Local AI: Governance Before Hardware Purchase
Benedikt Langer
10 min readFour developments over two weeks show that locally operated AI goes far beyond the tech stack. ...
6 Min. read time
In just eight days, Washington has shifted the dispute over Chinese AI models from analysis to the executive office. Scott Bessent mentions sanctions, Michael Kratsios levels a specific distillation accusation, and over a hundred companies sign a counter-letter. For Europe’s three-year framework contract, the clause that mitigates platform failure is what counts.
Key Takeaways
RelatedHow to slow open source without banning it / Kimi halts subscriptions: 7 checks for AI capex
On July 21, US Treasury advisor Scott Bessent uses the word “sanctions” in a Fox Business interview. The government supports open models, he says. But when it comes to intellectual property theft, that support ends. He calls “distillation” the technical term he equates with theft. Watermarks from US language models are found in many Chinese models, he claims.
The next day, Michael Kratsios, director of the White House Office of Science and Technology Policy, takes to X publicly. He accuses Moonshot AI of distilling Anthropic’s Fable to develop K3. The lab allegedly built an internal platform to distill US models at scale and covertly, rapidly switching access routes. Legitimate distillation, he says, is valuable-“large-scale, covert industrial distillation” is unacceptable. No public evidence has been presented.
What is distillation? A process where a smaller model is trained on the outputs of a larger one, adopting its behavior without access to the original training data. In research, this is common practice for efficiency. It becomes contentious when a commercial model is systematically and covertly scraped: then the question arises whether intellectual property has been siphoned off. This is precisely the line between allegation and proof in the current conflict.
On July 24, Nvidia CEO Jensen Huang publishes the letter Open Weights and American AI Leadership. Around 25 initial signatories join, including Nvidia, Microsoft, Meta, IBM, Dell, Palantir, Mistral, the Linux Foundation, Hugging Face, Andreessen Horowitz, and Y Combinator. Policymakers should keep the field of leading models diverse and avoid premature restrictions on open models. Concerns about illicit extraction belong in targeted legal and commercial frameworks-not blanket bans.
By July 25, the number of signatories doubles to 50. OpenAI and Google join. Amazon and Anthropic are absent at this point, according to Forbes. On July 27, AWS CEO Matt Garman announces Amazon’s participation on X. The same day, Anthropic CEO Dario Amodei publishes a blog post outlining the company’s stance. The current signatory list at Microsoft now includes over a hundred companies, such as SAP and Siemens. Anthropic remains absent.
Those who judge Anthropic solely by its missing signature are misreading the conflict. In his blog post from July 27, Amodei states explicitly: “Anthropic has never advocated for a ban on open-weights models.” His primary concern is the risk of authoritarian governments building models more powerful than those developed in the U.S. Such systems could cement long-term military superiority or enable deep repression within their own borders. He names the Chinese Communist Party as the most capable threat-but not the only one.
Whether these models are released with open weights is irrelevant. Equally irrelevant is whether U.S. companies use them. The concern centers on the models’ origin, not their openness. And that shifts the entire narrative.
A European procurement team no longer categorizes “open” as inherently risky. Instead, models flagged by Washington as problematic appear far more dangerous. Closed U.S. frontier systems and Western open models occupy a different risk category than Chinese open systems. The headlines frame this as a debate over open source. But the real battle in the corridors of power is about origin and control.
The existing export controls already target model weights-but from the opposite angle. The BIS Framework for Artificial Intelligence Diffusion, issued on January 15, 2025, introduced ECCN 4E091 for unpublished weights of advanced models exceeding 1026 training operations. Published weights are explicitly exempt. The regime regulates the export of U.S. frontier weights abroad-but not the import of Chinese open models.
Against a lab, tools like the Entity List, end-use controls, or sanctions under IEEPA and OFAC come into play. Bessent only mentioned the word “sanction.” Which instrument he meant remained unclear. No listing has occurred to date. For a European company, a listing doesn’t automatically ban the use of already downloaded weights. The critical points become payments, licenses, support contracts, and access via U.S. cloud APIs.
Secondary effects kick in before primary law. Banks, payment providers, and cloud services with U.S. ties steer clear of listed companies long before any European regulation exists. The fastest way to remove a model from the European market is through the platform. Delisting from Azure, Bedrock, or Vertex cuts off API access within days.
