Fable Can't Enter China, But GPT Can
Chips got blocked, but the models didn't—and that gap is sovereign AI's real face.
Opening
Dear reader, on July 9th, OpenAI unveiled GPT-5.6. It comes in three variants—Sol, Terra, and Luna—and the most powerful of them, Sol, was only released after clearing a US government safety review first. The reason: its cyberattack-related capabilities were judged too dangerous. Most of the coverage has focused on benchmark scores and pricing.
But that same week, my eye caught a much more important story that slipped by quietly. The Financial Times reported that OpenAI and Google have been selling cutting-edge AI to Chinese companies blacklisted by the US Department of Defense.
On one side, a model only ships after clearing a government review. On the other, that same class of model is being used by subsidiaries of blacklisted companies. Let me give you the conclusion up front: in 2026, the real sovereignty over AI doesn’t sit with governments—it sits in the terms of service of three companies deciding who gets to buy the model.
Two Scenes, Same Week
The first scene is GPT-5.6. OpenAI rolled the model out to a small group of trusted partners first, at the request of the US government. That’s because Sol, the most powerful variant, far outpaced the previous generation at cyber-offense work—finding vulnerabilities and writing attack code. It’s a fairly strict picture: the government scrutinizing each model one by one.
The second scene is the exact opposite. According to the Financial Times, OpenAI and Google have been supplying AI services to Singapore-based subsidiaries of Alibaba, Baidu, and Tencent. All three parent companies have been designated by the US government as linked to the Chinese military. Once the FT’s reporting began, OpenAI said that last month it cut off API access for Alibaba-affiliated users, citing signs of “distillation.”1
Let’s check both companies’ reasoning too. OpenAI explained: “We don’t allow access from within China, but in jurisdictions where safeguards can be enforced and distillation monitored, we permit some Chinese-affiliated companies to use our services.” It added that “access shouldn’t be decided by nationality alone—it’s better for the world to run more AI built on democratic values than AI controlled by authoritarian governments.” Google likewise acknowledged offering services within policy limits in Hong Kong and Singapore, while admitting that regional restrictions alone can’t fully stop distillation.
And there’s a third company: Anthropic. It took the opposite path entirely. It blocked access to its frontier models, Mythos and Fable, for any company headquartered in China—and for any overseas entity that company majority-owns. Just last week, it closed even the loopholes some Chinese firms had been using to get around the block. Same frontier models,2 yet each company has drawn the border in a completely different place.
Why Does This Gap Exist?
That raises a question: why is the US government letting this slide? The answer lies in the gap between what Washington chose to control and what it chose not to.
The US has long controlled “chips.” “Models” are a different story. In January 2025, the Biden administration created the AI Diffusion Rule,3 which for the first time tried to bring model weights themselves under export control—but the Trump administration rescinded the rule that May. Chip export controls have since loosened as well; starting in January 2026, some chips bound for China are being approved on a case-by-case basis.
As a result, the US today manages individual models like Fable, Mythos, and GPT-5.6 through government review, but doesn’t broadly ban China-headquartered companies from using frontier AI itself—even companies on the Pentagon’s 1260H list.4 That list grew to 188 entries in June 2026 after Alibaba and Baidu were added, but being on the list doesn’t mean a company is barred from using US software. Chris McGuire, who oversaw export controls at the Biden White House, told the FT: “The administration always says we have to beat China on AI, but on export controls—the actual tool that could slow China down—we’ve done nothing.”
So why is this dangerous? Because of distillation. Distillation means taking the outputs of a strong model and using them to train another model. A single point of access can amount to a transfer of capability. Anthropic revealed earlier this year that Chinese AI labs DeepSeek, Moonshot, and MiniMax had distilled Claude, and recently reported to Congress that an Alibaba affiliate used 25,000 fake accounts to generate 28.8 million conversations in order to extract capability. 28.8 million conversations is roughly 790 years’ worth if one person held 100 conversations a day without a single day off. That’s how much knowledge leaked out through a single channel.
In the words of AI policy and security expert Joe Kawam, Chinese labs are “systematically extracting frontier capability without paying the computing, engineering, and safety costs that US companies bore.” The moment you sell API access, you may effectively be exporting capability. Yet there’s a reason Washington can’t clamp down on models as hard as it does on chips. Chips are physical goods that customs can catch at the border; a model’s output crosses borders in a single line of API code. There’s also no consensus yet on how far to control open-weight5 models, or where to draw the line on free software distribution. Even where the will to control exists, the tools don’t quite fit the job.
Redefining “Sovereign AI”
These days, countries everywhere talk about “sovereign AI.” France is grooming Mistral as its national champion model. Saudi Arabia set up HUMAIN with sovereign-wealth-fund money and secured 200,000 Nvidia GPUs. The UK created a £500 million sovereign AI task force. Sovereign AI usually conjures an image like this: a country directly owning its own stack, from chips to data to models.
But the sovereignty this FT report actually reveals in 2026 lives somewhere else. The very top of frontier AI is still held by two or three US companies, and the real decision of “who gets to use this” is made not by governments but by those companies’ access policies.
The problem is that the companies don’t agree with each other. Anthropic treats model access as an export-control issue. It blocks China-headquartered firms by nationality, and says it has given up hundreds of millions of dollars in revenue as the price. OpenAI, by contrast, treats this as a matter of “values and markets.” It draws the line not by nationality but by whether monitoring is possible, arguing it’s better to spread AI built on democratic values more widely. Neither side is entirely wrong. But one thing is clear: decisions that a nation-state would once have made as a matter of sovereignty are now being made by three private companies, each using its own criteria.
