August 12, 2026 · AI

Congress Wants Chinese AI Models Out of Government. Watch Where That Line Moves Next.

The security case for keeping Chinese models out of federal systems is real, but the same logic aimed at the private market would mostly tax the small businesses who cannot afford the alternative.

Federal agencies are about to lose the option of using the cheapest AI models on the market, and that is probably the right call. What worries me is who else that logic gets pointed at next.

The No Adversarial AI Act, introduced in the House as H.R. 4142 and the Senate as S.2177 by Rick Scott and Gary Peters, would require the Federal Acquisition Security Council to maintain a public list of AI models built by foreign adversaries and bar agencies from using them, with narrow exceptions reported to Congress and the White House budget office. Bipartisan cosponsors on both sides of the Capitol tell you this is not a fringe idea.

It also arrives in the middle of a real shift in how American companies buy AI. According to PYMNTS, the share of tokens that US companies routed to Chinese models on OpenRouter, a marketplace that lets developers call dozens of models through one API, climbed from 11.5 percent at the start of 2026 to 45 percent by early July. House committees have already sent letters to Airbnb and Cursor asking about their use of China-origin models. This is not a hypothetical. It is happening at scale, right now, in production.

The reason is money. A UBS analysis reported by Cryptobriefing put Chinese open-weight models like DeepSeek, Qwen, Kimi, and GLM at $2 to $3 per million output tokens, against roughly $15 for comparable US models, with JPMorgan describing the gap as up to 50 times on a per-token basis in some comparisons. Run the arithmetic on a mid-size company processing 100 million output tokens a month, a realistic number for a business layering AI into support, sales, and internal tools: that is the difference between a $250 bill and a $1,500 one. UBS found roughly 60 percent of companies actively tracking their AI spend are already shifting workloads toward the cheaper option. That is not disloyalty to American vendors. That is a finance department doing its job.

Here is the steelman for restricting these models anyway, and it deserves a fair hearing, not a dismissal. Open-weight models ship with training data and pipelines nobody outside the lab can fully audit, and that opacity is a real attack surface, not paranoia. Anthropic, working with the UK AI Security Institute and the Alan Turing Institute, found that as few as 250 poisoned documents, a fixed number regardless of model size, were enough to plant a working backdoor in the models they tested. The study used a benign trigger, not malware, but it proves the mechanism is practical. Separately, F5 Labs documented that some open-weight model files still rely on Pickle-based serialization, a known code-execution risk in tampered files. And researchers cited by Semafor found DeepSeek's public model denied that Uyghur detention camps exist, while a distilled version of the same model, stripped of certain fine-tuning, gave a factually different answer. A model that edits reality on command from its training regime is not one you want deciding what a government analyst sees. Keeping that out of federal systems is defensible, and I do not think it is protectionism dressed up as security.

The line I would watch is whether that argument gets extended from "the government should not buy this" to "your business should not either." Those are different questions. A federal agency has an alternative: pay more for a vetted US model, funded by taxpayers who are not choosing between that and payroll. A ten-person marketing agency or a regional healthcare practice does not have that slack. A blanket restriction on the cheap tier would not fall on OpenAI and Anthropic's existing customers, who already pay full price. It would fall hardest on the businesses that only got into AI because the price dropped enough to make sense.

The better answer, and the one the bill in front of Congress actually reflects, is disclosure and scope, not a ban on competition. Make provenance a real requirement for anyone selling into sensitive environments. Let the market route routine, non-sensitive workloads to whatever is cheapest and audited, and reserve trusted, higher-cost models for the data that needs it. That is model routing, the same discipline that keeps AI spend sane at any company, not just a government one. I help clients draw that line every week: what actually needs the expensive, vetted model, and what runs fine on something a tenth the price. Getting that boundary right is worth a look before regulation draws it for you. Let's talk about where yours sits.

Sources

Every factual claim above is drawn from these independently published sources, linked inline where first referenced.

Let's talk

Tell us what's on your mind.

You don't need a polished brief to reach out. A two-line email about what's bugging you is plenty; we'll tell you straight if we're the right fit, and what we'd tackle first.

We'll scope the work around your workflow, goals, and timeline before quoting anything, so you know what's included before committing.

LocationBoca Raton, Florida
CoverageSouth Florida + remote nationwide
Status Now accepting clients