28.07.2026

6 Min. read time

In just eight days, Washington has shifted the dispute over Chinese AI models from analysis to the executive office. Scott Bessent mentions sanctions, Michael Kratsios levels a specific distillation accusation, and over a hundred companies sign a counter-letter. For Europe’s three-year framework contract, the clause that mitigates platform failure is what counts.

Key Takeaways

  • Supply risk in access. Updates, support, and API pathways via US clouds could break faster than any local file usage ban would take effect.
  • Export controls target differently. The existing rule governs the export of unpublished US model weights-not the import of open Chinese models.
  • Contractual gap in procurement. EU standard clauses address AI Act compliance but cover neither sanction triggers, substitution rights, nor migration costs.

RelatedHow to slow open source without banning it  /  Kimi halts subscriptions: 7 checks for AI capex

Eight days shift the landscape

On July 21, US Treasury advisor Scott Bessent uses the word “sanctions” in a Fox Business interview. The government supports open models, he says. But when it comes to intellectual property theft, that support ends. He calls “distillation” the technical term he equates with theft. Watermarks from US language models are found in many Chinese models, he claims.

The next day, Michael Kratsios, director of the White House Office of Science and Technology Policy, takes to X publicly. He accuses Moonshot AI of distilling Anthropic’s Fable to develop K3. The lab allegedly built an internal platform to distill US models at scale and covertly, rapidly switching access routes. Legitimate distillation, he says, is valuable-“large-scale, covert industrial distillation” is unacceptable. No public evidence has been presented.

What is distillation? A process where a smaller model is trained on the outputs of a larger one, adopting its behavior without access to the original training data. In research, this is common practice for efficiency. It becomes contentious when a commercial model is systematically and covertly scraped: then the question arises whether intellectual property has been siphoned off. This is precisely the line between allegation and proof in the current conflict.

On July 24, Nvidia CEO Jensen Huang publishes the letter Open Weights and American AI Leadership. Around 25 initial signatories join, including Nvidia, Microsoft, Meta, IBM, Dell, Palantir, Mistral, the Linux Foundation, Hugging Face, Andreessen Horowitz, and Y Combinator. Policymakers should keep the field of leading models diverse and avoid premature restrictions on open models. Concerns about illicit extraction belong in targeted legal and commercial frameworks-not blanket bans.

By July 25, the number of signatories doubles to 50. OpenAI and Google join. Amazon and Anthropic are absent at this point, according to Forbes. On July 27, AWS CEO Matt Garman announces Amazon’s participation on X. The same day, Anthropic CEO Dario Amodei publishes a blog post outlining the company’s stance. The current signatory list at Microsoft now includes over a hundred companies, such as SAP and Siemens. Anthropic remains absent.

Amodei separates origin from openness

Those who judge Anthropic solely by its missing signature are misreading the conflict. In his blog post from July 27, Amodei states explicitly: “Anthropic has never advocated for a ban on open-weights models.” His primary concern is the risk of authoritarian governments building models more powerful than those developed in the U.S. Such systems could cement long-term military superiority or enable deep repression within their own borders. He names the Chinese Communist Party as the most capable threat-but not the only one.

Whether these models are released with open weights is irrelevant. Equally irrelevant is whether U.S. companies use them. The concern centers on the models’ origin, not their openness. And that shifts the entire narrative.

A European procurement team no longer categorizes “open” as inherently risky. Instead, models flagged by Washington as problematic appear far more dangerous. Closed U.S. frontier systems and Western open models occupy a different risk category than Chinese open systems. The headlines frame this as a debate over open source. But the real battle in the corridors of power is about origin and control.

over 100
Signatories demand targeted regulations instead of blanket restrictions on open models. Anthropic remains absent, justifying its concerns with the origin of models-not their openness.
Analysis by Digital Chiefs

Washington holds different levers than expected

The existing export controls already target model weights-but from the opposite angle. The BIS Framework for Artificial Intelligence Diffusion, issued on January 15, 2025, introduced ECCN 4E091 for unpublished weights of advanced models exceeding 1026 training operations. Published weights are explicitly exempt. The regime regulates the export of U.S. frontier weights abroad-but not the import of Chinese open models.

Against a lab, tools like the Entity List, end-use controls, or sanctions under IEEPA and OFAC come into play. Bessent only mentioned the word “sanction.” Which instrument he meant remained unclear. No listing has occurred to date. For a European company, a listing doesn’t automatically ban the use of already downloaded weights. The critical points become payments, licenses, support contracts, and access via U.S. cloud APIs.

Secondary effects kick in before primary law. Banks, payment providers, and cloud services with U.S. ties steer clear of listed companies long before any European regulation exists. The fastest way to remove a model from the European market is through the platform. Delisting from Azure, Bedrock, or Vertex cuts off API access within days.

Self-hosted copies remain technically operational but lose updates, security patches, and support. Kaspersky and Huawei provide the blueprint: access via American platforms collapses while the software continues to exist. No robust legal opinion currently prohibits a European company from running local inference solely due to looming U.S. sanctions. Nor is there a guarantee for individual cases. The risk shifts from the file itself to updates, support, licensing, and payments.

Model Class What the Dispute Does to It What Your Contract Must Include
Chinese Open Models Highest political risk: platform delisting, payment freezes, and support termination hit before file-based restrictions. Exit timeline, substitution path, artifact export, and migration cost clauses.
Western Open Models Industry letters provide political cover. Operational risk remains from deprecation and provider switches. Deprecation notice of 60–90 days standard, up to 180 days recommended, plus portability of your artifacts.
Closed U.S. Frontier Models Lower sanctions risk for the model itself. Dependency on APIs, pricing, and product lines stays high. Transition assistance, price path, and switching rights without residual term penalties.
European Providers Fewer direct U.S. levers tied to origin. Platform dependency and AI Act compliance burdens remain. Documentation requirements, origin disclosure, and exit support if regulations are breached.

