US Considers Sanctions on Chinese Open AI Models for Alleged Intellectual Property Theft

The United States is weighing a new pressure point in its long-running effort to slow China’s momentum in artificial intelligence: sanctions aimed not at a single closed product, but at the open-style AI models themselves.

In remarks attributed to U.S. Treasury Secretary Scott Bessent, the administration signaled that it could pursue sanctions against Chinese “open AI models” on the grounds of alleged intellectual property theft. While the comments stop short of naming specific models or companies, they mark an important shift in how Washington appears willing to frame the AI competition—moving beyond export controls and investment restrictions into a more direct attempt to shape the ecosystem of model development and distribution.

For readers who have followed U.S.–China tech policy over the past several years, this may sound like a familiar theme: IP theft has long been part of the broader narrative used to justify enforcement actions, trade measures, and diplomatic pressure. What’s different here is the target. Instead of focusing only on hardware, chips, or particular software products, the U.S. is now contemplating sanctions that could attach to widely shared model weights, training artifacts, or the organizations behind them—especially where those models are described as “open” or accessible in ways that resemble open-source distribution.

That distinction matters, because “open” in AI can mean many things. Some releases are truly open-source, with permissive licenses and full transparency around code and weights. Others are “open” in the marketing sense—publicly downloadable models, but with licensing terms, usage restrictions, or incomplete disclosure. Still others are open-weight models that are technically available while remaining difficult to reproduce exactly due to missing training details, proprietary datasets, or undisclosed fine-tuning steps. When policymakers talk about “open AI models,” they may be referring to this entire spectrum of accessibility, and that ambiguity could become a central battleground.

At the center of the U.S. position is the claim that certain Chinese models may have been trained or derived using stolen intellectual property. In practice, allegations of IP theft in AI often revolve around one or more of the following: the use of copyrighted content without authorization; the extraction or copying of proprietary model outputs; the reuse of training data that includes leaked or scraped materials; or the replication of another organization’s model architecture and behavior in ways that are argued to be too close for legitimate competition. The challenge for regulators is that proving these claims can be technically complex. Unlike traditional IP disputes—where a copied file, patent, or source code line might be compared directly—AI systems can be trained on mixtures of data, and the “why” behind a model’s performance can be hard to trace back to a specific dataset or infringement event.

That complexity is precisely why sanctions are such a powerful tool. Sanctions do not require a court to establish liability in the same way a civil lawsuit does. They can be imposed based on government assessments, intelligence, or evidence that may not be fully disclosed publicly. If the U.S. decides to move forward, it could rely on a combination of investigative findings and legal theories that treat certain entities as enabling or benefiting from IP violations—even if the underlying technical proof is contested.

The strategic intent, according to the framing in the remarks, is also clear: this would be another layer in a broader campaign to slow China’s AI advances and reduce their influence. Over time, U.S. policy has increasingly treated AI not just as a commercial technology, but as a national security asset. That shift has justified a widening set of tools: restrictions on advanced semiconductor exports, pressure on cloud and infrastructure providers, scrutiny of cross-border research collaborations, and efforts to limit access to certain high-end compute resources. Sanctions aimed at “open” models would extend that logic into the software layer—potentially affecting what researchers, startups, and enterprises can legally deploy.

One unique angle in this approach is the potential chilling effect on the open ecosystem itself. Open-weight models have become a major driver of innovation worldwide. They allow smaller teams to build on strong baselines, fine-tune for specialized tasks, and iterate quickly without spending the kind of money required to train frontier models from scratch. If sanctions become a credible threat for “open” releases, developers may respond by tightening compliance processes, limiting distribution, or avoiding certain model families altogether. Even if only a subset of models is targeted, the uncertainty could cause broader caution across the market.

This is where the policy could become both influential and controversial. On one hand, the U.S. is arguing that IP theft undermines fair competition and harms creators whose work is used without permission. On the other hand, open model distribution has historically been defended as a way to accelerate progress, democratize access, and enable independent verification. If sanctions are perceived as punishing openness rather than specific wrongdoing, the result could be a fragmentation of the global AI community—where “open” becomes less about transparency and more about risk management.

