The US–China AI rivalry entered a new phase this week. A joint NSA, CISA, and FBI advisory publicly named six Chinese AI labs for “industrial-scale” model distillation from American frontier models. DeepSeek launched a new model, picked lead underwriters for a $75 billion IPO, and ordered 160,000 Huawei chips for a gigawatt-scale datacenter. Huawei tightened its stranglehold on China’s AI accelerator market as Nvidia’s share collapsed to near zero. China’s Supreme People’s Court issued the country’s first AI judicial rules. And Tencent’s open-source Hunyuan Hy4 became the most-used model on OpenRouter. Here is your China AI Weekly for September 7–13, 2026.


The Distillation Row Goes Nuclear

A joint advisory from the NSA, CISA, and FBI (AA26-251A), published September 8, named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI for what it called “industrial-scale model distillation campaigns” targeting Claude, GPT, Gemini, and Grok since at least late 2024. The advisory alleges billions of tokens were extracted across millions of exchanges, “likely with Chinese government awareness.” Techniques reportedly included automated jailbreak tooling, rotating API keys to evade rate limits, and a gray-market proxy network known as “transfer stations” to bypass geo-restrictions. DeepSeek was specifically accused of organized campaigns targeting reasoning capabilities to build R1 and V3; Alibaba was accused of distilling to improve Qwen.

Three days later, Anthropic published a threat-intelligence report quantifying the scale. The company said it detected and disrupted illicit distillation by Alibaba, Moonshot, DeepSeek, Xiaomi, and Zhipu across five campaigns totaling approximately 190 million exchanges. About 151 million of those were linked to Alibaba between May and July 2026. DeepSeek was accused of routing customer exchanges to Claude without notifying its own customers — over 12 million distillation attacks in 14 days during July alone. Anthropic responded by banning accounts, reducing the detail level of reasoning transcripts, and engaging authorities.

China’s response was swift. MOFCOM dismissed the allegations as an attempt to monopolize the AI industry and threatened “resolute countermeasures.” MFA spokesperson Mao Ning said China’s AI progress “stems from self-reliance and open cooperation.” Within 48 hours, the US Treasury signaled that sanctions are “on the table” for companies continuing at-scale capability extraction. Potential Entity List actions loom for firms found to have crossed into IP theft.

This lands days before the planned mid-September US–China AI safety dialogue — the first dedicated bilateral AI talks of Trump’s second term — and ahead of the September 24 Trump–Xi summit in Washington. Though the talks’ timing is unconfirmed (the White House denied a mid-September meeting, while Treasury suggested October), the distillation row has already poisoned the well. For enterprises, the message is clear: model provenance is now a compliance question, not a research-ethics one.

For teams running enterprise AI consulting workloads, any production deployment of Chinese open-source models needs a documented governance framework, vendor-neutral architecture, and a fallback model path. Capabilities derived from restricted frontier models could create compliance risk if regulations tighten. A formal AI governance and security review should sit ahead of any open-weights pilot.


DeepSeek’s Triple Play: V4.1 Flash, IPO, and a Gigawatt Datacenter

DeepSeek had arguably the busiest week of any AI company in the world.

V4.1-Flash Launch

On September 10, DeepSeek launched V4.1-Flash — the smallest model in its new architecture family and its first with native multimodal capability. Pricing is aggressive: a fraction of a cent per million tokens, with a 60% cache-hit price cut. DeepSeek claims V4.1-Flash outperforms Moonshot’s Kimi K3 while steeply undercutting rivals on cost.

Starting September 14, DeepSeek is retiring V4-Pro and auto-rerouting all inference to V4.1-Flash, billing at the cheaper rates. The market reaction was immediate: MiniMax and Z.AI each dropped over 8% in Hong Kong trading, and Alibaba fell more than 2%.

IPO Plans

Reuters reported on September 9 that DeepSeek has tapped CITIC Securities as lead underwriter for a STAR Market IPO in Shanghai, aiming to begin the process this year. A funding round in progress would value the company at ¥500 billion (~$75 billion). The company raised approximately $7.4 billion in June at a post-money valuation exceeding $50 billion. Founder Liang Wenfeng personally contributed ¥20 billion to that round, with Tencent (¥10 billion) and CATL (¥5 billion) as the largest external shareholders. Other backers include JD.com, NetEase, and IDG Capital.

