Pulling up the ladder


· 16 min read
In January 2025, a Chinese laboratory most people had never heard of released an AI model that performed nearly as well as systems costing far more and gave it away for anyone to download. DeepSeek's R1 wiped hundreds of billions from American technology stocks in a day, and it changed the conversation in Washington. The worry was no longer that China might catch up at the frontier, but that the most capable models were being handed out free, their inner workings open for anyone to adapt and run. Out of that alarm has come a push to restrict open models, to wall off not just Chinese systems but the open approach itself.
The instinct is understandable, and the diagnosis is wrong. It treats a model's openness as the hazard, even though openness is the one feature that can be turned to advantage. A model, once its weights are released, cannot be recalled, and no restriction reaches the copies already in circulation. The real question is never whether a capable model exists somewhere in the world, but who depends on whom to run it. That dependency, along with the physical compute these systems are trained on, is where the genuine exposure sits, not in the model file. Lock down the West's own open models, and you buy almost nothing in safety, while handing a few incumbents a protected market and conceding the global standard to China.
It helps to be precise about the word. An open-weight model is one whose trained parameters anyone can download and run on hardware they control, whereas a closed model can be reached only through its maker's online service. It is the open kind that policy has now turned against. Federal agencies and at least seventeen US states have barred DeepSeek from government devices, and bills moving through Congress would shut Chinese models out of federal use altogether. The instinct is not America's alone. Europe's AI Act exempts open models only conditionally, with the relief falling away once a model is judged to carry systemic risk or a licence places any condition on its use, so the compliance weight lands on whoever modifies and redistributes, the open developer. Britain has so far stayed lighter, with no statutory regime of its own. Some of this is sensible. A government department has no business posting its documents to a model that runs on servers under Chinese jurisdiction, and a rule against that closes a real hole. The trouble begins when the same instinct runs past the hosted service and reaches for the weights themselves, as though the downloadable file were the thing to fear.
The case for restriction deserves to be met at its strongest. Safety conditioning, the layer a laboratory adds so a model refuses harmful requests, can be stripped away with a few hours of fine-tuning, and once those altered weights are circulating, the original safeguards cannot in practice be restored. Nor is this any longer a matter of second-rate systems catching up: the best open models now sit just behind the proprietary frontier at a fraction of the cost, several of the strongest among them Chinese. A frontier-grade model, with its safeguards removed, could lower the barrier to a biological weapon or automated cyberattacks, and China's 2017 intelligence law, which obliges its companies to assist the state, makes any Chinese-hosted model a plausible point of collection. None of that is invented, and what follows takes all of it seriously.
What the case does not take on trust is the identity of the people pressing it hardest, because the loudest arguments for restriction come from the firms with the most to lose if open models spread. On Menlo Ventures' enterprise numbers, three closed providers, Anthropic in front, hold about 88 per cent of the corporate model market between them, and the cheap open models are the one force pulling customers the other way. These companies hold a sincere view about safety, and the dangers they describe are not imaginary. But they also have a balance sheet to defend.

A few closed labs dominate the enterprise model market, and the same firms are pressing to restrict the open alternative. Source: Menlo Ventures, 2025.
The commercial stake is the part the safety framing tends to leave unspoken. A year ago, the capability gap allowed the closed labs to charge a premium that few customers thought to question, and that gap has been closing month by month. On the benchmarks buyers rely on, the leading open models from DeepSeek and Qwen now run within striking distance of the best closed systems, with the proprietary lead retreating to the hardest reasoning and the most open-ended agentic work. The price gap has not closed at all. When DeepSeek made a steep discount on its flagship model permanent in May, it set output at well under a dollar per million tokens, leaving the gap to the Western frontier somewhere between 30 and 100 times, depending on the comparison. That is a price floor laid down on purpose, and the routing has followed it. On OpenRouter, the API gateway that now moves around twenty-five trillion tokens a week, five times the volume of six months earlier, seven of the ten most-used models are Chinese, with the strongest American system trailing the leaders. The dull, high-volume traffic goes to a cheap, open model, while the frontier system is reserved for work that needs it. The incumbents keep the top, where difficulty and reliability still command a premium. What hollows out beneath them is the lucrative middle, the ordinary high-volume work that pays the infrastructure bills, and that is the ground open models take first.

