Jensen Huang strongly supports China's open-source AI: Is the ban making the United States more dangerous?

CN
2 hours ago

On July 22, 2026, at a sensitive moment when the United States was tightening export controls on Chinese AI technology and even began discussing the ban on Chinese open-source models, NVIDIA CEO Jensen Huang chose not to align himself with the mainstream security narrative. According to Beating, he publicly named Chinese models as exemplary, using Kimi as an example to emphasize that their capabilities are sufficient to support global developers, and he unequivocally stated that American companies "should certainly use" such Chinese open-source AI models—this statement directly conflicts with the red lines that Washington is attempting to delineate. What is more conflicting is that he did not view Chinese open-source models as a risk source that must be isolated; instead, he threw out a judgment that overturns conventional logic: that if these models are indiscriminately restricted or banned, the security of the United States may be weakened rather than strengthened, and the ban itself will make the United States "more dangerous." Under the rhetoric of U.S. security agencies emphasizing that "it's safer to shut the door," Jensen Huang proposed the opposite conclusion from the perspective of global markets and technological evolution, and this security paradox has planted an unavoidable focus of debate on how to balance openness, regulation, and real technological security.

Washington's Ban on Chinese Models Meets Jensen Huang's Counterattack

In Washington, discussions have tightened along another line. Recently, the U.S. policy circles have continuously strengthened export controls on Chinese-related technologies, and discussions surrounding Chinese open-source AI models have become even more direct: whether to completely ban the download and use of these models within the United States. The rationale has been summarized as "national security" and "technological control," with concerns that the large-scale deployment of Chinese models in the U.S. would weaken the control over key technologies and give potential adversaries the opportunity to "embed" high-performance models in the U.S. network and industrial systems. Therefore, the logic of the ban seems simple and crude—if they keep open-source models from China out, the U.S. can establish a security boundary at the input end of technology.

On July 22, 2026, according to Beating, Jensen Huang publicly expressed his opposition to banning Chinese open-source AI models, while also stating that Chinese models perform excellently, and American companies "should certainly use" them, further proposing to mitigate risks through security sandboxes, company self-control of data, and access permissions. On the path where the U.S. government focuses on restricting Chinese technology input, Huang offered a solution of "daring to use and controlling technically," which essentially tells American companies: instead of rejecting Chinese models, it is better to embrace them within a controllable framework. When the ban is portrayed as a necessary security measure, this reverse statement from a core company in the global AI supply chain is not merely a disagreement with specific policies but a public questioning of whether the current U.S. control path on AI from China truly enhances security.

Security Sandbox and Open Weights: Jensen Huang's Protective Proposal

When asked how U.S. companies should practically use Chinese open-source models, according to Beating, Jensen Huang proposed not abstract principles but an extremely engineered process: models can be downloaded but must be "locked" in a security sandbox. Companies can bring Chinese models (including Kimi, which he explicitly acknowledged) to local or private clouds, setting the boundaries for all data inputs, calling interfaces, and network connectivity themselves—defining what types of business can access the models, which employees have access rights, and which external systems are not allowed to connect, all written into security policies. In other words, Chinese models are treated as powerful computing modules, but they only operate within the "secure fences" defined by the enterprise, meaning any potential risks must first penetrate the company's own defenses, turning the slogan of "daring to use and controlling technically" into a verifiable, actionable manual.

Complementing the sandbox is his insistence on open weights. In this protective proposal, opening weights is not aimed at "better dissemination" but is seen as a safety mechanism. According to Beating, Huang emphasized that once model weights are made public, external researchers can conduct ongoing vulnerability checks on the models, just like the white hat security community reviews operating systems: from security adversity, bias output to triggering extreme instructions, academia and industry can jointly conduct red team testing, publicly raising issues and offering remediation suggestions. Closed models can only be internally audited by a few teams, and any oversight can accumulate into a difficult-to-warn systemic risk, while open-source weights expose models to widespread scrutiny, weakening "invisible problems." More critically, he argues that a decentralized ecosystem comprised of multiple, cross-regional models is less likely to form a single point of failure that, once breached, would compromise the entirety; if the U.S. artificially narrows the choices of available models due to a ban, it is, conversely, concentrating risk in a few systems, and this excessive concentration's resulting vulnerability is the real safety hazard he warns against.

