The catch is that many of the strongest open models, including DeepSeek, Z.ai, Xiaomi 1810.HK, MiniMax 0100.HK, Tencent 0700.HK and Alibaba 9988.HK, are Chinese. The share of tokens used by U.S. users on Chinese open-source models via OpenRouter — a platform that enables developers to access a range of AI models — hit 64% in the week of July 13.
It is a difficult balancing act. Users switching to models developed by Chinese labs cannot be sure that future updates or restrictions will remain politically neutral. Hidden security risks may surface only after deployment, especially if models generate or execute code. Washington is already debating whether to restrict, or effectively ban, some Chinese open-weight models in the United States, Reuters reported, citing sources. Beijing is similarly discussing limits on overseas access to its own advanced models, Reuters has reported. Open-source AI, therefore, risks becoming another contested strategic technology, much like advanced chips made by Nvidia NVDA.O.
Western firms are racing to offer alternatives. Giant hedge fund Bridgewater Associates used Tinker, a new open-source model released by U.S.-based Thinking Machines, to build a custom version of Alibaba's Qwen, which outperformed top proprietary models at a lower cost. Meta's Llama, Europe's Mistral and Nvidia's model offerings are part of the same shift. Consultant McKinsey reckons the market for sovereign models, data and tooling could reach $100 billion to $140 billion by 2030.
Governments face the hardest dilemma. Most states lack the money, computing power and expertise to train competitive models independently. Countries that lack capital may trade high-quality domestic data for access, as Iceland did in its partnership with OpenAI for language preservation.
Richer countries can go further. India's information technology ministry chose local startup Sarvam AI to develop the country's first indigenous foundation model. South Korea provides funding, processing power and data-centre support under a national "Sovereign AI Foundation Model" project. Japan has bought thousands of Nvidia's latest chips to build homegrown foundation models for robotics and other uses.
Even so, sovereignty rarely means full independence. Countries still rely heavily on adapting American-made open-weight models. Data from the Center for a New American Security shows that Meta’s Llama family appears in 36% of projects, ahead of France’s Mistral and Alibaba’s Qwen.
Countries outside China and the United States may therefore need to cooperate. Project Tapestry, backed by the AI Alliance and advised by former Meta chief scientist Yann LeCun, aims to let countries and institutions co-train an open base model while keeping sensitive data local and building sovereign derivatives. These efforts may increase control, but they will take time.
Open-weight AI will therefore not kill proprietary models, just as the open-source Linux operating system did not spell the end for Microsoft or Oracle. But the shift may reduce the routine enterprise work customers send to OpenAI and Anthropic, crimping their pricing power. What began as a choice between cheap open models and expensive closed ones is becoming a contest between competing forms of dependence. Companies and governments will discover that a perfect AI hedge remains expensive and elusive.