Skip to Content
OPINION

Thought for the week: A shifting AI policy landscape

As AI policy evolves in China and the U.S., organizations should reassess strategy, dependencies and risks.

Published
Subscribe to IAPP Newsletters

Contributors:

Brian Hengesbaugh

CIPP/US

Global Chair, Data and Cyber

Baker McKenzie

Editor's note

The IAPP is policy neutral. We publish contributed opinion pieces to enable our members to hear a broad spectrum of views in our domains. 

This article is part of an ongoing series that will explore issues or recent developments in data, cybersecurity and artificial intelligence governance.

A recent article by The Wire China highlights remarks by China's President Xi Jinping at the annual World AI Conference in Singapore where he praised the open sharing of AI models while cautioning the need for restrictions on openness to keep artificial intelligence technology secure. 

The backdrop is that China's leading AI companies have often released their AI models openly. Such openness can come in the form of open weight, where companies can download the trained model parameters — the weights are billions of numerical values that encode what the model learned during training — and then fine-tune and run the model. 

It can also consist of open-source models, where companies can download the weights, but also the training and inference code, training data and other information. A useful baking analogy is that open-weight models are like getting the finished cake you can decorate or modify, whereas open-source is getting the recipe for the cake. Open-weight and open-source models are generally better on transparency and auditability than closed models. However, they are also outside the control of the developers and they are more vulnerable to abuse by bad actors, who have more ability to strip safeguards and misuse the models for cyberattacks or other malicious purposes.

China seems to be considering a more restrictive policy of selective openness. Beijing would continue to keep good-enough models open but restrict access to the most advanced models. This potential shift in policy echoes recent changes in U.S. policy, where the U.S. government initially voiced strong support for allowing AI developers and deployers to proceed without regulation, but a bit down the road started establishing voluntary and later mandatory, under export control and other rules, oversight of AI models for national security purposes.

The article strikes a potential point of optimism by noting that U.S. Treasury Secretary Scott Bessent floated the idea of a bilateral protocol for best practices in evaluating the risks of AI models following the Trump-Xi summit in May. Whether such line drawing and policymaking could ever be done between and among the U.S. and China remains to be seen, but the article finishes with a directional note that the "days when the frontier of AI went unregulated may quicky be ending, in Beijing as much as in Washington."

What does this mean for global business?

As with any question, the right answer(s) for any company depends on its industry vertical, geographic footprint and other factors.  As a general matter, however, companies should consider several key points in this context.

Prepare for more US and China policy changes

There is every reason to expect that China and the U.S. are going to continue to perceive enhanced cyber, national security and other risks associated with frontier AI models. The policy responses in both Washington and Beijing could likely involve variations on limitations to access to AI models, chips, model weights, cloud computing resources and more.

Lower your expectations for policy alignment

Other than a general trajectory toward more and different restrictions of varying types, it is difficult to imagine a scenario in which China and the U.S. coordinate substantively on how to draw lines and manage risks on these issues. Among other points, the U.S. Office of the Director of National Intelligence's 2026 Annual Threat Assessment highlights how China poses persistent cyber threats to the U.S. government, private-sector and critical infrastructure. As such, an in-depth, collaborative analysis of the cyber risks of frontier AI models seems a bit out of reach in this context.

Update your AI inventory and dependency map

Global companies should establish and/or update their AI inventory and dependency map that would answer questions such as "which business processes would fail if model ABC became unavailable?" Such a map could assess models used, vendors, hosting location, jurisdiction, data flows and critical business functions.

Leverage a COSO framework analysis of likelihood/severity to assess risks

The company should then evaluate its map within a Committee of Sponsoring Organizations of the Treadway Commission framework, or similar analytical framework, to examine the likelihood and severity of potential risks associated with the unavailability of AI models or services based on geopolitical developments or other policy shifts. The analysis would need to take into account not only the company's specific situation, but the current landscape associated with export controls, sanctions, national security, foreign investment and other laws, regulations and restrictions.

Develop a strategy to manage risks

The resulting strategy to mitigate risks will vary greatly depending on the company and its resources and risk assessment. Possible steps could include building out a multimodel strategy, network segmentation/bifurcated architecture between China and the U.S., establishing an open-weight model contingency and other elements.

Consider an AI tabletop exercise

Companies could also consider an AI tabletop exercise to address a situation where a significant policy change or geopolitical development in China, the U.S. or other market disrupts company operations.

As noted, there is no one-size-fits-all answer for companies, and the specifics of how policy developments play out in the coming weeks and months are difficult to predict with accuracy. Having said that, organizations should be working on strategy and risk management with their eyes wide open to the current developments. 

CPE credit badge

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.

Submit for CPEs

Contributors:

Brian Hengesbaugh

CIPP/US

Global Chair, Data and Cyber

Baker McKenzie

Tags:

AI and machine learningAI governance

Related Stories