Four separate attempts to restrict Chinese AI models reached internal consideration inside the Trump administration last year and were killed before any took effect, Axios reported Monday, and parts of the government are weighing them again. The abandoned measures ranged from Entity List designations for Chinese AI labs to an executive order that would have made U.S. companies liable for breaches of any Chinese model they hosted. Sources close to the administration tied the revival to Moonshot AI's release of Kimi K3 last week, and the report noted that a ban could lock in dominance by OpenAI and Anthropic.
What Changed
- Four attempts to restrict Chinese AI models reached internal consideration inside the Trump administration last year and were killed before any took effect, Axios reported Monday. Moonshot's release of Kimi K3 has revived them.
- The measures were Entity List designations for Chinese AI labs, an NSA and Office of the National Cyber Director advisory, a draft executive order putting breach liability on U.S. hosts, and Commerce supply-chain rules circulated last summer.
- Sources describe procurement rules, Entity List threats and public pressure campaigns as the likelier instrument, and say AI labs or their allies pitch a ban on open-source models every three to five months.
- Hugging Face ran Z.ai's open-source GLM 5.2 on its own infrastructure to investigate a breach after guardrails on U.S. frontier models blocked its incident responders.
AI-generated summary, reviewed by an editor. More on our AI guidelines.
The Entity List and the draft executive order
Those sources laid out the four measures to Axios. The Commerce Department considered adding multiple Chinese AI labs to the Entity List, which would effectively cut off U.S. access without a license. The National Security Agency and the White House Office of the National Cyber Director weighed an advisory about threats tied to Chinese labs, a step that would have discouraged companies from using their technology. White House officials drafted an executive order allowing U.S. companies to host Chinese models only if they could guarantee security and accept liability in a breach. Commerce separately circulated draft rules within the administration last summer that leaned on its authorities to secure domestic supply chains, aimed at Chinese open-source models. Administration officials who wanted to keep regulation from stifling innovation killed all of them, according to the report, which linked the current revival to a shift in personnel: key voices such as former White House adviser Sriram Krishnan have left, and national security hawks have grown louder. More capable Chinese models and fresh cybersecurity fears fed the same momentum.
Neither the White House nor the Commerce Department responded to requests for comment.
Procurement rules and public pressure
An outright ban may not be the mechanism. "What's actually happening is slower and more durable," one source familiar with government discussions said, citing procurement rules, Entity List threats and public pressure campaigns aimed at U.S. companies using Chinese models.
A second source familiar with those discussions framed the effort differently, as a push to highlight potential backdoors and security gaps in Chinese models along with the governance problems that follow, paired with encouragement for a more innovative U.S. open-source sector.
The approaches keep coming. One source close to the administration said leading AI labs or their allies arrive with an idea to ban open-source models every three to five months.
The public pushback from Sacks and Gurley
David Sacks, an outside White House AI adviser, wrote Sunday on X: "We are at a critical inflection point in AI policy. The leading closed labs, already a duopoly in terms of AI model revenue, want the government to eliminate their open-source competition." Sacks has long warned against regulatory capture that would benefit the largest U.S. labs.
Get Implicator.ai in your inbox
Strategic AI news from San Francisco. No hype, no "AI will change everything" throat clearing. Just what moved, who won, and why it matters. Daily at 6am PST.
No spam. Unsubscribe anytime.
Bill Gurley, president and founder of the P3 Institute, called open models ordinary cost-leadership competition in a Washington Post op-ed published the same day. He set Anthropic and OpenAI, both preparing to go public at valuations near $1 trillion, against Zhipu, a lab that gives its models away and carries a Hong Kong market capitalization above $100 billion.
Know someone who'd find this useful? ✉️ Email it to a friend in one click, or they can subscribe free here.
Ben Thompson questioned in Stratechery whether listed token prices establish a Chinese cost advantage at all. Kimi K3 lists at $3 per million input tokens and $15 per million output tokens, against $5 and $30 for Sol. Kimi reportedly burns significantly more tokens during reasoning, which erodes the posted gap, and Thompson's analysis led him to doubt that Chinese models are cheaper to serve on a marginal-cost basis.
Hugging Face turned to GLM 5.2
Hugging Face said an autonomous AI agent system breached its production infrastructure early last week. Its incident responders were stymied by guardrails on unnamed U.S. frontier models that "cannot distinguish an incident responder from an attacker," the company wrote, so the team ran Z.ai's open-source GLM 5.2 on its own infrastructure to analyze the more than 17,000 logs the attackers left behind.
Thompson cited that incident as evidence that current U.S. directives push defenders toward Chinese systems, because restrictions on domestic frontier models block the incident-response work security teams need.
The pressure on Washington runs in both directions. Xi Jinping urged countries to "encourage open source, openness, collaboration and sharing" at the World Artificial Intelligence Conference in Shanghai, in a speech whose text Chinese state media published July 18. Alibaba, which showed a preview of its Qwen3.8 Max model days later, plans to release its weights.
Frequently Asked Questions
What did the Trump administration actually consider?
Four measures, none of which took effect. Commerce weighed adding multiple Chinese AI labs to the Entity List, which would cut off U.S. access without a license. The NSA and the White House Office of the National Cyber Director considered an advisory on threats tied to Chinese labs. White House officials drafted an executive order permitting U.S. companies to host Chinese models only if they guaranteed security and accepted breach liability. Commerce also circulated draft supply-chain rules last summer.
Why were they abandoned, and what revived them?
Administration officials who wanted to keep regulation from stifling innovation killed all four, according to the report, which linked the current revival to a shift in personnel. Key voices such as former White House adviser Sriram Krishnan have left, and national security hawks have grown louder. More capable Chinese models and fresh cybersecurity fears added to the momentum.
Is an outright ban the likely mechanism?
Sources familiar with government discussions point elsewhere. "What's actually happening is slower and more durable," one said, citing procurement rules, Entity List threats and public pressure campaigns aimed at U.S. companies using Chinese models. One source close to the administration said leading AI labs or their allies arrive with an idea to ban open-source models every three to five months.
Why does the Hugging Face breach matter to this debate?
Hugging Face said an autonomous AI agent system breached its production infrastructure early last week, and its responders were stymied by guardrails on U.S. frontier models that "cannot distinguish an incident responder from an attacker." The team ran Z.ai's open-source GLM 5.2 on its own infrastructure to analyze more than 17,000 logs. Ben Thompson cited the incident as evidence that current U.S. directives push defenders toward Chinese systems.
What are open-model advocates arguing publicly?
David Sacks, an outside White House AI adviser, wrote Sunday on X that the leading closed labs are "already a duopoly in terms of AI model revenue" and want the government to eliminate their open-source competition. Bill Gurley of the P3 Institute called open models ordinary cost-leadership competition in a Washington Post op-ed the same day.
AI-generated summary, reviewed by an editor. More on our AI guidelines.



IMPLICATOR