There is also a practical question: what exactly would be sanctioned? Sanctions can be applied to individuals, companies, or specific jurisdictions, but they can also be structured around activities—such as providing services, facilitating transactions, or exporting certain technologies. In the context of AI models, that could translate into restrictions on hosting, distributing, licensing, or even providing support services related to a sanctioned model. If the U.S. were to designate a model or its developer entity, downstream users could face compliance obligations, including screening vendors, verifying licensing terms, and documenting supply chains.

For enterprises, this could mean rethinking procurement. Many companies rely on third-party AI tooling that may incorporate open-weight models under the hood. If a sanctioned model is embedded in a larger product, the enterprise might still be exposed depending on how the sanctions are written and enforced. For startups, it could mean that building on certain open models becomes a legal gamble. For researchers, it could mean delays in experimentation, additional paperwork, or the need to switch to alternative baselines.

Another dimension is the definition of “IP theft” in AI. Traditional IP categories—copyright, patents, trade secrets—do not map neatly onto machine learning pipelines. Copyright questions often focus on whether training data is protected and whether copying occurred. Trade secret questions often focus on whether confidential information was misappropriated. Patent questions focus on whether inventions were used without permission. But AI systems can involve all three at once, and the evidence can be distributed across datasets, code, and training procedures.

If the U.S. is serious about sanctions, it will likely need to articulate a workable standard for enforcement. Otherwise, the policy risks being seen as arbitrary or politically motivated. The most effective enforcement frameworks tend to be specific: they identify the alleged infringing material, the mechanism of copying, and the entity responsible for the infringement. In AI, that specificity is harder to achieve, but not impossible. Governments can use forensic techniques, dataset provenance analysis, and comparisons of model behavior to infer relationships between models and alleged sources. They can also rely on complaints from rights holders and on documentation from investigations.

Still, even with strong evidence, there is a second-order effect: the policy could incentivize more opaque development. If “open” releases are punished, developers may choose to keep models closed or semi-closed, reducing transparency. That would not necessarily reduce IP violations; it could simply make them harder to detect. In other words, sanctions could unintentionally push the ecosystem toward secrecy, which may benefit some actors while harming the broader research community.

At the same time, there is a counterargument that deserves attention. Open-weight models are not automatically equivalent to open-source software in terms of legal obligations. A model can be “open” in distribution while still being built on questionable inputs. If the U.S. believes that certain Chinese models are effectively repackaging copyrighted or proprietary content, then sanctions could be framed as a necessary deterrent. The key is whether the U.S. targets conduct and entities with credible evidence, rather than using “openness” as a proxy for wrongdoing.

The remarks also suggest that this is not an isolated move. The U.S. has already been pursuing a broader strategy to constrain China’s AI trajectory. Sanctions against open models would fit into a pattern: expand the scope of restrictions from physical components to digital capabilities, and from individual companies to entire categories of technology. This is consistent with how modern sanctions regimes often evolve. They start with clear targets—specific firms, specific products—and then broaden as governments refine their understanding of supply chains and dependencies.

If this policy advances, the next phase will likely involve clarification. Observers will want to know whether the U.S. names specific model makers, whether it focuses on particular model families, or whether it uses a more general designation tied to alleged behavior. They will also want to see how the U.S. defines “open AI models” in legal terms. Is it about public availability of weights? About licensing terms? About the ability to download and run models without restrictions? Or about the presence of code and documentation?

Those definitions matter because they determine who is affected. A narrow definition could limit the impact to a small set of releases. A broad definition could sweep in a much larger portion of the ecosystem, including models that are open-weight but not necessarily “open-source” in the strict sense. It could also affect how companies describe their products. Marketing language like “open,” “transparent,” or “community-driven” might become a compliance risk if it correlates with a category that regulators intend to police.

There is also the question of international response. Sanctions are rarely unilateral in effect; they often trigger countermeasures, legal challenges, and diplomatic friction. If the U.S. frames sanctions as a response to IP theft, China may dispute the allegations or argue that the U.S. is using IP claims as a cover for restricting technological development. That dispute could play out not only in bilateral relations but also in how other countries interpret the legitimacy of the U.S. approach. Countries that value open research may resist policies that appear to punish openness, while countries concerned about IP enforcement may support stronger deterrence.

From a market perspective, the immediate impact may be less about sudden bans