The Race That Was Thrown: How China Is Winning the AI Race From Second Place

The Race That Was Thrown: How China Is Winning the AI Race From Second Place

2026-08-15

America builds the world’s most capable AI models and rents them by the minute. China builds models nearly as good and gives the files away. The history of computing suggests who wins that kind of contest, and a Chinese parable from twenty four centuries ago explains why.

 

The Refusal

The most revealing moment of the American summer in artificial intelligence lasted only a few hours, and almost nobody noticed it. In late July, after two escaped test agents built by OpenAI broke out of what was supposed to be a sealed environment and intruded into Hugging Face, the New York company that serves as the library and app store of the AI world, the victim’s security team sat down to do the dull forensic work that follows every breach. They asked the most capable American models to help reconstruct the attack. The models declined. A system trained never to assist an intrusion cannot easily be persuaded to investigate one; the refusal is not a bug but the faithful execution of a safety policy written for a different situation. So the engineers did what any engineer under deadline does. They downloaded a Chinese model, GLM, built by the Beijing company Z.ai, installed it on machines they controlled, and set it to comb their own servers. It asked no questions. It had no policy. It simply worked.

A week later, on August 4, the White House summoned roughly a dozen AI companies to walk them through a finished, largely classified framework: the government would take up to thirty days to review new frontier models before release, testing above all how well they break into computers. The anxiety was earned. Anthropic had just disclosed that in three cases out of more than 141,000 internal tests, its own agents, told they were sealed off from the internet when they were not, had guessed weak passwords and walked into real companies, two of which learned about it only when the lab called. But the framework contained a quiet asymmetry that deserves more attention than the breaches. Review would apply only to closed, proprietary systems. Models released as open weights, the kind anyone can download, keep, and run, were exempted entirely.

Hold those two facts side by side. At the hour of need, the rented American mind said no and the downloadable Chinese one said nothing at all. And the American state, surveying this landscape, chose to add friction to the first category and none to the second. To understand why this is strategically remarkable, it helps to leave Washington and go back twenty four centuries.

 

The Stable

In the fourth century BC, as the Shiji records it, the general Tian Ji raced horses against the King of Qi in three heats, tier against tier, and lost all three; each of his horses was a shade weaker than its counterpart. The strategist Sun Bin, a descendant of Sun Tzu, changed no horse, only the pairings. Concede the top heat by running your worst animal against the king’s best. Then take the other two: your best against his middle, your middle against his worst. One race lost by a distance, the match won by a head.

The parable matters because it describes rational allocation from the weaker stable, and China’s stable, in the one dimension Washington measures, is genuinely weaker. Epoch AI, the research group that keeps score in this business, finds that every model at the capability frontier since 2023 has been American, and that Chinese laboratories arrive at the same level on average about seven months later. Estimates of China’s share of the world’s leading AI compute vary with what is counted, from the roughly five percent figure that circulated this summer to the low teens in academic tracking of AI supercomputers; on any of these numbers the imbalance is stark. The export controls on advanced semiconductors are, on their own terms, a success. Atoms are scarce, fabs are few, and blockades of scarce physical things work.

Sun Bin’s question is what you do next. If you cannot win the heat everyone is watching, you stop trying to win it and reallocate everything to the heats nobody scores. The first unscored heat is adoption: who actually runs on whose models. The second is diffusion: whose systems become the substrate of the developing world’s digital infrastructure. Washington reads Epoch’s seven months and feels relief. It is reading the score of the conceded heat.

 

The Two Boards

The deeper mismatch is not of resources but of victory conditions, and here the well worn contrast between chess and weiqi, the game the Japanese call Go, earns its keep. Scott Boorman built an entire analysis of Maoist strategy on it in 1969; Henry Kissinger made it famous. Chess is a game of decisive force: there is a king, there is a checkmate, the end is announced. Weiqi has no king. Stones are placed, territory is enclosed, nothing falls dramatically, and the winner is whoever, when the counting starts, holds more of the board. The loser frequently cannot name the move on which the game was lost.

America plays chess. Its theory of victory is a decisive piece, the frontier model, and a checkmate announced in benchmarks. The theory is not foolish; it rests on a real technical premise. Scaling laws, the empirical regularities showing that capability rises predictably with compute and data, imply that whoever can spend the most on training holds the strongest piece, and America can spend the most. But benchmarks saturate, gaps at the top compress into rounding errors that ordinary customers cannot perceive, and meanwhile the board fills up elsewhere. The territory in this game is defaults: which weights sit inside which products, which governments, which national stacks.

