The Agentic Enterprise AK · Morning Edition · 7 min read | Thursday, July 23, 2026 Half your tokens run on models Washington may be about to restrict. Chinese open-weight models quietly became core US enterprise infrastructure, carrying 46.4% of routed tokens on OpenRouter. This week Washington moved to restrict them. The White House accused Moonshot of building Kimi K3 by stealing Anthropic's Fable, and officials are weighing a menu of restrictions. But these models are open-weight and run locally, so an outright ban is close to unenforceable, which means the real effect lands on the enterprise as legal and continuity risk, not on Beijing. And it exposes a hole: there is no strong American open-weight alternative, the exact gap Chamath Palihapitiya says Elon Musk should fill by open-sourcing Grok. | | The Big StoryGovernance / Policy |
The Chinese models running US enterprises just got a Washington problem. | A | lmost half of the AI traffic routed through OpenRouter, a popular multi-model API layer, now goes to Chinese open-weight models: 46.4% of routed tokens, with DeepSeek alone at 17.6% as of July 2026. That is not a hobbyist statistic. It means Chinese labs quietly became default infrastructure for a large slice of US developers and enterprises, chosen for the same reason this newsletter has tracked all week: frontier-class capability, published weights, cheap to self-host. This week Washington decided that was a problem. |
The Trump administration is weighing restrictions on advanced Chinese AI models, with Kimi K3 named specifically, per reporting dated July 20. Officials are said to be considering a menu of tools: Entity List designations for Chinese labs, federal procurement bans, security advisories, and liability requirements aimed at the companies that use these models. The White House then escalated from policy to accusation. On July 22, science and technology director Michael Kratsios said Moonshot AI built Kimi K3 by covertly distilling Anthropic's Fable at industrial scale, on Nvidia GB300 servers in Thailand that are barred from sale to China. Anthropic returned Fable 5 to public access July 1; Kimi K3 shipped July 16, a 15-day window the administration reads as consistent with industrial distillation. Here is the problem with the crackdown, and the reason it matters more to a CIO than to a diplomat. These models are open-weight. The weights are already downloaded, mirrored, and running on private servers with no vendor in the loop. There is no license server to shut off and no API to revoke. An outright ban is close to unenforceable. So the pressure does not remove the models from your stack; it converts them into a liability. If procurement rules and use-based liability requirements land, the 46.4% of traffic currently flowing to Chinese models becomes a compliance question for the enterprises running them, not for the labs that made them. Half the market's routed intelligence is suddenly sitting under a policy cloud, and the exposure is yours, not Beijing's. A ban on open weights does not delete the model from your servers. It moves the risk onto your balance sheet and calls it compliance. |
The crackdown also exposes what the US does not have: a strong domestic open-weight alternative. Chinese models won share precisely because the best open options were not American. That gap is what Chamath Palihapitiya pointed at on July 21, arguing Elon Musk should flip xAI's Grok to open source, calling it a potential "checkmate." His logic is economic, not patriotic: open-sourcing the model pushes margin out of the commoditizing model layer and down into infrastructure and up into applications, both of which Musk owns, with the data-center-in-space ambition as the long tail. Hugging Face chief executive Clement Delangue replied simply, "yes." Whether or not Musk does it, the strategic point stands. If Washington is going to make Chinese open weights radioactive, American enterprises need an open-weight option they can actually defend, and right now they do not have a leading one. The Spearhead Take The risk here is not any single model. It is concentration. If a meaningful share of your AI workloads routes to Chinese open-weight models, whether directly or through an aggregator, you have taken on policy risk you probably never priced. The move is not to panic-rip Kimi or DeepSeek out of production this week; the accusation is unproven and a ban is unenforceable anyway. The move is to know your exposure: which workloads touch which models, whether you could switch providers in days rather than months, and whether you can document the provenance of what you run. Chamath is right that the real fix is a credible American open-weight alternative. Until one exists, treat model sourcing as a supply-chain decision, because this week it became one. |
| The Obvious & The Overlooked Three reads the headline gives you. Three it doesn't. The Obvious Washington is moving to restrict Chinese AI models. Officials are weighing Entity List designations, procurement bans, and use-based liability, with Kimi K3 named. Tom's HardwareThe White House added a theft accusation. Kratsios said Moonshot built Kimi K3 by distilling Anthropic's Fable on export-controlled hardware. Seeking AlphaChinese models are already core US infrastructure. They carry 46.4% of routed tokens on OpenRouter, DeepSeek alone 17.6%. FourWeekMBA | The Overlooked A ban on open weights is close to unenforceable. Weights run locally with no vendor control surface, so restrictions chill use rather than remove the models. Tom's HardwareThe exposure lands on the enterprise, not the lab. Use-based liability makes the company running the model the compliance target, not the one that built it. Seeking AlphaThe crackdown exposes a missing US open-weight option. Chinese models won share because the leading open weights were not American; there is still no strong domestic one. Chamath on X |
