Washington Is Writing a Ban on Software That Has Already Been Downloaded
Export controls need a chokepoint, and an open-weight AI model does not have one. What the reported crackdown would actually touch — and what to ask before the word "ban" does your thinking.
I should own a bias before I make an argument, because it is the kind of bias that makes a person sound clever while being lazy.
Whenever a government announces that it is going to stop people from copying a file, a small and unhelpful voice at the back of my head says: no, you are not. That voice has been with me a long time. It turned up for CD copy protection, which held for roughly as long as it took someone to notice the shift key. It turned up for DVD region locks. It turned up for the export rules of the 1990s that classified strong encryption as a munition, back when a mathematician was told to register as an arms dealer for wanting to publish his own source code. It turned up for a decade of file-sharing lawsuits aimed at teenagers, which achieved a great deal of misery and very little scarcity.
The voice has a decent track record. It is also insufferable, and I do not entirely trust it — because "you cannot stop people copying things" is an engineering observation, not a moral one. Plenty of things ought to be hard to copy. And the thing that actually flattened music piracy was not enforcement at all; it was a product people preferred at a price they would pay. The reflex is right about mechanics and often wrong about consequences.
So when the news landed this week, I felt the reflex fire — and then I went and read the paperwork instead, because a reflex is not an argument.
What is actually on the table — and what is not
Here is the fact pattern, in order, with the boring parts left in.
On Friday, July 24, 2026, two dozen companies signed a letter urging policymakers to avoid "premature restrictions" on open-weight AI models. Nvidia, Microsoft, Meta, Palantir, IBM, Hugging Face, Mozilla, Replit and the Linux Foundation were among them. On the day, OpenAI, Anthropic and Google were not. (The live document has kept collecting names since — as of the weekend it runs past thirty organizations and OpenAI's name has appeared on it, while Anthropic's and Google's still have not. Treat any "who signed" claim as a snapshot with a date attached.) Microsoft put the same text on its own corporate site, which is a reasonable measure of how much the signatories wanted this seen.
An open-weight model is not the same thing as open-source software, and the difference matters. The letter's own definition is the useful one: software that anyone can download, inspect, modify and run on their own infrastructure. The trained numbers are published; the training data and the pipeline usually are not. You get the engine, not the factory.
Now the part that triggered the letter. Four days earlier, Axios reported that the administration was reviving a push to restrict Chinese open-weight models on cybersecurity grounds, after the launch of Moonshot AI's Kimi K3. Trade press picked it up: the administration has reportedly been considering banning Chinese open-weight models and possibly sanctioning the companies behind them.
Read that sentence again and notice every hedge in it, because they are load-bearing. There is no rule. There is no Federal Register notice. There is no defined enforcement mechanism. There is reporting, sourced to unnamed officials, about something being weighed. And the word "ban" is covering at least three different instruments that behave nothing alike:
A procurement ban. The No Adversarial AI Act, introduced in June 2025, would create a federal list of AI tools from companies based in China, Russia, Iran and North Korea. The companion measure Representatives Moolenaar and Krishnamoorthi introduced would require the Federal Acquisition Security Council to publish that list. Introduced is not passed. And it governs what federal agencies may buy — not what you may run.
A trade blacklist. Entity List designation of Chinese labs, reported as under consideration, never issued for AI labs.
A liability shift. An executive order making US firms answerable for hosting foreign models — drafted, shelved, reportedly revived, and the one item here with no public document behind it.
Not one of those is a prohibition on possessing a file you already have. That is not a technicality. It is the entire problem.
Because here is the thing about a chokepoint: it has to actually choke. Whatever you make of Washington's chip controls, they at least have something to grip, because a datacenter GPU is a physical object that moves through a license and a customs form. Washington has even export-controlled a model once already, ordering Anthropic in June to get a license before transferring its frontier systems abroad. I wrote about that one in June; the detail that matters now is that those weights had never been published. There was a door, so a lock made sense.
Open weights have no door. They exist as files mirrored across public repositories and independent torrents, hard to fully recall once released; once a company has downloaded them it can run the model offline in an air-gapped room where no regulator can see which model is running. Firms routinely fine-tune, quantize and distil those models against their own data until provenance blurs and "where does the foreign model end" stops having an answer.
And the most striking concession comes from the pro-open side, not the hawks. The letter says it plainly: once released, weights are beyond the original developer's control, and modified versions are difficult to trace or reverse. The signatories concede the irreversibility and then reject prohibition as the remedy.
The strangest part of this whole episode is that the US government already ran the analysis. In July 2024, the report Commerce published through its telecom agency concluded, after weighing three policy approaches, that the government should not restrict the wide availability of model weights for dual-use foundation models at this time. Monitor, build capacity, revisit. Two years later the question is back as though it had never been asked.
Now let me argue against myself
If I stopped here, I would have written a satisfying piece and a dishonest one. The security case is not stupid, and the strongest version of it does not come from politicians.
It comes from the safety researchers — and it is precisely the irreversibility argument, pointed the other way. A RAND analysis of open-weight evaluation makes the point cleanly: once models are publicly released, control over their distribution is lost, vulnerabilities found after release cannot be patched, and access cannot be revoked. If that is true, then everything has to happen before publication, and the pre-release evaluation had better be extraordinary. It is not. The same paper's systematic review of open-weight releases from 2025 through April 2026 found that one model family out of thirty-seven met its full set of proportional evaluation criteria, and most met none of them.
The biosecurity version is blunter still. An independent policy essay from April — argument, not institutional finding — puts it plainly: with downloaded weights there is no API to monitor, no company to refuse the request, and no recourse once they are out. You cannot rate-limit a file on someone's laptop.
And my crypto-wars reflex has a serious problem, which I would rather state myself than have shouted at me. The Ninth Circuit protected source code — text a human writes to express an idea to another human. Model weights are not that. Alan Rozenshtein has argued the case that weights are not speech at all: no human writes them, no human can read them raw, and they function solely as machine-readable instructions. He and his co-authors add that a rule aimed at what a model does rather than what it expresses is not necessarily a First Amendment problem. The 1990s carve-out that left published source code outside prior approval may simply not transfer.
Nor are the underlying worries invented. In April 2025 the House Select Committee on the CCP published a report finding that DeepSeek is owned and operated by a CCP-linked company and that its platform funnels American user data through unsecured networks to China — congressional findings, not a court's, and worth holding at that weight. Separately, Treasury Secretary Scott Bessent said this week that the administration would examine whether Chinese firms were stealing American intellectual property and that it has "the ability to sanction them because of this theft" — a claim about watermarks and copying, which is a different accusation again from the backdoor theory. On that last one, Jensen Huang told Axios there is a misconception that somehow there are backdoors connected to China, and that whoever downloads a model can fine-tune and guardrail it themselves. He also sells the hardware open weights run on, which is worth remembering here. Three charges, three different burdens of proof. They should not be blended, in either direction.
So: the risk is real, the irreversibility is real, and the constitutional escape hatch may not be there. What is still missing is the mechanism. Every one of those arguments is a reason to think hard about release. None of them is a way to un-download a file.
Paris made the opposite bet — and made it on purpose
France offers the cleanest counter-model here, and it is not because Europe is softer on China. It is because Europe did the maths from a different starting position.
When you are not the country that owns the frontier labs, closed models are a dependency, not an asset. Every prompt goes to somebody else's servers under somebody else's law. Open weights, from that vantage point, are the hedge: you can download them, host them on your own soil, audit them, adapt them to your own language, and never send a citizen's data across an ocean. Openness stops being the hazard and becomes the sovereignty strategy.
Mistral is the concrete version of that bet — a French lab that built its reputation on releasing weights, and one that Commerce's own 2024 report named among the developers making models widely available. It signed the July letter alongside the American giants, which tells you the interest here is not national but structural. And the Brussels argument that ran alongside the AI Act was made in the same key: Mozilla pressed lawmakers that obligations should not disincentivize open source development, because permissive licensing is exactly what lets outside researchers evaluate a model's safety at all.
You do not have to think Europe got the details right — the AI Act's implementation has been a grinding, contested business — to notice the difference in instinct. One capital treats a downloadable model as a leak to be plugged. The other treats it as the only version of the technology it can ever fully inspect.
Meanwhile the irony compounds from the other side of the world. Reuters reported this week that Beijing is reaching for the same lever from the other end, consulting Alibaba, ByteDance and Zhipu about limiting the transfer of training data abroad and restricting foreign downloads of their model weights. Two governments, the same month, both trying to build a customs post around a number.
Where this goes if nobody blinks
Let me sketch the world we get if the pressure strategy proceeds, because it is more absurd than dramatic.
Picture 2028. No possession ban ever passes, because none was ever drafted. What arrives instead is a form. Every federal contractor must certify that no component of its AI stack derives from an adversary-developed model. Procurement questionnaires grow a new section: model bill of materials. And nobody can honestly complete it.
A logistics firm in Ohio runs a model its vendor fine-tuned from a base its vendor bought from a startup that quantized weights downloaded in 2026 from a repository that has since gone dark. Four hops, no receipts. The compliance officer has a choice between an attestation she cannot verify and losing the contract. She signs. Multiply by fifty thousand firms.
The models keep working. They work offline, in a rack, with the network cable pulled — which was always the point of self-hosting. Enforcement, having nowhere else to land, lands on the Americans: the startups, the hospital IT departments, the small manufacturers who chose the cheap capable model because the expensive one was priced for a Fortune 500 budget. The Chinese labs, being outside the jurisdiction, absorb none of it. Their downloads go up, because a technology that Washington fears is a technology that works.
And on the other side, Beijing's mirror controls bite: the next Kimi ships weights-restricted, the release notes get shorter, and the one genuinely useful thing about the whole ecosystem — that outsiders could open the thing up and look — quietly ends. Nobody bans anything. Everybody loses the inspection window.
What the people who study this for a living actually say
The striking thing is how little ideological daylight there is on the mechanics.
From the center-left, Kyle Chan of Brookings put it on the record: it is ultimately impossible to ban China's open-source AI models because the weights are freely available on the internet, and trying raises First Amendment questions besides. In the same reporting, Daniel Remler of CNAS — a national-security shop, not a tech-libertarian one — notes the worry that action against Chinese models could harm the start-ups using them and chill support for open models generally.
From the market-liberal side, Kristian Stout at the International Center for Law & Economics argues that stretching export controls over open weights will miss both the harm and the conduct causing it, and offers the deliberately unglamorous alternative: harden the laboratories, police the APIs, monitor the physical infrastructure. Less satisfying than a ban. Considerably more likely to work.
The hawks supply the numbers rather than the rebuttal. CSIS reports that Chinese models accounted for 41 percent of Hugging Face's downloads over the previous year and spread through repositories, GitHub, cloud providers, local deployments and third-party inference platforms — five channels, no single valve. Hugging Face's own analysis finds that among newly released models, Chinese downloads have surpassed every other country's. Stanford's DigiChina researchers, who have mapped the ecosystem model by model, conclude that Chinese open-weight models are now unavoidable in the global competitive AI landscape and that policy should start from granular knowledge of real-world deployment rather than a headline.
Even the industry's bluntest line lands as analysis rather than lobbying. Replit's chief executive Amjad Masad: banning Chinese open models is as good as banning open models in general. He may be self-interested. He is also describing the mechanism accurately.
So what does this mean for you?
Nothing is illegal today. That is the first thing to hold on to — and the second is that policy of this shape usually reaches you through your employer, your vendors and your prices, not through a police officer.
Learn which of your tools sends data out and which does not. "Using a Chinese model" through a web app, where your text travels to servers abroad, is a genuinely different risk from a self-hosted open-weight model running inside your company's network. Same family name, opposite data flows. Most coverage collapses the two.
If you buy software for an organization, start asking for a model bill of materials now. Which base model, which fine-tune, which license, which country of origin. Vendors that cannot answer today will not answer faster under a compliance deadline.
Watch procurement, not prohibition. The real instrument is a published federal list and the contract terms that follow it. If you sell to government at any level, that list is your regulation.
Read the letter yourself. It is three pages. It concedes more than its critics expect and asks for less than its supporters imply, and you will read the next headline about it differently.
Be skeptical of the word "ban" in every direction — including from people, like me, whose instincts run against the policy. Ask what the instrument is, who it binds and how it would be enforced. Half of these stories dissolve on the third question.
If you have views, aim them at the mechanism. Contacting a representative about "AI policy" achieves nothing. Asking whether they will support restrictions with no enforcement path, and what they would fund instead — evaluations, lab security, incident reporting — is a question staff have to answer.
The lesson, as I see it
My reflex was right about the mechanics and too pleased with itself about everything else. You cannot un-download a file. That is simply true, it is conceded in the industry's own letter, and it does not become false because the security concerns are legitimate.
But "you cannot stop the copying" was never the end of the argument. It is the beginning of a better one. If the artifact cannot be controlled after release, then the leverage sits everywhere else: in what gets released and after what testing; in the security of the labs; in the conduct of the people deploying these systems; in whether American models are good enough and cheap enough that no one has to choose a foreign one to afford the work. Those are harder than a list. They are also the only levers still attached to anything.
My vote? Fund the boring instruments. Publish the evaluations. Stop writing rules whose enforcement plan is hope — and stop pretending that a customs form can stand in front of a number that has already been copied ten thousand times.
The HAIA Foundation argues for AI policy that reckons with how the technology actually behaves, not how it would be convenient for it to behave. If that is your kind of thing, subscribe — it is free, and it is the whole point.




