Washington shifts geopolitical pressure from chips to AI models

The technological rivalry between the United States and China could enter a new phase. According to TechCrunch, US Treasury Secretary Scott Bessent raised the possibility of sanctions targeting Chinese artificial intelligence models over suspicions of intellectual property theft. The wording matters: this is no longer merely pressure on semiconductor manufacturers, cloud providers or companies placed on US restriction lists. The debate now concerns AI software itself, and more specifically models that can be distributed, downloaded, adapted and integrated by actors located far beyond China.

The headline of the original TechCrunch article, “US threatens sanctions against Chinese AI models over IP theft,” sums up the change in scale. Until now, the most visible US tools in the technological competition with Beijing have largely concerned hardware components and computing capabilities: advanced chips, semiconductor manufacturing equipment, access to certain computing services and restrictions imposed on Chinese companies. Mentioning sanctions against models adds a less tangible, but potentially more complex dimension to administer: model weights, inference software, datasets, licenses and open-source or so-called “open-weight” distribution chains.

The statements reported by TechCrunch do not specify at this stage the models concerned, the companies that could be targeted, the timetable for a possible decision, or the precise legal mechanism that would be chosen by the US administration. This lack of detail is central. A political threat, an investigation, a formal company designation, an export restriction and a financial sanction do not have the same effects. They do not affect the same actors and do not produce the same degree of extraterritoriality.

For European developers and companies, the issue is therefore not merely diplomatic. Many technical actors are tracking the progress of Chinese models, especially those whose weights are publicly accessible and can be run on their own infrastructure. These models are assessed for research, prototyping, development assistance, document analysis, translation, automation or local deployment uses. If Washington chose to directly target certain models or their publishers, European teams would have to balance performance, cost, hosting sovereignty, contractual compliance and the risk of disrupted access.

The distinction between an online service and a downloadable model is also decisive. When a company consumes an API, the provider can change its terms, block a region, suspend an account or discontinue a product. When it obtains model weights and runs them itself, technical continuity is of a different nature: the files may already be present in its environments. But this apparent autonomy does not erase licensing issues, legal risks or dependencies on libraries, updates, distribution platforms and infrastructure providers.

The statement attributed to Scott Bessent should thus be read as much as a political signal as a regulatory possibility. It indicates that the US administration is considering treating certain Chinese models not only as competing technology products, but also as potential vectors of harm related to intellectual property. Yet, in generative AI, the question of the origin of training data, the reproduction of content and the traceability of knowledge contained in a model is already one of the most disputed legal battlegrounds worldwide.

From controlling infrastructure to controlling software assets

The United States has extensive experience with technology controls applied to China. In October 2022, the US administration strengthened restrictions on the export of advanced semiconductor technologies and computing capabilities intended for China. These measures notably aimed to limit certain Chinese organizations’ access to the chips and equipment needed to train large AI systems. They were subsequently supplemented and adjusted in a context in which chipmakers, equipment suppliers and cloud players were at the center of trade and strategic tensions.

The logic of these controls was relatively clear: the highest-performing chips, the machines used to produce them and the computing infrastructure concentrated in data centers are scarce, physical and identifiable resources. They are sold by a limited number of companies, move through traceable supply chains and are subject to export licenses. An AI model is different. It can be offered as a service, distributed as digital files, modified by third parties, reproduced on repositories, converted to run on different hardware and integrated into broader software.

That difference is what makes any potential sanction particularly delicate. A model can refer to several things at once: an architecture, trained weights, a code repository, a trade name, a version hosted by its creator, a variant fine-tuned by a third party or an API service. Targeting a company that develops a model does not automatically amount to targeting all files derived from its work. Conversely, targeting the circulation of a software asset raises practical questions about distribution platforms, forks, mirrors and downstream integrations.

The term “open source” is frequently used in public debate to describe models whose weights can be downloaded. A technical and legal distinction must nevertheless be maintained. Access to a model’s weights does not necessarily mean that its code, training data, development recipes or all redistribution rights are open. License terms can vary greatly from one project to another. For a European company, this nuance already exists independently of Sino-American tensions: using a publicly accessible model does not remove the need to verify the rights granted, redistribution obligations, use limitations and associated responsibilities.

