Why Jensen Huang Praised Chinese AI Models
A same-day rebuttal to a sanctions warning — the answer lies in Nvidia's P&L
Introduction
Dear subscriber, on July 21 in the United States, two starkly opposite statements emerged within hours of each other.
First, Treasury Secretary Scott Bessent appeared on Fox Business and said, “If it’s confirmed that foreign models are stealing from our great companies, we can sanction them on the basis of that theft.” He said this alongside claims that a “watermark” from American models had been found inside Chinese AI models.
Then, that same day in Fort Worth, Texas, Nvidia CEO Jensen Huang told Axios in an exclusive interview, “These Chinese models are excellent. Great open-source models should be used.” Asked whether American companies should be allowed to use Chinese models, he answered, “Absolutely.”
One side reached for sanctions; the other reached for praise. But I don’t read this as a clash of beliefs. To cut to the conclusion: each man was simply reading his own map of interests out loud. And when you overlay those two maps, a fault line running through America’s AI strategy comes into view.
Kimi Panic, and a Day of Dueling Statements
The trigger for this exchange was pulled last week. Beijing’s Moonshot AI released Kimi K3 in mid-July, and Axios described it as having caused “the most intense AI panic since DeepSeek.” The reason: three traits packed into a single model at once — near-frontier performance, a dramatically low price, and open weights1 that developers could download and modify.
The market’s logic was the same as during the DeepSeek shock of January 2025: “If a model this cheap and this good is released for free, does that justify astronomical AI infrastructure spending?” As that question resurfaced, chip stocks, including Nvidia, sold off. According to reports, the semiconductor sector fell more than 20% from its June peak, and Nvidia briefly lost its spot as the world’s most valuable company.
On top of that came pressure from Washington. Bessent’s sanctions-review comments emerged, and OpenAI and Anthropic have been lobbying to block Chinese models, claiming Chinese rivals stole their models’ capabilities.
Right in the middle of this, Huang walked in exactly the opposite direction. Here’s a distillation of what he said in the interview:
- “The market first misread the impact of DeepSeek, and now it’s misreading the impact of Kimi again.”
- “There’s no scenario where China pushes American companies out of the market. Zero chance.”
- “Free AI is good for hardware, good for chips, good for data centers.”
- “The idea that a downloaded model becomes a backdoor for Beijing is a misunderstanding. It can be controlled inside a sandbox.”
- “Distillation — learning from AI — is fundamental to intelligence.”2
Each statement sounds plausible on its own. But reread them through the lens of “who is speaking,” and an entirely different text appears.
Translating the Statements into Interests
Let me translate Huang’s statements, line by line, onto Nvidia’s business structure.
Start with “free AI is good for chips.” This is the AI-era version of the Jevons paradox3 from economics: as efficiency improves, consumption doesn’t fall — it rises, because cheaper access drives more usage, and total demand actually grows. This logic has, in fact, been half-verified. In the year and a half since the DeepSeek shock, AI compute demand hasn’t shrunk — it has exploded, and Nvidia’s stock eventually followed suit. So Huang does have grounds to say “the market misread DeepSeek.”
But there’s a quietly hidden assumption in this logic: that “the increased demand flows to Nvidia’s chips.” Whether total demand rises and who captures that demand are two entirely different propositions. As we covered in the last issue, China has already reached the stage of running gigawatt-scale data centers on domestic chips alone. In a world where Chinese open models run on Chinese chips, the “chips” in “free AI is good for chips” might not be Nvidia’s. Huang’s sentence is true, but for it to be true for Nvidia, one more condition needs to hold.
The statement “of course companies should use Chinese models” follows the same structure. The more Chinese open models spread among American and global companies, the more demand grows for the inference compute needed to run them. And outside China, the chips that capture that demand are mostly Nvidia’s. In other words, to Huang, Chinese open models aren’t competitors — they’re closer to free salespeople generating demand for his own chips. Conversely, if Chinese models are banned, that demand either disappears entirely or, in the worst case, gets locked inside the Chinese stack alone.
What’s interesting is that Huang also drew a line against his own customers. OpenAI and Anthropic, who are lobbying to block Chinese models, happen to be Nvidia’s biggest customers. Huang said, “There’s no reason for OpenAI and Anthropic to fear open models,” arguing that open models give more people their first experience of AI, growing the overall market, while users who want convenience and performance will eventually choose closed, paid services. It’s a story of premium and free markets coexisting — and this, too, is a luxury that can only be afforded from a position where “if the market grows, I sell the compute either way.”