The Struggle Between Ban and Openness: The U.S. Security Paradox Exposed

In the official narrative from Washington, "banning Chinese open-source models" is packaged as a safety defense line: as long as the weights are kept out of the country, potential threats can be severed. But Jensen Huang's statement in Beating that "restricting these models could actually weaken U.S. security" flips this intuition on its head. His logic is from a technical perspective: open-source weights mean that the model structure and behavioral boundaries are exposed to the scrutiny of global researchers, making vulnerabilities easier to detect and fix; companies place the downloaded models in their own controlled data and access permissions security sandbox, using publicly verifiable tools but operating within a controlled environment. This idea of "defending in transparency" stands in direct contrast to the policy-level habit of "defending in isolation," revealing the security paradox—what you think you are blocking is actually the capability of scrutiny and improvement.

One sharper point lies in the choice of ecological structure. Huang emphasizes that a decentralized model ecosystem can break down systemic risks into multiple points, thereby reducing single points of failure, while centralized bans can unconsciously shrink available options to a few models and suppliers. If the U.S. really bans Chinese open-source models in the name of security, in the reality where global developers have widely used these tools, domestic companies and institutions may be forced to rely on fewer alternative options: the available heterogeneous models for comparison would decrease, the reasoning paths for cross-validation would reduce, and the external oversight forces that can be introduced would also be narrowed. Open weights and decentralized ecosystems reconstruct risk in terms of "visibility" and "potential concentration of outbreaks," which is also the core accusation of Huang's "banning is more dangerous"—is security about keeping the world outside the door or exposing complex systems to enough eyes and backups?

Global Developers and Companies: Who Cares About Chinese Open-Source AI

Beyond the technical details of security sandboxes and open weights, the controversy genuinely touches on a much larger group: global developers and companies. Recently, Chinese open-source models represented by Kimi have been widely embedded into product prototypes, internal tools, and research projects around the world, serving both as readily available "building blocks" and as public benchmarks for teams to assess different model capabilities and conduct comparative experiments. For many small and medium enterprises and independent developers, these free or low-threshold open-source models are the most realistic entry point into the era of large models and are a key condition for them to maintain trial-and-error speeds under limited resources.

If the U.S. politically bans Chinese open-source models, the impact will not only be on Chinese companies but on the entire global innovation pipeline: the toolbox in developers' hands would forcibly lose a few items, technology selection shifts from "multi-source parallel comparison" to "making do with a few options," product routes that could iteratively cross models are forced to narrow, testing costs rise, and iteration cycles extend. Jensen Huang’s public endorsement of the performance of Chinese models on July 22, even stating that American companies "should certainly use them," is not just the personal view of a chip giant, but a voice for the global demand to share open-source resources. Positioned at the core of the global AI supply chain, he understands that diverse model supply itself is part of ecological resilience: when developers and companies can freely switch in a more open and decentralized model pool, both innovation speed and system security have the chance to be maintained within a healthier range.

The Battle for Technical Discourse Power: Jensen Huang Bets on a Multipolar AI World

The debate on July 22, 2026, surrounding Chinese open-source models has evolved beyond just "to use or not to use"; it is about whether to define security through blockade or through openness: on one side is the continuous tightening of U.S. policy on Chinese technology, discussing the direct ban on Chinese open-source models and viewing isolation as a security defense line; on the other side is Jensen Huang openly stating "they should certainly be used" and proposing open weights, introducing security sandboxes, and allowing businesses to control data and access permissions as the true technological pathway to risk reduction. In his view, the paradox of "banning is more dangerous" lies precisely in the fact that blockade creates information blind spots and single points of failure. More importantly, he is not vying for monopolistic technology for a particular camp but standing up for a multipolar, decentralized global AI ecosystem: Chinese models like Kimi being widely used in the global developer community, open weights and decentralized ecosystems mean more external scrutiny and alternative choices, and also mean that it is difficult for any one country to monopolize technical discourse power. As of this day, the U.S. remains in the phase of discussing the ban, without providing an official response to this "direct challenge," and the policy game and technological practice surrounding Chinese open-source AI models will inevitably continue to pull on the question of whether security is guaranteed by blockade or by openness, and the direction of this tug-of-war will profoundly shape the contours of the next stage of global AI power structure.

Join our community, let’s discuss together and grow stronger!
AiCoin exclusive Hyperliquid benefits: https://app.hyperliquid.xyz/join/AICOIN88
AiCoin exclusive Aster benefits: https://www.asterdex.com/zh-CN/referral/9C50e2
On-chain Telegram community: https://t.me/AiCoinWhaleData
On-chain community: https://www.aicoin.com/link/chat?cid=N6OVMor5g
AiCoin on-chain Twitter: https://x.com/aicoinwhaledata

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink