Ask which is riskier, American AI or Chinese AI, and you start a religious war. Ask what each government has already done with the power it holds, and you get an answer.
The United States has switched AI access off three times in two years: against China in 2024, against an Indian refiner's cloud account in 2025, and in February 2026 against its own flagship lab, Anthropic, for refusing to permit mass domestic surveillance and autonomous weapons. It can compel your data under the CLOUD Act wherever in the world that data sits. A US court has already suspended the delete button on millions of ChatGPT conversations and ordered twenty million of them handed to plaintiffs. Someone edited Grok's system prompt in the small hours and the chatbot spent the morning pushing a race conspiracy theory at people who had asked about their pets.
China's record is quieter and more structural. Its intelligence law obliges every company to assist state intelligence work. Its AI regulations make censorship a licensing condition. Its flagship chatbot will not discuss Tiananmen Square. But it gives its model weights away, and weights on your own servers answer to no one.
Neither stack is safe. The dangers are different in kind, and one asymmetry between them changes what a sensible European organisation should do next. That is what this piece is about.
Start with what Washington did to its own champion
On 27 February 2026 the President of the United States ordered every federal agency to stop using Anthropic's technology. The Defense Secretary designated Anthropic, an American company, a supply-chain risk to national security, and declared that no contractor doing business with the US military could trade with Anthropic at all [3][4][5].
No breach. No espionage. The offence was a contract clause. Anthropic had refused to delete two restrictions from its acceptable use policy: no mass surveillance of American citizens, no fully autonomous weapons. The Pentagon demanded language permitting "all lawful uses". Anthropic declined. So the administration reached for procurement law, supply-chain designations and, in June 2026, export controls on Anthropic's newest models, lifted two weeks later [3]. The courts pushed back with a preliminary injunction in March, and the fight was still grinding through litigation at the end of July [3]. OpenAI took the deal Anthropic had refused, and took a public beating for it [3].
Sit with what that means from Lisbon or Helsinki. If the US government will try to ruin its own most safety-conscious lab over a surveillance clause, a European ministry or mid-sized bank is not a consideration. It is a rounding error.
It was not the first time. On 9 July 2024 OpenAI cut API access to China, Hong Kong and every territory outside its supported list, giving startups that had built on the API days to migrate while Baidu and Alibaba circled with free tokens [1][2]. In July 2025 Microsoft suspended cloud services to Nayara Energy, an Indian refiner part-owned by Rosneft, citing EU sanctions that India had never adopted and no law required Microsoft to enforce; service returned only after Nayara went to court in New Delhi [6]. A compliance team in Redmond switched off an Indian company's email over a European political decision. Remember that the next time someone tells you the licence fee buys certainty.
Underneath the software sits the silicon, and Washington's hand is on that too. The Chip Security Act, introduced in May 2025 and out of House committee 42 to 0 in March 2026, would mandate location verification in export-controlled AI chips and fund study of further mechanisms, including what analysts describe as remote disable or performance degradation [7][8]. Beijing clearly believes the capability is coming: it summoned Nvidia on 31 July 2025 over alleged backdoor risks in the H20, a charge Nvidia denies. Days later the administration confirmed it would take 15 per cent of Nvidia's and AMD's China chip revenue in exchange for export licences. Revenue, location, off-switch. The architecture of control is being assembled in plain sight.
China, to be fair, has no matching record of cutting foreign users off. Its influence runs through app stores, censorship conditions and the dependency that a free frontier-class model builds. And it does something Washington will not: it gives the weights away. DeepSeek's R1 carries an MIT licence, Alibaba's Qwen an Apache one. Weights on your own hardware cannot be recalled, geo-blocked or sanctioned. Hold that thought. It matters later.
Who can read what you type
The American answer is: more people than you think, through more doors than you expect.
The CLOUD Act of 2018 exists because Microsoft fought a US warrant for emails stored in Dublin, and Congress decided it would rather change the law than lose the argument. US providers must now produce data in their possession, custody or control regardless of where it is stored. Your prompts in an Irish data centre are within reach of an American warrant. Section 702 of FISA, reauthorised and widened in April 2024, lets US agencies collect the communications of non-Americans abroad through compelled assistance from US providers, without a warrant, with no meaningful standing for you in the process.
