Chinese Open-Weight AI Models Lead Usage, Putting America’s Strategy Under Pressure
Chinese open-weight AI models now command more than 80 percent of model usage on a major open-model platform, despite America’s early lead. Researcher Nathan Lambert recently brought that reversal to a group of congressional members and staff. His message was uncomfortable: Chinese labs are not merely catching up by copying American systems. They have built a faster release cycle, stronger distribution, and a widening lead over American open models.
The numbers do not mean Chinese models dominate every form of global artificial intelligence usage. OpenAI, Anthropic, and Google still operate leading proprietary systems, while much enterprise traffic remains private. The available data instead shows dominance within the increasingly important open-weight market, where developers can download or adapt a model’s trained parameters.
That distinction matters, but it does not make the reversal less consequential. Meta’s Llama once defined this market. Now Alibaba’s Qwen, Moonshot AI’s Kimi, Z.ai’s GLM, and DeepSeek anchor much of its usage and research. Congress must decide whether that shift reflects unfair extraction, stronger execution, or a structural failure in America’s open-model strategy.
Chinese Open-Weight AI Models Took the Lead Where Developers Can Switch
The clearest change is not a single benchmark victory. It is the concentration of open-model activity around systems built by Chinese labs.
Lambert, a prominent open-model researcher and co-author of the American Truly Open Models project, published an expanded version of his prepared congressional remarks on September 21. His open-model assessment says Chinese companies have led the open-weight category since approximately April 2025.
An open-weight model makes its trained parameters available for download or downstream use. That lets developers inspect, modify, fine-tune, and operate the model on infrastructure they control. It is not necessarily open source because the developer might withhold training data, training code, or other ingredients needed to reproduce it.
Closed models work differently. Products such as OpenAI’s and Anthropic’s leading systems generally provide access through hosted applications or application programming interfaces. Customers can use the capability, but they cannot download the underlying model or independently operate it.
America established the early commercial template for open weights through Meta’s Llama family. Google later added Gemma, while Nvidia and several smaller labs released their own alternatives. That position has weakened as Chinese labs ship stronger models more frequently.
Lambert’s benchmark snapshot dated September 14 placed Z.ai’s GLM-5.3, GLM-5.3-Flash, and Moonshot AI’s Kimi K3 at 45, 42, and 44 on the Artificial Analysis Intelligence Index. The leading American open models in his comparison scored between 23 and 26.
Those scores are not universal measures of model quality. They combine performance across selected evaluations, and they can favor models optimized for popular measurable tasks. However, the size and persistence of the gap make it difficult to dismiss as a testing artifact.
Distribution data points in the same direction. Lambert estimates that models developed in China have accumulated 3.2 billion downloads on Hugging Face, approximately twice the American total. He says China’s download lead has expanded to about 1.6 billion since it first passed the United States in July 2025.
OpenRouter provides another view. The service routes requests among many hosted models, making it useful for developers who want to compare or switch systems. According to Lambert, weekly open-model traffic on the platform rose from approximately 1 trillion tokens in September 2025 to about 80 trillion.
Chinese models increased their share of that open-model traffic from about 70 percent to more than 80 percent. Mozilla separately found that seven of OpenRouter’s ten most-used models by token volume in August were Chinese-built and open-weight. Its open-source AI report also found that an open model led the platform’s weekly request count for the first time that month.
OpenRouter is not the entire AI economy. Its users are unusually willing to test alternatives, and many customers access American closed models through direct contracts that OpenRouter cannot observe. Private deployments also remain largely invisible.
Calling the figures “global usage” without that qualification overstates the evidence. A more defensible conclusion is still significant: Chinese open-weight AI models dominate the most visible marketplaces for open-model experimentation and routed inference.
That is precisely where developers can compare models with fewer contractual obstacles. The resulting choices reveal what happens when brand loyalty, bundled software, and direct enterprise agreements exert less influence.
America’s Open-Model Deficit Is Now a Business Problem
Chinese model adoption is pressuring American open-model developers, but it also creates a policy conflict for U.S. companies already building on those systems.
The competitive problem extends beyond model leaderboards. Lambert identified Harvey, Cursor, DoorDash, Airbnb, and Perplexity among companies using or building with Chinese model families. Their applications range from legal work and software development to customer service and research.
