On 16 July, the Chinese lab Moonshot AI released Kimi K3: 2,800 billion parameters, the largest model ever put into open weights. On 3 August, Alibaba unveiled Qwen 3.8-Max, 2,400 billion parameters of which 95 billion active, multimodal, with weights announced for the following week — a first at that scale for Alibaba.

Three weeks, two front-rank models, distributed free to the whole world. Models whose training runs into hundreds of millions of dollars.

The question going around is a fair one: why? The answer you hear most often — “it is technological lock-in” — has the merit of pointing at a real strategy. But it describes the mechanism badly, and that imprecision stops you seeing where the real risk sits.

What “open weights” means exactly

First clarification, because everything else depends on it.

A model in open weights makes its trained parameters available: you download them, you run them on your own servers, you modify them. Kimi K3 and the Qwen models are released under permissive licences of the Apache 2.0 or MIT type — commercial use allowed, no royalty, and a model you fine-tune belongs to you.

This is not open source in the strict sense, which would require publishing the training data and the complete chain. Nobody does that, in China or in the West. The confusion between the two terms suits the vendors, and it muddies the debate.

The difference with a proprietary model is considerable. With a closed API you rent access: the provider can change its prices, alter its model, restrict a use or shut the service down — which is exactly what has just happened to Sora users, whose shutdown OpenAI has announced. With downloaded weights, none of that can be taken away from you.

The figures nobody looks at: the switch has already happened

This is the point media coverage misses almost systematically. We debate whether China will catch the United States up, while on the ground of distribution the matter is settled.

On Hugging Face, the main platform for distributing models, Chinese models now account for 41% of downloads over the last twelve months — overtaking the United States for the first time. Alibaba’s Qwen family has passed one billion cumulative downloads, dethroning Meta’s Llama as the most downloaded open model in the world. It anchors more than 200,000 models carrying its label and more than 113,000 derivatives. Around 40% of all new language model derivatives created on the platform today start from a Qwen base. In June 2026, Chinese models held five of the ten top places in the trending list.

On real usage, the gap is wider still. On OpenRouter, the main neutral router distributing requests to dozens of models, Chinese open-weight models accounted in May 2026 for around 61% of all tokens consumed, and four of the five most used models were Chinese. At Vercel, the share of open-weight models in the tokens passing through its production gateway rose from around a ninth in April to 29% in June 2026.

The most telling figure comes from a report by the US commission on economic and security review: around 80% of American AI startups use a Chinese base model to build their applications.

In other words, while Washington debates export controls, the American software ecosystem itself has largely been built on Chinese foundations. We had already noted that contradiction when analysing the copying accusation levelled at Kimi K3.

The “two loops” strategy

The most useful document for understanding the overall logic is not Chinese: it is a report published on 5 March 2026 by the U.S.-China Economic and Security Review Commission, the body created by the US Congress to monitor the economic relationship with Beijing. Its title — Two Loops — describes a two-storey arrangement whose halves reinforce each other.

The digital loop is the one everybody sees: release open models, let a worldwide community test, fix and adapt them, and collect the fruit of that work for nothing. The 113,000 Qwen derivatives are so many improvements nobody invoiced Alibaba for.

The physical loop is the one that gets ignored. Free models deploy without licence friction into factories, logistics and robotics — sectors where China already has industrial scale with no equivalent anywhere. Those deployments produce real-world data, which serves to improve the next models. Beijing has in fact formalised that advantage by designating data as a factor of production, allowing companies to carry their data assets on their balance sheets.

The commission’s conclusion is harsh on American policy: export controls target the digital loop — access to the chips needed to train frontier models — and are largely inoperative on the physical loop.

The underlying economic principle is a classic: you commoditise your competitor’s product to move the value to where you are strong. If a free model does 95% of the work of a $20-a-month subscription, the competitor’s business model collapses, and the value migrates to the application and to compute. It is the same mechanic that made NVIDIA’s CUDA ecosystem a success, but turned around. The price war started by the Chinese vendors is its most visible component.

”Technological lock-in”: the phrase is wrong, the risk is not

This is where precision matters, because the analogy going around is misleading.

Technological lock-in, properly speaking, describes a situation where changing supplier becomes prohibitive because that supplier controls something you cannot do without. That is the case for a proprietary operating system, a closed file format, an API your product rests on entirely.

A model under Apache 2.0 is very precisely the opposite. The weights you downloaded are on your disks. The licence is irrevocable for the version you obtained. If Alibaba shut down tomorrow, your deployment would carry on working. If Beijing decided to ban the export of new models — a hypothesis that circulated this summer — it would not affect what you already have. No proprietary API offers that guarantee.

The risk exists, but it is of a different nature, and it is worth naming correctly:

The cost of migrating is operational, not legal. Nothing stops you changing model; what costs is rewriting the prompts, redoing the evaluations, retraining the adapters, adjusting the serving infrastructure. That cost is real but bounded, and it is the same whatever the model’s country of origin.

