This week in The Red Report

For those who wish a more in depth discussion of Red Report analyses, please sign up for Red Report Live, a one-hour discussion with the authors. Each session is one hour and costs $250 per attendance or $2,500 for an annual subscription to 12 sessions. To sign up, please email [email protected].

From Zhongnanhai: This week in Chinese Politics

How AI is defining the upcoming US-China summit

AI safety will likely play a prominent role in US-China talks this month, but each side wants different outcomes. Any agreements on AI safety should be met with skepticism.

Analysis

Xi Jinping’s planned visit to Washington later in September will be a chance for the US and China to discuss their ongoing trade war, bilateral security issues, and, perhaps most importantly, the future of AI. AI safety will be prominent in discussions about areas of potential cooperation. Both governments have expressed concerns about the risks posed by AI in recent incidents from Open AI and Hugging Face to Kimi

As the Chinese government previously expressed, the concern is less about the intent behind these models’ developers and more about these model’s dangerous capabilities. Finding a position in which both governments can claim leadership in determining guardrails for global AI safety will likely be popular at home, although the question of whether each side can verify compliance or whether AI agents can indeed be prevented from going rogue, will remain. 

The US and China may interpret facts and even definitions very differently, which will lead to very different negotiated outcomes. When China says “AI safety,” for example, it means not only protecting individuals, companies, and infrastructure from AI-derived cyber attacks, but also ensuring that the CCP’s politics is injected into AI-generated data. “Safety” therefore means not just protection from attacks, but also protecting the CCP’s monopoly power over Chinese society. 

The CCP position incentivizes PRC-based companies to engage in messaging about supporting AI safety, which many are doing to attract political support (or at least avoid political retribution). It also provides an opening for the CCP to attack US companies for failing to adequately support safety measures. One Chinese commentator labeled Anthropic, for example, as “the American Disease,” reflecting broader CCP views that US AI is endangering in terms of tech development and for China’s position in the world. 

Added to China’s rhetoric, the US is similarly pushing for AI safety, albeit with a priority for US security. Two recent moves in Congress, for example, push for AI safety through guardrails on models, a prioritization of US over Chinese models (particularly open-weight), and a push to onshore robotics and other tech manufacturing to the United States through the proposed GUARD Act. 

Differing positions on AI safety are challenging to compromise during a negotiation, such as those planned for this month. Negotiators will need to get creative and find areas of cooperation if a solution is to be reached at the Trump-Xi summit. What is more likely is that the US and China will continue to hold differing ideas about what AI safety means or should be implemented and fail to reach a meaningful agreement. In the meantime, US companies will be left in the lurch for determining their own approach to AI safety amid persisting policy uncertainty.

On the Hill: Developments in US China policy

Chinese AI: a threat, a bargain, or both?

The White House told AI companies it won't test Chinese open-weight models, while separately floating a ban on those same models.

Analysis

The United States government is struggling to decide what counts as acceptable risk regarding Chinese AI models. On August 5, the White House quietly informed AI companies that it would not subject Chinese open-weight models to its new safety testing framework. The logic is almost charming in its honesty: once a model's weights are out in the wild, testing or monitoring are challenging, and so why pretend otherwise? 

Meanwhile, the administration has signaled its plans to add Chinese AI companies to the Entity List, which effectively bans any company wanting to do business with the US government from working with the listed company, largely over allegations that Moonshot AI's Kimi K3 was built by distilling a US lab's model. 

The working theory in Washington appears to be that in the absence of effective regulation, the only viable solution is a total ban on Chinese models. In other words, Chinese open models are too slippery to regulate, but too dangerous to allow. The US government’s enforcement of this position, however, is proving more challenging. 

In response, Silicon Valley has organized itself into two camps. One group of around two dozen companies, including Nvidia, Microsoft, Meta, and Hugging Face, signed a letter asking regulators not to impose "premature" restrictions on Chinese open-weight models. Their logic is that distillation is just how the sausage gets made in AI development. Almost 180 startups penned a supporting letter out of concern that a ban would cut off the cheap infrastructure that they need to compete with better-funded companies. 

A second group of closed-weight model heavyweights, including OpenAI and Anthropic, declined to sign either letter as they are the companies with the most to lose if "open" and "closed" models are regulated in the same way. Moreover, Anthropic is pushing for tighter restrictions on Chinese AI models. 

In short, US industry can't agree on what to regulate and how. The US government can't agree on what to regulate and how. And the one thing everyone agrees on is that somebody else should go first. Amid this paralysis, Chinese models are making rapid progress in the United States. Chinese model usage grew from 4.5% of enterprise token volume on OpenRouter (a gateway that grants simultaneous access to multiple AI models) in early 2025 to a weekly peak of 46% by mid-2025. Alibaba's open-weighted Qwen model logged more than a billion downloads on the US-based tech company Hugging Face this year. US evaluations found that DeepSeek's V4 Pro trails US frontier labs by only about eight months and that Z.ai's open-weight GLM-5.2 already matches the cyber capabilities of Anthropic's Opus 4.6. 

