| Len Khodorkovsky was deputy assistant secretary of state for digital strategy from 2017 to 2020. Last month, a Chinese artificial intelligence lab, Moonshot AI, released a model that stunned the industry. It tested at near-frontier performance while costing much less than leading American systems to use. And the lab promised to release an open-weight version — meaning anyone could download and run the model — in the coming weeks. Days after the launch, a coalition of AI and technology companies published a letter defending open-weight models as essential to American innovation. Both developments reignited a familiar debate over whether AI should be open or closed. But that misses the point. Whether a model is open or closed, the more important distinction is whether it was built through innovation or through theft. “There is nothing innovative about systematically extracting and copying the innovations of American industry,” Michael Kratsios, director of the White House Office of Science and Technology Policy, wrote in a memo. He wasn’t criticizing open-weight AI. He was describing what the administration alleges is a pattern of industrial-scale intellectual property theft by Chinese AI companies. The distinction matters because openness isn’t the problem; provenance is. A company that spends billions training a frontier model and later releases its weights (the numerical parameters that encode the model’s knowledge) to the public is making its intellectual property broadly available. A company that secretly extracts another firm’s proprietary model and repackages it at a lower price, or even gives it away for free, is doing something else entirely. The fault line in the debate is something called distillation. Most AI labs engage in the practice — sending their most powerful models thousands, sometimes millions, of prompts, collecting the answers and using them to train smaller, cheaper models that absorb much of the original’s capability. Distilling your own model is efficiency. Distilling someone else’s through fake accounts, masked routers or other underhanded methods is theft. And focusing on open weights is a distraction. Even Anthropic, whose models are at the center of recent allegations, has emphasized that the issue isn’t open-weight AI itself. CEO Dario Amodei recently reiterated that Anthropic has never advocated banning open-weight models. The concern, he argued, is industrial-scale distillation backed by an authoritarian state. The company has alleged that Chinese labs, including DeepSeek, Moonshot AI and MiniMax, created roughly 24,000 fraudulent accounts and engaged in 16 million exchanges with Anthropic’s Claude to illicitly extract its capabilities. OpenAI has similarly told Congress that DeepSeek unlawfully circumvented restrictions. More recently, Kratsios alleged that Moonshot AI distilled Anthropic’s Fable model to develop its groundbreaking Kimi K3 model. Western labs initially trained their models on vast amounts of scraped public data and intellectual property — an issue that’s still being litigated. But there is a big difference between training on the internet and deliberately extracting a competitor’s finished model through techniques designed to avoid detection. The pattern with Chinese open-weight models tracks a familiar playbook in other strategic industries: Beijing acquires the technology by whatever means possible, undercuts on price and locks in the market. Huawei was indicted for stealing T-Mobile’s trade secrets. Sinovel was convicted of stealing ASMC’s source code. Defenders of China’s AI strategy note that giving away a model for free isn’t “dumping” in the trade-law sense, since there is no price discrimination when something is public domain. That is beside the point. If the model was built, as U.S. companies and the White House allege, by stealing another company’s intellectual property, then it’s cheap for the same reason counterfeit goods are cheap: Someone else already paid the bill. The stakes extend well beyond the balance sheets of a handful of AI companies. Frontier AI models are becoming foundational infrastructure for governments, businesses, education, health care and national defense. As Chinese models are embedded into applications used by billions of people, they become harder to remove, echoing the dependency Washington says Beijing created with Huawei and 5G. As Chinese leader Xi Jinping recently put it, open-source AI is a “rare and historical opportunity” to shape the technology’s global development and reduce reliance on the United States. Beijing understands that leadership in AI is not just about selling software. It is about shaping the technological architecture on which future economies and societies will depend. None of this makes open-weight AI the enemy. Independently developed open models deserve the same legitimacy as any hard-won invention their creators choose to share. The goal should not be to regulate openness but to protect innovation. Policymakers should require greater transparency around model lineage for high-risk applications, establish trusted certification standards for critical infrastructure and hold deployers accountable when they rely on models of unknown origin in sensitive environments. Open and closed models alike should be free to compete, but on the same legal and ethical terms. The future of AI should be decided by better ideas, not by better theft. To worry or not to worry?For those who fear that the economy is being buoyed by an AI bubble, the collapse of Situational Awareness, a hedge fund, is exactly the sort of story they don’t want to hear. The fund was founded in 2024 by then-22-year-old Leopold Aschenbrenner, a former employee of OpenAI who was so confident in the AI boom that he borrowed tens of billions of dollars to bet against companies he believed AI would drive out of business, such as Adobe. But he was wrong: Adobe is doing well, and many of the AI infrastructure companies he invested in have taken a beating in the last month. That forced the fund to sell off most of its public positions, with hedge fund giant Citadel coming in to rescue it. Just because a tech “wunderkind” ended up being a bad speculator doesn’t mean AI’s economic potential is empty. Still, Aschenbrenner serves as a powerful symbol of over-exuberance in the market, which is a legitimate concern. Shares of tech companies tumbled last week, partly because of competition from China but also partly because of impatience from investors over AI’s profitability. Meanwhile, many companies are starting to realize the tech’s productivity gains have not yet lived up to their hype. That’s led some analysts to predict a market-wide correction soon. Adding to the alarm: Some finance watchers have fretted for a while about the circular deals underpinning much of the investments in AI infrastructure – that is, one company buys a stake in another one, and the second company uses that capital to purchase more goods from the first. These are not necessarily unsound arrangements – if things go well. But if they don’t, they risk cascading losses. Nobody knows how this will all play out, and predictions about bubbles bursting far outnumber actual market collapses. But it is by no means unreasonable to fear what lies ahead. Essential reading- The Argument’s Kelsey Piper explored the opposition to self-driving cars from trial lawyer groups.
- The New York Times editorial board makes the case against granting the U.S. government a financial stake in AI companies.
- NPR reports that people with criminal records are using AI to break down barriers to employment.
More Post coverage of AI |