As China’s promiscuous AI models grow in capabilities and popularity, the debate over what to do about them is heating up again.
There is talk that the Trump administration may try to ban them (though it has not yet acted on that idea). Meanwhile, manufacturers of proprietary models, particularly OpenAI and Anthropic, seem increasingly concerned about them.
Openweight models such as Moonshot AI’s Kim K3 and Alibaba’s Qwen provide inference at a fraction of the token cost of closed-source models offered by large US labs. The scary thing is that they pose some sort of threat. Indeed, they threaten the profit margins of large proprietary AI laboratories.
But should companies running these models in their data centers succumb to the fear that they could become vectors for Chinese hackers?
No, says Arcee CTO Lucas Atkins. Arcee is building an open model that provides U.S. companies with a homegrown alternative to the Chinese model.
If startups benefit from banning the Chinese model, so will Arcee. But Atkins argues that China’s open model is no more dangerous than other open source software used by companies. In fact, he says, they offer perks to his company as well.
“A lot of people see this as being similar to a Chinese software program, like it’s coded with an x, y, z kind of intent, something that a malicious party can easily command,” he said.
“That’s basically not how these models are trained. Arcee or Alibaba creates a model, someone runs it in their own environment, and there’s really no way for us to access it,” he explained.
Most of these models are what is known as “open weight” and are not actually fully open source software, but the source code (the part that actually runs on the server) is similarly largely visible and reviewable when downloaded from open source sites such as Hugging Face. (What is not available are the methods and data used to train the model.)
Large organizations should apply Model Core to their security testing and inspection processes. Additionally, models can often be post-trained for specific applications to test for areas such as bias, toxicity, hallucinations, and hypersensitivity to certain topics. So interact with, optimize, and understand your model before users start prompting it.
Is it possible that the model used to code could somehow throw a malicious backdoor into the code I write?Again, it’s theoretically possible, but it would require some acrobatic feats to accomplish.
“There’s no reason why a sufficiently sophisticated actor can’t train a model to be a completely amazing coding model in all situations, but when presented with a certain type of code base, some hidden training will kick in,” hypothesized Atkins, who spends his days training models. But he also added: “I don’t know how they do this.”
Large-scale language models are inherently creative, so it’s highly unlikely that modern models will spit out malware in response to a perfect storm of pre-planned contexts and prompts. Companies are even less likely to use that code.
Is it possible that it will happen in the future? That’s anyone’s guess. But companies are building AI apps to be model agnostic and use multiple models. Therefore, companies do not have to use Chinese models forever, even if they are the best at current prices.
“Instead of talking about how to ban the Chinese model, I think we should be talking about how to foster a good, open ecosystem here in the United States,” Atkins said.
Arcee also benefits from Chinese models. Because they’re open, startups “benefit from the models being good because we can learn what they’ve done; we can build on top of them; and they can learn what we’re doing,” he says. “We have a lot of respect for the people who are building these models, the individual researchers.”
Ultimately, the way to compete with Chinese models is to “release a better model,” Atkins said. “We need to give them something to talk about.”
If you buy through links in our articles, we may earn a small commission. This does not affect editorial independence.
