Technology · Artificial intelligence
Chinese open-weight AI models challenge European sovereignty calculus
European firms weigh whether locally hosted Chinese systems offer more control than US proprietary alternatives, complicating Brussels' self-reliance agenda.
European companies are quietly testing a proposition that would have seemed contradictory two years ago: that Chinese artificial intelligence models, run on their own servers, might actually strengthen the continent's technological sovereignty rather than undermine it. The argument, advanced by consultants and infrastructure providers, rests on a distinction between where a model originates and where it executes, a distinction that Brussels' regulatory framework has yet to fully absorb.
The shift is driven by the maturation of Chinese open-weight foundation models, systems whose underlying parameters are published and downloadable, allowing any organisation to host, fine-tune and operate them without ongoing dependence on the original developer. Models from companies such as Zhipu AI, Moonshot AI and the Alibaba-backed Qwen series have closed much of the performance gap with leading US proprietary systems, while costing a fraction of the price to run at scale.
The sovereignty paradox
Volker Pfirsching, a Munich-based partner at management consultancy Arthur D. Little, articulated the core tension in an interview this week. "A Chinese-developed open-weight model operated on European infrastructure, with data remaining under the company's control, may in some respects offer greater operational sovereignty than consuming a proprietary foreign model that can be changed, repriced or withdrawn remotely," he said. The observation cuts across the grain of European policy, which has tended to equate technological sovereignty with the nationality of the supplier.
Pfirsching's point is operational, not political. A European firm using OpenAI's GPT-4o or Anthropic's Claude via API has no control over model versions, pricing, availability or data processing terms. The US provider can deprecate an endpoint, raise prices, or alter behaviour with minimal notice. By contrast, an open-weight model, whether Chinese, French or American in origin, downloaded onto servers in Frankfurt or Paris, governed by European staff, subject to EU data protection law, and fine-tuned on proprietary data never leaving the premises, gives the deploying organisation full technical control.
Open-weight versus open-source: a critical distinction
The industry uses "open-weight" precisely because these models are not open-source in the traditional sense. The training data, training code, and often the methodology remain proprietary. What is released are the model parameters, the billions of numerical weights that define the model's behaviour. This is sufficient for inference and fine-tuning, but not for full reproducibility or independent audit of the training process. For European enterprises, the distinction matters: they gain deployment autonomy but not supply-chain transparency.
Chinese labs have been notably aggressive in releasing open-weight models. Zhipu AI's GLM series, Moonshot's Kimi, and Alibaba's Qwen family have all published weights under permissive licences allowing commercial use. Western counterparts have been more cautious: Meta's Llama series is the most prominent open-weight family from a US company, while French startup Mistral AI has released several models under Apache 2.0. The Chinese releases have accelerated a competitive dynamic that benefits European adopters, more choice, lower cost, faster innovation.
Brussels' regulatory framework pulls in the opposite direction
The European Union's approach to AI sovereignty has been shaped by the AI Act, which entered into force in August 2024 and classifies systems by risk rather than origin. The regulation imposes obligations on providers and deployers of high-risk AI systems, including transparency, data governance, and human oversight requirements. It does not restrict the nationality of foundation model providers. However, the accompanying political rhetoric, from the European Commission's 2021 "Strategic dependencies and capacities" communication to the 2023 European Economic Security Strategy, has consistently framed non-European critical technology dependencies as vulnerabilities to be reduced.
This creates a policy mismatch. The law is origin-agnostic; the strategy is origin-sensitive. A German manufacturer deploying a fine-tuned Qwen model on its own infrastructure complies with the AI Act's deployer obligations. But the same manufacturer may find itself at odds with procurement guidelines for critical infrastructure, defence, or public sector contracts that implicitly or explicitly prefer European-origin technology. The European Commission's Digital Decade targets include 75% of European enterprises using AI by 2030, but the policy toolkit for achieving this, funding for European foundation models through Horizon Europe, the AI Factories initiative, the EuroHPC Joint Undertaking, assumes the solution is European-developed models.