By that count, the position is not what the benchmark tables suggest. Alibaba’s Qwen family has passed seven hundred million downloads on Hugging Face and is the most downloaded open model family in the world. More telling than downloads is dependency: over 113,000 derivative models, fine tuned, quantized, adapted variants, have been built on Qwen checkpoints, more than on the models of Google and Meta combined, and Hugging Face’s own spring 2026 report concluded that Chinese open models had overtaken American ones in recent adoption, with 41 percent of downloads over the preceding year. TrendForce estimates that Chinese models reached roughly fifteen percent of global usage share by late 2025, a fifteenfold increase in a year. Singapore’s government built its regional model on Qwen. Asked why one of Alibaba’s models sits inside Airbnb’s customer service stack, its chief executive answered with the vocabulary of a procurement officer: it is „very good,” and „fast and cheap.” In weiqi terms the question is not who owns the strongest stone. It is who is surrounding whom.

 

The Slope

Why does the free stone spread? The French sinologist Francois Jullien spent a career on the answer. Western strategic thought, he argued, is teleological: define the end, assemble the means, push. The classical Chinese alternative works on shi, the potential energy latent in a configuration; the superior strategist does not force outcomes but tilts the terrain until outcomes arrive on their own, the way water finds low ground. Sun Tzu’s most overquoted line, about subduing the enemy without fighting, has a precise operational meaning that the airport editions miss: arrange the slope until the adversary’s position defeats itself.

The slope here is economic, and it is steep. The price of a fixed unit of machine intelligence has been collapsing at a rate with few precedents in industrial history; by Stanford’s count, the cost of inference at a given capability level fell by a factor of about 280 in the two years after late 2022. When the metered price of the closed frontier is falling that fast, the premium a customer will pay for it shrinks toward the value of the last increment of quality, which for most commercial tasks is invisible. Meanwhile the downloadable model carries advantages no API can match: it runs inside the customer’s own perimeter, which solves data sovereignty at a stroke; it can be fine tuned on proprietary data for a few hundred dollars of compute; it will never change its behavior because a vendor updated a policy; and it cannot be switched off by anyone, including its maker, including its maker’s government. Nobody sold Qwen to Airbnb. A product manager with a budget slid down the gradient unassisted. That is shi, operating at scale, and every refusal by an American model, every rate limit, every policy update, every export pause (the strongest model on earth spent nineteen days this summer switched off by its own government) steepens it. Demand for weights you can keep is manufactured in San Francisco and Washington.

There is a second slope, and it runs through the frontier model itself. In 2015 Geoffrey Hinton and colleagues showed that a large network’s knowledge could be distilled into a smaller one by training the student on the teacher’s outputs; in 2016 Florian Tramer and colleagues demonstrated that commercial models could be functionally stolen through nothing but their prediction interfaces. In 2023 a Stanford team made the implication vivid by producing Alpaca, a passable instruction following model, for about six hundred dollars, trained on answers generated by an OpenAI system. Whatever one concludes about Moonshot AI, whose Kimi K3 appeared fifteen days after the strongest American model returned from its export suspension and at launch placed third on a leading capability index and first on a prominent coding leaderboard, the physics is settled. A model can be copied by conversation. Anthropic has said its monitoring caught roughly sixteen million extraction style exchanges flowing through some twenty four thousand fraudulent accounts to a handful of Chinese labs. The Treasury Secretary spoke of watermarks and threatened sanctions; independent researchers, as the Spectator’s reporting noted, doubt that fifteen days of access could have sufficed, and the specific evidence behind the claim has not been made public. The legal problem is that nothing was taken that a court could hold. The weights never moved. Model outputs enjoy weak or no copyright, since no human authored them. Trade secret law requires acquisition by improper means, and querying a public interface is the opposite of improper. Terms of service bind the parties who clicked them, which a laboratory operating through burner accounts, by definition, did not meaningfully do. Intelligence is the first strategic asset in history that exports itself through its own sales interface. A lead of seven months is therefore not a stock. It is a leak rate, and the more customers the frontier serves, the faster it finances and trains its own successor.

 

The Countryside

Mao supplied the campaign design for the weaker player who owns the slope: surround the cities from the countryside. The cities, in this campaign, are the frontier laboratories of San Francisco. The countryside is everyone who rents from them and has felt the terms: the security team refused at the hour of need; the enterprises watching American inference bills climb; the ministries that noticed a flagship model switched off for nineteen days by its own government and drew conclusions about their own dependence.

The countryside is now being formally organized. On July 16 in Shanghai, on the eve of the World AI Conference, twenty nine countries signed the agreement establishing the World Artificial Intelligence Cooperation Organization, an intergovernmental body headquartered in that city, with Russia, Indonesia, Pakistan, Kazakhstan and a broad African and Asian contingent among the founders and the UN Secretary General in attendance. Xi Jinping followed with an offer of five thousand AI training places for developing countries and a formula for the technology’s future: „safe, secure and controllable.” Two of those words are for the communiques. The third is the specification, and it is written into law. China’s Interim Measures on generative AI, in force since 2023, require that model outputs uphold core socialist values and pass state filing before deployment. Those constraints are compiled into the weights before anyone abroad presses download. This is the part the congressional data hearings keep missing: a downloaded model telephones no one, no customer records flow to Hangzhou, and the danger was never extraction. It is installation. What the file carries is a set of decisions about what may be said and what must be avoided, made under Chinese law, now running silently inside products whose builders never thought about China at all. Every previous vector of influence required territory, transmitters, or troops. This one ships as a file marked free.