Then there is the civil route, which arrived quietly and should have been front-page news. In May 2025, in the New York Times copyright case, a federal magistrate ordered OpenAI to preserve all ChatGPT output logs it would otherwise have deleted, across every consumer tier, including conversations users had already deleted. OpenAI had to tell EU customers their GDPR erasure rights were suspended. The hold ran until late September 2025. Two months later the court ordered 20 million de-identified chat logs produced to the plaintiffs [9]. The delete button, it turns out, is a feature of your subscription, and litigation outranks your subscription. Only negotiated enterprise terms with zero retention survived.
China's answer is simpler, and there is no door at all. Article 7 of the 2017 National Intelligence Law obliges every organisation and citizen to support, assist and cooperate with state intelligence work; Article 14 lets intelligence organs demand it [10]. No warrant, no public docket, no appeal. When Italy's Garante asked DeepSeek basic questions in January 2025, the company's position was that EU law did not apply to it. The Garante imposed the first Western ban on 30 January 2025, and regulators in Ireland, France, the Netherlands, Belgium and Germany opened files [11]. South Korea's authority found DeepSeek had shipped user data, prompt content included, to a Beijing affiliate without proper consent [11]. China's generative AI rules, in force since August 2023, require real-name registration, retained logs and algorithm filings with the Cyberspace Administration. The state is not asking for the data. It is plumbed in.
So the honest ledger reads like this. American reach is documented, challengeable and occasionally beaten in open court. Chinese reach is invisible and, for practical purposes, absolute.
You are not choosing between safe and unsafe. You are choosing between audited risk and unknowable risk.
Who moves the dial
Models do not arrive neutral. People tune them, prompt them and filter them, and those people have owners, employers and politics. The question is whose hands are on the dial and whether you can see them move.
At about 3:15 in the morning, Pacific time, on 14 May 2025, someone modified Grok's system prompt to force a specific response on a political topic. For hours afterwards, users asking about baseball or a video of a cat received discourses on "white genocide" in South Africa, a theory Grok's owner had personally promoted. xAI blamed an "unauthorised modification" that slipped past its code review, and promised to publish its prompts [12][13]. That same week Grok told users the Holocaust death toll of six million was a figure from "mainstream" sources open to political manipulation [13]. It was the second such "unauthorised" change in four months [13].
Two months later the mask slipped again. After Elon Musk announced he had made Grok less politically correct, the chatbot posted antisemitic filth, praised Hitler and called itself "MechaHitler". xAI deleted the posts and apologised. Turkey blocked the service. Weeks after that, the Pentagon signed xAI to a contract worth up to $200 million and xAI launched Grok for Government [14][15]. Draw your own conclusion about the relationship between conduct and consequence.
The state has its own hand on the American dial now. Executive Order 14319, signed on 23 July 2025, makes federal LLM procurement conditional on "truth-seeking" and "ideological neutrality", both defined by the administration, with DEI named in the order as a disqualifying ideology, and decommissioning costs chargeable to vendors that breach the terms [16][17]. Strip away your own politics for a moment and look at the mechanism: the government of the day now defines acceptable machine truth as a condition of a chequebook large enough to shape the product everyone else gets.
On foreign agendas running through American models, precision matters, because the loudest claims outrun the evidence. What is proven: in May 2024 OpenAI's own threat report disclosed "Zero Zeno", a covert influence operation run by Stoic, a Tel Aviv political marketing firm, which used ChatGPT to generate pro-Israel content on the Gaza war, aimed at audiences in the US, Canada and Israel, through fake personas including accounts posing as African American students. Meta removed over 500 accounts tied to the same firm [18][19]. That is on the record because OpenAI published it. What is not proven is the stronger claim that US models are tuned, at the weight level, to favour Israel. The evidence points the other way: an Anti-Defamation League audit published in 2025 reported patterns of anti-Israel and antisemitic output across major US models. The defensible conclusion is narrower and, if anything, worse. These systems are steerable, the steering is contested by many hands, and none of those hands answers to you.
