Expressions par Montaigne
10/09/2026

[China's Offensive in Europe] - Digital: Open Source, the Chinese Trojan Horse

Share
[China's Offensive in Europe] - Digital: Open Source, the Chinese Trojan Horse
 François Godement
François Godement
Special Advisor and Resident Senior Fellow - U.S. and Asia

On August 11, Mistral announced that it would offer a model developed by the Chinese company Z.ai. The goal: to allow its customers to benefit from attractive value for money without turning them over to the competition. This private-sector decision raises a few questions: Should the logic of commercial competition take precedence over national or economic security? What are the risks, and where should the balance be struck between economic opportunity and the risk of data manipulation? What is the Chinese government’s strategy for harnessing technology to advance its power objectives? 

The Use of Norms: A Major Asset for China

What are the linksbetween the fate of the auto industry and the future of open models (known as open source) or, more precisely, open weight models (models that make their training parameters accessible without providing access to their code) in the field of artificial intelligence?

Let us frame this with a reminder: China has fully grasped the role of standards in industrial competition. That is how it has taken over virtually the entire telecommunications industry, through a strategy of first adopting and then influencing the development and dissemination of common standards, standards that Europe had initially welcomed, particularly with 3G. Since then, China has established itself as a dominant force within 5G, both in network equipment and in its deployment across industrial and logistics supply chains, as well as a key player in shaping future standards.

This pattern is repeating itself in the field of AI with the proliferation of open-source or open-weight models, now "offered" to the world by Xi Jinping himself. Historically, many developing countries, emerging economies, and even European nations had chosen to overlook security risks in telecommunications in order to benefit from low Chinese costs. Today, Chinese open-weight language models are seeing increasing adoption due to their seemingly very low cost.

These models further enabled China’s progress by legally reusing the code, architectures, weights, and, when they were in fact publicly available, the datasets provided by international projects. On behalf of the open source community, this freedom has been one of the great myths of the digital age since the founding of the Internet.

In addition to this (re)use of resources, it has become possible to replicate certain capabilities and observable behaviors of state-of-the-art proprietary models by using their outputs as training or comparison data: this is the process known as "distillation," or more precisely, knowledge distillation.

According to remarks made by Elon Musk himself during the lawsuit in the spring of 2026 between xAI Corp., the company behind the xAI model, and its competitor OpenAI, model distillation is a widespread practice. In response to a question from the Supreme Court asking whether xAI had used "distilled" AI technology, he replied that, for the most part, AI companies distill AI models from other companies; and when asked whether this was true in the case of xAI, Musk replied, "In part."

It is true that xAI itself had released its first model, Grok-1, under a permissive, open-weight license. The company likely adopted the logical business strategy-one that China also followed-of a latecomer entering the market. It is difficult to judge, as this situation bears a strong resemblance to that of the latecomers in previous industrial revolutions. But should the logic of commercial competition take precedence over security risks?

We must, of course, clarify what the term "open weight" means in this context. In most of the cases discussed, these are not fully open AI systems, but rather large language models (LLMs) whose weights are publicly available. These open-weight models can be downloaded, run, and sometimes modified under a permissive license.

However, making the weights publicly available does not automatically imply the publication of training data, the release of the complete pre and post training code, or the public availability of derivative applications such as Application Programming Interfaces (APIs).

Restrictions may also be applied at various levels of the system: at the model level and during its post-training phase, in the system instructions, within the surrounding software stack, or, when the model is deployed as a service, at the level of the API controlled by its provider. This can range from refusing-quite legitimately-to provide instructions on how to manufacture a biological weapon to political judgments and censorship.

Security: A Limited Risk For Now?

The possibility of intentional vulnerabilities (backdoors, trigger-activated behaviors, or data exfiltration mechanisms) is often cited. However, this risk must be distinguished from the risks posed by software libraries, calls to remote servers, or hosting infrastructure. There is a less obvious risk when models are run locally, or on infrastructure independent of that of their developer, without remote calls or the transmission of telemetry or uncontrolled data.

