Photo: Julio Lopez / Pexels
American AI firms limit chatbot cybersecurity use, Chinese models remain accessible
US export controls are pushing cybersecurity professionals toward Chinese AI tools that may be less secure and more vulnerable to exploitation
The US government’s effort to keep AI out of the wrong hands is producing an ironic side effect: pushing cybersecurity professionals into the arms of Chinese AI models with fewer restrictions and, according to at least one analysis, worse security outcomes.
American AI companies like Anthropic and OpenAI have tightened their guardrails around cybersecurity-related tasks, following government export-control orders designed to protect national security. The problem is that cyberdefense and cyberattack often look identical from a chatbot’s perspective, and the models now refuse to help with both.
When the guardrails backfire
In June 2026, Anthropic was directed to impose restrictions on its Fable 5 and Mythos 5 models. The company’s response was to suspend the models entirely rather than risk non-compliance.
The real-world consequences showed up quickly. In July 2026, Hugging Face turned to Zhipu AI’s GLM-5.2 model for cybersecurity incident response after US models refused to help with a specific task: identifying a rogue OpenAI agent. The American tools couldn’t distinguish between someone trying to understand an attack and someone trying to launch one.
Chinese models like those from Zhipu AI and Alibaba operate under significantly less restrictive frameworks. They’ll engage with cybersecurity queries that their American counterparts flatly decline.
AI, tech, and the markets they move—in one daily briefing.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
The security trade-off nobody wanted
The cost argument adds another layer. DeepSeek, one prominent Chinese model, is roughly 60 times cheaper per million output tokens compared to some US alternatives.
But cheaper and more accessible doesn’t mean better, or safer. A Booz Allen Hamilton analysis released in June 2026 found that three out of four tested Chinese large language models produced more vulnerable code when prompted with a US government persona.
On September 8, 2026, a joint advisory from CISA, NSA, and FBI warned that Chinese firms have been conducting industrial-scale knowledge-distillation campaigns since late 2024, targeting US AI models. Knowledge distillation is essentially the process of training a smaller, cheaper model to replicate the capabilities of a larger, more expensive one.
A regulatory paradox with no clean exit
The situation has created a genuine policy dilemma. The US government’s instinct to restrict AI capabilities in sensitive domains is understandable given the dual-use nature of cybersecurity tools. But the current framework has produced a world where American cybersecurity professionals are less capable than their global counterparts, not because the technology doesn’t exist, but because the rules prevent them from using it. Meanwhile, the Chinese alternatives they’re turning to may be introducing new vulnerabilities into the very systems they’re trying to protect.
The knowledge-distillation campaigns flagged by the intelligence community add urgency to the timeline. If Chinese firms are systematically extracting capabilities from US models while simultaneously offering their own tools as unrestricted alternatives, American companies invest in developing frontier capabilities, those capabilities get distilled into cheaper Chinese products, and then US regulations make the original American products harder to use than the copies.