Big tech borders are completely porous.
OpenAI and Meta spent billions building frontier artificial intelligence architectures. They thought their safety guardrails and export controls would keep these capabilities out of foreign defense sectors. They were wrong. Recent reports show that Chinese military-affiliated researchers are actively using American large language models to train defense systems. Meanwhile, you can find other stories here: The Ghost in the Machine After Australia Tried to Switch It Off.
You shouldn't be surprised. Open-weights models make containment impossible. Once a powerful model is released into the wild or leaked via API endpoints, defensive walls crumble.
Let's break down what's actually happening, why current export controls are failing, and what this means for national security moving forward. To understand the complete picture, check out the excellent article by The Verge.
The Reality of Open Weights
Open-weights models change the rules of engagement. When labs like Meta release Llama or when researchers fine-tune publicly available checkpoints, they hand out a finished product.
You don't need to steal source code if you can download the weights directly from a public repository. Chinese researchers affiliated with institutions like the People's Liberation Army Academy of Military Science took open-source American models and adapted them. They built localized tools for intelligence processing, chat-based tactical simulations, and operational planning.
The strategy is straightforward. Instead of spending billions training a foundation model from scratch, you take a top-tier US model, strip its safety filters through fine-tuning, and point it at military objectives.
It's efficient. It's cheap. And current trade policies didn't stop it.
Why Export Controls Are Mostly Theater
Washington loves a good export ban. Policymakers think that restricting the shipment of physical microchips like Nvidia H100s to specific addresses solves the proliferation problem.
That logic has massive holes.
First, cloud computing rentals bypass physical shipping restrictions. Researchers can access US-based or third-party cloud infrastructure from anywhere on earth. Second, open-weights software doesn't respect customs checkpoints.
Here is what lawmakers keep missing:
- Hardware restrictions only slow down massive data center builds, not algorithm adaptation.
- Software downloaded via public links bypasses customs inspections entirely.
- Fine-tuning a pre-existing model requires a fraction of the compute needed to train one from day one.
When you rely solely on hardware bottlenecks, you ignore the fluid nature of digital assets.
What the Defense Sector is Actually Doing with These Models
Intelligence analysis is a massive bottleneck for any military. Thousands of hours of intercepted communications, satellite reconnaissance reports, and open-source intelligence sit in backlogs.
Human analysts can't read fast enough. Large language models can.
By adapting American models, defense researchers create automated synthesis engines. These systems scan foreign media, parse translated documents, and summarize complex battlefield developments in seconds. They simulate war games, testing various tactical responses against virtual adversaries trained on historical data.
It's not about Terminator-style automation just yet. It's about cognitive acceleration. The side that processes battlefield data faster wins. Using existing Western architectures gives foreign researchers a shortcut to that speed.
The Flawed Logic of Corporate Safety Guardrails
Silicon Valley executives love talking about alignment. They implement safety classifiers that refuse to answer questions about building bombs or planning cyberattacks.
These filters are fragile.
If you have direct access to the model weights, you can run unaligned fine-tuning. You strip away the safety layer through reinforcement learning from human feedback or direct dataset injection. The model forgets its corporate upbringing very quickly.
Expecting commercial tech companies to act as geopolitical border guards is a recipe for failure. Their primary goal is user adoption and developer ecosystem growth. Restricting access too tightly hurts their bottom line.
The Path Forward for National Security
Policymakers need to stop pretending that software can be locked in a vault once it reaches a certain scale.
We need a complete shift in how national security agencies view open-source architecture. If a model crosses a specific capability threshold, releasing its raw weights publicly might constitute an unrecoverable security leak.
Companies building frontier systems must accept stricter auditing requirements before public releases. At the same time, defense agencies need to invest heavily in counter-AI capabilities, focusing on how to disrupt, poison, or outmaneuver models being used against them.
Stop relying on wishful thinking. The open-source genie isn't going back into the bottle, and ignoring how easily advanced code crosses borders is a dangerous gamble.