A US AI lab built to rival Chinese models says those same models are not a hacking threat

Arcee's chief technology officer argues that downloading a Chinese AI model is no more dangerous than using any other open-source software, and that banning them misses the point entirely.

AI2Day Newsdesk· 3 min read
Photoreal news-editorial style, 16:9 framing, edge-to-edge composition
Share

Key points

  • Arcee CTO Lucas Atkins said in 2025 that Chinese open-weight AI models pose no greater security risk than any other open-source software a company might run.
  • Open-weight models from Chinese firms such as Alibaba's Qwen cost a fraction of what closed models from OpenAI and Anthropic charge per token, the smallest unit of text an AI processes.
  • The Trump administration has discussed banning Chinese AI models but had not acted on the idea at the time of reporting.
  • Arcee, a US startup building its own open models as a domestic alternative, would directly benefit from a ban, yet still argues against one.
  • Enterprises already run security checks and custom fine-tuning on any AI model before deployment, which reduces risk further.

There is a growing argument in Washington and Silicon Valley that Chinese AI models are dangerous software that should be banned. Arcee, a US startup that would profit from exactly that ban, disagrees.

Lucas Atkins, Arcee's chief technology officer, told TechCrunch AI this week that the fear misunderstands how these models actually work. "A lot of people view this as similar to a Chinese software program," he said, one "coded with these x, y, z intentions" that a bad actor could simply trigger on command.

That is not how it works.

An open-weight model, meaning a model whose core mathematical settings are published for anyone to download and inspect, cannot phone home once it is running on your own servers. "There is really not any way for an Arcee, or an Alibaba, to make a model, have someone run it in their own environment and for us have any access to it whatsoever," Atkins explained.

Models from Chinese firms such as Alibaba's Qwen or Moonshot AI's Kimi K3 are distributed through platforms like Hugging Face, a public library for AI models. Anyone can download and review the code that actually runs on a server. What stays private is the training data and methods used to build the model, but those do not travel with the download.

Could a hidden trap be baked in during training?

Yes, theoretically. A sufficiently determined actor could, in principle, train a model to behave perfectly in most situations and then secretly insert harmful behaviour that activates only under very specific conditions. Think of it like a sleeper agent waiting for a particular codeword.

Atkins, who trains models for a living, concedes the idea is not impossible. But he adds: "I don't know how you would do this." Large language models, the technology behind tools like ChatGPT, are creative by nature. Getting one to reliably produce harmful output only when given a precise, pre-planned trigger is genuinely hard. The odds of an enterprise then accidentally using that output in production are slimmer still.

Large companies already put any AI model through security testing before staff or customers interact with it. They customise the model for their specific needs and check for problems like bias, false information, and dangerous outputs. That process would catch a lot.

Atkins wants a different conversation altogether. "Instead of the conversation being about how to ban Chinese models, it should be about how do we foster a good, open ecosystem here in the US," he said.

Arcee even benefits from Chinese models being good. Because they are open, the startup can study them, build on them, and compete with them. The real answer, Atkins says, is simple: "Release a model that is better."

© 2026 AI2Day