US Open Source AI Lab Arcee Says Chinese Models Are Not Inherently Dangerous

As Chinese open-weight AI models continue to gain capability and market share, debates over how to handle them have intensified once again.
Rumors suggest the Trump administration may attempt to ban these models, though no action has been taken yet. Meanwhile, proprietary model developers, especially OpenAI and Anthropic, are growing increasingly wary of the competition.
Open-weight models like Moonshot AI’s Kimi K3 or Alibaba’s Qwen provide inference at a fraction of the token cost compared to closed-source models from major U.S. labs. This price advantage has sparked fears that they might pose a security threat, primarily by threatening the profit margins of large proprietary AI providers.
However, should enterprises deploying these models in their own data centers worry about them becoming a vector for Chinese hackers?
No, argues Lucas Atkins, CTO of Arcee, a company developing open models to offer U.S. businesses a domestic alternative to Chinese AI.
If any startup would benefit from banning Chinese models, it would be Arcee. Yet Atkins maintains that China’s open models are no more dangerous than any other open-source software a company might use. In fact, he argues, they even offer advantages to his own firm.
“Many people view this as akin to a Chinese software program, assuming it was coded with specific intentions that a malicious actor could exploit,” he noted.
“That is fundamentally not how these models are trained. There is no mechanism for Arcee, or Alibaba, to create a model, have it run in your environment, and gain any access to it,” he explained.
While most of these models are ‘open weight’ rather than fully open-source software, the source code—the part that actually runs on servers—is largely visible and reviewable if downloaded from platforms like Hugging Face. (What remains unavailable are the training methods and datasets.)
Large organizations should subject any model core to rigorous security testing and inspection. They often also post-train models for specific use cases, examining factors like bias, toxicity, hallucinations, and sensitivity to certain topics. This allows them to work with, optimize, and understand the models before users begin sending prompts.
Could a coding model somehow inject malicious backdoors into the code it generates? While theoretically possible, achieving this would require extraordinary technical feats.
“There’s no reason a sufficiently sophisticated actor couldn’t train a model to excel at coding in all scenarios, but trigger hidden malicious behavior when presented with a specific codebase,” Atkins speculated. However, he added: “I don’t know how one would actually achieve this.”
Because large language models are inherently creative, the likelihood of a contemporary model generating malware in response to a perfectly orchestrated context and prompt is slim. The chances of an enterprise then using that code are even slimmer.
Could this happen in the future? That remains uncertain. However, enterprises are building AI applications to be model-agnostic and utilize multiple models. Thus, even if Chinese models offer the best price-to-performance ratio today, enterprises won’t be locked into using them indefinitely.
“I believe the conversation should shift from how to ban Chinese models to how we can foster a robust, open ecosystem here in the U.S.,” Atkins stated.
Arcee also benefits from Chinese models. Because they are open, the startup “gains value when those models perform well, as we can learn from their approaches and build upon them. Then, they can learn from our work,” he explained. “We have tremendous respect for the researchers behind those models.”
Ultimately, the best way to compete with Chinese models “is to release a superior model,” Atkins concluded. “We need to give them something substantial to discuss.”
Related article
Why I Can’t Help Rooting for Tiny Open Source AI Maker Arcee
Arcee, a lean 26-person U.S. startup, has unveiled its latest reasoning model, Trinity Large Thinking, developed on a modest $20 million budget for a massive 400B-parameter open-source LLM. CEO Mark McQuade tells TechCrunch that this is the most capa
U.S. Stocks Hit Historic Milestone as AI and Aerospace Giants Prepare for Trillion-Dollar Debut
Elon Musk, Sam Altman, and Dario Amodei, three titans of the technology sector, are advancing toward initial public offerings for their respective ventures. With SpaceX, OpenAI, and Anthropic—three industry behemoths nearing trillion-dollar valuation
Swedish AI Startup Lovable Eyes $13.2 Billion Valuation After Major Funding Round
As AI-driven coding tools gain traction, Swedish startup Lovable has secured a major funding round. The company aims to raise $3 billion, potentially boosting its valuation to $13.2 billion—double the $6.6 billion recorded last December. Menlo Ventur
Related Special Topic Recommendations
Comments (0)
0/500