Capability against output price for the leading models in 2026, on a logarithmic price scale. The open models trail by a few points while costing a fraction as much to run. Sources: public leaderboards and providers' price lists (2026).
Seen against that backdrop, the instruments under discussion line up a shade too neatly with the interests of the firms proposing them. A licensing regime only a well-funded laboratory could satisfy would fall hardest on the open developer and barely graze the closed provider serving from behind an API, as would a compute threshold that bites at release, or a liability rule making the original developer answerable for whatever a downstream user later does. Each is presented as a matter of public protection, yet each would impose on the few firms large enough to comply a duty that ought to belong to the state. When the people who stand to profit from a particular answer are the ones drafting it, that answer deserves a more sceptical reading.
The theft charge must be read in the same light, more so now that it has grown from a corporate grievance into a centrepiece of government policy. In April 2026, the White House accused Chinese entities of industrial-scale copying of American models, after Anthropic reported that three Chinese labs had run extraction attempts against its Claude models using some 24,000 fake accounts. It helps to see what distillation is, because it ties this grievance to the commercial one. A cheaper model is trained on the outputs of a more capable one, learning to imitate it, so the technique that lets a Chinese lab approach the frontier on a fraction of the budget is also what produces the cheap open model that undercuts the incumbent's price. Theft and lost market are the same anxiety wearing two faces. The grievance is real enough. But the administration's own memo concedes both that a distilled model does not reproduce the full performance of the original and that lawful distillation is how a great many efficient open models are built. The objection turns out to be to a method of copying, not to openness as such. Walling off the West's own open models would do nothing to stop the copying, while removing the one thing that gives the rest of the world a reason to choose a Western system over a Chinese one. Theft is an argument for hardening the laboratories and pursuing the people doing the stealing, not for shutting the door on everyone else.
Even setting aside every motive, the remedy cannot deliver what is asked of it. We have run this experiment before. In the 1990s, Washington treated strong encryption as a weapon and restricted its export, yet the cipher crossed every border regardless; the policy's lasting achievement was to hobble American firms, while the mathematics spread anyway. Weights share the one property that decides the matter: once a file is out and copied, it does not come back. Restricting the West's own open models does nothing to the Chinese ones already in circulation.
I have spent enough years building systems that sit on critical national infrastructure, lately in smart energy, to know the choice an organisation faces is not whether to touch a model like this but how. The data that moves through a grid or a metering network is sensitive and tightly regulated, and the question that matters is never the model's cleverness, but where the data goes when the model runs. Run it on hardware you control, so the weights can be inspected, the telemetry switched off, and the sensitive data kept within your own environment. The danger lies in the other mode: the one where prompts and operational records are sent to a provider's servers in another jurisdiction. Openness is what lets that cord be cut, because an open model can be lifted clean off its origin and run on your own terms, where a closed hosted service cannot. The file is the wrong thing to be afraid of. The exposure has been sitting in the pipe all along.
If the safety case for a ban is thin, the strategic case against one is what ought to weigh most. What a country inherits along with a foreign model is not merely a set of technical defaults. A model carries the worldview of whoever trained it, and the imprint can be measured. One study that put 145 questions about Chinese politics to the leading systems found the Chinese models declining to answer far more often, DeepSeek refusing about a third of them, whereas the open Western models refused almost none.

Refusal rates on 145 questions about Chinese politics, asked in Chinese. The Chinese-trained models decline far more often than the Western ones. Source: Pan and Xu, PNAS Nexus, 2026.
This is not a peculiarly Chinese failing. Separate audits show every maker's model falling quietest on the subjects closest to home. The more insidious effect is the one that never announces itself, the answer that reads as perfectly even-handed while leaning a particular way. A country that runs its public services on a foreign model is absorbing assumptions about what may be said and how, and the deeper that model reaches into schooling and administration, the more those assumptions harden into what a population takes to be normal. This is the deepest reason the open standard matters, because the alternative to shaping it is not neutrality. It is someone else's inheritance.
The stakes run highest in precisely the places the West is inclined to watch least, across the emerging economies of Africa and South Asia. There China is laying down an AI-era extension of its Digital Silk Road, pairing cheap energy and connectivity with the open models that run on them at a price Western vendors will not trouble to match. Huawei opened the first major public cloud region in North Africa in 2024, grew it by 140 per cent within a year, and now leads the carrier cloud across much of Sub-Saharan Africa. To a government that will never train a frontier system, the capable open model, arriving bundled with affordable compute, becomes the default, with the Chinese standards and data rules baked into it arriving quietly along with it.
The leverage that genuinely works has been in plain sight the whole time, down at the physical layer the restriction debate keeps stepping around. This is where the frame I have argued for over the past year, growth under hard limits, applies most directly: what sets the ceiling on the most dangerous capability is compute and power- the silicon and electricity it takes to train and run a frontier model, and that is concentrated and visible in a way a weight file never is. By Epoch AI's reckoning, the United States holds roughly three-quarters of the world's high-end AI compute, a grip no licensing regime for downloadable files could begin to approach. It is also a grip Washington is using with a curious incoherence. Late in 2025, it moved to allow Nvidia to sell its H200 chips to approved buyers in China, a shift formalised in a Commerce Department rule the following January, turning near-prohibition into case-by-case approval under a reported arrangement that handed the United States about a quarter of the revenue from each sale. The deeper point survives the contradiction. The most advanced chips remain under control, and building a frontier-class model from nothing still demands vast, concentrated infrastructure that cannot be hidden from a power grid.
That constraint binds the training of a model, but not the inference that follows, and the gap between the two is becoming one of the most consequential facts in the field. The division is not lost on the people running the closed labs. Sarah Friar, the chief financial officer of OpenAI, recently described training as something that "mostly still all happens here in the United States," kept on home soil so that the finished model remains, in effect, a national asset. For inference, she added, "we want that to be global." That is the architecture set out by the company with the most commercial reason to argue for control. It places the security logic squarely on the training run and the compute beneath it, not on the open models that perform inference everywhere else. A frontier training run must sit beside an enormous quantity of power, a single large facility now drawing anywhere between a hundred megawatts and a full gigawatt, the appetite of a mid-sized city, so the binding limit is no longer the chips but the grid itself. The International Energy Agency expects close to a fifth of planned data-centre projects to stall while they wait for a connection.
Serving a model is a wholly different proposition, and its economics point in a single direction. The more inference is distributed across hardware scattered across the world, the more it favours models that can be placed on that hardware, downloaded, shrunk to fit, and run by whoever owns the machine. A model reachable only through its maker's online service cannot be put on a private box at all, since the weights never leave the provider. A closed model can, in principle, be licensed to run on a device, but it remains the vendors’ to control and meter even there. Only the open tier lets anyone freely place capability on their own hardware, adapt, and keep what it produces, which is why, as compute moves to the edge, open models are the ones that fit.

