
Arcee, a US open source AI lab, says Chinese models are not inherently dangerous
Quick Answer
Arcee's CTO Lucas Atkins argues that Chinese open-weight AI models, like Alibaba's Qwen, are not inherently dangerous and can provide benefits to U.S.
Quick Take
companies. He emphasizes the need for a competitive U.S. ecosystem rather than bans, asserting that enterprises can safely use these models with proper security measures.
Key Points
- Chinese models like Alibaba's Qwen offer lower inference costs than U.S. proprietary models.
- Atkins claims Chinese open models pose no more risk than any other open-source software.
- Enterprises should conduct security testing on any AI model they implement.
- Arcee benefits from learning from Chinese models to improve their own offerings.
- The focus should be on fostering a robust U.S. AI ecosystem, not banning models.
DeepSignal Analysis
What happened
Lucas Atkins, CTO of Arcee, argues that Chinese open-weight AI models, such as Alibaba's Qwen, are not inherently dangerous and can benefit U.S. companies. He emphasizes the importance of fostering a competitive U.S. ecosystem instead of imposing bans on these models, suggesting that enterprises can safely utilize them with appropriate security measures.
Key evidence
- Atkins states that Chinese open-weight models are no more dangerous than any other open-source software, asserting that they can provide benefits to U.S. companies.
- He notes that large organizations should conduct security testing on any AI models they use, including examining bias and toxicity before deployment.
- Atkins believes that the focus should shift from banning Chinese models to creating a robust open ecosystem in the U.S. to compete effectively.
Why it matters
The discussion around the safety of Chinese AI models reflects broader concerns about cybersecurity and competition in the AI industry. By advocating for a competitive U.S. ecosystem, Atkins highlights the potential for innovation and collaboration, which could lead to advancements in AI technology. This perspective may influence policymakers and industry leaders as they navigate the complexities of global AI development.
📖 Reader Mode
~3 min readAs Chinese open-weight AI models grow in capability and popularity, arguments about what should be done about them have once again reached a fever pitch.
There’s talk that the Trump administration might try to ban them (though it hasn’t yet acted on the idea). Meanwhile, proprietary model makers, particularly OpenAI and Anthropic, appear increasingly concerned about them.
Open-weight models such as Moonshot AI’s Kimi K3 or Alibaba’s Qwen offer inference at a fraction of the token cost of closed source models from these large U.S. labs. The fear is that they also pose some sort of threat. Certainly they threaten the profit margins of the large proprietary AI labs.
But should enterprises running these models in their own data centers succumb to the fear that they could be a vector for Chinese hackers?
No, says Lucas Atkins, the CTO of Arcee, which is building open models to give U.S. companies a homegrown alternative to Chinese models.
If any startup would benefit from a ban on Chinese models, Arcee would. But Atkins says China’s open models are no more dangerous than any other open source software a company may use. In fact, he says, they even offer benefits even to his own company.
“A lot of people view this as similar to a Chinese software program. Like, it was coded with these x, y, z intentions” that a bad actor could simply command, he said.
“That is fundamentally not how these models are trained. There is really not any way for an Arcee, or an Alibaba, to make a model, have someone run it in their own environment and for us have any access to it whatsoever,” he explained.
While most of these models are what’s known as “open weight” and are not really fully open source software, the source code (the part that will actually run on servers), if it is downloaded from open source sites like Hugging Face, is similarly largely visible and reviewable. (What isn’t available is the methods and data used to train the models.)
Large organizations should put any model core through their security testing and inspection processes, and they will also often post-train the models for their specific uses and can examine areas like bias, toxicity, hallucinations, and sensitivity to certain topics. So they work with, optimize, and understand the models before people start sending them prompts.
Could a model that is used for coding somehow throw malicious backdoors into the code it writes? Again, while that’s theoretically possible, it would require acrobatic feats to accomplish.
“There’s no reason that a sophisticated enough actor couldn’t train a model to be a completely amazing coding model in every circumstance, but when presented with a certain type of code base … some hidden training would kick in,” Atkins, who spends his days training models, postulated. But he adds: “I don’t know how you would do this.”
Because large language models are by nature creative, the odds are slim of getting a contemporary model to spit out malware in response to a preplanned perfect storm of context and prompt. Even slimmer are the chances that any enterprise would then use that code.
Could it happen in the future? That’s anyone’s guess. But enterprises are also building their AI apps to be model-agnostic and to use multiple models. So even if Chinese models are the best for the price today, enterprises won’t be locked into using them forever.
“I think instead of the conversation being about how to ban Chinese models, it should be about how do we foster a good, open ecosystem here in the U.S.,” Atkins says.
Arcee also gains advantages from Chinese models. Because they are open, the startup “benefits from those models being good because we can learn what they did. We can build on top of them. Then they can learn what we do,” he says. “We have tremendous respect for the people building those models, the individual researchers.”
Ultimately, the way to compete with Chinese models “is to release a model that is better,” says Atkins. “We need to give them something to talk about.”
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
— Originally published at techcrunch.com
Want this in your inbox every morning?
Daily brief at your local 8am — bilingual EN/中文, free.
More from TechCrunch
See more →
AI chip startup Etched defies skeptics, hits $10.3B valuation from big-name investors
AI chip startup Etched has achieved a $10.3 billion valuation after a $300 million Series C funding round, led by Sequoia and supported by notable investors like Andreessen Horowitz. The company claims to have developed innovative low-voltage chips for AI inference, significantly enhancing performance and reducing costs, with $1 billion in orders already booked.