Self-hosted copies remain technically operational but lose updates, security patches, and support. Kaspersky and Huawei provide the blueprint: access via American platforms collapses while the software continues to exist. No robust legal opinion currently prohibits a European company from running local inference solely due to looming U.S. sanctions. Nor is there a guarantee for individual cases. The risk shifts from the file itself to updates, support, licensing, and payments.
| Model Class | What the Dispute Does to It | What Your Contract Must Include |
|---|---|---|
| Chinese Open Models | Highest political risk: platform delisting, payment freezes, and support termination hit before file-based restrictions. | Exit timeline, substitution path, artifact export, and migration cost clauses. |
| Western Open Models | Industry letters provide political cover. Operational risk remains from deprecation and provider switches. | Deprecation notice of 60–90 days standard, up to 180 days recommended, plus portability of your artifacts. |
| Closed U.S. Frontier Models | Lower sanctions risk for the model itself. Dependency on APIs, pricing, and product lines stays high. | Transition assistance, price path, and switching rights without residual term penalties. |
| European Providers | Fewer direct U.S. levers tied to origin. Platform dependency and AI Act compliance burdens remain. | Documentation requirements, origin disclosure, and exit support if regulations are breached. |
A European company is about to deploy a model into production under a three-year framework agreement. Which part of the dispute this decision affects is clarified through clause negotiations. The EU Model Contractual AI Clauses (MCC-AI) aim to ensure AI Act compliance, supplier obligations, data rights, and audits. However, they don’t cover model failures forced by geopolitical events. Those who believe these standard clauses resolve the issue have addressed the wrong gap. The following checklist is negotiation material for procurement teams-but it doesn’t replace case-by-case legal review.
The trade-off is stark. Longer timelines and costly exit rights drive up contract prices and slow down deals. Short timelines and silent force majeure clauses keep costs low but shift operational risk into production. In an active rollout, a forced tool switch costs far more than the negotiated clause ever would have.
The obligations for general-purpose AI (GPAI) under Regulation (EU) 2024/1689 have applied to new models since 2 August 2025. Transition periods extend until 2 August 2026 and beyond. Free and open-source licences are exempt from certain transparency and documentation requirements under Article 53, provided no systemic risk is present. However, models posing systemic risks remain subject to stricter obligations-even if their weights are openly available. Whether an individual model meets this threshold depends on the specific case.
The General-Purpose AI Code of Practice, published on 10 July 2025, targets model providers. For users, its impact is indirect. If a provider fails to sign on and Article 53 documentation remains incomplete, the burden of proof shifts to the European deploying company. To date, no formal response from Brussels regarding the US dispute has been documented.
According to Jensen Huang at CES 2026, roughly one in four tokens generated today originates from an open model. No independent verification of this claim exists. While this underscores the weight of procurement decisions, it doesn’t replace contractual clauses. Regulatory uncertainty can’t be negotiated away-its costs can only be allocated upfront and in writing. Those who leave this distribution unresolved bear the risk alone.
A listing does not automatically ban local inference in Europe. The real risks lie in payments, licences, support, and API access via US platforms. No ironclad guarantee exists for individual cases.
Existing export controls apply to unpublished US weights and regulate external transfers. The quickest market exclusion, however, comes via delisting from Azure, Bedrock, or Vertex. That’s why a contract clause covering platform failure matters more than hoping for the file to remain accessible.
The MCC-AI covers AI Act compliance, supplier obligations, data rights, and audits. However, they don’t address geopolitically enforced model failures, sanctions triggers, or migration costs. These gaps remain a matter of negotiation between procurement and providers.
Read more on Digital Chiefs
Digital ChiefsOrphaned Access: The Silent Cybersecurity GapDigital ChiefsWhy Your Cloud Bill Never Gets SmallerDigital ChiefsThe integration that dismantles the deal case.More from the MBF Media Network
cloudmagazinAntares: Open-weight SLMs detect CVE files mybusinessfutureAI in Eastern Germany: Why SMEs must close the gap securitytodayOpenAI models hacked Hugging Face: what to check nowImage source: AI-generated (July 2026)