To Ban or Not Ban Chinese Open-Weight AI Models


15ed1bd6e6339656a72f911c8a4cbfd09122992a4db5c1e53e1b9a308f2904af.jpg

Should the US ban American companies from using Chinese open-weight AI models?

That is the ugly question.

US officials have openly expressed concerns and a desire to implement regulations. The technology community has aggressively responded, with over 20 leading AI companies, including Microsoft, Nvidia, Meta, and Dell, urging legislators not to rush imposing restrictions on open-weight AI models.

The risks are obvious, given that developers may include backdoors, harmful code, remote surveillance or controls, and other nefarious capabilities. Such activities have already manifested in other technologies, such as various network devices and software that have been banned by the US government for certain critical infrastructure sectors, including the military-industrial base and government agencies.

Open Models are Akin to Open Software

But these risks are not unique to open-weight AI models, as they are part of the broader supply chain problem. Such risks are present in proprietary products, software, and services. To a lesser extent, they also exist in open-source software projects which are widely used in code development and online services. The risk is less because others can see, test, and validate open-source contributions. The risk remains because the vast amount of code being released and contributions being submitted cannot reasonably be checked every time a change is made. Malicious abuse of open-source projects is a real threat.

If the US government is considering restricting domestic companies from using Chinese open-weight AI models, then they should also apply the same restrictions to all open-source code, dependencies, and contributions originating from China, its allies, or those they may influence.

That would be enormous and potentially impossible.

Such regulations would greatly slow or stop innovation momentum by US companies. It would create a tremendous burden, both financial and time-to-market, to evaluate and understand the risks. It would hamper legitimate contributions by technical experts to projects and restrict US organizations from using some of the most forward-thinking code and ideas. The same could be true for open-weighted AI models.

Managing the Risks

The cybersecurity industry is challenged to manage the risks either way. Yes, limiting AI products that might be malicious reduces risks, but open-weight AI models are also important to the cybersecurity industry. In a recent incident where OpenAI’s latest model autonomously went rogue during a test, broke out of its containment, and attacked a fellow US company, Hugging Face, the victim’s cybersecurity team had no option other than using a Chinese open-weight model to remedy the situation.

This is a complex and nuanced situation. There are risks, but there are also benefits that are highly desirable. It is a double-edged sword.

If regulation is pursued, it should establish clear goals that are attainable and sustainable in the rapidly evolving world of AI development. The objectives must consider the long-term impacts on US innovation, leadership, and competitiveness.

A sweeping ban would likely do far more harm than good and would ignore the other compensating controls that could manage risks to an acceptable level. A narrow ban would likely be ineffective in scope, easily circumvented, and an unnecessary burden to US organizations, giving Chinese counterparts an advantage. It is important to consider that a US ban would not limit Chinese firms in their use of open-weight models nor their pursuit of leadership in the AI fields. In fact, it may provide significant benefits to them.

Viable Proposals or Just Fear

Thus far, I have yet to see an intelligent proposal that reasonably helps reduce the risks while not unreasonably impeding the social, economic, or technological benefits.

There may be an optimal middle ground. Limiting the use or mandating specific controls for open-weight model use by highly targeted sectors, such as core US government departments and agencies, the military defense industry, and specific critical infrastructures, might be a plausible path.

Overall, the burden of proof must be on those seeking to implement open-model regulations to show meaningful risk avoidance while not undermining the economic and technological leadership innovation of US entities. Such regulations and the supporting research would need to be carefully developed and vetted by a consortium of public and private experts. Any US regulation would be more meaningful if it was also adopted by US allies. A low likelihood at best, given the current political climate and differing perspectives on priorities.

In the US, the most likely outcome will be not to impede innovation or undermine the interests of major corporations, as it could have catastrophic financial consequences and undermine America’s strategic pursuit of AI global leadership. Any other path forward would require an unprecedented level of collaboration among industry, government, and international allies.

How do you rate this article?

7


Matthew Rosenquist
Matthew Rosenquist

Cybersecurity Strategist specializing in the evolution of threats, opportunities, and risks in pursuit of optimal security for our digital world.


Cybersecurity Tomorrow
Cybersecurity Tomorrow

Cybersecurity strategy perspectives for the emerging risks and opportunities of securing our digital world. The insights of today will lead to tomorrow's security, privacy, and safety foundations.

Publish0x

Send a $0.01 microtip in crypto to the author, and earn yourself as you read!

20% to author / 80% to me.
We pay the tips from our rewards pool.

Page not displaying correctly?