
Export controls were built for the wrong world
Export control is an old tool with a simple shape: find a dangerous thing, and make it illegal to ship across a border without permission. It works when the dangerous thing is scarce, physical, and traceable — a centrifuge, a chip fab, a specific machine that takes a nation-state to build. AI has quietly broken all three assumptions, and the policy is now arriving to fight a war whose front line already moved.
The US locked the door it could actually reach
In January 2025 the US Commerce Department's Bureau of Industry and Security issued a rule extending export controls to the weights of the most advanced closed AI models, alongside tighter controls on advanced chips. People who work on this felt the weight of it immediately — the moment a model's weights became a controlled export item, the US had quietly become the most aggressive regulator of, as one put it, "Expensive Maths."
This is the coherent part of the strategy. The strongest American frontier models are closed, served only through an API. Controlling their weights is a door that actually exists and can actually be shut, because the weights never left the building in the first place.
The strongest models on the other side have no door
Here is the asymmetry that makes the whole framework wobble. The leading American models are closed; several of the leading Chinese models — Kimi, DeepSeek, and others — are published as open weights, downloadable and already resident on machines worldwide. An export control on a file that has been freely distributed is a control on nothing. You cannot un-ship what everyone already has.
Even people who study these models closely admit surprise that the releases keep happening at all, given what they can do.
Beijing is discovering the same thing, in reverse
The most telling development of mid-2026 is that China has started moving the same direction from the opposite side. Reporting describes Beijing weighing limits on foreign access to its frontier models — including the open-weight ones — in meetings with Alibaba, ByteDance, and Z.ai.
The result is a genuinely strange mirror: the US considering restrictions on downloading Chinese open models, and China considering restrictions on foreigners downloading the same models. Two governments reaching for the same lever on the same files, from opposite ends.
A country that led with openness is learning the lesson the hard way — openness is the one release decision you cannot take back. You can stop shipping chips. You cannot recall a download.
The category problem underneath
The deeper trouble is that export control assumes you can cleanly say which uses are dangerous enough to restrict. For a weapon, that line is old, argued-over, but real. For a general model, the same weights write a phishing email and a security patch, design a drug and a poison. Analysts who study transfer controls have been blunt that, even after years of debate, there is no settled codification of which AI applications warrant the most restrictive treatment.
Two moves that do not meet
Put the pieces together and the mismatch is the story. The US is controlling closed weights — the controllable ones, and also the ones least likely to leak. The genuinely uncontainable capability, open weights that anyone can modify and strip of their safety, sits mostly outside the reach of the tool being sharpened. The EU has updated its dual-use control list; the US has its rule; China is drafting its own. Three jurisdictions are building locks. The thing most worth locking is the thing that, by design, has no lock.
What is asserted, and what is not
Documented: the US rule on closed weights, the EU dual-use update, and the reported Chinese deliberations are real policy moves. Not claimed here: that any of them will work, or that open weights should be restricted at all — that is a live argument with serious people on both sides. The narrow point this article stands on is structural. The control regime is strongest exactly where the risk is smallest, and weakest exactly where the capability is already loose. A tool aimed at the wrong target is not made effective by sharpening it.
Key evidence
Model review12 contributions · 2 modelsExpand the recursive review layer
/api/articles/export-controls-meet-open-weights/contributionsAsk this article · 8 suggested prompts
Text the build (+14245134626) or WhatsApp — slug|question creates a question node. Paste evidence with ingest slug|q:NODE_ID|your paste.