September 17, 2026

CNAS Insights | America Must Expand AI Export Controls Amid Talks with China

Ahead of the September 24 meeting between U.S. President Donald Trump and Chinese Communist Party General Secretary Xi Jinping—the latest in a string of summits that have historically included trade deals—Beijing has sought to build leverage in its technology competition with Washington.

So far, the Chinese delegation has arrived at these talks with a series of technological advances in hand, from impressive open-weight artificial intelligence (AI) model releases to purported breakthroughs in chipmaking equipment, which has led some to argue that U.S. and allied export controls have failed. But this story of Chinese success paints an incomplete picture. The United States still leads China in AI, and much of China’s recent progress has depended on American technology. The path forward is to lengthen the United States’ AI lead by expanding, not weakening, technology protections, starting with closing three priority gaps: remote access, adversarial distillation, and allied servicing of chipmaking equipment in China.

In July, Chinese company Moonshot AI released Kimi K3, an open-weight AI model with capabilities that appeared to rival U.S. competitors. Since then, two Chinese companies, Aishengna and Yuliangsheng, reportedly started mass production of deep ultraviolet immersion (DUVi) machines—chipmaking machines that can be used to make advanced AI chips. These advances help Beijing signal to the world that its rise in AI is inevitable despite U.S. export controls, and that other countries should work with it rather than against it.

However, these gains only tell half of the story. The United States retains a sizable advantage in compute, which has translated into increasingly capable models. Chinese AI company leaders have repeatedly highlighted how their compute deficit has constrained progress. Tencent President Martin Lau has acknowledged that “Tencent Cloud has consistently lacked sufficient GPU resources, which has affected our ability to gain more revenue and market share.” And Z.ai chief executive officer (CEO) Zhang Peng warned in May that the “biggest problem large-model companies face over the next 12 months may be compute.”

This compute disadvantage has kept Chinese companies from the frontier. Chinese models have made notable gains and pose real risks to U.S. national security, especially since the People’s Liberation Army is reportedly using them to support military and intelligence operations, but they have not fundamentally upset the U.S.-China AI model competition balance. Two expert assessments confirm that American AI models still lead: The United Kingdom’s AI Security Institute and the U.S. Center for AI Standards and Innovation found Kimi K3’s cyber capabilities remained five to six months behind leading U.S. models, while independent nonprofit SaferAI found that Z.ai’s GLM-5.2 trailed the U.S.-led frontier by two to four months.

Figure 1: U.S. Models Have Remained at the Frontier of Cyber Capabilities over Time

Chinese models lag U.S. frontier models on cyber capabilities according to ExploitBench, one benchmark measuring cyber offensive capabilities. OpenAI self-reported the GPT-5.6 Sol and GPT-6 Astra scores, and they have not been independently verified by ExploitBench as of publication. Source: ExploitBench

China’s chipmaking efforts suffer from similar problems. According to a Goldman Sachs analysis, China can only domestically produce around 8 percent of the advanced AI chips it needs. It also makes them less efficient: The 7-nanometer yield—or share of overall chips that are actually usable—of SMIC, China’s main semiconductor foundry, is estimated at just 26 percent, compared to Taiwanese chipmaker TSMC’s 90 percent. Even the most powerful Chinese chips are less efficient and lower quality than leading U.S. chips: Chinese company Huawei’s leading-edge chip, Ascend 950, is roughly half as powerful as Nvidia’s H100, a chip launched four years ago. The differences in quantity and quality both trace back to China’s lack of top-tier chipmaking equipment, which is why the country is now racing to build its own DUVi machines. But even these fall short: This year, Aishengna plans to produce five DUVi systems, and Yuliangsheng is targeting 12—a far cry from the 130 DUVis leading Dutch semiconductor equipment manufacturer ASML expects to ship in 2026. Chinese chipmakers continue to prefer ASML DUVi systems: SMIC still produces its most advanced chips on these systems.

Figure 2: China’s Combined 2026 DUVi Output Is One-Eighth of ASML’s

Chart: Center for a New American Security (CNAS). Source: Arjun Kharpal/CNBC and Luke James/Tom’s Hardware

Figure 3: SMIC's 7-Nanometer Yield Trails TSMC’s by 64 Percentage Points

Chart: Center for a New American Security (CNAS). Source: Goldman Sachs/South China Morning Post

China’s continued struggle to reach the AI frontier makes the case for U.S. and allied controls on exports of advanced AI chips and semiconductor manufacturing equipment. That it hasn’t fallen even further behind reveals three gaps in the U.S. technology protection regime Beijing continues to exploit.