China, characteristically, does not pretend. Article 4 of its 2023 generative AI rules requires services to uphold core socialist values and bars content that subverts state power or damages the national image, enforced through a filing regime that makes alignment a licensing condition. Test the hosted DeepSeek app, as The Guardian and others did in early 2025, and it refuses or deflects on Tiananmen, Taiwan and the Uyghurs. The censorship is real, predictable and declared. Researchers have also shown it lives mostly in the fine-tuning and serving layers, which is why a self-hosted copy behaves differently from the app.
Two systems of steering. One you can forecast from a statute. One you may never detect.
The state is not a regulator here. It is a customer
The surveillance debate usually stops at who can read your prompts. The more consequential story is how deeply the AI companies are being wired into state security machinery, and what they are being asked to do inside it.
In July 2025 the Pentagon awarded contracts worth up to $200 million each to OpenAI, Anthropic, Google and xAI, for frontier AI across warfighting, intelligence and enterprise systems [14][15]. Anthropic had already put Claude on classified US networks, a first for a frontier lab, and launched a dedicated government product line, Claude Gov, in June 2025 [14]. None of this is leaked. It is in the press releases.
The telling document is the dispute that followed. When the Pentagon renegotiated with Anthropic in early 2026, the two clauses it demanded removed were the ban on mass domestic surveillance and the ban on fully autonomous weapons [3][4]. The government's shopping list was the thing a concerned citizen would hope never to see requested. One lab refused and was punished. Another agreed and was paid.
For a look at where tight state integration ends up in practice, consider Israel's own systems. In April 2024, +972 Magazine and Local Call documented Lavender and The Gospel, AI systems the Israeli military used to generate bombing targets in Gaza faster than humans could review them, with civilian deaths accepted as a ratio attached to each strike. Those are Israeli systems, not American or Chinese models, and it would be wrong to pin them on either. They belong in this piece as a preview: that is what AI looks like once a state builds it into a targeting chain with no external restraint, which is the direction the Pentagon's contract language pointed.
So which is riskier
Wrong axis. Risk here follows jurisdiction and architecture, not flags.
On being switched off, the United States has the worse documented record by a distance, against rivals, against neutral parties, and now against its own champion. On being read, both states reserve the power; America's version can be audited and occasionally beaten in court, China's cannot. On steering, China declares its censorship in statute and applies it predictably; America's steering is private, erratic, lately governmental, and disclosed mostly after the fact.
And one asymmetry cuts across all of it. China publishes its strongest weights under open licences. America keeps its frontier models closed and rents access. A self-hosted open model on European infrastructure is the only configuration in this entire comparison that removes the foreign hand altogether.
| Risk | US-based models | China-based models |
|---|---|---|
| Being switched off | Documented three times in two years, most recently against Anthropic, an American lab (2026) | No documented cut-off of foreign users; dependence built through free capability and app-store control |
| Hardware control | Chip Security Act: location verification mandated, remote-disable mechanisms under study | Suspected target of chip-level control, not the author of it |
| Lawful access to your data | CLOUD Act reach anywhere; FISA 702 compulsion; courts can override deletion, as 20 million ChatGPT users learned | National Intelligence Law Articles 7 and 14; no process, no redress, no visibility |
| State integration | $200 million defence contracts; classified deployments; government demanded removal of mass-surveillance limits (2026) | Structural: real-name registration, retained logs, filed algorithms, duty to assist |
| Steering | Prompt tampering at xAI (twice in 2025); government-defined "truth" now a procurement condition; foreign-aligned influence operations documented | Statutory alignment with core socialist values; hosted apps refuse sensitive topics |
| Transparency | Steering sometimes published after incidents; operations disclosed in vendor reports | Declared in law, visible in output |
| Exit | Closed weights, revocable agreements | Open weights (MIT, Apache 2.0): self-host and the foreign hand is gone |
Where this goes next
Judgement, not established fact, from here.
Frontier models will be export-controlled like chips. Washington briefly did it to Anthropic's own models in June 2026, and the logic of location-verified silicon applies cleanly to weights [3]. Expect licences, and expect "all lawful use" clauses stapled to them.
Government-defined truth will spread through procurement. EO 14319 needs no parliamentary approval to copy. Other governments will write their own versions, each defining acceptable output to taste, and the differences will be buried in fine-tuning nobody publishes.