Compute Buildout

DeepSeek ordered 160,000 Huawei Ascend 950DT chips (~¥18 billion / $2.56 billion) for a 1-gigawatt datacenter in Ulanqab, Inner Mongolia, optimized primarily for inference. By raw chip count, this would exceed Western deployments like xAI’s Colossus and Google’s TPU Virgo clusters — though performance per chip and delivery timelines remain open questions. DeepSeek’s V4 architecture was designed from the ground up for Huawei Ascend 950PR, and both V4-Pro and V4.1-Flash run on Ascend.

For enterprise architects, DeepSeek’s week underscores a strategic shift: China’s leading AI lab is vertically integrating around domestic silicon, aggressive pricing, and capital markets — building an end-to-end stack that bypasses American technology entirely. Teams evaluating Azure consulting services should note that the bifurcation of AI infrastructure is accelerating.


Huawei’s Chip Grip: Domestic Silicon Is Now the Default

Huawei is projected to hold 50–62% of China’s domestic AI accelerator market in 2026, while Nvidia’s share has collapsed to near zero. Jensen Huang himself acknowledged the collapse from 95%. Huawei targets 750,000 Ascend units in 2026, with ByteDance and DeepSeek alone accounting for approximately 510,000. Not a single H200 has been sold in China despite US approval — Chinese customs is blocking shipments.

The Binding Constraint: HBM, Not Logic

SMIC can produce dies for over 1 million Ascend chips per year, but domestic HBM capacity (CXMT/HiZQ) supports only 250,000–300,000 finished accelerators annually — a roughly 60% shortfall without foreign stockpiles. This constraint is now hitting prices hard. A Reuters exclusive on September 10 reported:

  • Ascend 950DT card: now quoted above ¥250,000 (~$37,255) — up 20–50% in two months, comparable to Nvidia’s B200. Ships Q4 2026.
  • Ascend 950PR: ~¥60,000 → above ¥80,000 (+30%)
  • Ascend 910C: ~¥90,000 → above ¥110,000 (+~22%)
  • Cambricon “690,” MetaX, and Iluvatar CoreX: all raising prices 20–30%

The cause is a global HBM squeeze compounded by December 2024 US export controls on advanced HBM. Chinese firms are relying on stockpiles and black-market supply.

Lithography Advances

Yuliangsheng, a Shanghai company spun out of SiCarrier, co-developed China’s first advanced DUV lithography machine. Approximately 12 units are targeted by end-2026, with testing underway at SMIC and Huawei production lines — though performance still lags ASML. Huawei’s Kirin 2026 / Kirin 9050 Pro uses a proprietary LogicFolding architecture that raises transistor density 55% (to 238M/mm²) and cuts NPU power 66%, credited by Huawei’s Tingbo He to EUV restrictions forcing wafer-to-wafer 3D logic stacking. SMIC remains at 7nm-class (N+3); the Ascend 950DT is built on SMIC N+3 with 144GB HiZQ 2.0 HBM delivering 4.0 TB/s bandwidth.

The “Four Little Dragons”

China’s leading independent AI chip startups — Enflame Technology, Moore Threads, MetaX, and Shanghai Biren — are now all public. Enflame is raising approximately $900 million in a Shanghai IPO and reported 1,475% year-over-year Q1 sales growth. Together they target China’s $90 billion AI semiconductor market.

For enterprises, the chip story is a supply-chain planning imperative. Any 2027–2028 capacity plan assuming free-flow semiconductor equipment to Chinese partners needs a fallback. Pin model provenance in procurement — require vendors to disclose training hardware and weights origin in RFPs. Pre-stage a second region if your inference depends on Chinese-built capacity.


China’s First AI Judicial Rules

The Supreme People’s Court issued “Opinions on the Lawful Adjudication of Disputes Involving Artificial Intelligence” (Fa Fa [2026] No. 10) on September 7 — China’s first nationwide judicial guidance on AI disputes. The 24 provisions span five sections and cover the full spectrum of AI-related civil liability.

