Nvidia's CEO argues openly downloadable Chinese models are safer to use than closed ones, breaking with the U.S. policy line tightening around Beijing.
Jensen Huang says U.S. companies should "absolutely" be allowed to use Chinese AI models. In a sit-down with Axios co-founder Mike Allen, he argued the security case that runs against Washington's recent posture: a model that can be downloaded, inspected, fine-tuned, and guardrailed is safer than one shipped as a black box. "There's a misconception that there's some backdoor," the Nvidia CEO said, according to Tom's Hardware's write-up of the interview. "You can download the model. You can fine-tune it. You can enhance it. You can guardrail it."
The position lands inside an unusually active week of U.S.–China AI policy. On July 21 2026, Treasury Secretary Scott Bessent threatened U.S. sanctions on Chinese AI over alleged intellectual-property theft, according to CNBC, the same day TechCrunch reported that Washington is preparing a broader sanctions posture. The trigger that pulled Huang into the debate was Moonshot AI's Kimi K3, a 2.8-trillion-parameter open-weight model the Chinese lab has positioned as comparable to GPT 5.5 and Anthropic's Claude Opus 4.8 at roughly one-third the cost.
The inversion in Huang's argument is that Washington has already been quietly applying open-inspection logic in the other direction. The U.S. has placed export restrictions on Anthropic's Mythos and Fable 5 models, lifted after Anthropic added a vulnerability filter. OpenAI's ChatGPT-5.6 also drew restrictions, and Washington has told OpenAI not to release new models without approval. In each case the fix was technical and observable, not geopolitical.
Huang's broader claim is that rapid testing and iteration make any model more secure, regardless of origin. "One single model, one single point of attack, one single source of failure," he said, in the version of the quote carried by Firstpost and The Next Web. He supports both open and closed releases. Open models, he argues, are needed for science and cybersecurity because researchers and defenders can actually look at them.
The strongest counter-position sits one layer up from where Huang is arguing. A model that passes a quick red-team inspection can still carry a deeper vulnerability in its training data, the layer Bessent's sanctions threat actually targets. Guardrails visible to the deployer can be stripped by a downstream user. And the U.S. controls on Anthropic and OpenAI were about restricting export, not restricting domestic use of foreign models, so the parallel Huang is drawing does not quite line up. None of that refutes his inspection argument. It is a reminder that the security question has more than one floor.
The next move to watch is whether Bessent's sanctions regime is framed at the training-data layer, where Beijing has more leverage, or at the deployment layer, where Huang's logic is strongest. The Bessent posture, as Yahoo Finance summarizes it, treats IP theft as the primary vector. Huang is treating the model artifact as the primary vector. If the sanctions land on training data, Huang's argument is intact. If they try to land on the model artifact, the U.S. will have to explain why the same logic does not apply to U.S. exports of Mythos, Fable 5, and ChatGPT-5.6.