If American AI Needs Sabotage, It Is Losing
A former White House AI adviser, now at OpenAI, predicts Washington's best move against Chinese models like Kimi K3: have federal agencies manufacture fear, "not that well justified". That is not AI safety. It is a rumour with a federal seal, and a ban that never has to answer for itself.
Dean Ball spent part of last year advising the White House on AI policy, and two weeks ago he joined OpenAI. So when he predicts what Washington will do, it is not just one guy guessing on the internet. His thread on X about Kimi K3 starts with an uncomfortable admission (for him): the Chinese open-weight model is very good, more or less on par with the best public models of early 2026.
By point five, the imagined American response is no longer to build something better, make it cheaper or compete on merit. Ball predicts that the Trump administration will at some point realise its "best strategy" is to "create large amounts of regulatory risk" around the use of open-weight Chinese models.
The government would not need to ban anything. Ball himself calls banning open source "one of the dumber motifs of AI policy discussion". Instead, every agency would be directed to issue soft law that creates fear, uncertainty and doubt. His example: "A Federal Reserve Advisory Bulletin found that there may be backdoors in Chinese AI models." In his words, "it needn't be that well justified". It just needs to create enough regulatory risk that banks, insurers, healthcare companies and every other regulated enterprise decide the models are not worth the trouble.
But not too much fear. The government should avoid scaring the hyperscalers away from serving Chinese models, because that would push startups toward sketchier providers. Ball calls this a "happy middle ground" and assumes the administration "will do some version of this".
My first reaction was: LOL.
Is American AI really so insecure about its own products that it needs federal agencies to frighten customers away from the competition?
This is not statecraft, but market sabotage by memo: the state degrading a competitor's product on purpose, with no evidence attached.
Rumour with federal letterhead is not AI safety
Ball is predicting, not recommending, as he said it himself in a follow-up, after the thread blew up: he was describing what he believes will happen, "not proposing it like a good idea". The distinction matters, but look at what his correction corrects, and what it does not. He softened the claim that open-weight models are decelerationist, except for the part that counts: they "decelerate capex spending on the margin", which he calls "straightforwardly true". He retracted nothing of point five. He did not say the FUD campaign would not happen. He did not say it would not work. He did not say it would be wrong. The strongest objection he could produce about this whole direction of travel is that you don't have to like it, and that he doesn't. When the only available objection to state-manufactured suspicion is a matter of taste, the correction does not solve the problem but confirms it.
Here is a former White House AI adviser, now at OpenAI, calculating the optimal dosage of manufactured fear: enough to push regulated enterprises off the models, not so much that the cloud giants stop serving them. On the affiliation, let's be clear, because this whole argument forbids me the shortcut: I am not saying his employer wrote his opinions, and he flagged the awkwardness himself. Arguments do not become wrong because of where their author works, any more than models become dangerous because of where they were trained. But when the person modelling fear dosage against a competitor sits inside the leading incumbent, asking the public to simply trust the neutrality of the analysis is asking a lot. That is a problem of institutions, not of one man's soul, and it is exactly why the standards have to be public and the evidence has to be published.
And the best part: he does not even believe the danger himself. Two points earlier he writes that he "might be fine" with models of this risk level being open weight. One point later, that they make the world more dangerous "but not so much more that you'll really notice". So the campaign he predicts would manufacture a fear that its own forecaster does not hold.
When people who were recently in the room describe fear without evidence as an administration's best strategy, in the tone of a user manual, the prediction starts to do the work of normalisation, whatever the author intended.
Could a Chinese model contain a backdoor? Of course. And let's be honest about that problem: detecting a deliberately implanted behaviour inside model weights is still an unsolved research problem, and this kind of behaviour can survive safety training and pass standard evaluations. But it applies just as much to every model you did not train yourself, including the closed American ones you cannot inspect at all. And the one espionage channel everyone agrees is real, your data flowing to somebody else's servers, is exactly the channel an open-weight model removes when you run it on your own hardware... it's also exactly the channel a hyperscaler-only regime rebuilds.
So test: define the security standards, inspect the weights and the software around them, examine the training and deployment supply chain, publish the evidence, give independent researchers enough to reproduce it, and run the same tests on American, European and Chinese systems. Then restrict the models that fail. And if the real standard is that nobody can prove the absence of backdoors, then say it openly, and watch every model on Earth fail together.
A model's passport is not a security audit. An American model is not safe because it is American, and a Chinese model is not compromised because it is Chinese. A government notice designed to create suspicion without sufficient evidence is not risk management. It is propaganda with a regulatory seal.
It is also, conveniently, a ban that never has to answer for itself. No legislative debate, no published threshold, no evidence to contest, no official who owns the decision. Regulated companies just retreat, because their legal and compliance teams cannot afford to gamble. That is exactly why the tactic would work and also exactly why it should be disqualifying.
