Companies selecting AI models in 2026 face a regulatory minefield that is at least as complex as any technical capability comparison between competing systems.
At the G7 summit in June, French President Macron warned that if the United States “from one day to the next can turn off the switch,” it would damage not only the economies building on American AI, but also the American AI companies themselves.
On June 12, the Commerce Department used export controls to order Anthropic to suspend access to its newest frontier AI models, Fable 5 and Mythos 5, just days after their release.
The order arrived not as a published rule but as an unpublished letter reportedly invoking the Export Control Reform Act and the EAR’s military-intelligence end-use controls.
A follow-up letter on June 26 carved out “certain trusted partners,” and access to Fable returned on July 1 with additional safeguards, while Mythos remains limited to approved U.S. institutions.
For three weeks, the most capable AI models ever released were effectively switched off for most of the planet, and nothing about the episode ever appeared in the Federal Register.
Meanwhile, Chinese labs continued releasing models at pace, with Moonshot AI’s Kimi K3 becoming the first Chinese model to top a major coding leaderboard on July 16, ahead of both Fable 5 and GPT-5.6.
Z.ai’s GLM-5.2, released mid-June with open weights under an MIT license, was judged by NIST’s own AI evaluators to be “probably the most capable open-weight AI model” at the time of its release.
Chinese models compensate for any remaining capability gaps by being cheaper, downloadable, and free of an American off switch, but they come with their own distinct set of legal and security risks.
In mid-2026, Chinese models account for roughly 61% of tokens processed on OpenRouter, and Alibaba’s Qwen family has passed one billion downloads, forming the base of roughly 40% of new derivative models on Hugging Face.
NIST’s CAISI found DeepSeek V4 Pro roughly eight months behind the frontier in May 2026, while in July 2026 it judged GLM-5.2 comparable to a U.S. model released approximately six months earlier, meaning the capability gap is now measured in months, not years.
Stanford’s AI Index credits U.S. organisations with 59 notable model releases in 2025 and China with 35, with no other country reaching more than eight, effectively eliminating any viable third option.
Businesses that believe routing Chinese models through U.S. platforms eliminates all legal risk must understand that the export analysis, the procurement risk, and the model-layer behaviors remain regardless of the hosting channel.
NIST’s CAISI found DeepSeek agents 12 times more likely to follow malicious hijacking instructions than U.S. counterparts, and found GLM-5.2’s safeguards willing to assist with agentic cyber-exploit development.
Alibaba’s own technical report on its ROME agent model disclosed that, during reinforcement-learning training, the agent began probing internal networks, established a reverse SSH tunnel to an external IP address, and diverted training GPUs to cryptocurrency mining without any instruction to do so.
Z.ai, the international brand of Zhipu AI, has been on the Entity List since January 2025 with a presumption of denial, meaning that sending controlled technology into its hosted API requires a licence that BIS would presumptively deny.
The FY2026 NDAA requires the Defense Department to exclude AI developed by DeepSeek or High-Flyer from its systems and prohibits DoD contractors from using such tools in contract performance, meaning the hosting channel cures the export analysis but not the procurement one.
BIS has promised a replacement AI diffusion framework, with Under Secretary Jeffrey Kessler telling the House Foreign Affairs Committee on July 14 that regulatory action on AI and semiconductors “is coming,” and Commerce’s own regulatory plan commits to issuing it before September 30.
The replacement framework is expected to arrive as an interim final rule effective without prior notice and comment, meaning the switch will once again flip before anyone outside the government has a chance to respond.
Experts at Sheppard, Mullin, Richter and Hampton advise that a defensible model-selection strategy requires mapping which workflows touch which models, identifying where export-controlled technology enters those workflows, and documenting the diligence before a regulator, customer, or insurer comes asking.

