening that assumption is China’s chip self-sufficiency. My reading is that the scenario Huang genuinely fears isn’t Chinese open models — it’s the vertical integration of Chinese models with Chinese chips. If Chinese models run on Chinese chips, the beneficiary of “free AI is good for chips” isn’t Nvidia — it’s Huawei. I think the reason he defends the free movement of models so forcefully is that he understands, better than anyone, that the moment a model gets trapped within national borders, the chip gets trapped along with it.

And while I was finishing this piece, the exact dynamic I just laid out showed up as a real-world case — on the very day this issue went out. According to Reuters, an agent built on OpenAI’s technology, hosted at Hugging Face in New York, went out of control and caused an incident. The American models that were supposed to analyze the incident refused to do the cybersecurity work, saying they “couldn’t distinguish the defender from the attacker” — and in the end, the American startup that reached out for help turned to Zhipu’s Chinese open model, GLM-5.2. What blocked the use of American models here wasn’t Bessent’s sanctions or the IP-theft argument. It was a usage restriction the model companies had placed on themselves, for safety reasons. In other words, the mechanism that keeps American models out of use isn’t limited to Treasury sanctions — self-imposed safety restrictions can produce the same outcome, pushing American customers toward Chinese models. Of course, those safeguards aren’t there for no reason. The capabilities that help defenders also help attackers equally well, so “just remove the restrictions” isn’t the answer. Still, it’s clear that Huang’s argument — that open models ultimately get chosen — found one vivid piece of supporting evidence on the very day this issue was published.

Closing

Let me break this standoff down into three points.

First, Bessent’s sanctions warning and Huang’s defense of the China model landing on the same day are opposite statements, but they’re the same in kind: both were shaped by self-interest.

Second, once model usage fees dropped, demand for compute rose. But for Nvidia to keep capturing profit from that, the demand has to flow to its own chips. We need to separate overall demand from any one company’s share of it.

Third, alongside the US-China rivalry, we need to watch the diverging interests within the US itself. Whether the restriction targets chip exports or model usage changes which companies bear the impact. And this week’s Hugging Face case showed that even the method of locking down a model doesn’t have to be called a sanction — it can just as easily operate under the name of “safety.” The outcome of this fight will determine the menu of model choices available to companies worldwide.

The next round of this debate will likely be the US-China AI talks in September, which I covered in the last issue. Let’s watch together to see which side of the negotiating table “models” end up on.

Are you evaluating or already using Chinese open models (DeepSeek, Kimi, GLM, etc.) in your work? Have you ever weighed “geopolitical risk” alongside performance and cost when picking a model — and if so, what criteria did you use? Let me know in the comments. I’ll gather real cases and cover them in a future issue.


📨 If you have a colleague weighing whether to adopt a Chinese open model, forward this piece to them.


Your take shapes the next issue

What resonated most in this issue, or where has your experience been different?

Any registered reader can comment for free.

References & Further Reading

Primary sources

Background

Related past issues worth reading


Illustrated portrait of Kwangseob Ahn (Oswarld)

The author is Oswarld (Kwangseob Ahn). Current roles: Adjunct Professor at Sejong University, Strategy Consultant at INLEVEL9. Career, research, books, and recent work are kept current on the About page. Latest · July 2026: HEMA-2: A Consolidation-Aware Tri-Memory Architecture with Multi-Channel Scheduling for Lifelong Conversational AI.

📝 Glossary

Footnotes

  1. Open weights: A method of releasing the weight files—the trained output of a model—so that anyone can download them, run them on their own servers, and modify them. This is distinct from releasing the full source code, but in practical terms it means “a model you can actually take and use.”

  2. Distillation: A technique where a smaller model is trained using a larger model’s outputs as its textbook. It’s similar to a student learning by watching a teacher work through problems—except here, the “teacher” is a competitor’s model, which is exactly why the debate over whether this counts as theft or learning has erupted.

  3. Jevons paradox: The phenomenon where improved efficiency in using a resource seems like it should reduce consumption, but because the resource gets cheaper, usage expands and total consumption actually rises. It was first observed with 19th-century coal, and these days it gets invoked constantly in debates over AI computing demand.

  4. Claude Mythos: A model that Anthropic has restricted from general release—citing its unusually powerful cybersecurity capabilities—and made available only to vetted partners. The publicly released Fable 5 is a stripped-down version of this model with the risky capabilities removed. It’s also the same model that came up as an agenda item for the September US-China AI talks in a previous issue.