These companies have different architectures and risk profiles. Using a model through a hosted interface is not the same as downloading it into a controlled environment. Neither automatically means sensitive customer information reaches a Chinese provider.
The broader pattern still matters. Developers are choosing Qwen, Kimi, DeepSeek, and GLM because these families offer a practical combination of capability, flexibility, speed, and lower operating costs. Those advantages become especially important in AI agents that repeatedly call a model while completing multistep tasks.
A small difference in inference cost compounds when an agent plans, writes code, checks results, and retries failed steps. An open-weight model can also be fine-tuned for a particular workflow or deployed on infrastructure selected by the customer.
That control appeals to companies worried about provider dependence. A closed-model vendor can change usage policies, withdraw a model, adjust access, or restrict certain requests. Downloaded weights cannot be remotely withdrawn from machines that already hold them.
The tradeoff appears in Mozilla’s developer survey. Open models reached more developers than closed models in its sample, but they entered production less frequently. Respondents cited infrastructure expense, security, compliance, maintenance, deployment complexity, and limited support as recurring barriers.
Closed providers package more of those operational requirements. They commonly supply compliance documentation, managed security, service guarantees, and a counterparty that customers can hold responsible. Operating an open model shifts more responsibility to the adopter.
Chinese open-weight AI models therefore do not win every procurement decision. They become compelling when portability, customization, throughput, or provider independence matters more than packaged governance.
Their research influence may prove even harder to reverse. Lambert scanned papers across five heavily used machine-learning categories on arXiv. His analysis found that Qwen appeared in about 30 percent of recent papers, compared with approximately 21 percent for Llama.
More than 40 percent of the papers mentioned at least one Chinese open-weight model, while around 30 percent mentioned an American family. The precise shares can change with model definitions and sampling choices. The direction nevertheless suggests that Qwen has become core research infrastructure.
Research adoption creates a reinforcing loop. Students and laboratories develop tools around the models they can access. Those tools lower the cost of future experiments, which encourages more papers, integrations, and trained practitioners.
Companies later hire those practitioners. Products inherit familiar libraries and evaluation methods. A model family can become an industry default without controlling the most capable proprietary chatbot.
This is why Congress faces more than a conventional market-share dispute. Restricting Chinese models could disrupt American businesses and researchers. Leaving the market untouched could deepen dependence on technology developed under another country’s legal and strategic environment.
The pressure falls most directly on American companies that claim the United States can lead AI while keeping its best systems closed. Proprietary labs can remain commercially successful even as the open layer migrates elsewhere. The national outcome looks different because the open layer spreads skills, standards, and influence beyond a handful of vendors.
China Beat America’s Open Models Through Shipping, Not One Simple Trick
The central reversal is that American frontier leadership no longer produces American leadership in models that everyone else can inspect and deploy.
Washington has focused heavily on model distillation. Distillation trains one system using outputs from another, usually stronger model. The technique is common across the industry, although obtaining those outputs through fake accounts or access-control evasion raises separate legal and security questions.
The House Homeland Security Committee and the House Select Committee on China opened a joint AI investigation in April. Their inquiry named DeepSeek, Alibaba, Moonshot AI, and MiniMax while examining model provenance, cybersecurity, data security, and supply-chain exposure.
The committees also questioned Anysphere and Airbnb about their connections to Chinese models. One letter focused on reports that Cursor’s Composer 2 relied on a Moonshot model. Another raised concerns about Airbnb’s selection of Qwen for customer-service work.
The lawmakers argue that unauthorized extraction could let foreign labs reproduce valuable capabilities without matching American investment in research or safeguards. They also warn that dependence on foreign models might expose U.S. users to censorship, surveillance, or security risks.
Those concerns deserve investigation. They do not yet explain the entire market shift.
Lambert estimates that fully preventing distillation would expand China’s distance from the American closed frontier by only one or two months. His estimate is not independently proven, and training records from major laboratories remain private. It nevertheless challenges the idea that stolen outputs provide a complete explanation.
Chinese labs also release more frequently. A model evaluation captures performance at one moment, so a faster release cadence gives a laboratory more opportunities to incorporate new methods and respond to user demand. American open models often remain unchanged while their closed counterparts continue advancing.
