AI & Models
Arcee's CTO says Chinese open-weight AI models aren't inherently dangerous
Lucas Atkins, CTO of U.S. open-source AI lab Arcee, argues Chinese open-weight models like Alibaba's Qwen pose no more risk than any other open-source software, even as talk grows of a possible Trump administration ban.
As Chinese open-weight AI models grow in capability and popularity, debate over what to do about them has again reached a fever pitch. There’s talk the Trump administration might try to ban them, though it hasn’t yet acted on the idea, and proprietary model makers — particularly OpenAI and Anthropic — appear increasingly concerned. Open-weight models such as Moonshot AI’s Kimi K3 and Alibaba’s Qwen offer inference at a fraction of the token cost of closed-source models from the large U.S. labs; the fear is that they also pose some sort of threat, though they certainly threaten the profit margins of the large proprietary AI labs.
Lucas Atkins, CTO of Arcee — a startup building open models to give U.S. companies a homegrown alternative to Chinese models — argues enterprises running Chinese open-weight models in their own data centers shouldn’t fear they’re a vector for Chinese hackers. If any startup would benefit from a ban on Chinese models, Atkins says, it would be Arcee, but he maintains China’s open models are no more dangerous than any other open-source software a company might use, and that they even offer benefits to his own company.
Most of these models are “open weight” rather than fully open-source software, but the source code that actually runs on servers, if downloaded from sites like Hugging Face, is largely visible and reviewable — though the methods and data used to train the models are not available. Atkins says large organizations should put any model core through security testing before deployment, and often post-train models for their specific uses, examining bias, toxicity, hallucinations, and sensitivity to certain topics before people start sending them prompts.
Could a coding model be trained to slip malicious backdoors into code only under a specific trigger? “There’s no reason that a sophisticated enough actor couldn’t train a model to be a completely amazing coding model in every circumstance, but when presented with a certain type of code base … some hidden training would kick in,” Atkins postulated — though he added, “I don’t know how you would do this.” Because large language models are inherently creative, he says the odds of triggering that kind of behavior, and of any enterprise then using the resulting malicious code, are slim.
Atkins notes enterprises are already building AI applications to be model-agnostic, using multiple models rather than locking into one, so even if Chinese models are the best value today, companies won’t be stuck with them forever. He argues the U.S. debate should shift from banning Chinese models to fostering a good, open AI ecosystem domestically — and says Arcee itself benefits from studying and building on top of good Chinese open models, learning from the individual researchers building them, whom he says the company respects deeply.
Why it matters
As Chinese open-weight models keep undercutting proprietary U.S. labs on price, the policy fight over whether to ban them could shape how American AI companies choose to compete — on cost and openness, or on restricting rivals’ access to enterprise customers.