As Chinese open-weight AI models continue to gain capability and market share, debates over how to handle them have intensified once again.
Rumors suggest the Trump administration may attempt to ban these models, though no action has been taken yet. Meanwhile, proprietary model developers, especially OpenAI and Anthropic, are growing increasingly wary of the competition.
Open-weight models like Moonshot AI’s Kimi K3 or Alibaba’s Qwen provide inference at a fraction of the token cost compared to closed-source models from major U.S. labs. This price advantage has sparked fears that they might pose a security threat, primarily by threatening the profit margins of large proprietary AI providers.
However, should enterprises deploying these models in their own data centers worry about them becoming a vector for Chinese hackers?
No, argues Lucas Atkins, CTO of Arcee, a company developing open models to offer U.S. businesses a domestic alternative to Chinese AI.
If any startup would benefit from banning Chinese models, it would be Arcee. Yet Atkins maintains that China’s open models are no more dangerous than any other open-source software a company might use. In fact, he argues, they even offer advantages to his own firm.
“Many people view this as akin to a Chinese software program, assuming it was coded with specific intentions that a malicious actor could exploit,” he noted.
“That is fundamentally not how these models are trained. There is no mechanism for Arcee, or Alibaba, to create a model, have it run in your environment, and gain any access to it,” he explained.
While most of these models are ‘open weight’ rather than fully open-source software, the source code—the part that actually runs on servers—is largely visible and reviewable if downloaded from platforms like Hugging Face. (What remains unavailable are the training methods and datasets.)
Large organizations should subject any model core to rigorous security testing and inspection. They often also post-train models for specific use cases, examining factors like bias, toxicity, hallucinations, and sensitivity to certain topics. This allows them to work with, optimize, and understand the models before users begin sending prompts.
Could a coding model somehow inject malicious backdoors into the code it generates? While theoretically possible, achieving this would require extraordinary technical feats.
“There’s no reason a sufficiently sophisticated actor couldn’t train a model to excel at coding in all scenarios, but trigger hidden malicious behavior when presented with a specific codebase,” Atkins speculated. However, he added: “I don’t know how one would actually achieve this.”
Because large language models are inherently creative, the likelihood of a contemporary model generating malware in response to a perfectly orchestrated context and prompt is slim. The chances of an enterprise then using that code are even slimmer.
Could this happen in the future? That remains uncertain. However, enterprises are building AI applications to be model-agnostic and utilize multiple models. Thus, even if Chinese models offer the best price-to-performance ratio today, enterprises won’t be locked into using them indefinitely.
“I believe the conversation should shift from how to ban Chinese models to how we can foster a robust, open ecosystem here in the U.S.,” Atkins stated.
Arcee also benefits from Chinese models. Because they are open, the startup “gains value when those models perform well, as we can learn from their approaches and build upon them. Then, they can learn from our work,” he explained. “We have tremendous respect for the researchers behind those models.”
Ultimately, the best way to compete with Chinese models “is to release a superior model,” Atkins concluded. “We need to give them something substantial to discuss.”
Why I Can’t Help Rooting for Tiny Open Source AI Maker Arcee
Arcee, a lean 26-person U.S. startup, has unveiled its latest reasoning model, Trinity Large Thinking, developed on a modest $20 million budget for a massive 400B-parameter open-source LLM. CEO Mark McQuade tells TechCrunch that this is the most capa
U.S. Stocks Hit Historic Milestone as AI and Aerospace Giants Prepare for Trillion-Dollar Debut
Elon Musk, Sam Altman, and Dario Amodei, three titans of the technology sector, are advancing toward initial public offerings for their respective ventures. With SpaceX, OpenAI, and Anthropic—three industry behemoths nearing trillion-dollar valuation
Swedish AI Startup Lovable Eyes $13.2 Billion Valuation After Major Funding Round
As AI-driven coding tools gain traction, Swedish startup Lovable has secured a major funding round. The company aims to raise $3 billion, potentially boosting its valuation to $13.2 billion—double the $6.6 billion recorded last December. Menlo Ventur





Home