The supply-chain dependency that won't disappear
Pfirsching's argument has a blind spot: open-weight models are not static artefacts. They require updates, security patches, performance improvements, compatibility fixes for new hardware, extensions for new modalities. The organisation that trained the model controls the roadmap. A European firm hosting a Chinese model today gains operational autonomy but inherits a dependency on the Chinese lab's future release decisions. If the lab stops publishing updates, shifts licence terms, or is directed by Beijing to withhold releases, the European deployer faces a fork: maintain an increasingly stale model, invest heavily in independent continued development, or migrate.
This is not hypothetical. The US export controls on advanced semiconductors, tightened in October 2022 and again in 2023, demonstrated how quickly hardware dependencies can be weaponised. Chinese AI labs operate under a regulatory environment where the Cybersecurity Law, Data Security Law, and Personal Information Protection Law grant the state broad access and direction powers. European firms adopting Chinese foundation models are not merely buying software; they are entering a long-term relationship with an entity subject to a different legal and political order.
European alternatives exist but face scaling challenges
The European ecosystem has not been idle. Mistral AI, founded in 2023, has raised over €1 billion and released models competitive with GPT-3.5-class systems. Aleph Alpha in Heidelberg pivoted from foundation model training to sovereign AI infrastructure for governments and enterprises. The EuroHPC Joint Undertaking has procured exascale-class supercomputers, LUMI in Finland, Leonardo in Italy, MareNostrum 5 in Spain, explicitly to train European large language models. The AI Factories initiative, launched in 2024, aims to couple compute access with data, talent and startup support.
Yet the gap in capital, talent density, and training data scale remains substantial. US labs have raised tens of billions; Chinese labs benefit from vast domestic markets and state-directed compute allocation. European ventures operate in a fragmented capital market, with stricter data protection constraints on training data, and a regulatory environment that, while harmonised, adds compliance overhead. The result: European open-weight models lag the frontier by 12 to 18 months, a gap that feels permanent to enterprises making procurement decisions today.
Sectoral divergence in adoption appetite
The willingness to adopt Chinese open-weight models varies sharply by sector. Manufacturing, logistics, and mid-market software companies, sectors where AI is a productivity tool rather than a strategic differentiator, are the most open. They value cost-performance, deployment flexibility, and the ability to keep proprietary process data on-premise. Financial services, telecommunications, and defence-adjacent industries remain cautious. Regulators in these sectors, BaFin in Germany, ACPR in France, the ECB's supervisory arm, have not issued specific guidance on foundation model origin, but their expectations for supply-chain resilience and auditability effectively disfavour opaque upstream dependencies.
The public sector is the hardest case. The EU's Interoperable Europe Act and national digital sovereignty strategies (France's "Cloud de confiance", Germany's "Sovereign Cloud") create a presumption in favour of European-origin stacks. A French ministry deploying a Chinese model, even on French servers, would face political scrutiny that a Mistral deployment would not. This is not purely protectionism; it reflects a legitimate democratic preference for accountable supply chains in systems that mediate citizen-state interactions.
The emerging middle ground: model distillation and synthetic data
A technical workaround is gaining traction. European firms are using Chinese (and US) open-weight models as teachers, generating synthetic training data, annotating datasets, and producing distilled smaller models that inherit capabilities without the parameter count or the upstream dependency. A 7-billion-parameter model distilled from a 72-billion-parameter Chinese teacher can run on modest infrastructure, be fully owned, and avoid ongoing reliance on the teacher's releases. This approach, sometimes called "model extraction" or "knowledge distillation", sits in a grey zone: it leverages the frontier model's capabilities without adopting its supply chain.
The legality is unsettled. Most open-weight licences permit distillation for internal use; some restrict commercial redistribution of derived models. The EU's proposed AI Liability Directive and Product Liability Directive revision may eventually clarify whether a deployer of a distilled model bears responsibility for upstream defects or biases. For now, enterprises proceed cautiously, documenting the lineage of each model in their model cards and risk assessments.
Sources
People mentioned
Volker Pfirsching
Organisations
Arthur D. Little · European Commission