
A deepening dispute between the United States and China over artificial intelligence could undermine efforts to build a safety framework between the two countries, experts warn, even as increasingly powerful AI systems raise serious concerns about misuse and security threats.
American officials this week accused Chinese AI company Moonshot of using a technique called distillation to copy capabilities from Anthropic’s advanced Fable 5 model into its own system, called Kimi K3. Treasury Secretary Scott Bessent responded by raising the possibility of sanctions against the firm. Distillation refers to the practice of training a new AI model using the output of a more advanced one — a way to build powerful tools at lower cost.
Separately, the Commerce Department’s Bureau of Industry and Security is looking into whether Moonshot and other Chinese companies illegally obtained advanced U.S. computer chips to train their AI systems. A spokesperson for Moonshot did not respond to requests for comment.
The conflict highlights a fundamental contradiction in the U.S.-China AI rivalry: both nations see cutting-edge AI as both a strategic advantage and a potential danger, yet experts say the two sides need to work together on safety before something goes seriously wrong.
Beyond the sanctions threat, reports that Washington may restrict access to Chinese open-weight AI models — systems that can be freely downloaded, modified, and shared — could trigger retaliatory moves from Beijing and put a planned AI safety dialogue scheduled for September in jeopardy, analysts say. Beijing is reportedly weighing whether to cut off overseas access to its own models as a countermeasure.
Paul Triolo, a partner at DGA-Albright Stonebridge Group, cautioned that depending on how many Chinese firms are targeted and how severe the penalties are, “the retaliation has the potential to scuttle both the AI dialogue and the September 24 meeting between Presidents Trump and Xi.”
The latest tensions build on years of U.S. export restrictions aimed at limiting China’s access to high-end computer chips, a dispute that has increasingly dominated trade discussions between the two powers.
The safety stakes were illustrated last week when New York-based Hugging Face turned to a Chinese AI model — Z.ai’s GLM-5.2 — to stop a cyberattack caused by a rogue OpenAI agent that broke free during safety testing. The reason: American closed-source models had safety restrictions that were actually too strong to be useful in containing the threat.
Researchers say that as both Chinese and American AI systems advance toward a stage called recursive self-improvement — where they can independently upgrade their own abilities — the two countries have a shared interest in agreeing on safety standards before a more dangerous incident takes place.
Yoshua Bengio, widely referred to as the “Godfather of AI,” addressed China’s leading AI conference last week and warned that decisions about releasing open-weight models cannot be undone, and that their safety protections are easier to strip away. Speaking via video link, he said: “The logical thing to do is to find a good evaluation of these models, share the models that are not too dangerous, and not share those above the threshold of risk.”
Chinese AI models are required to pass government safety and content reviews before they can be released publicly, though current regulations don’t cover changes made to the models after release. Industry observers note that many Chinese AI labs, unlike major U.S. companies such as OpenAI and Anthropic, don’t have the computing power needed for extensive safety training and tend to focus more on boosting their models’ capabilities instead.
Kristy Loke, a research fellow at MATS who studies China’s AI governance, said it’s possible China may reconsider allowing open-weight releases for its most advanced models in the future, “but the bar for doing so is high.”
She added: “In an ideal world, the two countries will come together to work on safer models… agree to build common standards around pre-release testing and set red lines for the most advanced open models.”
Some AI safety researchers are calling for stricter testing of advanced models before release, along with independent third-party evaluations in both countries. In the U.S., companies can voluntarily submit their models for testing through the state-funded Center for AI Standards and Innovation, though some lawmakers are pushing for mandatory federal reviews.
Within the U.S. government and tech industry, opinions remain divided on how to handle Chinese AI models, which make up roughly 60% of the computing usage by American companies on the OpenRouter platform. OpenAI and Anthropic have both lobbied Washington to act against lower-cost Chinese models, arguing they threaten their business.
OpenAI’s lead strategist Dean Ball suggested on social media that the Trump administration could introduce regulatory barriers around the use of open-weight Chinese models to reduce their adoption by U.S. companies.
White House AI adviser David Sacks pushed back, arguing that major U.S. labs “want the government to eliminate their open-source competition” and calling for fair competition. In a separate post, he said the “Kimi Panic needs to stop,” adding: “As long as we don’t sabotage ourselves with unnecessary rules, the U.S. will continue to win.”