Meanwhile, Beijing is considering its own restrictions on overseas access to leading Chinese models, including Qwen. While nominally for security reasons, restrictions would follow a similar logic to Chinese business practice in other sectors: flood foreign markets with cheap or free products to hook users, push local competitors out of business, then start charging a premium for continued access. This give-it-away-then-lock-it-down pattern is a deliberate industrial dominance strategy, not a new playbook. But it works best when your opponent cannot decide whether Chinese AI is a threat, as with the case of AI in the United States’ "AI blind spot."

US companies evaluating Chinese open-weight models can't wait for Washington to decide. Rather, the strategic move is to build a standing legal and security review now. This includes separating, where possible, the risk of a PRC-hosted service, which comes with data-transfer and jurisdiction complications and dangers, from that of a self-hosted open-weight model. Meanwhile, US companies will have to be nimble and adaptive, given the US government cannot decide how to proceed.

Business Matters

The unanticipated consequences of US tariffs on China

The US’s tariff strategy continues to produce unintended consequences. On the home front, Canada appears to have learned from China about how to deal with a bellicose US trade strategy, while the US’s silicon blockade of China has spurred unprecedented corporate reinvestment into R&D among China’s major AI companies.

Analysis

Since US-Canada trade talks collapsed last week, a familiar story has played out: the US levied tariffs against Canada, followed by Canadian Prime Minister, Mark Carney, imposing a set of retaliatory tariffs on the US just days later. US tariffs are claimed to “offset Canadian discrimination” and bring the effective tariff rate on affected Canadian products to just under seven percent. Canada’s retaliatory tariffs are as high as fifty percent on certain products, and have been described as a “dollar-for-dollar” countermeasure. While there is a small window of time before the Canadian tariffs take effect on September 8, the recent naming dispute over Lake Ontario suggests little interest from either side in resolving the conflict. 

If one were to substitute “China” for “Canada” in the above description, no one would notice anything odd. China’s strategy of imposing targeted tariffs that match US tariffs in value is an established strategy we have seen play out multiple times over the past several years. What is new, however, is that another country is now learning from China’s playbook about how to handleUS government tariffs. While this strategy will not work for everyone, as some amount of leverage is needed, it very well may do for Canada. Our northern neighbor is one the US’s top trading partners, and it has significant financial leverage in states with key Republican elections coming up this November. Moreover, as the supplier of the vast majority of imported US natural gas and electricity, as well as almost 60 percent of imported US crude oil, Canada still has levers to pull. 

The Chinese AI sector has been the other unexpected winner from US tariffs, with new quarterly figures suggesting high confidence in the Chinese domestic market.

In its second quarter reporting, Alibaba recorded a nine percent increase in revenue, which was counterintuitively accompanied by a staggering 75 percent drop in overall profits. The cause of this disparity is not poor e-commerce performance, but the fact that Alibaba is aggressively investing in AI. With a three-year AI investment plan valued at approximately US$56B, the company already invested half the expected funds, which will be used to build out new data centers and compute, build new AI chips, expand cloud infrastructure, improve its Qwen AI models, and develop new AI-based applications. While this level of investment is a gamble, the company is confident it can recoup its expenses within three years of completing the investment. 

Alibab’s confidence is shared by Chinese AI competitor Huawei, which reported the year’s first-half revenue increasing by 9.6 percent while overall profits dropped by 36 percent. Huawei’s AI products are proving to be a double-edged sword for the company, insomuch as AI products have driven recent growth but keeping up with demand while simultaneously innovating requires ever-more intensive capital investment. With R&D commitments reaching an all-time high of 25.2 percent of total revenue at the end of Q2, however, Huawei seems confident that taking such a big risk is bound to pay off.

The confidence of companies like Alibaba and Huawei to make such bold investment decisions stems from US tariffs and the broader US-China trade war. As decoupling and derisking advances, so do the isolation of US and Chinese markets from one another. For Chinese companies, this means not having to compete domestically with industry-leading US products, from AI models and chips, to other advanced tech products. With a captive domestic market, Chinese companies are able to take enormous financial risks with the full knowledge that they have exclusive access to the world’s largest market and its still-growing demand for such products. 

Such cover for risk taking means that Chinese companies will be able to more freely experiment with innovation and may be able to close the technological gap with their US competitors at a faster rate than their US competitors. US tech companies will need to grapple with how to compete against such advantages enjoyed by their Chinese counterparts. 

Tech Futures

Immigration uncertainty undermines tech companies

The US government’s immigration policies are causing major uncertainty for US companies that rely on global expertise.