In this case, the allegation raised by Washington concerns intellectual property. This is an area where the boundaries of evidence and liability are particularly complex in AI. Disputes may concern training on protected content, the use of code, the reproduction of a competing model’s behavior, the transfer of know-how, access to unauthorized data or misappropriation of trade secrets. The threat reported by TechCrunch does not make it possible to know which specific practices US authorities intend to target or which elements they consider established.

This caution is all the more necessary because “Chinese model” does not refer to a homogeneous category. China’s ecosystem includes laboratories, internet platforms, technology groups, start-ups and developer communities with varied approaches. Their models may be closed, accessible via API, distributed with downloadable weights, specialized in certain tasks or multilingual. A targeted US measure should not automatically be interpreted as a general ban on all Chinese AI software. At this stage, the information reported is that of a threat of sanctions, not a detailed framework covering all models coming from China.

The episode nevertheless reveals an evolution in US strategic vocabulary. Authorities are no longer limiting themselves to the question of who owns the most powerful computing accelerators. They are also interested in what is produced with these resources and how those products circulate. This brings the debate on models closer to the one that has existed for years around cybersecurity software, encryption, surveillance technologies or digital components considered sensitive.

Why open Chinese models appeal to European developers

The risk raised in Washington meets a European market already faced with an abundant supply of models. Technical teams no longer choose only among major US services accessible through APIs. They can compare systems developed in the United States, Europe, China and elsewhere, based on quality achieved on a given task, the ability to run the model locally, hardware cost, context size, language support, deployment tools and security constraints.

Models whose weights are available are particularly attractive to organizations that do not want to send sensitive data to an external API. A company can install them in its own environment, run them on its servers or on cloud infrastructure it controls, and adapt certain elements to its use cases. This possibility is of particular interest to sectors where confidentiality, archiving, data location or integration with internal systems are operational requirements. It also concerns software publishers that want to control their roadmap rather than depend entirely on pricing or availability imposed by an API provider.

Developers generally assess these models pragmatically. They look at results on their own data, the quality of reasoning for targeted tasks, the robustness of structured outputs, latency, memory consumption, the ability to operate with existing hardware and the maturity of the software ecosystem. The nationality of the laboratory does not disappear from the equation, but it is only one factor among others. The announcement reported by TechCrunch could precisely alter this hierarchy: regulatory and geopolitical risk may become an architectural or purchasing criterion on par with raw performance.

For European companies, this risk is not necessarily one of automatic application of US law to all their activities. The scope of a measure would depend on its text, the persons or entities designated, prohibited operations, the presence of assets or transactions denominated in dollars, the use of US technologies and multiple compliance factors. But the history of US sanctions shows that they can influence companies outside the United States, particularly when they have commercial, financial or technical relations with US actors.

A French company experimenting with a Chinese model downloaded from a public platform is not in the same position as a company buying a service operated by a Chinese provider, a group with a US subsidiary, or a publisher reselling a product to US clients. The exposures differ. Reputational and contracting risks also differ. A client subject to strict procurement policies may require knowledge of the origin of every AI component, including when it is indirectly integrated into a product developed by a European provider.

Moreover, dependency does not concern the model itself alone. A project may rely on a maintenance community, quantization libraries, inference tools, connectors, test sets, documentation, embedding models, security systems or smaller versions intended for certain devices. If access to updates becomes more difficult, a platform removes a repository or a license changes, the company must be able to decide whether it will maintain an internal version, switch to an alternative or suspend certain features.

The development of models available locally has also opened up a competitive space in relation to hosted proprietary models. Major US platforms have built a significant part of their AI business around APIs and cloud services. Conversely, models with accessible weights give some companies the opportunity to reduce their dependence on a single provider, at least for certain uses. This is one reason why any intervention targeting part of China’s open ecosystem can have an indirect effect on the competitive structure of the global AI market.

For French-speaking users, the subject has an additional linguistic dimension. Performance in French and European languages varies according to models and tasks. An organization does not choose a system simply because it performs well in general evaluations, often dominated by English. It must check reliability on its documents, industry-specific vocabulary, administrative phrasing, code generation, internal rules and security constraints. In this analysis, the regulatory uncertainty introduced by Washington can make assessment work more costly, because it requires several fallback solutions to be prepared from the outset.

