Skip to main content
Live
Main content

Arcee CTO says Chinese open-weight models are not a security threat

Lucas Atkins, whose US lab competes directly with Qwen and Kimi K3, argues a ban would hurt American AI more than help it.

Jaeden Schafer
Editor in Chief · · 5 min read
Arcee CTO says Chinese open-weight models are not a security threat

Arcee, a US open-source AI lab that would stand to gain commercially from any American ban on Chinese models, says such a ban would be a mistake. Chief technology officer Lucas Atkins argues that open-weight models from Moonshot AI, Alibaba, and other Chinese labs are not inherently more dangerous than any other open-source software an enterprise already runs. His position, laid out on July 22, 2026, cuts against the direction of both the Trump administration, which has floated restrictions, and the largest US proprietary labs.

The commercial stakes behind the debate are straightforward. Open-weight Chinese models such as Moonshot AI's Kimi K3 and Alibaba's Qwen deliver inference at a fraction of the token cost of closed models from OpenAI and Anthropic. That pricing gap is squeezing the unit economics of the largest US labs at exactly the moment enterprises are choosing which model families to standardize on. A federal ban would relieve that pressure. Arcee, which builds US-made open models pitched as a homegrown alternative, would be one of the most direct beneficiaries.

Atkins is arguing against the ban anyway. His technical case is that the popular framing — that a Chinese model is like a piece of Chinese software with hidden instructions its makers can activate remotely — misunderstands how models work. A downloaded model runs entirely inside the customer's environment. The lab that trained it has no channel back in.

Key facts

  • 01Arcee CTO Lucas Atkins says Chinese open-weight models pose no inherent security threat to US enterprises running them locally.
  • 02Atkins argues the policy conversation should shift from banning models like Qwen and Kimi K3 to fostering a stronger US open-source ecosystem.
  • 03Open-weight models from Moonshot AI and Alibaba offer inference at a fraction of the token cost of closed models from OpenAI and Anthropic.
  • 04Arcee, which builds US-based open models, would be a direct beneficiary of a ban but is arguing against one anyway.
  • 05Atkins concedes a hidden coding backdoor is theoretically possible but says he doesn't know how one would be built in practice.

The distinction he draws is between open-weight and fully open-source. Most of the Chinese releases are open-weight: the weights and the runnable code are downloadable from Hugging Face and can be inspected, but the training data and training recipes are not. Enterprises can still route these models through the same security testing, red-teaming, and post-training they apply to any third-party dependency, and can measure bias, toxicity, hallucination behavior, and topic sensitivity before a single production prompt is sent.

The subtler worry is a coding model with a sleeper: a system that writes clean code across every normal benchmark but injects a backdoor when it encounters a specific target codebase. Atkins concedes the scenario is not impossible in theory. A sophisticated actor could in principle train that behavior in. He also says he does not know how anyone would actually engineer it reliably, given that large language models are creative and non-deterministic by design. Getting the right prompt-plus-context to trigger the malicious output, and then getting an enterprise to ship that output, is a long chain of coincidences.

There is also a structural argument against lock-in fears. Enterprise AI stacks are increasingly built to be model-agnostic and to route across multiple providers based on task, cost, and latency. Even where Chinese open-weight models are the best price-performance option today, customers are not signing up for a permanent dependency. Swapping models is a config change, not a rebuild.

Atkins reframes the policy question around ecosystem strength rather than exclusion. He argues Arcee itself benefits from Chinese models being good, because the weights and papers surface techniques his team can learn from and build on, and vice versa. He credits the individual researchers behind those labs and says the productive response is competition, not prohibition.

I think instead of the conversation being about how to ban Chinese models, it should be about how do we foster a good, open ecosystem here in the U.S.
Lucas Atkins, CTO of Arcee

The counterweight to his position is coming from the largest US labs and from national-security voices in Washington, who point out that even if today's Chinese open-weight releases carry no smuggled behavior, the supply chain for future releases sits outside US oversight. There is no equivalent of an export-control review for a model checkpoint uploaded to Hugging Face. Whether that gap justifies a ban, a disclosure regime, or nothing at all is the actual live question, and it is not one a single CTO's technical read can settle.

Related · from this week
Alibaba releases Qwen3.8-Max, a 2.4-trillion-parameter model rivaling Claude
Jaeden Schafer · 5 min read →

Arcee's stance matters because it comes from the constituency a ban would most directly protect. When the company most positioned to profit from restrictions tells Washington the restrictions are not needed, and that the better answer is to release a better model, that reframes the debate away from a defensive posture and toward capability. The pressure on US open-source labs to actually ship something competitive with Qwen and Kimi K3 just got a little heavier — and, in Atkins' framing, that is the point.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

Alibaba releases Qwen3.8-Max, a 2.4-trillion-parameter model rivaling Claude
Models

Alibaba releases Qwen3.8-Max, a 2.4-trillion-parameter model rivaling Claude

Alibaba's largest model to date ranks second only to Anthropic's Fable 5 on Arena.AI, with open weights due next week.

Jaeden Schafer5 min read
Chinese AI models Kimi K3 and Qwen3.8 close the gap on OpenAI and Anthropic
Analysis

Chinese AI models Kimi K3 and Qwen3.8 close the gap on OpenAI and Anthropic

Six of OpenRouter's top 10 tools are already Chinese. The latest releases from Moonshot and Alibaba shouldn't be shocking anyone.

Jaeden Schafer5 min read
LLMs believe false claims even when training data labels them as lies
Models

LLMs believe false claims even when training data labels them as lies

A new preprint finds Qwen, Kimi, and GPT-4.1 absorb fabricated facts at an 88.6% belief rate even after explicit negation warnings.

Jaeden Schafer5 min read