Nvidia's Jensen Huang defends Chinese AI: "Open-source models that are excellent should be used"

Julio Franco

Posts: 9,323   +2,257
Staff member
Big quote: Jensen Huang just spent a week watching his company's valuation get hit by the threat of a Chinese open-weight model. His response was to go on the record defending it. Speaking to Axios in Fort Worth, Texas, at the opening of a new phase of the Wistron plant that builds Nvidia's AI infrastructure, the Nvidia CEO said American companies should "absolutely" be free to run Chinese models. "These Chinese models are excellent," he said. "Open-source models that are excellent should be used." Asked whether China could displace American labs, he was blunt: "Zero possibility."

The timing is what makes it interesting. Moonshot AI released Kimi K3 on July 16. Independent evaluators put it third on Artificial Analysis' Intelligence Index, only behind Anthropic's Claude Fable 5 and OpenAI's GPT-5.6 Sol, and first on Arena's blind Frontend Code Arena board.

The market took it about as well as it took DeepSeek. The Philadelphia Semiconductor Index fell 12.5% in a week, its worst stretch in 15 months. Taiwan's benchmark dropped more than 6%, Japan closed down 4%, and Chinese AI stocks actually got hit harder than American ones, with Zhipu down as much as 30% in Hong Kong and MiniMax off 16%.

"The market misunderstood the impact of DeepSeek the first time," Huang told Axios, adding that Wall Street has "misunderstood the impact of Kimi again this time."

His pitch is one Nvidia has made before, delivered without much subtlety this time: "Free AI should be great for hardware. Free AI should be great for chips. Free AI should be great for data centers." The logic is that as cheap, capable models get used more, not less, more usage means more chips running somewhere. He also argued open models don't cannibalize OpenAI and Anthropic, but they give people a free first taste, and plenty of those people end up paying for something faster and more reliable.

Bloomberg's analysis of K3 noted that where DeepSeek's story was about cheaper training, Moonshot's is about a much larger model that leans harder on memory infrastructure.

The security argument, flipped

Huang waved off the idea that a downloaded Chinese model is some kind of backdoor to Beijing, pointing out you can inspect the weights, tweak them, and run the whole thing sealed off from the internet if you want. His argument is that openness actually makes things safer, because more people are looking for problems. Lock everything into one closed system, he said, and "if everything just becomes one single model, one single point of attack, one single source of failure, I think the world is much, much more vulnerable."

Then he turned that same logic on an American company. Huang said Anthropic should open up Claude Mythos, its cybersecurity model that's currently restricted to a vetted group of partners, calling it something that "should be available as a service" and arguing "holding Anthropic back is not in the benefit of the United States." His framing: "Just because Mythos is not available, open models are available anyhow."

It is worth noting that Nvidia is one of the partners with access to Mythos already, through Anthropic's Project Glasswing program. Glasswing has grown from around 50 partners to roughly 200 across about 15 countries, and Anthropic has said models this capable will likely be widely available within 6 to 12 months regardless of what it decides.

Meanwhile, in Washington...

Huang's comments landed hours after Treasury Secretary Scott Bessent told Fox Business the administration is looking into whether Chinese AI models were built on stolen US intellectual property.

"If we see ... that overseas models are stealing from our great companies, we have the ability to sanction them because of this theft," Bessent said, pointing to what he called "watermarks" of US models showing up inside Chinese ones, with action possible within days or weeks. He also floated whether US companies should have to disclose to customers when they're running Chinese models.

Behind the scenes, Axios says this fight has been simmering for a while. US Commerce has been considering blacklisting Chinese AI labs since last year, and the White House had a draft executive order that would've made US companies liable for running Chinese models. All of it stalled, but Kimi's release seems to have brought it back to life.

Jensen Huang split the difference on the "they stole our work" question: "Distillation, learning from AI, learning from other sources of knowledge, is fundamental to intelligence."

Read the incentives

Granted, all this commentary is not coming from a neutral party. Nvidia's China revenue is basically zero right now, down from a business Huang once said could be worth $50 billion a year. Huang has spent two years arguing against export controls, so of course he's going to say demand for AI is elastic and that restrictions can backfire. That said, he has also endorsed keeping Blackwell and Rubin out of China's hands.