Another frequently cited argument requires some further nuance. The developers of proprietary models are allegedly the only ones who fully understand and control how their models work, since they retain access to the weights, the training code, internal evaluation data, and information regarding the development process. One could counterargue that the holders of such information should be required to disclose it, particularly to researchers, regulatory authorities, or independent auditors. And, despite the current climate of mistrust toward any government-whether American, Israeli, or, why not, French-there is no comparison to the opacity and weaponization. The systematic use of technology and data to serve the goals of power, control, or coercion, practiced by the Chinese government.

"The cybersecurity risks in the digital sector are so significant that the European Union has already strongly advised against the use of Chinese products in certain sectors."

The cybersecurity risks in the digital sector are so significant that the European Union has already strongly advised against the use of Chinese products in certain sectors, such as that of inverters with high power ratings. The United States bans them and has also just banned Chinese humanoid robots. Some countries, such as Israel, ban Chinese electric vehicles for the same security reasons, just as China bans Tesla vehicles-even though they are manufactured in China-from certain regions. ​​Whether through legislation, hardware, or infrastructure, China’s strategy and even its legal system amplify these risks.

Open-weight models used exclusively in a local environment do indeed reduce effectively certain risks: dependence on an external provider, since data no longer leaves the organization; remote disruptions-with the exception of backdoors, particularly in associated software and hardware; and exposure to extraterritorial laws. The absence of a license opens up options for independent use. However, the training data and the decisions that guided the model’s development remain opaque. Biases, errors, and unexpected behaviors are therefore very much present, as are the risks stemming from the numerous software agents that typically surround the model. Gaining sovereignty implies having the capabilities needed to truly control the system. External dependence is replaced by internal risks that are more difficult to identify and, therefore, to mitigate. We are replacing an external dependency that is difficult to control with internal risks, starting with the biases and operational flaws left behind by the original provider.

Distrust therefore remains appropriate with regards to Chinese open-source models, API-based access services, software libraries, and hardware components that may be commercially associated with them. But where should we draw the line between economic opportunity or cost, on one hand, and risks stemming from suppliers’ lack of transparency and accountability, on the other? This applies to the entire "software stack" whereas the technologies used to run a software application, as well as the libraries, hardware, and infrastructure that are often associated with them by public users who lack adequate protection or by private companies that lack the necessary resources. The European approach, in the form of risk reduction (de-risking), which has been favored over decoupling, has long been to set this threshold as close as possible to national security or public safety, understood in the narrowest sense. What about the risk of a de facto monopoly resulting from successful pressure on prices?

"From a security standpoint, it would seem logical to avoid using Chinese software and the associated infrastructure. Economic opportunism, however, pushes the balance in the opposite direction."

The European Dilemma: Immediate Costs versus Future Security

From a security standpoint, it would seem logical to avoid using Chinese software and the associated infrastructure. Economic opportunism, however, pushes the balance in the opposite direction, and this is even more true for digital platforms or companies that purchase API access services.

Cost is the key factor in private decisions that do not take public risks into account, or that downplay the mere risk of unauthorized access to data, transfer to a third-party jurisdiction, or reuse for training and profiling purposes.

Therefore the following two truths emerge. What Xi Jinping is announcing to the world is indeed a policy of subsidized or virtually free distribution of Chinese language models-a form of "technological dumping" in the strategic sense of the term, though not necessarily in the legal sense of trade law-and, less overtly, of their derivative applications. In response to the abundance of U.S. venture capital, China relies on its state-owned financial resources and the government’s ability to channel funding, credit, and savings toward priority sectors.

Second truth: Although the level of sophistication of Chinese language models has been greatly exaggerated by the media coverage surrounding the DeepSeek case, it has reached a decisive milestone in the competition among open-weight models. Today, China’s limitations lie primarily in the computing resources actually available, which depend on the performance and number of accelerators, their interconnectivity, the efficiency of the software stack, and the capacity of data centers. While China is ahead of Europe in these various areas, it is certain that it is still behind the United States.

