This piece follows one change downstream. Chinese open-weight models have become the default open layer that builders and researchers reach for, while the closed frontier stays a few months ahead.
Key points
- Chinese open-weight models now carry most open-model usage and most new derivative models worldwide.
- The best open models trail the closed frontier by about four months, and that gap has stopped shrinking.
- The first-order effect is dependence: fine-tunes, products and papers inherit the Qwen lineage.
- The second-order effect is exposure: frontier-grade capabilities, including offensive cyber skills, likely spread to open weights within months.
- The third-order effect is political: Washington is likely to treat model lineage as a supply-chain question, and it has already shown it will use blunt tools against vendors.
- Chinese labs and cost-sensitive builders gain. Western open families and anyone with an audit burden lose.
The change
Open models have not caught the frontier. They have become the base layer instead, and that layer is mostly Chinese. By May 2026, Chinese open-weight models carried about 61% of tokens routed through OpenRouter, and about 70% of new derivative models built since late 2023 started from Qwen1. In science, open weights appear in 44% of single-model-family papers in 2026, up from 12.8% in 2023, and Chinese families account for about 60% of those choices2. Meanwhile the strongest open models, all Chinese, trail the closed frontier by about four months, slightly more than before3. We covered the tension between winning users and losing ground at the frontier in Contradictions. Here we ask what that tension produces.
What follows
First-order
- Lineage lock-in. When most derivatives start from one family, fine-tuning recipes, tooling and evaluation habits all form around it. Switching becomes costly even when a Western alternative is released.
- Western open families fade. Llama and Mistral lost share in both routing and research12. With less usage there is less community tuning, which likely widens the gap.
- Audit becomes the bottleneck. Builders now rely on models shaped by PRC content rules and state priorities1. Few have the capacity to check them for bias or hidden behaviour.
Second-order
- Research splits along geopolitical lines. Researchers at Chinese institutions have 2.23 times the odds of using open weights2. If export controls or sanctions reach model access, ongoing Western work that runs on Qwen could be disrupted mid-project2.
- Capability diffuses on a schedule. A four-month lag means every frontier capability is likely to be openly downloadable within a year3. That now includes offense. Closed models already find zero-days at a volume that outpaces patching4, and criminals have used an LLM to build a working zero-day exploit for a mass campaign5. We think it is plausible, about 60%, that an open-weight model reaches comparable vulnerability discovery by late 2027. We traced this convergence in Convergences.
- The real frontier concentrates. As open models settle into a lagging default, the leading edge stays with the few closed labs that control compute3.
Third-order
- Lineage becomes a supply-chain label. The Pentagon has already designated a US AI company a supply-chain risk, and a court later ruled that unlawful retaliation6. A government willing to do that to a domestic vendor is likely to reach for similar certification rules on Chinese-lineage weights. Contractors and their suppliers would then have to strip Qwen derivatives out of their stacks quickly.
- Superintelligence framing hardens the split. Once the race is framed as a contest for superintelligence, open weights read as national assets or national liabilities, not as neutral tools. That favours restriction over openness on the US side and deliberate release as industrial strategy on the Chinese side1.
- The shadow side. Defence then depends on the same few closed firms, and one vendor's standing with the government can decide critical-infrastructure security46.
Who gains, who loses
- Chinese labs gain a global developer base and default status, which shapes standards and tooling long after any single release1.
- Cost-sensitive builders and researchers gain capable, free models for local and on-device use, for as long as access stays legal.
- Western open families lose usage, derivatives and the community effort that keeps them competitive12.
- Defence contractors and regulated firms lose flexibility. They face the audit burden now and plausibly forced migrations later.
- Closed frontier labs gain leverage as the only source of leading capability, and they also carry more political risk63.
A glimpse ahead
Procurement notice, spring 2028: "Offerors must certify that no model weights, adapters or distillations derived from covered foreign lineages are used in deliverables. Attach lineage attestation for every model in the stack." A mid-sized analytics firm checks its pipeline and finds Qwen ancestry in four of its six production models. None of them was downloaded under a Chinese name.
Sources
- Chinese open-weight models dominate real-world token use and derivative models · institutional ↩
- Open-weight use in science reaches 44%, driven mainly by Qwen · peer-reviewed ↩
- Best open-weight models trail the closed frontier by about four months, and the gap has widened slightly · grey-lit ↩
- Mythos-class AI finds more than 10,000 high/critical vulnerabilities across every major OS and browser · disclosure · also helpnetsecurity.com ↩
- Google confirms the first AI-generated zero-day used in a planned mass-exploitation campaign · disclosure · also cnbc.com ↩
- The Pentagon labels a leading US AI company a 'supply chain risk'; a court rules the label unlawful retaliation · journalism · also cnbc.com ↩