| Moving Pieces Three developments worth a CIO's attention. Deals / InfrastructureOpenAI industrializes the buy side: a managed agent platform and a $30B data center On July 22 OpenAI launched Presence, an enterprise platform for building, governing, and improving production AI agents, with policies, guardrails, simulations, evaluations, approved actions, and post-launch tuning via Codex. The same day it announced Project Camellia, a self-designed, self-built data center campus in Effingham County, Georgia, near Savannah, at more than $20 billion and potentially exceeding $30 billion at full scale, with 3.2 gigawatts contracted from Georgia Power and capacity landing from 2028 through 2032. The enterprise read: while Chinese open weights get a policy cloud, the American buy side is selling the opposite of ambiguity, a governed, auditable, US-hosted stack. Presence sells the control layer a self-hosted open model lacks, and the data center is a bet that owning US infrastructure is itself a feature. Expect "American AI you can defend" to become a sales line. InfrastructureAWS calls it a renaissance and puts a number behind it AWS chief AI and technology officer Matt Wood described the current enterprise wave as a "renaissance" in a July 22 broadcast interview, citing a $15 billion AI revenue run rate and pointing to regulated industries as the ones leading adoption. Amazon Bedrock now hosts OpenAI's frontier models alongside Anthropic's Claude, positioning AWS as the neutral distribution layer regardless of which lab wins. The enterprise read: if Chinese models become legally fraught, the hyperscaler pitch gets stronger, because a curated menu of vetted, US-hosted models is exactly what a compliance team wants. The model wars are becoming a procurement menu, and governance across that menu is the product now, not the model itself. PolicyAnthropic's lobbying spend jumps 26% after Commerce pulled its models offline Anthropic spent $1.97 million on federal lobbying in Q2 2026, up 26% from Q1 and enough to outspend Nvidia, with its first-half total already above its full-year 2025 spend. Axios and CNBC trace the surge to two weeks in June when the Commerce Department took Anthropic's latest models offline, after which the company worked, through an in-house team and nine outside firms, to get the order lifted and to shape rules on export controls, cybersecurity, and AI safety standards. The enterprise read: the same government now defending Anthropic's IP against Moonshot took Anthropic's own models offline weeks earlier. Regulatory availability cuts both ways, and for anyone standardizing on a single frontier lab, US or Chinese, model access is now a continuity risk, not a hypothetical. | On the Radar Three signals, sharpened. | Open Source | Chamath Palihapitiya urged Elon Musk to open-source Grok, calling it a possible "checkmate." He argued it would move margin from the model layer into infrastructure and apps; Hugging Face's Clement Delangue replied "yes." Chamath on X | | Infrastructure | OpenAI raised planned AI infrastructure spending toward $750 billion. Reported alongside the Georgia announcement, a marker of how much capital the US buy side will sink into owning compute. Quartz | | Adoption | HCLTech found only 18% of enterprises see significant revenue impact from AI, against 90% reporting workflow transformation. A reminder that model choice is not the constraint on returns. Webnewswire |
| The Number 46.4% Of routed tokens now go to Chinese models Nearly half of OpenRouter's routed token traffic goes to Chinese open-weight models, with DeepSeek alone at 17.6%. OpenRouter is a multi-model API layer developers use to plug into many models at once, which makes its routing data a rough proxy for what production systems actually call. The figure is the whole tension in one number. Nearly half of the intelligence routed through this layer comes from labs Washington is now moving to restrict, and it got there on the merits, because the models are strong and cheap to run. That is why the crackdown is so awkward. You cannot restrict 46.4% of a market's routed traffic without imposing a switching cost on the American companies that built on it, and there is no equally strong American open-weight option to switch to. The number is both the reason for the policy and the reason it will hurt. | Counter-Signal SkepticA ban you cannot enforce is not a reason to rip out your stack. The reflexive enterprise response to "Washington may restrict Chinese AI models" is to purge Kimi and DeepSeek from production immediately. Slow down. Two things temper the panic. First, the mechanics: open weights already running on your servers cannot be recalled, and reporting is explicit that an outright ban would be nearly impossible to enforce. What is realistically on the table is procurement rules and use-based liability, which change your risk calculus but do not force an overnight migration. Second, the accusation against Moonshot is unproven, resting largely on a 15-day timeline, and a theft claim is not a court finding. The disciplined response is neither purge nor shrug. It is to map exposure and preserve optionality. Know which workloads route to which models, keep an abstraction layer so you can switch providers in days, and document provenance for anything in production. If liability rules land, you want to have already moved regulated and customer-facing workloads onto models you can defend, while leaving internal, low-stakes tasks on whatever is cheapest. The mistake is treating this as binary, all-Chinese or none. The enterprises that handle it well will treat model sourcing the way they treat any other supply chain, with diversification and a plan to switch, not a purity test. | From the Field A large share of American enterprise AI quietly came to run on Chinese open-weight models. This week that quiet arrangement stopped being quiet. When close to half the traffic on a major routing layer flows to labs your own government is moving to restrict, the exposure was there all along; the policy just made it visible. What makes this genuinely hard is the enforceability paradox. Open weights are the thing that made these models attractive, cheap, self-hostable, no vendor lock-in, and they are also the thing that makes a ban nearly meaningless. The weights are already out. So the pressure does not fall on Beijing or on Moonshot. It falls on the American CIO who has Kimi or DeepSeek somewhere in production and now has to decide what to do about a risk that is real but unquantified. The deeper problem Chamath put his finger on is that the US does not have a strong open-weight answer of its own. Chinese labs did not win American developers by accident; they won because the best open option was not American. You can restrict the supply, but if you have not built a domestic substitute, you have just raised costs for your own companies and pushed them toward closed, metered vendors. Whether or not Musk open-sources Grok, the gap he is being asked to fill is real. Model sourcing is now a supply-chain decision. Know your exposure, keep the ability to switch, and document what you run. The teams that already treat models as interchangeable components will barely feel this. The ones that hard-wired a single model into production are about to learn what concentration risk costs. Let's get to production, AK | | The Agentic Enterprise Know more about AI than 95% of your peers. By 7 AM. A daily AI intelligence briefing for enterprise leaders, published by Spearhead. We build AI systems that work. Strategy. Engineering. Production. Outcomes. © 2026 Spearhead. All rights reserved. |
|