The good news is that his core claim could soon be verified. Every number on Kimi K3 so far comes from Moonshot itself or from early API testing. The full weights go public on July 27, and at that point the benchmarks either hold up under independent testing or they don't.

Anthropic has accused Moonshot of training on 3.4 million Claude conversations earlier this year, though analyst Nathan Lambert's take is that even if some of that happened, it's not enough to explain how good K3 actually is. Separately, Epoch AI estimates the gap between the best open and closed models is now down to around three months.

If that gap keeps shrinking, the real question stops being whether US companies should be allowed to use Chinese models, and starts being whether banning them would even do anything once the weights are already sitting on servers everywhere.

Permalink to story:

 
With all of the "Anti AI-Data Center" protests in America and elsewhere (some funded by the CCP), along with the massive solar farms China has built, it's pretty easy to know how it will end up.
China will "welcome" these corporations to build these massive AI-data centers. And we know what
the CCP will do with the data.
 
With all of the "Anti AI-Data Center" protests in America and elsewhere (some funded by the CCP), along with the massive solar farms China has built, it's pretty easy to know how it will end up.
China will "welcome" these corporations to build these massive AI-data centers. And we know what
the CCP will do with the data.
They really aren't limited too much by the chips themselves. As long as you can pool memory you can scale things they can do what we're doing. You can do the same work on a strix halo system with 128gb of ram as on the RTX 6000 pro, it just takes longer. The thing about these workloads is that they're scaleable. nVdias tech certainly makes it easier, but there isn't anything stopping them from making data centers equal in compute or capabilities as we have have in the US.
 
Last edited:
Distill those rich mofos AI's and then make even better AI, he added. Steal smart, not work hard.
Especially stealing from a thief is not the same...

Btw I seen some claims Chinese distiled fable to create Kimi k3, like it would be possible to distil it in 3 days, and then train such model in another few....;)
 
All Chinese TBMs follow the same trajectory - hype fanned by swarms of trolls and bots, people doing simple tests (for which these models are super-optimized) which adds to the hype, China -financed media trying to induce panic .. all that for about 2 weeks. Then some try to use the models for real work, they are not at all that good, and all the noise goes away.

The good news is, both OpenAI and Anthropic seem to have taken measures against IP theft, maybe others too, so Kimi 3 is probably the last TBM .. or there may be one more, but it's all the same - the TBM period will be over soon.
Besides, most people already realized that using Chinese models is akin to using pirated software - it's free of charge, but infected, and can cause colossal damage. Bessent is totally right that US companies should have to disclose to customers when they're running Chinese models, because that puts them at risk.
 
All Chinese TBMs follow the same trajectory - hype fanned by swarms of trolls and bots, people doing simple tests (for which these models are super-optimized) which adds to the hype, China -financed media trying to induce panic .. all that for about 2 weeks. Then some try to use the models for real work, they are not at all that good, and all the noise goes away.

The good news is, both OpenAI and Anthropic seem to have taken measures against IP theft, maybe others too, so Kimi 3 is probably the last TBM .. or there may be one more, but it's all the same - the TBM period will be over soon.
Besides, most people already realized that using Chinese models is akin to using pirated software - it's free of charge, but infected, and can cause colossal damage. Bessent is totally right that US companies should have to disclose to customers when they're running Chinese models, because that puts them at risk.
Infected with what exactly? The irony is that this is an open source model where you can inspect all the weights and run it offline, so you have way more oversight and control, and an ability for it to never even see a Chinese server compared to a model from OpenAI or Claude where you feed it a prompt, it goes into a black box in their closed models and you get an answer, so on that basis I can't see how it would be "infected" really

And with all this talk of "pirated software", it is distillation, which is not pirated, more so just copying some of someone's homework, improving on it and then releasing that, so I can't see how it is pirated, maybe a bit grey vs a wholly self made model, bult ultimately its not like any of these AI companies play remotely fair, so banging on about piracy is full on "oh but they are Chinese, they are communist, China bad", as if the US AI companies aren't farming data and happily handing it over as required.

