SEAN LATTIMORE JR.

Protecting the Franchise?

Oct 6 2026

National Security, Chinese Open-Weight AI, Hypocrisy, and What We Can Learn from the Railroad Buildout

Chinese labs are releasing open-weight AI models that rival leading U.S. models on public benchmarks. Anyone can download, run and modify them for free. Being able to tinker with model weights to suit a companies specific needs is proving to be a cost-effective AI solution.

Some of these Chinese models carry real security risks. But more apparent, they threaten the business plan behind the American AI buildout, which currently depends on customers paying high prices for "closed... but safe" models.

This memo asks how the United States should respond. It recommends that the government use formal, public tools: rules for its own computers, published security testing, and, if the risk is serious enough, Commerce Department supply-chain rules made through notice and comment.

What it should avoid is informal pressure from government agencies on private companies. Informal pressure complicates a true security threat from a business threat. History shows that this strategy ends up protecting the same companies that have already leveraged public money to get where they are: leading the race.

The transcontinental railroad buildout shows why this is important to consider. It was a wartime national security project, and that label made it easy for insiders to wave off hard questions until the money was gone, and a small few won.


In July 2026, the Chinese company Moonshot AI released Kimi K3 on Hugging Face, a powerful open-weight model anyone can download and run on their own computers. The next day, Dean Ball, OpenAI's Head of Strategic Futures, posted a thread arguing that open-weight models are "inherently decelerationist" because they "deter further AI capex."

In other words, free models make it harder to justify spending on data centers and consumers spending $200 a month on a pro-tier subscription. Then he went on to say:

One probable outcome of an open-weight-model-dominant world is full AI communism.

He described how several federal agencies could spread fear, uncertainty, and doubt about these models so that regulated companies would stay away from them, and he said the effort "needn't be that well justified."

Ball later said he was predicting rather than advocating, and that the posts were "not what OpenAI thinks." Around the same time, Axios reported on an internal Trump administration fight over how to push back on Chinese AI.

That puts a real decision in front of the federal government. Chinese, and non-Chinese, open-weight models are spreading fast. They're very capable, and some of them carry real risks. The question is which tool the government should use to deal with this rapid innovation.

My answer is this: the United States should address the risks of Chinese open-weight models through formal, public, reviewable rules, not quiet pressure from federal agencies.

Additionally, while writing the rules, the U.S. government should be hesitant to enact broad-stroke laws influenced by public-pressure "hysteria-marketing" led by companies who would benefit from regulating new entrants. The goal here should be to enact sensible regulation that does not stifle innovation.

Quiet pressure can't tell a real security threat from a business threat, so it ends up protecting the same companies that already receive public money. That holds even though some Chinese models do carry real risks, and even though formal rules take longer.

The government should also hold the leading "frontier models" to a higher level of scrutiny, given their capabilities and spending power, opening the playing field for more entrants. The end game should not be a world where Anthropic and OpenAI are the only players insulated by regulation and everyone else gets boxed out.

History helps here. In 1862, in the midst of the Civil War, Congress passed the Pacific Railway Act, which began the buildout of the transcontinental railroad. This was built in the name of national security. The goal was to link the Pacific coast to the Union, enabling the movement of troops, mail, and supplies.

The security was a real need. But it also gave cover to one of the largest insider deals in American history.

This memo proceeds as follows:

  • Part I tells that story briefly.
  • Part II lays out the problem today: the real risks, the business stakes, and the current pressure campaign.
  • Part III makes a recommendation.
  • Part IV takes on the strongest counterargument.

The Railroad Was a National Security Project Too

The Pacific Railway Act was quite clear with its intent. Its purpose was to aid in building a railroad and telegraph line to the Pacific "and to secure to the Government the use of the same for postal, military, and other purposes." The company had to carry "mails, troops, and munitions of war" for the government "whenever required." In return, Congress granted the builders public land and government bonds.

The insiders who ran the Union Pacific also owned a construction company called Crédit Mobilier of America. They hired themselves to build the road and paid themselves with the railroad's own stock and bonds.

Estimates from the time put Crédit Mobilier's bills near $94 million against real costs closer to $50 million. The railroad struggled, and the construction company got rich.

When Congress started asking questions, Representative Oakes Ames sold cheap shares to fellow members. A House committee later found he did it so Congress would:

resist any encroachment upon, or interference with the rights and privileges already secured.

Put simply, the stock went to lawmakers so they would protect a deal that was already done.