The dependence sits in the ecosystem, not in the model. Tools, tutorials, fine-tuning datasets and team skills build up around one family of models. When 40% of new derivatives start from Qwen, that is where gravity forms — not in a contract.

The real point of asymmetry is the scarcity of alternatives. If Western open models stop being competitive, the choice disappears in practice, without any lock having been fitted. That is a market risk, not a licensing one.

What these models refuse to say

There is, on the other hand, one dependence that does not vanish when you change server: the one written into the parameters themselves.

The available work converges. A study from Stanford University’s China centre establishes that models of Chinese origin show substantially higher refusal rates, shorter answers and inaccurate answers on political questions, compared with models developed elsewhere. The subjects involved are documented: Taiwan, Tibet, Xinjiang, the events of 1989, criticism of the Party leadership.

Researchers distinguish hard censorship — outright refusal to answer — from soft censorship, made of evasive answers or deflections. Recent work shows that the model’s intermediate reasoning is sometimes suppressed or rewritten before being returned.

Two important nuances, usually left out.

First, the behaviour is not uniform. Independent tests put some versions of Kimi, at Moonshot, at a level of neutrality close to Western models, while some versions of DeepSeek filter far more aggressively. Speaking of “Chinese models” as a homogeneous block is a convenience.

Second, and this is the summer’s most interesting result: that censorship does not necessarily survive the distillation process. The Californian lab CTGT, led by Cyril Gorlla, published work at the end of July 2026 showing that a “student” model trained from DeepSeek V4 Flash does not systematically inherit the same restrictions as the source model. The protocol rested on 152 pairs of questions — China-related questions and control questions — assessed by models from four different labs.

In other words, the bias is real and measurable, but it is modifiable by whoever holds the weights. Which is, once again, the exact opposite of lock-in.

Europe has answered, and Mistral is not what it chose

Faced with this situation, the European Union made its decision on 19 June 2026: the EUROPA consortium, led by the Italian start-up Domyn (formerly iGenius), won the Frontier AI Grand Challenge. Its mission is to build an open model of more than 400 billion parameters, covering the Union’s 24 official languages and trained on European supercomputers. The consortium gets 2.5% of EuroHPC compute capacity for a year, one of the largest allocations the Union has ever granted. Domyn’s chief executive promises an open source delivery within a year.

The choice came as a surprise: Mistral was not selected. The French champion is pursuing its own path — a valuation of 11.7 billion euros in a round led by the Dutch firm ASML, $830 million raised for its first French data centre, 722 million euros committed for 13,800 NVIDIA graphics processors.

Those amounts also say how wide the gap is. France announced 109 billion euros of investment at the Paris Summit of February 2025, and the Commission launched a 5 billion euro Scaleup Europe fund at the end of May 2026. But the dependence reaches into the financing itself: the European champion’s main investors are not European, and the processors bought are American. We covered that tension from the angle of health and banking data in our analysis of who actually processes your data.

What this changes in practice

For a European company, the relevant question is not the model’s nationality but the use made of it. For code, translation or technical document processing, the risk gap is small and the cost gap considerable. For information analysis, geopolitical subjects or decisions that carry liability, you have to test the model’s behaviour on your own cases — a rule that holds for every model, whatever its origin.

For an independent developer, the terms have changed: frontier performance is no longer behind a subscription. That is what our comparison between the most expensive model on the market and the largest open model ever released shows, where the quality gap does not always justify the price gap.

For a public decision-maker, the American report suggests the battle is not being fought where we are looking. Restricting access to chips acts on the training of frontier models, not on distribution nor on industrial data. That also explains Chinese institutional activism, whose creation of a world AI governance organisation we set out in detail.

For the European user, finally, part of the subject is already settled by law rather than by technology: the transparency obligations that came into application on 2 August 2026 apply to systems placed on the European market, regardless of the vendor’s flag.

To follow how the balance of power shifts, our AI ranking and its open source category are updated continuously.

What to take away

China is not distributing its models out of generosity. It is applying an explicit industrial strategy, documented by American analysts themselves: commoditise the model to move the value towards the application, the hardware and physical deployment, while capturing for free the improvement work of a worldwide community.

The strategy is working, and the figures leave little room for doubt: 41% of global downloads, 61% of tokens consumed on the main neutral router, 80% of American AI startups.

But “lock-in” is the wrong word. Weights under a permissive licence sitting on your servers are the least constraining form of dependence that exists — far less so than a proprietary API the provider can close overnight. The real risk is not contractual: it comes from the gravity of an ecosystem, from the scarcity of alternatives, and above all from what the models have learned not to say — a measurable bias, but one that whoever holds the weights can correct.

That may be the most uncomfortable point in this story: China has chosen the strategy that leaves its users the most free, and that is precisely what makes it effective.

The figure to keep

80%. That is the proportion of American artificial intelligence startups building their applications on a Chinese base model, according to the report by the US commission on economic and security review published in March 2026. While Washington restricts the export of its chips, its own fabric of young companies has settled on foundations that came from elsewhere.