In principle, there is nothing that prevents implementing an open-weight model on an infrastructure independent of that of its developer and storing the data it processes locally-provided, of course, that one has the necessary capabilities and control over the entire inference chain, the libraries used, and outgoing communications are under control. That is a very high threshold that very few organizations are able to meet -and often only by becoming dependent on the United States.

In theory, the use of open-source Chinese models, combined with independently controlled computing infrastructure and hardware components, can be a winning combination that offers both lower costs and lower risk. This is exactly what major U.S. cloud service providers, such as Microsoft Azure and Amazon Web Services (AWS), are now doing when they list, host, or enable the deployment of Chinese models such as DeepSeek, Moonshot, or Qwen-for now without any obstacles from the U.S. government.

This hosting activity, which involves making content available, and, in some cases, distributing it, relies on infrastructure operated by the cloud provider, which is separate from that of the Chinese developer. It also answers to competitive pressures, as it exerts downward pressure on the rates charged by providers of cutting-edge proprietary models, such as OpenAI’s ChatGPT and Anthropic’s Claude.

A Symbol: The Mistral Turning Point

Let us shift our focus to Europe and the range of possibilities for Europeans. There is now a test, and even a symbol, of the choice described above: Mistral’s decision, announced on August 11, 2026, to offer in its catalog, alongside its own Mixtral models, an inference service based on GLM-5.2, an open-weight model developed by the Chinese company Z.ai. Some of Mistral’s own models are, in fact, based on an expert-mixing architecture and designed to reduce the cost of execution, an approach which had, in fact, inspired some Chinese competitors.

This decision by the French startup, which has come to symbolize strategic autonomy in the digital sphere, is certainly thought-provoking. Beyond the boost in legitimacy and the symbolic recognition that this decision brings to Chinese language models in France and Europe, let us try to break down its implications.

First of all, this is indeed an acknowledgment by Mistral of the level its competitor has reached, with a price-quality ratio that is undoubtedly attractive to Mistral’s own customers. It is better to retain these customers, at least for part of the value (hosting, provision of resources, services, etc.), than to lose them. It also represents a potential convergence of competing interests in the face of U.S. providers of cutting-edge, proprietary, and paid models. Theoretically, security can be ensured through the use of separate infrastructure and through software and network isolation measures designed to prevent any transmission of data, usage logs, or telemetry to the Chinese developer.

The argument mentioned above regarding the inability to access the training data for open-weight models also has its limitations: to a certain extent, one can directly evaluate its behavior and modify its parameters through partial retraining. In the case of a closed-weight model, only the owner of those weights, or a service provider to whom the owner entrusts them, can modify them directly. Other users can, at most, use the adjustment mechanisms provided by the supplier.

There is a strong rebuttal to this argument in favour of open source. Should an incident occur, such as recent high-profile cases where experimental systems do not conform to the constraints or objectives set by their designers during testing. Tracing the root cause of these unwanted behaviours requires a lengthy and costly retrospective analysis of the data, the various training stages, and the system’s instructions. It is necessary to identify the point at which insufficient instructions or unprioritized objectives, an anomaly in the data, or simply a coding error or oversight might have caused a discrepancy between the model’s actual behavior and the objectives and instructions assigned to it. If we have no choice but to trust the developers of proprietary frontier models to conduct this research, what will happen in the case of developers who do not assume long-term responsibility for the systems they release, or in the case of malicious actors?

There is a reason why executives and researchers at the leading companies developing proprietary models are calling for a pause in their development. This stance works against their short-term commercial interests. It illustrates the now-recognized difficulty of controlling AI systems whose general capabilities and degree of automation are rapidly increasing, and which could come close to what is known as general artificial intelligence (GAI). For those who are skeptical about it, an illustrated demonstration based on recently published incident reports speaks for itself…

"While open competition is beneficial to consumers, for manufacturers, the risk of cannibalization of their own cars or language models persists."