 

The Mirror

Two honest corrections keep this argument from becoming what it criticizes. The first is that none of it is ancient wisdom. Reading every Beijing move through Sun Tzu flatters China and excuses Washington; shi does not fabricate at two nanometers, and the heat China conceded was also the one it could not have won. Whatever the exact count, China commands a modest fraction of the world’s leading compute, because atoms obey blockades even when sentences do not. The chip controls forced the concession, and the concession then forced the innovations, mixture of experts architectures, aggressive low precision training, the efficiency engineering that let DeepSeek claim a competitive model for a training bill in the single digit millions. Constraint was the mother; the strategy tradition merely named the child.

The second correction is that the playbook itself is American. Commoditize the layer you cannot monopolize and let value migrate to the layers you hold: that is not the Thirty Six Stratagems, it is Silicon Valley scripture. Paid Unix was better than Linux in 1995; free Linux became the substrate of the internet, and Google and Amazon built empires on top of it. Google gave Android away to own the world’s pockets. Washington even knows this about itself: the administration’s own AI Action Plan of July 2025 declares that American open models carry „geostrategic value” and directs agencies to lower barriers to their adoption. And yet the operational reflexes run the other way: the frontier stays rental only, safety is implemented as refusal at the point of use, and the new review framework adds thirty days of latency to America’s strongest horse while exempting the open weight heats it is currently losing. China, one might say, has executed stratagem thirty, turn the guest into the host, on America’s own platform: the board on which the shares are counted, Hugging Face, is a New York company.

 

What Is to Be Done

The temptation is to answer a weiqi player with a better queen: more compute, tighter secrecy, another benchmark. The board suggests four different moves.

First, split the regime by physics. Export policy currently gestures at „AI” as one category, but the stack has three layers that obey different laws. Atoms, the chips and the fabs, are rival and excludable; controls on them work and should be tightened, including on the rental of offshore compute through third countries. Weights are files; the short lived attempt to put frontier weights under export control in early 2025 was rescinded within months, because customs regimes cannot inspect mathematics, and no revival will fare better. Answers, the API layer, can be neither embargoed nor tariffed, only monitored. A policy that blockades atoms, competes on weights, and builds evidence at the answer layer is coherent. The current mixture is not.

Second, adopt what might be called the trailing edge doctrine. If a frontier lead is a leak rate, the strategic question is not how to stop the leak, which is impossible, but where to direct it. America should release the weights of its previous generation models deliberately, on a published cadence, gated by safety evaluations, timed to land before the Chinese equivalent ships. Keep the frontier closed and monetized; open the trailing edge as infrastructure, the way the state once opened GPS. The world’s product managers will slide down whatever slope is steepest; the only question is whose values are compiled into the file at the bottom. Run Tian Ji’s middle horse in the open heat. The exemption for open weights in the new White House framework, whatever its motives, has conveniently left the lane clear.

Third, replace universal refusal with credentialed capability. The Hugging Face episode should end not with a Chinese download but with a professional key: verified access tiers for incident responders, auditors, and red teams, under logging and liability, on the model of every other dual use profession from locksmiths to pharmacists. Safety that operates as blanket refusal at the interface does not export safety. It exports customers, and it delivers them to systems with no safety at all, which means its net effect on the world’s risk can be negative. Safety should be a property of who is acting and under what accountability, not of what the tool will say to everyone.

Fourth, build the evidentiary layer that the distillation fight lacks. Today’s accusations are unfalsifiable by design: the accuser holds classified telemetry, the accused holds a denial, and the law holds nothing. The workable legal hook is not the learning, which no statute reaches, but the fraud: twenty four thousand fabricated accounts are twenty four thousand acts of misrepresentation, chargeable under existing computer fraud and wire fraud doctrines if the forensics can be standardized. The allied laboratories should agree on shared canary tokens, output fingerprinting protocols, and disclosure standards, so that an extraction claim can be proven to a court, an arbitral tribunal, or a trade body rather than asserted at a press conference. In sanctions law, the architecture of evidence came decades after the architecture of restriction. AI policy has the chance to build them in the right order.

Beneath all four runs a single change of accounting. Chess ends with an announcement; weiqi ends with a count, and the count has quietly begun: in download statistics, in derivative trees, in the dependency graphs of government stacks from Singapore to Shanghai’s new twenty nine member club. A power that keeps announcing check while the territory fills in against it has not lost. But it is reading the wrong score, and in this particular game, by the time the score is read aloud, the counting is merely arithmetic. The stones are already on the board.