We forecast that by the end of 2028, US federal procurement will require buyers to certify the lineage of every model they use and will exclude Chinese-derived open weights, while Chinese families still carry most open-model use worldwide.
Key points
- We put about 65% on federal lineage attestation rules that exclude Chinese-derived weights being in force by end of 2028.
- The trigger is likely cyber: an open-weight model that matches today's gated vulnerability-finding systems.
- The rule would split the open layer into two tiers. US federal and regulated buyers would use a smaller Western tier, and everyone else would stay on Qwen and its peers.
- Chinese open weights keep their global default status, because the rule changes who may use them, not what they cost or how well they work.
- Builders who track model lineage now will face an audit. Those who don't may face a forced migration.
Our forecast
By 31 December 2028, a binding US rule (a FAR clause, a DoD procurement requirement or an equivalent agency mandate) will require federal contractors to attest that deliverables contain no weights, adapters or distillations derived from covered Chinese model families. At the same time, Chinese families will still account for more than half of open-model tokens on neutral routers. About 65%.
Why we think so
The series points one way. The signal scan found the open layer anchored in China: about 61% of OpenRouter tokens and about 70% of new derivatives built on Qwen1. Contradictions showed this dominance holds even though open models trail the closed frontier by about four months2. Usage share doesn't depend on catching the frontier. Research depends on these weights too. Open weights appear in 44% of single-model-family papers, and Chinese families make up about 60% of those choices3. That is too deep a dependence to unwind through market pressure alone. Only a legal rule could split it.
Convergences identified the likely trigger. Closed models already find zero-days faster than anyone can patch them4. Criminals have already built a working exploit with an LLM5, and Chinese state actors already sit inside US carrier routers6. With a four-month lag, an open model with comparable offensive skill is plausible by late 2027. When one appears, Washington will want a lever, and weights cannot be recalled once released. Procurement is the lever it can pull without new legislation.
Implications showed the government is willing to use it. The Pentagon labelled a domestic AI firm a supply-chain risk and ordered contractors to certify they didn't use its models7. A court struck that down as retaliation, but a rule aimed at foreign-lineage weights would stand on much firmer legal ground. Framing AI as a race for superintelligence makes the rule easier to justify, because it treats every downloaded model as a national asset or a national liability.
Global usage won't follow the rule. Token prices are at record lows, and Chinese hosts compete on price. Outside the federal perimeter, builders have little reason to switch.
How this call fails
It is 2029 and we were wrong. The most likely story is that the administration's industrial policy won out. The same race framing that justifies restriction was used to defend openness, as the 270-organization letter against release limits argued, and officials settled on softer measures such as disclosure or voluntary guidance. A second path is that a strong US open family retook the top open slot, so the problem looked like it was solving itself. A third is that Washington acted more broadly and restricted downloads or hosting outright. That would be a different forecast, and our procurement claim would miss by overshooting.
Who loses
- Federal contractors and their suppliers, who would have to trace Qwen ancestry buried in fine-tunes they never labelled.
- US researchers on federal grants, whose projects could be stopped partway through3.
- Western open-model hosts, who would serve a smaller, audit-heavy market at the same commodity margins, and already carry grid and siting costs89.
- Chinese labs, a little. They would lose a prestige market, but that market is small next to global default status.
First moves
- Build a lineage register for every model in production: base family, adapters, distillation sources.
- Keep deployments portable across model families, so switching away from a banned lineage means swapping weights rather than rebuilding the product.
- Test at least one Western open model on your real workloads now, while there is no deadline.
- If you rely on threat-sharing protections, plan for them to lapse. The statute now survives on short extensions10.
- Contractors should budget for attestation in 2027 bids.
What would change our mind
- An executive order or agency guidance that explicitly protects open-weight use regardless of lineage. That would cut our estimate to about 35%.
- Epoch's measured gap widening past six months with no open model close to Mythos-class. The cyber trigger would weaken2.
- Chinese share of router tokens falling below 45% by market forces alone, which would remove the need for a rule1.
- Draft language restricting downloads or hosting rather than procurement. That would tell us restriction is coming faster and broader than we forecast.
Sources
- Chinese open-weight models dominate real-world token use and derivative models · institutional ↩
- Best open-weight models trail the closed frontier by about four months, and the gap has widened slightly · grey-lit ↩
- Open-weight use in science reaches 44%, driven mainly by Qwen · peer-reviewed ↩
- Mythos-class AI finds more than 10,000 high/critical vulnerabilities across every major OS and browser · disclosure · also helpnetsecurity.com ↩
- Google confirms the first AI-generated zero-day used in a planned mass-exploitation campaign · disclosure · also cnbc.com ↩
- Chinese state actors hold persistent access inside US ISP backbone and provider-edge routers · institutional ↩
- The Pentagon labels a leading US AI company a 'supply chain risk'; a court rules the label unlawful retaliation · journalism · also cnbc.com ↩
- NERC issues a rare Level 3 alert after 1,000+ MW data center loads drop off the grid in seconds · journalism · also powermag.com ↩
- DOE models a 100x rise in US blackout risk by 2030 as load outruns firm capacity · institutional ↩
- The legal basis for US cyber threat-sharing survives on short-term extensions while CISA loses staff · journalism · also congress.gov ↩