Governance & ComplianceSecurity & Supply ChainMacro & Geopolitics

Behind the "Chinese Model Reference Line" Rumor: Why the U.S. Moved from Chips to APIs

On July 13, the Washington Post brought to light a policy discussion not yet made public: the U.S. government and the AI industry are reportedly exploring an open-model release framework that could use the current capabilities of leading Chinese open models as a reference point. A secondary summary reported that if a U.S. model’s capability does not exceed this reference line, the release process could be streamlined. The account was quickly reframed as “the White House will issue a separate open-model executive order” and even “U.S. models must not surpass Chinese models.”

The publicly available evidence does not go that far. The original report rests on a single anonymous source. There is no policy draft, no agency document, no White House confirmation, and no clarity on whether the capability in question would be measured by cybersecurity, programming, or composite evaluations. But the thread raises a question that has not previously entered public discussion: when a government decides whether to restrict a U.S. model, beyond asking “how dangerous is this capability,” should it also ask “has an equivalent capability already spread across the globe through Chinese open weights”? The latter question could directly alter how much incremental risk a unilateral restriction can still reduce.

To understand this new thread, one must first trace why the U.S. has moved from restricting advanced chips all the way to controlling cloud training, model weights, and API access. On the national-security axis, the United States pursues two goals simultaneously: enabling its own companies to build the most capable AI faster, while slowing strategic competitors and high-risk actors from acquiring equivalent capabilities. Chips, cloud, weights, and APIs are not four randomly chosen regulatory targets — they are distinct channels through which the same capability reaches other users. Each time a capability bypasses one gate, policy moves further downstream along the delivery chain to find the next control point.

Two events in June illustrate this trajectory. Anthropic’s Fable 5 and Mythos 5 were abruptly taken offline globally because of government restrictions on access by foreign nationals. OpenAI, also at the government’s request, limited the initial users of GPT-5.6 to a small set of screened institutions, with a full rollout arriving roughly 13 days later. U.S. AI national-security policy is expanding from controlling the inputs needed to produce frontier capabilities to managing who can access capabilities that have already been created. The various instruments do not yet form a unified release-licensing regime, but they all serve the same central axis: preserving U.S. capability leadership and controlling the speed and scope of its diffusion.

Why Chips Became the First Gate

The U.S. government authorized the Commerce Department to identify and control emerging and foundational technologies relevant to national security as far back as 2018. But algorithms and code can be copied rapidly across networks; the government cannot intercept them at the border the way it inspects physical goods.

In 2022, the U.S. placed its most powerful control point on advanced chips. Under the advanced computing rule published that October, the Bureau of Industry and Security (BIS) defined licensing scope using hardware performance, destination, end user, and end use. Large-scale training requires tens of thousands of advanced GPUs, and chips come with a physical supply chain that is easy to classify and track. By controlling chips, the government raises the cost for specific countries and entities to train frontier models.

This gate restricts where large-scale compute comes from. It cannot, by itself, address a different problem: once a model has been trained, the capability it already embodies can still reach others through other channels.

The Same Capability Begins Flowing Through Three New Channels

Beyond chips, there are three additional capability-delivery channels: a user can rent U.S. cloud compute to train models, can download weights that someone else has trained, or can directly call a model API. Each channel delivers something different, and each presents a different policy control point.

The first is cloud-based training. A foreign customer does not need to ship chips back home; they can rent compute from a U.S. cloud provider and train their own model remotely. Executive Order EO 14110 once directed the Commerce Department to draft rules requiring identity verification of relevant foreign customers and reporting of large-model training activities that might have malicious cyber applications. Those cloud-service reporting rules never advanced beyond the proposed stage and never took effect; EO 14110 was later revoked in its entirety, eliminating the policy basis for the proposed rules.

The second is model weights. Weights are the parameter files produced after training. Once downloaded, a user can run the model independently. When weights are widely distributed across the internet, existing copies are difficult to reliably recall. In January 2025, the Commerce Department published the AI Diffusion Rule, which attempted to bring advanced closed-source model weights whose training compute exceeds 10^26 operations under export controls, classified as 4E091. The rule did not control qualifying open-weight models, and the Export Administration Regulations have long excluded certain information and software that is already publicly released. That said, the specifics still depend on the classification and the manner of release. Before the rule entered actual enforcement, Commerce announced that it would not be enforced.

The third is hosted APIs. Model weights remain on the provider’s servers, and users access capabilities such as code generation, cybersecurity analysis, and agentic behavior directly over the network. A Commerce Department cloud-computing advisory opinion from 2009 held that a service that merely provides computing capability without transmitting controlled software or technology to the user does not fall within the scope of export controls. The 2025 AI Diffusion Rule also explicitly preserved model APIs and inference cloud services. General rules therefore do not broadly classify ordinary API calls as exports. The Anthropic case, however, shows that the government is already attempting to restrict specific foreign nationals’ access to specific model APIs. A single company-specific directive does not mean industry-wide rules have changed.

U.S. AI national-security policy controls two classes of problems: upstream, through chip licensing and cloud identity reporting, it influences who can train; downstream, through weight classification and API access directives, it influences who can use capabilities that have already been created.