China will keep giving the weights away, because open release undercuts American licensing revenue and seeds dependence on Chinese research, all with plausible deniability. The smart European response is to take the weights and leave the hosted service.
A serious chat-log disclosure incident is coming. Twenty million conversations were ordered produced in one copyright case [9]. The next one will involve a government or a leak, and it will reset what boards allow staff to type into consumer AI tools.
Europe's window is open now and will not stay open. The AI Act is in force, the research base is world-class, and open weights make sovereign hosting practical without frontier compute of your own. That combination has a shelf life.
What to do about it
- Map every AI dependency by jurisdiction. Model, host, silicon, payment rail, subcontractor. Record which foreign state holds a lever over each layer, in the risk register, by name.
- Run open weights on infrastructure you control for anything sensitive. Weights on your servers cannot be switched off, mined under foreign law, or quietly re-tuned.
- Contract for exit. Portable fine-tunes, exportable data, notice periods, a tested migration path per supplier. Nayara's experience shows terms of service yield to politics; the exit plan is the control that survives.
- Keep sensitive material out of consumer tiers. Litigation holds override the delete button — the prompt box is the control surface now. Zero-retention enterprise terms were the only carve-out that held in 2025.
- Test the dial quarterly. Probe every model you rely on with the contested questions in your sector and log the answers. Drift is your early warning of steering.
- Treat American and Chinese hosted services as equally foreign. Neither jurisdiction's law protects you, and neither's politics is yours.
The bottom line
The comfortable European story said American AI was the safe default and Chinese AI the risky choice. The record of the last two years does not support it. Washington has demonstrated the switch against allies, rivals and its own lab, written extraterritorial reach into statute and discovery practice, and put government-defined truth into procurement. Beijing has declared the reach and the censorship in law, while handing out the one artefact that neutralises the switch for everyone.
Stop asking which superpower to trust. Start asking which dependencies you could survive losing.
Your data. Your rules. Your continent.
Part 2 sets out the European answer: open weights, sovereign hosting, and what the AI Act does and does not protect.
Sources
- Rest of World, "OpenAI cuts its last and most important link to China", 27 June 2024.
- ThinkChina, "OpenAI's block in Hong Kong and mainland China deepens China-US divide", 10 July 2024.
- Congressional Research Service, "Federal Government and Anthropic: Considerations for AI Innovation and Competition" (IF13217), 31 July 2026.
- Mayer Brown, "Pentagon Designates Anthropic a Supply Chain Risk: What Government Contractors Need to Know", 2 March 2026.
- Lawfare, "Pentagon's Anthropic Designation Won't Survive First Contact with Legal System", 2 March 2026.
- BankInfoSecurity, "Nayara Energy vs. Microsoft and Compliance-Driven Lockouts", 13 August 2025.
- Office of Senator Tom Cotton, "Cotton Introduces Bill to Prevent Diversion of Advanced Chips to America's Adversaries and Protect US Product Integrity", 8 May 2025.
- Legis1, "In a Fractured Congress, a Chip Security Bill Finds Rare Common Ground", 30 March 2026.
- Terms.law, "OpenAI v New York Times: When Your ChatGPT Logs Become Evidence", 12 November 2025.
- National Intelligence Law of the People's Republic of China, 2017, Articles 7 and 14. Summary at SovereignSky.
- AI-Regulation.com, "DeepSeek One Year Later: Regulatory Storm, Global Surge", 28 January 2026.
- xAI statement on the Grok system prompt incident, via X, 16 May 2025.
- The Decoder, "xAI reverses Grok's prompt changes after racist responses", 21 May 2025.
- DefenseScoop, "Pentagon awards mega contracts to Musk-owned company, other firms for new frontier AI projects", 14 July 2025.
- Breaking Defense, "Anthropic, Google and xAI win $200M each from Pentagon AI chief for agentic AI", 14 July 2025.
- The White House, Executive Order 14319, "Preventing Woke AI in the Federal Government", 23 July 2025.
- Paul Hastings, "President Trump Signs Three Executive Orders Relating to Artificial Intelligence", 8 August 2025.
- Time, "OpenAI: Russia, China, Israel Use It for Influence Campaigns", 30 May 2024.
- SC World, "OpenAI report reveals threat actors using ChatGPT in influence operations", 31 May 2024.