Training concentrates at a single grid-bound site; inference spreads across hardware people already own, and only a model that can run on that hardware will run there. As compute moves to the edge, openness becomes a precondition. Schematic; training-power figures from the IEA, 2025.
Distillation squeezes a large model down into a small one that keeps most of its ability, and the models that run well on a laptop or a modest on-premise box are the distilled and quantised ones, the open middle tier rather than the largest hosted systems, now reaching mainstream consumer machines as the chipmakers build local capability into them. Google's Gemma family is the clearest illustration of the direction. It is released openly in graded sizes, a mid-sized version that handles text, images and audio on a standard sixteen-gigabyte laptop, and a roughly four-billion-parameter variant light enough for the Arm processors that sit in phones and home gateways. The point is not any single model, but the spread built on top of one. Google reports that its open models have been downloaded several hundred million times and adapted by its community into more than a hundred thousand variants. Any single one of these is necessarily specialised, tuned to fit the memory and power it must run in. But because the weights are open, they can be adapted into a vast range of them, a model for vision here and for code or a particular language there, so the breadth of capability lives across the open ecosystem rather than inside any one system. A closed model offers what its vendor chose to build; an open base becomes a platform; the world extends in directions the original laboratory never planned; and that accumulating breadth is part of what makes an open standard so hard to displace once it takes hold.
The shift to the device carries a quieter consequence. When a model runs on a phone or a laptop, the user has bought the machine and pays the power, so the cost of the build-out moves onto the customer, and openness then decides who keeps the value created on it. An open model leaves both the cost and the value in the user's hands, whereas a closed one, pushed onto the same device, is the worst of both worlds: the user funds the hardware, while the capability remains metered and the value flows back to the provider. The incumbents are content to see AI move onto consumer hardware, which shifts the bill for the build-out onto millions of buyers. What they resist is the open model that would let those buyers keep the value as well, the same capture instinct seen from the other side.
Strip the argument back, and it is simple. The capability is already out. Restriction cannot reach it; the firms calling for it have a motive, and the bill for it would fall on the West. That is the whole of the case.
The posture all this points towards is harder and less satisfying than a ban, and its strength is that it holds even in the worst case. If a determined actor can really strip an open model down for harm, no restriction would answer that, since the already-released Chinese models would render it pointless. Defence does answer it and improves with the same capability that creates the threat, continuing to work after the first copy has escaped. The first task is to build rather than forbid: to keep the Western open models good enough to hold the substrate open on terms the West can shape, and within reach of the markets China is courting. The bill would come to less than the subsidy the West already pays its own champions and would buy real influence where the next several billion users are arriving. Those same models are the best tools for defensive work, finding weaknesses in critical infrastructure before an attacker does and driving the systems that detect misuse. Governance should be spent where it still bites, keeping sensitive workloads off foreign-hosted endpoints and writing procurement for critical infrastructure to exclude any service that ships data abroad or refuses inspection. The standards work deserves as much seriousness as the models themselves, because whether the open baseline is shaped inside Western standards bodies or surrendered to Chinese ones gets settled in committee rooms that rarely make the news, years before any regulation is drafted. None of it is served by letting the firms that profit from restriction hold the pen.
The capability is already loose, and it will go on diffusing whatever Washington decides about its own companies, so what the West still holds is only its own side of the line. There the choice is a real one. It can shape the open frontier and keep it within reach of the world that is choosing now, building, as it goes, the defences that irreversible technology demands. Or it can lock its own models away to shelter a handful of incumbents and watch the substrate and the standard pass to China. Pulling up the ladder feels like taking control, yet the capability is already on the ground below. What remains undecided is whose standard the world builds on.
illuminem Voices is a democratic space presenting the thoughts and opinions of leading Sustainability & Energy writers, their opinions do not necessarily represent those of illuminem.
Curious how major companies measure up on climate? On illuminem’s Data Hub™, explore verified emissions data, net‑zero targets, and sustainability performance of thousands of firms — from industry leaders to emerging innovators.
illuminem briefings

AI · Nuclear
Jonathan Lishawa

AI · Energy
illuminem briefings

AI · Green Tech
The Wall Street Journal

AI · Green Tech
Axios

AI · Green Tech
Vatican News

AI · Nuclear