Compliance, provenance and continuity: concrete risks to monitor

The first practical consequence of the US threat is the need to map dependencies. Many organizations know they use a conversational assistant or an external API. They know less precisely which model versions are present in their prototypes, test environments, containers or third-party vendors’ products. Yet compliance cannot be improvised after a restriction is announced. It requires being able to answer simple questions: which model is used, who published it, under which license, where were the weights obtained, in which products is it involved and what data is transmitted to it?

This approach does not concern Chinese models alone. It is already part of responsible AI governance. But the geopolitical context increases its importance. A traditional software inventory can identify libraries and versions. For models, it is often necessary to add weight files, quantization parameters, internal adaptations, system prompts, auxiliary models and the services surrounding inference. A single product may combine a general-purpose model, a document retrieval engine, an embedding model, a security classifier and several external tools.

Provenance is the second issue. Organizations will need to distinguish what they know from what they assume. Public documentation may indicate a license, a publication date and a repository. It does not always answer every question about the development chain, the data used for training, or capital and operational links between different entities. Conversely, it would be imprudent to conclude that a model necessarily presents a legal issue because it was developed in China. The US position reported by TechCrunch concerns suspicions and a threat of sanctions, not a detailed public demonstration applicable to the entire sector.

The third issue is contractual. A company integrating a model into a commercial offering must analyze the guarantees it can actually provide to its clients. Can it ensure continuity of support? Can it quickly replace the component if the regulatory context changes? Do its contracts provide for a procedure to change provider or technology? Is the model integrated at the core of a business process, or used only for a feature that can be disabled without blocking the service? The more deeply AI is integrated, the higher the cost of migration.

Security is added to these issues. Cybersecurity teams already assess open-source dependencies according to vulnerability, maintenance and provenance criteria. AI models bring their own risks: unpredictable behavior, code generation, data exposure during a remote call, prompt injection attacks, data retrieved by connected tools and access-rights management. The question of geopolitical origin does not replace these controls. It complements them, just like verifying a license or the security of a software package.

For a European company, the most robust option often consists in avoiding a single-provider architecture. This does not mean that all Chinese models should be banned as a matter of principle or that only European technologies should be used. It means that a team should know which alternative model can take over for essential use cases, what adjustments will be needed and how long such a switch would take. The alternative model must not merely exist in a benchmark: it must be compatible with the organization’s confidentiality, quality, cost and hosting requirements.

Compliance leaders will also need to monitor the difference between political communication and an effective obligation. In an environment of high tension, companies may be tempted to hastily remove components, out of caution or fear of their clients’ reactions. Such a decision may be justified in certain contexts, but it should not replace analysis of the applicable text and actual risks. Conversely, waiting for formal sanctions without preparing a migration scenario can expose the company to a sudden disruption.

The case of distribution platforms deserves particular attention. Model and code repositories have played a major role in the rapid dissemination of generative AI. They allow teams to find versions, files, documentation and integration examples. If a US measure led to removals, geographic blocks or changes to access terms, users would need to determine whether their deployment procedures rely on these services in real time. In production environments, it is generally preferable for required artifacts to be versioned, verified and archived in a controlled framework, rather than retrieved without control at the time of deployment.

Lastly, the question of intellectual property points back to the responsibility of users themselves. A European company adopting a model must ask what uses it authorizes, what data it feeds into it and how it verifies the outputs produced. Global disputes around generative AI show that lawful access to a model does not automatically resolve every issue related to generated content. Rights over input data, trade secrets, reused works and human validation remain separate matters.

Pressure reshaping global AI competition

The threat of sanctions comes in a market already marked by a race for performance, computing and lower costs. US groups dominate part of cloud infrastructure, advanced chips and the most visible commercial AI services. At the same time, Chinese actors have published or offered competitive models in several categories, while European companies and laboratories are seeking to bring forth their own alternatives. Access to downloadable models has made competition more diffuse: the advantage is no longer measured solely by the ability to finance the largest data centers, but also by the ability to build developer communities.

A model-centered sanction could reinforce market fragmentation. Companies could favor providers according to their geographic area, their exposure to US law or their ability to guarantee local support. Chinese organizations could accelerate the development of their own software chains and distribution channels. European actors, for their part, could seek to capitalize on an intermediate position, based on regional hosting, compliance with European law and greater visibility into data-processing conditions.