Compute Thresholds and Capability Tests Answer Two Different Questions

“Regulation upgrading from compute thresholds to capability red lines” sounds like a substitution. In practice it is more like a division of labor. Compute answers who should enter reporting or screening scope; capability testing answers whether the risks the government worries about have actually materialized.

EO 14110 used training compute to define the reporting population. Models reaching 10^26 operations — or 10^23 operations for models primarily using biological sequence data — required developers to report training and safety-testing information to the government. These two numbers are easy to audit but do not prove that a model is dangerous. Red-teaming results tell the government what capabilities a model actually exhibits in areas such as cyber and biology.

Signed in June 2026, EO 14409 goes further by requiring the government to directly test for advanced cyber capabilities — specifically a model’s capacity to carry out tasks related to sophisticated cyberattacks. A model that crosses the testing threshold receives the classification label covered frontier model.

This label does not currently trigger an automatic release ban. EO 14409 connects to a voluntary cooperation framework: developers may give the government advance access for up to 30 days before providing the model to other trusted partners. The same section of the executive order explicitly states that these arrangements do not authorize the government to establish mandatory licensing or pre-clearance. Capability assessments can also serve other decisions. The memorandum of understanding between CAISI and the General Services Administration (GSA) introduces evaluation methods into federal procurement support processes but does not prescribe that a particular test score automatically determines procurement eligibility.

Timeline of U.S. AI national-security policy from 2018 to 2026: hard chip controls, training-compute reporting, open-weight monitoring, closed-weight classification, cyber-capability testing, and API access cases appear in parallel, interspersed with revocations and suspensions.

How a Model Is Delivered Determines How Far the Government Can Reach

The Anthropic service shutdown turned delivery method from an abstraction into a real consequence. Commerce directed Anthropic to restrict all foreign nationals’ access to Fable 5 and Mythos 5. The directive targeted a class of users; it did not require that the two models be taken offline globally.

The problem lay in execution. The centralized API is operated uniformly by Anthropic. The company could shut down the service, but it could not reliably determine the nationality of the user behind each call on short notice. To avoid violating the directive, Anthropic chose to suspend service for all customers first. The combination of a targeted demand, the difficulty of identity screening, and the company’s compliance choice ultimately caused global users to lose access simultaneously.

The shutdown was not permanent. Following subsequent negotiations and licensing adjustments, Fable 5 resumed global service on July 1, 2026, while Mythos 5 remained limited to specific partners under trusted access. The government’s original letter, the technical basis, and the question of whether ordinary APIs are generally subject to the same authority remain publicly unanswered.

The public record therefore does not support the notion that the government possesses a physical switch that can remotely shut down all models. When a centralized service provider receives a demand that is difficult to enforce with fine granularity, it may use its own backend controls to carry out the shutdown; what users experience then resembles the flipping of a switch. Open weights are different. Once weights are released, users can run already-downloaded copies independently of the original developer. The government cannot rely on a single company to recall all those copies.

The differences among chips, cloud, weights, and APIs ultimately push policy toward a harder question. The government cannot ask only how dangerous a model is in itself; it must also consider whether equivalent capability has already spread through other channels. The first question determines whether intervention is warranted; the second determines how much effect a unilateral U.S. restriction can still achieve.

The Real Fork Ahead: Dangerous Capability vs. Global Availability

Existing formal policy primarily addresses the first type of question. The July 13 “Chinese model reference line” report provides the first public clue about the second. I refer to them here as the “dangerous-capability line” and the “global-availability line” purely as an analytical aid; these are not official policy terms used by the government.

The dangerous-capability line asks whether a model materially increases concrete threats such as cyberattacks or biological risks. Even if a foreign actor has already released an equivalent model, a U.S.-developed model could still add new scale, reliability, or ease of access, so this risk does not automatically vanish.

The global-availability line asks a different question: if an equivalent capability has already spread widely through foreign open weights, how much incremental risk can a unilateral U.S. restriction on its own companies still reduce? The safety benefit of a restriction may decline, while the competitive cost rises. Global availability may therefore influence scrutiny intensity or fast-track eligibility, but it cannot substitute for a dangerous-capability judgment.

Citing undisclosed discussions, the Washington Post reported that some have proposed using the capabilities of leading Chinese open models as a reference point for U.S. open-model policy. This is a single anonymous report with no formal text. It may become nothing more than a fast-track reference, or it may ultimately change nothing at all; at present it cannot be written up as a release ceiling or a prohibition line.

Future policy may need to consider two lines simultaneously: the dangerous-capability line assesses how much cyber or biological risk a model adds; the global-availability line assesses whether an equivalent capability has already been irreversibly diffused through open weights.

When a new regulatory development surfaces in the future, three questions can be asked first:

  1. Through which channel does this capability reach users — chips, cloud compute, model weights, or API?
  2. Can the government directly restrict this channel, or must it rely on companies to enforce the restriction through their own systems?
  3. Has an equivalent capability already been irreversibly dispersed through open weights?

Those three answers reveal more about the practical consequences of a policy than “is the U.S. moving toward blanket AI approval” ever could.