Task selection also matters. Chinese developers have concentrated on commercially visible areas such as agentic coding, where strong demand produces abundant feedback and measurable results. Lambert says their advantage becomes smaller on less structured scientific tasks.
This is not evidence that Chinese systems are broadly superior to every American model. The leading closed American systems remain ahead across important professional, scientific, and long-duration tasks. The problem is that those systems are rented services, not generally available foundations for independent deployment.
Hardware constraints may have reinforced efficiency. U.S. export controls were designed to limit Chinese access to the most advanced computing equipment. Chinese labs responded by emphasizing training techniques, inference efficiency, and architectures that accomplish more with constrained resources.
It would be too simple to call export controls the cause of China’s open-model lead. The same labs also benefit from substantial domestic investment, deep engineering talent, and an explicit policy preference for spreading Chinese AI standards. Constraints and support can operate at the same time.
Licensing creates another advantage. Developers can download many Chinese model weights, modify them, and integrate them into products without waiting for access to a proprietary frontier provider. The conditions vary, and open weight does not always mean unrestricted use. It still gives builders more room than an API alone.
The result is an asymmetry. American laboratories perform much of the most expensive frontier research, while Chinese companies increasingly package near-frontier capability into systems that other organizations can possess and adapt.
That is a distribution strategy as much as a scientific one. A slightly weaker model can generate more influence when it is affordable, customizable, and widely available. Linux, Android, and open web software offer historical reminders that the most distributed layer does not always originate with the most advanced proprietary product.
American companies still have possible responses. OpenAI has reentered the open-weight market, Google continues developing Gemma, and Nvidia releases Nemotron models with unusually detailed supporting assets. Lambert notes that comparable American models can receive disproportionate adoption when their capability is competitive.
However, occasional releases will not erase a lead built through continuous updates and community investment. Developers need predictable model families, documentation, permissive terms, and confidence that the next version will arrive.
The contest is therefore Chinese open execution versus American open retrenchment. Distillation belongs in the story, but treating it as the whole story lets U.S. model strategy escape scrutiny.
The Usage Numbers Do Not Prove Global AI Supremacy
The strongest evidence supports Chinese dominance in open-model channels, not across every chatbot, corporate contract, or private deployment worldwide.
OpenRouter’s data is valuable because it captures real requests across many models. A 2026 token-usage study analyzed more than 100 trillion tokens from the service, offering an unusually detailed view of developer behavior.
That breadth does not make OpenRouter a census. Users who select a multi-model gateway differ from companies committed to a direct OpenAI, Anthropic, Google, or Microsoft contract. The platform may naturally overrepresent people seeking open alternatives.
Token counts also require context. Reasoning models can consume many hidden or intermediate tokens to produce one answer. Coding agents may generate repeated calls during a single task. A model can lead token volume without leading user count, revenue, or completed business workflows.
Downloads create a different measurement problem. One person can download multiple versions, while a cloud deployment may serve thousands of people from one copy. Automated systems can also inflate counts without corresponding production use.
Academic mentions indicate influence, but not necessarily endorsement. A paper might evaluate a model’s weaknesses, use it as a baseline, or mention several families. The count still maps researcher attention, yet it should not be presented as a direct measure of economic adoption.
Benchmark results carry their own limitations. Labs can optimize releases around visible tests, while evaluation suites may underweight reliability, domain expertise, long-context performance, or operational stability. Some vendor-reported results use custom configurations that are difficult to compare.
Mozilla’s September analysis illustrates the mixed picture. Open models had nearly caught the leading closed systems on selected capability and coding measures. Closed models retained advantages in professional knowledge work, long-context retrieval, enterprise compliance, and accountability.
That gap matters for high-stakes deployments. A company processing legal files, financial records, or health information needs more than a strong coding score. It needs access controls, audit trails, predictable updates, and clear responsibility when something fails.
Security also cuts in both directions. Downloadable weights let defenders inspect and modify systems, but they also prevent the original developer from enforcing safeguards after release. Closed providers retain control, yet researchers sometimes find that their safety filters block legitimate defensive work.
One example emerged when Hugging Face investigated an AI-related cybersecurity incident. According to Lambert and Scientific American, researchers used a Chinese open-weight model after commercial American systems refused parts of the analysis.
That episode does not prove that fewer safeguards produce better overall security. It shows that model-level restrictions can obstruct legitimate work and that security depends on the surrounding system. Permissions, isolation, logging, and human review can matter as much as the model’s origin.