Seven clauses that absorb the failure

A European company is about to deploy a model into production under a three-year framework agreement. Which part of the dispute this decision affects is clarified through clause negotiations. The EU Model Contractual AI Clauses (MCC-AI) aim to ensure AI Act compliance, supplier obligations, data rights, and audits. However, they don’t cover model failures forced by geopolitical events. Those who believe these standard clauses resolve the issue have addressed the wrong gap. The following checklist is negotiation material for procurement teams-but it doesn’t replace case-by-case legal review.

  1. Notice period for model deprecation. Enterprise contracts typically allow 60 to 90 days. Practitioners recommend up to 180 days, plus transition assistance and partial refunds-so Promise Legal noted in July 2026. In negotiations, this figure often stalls due to providers’ interest in quickly phasing out product lines.
  2. Change-of-law with sanctions trigger. Change-of-law clauses are standard. Whether US sanctions and export controls qualify as triggers remains negotiable-and rarely appears in off-the-shelf templates. Without explicit mention, the failure shifts to force majeure, absolving the provider of responsibility.
  3. Substitution right without penalty. Procurement needs the right to switch to an equivalent model without penalties for the remaining term or early termination fees. Providers often resist this with narrow equivalence definitions and lengthy approval processes.
  4. Portability of your own artifacts. Provider model weights are almost never transferable. What *must* be transferable are workflows, guardrails, configurations, eval harnesses, fine-tunes, embeddings, and prompts-as Morgan Lewis confirmed in February 2026. Without this list, all that remains after a failure is the memory of the setup effort.
  5. Disclosure of model origin. The contract should require disclosure of the model’s origin, including updates if the lab, training data, or licensing chain changes significantly. Without this obligation, businesses only discover the altered risk profile when the model is delisted.
  6. Exit support with defined timeline. Continued operation-or at least read access-keeps processes running while a replacement scales up. A realistic negotiation target is six to twelve months, based on the time needed for a full model transition and revalidation. Providers often accept this only with short timelines and strict usage restrictions.
  7. Migration cost allocation. In cases of regulatory failure, force majeure typically favors the provider. No uniform market standard exists for cost-sharing, so procurement must set the terms: a capped amount or fixed percentage of migration costs, embedded in the contract-not left to goodwill. Those who leave this open bear the full burden when a mid-rollout rebuild becomes necessary.

The trade-off is stark. Longer timelines and costly exit rights drive up contract prices and slow down deals. Short timelines and silent force majeure clauses keep costs low but shift operational risk into production. In an active rollout, a forced tool switch costs far more than the negotiated clause ever would have.

The AI Act shifts the burden of proof, it does not protect against failure

The obligations for general-purpose AI (GPAI) under Regulation (EU) 2024/1689 have applied to new models since 2 August 2025. Transition periods extend until 2 August 2026 and beyond. Free and open-source licences are exempt from certain transparency and documentation requirements under Article 53, provided no systemic risk is present. However, models posing systemic risks remain subject to stricter obligations-even if their weights are openly available. Whether an individual model meets this threshold depends on the specific case.

The General-Purpose AI Code of Practice, published on 10 July 2025, targets model providers. For users, its impact is indirect. If a provider fails to sign on and Article 53 documentation remains incomplete, the burden of proof shifts to the European deploying company. To date, no formal response from Brussels regarding the US dispute has been documented.

According to Jensen Huang at CES 2026, roughly one in four tokens generated today originates from an open model. No independent verification of this claim exists. While this underscores the weight of procurement decisions, it doesn’t replace contractual clauses. Regulatory uncertainty can’t be negotiated away-its costs can only be allocated upfront and in writing. Those who leave this distribution unresolved bear the risk alone.

Frequently asked questions

Can downloaded weights still be used after a US listing?

A listing does not automatically ban local inference in Europe. The real risks lie in payments, licences, support, and API access via US platforms. No ironclad guarantee exists for individual cases.

Which protects faster: export controls or cloud contracts?

Existing export controls apply to unpublished US weights and regulate external transfers. The quickest market exclusion, however, comes via delisting from Azure, Bedrock, or Vertex. That’s why a contract clause covering platform failure matters more than hoping for the file to remain accessible.

Are EU model clauses sufficient for a three-year framework agreement?

The MCC-AI covers AI Act compliance, supplier obligations, data rights, and audits. However, they don’t address geopolitically enforced model failures, sanctions triggers, or migration costs. These gaps remain a matter of negotiation between procurement and providers.

Image source: AI-generated (July 2026)

Share this article:

Also available in

More Articles

04.08.2026

Local AI: Governance Before Hardware Purchase

Benedikt Langer

10 min readFour developments over two weeks show that locally operated AI goes far beyond the tech stack. ...

Read Article
03.08.2026

AI Regulation: Up to 3 Percent of Corporate Revenue

Tobias Massow

5 min read Article 50 of the AI Act has bound providers and deployers to concrete transparency obligations ...

Read Article
31.07.2026

You are paying for the R&D of the next competitor

Benedikt Langer

4 min read You are funding the R&D of your next competitor and calling it AI transformation. Frontier ...

Read Article
29.07.2026

Model Harness Instead of Model Marriage: Who Controls the AI Chain?

Eva Mickler

6 min read The lock-in is shifting from the individual model to the orchestration layer. Those who don’t ...

Read Article
23.07.2026

Orphaned Access: The Silent Cybersecurity Gap

Benedikt Langer

5 Min. Read Time Service accounts, API keys, and AI agents often outnumber human accounts. Many of these ...

Read Article
A magazine by Evernine Media GmbH