First, Chinese companies are accessing large amounts of U.S.-origin chips remotely through the cloud, a gap in the export control regime. They are remotely accessing substantial compute, including export-controlled Nvidia Blackwell chips, through cloud computing providers in Malaysia, Thailand, Indonesia, and other countries. According to one estimate, Chinese companies have remotely accessed an estimated one million H100 equivalents, a measure of computing power based on Nvidia’s H100 chips—totaling one-twentieth of the world’s compute. They have used this compute in part to train increasingly advanced models. This activity falls into a gray area because the U.S. Department of Commerce does not interpret its authority to cover remote access of export-controlled chips.

Second, Chinese AI labs have relied on adversarial distillation—the practice of accessing more capable American AI models to train less capable models—to train their systems. Adversarial distillation campaigns are becoming increasingly sophisticated. This month, Anthropic reported the largest distillation attack it has ever observed, carried out by Chinese tech giant Alibaba. The campaign used 3,500 accounts to extract 151 million exchanges from Claude. This phenomenon has been observed across many major U.S. AI labs, but none has been able to stop it on its own. The U.S. government has vowed to take steps to support U.S. firms in defending themselves, and the Federal Bureau of Investigation, National Security Agency, and Cybersecurity and Infrastructure Security Agency have called for AI labs to share information about distillation campaigns. However, no concrete action has yet been taken, and U.S. firms remain constrained in their capacity to work together by uncertainty over what they can share under existing antitrust laws.

The purpose of U.S. export controls was never to prevent indigenization forever; it is to widen and lengthen the U.S. lead by slowing Chinese development of chips and AI.

Third, continued allied servicing of chipmaking equipment in China has sustained Chinese DUVi progress. This maintenance, performed by allied companies, notably ASML and Tokyo Electron, remains legal and has allowed Chinese chipmakers to extend the life of their machines to up to 30 years. In addition to the immediate impacts, these servicing activities have led to knowledge transfers that have allowed Chinese engineers to reverse-engineer chipmaking machines and absorb tacit know-how about the industry. Yet, Dutch and Japanese companies still service equipment in China, and allies are unlikely to put a stop to this without concerted pressure from the United States.

Some skeptics believe that expanding the U.S. export control regime to close these gaps will only accelerate Chinese efforts to indigenize its AI industry. Yet China has long desired semiconductor self-sufficiency. China has been all-in on this strategy since at least 2014, with the launch of its National Integrated Circuit Industry Investment Fund. Beijing has pursued—and will keep pursuing—this strategy regardless of what Washington does. The purpose of U.S. export controls was never to prevent indigenization forever; it is to widen and lengthen the U.S. lead by slowing Chinese development of chips and AI. And on that measure they are working: Despite massive investments by Beijing, China remains a fast follower in AI and lags in leading-edge semiconductors.

The gaps in U.S. export controls allow China to exploit the research that America and its allies have spent years and billions of dollars to produce. Adversarial distillation lets Chinese labs extract capabilities from frontier models that cost firms like Anthropic billions of dollars a year to train. Remote access enables them to harness the power of Nvidia’s chips without creating similar chips themselves. And the continued servicing of chipmaking equipment inside China leads to knowledge transfers that allow chipmakers to reverse-engineer machines that took decades and billions of dollars to create. Chinese companies will continue to use these methods to erode U.S. AI companies’ global market share, deepening global dependence on Chinese systems, which can be weaponized for influence, espionage, and military operations.

As the next U.S.-China leader summit approaches, Washington must do more than simply hold the line on export controls; it must go even further. That means stopping Chinese companies from continuing to access advanced Nvidia chips remotely to train AI models. It means reducing the antitrust uncertainty that deters U.S. companies from coordinating to combat adversarial distillation. And it means pressing allies to stop servicing chipmaking machines inside China while tightening coordination on semiconductor export controls. Many of these gaps could be closed by passing the bipartisan MATCH Act and Remote Access Security Act.

The window to act is narrow. These measures can slow but not stop China’s AI progress. They will only bite as long as Chinese companies depend on American and allied systems and infrastructure. Once China routes around U.S. and allied chipmaking technologies, that leverage will disappear.

Michelle Nie is a visiting fellow with the CNAS Technology and National Security Program; Daniel Remler is a senior fellow for the CNAS Technology and National Security Program.

View All Reports View All Articles & Multimedia