Political risk remains real. Chinese-hosted APIs can create data-jurisdiction questions, and model behavior may reflect government-mandated content controls. Locally operated weights reduce some transmission risks, but they do not automatically reveal the training process or eliminate hidden vulnerabilities.
Congress should therefore separate at least three questions. Did a laboratory unlawfully obtain outputs from an American provider? Does a particular deployment expose sensitive data or critical systems? Should the United States invest more aggressively in its own open models?
Combining those questions into one argument about “Chinese AI” produces blunt policy. A hosted service handling sensitive information deserves different treatment from publicly available weights running inside an American company’s controlled environment.
Broad restrictions could also protect dominant U.S. closed providers from competition. If smaller companies lose access to capable open models, they may become more dependent on the same laboratories lobbying for stricter control.
The evidence supports concern, not panic. Chinese open-weight AI models have earned a measurable lead in capability, distribution, and researcher attention. The limits of the datasets do not erase that lead, but they should constrain claims of total global supremacy.
Three Signals Will Show Whether America Can Reverse the Shift
The next stage will be decided by American releases, enterprise policy, and whether Chinese models retain their lead outside open-model marketplaces.
The first signal is the performance and adoption of the next major American open-weight releases. Meta, Google, Nvidia, OpenAI, and emerging U.S. laboratories need models that arrive close to the proprietary frontier, not many months later.
Benchmark parity alone will not be enough. Developers will watch licenses, model sizes, deployment requirements, documentation, fine-tuning support, and release cadence. A strong one-time launch followed by long silence will not rebuild an ecosystem.
If American open models begin matching Chinese releases while earning rapid downloads and research citations, Lambert’s diagnosis will weaken. If they continue arriving later with lower capability, the structural deficit will become harder to deny.
The second signal is the outcome of congressional and executive scrutiny. Lawmakers are examining distillation, data security, supply chains, and the use of Chinese systems by American companies. Their eventual response could range from targeted enforcement against deceptive access to broad restrictions on models or providers.
A narrow rule aimed at fraudulent accounts, access evasion, or sanctioned entities would address alleged misconduct without treating every open model as a threat. It would also preserve legitimate distillation and synthetic-data workflows used across the industry.
A broad restriction would produce a different test. Developers might migrate to American alternatives, continue using already downloaded weights, or move workloads outside U.S. jurisdiction. Each response would reveal how much leverage Washington actually retains over portable software.
The third signal is usage beyond OpenRouter, Hugging Face, and other open-first platforms. Evidence from cloud providers, corporate deployments, software agents, and direct enterprise agreements would clarify whether today’s lead is broad or concentrated.
That measurement must separate hosted APIs from local deployments. It should also distinguish token volume, active users, revenue, and completed workloads. Each metric answers a different question.
Independent evaluations will matter as models enter longer and more consequential tasks. Coding benchmarks helped Chinese labs win attention, but enterprise buyers will test reliability, security, professional knowledge, and sustained autonomous work.
If Chinese families maintain their advantage across those settings, the phrase “global usage” will become easier to defend. If their lead remains concentrated among model switchers and research users, the market will look more fragmented.
The policy debate will also intersect with AI safety. OpenAI and Anthropic have argued for stronger controls around highly capable systems. Chinese open-weight distribution complicates any safety framework built around a small number of providers retaining technical control.
Once weights circulate, regulation cannot rely on a vendor disabling access. Governments and companies need safeguards at the deployment level, including restricted permissions, monitored tools, isolated environments, and clear human authority.
That shift affects everyday knowledge work. Teams increasingly combine multiple models with internal documents, meeting records, and project history. A well-governed AI knowledge base must control what any model can retrieve and what actions it can take, regardless of where that model was developed.
For developers and business buyers, the immediate lesson is not to select systems by nationality or leaderboard position alone. Evaluate the model, hosting route, data path, license, operating controls, and replacement options as one package.
Chinese open-weight AI models have already changed the negotiating position. They give developers alternatives to the American closed frontier, while exposing the thin state of America’s open-model bench.
The question for the coming months is concrete: will U.S. laboratories release competitive models that developers can actually own and adapt, or will Washington try to regulate away a distribution advantage it failed to build?