If you think this machinery is hypothetical, read Ball's follow-up again. The administration, he writes, already runs "a de facto licensing regime for frontier AI". De facto. Not voted, not written down as law, not contestable by anyone. Governing by unofficial pressure is not a prediction anymore. It is the operating mode, described from inside the tent.
The free market, until someone else builds a better product
The hypocrisy is almost impressive. American technology policy celebrates competition, innovation and the free market, right until a foreign lab releases a model that is good, open weight and outside American billing systems. Then suddenly the market needs a little assistance. Not through investment in better public infrastructure. Not through stronger research or cheaper, more open American models. Through vague federal warnings designed to make the competitor commercially radioactive.
Protectionism would at least be honest. This is protectionism without the courage to say its name, wrapped in national security language so that evidence becomes optional.
Ball does give a reason for sparing the hyperscalers: scare them too and startups will go to sketchier providers. Ok, take it at face value. But look at what this design admits. The models stay available, so availability was never the problem. What changes is who controls the channel, and who takes the margin. Regulated organisations get frightened into the arms of large, mostly American infrastructure companies, which become sanctioned tollbooths for access to Chinese intelligence. The supposed security risk does not disappear. It just gets a markup.
And Ball already told us what this strategy is protecting. In point three of the same thread, he writes that open-weight models "deter further AI capex". Not that they endanger banks. Not that they leak data. They deter capital expenditure. It is the one claim his correction kept and reinforced. That is what the fear campaign would defend, in his words, not mine. Industrial policy for incumbents, presented as national security.
Scarcity is not an argument against public infrastructure
This is exactly why AI should be treated as essential infrastructure, with public responsibilities attached. And Ball has a name ready for that position. In point four, he calls it "full AI communism", a "dystopian hellscape" where AI becomes a "public good" provided by the state, and he claims that every open-weight advocate concedes, in the end, that this is where things go. The menu he proposes has two options: AI as a private market product, defended if necessary by state-manufactured fear, or AI as a state monopoly. Anyone who has ever used a public water system, a rural electricity cooperative or a national health service knows this menu is false.
I know the semantic objection, too. AI requires scarce chips, electricity, water, networks, engineers and capital. Compute is rivalrous, access can be restricted, so economists will tell you AI is not technically a public good. So what? Electricity is scarce. Clean water is scarce. Healthcare requires hospitals, equipment, medicines, energy, trained professionals and enormous amounts of money. None of this appears in people's homes by magic. We produce, purify, transport, maintain and distribute all of it, through infrastructure built over generations. And broad access exists where societies decided that providing it is a public responsibility. This is what universal service means: not that the good is free or infinite, but that access does not depend on the goodwill of whoever owns the pipes.
Scarcity does not settle the political question. Scarcity is why the political question exists. When something is essential, expensive and controlled by a few actors, leaving its distribution entirely to those actors is not neutrality. It is a decision to let wealth and power determine access.
Admittedly, asking the United States to recognise this may be optimistic. The United States has produced most of the best AI on Earth, which is exactly why it is depressing to watch it reach for this. This is a country where 27.1 million people had no health insurance at any point in 2024, where the Consumer Financial Protection Bureau found 15 million people with medical bills on their credit reports as of June 2023, and where a federal court decided in July 2025 that those bills should stay there. Illness can become a credit event. That is not a technical necessity, it is a political choice about access to an essential good, and it gets renewed on purpose, in favour of the industries that profit from it. The emerging American vision for AI follows the same pattern: corporations own the infrastructure, intelligence is sold in tiers, and the state frightens people away from cheaper alternatives. The rest of the world does not have to import that pathology.
Treating AI as public infrastructure does not mean pretending compute is infinite, making every model free, releasing every dangerous capability or nationalising anything. It means treating baseline access, continuity, transparency and meaningful choice as public responsibilities. Concretely: shared and public compute. Open models where they can be released safely. Independent testing, instead of vendor claims and geopolitical insinuation. Interoperability, so institutions can actually leave a provider. Public-interest procurement. Restrictions based on demonstrated capabilities and risks, never on the nationality of the laboratory.
And most importantly: no government and no corporation gets to decide, alone and without evidence, which forms of intelligence everyone else is allowed to use.
Trust is not a nationality
I am not arguing that Chinese models should be trusted because they are Chinese. I am arguing that American models should not be trusted because they are American. Trust should come from evidence, inspection, testing, transparency and accountability. And institutions should keep the practical ability to change providers when that trust is broken.
Call that communist if you want. Ball already did, one point before explaining how the American state could quietly poison the market for a competitor it cannot comfortably beat. Between a public option for intelligence and a government that manufactures suspicion to protect incumbent business models, I think I know which one belongs in the dystopia.
American AI should win by producing better models, better products and better infrastructure. It is not by making agencies spread fear that you win a technology race. If American AI needs that, it is not winning. It is panicking with a policy memo.