This is guidance on applying existing law, not new AI-specific legislation. China still has no dedicated AI law. The rules draw on the Civil Code, Cybersecurity Law, Data Security Law, Copyright Law, PIPL, and Consumer Rights Protection Law.

Key Provisions

  • Deepfakes and voice cloning: Creating, using, or distributing identifiable digital replicas without consent infringes personality and voice rights.
  • Fault-based liability default: Courts weigh autonomy, transparency, risk level, preventive measures, and the ability to foresee and control outcomes. Existing law may provide strict liability in specific cases.
  • AI hallucinations: Providers may be liable if they fail to act after receiving valid notice. Users who deliberately prompt harmful content also bear liability.
  • Algorithmic price discrimination: Liability for unjustified differing terms offered to consumers.
  • Training data: Lawfully disclosed personal information processed within reasonable limits for training is generally acceptable unless an individual explicitly objects. Consent is required for high-impact processing.
  • Open-source exemptions: Qualifying developers who supply modules free on an open-source basis with public disclosure of function and security risks may receive liability exemptions.
  • AI-generated evidence: Parties must verify AI-generated evidence. Fabricating evidence or fraudulent litigation using AI leads to dismissal, fines, detention, and potential criminal prosecution.
  • Doxing (“box-opening”): Using AI to aggregate public data to expose private information constitutes infringement.

Vice President Tao Kaiyuan stated the guidance aims to “balance development and security.”

CAC Risk Posture

The Cyberspace Administration of China (CAC) is also escalating. Deputy DG Wang Lihong named five major AI security risks on September 1: (1) technical vulnerabilities and unreliable outputs, (2) capability gains and “extreme loss of control,” (3) agents with high system privileges, (4) misuse including biology and genetics, and (5) “technological hegemony.” The Qinglang campaign phase 2 has shifted from model and service compliance to AI-generated content and conduct — targeting impersonation, false information, and automated fake engagement.

For multinational enterprises operating in China, the judicial rules create a new compliance surface. AI systems that generate content, process personal data, or produce algorithmic decisions need documented governance aligned with these provisions. Teams should map existing AI deployments against the 24 provisions and identify exposure points — particularly around training data provenance, deepfake controls, and algorithmic transparency.


Tencent’s Hunyuan Hy4 Tops OpenRouter

Tencent open-sourced Hunyuan Hy4-preview on August 28 (770B total / 49B active Mixture-of-Experts, 1M context, Apache 2.0), and it has since rocketed to the top of OpenRouter’s global usage at 14.7 trillion tokens per week — a 379% month-over-month increase.

An optimized update on September 7 fixed “long thinking / over-verification” issues on complex tasks, reducing the number of reasoning turns and token usage while maintaining quality (confirmed by both benchmarks and human evaluation). The model uses 256 routed experts plus 1 shared expert with top-8 routing, and supports vLLM and SGLang with FP8 and BF16 precision. GGUF builds are available at approximately 214 GiB.

API pricing is competitive: $0.834/M input, $2.501/M output, $0.042/M cache-hit. The model is available through WorkBuddy, CodeBuddy, Yuanbao, ima, Tencent Cloud TokenHub, and OpenRouter. Free access on WorkBuddy and CodeBuddy ran for two weeks post-launch before adjustments on September 11.

Tencent also opened its WorkBuddy AI productivity platform to external developers, hardware partners, and enterprise customers. The platform now spans three layers: hardware (nine co-branded voice-input devices), application (branded AI workspaces for finance, legal, and healthcare), and developer (Skills, Experts, and Connectors APIs).

Other Model Releases

  • Alibaba released Qwen-Drive-1.0-4B under Apache 2.0 — the first open-source vision-language foundation model purpose-built for autonomous driving. Built on a frozen Qwen3.5-4B backbone with 3D perception, VQA, and motion planning capabilities. It scores 72.7 on MMMU.
  • Zhipu published GLM-5.3 weights after a safety delay.
  • DeepSeek released V4-Flash-Vision-Exp weights.
  • ByteDance committed $5.6 billion to domestic silicon procurement.