Analysis

Exit bans are a lever for controlling who can (and cannot) leave the PRC. This month, China’s State Council is expanding its criteria for when it can prevent individuals from leaving the PRC to explicitly include economic criteria, including individuals accused of violating export controls or providing false information on government documents. This new policy explicitly links business behavior, emigration, and travel with national security. If an individual is considered to be working for a company in an industry or on a technology that the CCP considers harmful to Chinese “national security” (purposefully vaguely defined) then the party has expanded authority to detain that individual. While the CCP already used this tool against the Manus AI executives earlier this year to prevent an acquisition by Meta, US-based tech company employees traveling to the PRC are now at heightened risk of detention. 

At the same time as China is threatening detention for tech workers, the United States is making it more difficult to hire those same workers. The White House is embracing increasingly tight  legal immigration policies ahead of November’s midterms. An executive order demanding fees of over $100,000 on H1B visas for skilled immigrants, for example, aims to relitigate a previous order from last year that was ruled unlawful by a district court. The new order will likely face similar legal challenges. But the point is not to succeed in court. Indeed, the Department of State’s announced delay in processing all immigrant visas speaks to the bigger policy, which is to raise the issue of immigration before the mid-term elections.

The uncertainty introduced by the changes and lack of clarity in US legal immigration makes for an extremely challenging hiring process for companies that say they rely on attracting skilled workers from abroad. Silicon Valley is particularly exposed. While the delay in processing is nominally to better screen for individuals who may rely on public welfare, US tech companies say the effect is to restrict US tech companies from securing the best personnel. Companies will be unable to secure visas for people whom they have decided to hire, but overseas workers will likely also see diminishing advantages looking to the United States in the first place. In response, workers who would otherwise build US models will turn towards working for or founding competitors to Silicon Valley outside the US.

At present, the White House is using immigration policy to pitch national security concerns against corporate competitiveness. The current logic is to force tech companies to hire US citizens over foreign nationals by cutting off access to hiring global workers. 

For US tech companies trying to hire and to predict both the PRC and US government’s next moves regarding exit bans and immigration, the heightened uncertainty will be challenging. For tech companies, internal policies clarifying travel to the PRC for employees and details about how to navigate potential detention will be vital. At the same time, staying updated on US policy changes while ensuring protections for current employees will be all the more important in the coming months.

Espionage Alert

US Tech Companies are approaching cyber hunting licenses with caution

The recently announced Administration CE-TCO Program permits US tech companies to become offensive, rather than just defensive, cyber actors. Engaging in offensive attacks, however, brings risks that likely outweigh the program’s intended benefits.

Analysis

The White House's recent National Security Presidential Memorandum authorized vetted US companies to conduct "Cyber Surveillance" and "Cyber Effects" operations against transnational cybercriminals. The move has generated a number of questions and little enthusiasm from the US tech sector. Industry sources tell us that the US companies with the greatest cyber capabilities have significant concerns that will cause hesitation among the companies that are most capable of participating.

First, once US companies become known program participants, their personnel and infrastructure will become priority targets for retaliation, including doxxing, swatting, and intrusions. While many PRC-based companies evolved as de jure or de facto agents of the Chinese state, US companies are not, and were never designed to be offensive actors. And they are not built to protect their personnel in this way.

Second, what happens if a US company targets the wrong organization? The CE-TCO definition excludes groups "wholly operated" by a foreign government, but many state intelligence and cyber services run their cyber operations through criminal and commercial cutouts precisely to preserve deniability. This is a common model in China and Russia. Hitting the wrong "criminal" could accidentally hit a state actor, with all the escalation that implies.

Third, US cover does not travel beyond the US’s borders. Operations transiting European infrastructure will still trigger EU regulations, including GDPR, the Computer Misuse Act, and NIS2 exposure that Washington cannot waive. US companies do not want to be responsible for collateral damage in important markets and potentially incur fines and other losses for questionable gains. The legal liabilities could be prohibitive, including potential bans from operating in certain markets. Industry sources tell us that the major tech firms, in particular, have zero interest in additional scrutiny by authorities like those in Europe. 

Fourth, the most capable cyber elements in the US private sector are well-resourced cyber red teams. These are the professionals who are paid to attack their own companies to reveal and patch vulnerabilities. These experts are neither equipped nor interested in offensive attacks against third parties on behalf of the United States. If they had wanted to work for the US government, they would already be working there rather than the private sector. 

This leads to an additional series of uncertainties. Who will fund these activities? How do US companies recuperate costs of such operations? If US cyber companies are privateers with letters of marque from the US government, how do these modern privateers make money? Will the US government go the same way as China in paying private contractors to contact cyber attacks, as for example, those uncovered by the iSoon leaks. Finally, what can a vetted private company do that current US capabilities in the military and intelligence community cannot already lawfully do? If the answer is "nothing new," then the risk-reward math doesn't favor private volunteers.

Book Recs

What we’re reading to better understand China

If you would like additional information and analysis tailored specifically for your specific business or institution, please contact us at [email protected].

Reply

Avatar

or to participate