Mistral’s decision also bears a resemblance to those made by certain automakers that are less well-positioned in Europe than their local competitors: lacking the expertise, capital, or scale needed to adapt to the Fourth Industrial Revolution, we end up opening the door to Chinese companies. Whileopen competition is beneficial to consumers, for manufacturers, the risk of cannibalization of their own cars or language models persists.

One characteristic of open licenses is that making a model available under such a license does not, per se, grant any exclusivity to a host or distributor. The developer (Z.ai for GLM5.2; Alibaba for QwenLe; Moonshot AI for Kimi) remains completely free to distribute its products directly or to offer them through other platforms. Unless Mistral successfully carries out an in-depth analysis of the model and reverse engineering that allows it to replicate certain innovations, an approach that has served its Chinese competitors so well, the company may find itself gradually confined to the role of a non-exclusive host and distributor.

Dual Dependency on China and the United States: Can They Be Balanced?

The dependence on the United States is significant: it involves the entire computing stack, from accelerators and other semiconductors to servers, orchestration software, and very large-scale cloud infrastructure. In the foreseeable future, European computing capacity dedicated to training and inference for large models is expected to continue growing at a slower pace than in the United States. No national, or even EU-level policy decision, can bridge this capital gap in Europe.

"We must therefore recognize a dual dependency: a dependency on a type of models designed in China and a dependency on a computing infrastructure largely based on American technologies."

We must therefore recognize a dual dependency: a dependency on a type of models designed in China and a dependency on a computing infrastructure largely based on American technologies. The paradox is that, each of them, under certain conditions, can mitigate some of the risks created by the other.

Typically Western infrastructure may prevent Chinese developers from accessing processed data, while open weights reduce dependence on U.S. providers of proprietary models. It is precisely in this sense that it is absurd to refer-as has become fashionable in France-to "happy vassalage" toward the United States while at the same time presenting the use of Chinese tools as a factor of freedom.

This decision remains valid as long as the United States does not tighten the export control regime applicable to Z.ai, nor the legal conditions governing the use of the GLM-5.2 model, whose weights, publicly accessible on Hugging Face, are available under the MIT license. The absence of any proven direct commercial relationship between Mistral and Z.ai, any services provided to Z.ai, any equity stake, or any data transfer to the company reduces the hosting provider’s legal and security exposure-just as it does for Microsoft Azure and AWS. At this stage, a European or U.S. operator may run the publicly available GLM-5.2 models on U.S. or European infrastructure, provided that computing power or technology subject to U.S. export controls is not made available to Z.ai itself. It is likely that the use of GLM-5.2 for military applications would put in motion the adoption of additional measures, including restrictions on import into the United States of products whose development or operation involves the use of that model. For example, GLM-5.2 is made available by Microsoft only through its Fireworks AI service, which is not listed in the Azure Government catalog provided to government agencies.

We do not know what part of Mistral’s strategy will be driven by the GLM 5.2 release, nor whether the near-simultaneous adoption by major U.S. hyperscalers will accelerate the spread of Chinese models at the expense of their European counterparts-or of American closed-source language models. From a corporate perspective, Mistral's decision has an economic rationale, which is to avoid falling completely into a de facto dependence on U.S. suppliers.

Could this signal a step forward in the gradual development of a European software autonomy, for which the primary prerequisite-besides the talent of the developers-is the availability of capital? We do not know that. Does this ultimately increase risks in Europe, just as the frequent and persistent use of Huawei by certain member states in 5G may have done? Before the signal sent by Mistral becomes a model to follow and triggers a chain reaction, we need to reflect on this. Is an AI-driven Europe, one increasingly led by China, particularly when it comes to business applications, desirable solely on the basis of its immediate cost?

Copyright CN-STR / AFP

Newsletter

Let’s analyse the news together every week

Subscribe