Let me sketch a concrete scene. Say a Gulf state sets up its own national AI company with sovereign-wealth-fund money and secures hundreds of thousands of GPUs. It looks like a textbook case of sovereign AI. But the moment it needs frontier-level performance to solve the hardest problems, it still has to call the API for Fable or GPT-5.6. If that access is cut off one day by a single line in a revised terms of service, those 200,000 GPUs become half-useless at the very top of the stack. You own the lower layers of the stack, but the switch at the top sits in someone else’s hands.
So I’d like to redefine sovereign AI this way: the core of sovereign AI isn’t “who builds the model,” it’s “who can turn off the tap.” No matter how many Mistrals and HUMAINs emerge, if the access switch for the top-tier model sits on a terms-of-service page in California, that sovereignty is only half real.
Oswald’s Lens
There’s something I’ve confirmed again and again while building GTM strategy: a product’s real moat isn’t the feature itself, it’s the power to control who you sell to. Good products can be copied. Good distribution and access control can’t be copied nearly as easily.
That’s exactly what’s happening in frontier AI right now. The model’s moat (technical edge) and its geopolitical function (who benefits from it) have merged into a single lever: who gets API access. The moment distillation turns every sale into a potential capability transfer, the trust-and-safety team enforcing the terms of service effectively becomes an export-control agency. I think that shift is the real heart of this story.
But before I take a side, let me be honest about two things. First, Anthropic-style total blocking may look clean in principle, but in practice it’s hard to enforce fully because of workaround accounts and overseas subsidiaries, and the revenue loss is significant. Second, OpenAI-style “monitor while selling” isn’t baseless either. If you can’t stop it anyway, the logic of steering usage toward channels you can monitor—and catching distillation there—actually worked once, with last month’s Alibaba block. My conclusion: given the economics of distillation, access policies that ignore nationality will get harder and harder to defend—but concluding that “blocking is automatically the right answer” is also a lazy judgment. This looks like a technology problem, but it’s really an institutional design problem about who gets the authority to draw the line.
Closing
Let me sum up today’s story in three lines.
First, in the same week GPT-5.6 launched after clearing a government review, it came out that OpenAI and Google have been selling advanced AI to subsidiaries of blacklisted Chinese companies. Second, because the US controls chips but has left models broadly open, the decision of whether to block access has fallen to three private companies. Third, that means the real question of sovereign AI isn’t “who builds it” but “who can turn off the tap.”
If you were the policymaker, which would you choose—Anthropic’s approach of drawing the line by nationality, or OpenAI’s approach of drawing it by whether monitoring is possible? Pick one and leave a short comment with your reasoning—I’ll gather readers’ choices and dig into them together in the next issue.
💬 Anthropic’s total block vs. OpenAI’s monitor-and-sell—which side are you on? Tell us why in the comments. We’ll factor it into the next issue. 📨 If you know a colleague curious about the intersection of AI and geopolitics, please pass this along.
References & Further Reading
Primary sources
- Financial Times, “OpenAI and Google sell AI models to blacklisted China groups”, 2026. ··· The starting point for today’s piece. It lays out the conflicting positions of OpenAI, Google, and Anthropic in one place.
- Anthropic, “Updating restrictions of sales to unsupported regions”, 2025. ··· See the company’s own official logic for why it blocks China-headquartered firms.
- Just Security, “The Case for Imposing Costs on China’s AI Distillation Campaigns”, 2026. ··· Why distillation is a blind spot in export control—the key evidence behind today’s piece.
- Fortune, “Pentagon accuses Alibaba, Baidu, BYD of supporting the Chinese military”, 2026. ··· Background and scale (188 entries) of the expanded 1260H list.
Background
- McKinsey, “What is sovereign AI?” ··· Start here if you want the standard definition of sovereign AI.
- Stanford HAI, “AI Sovereignty’s Definitional Dilemma” ··· Explains why “sovereignty” gets used so inconsistently.
- Federal Register, “Framework for Artificial Intelligence Diffusion”, 2025. ··· Read the original text on how model-weight controls (ECCN 4E091) appeared and then disappeared.
- CSIS, “DeepSeek, Huawei, Export Controls, and the Future of the U.S.-China AI Race” ··· The big picture of US-China competition over chips and models.
📝 Glossary
Footnotes
-
Distillation: A method of training one model by feeding it massive amounts of another, stronger model’s outputs as training material. It’s a problem because it lets someone copy the original’s capabilities at a fraction of the cost. ↩
-
Frontier Model: An AI model that represents the current state of the art at a given point in time. GPT-5.6 and Fable fall into this category. ↩
-
AI Diffusion Rule: A rule the US tried to create in 2025 that, for the first time, would have brought “model weights” (a model’s core parameters) under export control. It was later rescinded, so there’s currently no broad rule blocking models. ↩
-
1260H List: An annual list of “companies linked to the Chinese military,” compiled by the Department of Defense under Section 1260H of the National Defense Authorization Act. Being listed blocks contracts with the DoD, but doesn’t automatically ban commercial sales. ↩
-
Open Weight: A model whose weights—its core numerical parameters—are made public so anyone can download and run it on their own computer. Once released, it’s essentially impossible to recall, which makes export control especially difficult. ↩


Your take shapes the next issue
Reply with your experience or perspective — the best responses feed into future issues.
Sign in to commentAny registered reader can comment — it takes 10 seconds.