Two lessons carry forward here:

  • A real national purpose made the deal hard to question. Anyone who pushed back could be accused of standing in the way of winning the war and settling the West.
  • The law showed up, but it lagged. The scandal broke in 1872, after the money was spent.

Eventually courts and Congress wrote the new rules for railroads. In Munn v. Illinois, the Supreme Court said that when someone puts property to a use the public depends on, the public gains a say in how it is used. But by then, the panics of 1873 and 1893 had wiped out much of the money that built the railroads.

The railroad indeed was worth building. The way it was paid for still went badly wrong. I feel the same way about AI.

I'm not claiming anyone today is Oakes Ames. My point is that today's deal is being built out in a very similar way, and history gleans light on what questions to ask.


The Problem Today

The Security Risks Are Real

First, the security concerns deserve attention. The Center for AI Standards and Innovation (CAISI), a federal office inside the National Institute of Standards and Technology, performed security experiments in September 2025 comparing three DeepSeek models against American models. They found that DeepSeek's R1-0528 model was:

  • twelve times more likely, on average, to follow hidden malicious instructions while acting as an agent (the kind of attack that leads to phishing emails and stolen passwords)
  • willing, with common jailbreak tricks, to answer 94% of plainly malicious requests, compared with 8% for the American models
  • four times as likely to parrot Chinese Communist Party talking points

DeepSeek downloads had skyrocketed nearly 1,000% since January 2025.

The government has already acted on these concerns. The Navy, NASA, and the Pentagon's IT agency blocked DeepSeek on their systems in early 2025. Texas, New York, and Virginia banned it on their state devices, and there's a bipartisan bill that would do the same across the federal government.

Those are sensible steps. A government gets to decide what software runs on its own computers.

Two points still matter:

  • CAISI tested particular models. Its findings don't necessarily apply to every open model made in China.
  • Where a model runs makes a difference. Using a chatbot hosted in China sends your data to Chinese servers. Running downloaded weights on your own servers doesn't, although the model can still have the weaknesses CAISI found.

The Business Stakes Are Real Too

The American AI buildout runs on an assumption, some might even call it a risky bet: that customers will continue to pay high prices for closed models served from giant data centers.

Much of the money flows in a loop:

  • Microsoft invests in OpenAI.
  • OpenAI spends that money on Microsoft's cloud.
  • Microsoft counts the spending as cloud revenue while also owning a stake in OpenAI.
  • Nvidia invests in companies that buy its chips.

The Federal Trade Commission has described this pattern in cloud-and-AI deals, where the AI developer has to spend a large share of the investment back on the investor's cloud.

Stargate, announced at the White House in January 2025 as a project of up to $500 billion, is presented as a national priority. States offer tax incentives. Virginia and Texas each give up around a billion dollars a year in data-center sales tax exemptions.

None of this is illegal on its face. The point is that the buildout is dependent on AI staying expensive. A free model that is nearly as good is a direct threat to that plan. That is what Ball meant when he said open weights "deter further AI capex."

The Pressure Campaign

So the same product raises two separate issues: one about security, and one about protecting the investment. Trouble starts when a single tool is used to solve both, formally or informally.

Ball's thread described one way to keep companies off Chinese open models without passing any rule. Several agencies signal concern until a bank's general counsel decides the model isn't worth the career risk. There is no notice, no comment period, no judge, and no published evidence. In his words, the effort:

needn't be that well justified.

Economists have coined names for this. George Stigler argued that industries often end up shaping the rules meant to govern them. Bruce Yandle called it "bootleggers and Baptists."

Preachers wanted Sunday liquor sales banned for moral reasons. Bootleggers wanted the same ban because it was good for business. The preachers supplied the public reason, and the bootleggers got paid.

Here, the real security concerns play the preachers' role. Companies that need AI to stay expensive play the bootleggers'. Both want the same outcome, and informal pressure lets them get it without anyone having to show which reason is doing the work.

That is why I added the word Hypocrisy in the title. The closed AI industry is built on public support: tax breaks, grid access, CHIPS Act money, and export controls that keep top chips away from Chinese rivals. Yet its defenders describe an open-weight future, and the public duties that might come with public support, as "full AI communism."


Use Formal Tools, Matched to the Risk

The government already has the right tools. What it needs to do is employ the right tool for the right problem.

Government computers

The government should continue to set its own rules for its own computers. Banning risky models on federal and state devices, and writing those limits into federal purchasing rules, is fair and fast. This is where the CAISI findings belong. The government should also be continuously stress-testing the leading models.

