The API Loophole: How Chinese AI Companies Are Bypassing Chip Export Controls
The United States has spent three years tightening export controls on advanced semiconductors to slow China's AI progress, but a newly exposed technique reveals a structural weakness: Chinese AI companies can legally access American frontier models through their public application programming interfaces (APIs) and use that access to train competing systems. This gap in the export control architecture is now at the center of high-stakes negotiations between Washington and Beijing, with Treasury Secretary Scott Bessent set to meet Chinese Vice Premier He Lifeng this weekend to discuss AI governance ahead of President Donald Trump's state dinner with Chinese President Xi Jinping on September 24.
On September 9, the National Security Agency (NSA), Federal Bureau of Investigation (FBI), and Cybersecurity and Infrastructure Security Agency (CISA) issued a joint advisory accusing six Chinese AI companies of what they called "aggressive, malicious and targeted distillation activities at industrial scale." The companies named were DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. Distillation is a technique in which a smaller AI model, called a "student," learns to replicate the reasoning patterns and probability distributions of a larger "teacher" model by analyzing its outputs. The student model can then be deployed independently, without ongoing dependence on the original teacher.
The scale of the alleged activity is substantial. According to the advisory, DeepSeek used outputs from four versions of Claude, two versions of Gemini, five versions of ChatGPT, and Grok 4 to improve its own capabilities in areas including agentic reasoning, coding performance, and professional writing. Moonshot AI was accused of distilling 18 different US models to train its Kimi K2 and Kimi K3 systems. The NSA, FBI, and CISA stated that these campaigns were conducted "likely with Chinese government awareness" and that the activities "strengthened China's military and cyberattack capabilities".
Why Chip Export Controls Alone Cannot Stop This?
The core problem is that export controls have focused almost exclusively on hardware. The United States has restricted China's ability to purchase advanced Nvidia processors and blocked the Dutch equipment manufacturer ASML from selling its extreme ultraviolet (EUV) lithography machines, which are essential for producing chips below the 7-nanometer node. These restrictions have real teeth. However, they do not address what happens when a Chinese AI company sends hundreds of millions of queries to an American frontier model's API, purchases the outputs legitimately, and routes the requests through proxy services to avoid detection.
This is where the distillation technique becomes strategically significant. A smaller model trained through distillation can achieve performance levels comparable to much larger models while requiring far fewer computational resources to run. This means that even if China faces constraints on acquiring cutting-edge training hardware, it can still develop competitive AI systems by learning from American models' outputs. The training data for distillation is generated entirely through routine API access, which is legal under current export control frameworks.
How Are Open-Weight Models Reshaping the Competition?
China has also pursued a parallel strategy by investing heavily in open-weight AI models, which release their underlying parameters publicly so that any government or company can download, run, and modify them on sovereign hardware without ongoing dependence on the original developer. This approach offers a geopolitical advantage: foreign governments can deploy Chinese open-weight models as sovereign AI infrastructure, embedded into national defense and administrative systems, without any Chinese company or cloud provider retaining ongoing access.
The shift toward open-weight models has accelerated China's global influence in AI development. According to the Stanford HAI AI Index 2026, the US-China AI capability gap narrowed dramatically from 17.5 to 31.6 percentage points in 2023 to just 2.7 percentage points by March 2026. Chinese models now account for approximately 41 percent of downloads on Hugging Face, a major open-source AI repository, with cumulative global downloads of Chinese open-source AI models exceeding 10 billion. On OpenRouter, a traffic routing platform tracked as a proxy for global model adoption, Chinese models' share has risen to approximately 48 percent of global traffic while US models have fallen from roughly 74 percent to 32 percent.
This distribution strategy reflects what Georgetown's Center for Security and Emerging Technology researcher Kyle Miller has described as China "effectively trading away some proprietary control to gain speed and breadth," allowing capability to diffuse through the global developer ecosystem as a way to partially offset constrained hardware access while spreading Chinese AI architecture as the world's default open standard.
Steps to Understand the Emerging US-China AI Governance Framework
- API-Level Access Controls: The US and China are now discussing whether to establish common frameworks for managing API-level access to frontier AI models, recognizing that both sides understand the current architecture enables capability transfer that neither export controls nor closed-model strategies fully prevent.
- Open vs. Closed Weight Model Strategy: Treasury Secretary Bessent confirmed that weekend discussions will explicitly cover both open-weight and closed-weight models, a distinction that describes a geopolitical competition over who can run AI infrastructure without depending on another country's cloud services.
- Distillation as a Capability Transfer Mechanism: US agencies have identified distillation as an industrial-scale technique that allows smaller models to replicate the reasoning patterns of larger American models through legitimate API queries, creating a loophole that hardware-focused export controls cannot address.
China's Ministry of Commerce rejected the NSA, FBI, and CISA allegations as "groundless" and warned of retaliation if Washington uses the distillation issue to restrict Chinese AI companies. This defensive posture underscores how contested the issue has become heading into the Trump-Xi meeting.
Meanwhile, China is also making progress on an alternative path to advanced chipmaking. The Chinese Academy of Sciences has established a preliminary gate-all-around (GAA) device development path using less advanced deep ultraviolet (DUV) lithography, according to a speech by Ye Tianchun, a veteran from the academy's Institute of Microelectronics. The institute finished early integration for stacked nanosheet-channel GAA CMOS transistors using DUV tools, which Ye described as a "new early-stage MOS transistor process path for China's sub-3-nm advanced manufacturing". While this breakthrough is far from mass production, it demonstrates that China is charting an alternative path to advanced chipmaking amid US export restrictions, since ASML's state-of-the-art EUV machines remain blocked under US sanctions.
The convergence of these developments has created a complex negotiating environment. Treasury Secretary Bessent's language about "shared risks" and "avoiding bifurcation" reflects an understanding that both the United States and China recognize the current architecture of AI competition enables capability transfer that neither export controls nor closed-model strategies fully prevent, and that some common framework for managing API-level access might serve both governments' interests.
The stakes extend beyond AI governance. The talks this weekend will also address critical mineral flows, particularly rare earth elements. Since early August 2026, several Chinese rare earth suppliers have declined to ship to US companies following Beijing's decision to sanction the Responsible Business Alliance, a US supply chain monitor. A senior US official stated that China's performance on restoring rare earth flows "has not been up to par" and would be a central topic heading into the September 24 state dinner.
What makes the AI governance dimension particularly significant is that it exposes a fundamental tension in US technology policy. On one side, companies like Nvidia, OpenAI, Google, and Meta argue that they cannot afford to slow their pace of innovation, whatever the risks, for fear that China will pull ahead. On the other side, some researchers and safety advocates have called for a global slowdown and the establishment of international safeguards. The presence of Nvidia chief executive Jensen Huang and OpenAI chief executive Sam Altman at the Trump-Xi dinner signals that these companies will have a voice in how the two superpowers approach AI competition going forward.