US–China AI Safety Talks: Clouded by Distillation

The distillation row casts a long shadow over the planned mid-September US–China AI safety dialogue — reported by Reuters on September 4 as the first dedicated bilateral AI talks of Trump’s second term. The US side is reportedly led by Treasury Secretary Scott Bessent; China’s delegation may include Vice Premier He Lifeng or Ding Xuexiang.

The agenda reportedly covers joint monitoring of AI-directed cyberattacks, with the US floating that both countries’ AI labs should “police themselves” and share threat information. The US also plans to raise distillation concerns — now significantly harder after the NSA advisory and Anthropic report. China views the talks as a deliverable for the September 24 summit.

Conflicting signals persist. A White House official stated there is “no planned AI-related meeting in mid-September,” while Treasury suggested the sides “may meet in October.” The talks’ timing and format should be treated as unconfirmed.


What to Watch

  • Distillation enforcement. If the US moves from advisories to Entity List designations or sanctions, the impact on Chinese model evaluation and procurement will be immediate. Track Treasury and Commerce actions over the next two weeks.
  • DeepSeek IPO timeline. STAR Market listing approval and valuation finalization will signal whether China’s capital markets can sustain $75B-scale AI valuations amid geopolitical tension.
  • HBM supply chain. Price escalation of 20–50% in two months suggests the HBM bottleneck is tightening. Watch for CXMT/HiZQ capacity expansion timelines and any Chinese move to stockpile or secure alternative HBM sources.
  • AI safety talks. Whether the dialogue proceeds in September, October, or not at all will set the tone for the Trump–Xi summit and bilateral AI risk management cooperation.
  • Tencent Hy4 enterprise adoption. 14.7T tokens/week on OpenRouter is a leading indicator of production adoption. Watch for enterprise case studies and whether the open-source commitment holds as usage scales.

That is this week’s China AI Weekly — a week where the distillation fight moved from intelligence community whispers to public advisories, DeepSeek bet $75 billion on its independence from American technology, and China’s courts drew the first judicial boundaries around AI liability. The bifurcation of the global AI stack is no longer a forecast. It is the operating environment.

Building an AI architecture that survives the next regulatory shift? Big Hat Group delivers enterprise AI consulting and Azure-native deployments for teams that need vendor-neutral orchestration, model gateway patterns, and documented governance across open-source and proprietary models. Whether you are navigating distillation compliance risk or building a multi-region inference strategy, book a discovery call to scope the work.


Sources:

  • Reuters: “DeepSeek taps CITIC Securities for STAR Market IPO” (2026-09-09)
  • Reuters: “DeepSeek launches V4.1-Flash with aggressive pricing” (2026-09-10)
  • Reuters: “Huawei Ascend chip prices surge on HBM shortage” (2026-09-10)
  • Reuters Breakingviews: “China’s four little dragons of AI chips” (2026-09-07)
  • Reuters: “US-China prepare mid-September AI safety dialogue” (2026-09-04)
  • Bloomberg: “DeepSeek orders 160,000 Huawei Ascend chips” (2026-09-04)
  • Bloomberg: “DeepSeek V4.1 Flash triggers price war” (2026-09-10)
  • CNBC: “Anthropic reports 190M distillation exchanges by Chinese labs” (2026-09-11)
  • NSA/CISA/FBI Joint Advisory AA26-251A (2026-09-08)
  • Xinhua/China Daily: “Supreme People’s Court AI adjudication guidance” (2026-09-07)
  • Al Jazeera: “China slams US AI distillation accusations” (2026-09-09)
  • TrendForce: “Yuliangsheng DUV lithography development” (2026-09-08)
  • Chosun: “HBM shortage drives chip price surge” (2026-09-11)
  • China AI Bulletin #11: “Regulatory roundup” (2026-09-10)
  • aibase: “Tencent Hunyuan Hy4 optimized update” (2026-09-07)
  • Follow on X: https://x.com/kkaminsk