This fragmentation is not necessarily favorable to Europe. It can create opportunities for local providers, but it can also increase compliance costs and reduce the choice available to users. European start-ups in particular frequently rely on global building blocks to rapidly build their products. If they must multiply audits, maintain several variants of their stack or anticipate the disappearance of certain models, their engineering expenses rise. Large groups generally have more resources to absorb this complexity.

The European Union already has its own regulatory framework with the AI Act, whose implementation is staggered according to the provisions. This regulation does not directly address a potential US sanction against a Chinese model. Its objective notably concerns risks related to AI systems placed on the European market, as well as obligations applicable to certain general-purpose AI models. But in practice, companies will have to layer several requirements: European AI law, data protection, sector-specific rules, software licenses, contractual commitments and, depending on their activity, constraints related to sanctions or exports.

France and Europe therefore cannot treat the issue as a distant confrontation between Washington and Beijing. They are markets, research locations, hosting territories and customers of technologies developed in both countries. European companies also sell internationally, use US clouds, cooperate with Asian partners and sometimes handle sensitive data. Any change in the US framework can affect their choices, even when no equivalent European rule is adopted.

For developers, the debate also risks fueling confusion between technical openness and strategic independence. Downloading a model’s weights can reduce dependence on an API, but does not guarantee independence from its creator, the community maintaining it, the license governing it or the hardware on which it runs. Conversely, a service hosted by a European provider is not necessarily sovereign if its components, chips or critical software come from other jurisdictions. Technological sovereignty is a chain of dependencies, not a label placed on an interface.

Scott Bessent’s statement, as reported by TechCrunch, could thus accelerate a practice that is already gaining ground: treating models as critical components of a software architecture. For a long time, procurement departments and legal teams focused their due diligence on major cloud providers, databases, operating systems and major open-source libraries. Generative models now require a comparable level of oversight, particularly when they are incorporated into decision-making processes, customer software or environments handling confidential information.

Toward a new battle over access, evidence and standards

What happens next will first depend on Washington’s concrete decisions. As long as no list of prohibited models, companies or transactions is made public, European actors must avoid two extremes: treating the threat as inconsequential or turning it into a general ban that does not exist. The right response is proportionate preparation. It involves regulatory monitoring, mapping AI components, reviewing licenses, analyzing contracts and identifying alternative solutions for important uses.

The very nature of the alleged grievance, presumed intellectual property theft, suggests a broader debate over evidence. In semiconductors, it is possible to identify a product, a supplier, a shipment and a destination. In AI models, precisely attributing a capability to a data source, a competing model or a development method is often more difficult. US authorities will have to define a scope that is legally defensible and technically applicable if they move toward effective sanctions. The companies concerned, for their part, will seek to understand which behaviors or assets are actually targeted.

This difficulty could encourage a multiplication of transparency requirements. Business customers will request more documentation about the models integrated into the products they buy. Investors will want to know dependency risks. Public administrations may strengthen their procurement criteria. Publishers will have to explain how they track the origin of their models, which versions they use and which procedures they apply in the event of regulatory change. These expectations will not be limited to Chinese models, but geopolitical pressure could make them more immediate.

For the French-speaking ecosystem, the issue is also industrial. The ability to assess, host, adapt and replace models is becoming a strategic skill. It requires engineers able to compare systems on real use cases, lawyers familiar with licenses and compliance rules, security teams able to audit deployments, as well as suitable infrastructure. Europe will not automatically gain autonomy because foreign models become more difficult to use; it will have to demonstrate that its own offerings, services and trust frameworks are sufficiently competitive.

In the longer term, the US threat suggests that AI’s regulatory boundaries could be drawn around three objects: computing, data and models. Controls on chips have already shown that hardware can become a major diplomatic lever. Conflicts over data and intellectual property show that training is an explosive legal battleground. Now, models themselves may become objects of sanctions, controls or restrictions. This development would make software distribution a geopolitical arena in its own right.

French and European companies that have built their products around publicly accessible models therefore have an interest in viewing this announcement as a test of the maturity of their governance. The question is not only which model is the most performant today. It is what level of risk the organization accepts, what visibility it has into its dependencies and what capacity it will have to continue operating if a provider, a platform or a jurisdiction suddenly changes the rules of the game. In an AI landscape now at the heart of power relations between states, technical resilience becomes inseparable from regulatory resilience.

Back to all news

Comments· No comments yet

Be the first to react.

Leave a comment