Washington once put mathematics on a list of munitions. Through most of the 1990s a strong-enough encryption program was, to the United States government, a weapon; publishing it abroad counted as trafficking in arms, and Phil Zimmermann, who wrote the era’s most popular version, Pretty Good Privacy, spent three years under federal criminal investigation for letting his code leave the country. The government lost. Programmers printed the source in a book, sold it on T-shirts, and argued in court that code was speech. The case was dropped in 1996, the export rules were gutted before the decade closed, and the software they meant to contain reached every corner of the internet regardless.

That fight is being reopened this month, in Mandarin, with the roles reversed. On 21 July the Financial Times reported that China’s Ministry of Commerce has been consulting Alibaba, ByteDance and Zhipu on export controls for advanced AI models: a tiered regime of filing requirements for weaker open-source systems, security reviews for stronger ones, and a possible ban on releasing the most capable at all, with training data and downloadable model weights the things to be kept home. A parallel track would bar foreign fabricators, Qualcomm and TSMC among them, from producing advanced chips based on designs from Huawei, Alibaba and ByteDance. It landed days after Moonshot’s Kimi K3, an open-weight model, took the top of the Frontend Code Arena, the strongest open system shipped so far.

The reflex is structural before it is ideological. Whoever believes he holds the lead reaches for the wall; the instinct to contain a technology belongs to the party that thinks it is ahead, and it matters little whether the flag over the fab is American or Chinese. Beijing spent three years calling this same weapon economic bullying when Washington aimed it eastward. On nearing the frontier, it picks the weapon up. The trouble is that the weapon does not care who is holding it.

A wall around a general-purpose knowledge good does not hold; it only decides who gets to build the substitute.

Encryption is the clean rhyme because it was the same kind of thing: a general-purpose knowledge good, an algorithm cheap to copy that travels as text. Walls hold against objects, against a cargo of oil or a container of magnets, for a while. They do not hold against knowledge, which leaks through every seam a commercial incentive can find, and the incentive to move a frontier model is vast. This column read exactly this wall once already, in July, from the far side, when Washington’s chip embargo was seeding Huawei’s Ascend line faster than it was denying China compute. The mechanism is indifferent to direction. A wall around a general-purpose knowledge good does not hold; it only decides who gets to build the substitute.

What the coverage skips is why a challenger would ever want the wall down. China’s edge in this contest is distribution: it can spread its stack wider and cheaper than anyone, and reach is what converts a good model into a standard. Open weights, cheap Ascend silicon, and WAICO, the governance body built to carry Chinese standards into the Global South, are one strategy, and the strategy is diffusion. A wall reverses it. Keep Kimi K3 home and the coding teams in Jakarta and Lagos who would have built on it build on something else, seeding a foreign substitute and ceding the one prize a challenger actually needs, the standard everyone downstream is forced to adopt. The hoarding reflex is an incumbent’s move, and China is not yet an incumbent.

The hoarding reflex is an incumbent’s move, and China is not yet an incumbent.

The small states in the region are already pricing which stack computes. Singapore is courting both the frontier and the volume line at once, hedging Nvidia’s access against China’s cheaper Ascend build-out; Indonesia and Malaysia, both WAICO signatories, will run whichever silicon their data centres can actually power. For them a Chinese model wall is no abstraction. It decides whether the cheap, open, adopt-me stack stays cheap and open, and a declaration in Shanghai becomes a standard only when the systems they build on are the ones it governs.

So the column commits, and dates it. By 24 July 2027, China will not have imposed a broad, binding, enforced AI-model export regime that materially restricts the outbound diffusion of its frontier models and AI chips to third markets; the consultation stays a consultation, or hardens only into narrow design-fabrication rules that close the TSMC loophole while leaving the open-weight stack free to travel. Confidence sits at likely, around 0.75. The single load-bearing assumption is this: that Beijing still reads itself as the challenger who must win adoption to set the standard. Should it conclude instead that Kimi K3 means it now holds the frontier, the incumbent’s hoarding reflex takes over, and this call breaks. The firms asked to help build the wall have already objected that it would slow them down.1

Zimmermann’s code sits in every browser now, including the ones in Beijing. The wall that was supposed to keep it American taught the rest of the world to write it instead. A knowledge good has never once stayed behind the border of the country that led in it, and the country reaching for the border is usually the one that pays.

Footnotes

  1. Alibaba, ByteDance and Zhipu, the three firms consulted, are reported to have pushed back that tighter rules would slow their own development and weaken China’s chances in the global race. The wall’s designers would be its first tenants.