Also, even if you count it as piracy, AI companies have commited mass piracy, theft of original copyrighted works for training and other forms of stealing the works of original artists with not even an iota of care, compensation or acknowledgment of said creators or their work, so it is pot calling kettle black.

And this is just because in this case, the AI has had investors and VC's, who are highly intermingled with the goverment, wanting to keep their precious stock prices high for longer and not wanting an event that pops the bubble or in some way threatens their financial position based on crazy potential unrealised gains, until they can fleece the public in an IPO and make their losses public and make normal everyday people deal with their losses
 
Infected with what exactly? The irony is that this is an open source model where you can inspect all the weights and run it offline, so you have way more oversight and control, and an ability for it to never even see a Chinese server compared to a model from OpenAI or Claude where you feed it a prompt, it goes into a black box in their closed models and you get an answer, so on that basis I can't see how it would be "infected" really

And with all this talk of "pirated software", it is distillation, which is not pirated, more so just copying some of someone's homework, improving on it and then releasing that, so I can't see how it is pirated, maybe a bit grey vs a wholly self made model, bult ultimately its not like any of these AI companies play remotely fair, so banging on about piracy is full on "oh but they are Chinese, they are communist, China bad", as if the US AI companies aren't farming data and happily handing it over as required.

Also, even if you count it as piracy, AI companies have commited mass piracy, theft of original copyrighted works for training and other forms of stealing the works of original artists with not even an iota of care, compensation or acknowledgment of said creators or their work, so it is pot calling kettle black.

And this is just because in this case, the AI has had investors and VC's, who are highly intermingled with the goverment, wanting to keep their precious stock prices high for longer and not wanting an event that pops the bubble or in some way threatens their financial position based on crazy potential unrealised gains, until they can fleece the public in an IPO and make their losses public and make normal everyday people deal with their losses
Oh my .. you can inspect all the weights!!! But of course, how did I miss that?
--
Oops, I tried but .. weights seem to be just one colossal pile of numbers. How exactly do you "inspect" them?
Nobody knows what's inside that pile. It would be ridiculous to assume these models are not trained to inject backdoors and vulnerabilities when generating code, for example.
I used the pirated software analogy to emphasize that, just like pirated software, Chinese models are free of charge but infected. But you're right, they are pirated in the other sense too.
 
Oh my .. you can inspect all the weights!!! But of course, how did I miss that?
--
Oops, I tried but .. weights seem to be just one colossal pile of numbers. How exactly do you "inspect" them?
Nobody knows what's inside that pile. It would be ridiculous to assume these models are not trained to inject backdoors and vulnerabilities when generating code, for example.
I used the pirated software analogy to emphasize that, just like pirated software, Chinese models are free of charge but infected. But you're right, they are pirated in the other sense too.
Oh it would be ridiculous to assume they inject code, and especially so when you have the ability to see what the model is doing and run it on your own machine vs a closed model that gives you an answer and you really have no indication on what it is basing it on, so giving unsubstantiated claims of spyware really doesn't help the discussion at all.
Its just nonsense "oh but its foreign, they must be loading spyware into it" forgetting that ultimately its a business that provides a product and it should be gauged on its merits and risks on its own, and I'd say the ability to control what happens with your data and keep it on your own servers / infrastructure with an open source model is a benefit for many individuals / companies (not even going to delve into the past activities of the US on spying and so on since again I have no proof myself current AI models do so).

I'm well aware as are many others thay China is not sunshine and rainbows and not shy about its stance on censorship and so on for its own citizens, but neither is the stance the US takes, so ultimately, when on the nation front all you get is pot calling kettle black, you ignore that and focus on the product as it is, not start throwing strawman arguments and speaking like an investor since that is the only type of person that cares who makes said AI
Ultimately if AI is cheaper, simpler and better able to be used as a tool versus being this hyped up mega thing that has all people going mental and pumping this stock bubble that will pop with a huge bang the better for us all, investors are just scared of it like they are for anything making the bubble crystal clear and bringing everything down

And again, whether its "stolen" or not, people don't care in this case, everything within an AI is stolen 95% of the time anyway, so if AI companies don't care about respecting people's works and acknowledging them properly, why should we care about protecting their "work"?
 
Back