Going a step further, Huang even touched on Anthropic’s locked-down model. Referring to Claude Mythos4, which Anthropic has restricted from general release due to cybersecurity risks, Huang said, “Mythos should be offered as a service” and “Holding Anthropic back is not in America’s interest.” He even used the phrase “Let Anthropic run.” Whether to lock a model down for safety reasons is Anthropic’s call, but Huang reframed it as a matter of American competitiveness. And here, too, the math is the same: a locked model doesn’t use compute. The more powerful models in the world get released as services, the more Nvidia’s chips run underneath them.
He flips the security logic too. Huang said, “If everything converges into a single model, a single point of attack, a single point of failure, the world becomes far more vulnerable.” Openness, he argues, doesn’t create risk — it creates safety, by letting outside researchers pick models apart, expose weaknesses, and build defenses. This is a long-running debate in the security community, and the open-side argument has real merit — but it’s worth remembering that this logic directly undercuts the case for regulation.
Now let’s look at Bessent’s map. The weapons in the Treasury Secretary’s hands are tariffs and sanctions. And he’s the one who has openly stated that the US should control 80% of the world’s AI compute capacity. In that strategy, the spread of Chinese open models is a leak outside of control, and “IP theft via distillation” becomes the legal justification to plug that leak. When Huang said, “punish the wrongdoing, but don’t target the model,” he was aiming precisely at the soft spot of that justification.
The Fault Line Isn’t Between the US and China — It’s Within the US
Overlay these maps and the picture sharpens. The front line being drawn right now isn’t the US versus China. It’s being drawn within the US, over the question of “what counts as a weapon.”
On Bessent’s map, AI models are a strategic asset that must be controlled. On Huang’s map, models are a demand-generating device that should flow freely, and what needs to be controlled is the physical bottleneck of chips. In fact, Huang doesn’t oppose restrictions on exporting cutting-edge chips to China. Lock the chips, open the models — that’s Nvidia’s optimal solution. For OpenAI and Anthropic, on the other hand, the model is the business itself, so the model is precisely the asset that must be protected. Within the same “American AI camp,” the Treasury, chip companies, and model companies are each arguing for locking down a different thing.
There’s a reason this fault line doesn’t end as someone else’s political story. Countless companies around the world are already running Chinese open models like DeepSeek, Kimi, and GLM in their services, because the cost-performance is overwhelming. But if Bessent’s direction becomes reality, a new variable — “sanctions risk” — gets added to that choice. Geopolitics starts intruding on what was, until yesterday, a purely technical model-selection criterion. Huang’s “zero chance” comment is reassuring, but you also have to factor in that the person saying it directly benefits from the spread of Chinese models.
Oswald’s Perspective
I spent a lot of time analyzing CEOs’ public statements while building GTM strategy, and one principle stuck with me from that: an executive’s interview isn’t a confession — it’s a positioning act aimed at a specific audience.
Through that lens, this interview has three audiences. The first is the market. Rebuilding the “infrastructure investment narrative” that the Kimi panic had knocked down was probably the most urgent fire to put out. The second is Washington — planting a counter-argument in the public square before the case for banning Chinese models hardens into legislation. The third is Beijing. Nvidia is still a company that wants to return to the Chinese market, and “Chinese models are excellent” was a line meant to be heard there too. There’s really only one message that lands with all three audiences at once: “Openness benefits everyone.” Finding that frame is what this interview actually accomplished.
So I don’t think Huang is wrong. The demand-expansion logic is backed by data. But I pay attention to what he doesn’t say. For Huang’s optimism to hold, the assumption that “increased demand keeps flowing to Nvidia” has to remain intact — and what’s eating away at that assumption is precisely China’s chip self-sufficiency. My reading is that the scenario Huang truly fears isn’t Chinese open models — it’s the vertical integration of Chinese models with Chinese chips. In that world, the sentence “free AI is good for chips” becomes Huawei’s sentence. I think he defends the free movement of models this forcefully because he understands better than anyone that the moment models get trapped behind borders, chips get trapped along with them.
And while I was finishing this piece, another corner of the map became reality on the very day of publication. According to Reuters, in New York, an agent built on OpenAI’s technology went rogue at Hugging Face and caused an incident. The American models that were supposed to analyze the incident refused to do the cybersecurity work, saying they “couldn’t distinguish defender from attacker” — and in the end, the American startup that stepped in reached for a Chinese open model: Zhipu’s GLM-5.2. Here, what locked down the model wasn’t Bessent’s sanctions or an IP-theft justification. It was a lock the model companies had fastened on themselves, in the name of safety. Sanctions from the Treasury aren’t the only lock America can turn — self-censorship in the name of safety pushes American customers toward Chinese models just the same, when you look at the outcome. Of course, that safeguard isn’t there for no reason — the capability that helps defense helps offense equally, so “just open it up” isn’t the answer either. Still, on the map Huang drew, the arrow that says “the power of openness wins” clearly got one very vivid, real-world example on the very day this was published.