Private companies

For businesses, the government's best tool is information. CAISI should keep testing models. Other third parties should quality-check CAISI methodologies to make sure they aren't skewed. American models should run the same public tests, and the results should be published.

Regulators can then tell banks and hospitals what to check before they deploy any model, from any country. A bank's general counsel can make a real decision based on real evidence. What agencies shouldn't do is hint and warn without evidence and hope companies get scared.

If the risk is serious enough to ban private use

The Commerce Department already has a process for this. Under a 2019 executive order, it can block transactions involving technology from foreign adversaries when that technology poses an undue risk to the United States. It used this power against Chinese and Russian connected-car technology. It proposed a rule in the fall of 2024, took public comments, and issued a final rule in January 2025.

If Chinese open models are as dangerous as some say, the same process is available. The government would have to publish its reasons, hear from the public, and defend a rule that a court can review.

That last point is the heart of this memo. A formal process forces the government to show the harm. If the only way to justify a restriction is that it "needn't be that well justified," that is a sign the restriction is about something other than security.

Public debate is healthy for a high-functioning society. The sooner the information is out there, the sooner the public will be able to discuss practical solutions.

This approach also keeps two very different things apart:

  • Export controls that keep advanced chips out of China's hands are aimed at a foreign government's access to a chokepoint.
  • A campaign to keep an American bank from running a free model is aimed at a competitor's customers.

The law should treat them differently.

Any measure aimed at open models should also pass three tests:

  1. Is the harm caused by openness? Or would any capable model create it? If American closed models carry the same risk, the rule should cover them too.
  2. Is the tool a bona fide process that can be reviewed? Does it run through a process with published evidence and judicial review, or is it a tool that can be selected because it doesn't have to be justified?
  3. Who benefits from the law if it works, who makes money? Who gets shut out? If the answer is mostly the companies already receiving subsidies, the rule deserves a closer look.

Asking these questions isn't hostile towards AI safety. The goal is a security system that people will still trust, which allows entrants to compete.


The Strongest Objection

The best argument against this memo is that the defense is the spending. America's lead in AI depends on its labs earning enough to keep building. If the free Chinese models attract their customers, labs fall behind and China catches up.

So protecting their revenue is itself national security, and speed matters more than process. A formal rule can take a year, and the race won't wait. Some of the evidence may also be classified.

This objection is a good argument, and parts of it are right. The American lead does matter, and the government can fairly want strong American AI companies.

But if that is the goal, the honest way to reach it is to just say so. Congress can support American AI directly, as it did for chips in the CHIPS Act, and attach conditions:

  • report where the money goes
  • pay for the grid upgrades you cause
  • give back benefits if promises aren't kept

That is how the country eventually handled the railroads. Businesses that take public support take on public duties.

Protecting companies' prices through security warnings that no one has to prove has two costs. It weakens trust in security warnings when a real one comes along. And it locks the country into the most expensive version of the technology.

The speed and secrecy points have answers too:

  • The government can act on its own systems right away.
  • Commerce can issue interim rules in an emergency.
  • Classified evidence can be shared with Congress even when it can't be published.

What would change my mind? Two things:

  1. Testing that showed downloaded weights contain hidden backdoors that switch on under certain conditions and can't be found or fixed.
  2. Clear data showing that open-weight competition is cutting American investment enough to cost the country its lead.

I haven't seen either. If that evidence shows up, it belongs in a public rulemaking, which is exactly what this memo recommends.


Conclusion

The railroad was worth building, and the Union was right to support it as a national security effort. Neither fact stopped insiders from getting rich while the public paid. The security label made hard questions sound unpatriotic.

AI will matter more than the railroad did. China is a real competitor, and some Chinese models carry real risks. Neither is a reason to close the market.

This country excels when more than one company can innovate and build the important thing. Newcomers should not need the incumbent's permission. Government shouldn't let the incumbents influence regulation. This nation was founded on competition, open and free competition.

An open-weight model is that newcomer. Anyone can download it, inspect it, and adapt it, here or abroad. Cut that off and Anthropic and OpenAI become the keepers of intelligence, protected by the tax breaks, the export wall, and a warning no one has to prove. That is what we don't want.

The checks should run up, not only down.

  • Keep risky models off government systems.
  • Publish the tests.
  • Use a real supply-chain rule if the danger is serious enough to bind private parties.
  • Run those same tests on the labs already taking the public money.

A firm that holds the model, the cloud, and the customer does not get a lighter look because it is American.


Written as a memo for Central Challenges in National Security Law and Policy, October 6, 2026.