Enterprise AI is moving onto servers companies own. The strongest models built to run there come from Chinese labs, and the West has not governed what that means.
In January, a federal judge in the Southern District of New York ordered OpenAI to hand over twenty million de-identified ChatGPT conversations to news organizations suing it for copyright infringement. OpenAI could comply because the conversations lived on its own servers. That is the condition of hosted AI: the record sits with the provider, and control over it passes to whoever a court names. The sample came from consumer accounts, but the principle reaches any company that runs its thinking through someone else’s infrastructure.
Satya Nadella has given the cost a name. In a July essay, he calls it the Reverse Information Paradox: a buyer of hosted intelligence pays twice, once in cash and again in the proprietary knowledge the model absorbs to become useful. Every prompt and correction teaches the provider’s system something about the customer’s business. Run the model on hardware you control, and both the record and the learning stay inside your gates.
This is why enterprise demand is moving toward open-weight models, the ones whose trained parameters can be downloaded and run on hardware a company owns. The hardware arrived this year at every scale, from laptops running 120-billion-parameter models on Nvidia’s RTX Spark to corporate GPU servers running larger systems with no hyperscaler in the loop.
The problem sits in the AI scoring leaderboard. On the Artificial Analysis Intelligence Index in mid-July, Moonshot’s Kimi K3, a 2.8-trillion-parameter model with open weights due July 27, ranked fourth in the world, behind only Anthropic’s Fable 5 and two configurations of OpenAI’s GPT-5.6.
Z.ai’s GLM-5.2 leads the models whose weights are published, ahead of DeepSeek’s V4 and MiniMax’s M3. Release by release since 2025, the strongest open-weight models have come from Chinese labs.
Closed frontier vs. the open tier. Source: Artificial Analysis Intelligence Index (v4.1), mid-July 2026; company announcements.
That lead is now state policy.
Opening the World AI Conference in Shanghai on July 17, Xi Jinping urged countries to seize the opportunity of open-source AI, cast China as a supplier of AI public goods, and welcomed a new World AI Cooperation Organization that twenty-nine countries had set up a day earlier, headquartered in Shanghai. Ben Thompson reads the move as commoditizing your complements: give the model away, and value flows to the physical industries (robotics in particular) built on top of it, where China leads.
Most companies never needed a frontier generalist AI model anyway. A logistics firm’s model does not have to design rockets. Fine-tune a smaller open model on your own data and you get a system that beats a hosted generalist at your actual work, fits on hardware you own, and keeps the training signal inside the company. The Western side is moving there too. Mira Murati’s Thinking Machines released Inkling, a 975-billion-parameter open model under Apache 2.0, the largest Western open-weights release to date, but it still significantly trails the Chinese flagships. Palantir’s Alex Karp told CNBC that enterprises are shifting to open weights for cost and for control over their models, data, and compute.
Western controls do not reach any of this.
Germany, Italy, Australia, and several US agencies moved against the DeepSeek app because it sends what users type to servers in China. An open model running on a company’s own hardware sends nothing anywhere.
Export controls target chips entering Chinese data centers. How they apply to a Chinese model file sitting on a server in Frankfurt is unsettled. With the new cooperation organization, Chinese open models now travel through diplomatic channels that no app-store ban touches.
What remains, once data movement is off the table, is the model itself: its provenance and lineage. Lineage runs through distillation, which is training a new model on the outputs of a stronger one. Western frontier labs forbid distillation in their terms of service, which cuts Western open-source AI model builders off from the best teachers. In contrast, Chinese labs distill the American frontier anyway and face little enforcement. Thinking Machines has disclosed that Inkling’s training drew on Moonshot’s Kimi K2.5. The chain now runs Western open models learning from Chinese ones, which learned from an American frontier that Western builders are barred from using.
Read through the trust-intelligence-power triangle, the shift is structural. The West competed on Intelligence, treating the best model as the prize. Self-hosted inference ends that scarcity, and advantage drains toward the layers that stay scarce: the Power under the model and the Trust the model carries. The West leads on Power and on the closed AI frontier. It has not governed the Trust layer of the open models that companies can own outright, and those are Chinese.
The response works across all three layers.
On Intelligence, compete for the self-hosted tier: legislation making training data fair use, and barring terms of service that forbid distillation, would let Western open models learn from the Western frontier at the source.
On Trust, govern provenance where models are distributed and bought: platform catalogs such as Microsoft’s Foundry Local can disclose what a model was distilled from and who modified it, with CAISI authoring the standard and binding directives keeping unvetted weights off federal systems.
On Power, move safeguards from the network to the model: self-hosted inference leaves little traffic to inspect, so evaluation and red-teaming of the weights become the checkpoint, work CAISI and the United Kingdom’s AI Security Institute already run.
For years, sovereign AI was governed at the central facilities: a data center you can locate, a chip you can license, a cloud account you can subpoena. A growing share of intelligence now runs past all three, on hardware that companies own precisely to keep their data and their learning to themselves. The motive is sound. The gap is that the models best suited to fill it carry a provenance the West has not measured.
Every organization will own its AI. The West should make sure that what gets owned is something it helped build.
A note on independence: All opinions shared in this newsletter are my own and do not reflect the views of dmg events, ADIPEC, or any affiliated organizations. This is personal analysis, not institutional positioning.
Sources
• Judge orders OpenAI to produce 20M ChatGPT logs (Bloomberg Law)
• Nadella, “The Reverse Information Paradox” (essay)
• Nvidia RTX Spark and Windows AI runtime (Windows Blogs)
• Artificial Analysis Intelligence Index (leaderboard)
• Moonshot Kimi K3 closes gap with US rivals (Bloomberg)
• Alibaba previews open-weight Qwen3.8-Max (The Decoder)
• Xi promotes open-source AI at WAIC Shanghai (US News)
• World AI Cooperation Organization, 29 founding countries (Quartz)
• Thompson, “Who’s Afraid of Chinese Models?” (Stratechery)
• Thinking Machines releases Inkling open-weights model (SiliconANGLE)
• Karp: enterprises shifting to open-weight models (CNBC)
• Palantir + Nvidia Nemotron for sovereign environments (Business Wire)
• Germany asks Apple, Google to block DeepSeek app (CNBC)
• CAISI evaluation of DeepSeek finds shortcomings and risks (NIST)
• The TIP (trust-intelligence-power) stress-test framework (Sovereign Compute)



Excellent analysis!
Strong piece, Ivan. The Trust layer also has to survive inference. Once weights are inside an institution, the consequential object is often the account they produce: what sources shaped it, what was inferred, who authorised reliance, where it travelled, and whether later corrections reached every derivative. Self-hosting can improve custody while leaving the chain of meaning broken. Digital Narrative Care is building assurance for that downstream institutional-memory layer.