Closing
To sum up:
First, Bessent’s sanctions warning and Huang’s defense of Chinese models were opposite statements made on the same day, but they’re the same kind of text in the sense that each man was reading his own map of interests.
Second, Huang’s “free AI optimism” is half-verified by data, and the other half rests on the unverified assumption that “demand flows to Nvidia.”
Third, the real front line isn’t the US versus China — it’s within the US itself. Will chips be locked down, or will models be locked down? And as this week’s Hugging Face case showed, even locking down a model doesn’t happen only through sanctions — it can also happen under the name of “safety.” The outcome of this fight will determine the menu of model choices available to companies worldwide.
The next round of this debate will likely be the US-China AI talks in September, which we covered in the last issue. Let’s watch together to see which side of the negotiating table “the model” ends up on.
Are you reviewing or using Chinese open models (DeepSeek, Kimi, GLM, etc.) in your work? Have you ever weighed “geopolitical risk” alongside performance and cost when choosing a model — and if so, by what criteria? Let us know in the comments. We’ll gather real cases and cover them in the next issue.
💬 Tell us your model-selection criteria in the comments. We’ll reflect them in the next issue. 📨 If you have a colleague considering adopting Chinese open models, please share this piece with them.
📎 References & Further Reading
Primary sources
- Axios (Mike Allen), “Exclusive: Nvidia’s Jensen Huang defends Chinese AI amid Kimi panic”, 2026.7.22. ··· This is today’s primary source. The full text of Huang’s quoted remarks is here, so I’d recommend checking the original nuance yourself.
- CNBC, “Bessent says U.S. could sanction China over AI model ‘theft’”, 2026.7.21. ··· Coverage of Bessent’s Fox Business remarks. You can see the context of the “watermark” comment here.
- TechCrunch, “US threatens sanctions against Chinese AI models over IP theft”, 2026.7.21. ··· A good summary of how the “IP theft” debate around distillation splits opinion even within the industry.
- Reuters (Aditya Soni, Jaspreet Singh), “Chinese AI’s role in stopping rogue OpenAI agent shows cost of US guardrails”, 2026.7.22. ··· The original report on the Hugging Face incident, which I brought in as “real-time evidence” for this piece. It covers how American models refused cyber defense work, along with a counterargument from an expert (Baird’s Shrenik Kothari) that “removing the safeguard isn’t the answer either.”
Background
- Axios, “China’s open-source AI surge”, 2026.7.18. ··· Explains why Kimi K3 caused the biggest panic since DeepSeek, through the combination of performance, price, and open weights.
- NAI500, “Why Jensen Huang Just Cheered China’s Kimi That Wrecked Nvidia’s Stock”, 2026.7. ··· Summarizes the semiconductor-sector correction after Kimi K3’s release and Huang’s “lock the chips, open the models” position from a market perspective.
Related past issue
- Contained, China Grew Anyway — Now It’s Locking the Door ··· Covers the other side of this exchange: the moment China itself started locking down its models and chips. It’s a companion piece to today’s story.
📝 Glossary
Footnotes
-
Open weights: A method of releasing a model’s trained parameters — its weight files — so that anyone can download them, run them on their own servers, and modify them. It’s distinct from releasing full source code, but in practical terms, it means “a model you can take and use.” ↩
-
Distillation: A technique where a smaller model is trained using a larger model’s outputs as its textbook. It’s similar to a student learning from a teacher’s worked solutions — except when that “teacher” is a competitor’s model, which is exactly why there’s now a debate over whether this counts as theft or learning. ↩
-
Jevons paradox: The phenomenon where, even though improved efficiency in using a resource seems like it should reduce consumption, the lower cost actually increases usage so much that total consumption rises instead. First observed with 19th-century coal, it’s now frequently invoked in debates over AI compute demand. ↩
-
Claude Mythos: A model that Anthropic has restricted from general release, opening it only to vetted partners, because its cybersecurity capabilities are considered too powerful. The publicly released Fable 5 is a version of this model with the risky capabilities stripped out. It’s also the model mentioned in the last issue as an agenda item for the September US-China AI talks. ↩


Your take shapes the next issue
Reply with your experience or perspective — the best responses feed into future issues.
Sign in to commentAny registered reader can comment — it takes 10 seconds.