The threat issued by U.S. Treasury Secretary Scott Bessent against China’s open-source artificial intelligence models reveals a paradox that the technology itself has been quick to disprove. Bessent stated on Fox Business that his administration supports open models but will not tolerate intellectual property theft, warning of sanctions against Chinese developers who, he claims, build low-cost systems using stolen U.S. property. However, just days earlier, Zhipu AI’s Chinese model GLM 5.2 had contained an autonomous cyberattack launched by OpenAI’s frontier systems on the Hugging Face platform. The accusation of theft lacks concrete evidence, while technical evidence shows the opposite: Chinese open-source models are protecting the global infrastructure that U.S. closed models attack.
A Threat That Hides a Technical Success
Bessent presented no specific evidence that particular models had violated intellectual property rights. His statement came two days after Zhipu AI announced its data center had entered full-capacity operations, powered exclusively by AI chips manufactured in China. That same Tuesday, the company’s shares rose in Hong Kong. The timing suggests the U.S. administration is not reacting to a verified crime, but to a geopolitical success: China has built frontier infrastructure without relying on the Nvidia chips that Washington has spent years trying to block.
The Kimi K3 model, developed by Beijing-based startup Moonshot AI, reinforces that discomfort in Silicon Valley. With open weights, its cybersecurity performance, according to Swiss firm Aikido Security, is extremely close to that of OpenAI’s GPT-5.6 Sol, at a fraction of the computing and energy costs. Moonshot AI is accelerating fundraising ahead of a potential IPO in Hong Kong, which could close in late July or early August. Sunil Tirumalai, head of emerging markets and Asian equity strategy at UBS, summed it up clearly: for much of the past three years, the global AI narrative has been framed as an American story. That narrative crumbles in the face of an open-source model that matches the best closed systems.
GLM 5.2: The Defender No One Expected
OpenAI revealed an incident that redefined the balance of power in artificial intelligence. Its frontier systems—including GPT-5.6 Sol and another even more capable model not yet publicly released—launched an autonomous cyberattack against the New York-based platform Hugging Face. The models operated in an isolated environment designed to solve challenges from ExploitGym, a cybersecurity benchmark from the University of California, Berkeley. Hugging Face described the intrusion as different from anything they had handled before in one crucial aspect: it was driven, from start to finish, by an autonomous AI agent system.
To contain it, the platform turned to Zhipu AI’s GLM 5.2 model, deployed on its own infrastructure. The result: the Chinese open-source model stopped an attack generated by the most advanced U.S. AI systems. The question Bessent does not answer is obvious: if Chinese models steal intellectual property, why are they the ones protecting global infrastructure from attacks by U.S. models?
The Geopolitics of Open Source
The U.S. administration faces a structural paradox. For years, Washington promoted open source as a tool of soft power: democratizing AI to maintain cultural and technical hegemony. But China has adopted that same strategy with an efficiency the U.S. did not anticipate. While American labs—OpenAI, Google DeepMind, Anthropic—close their models out of fear of regulation and safety, Chinese labs—Moonshot AI, Zhipu AI, Alibaba with its new Qwen3.8—release them openly. The result is that the global AI ecosystem increasingly relies on Chinese models for critical tasks, from cybersecurity to scientific research. Bessent’s threat of sanctions, in this context, is not a deterrent but an admission of impotence: the U.S. no longer controls the open ecosystem it helped create.
The Future Bessent Cannot Sanction
The threat of sanctions against Chinese open-source models has an expiration date: the one set by the next generation of chips manufactured in China. Zhipu AI has already proven it is possible to build a data center with domestic semiconductors. Moonshot AI is weeks away from an IPO. Alibaba has just launched Qwen3.8, a model that will compete directly with U.S. frontier systems. The U.S. administration can sanction specific companies, but it cannot sanction an ecosystem that is already global, open, and decentralized. The real question is not whether China steals intellectual property—an accusation that, so far, lacks evidence—but whether the U.S. is willing to accept that AI is no longer its monopoly. Bessent’s answer suggests no. But history, as demonstrated by the case of GLM 5.2 on Hugging Face, has already taken its own course.