
As the White House meets Tuesday with AI companies to discuss a finished voluntary framework for testing frontier AI models’ cybersecurity risks, Senate Democrats are blaming the Trump administration’s lack of clarity on AI governance for fueling an increase in American companies outsourcing their operations to cheaper Chinese AI alternatives.
“The Trump administration’s unfocused, ad-hoc approach to AI risks America’s economic security and competitiveness,” Sen. Kirsten Gillibrand said in a letter before the meeting. “The American people and leading AI companies need clear rules, not constantly changing dictates from the White House. Current administration policy is a disaster, failing to address security risks while threatening American innovation and pushing the world to Chinese alternatives.”
The voluntary framework stems from a June 2 executive order that lets the government review powerful new AI models for national-security risks for up to 30 days before they launch. But details were scarce. On Monday, when the administration announced it met its deadline to finish the framework, but didn’t disclose what was actually in the document, who has seen it, or when companies will begin using it. Google, OpenAI and Anthropic—all reportedly in attendance at Tuesday’s closed-door meeting—reviewed a draft and submitted edits in late July, Politico reported. A White House official also told the publication the administration is engaging with “many more” industry partners than just those three labs.
Gillibrand’s letter, also signed by four other Democratic senators—Chris Coons, Mark Kelly, Adam Schiff, and Mark Warner—pressed the administration for details on what they called its “unpredictable approach” to frontier AI oversight. The letter cited the Commerce Department’s June 12 export-control directive that forced Anthropic to pull its Fable 5 and Mythos 5 models offline worldwide, and a separate request that OpenAI limit rollout of its newer GPT-5.6 system to vetted partners.
“Without consistent policy governing American models,” the senators wrote, “consumers and businesses would be incentivized to migrate to models from foreign vendors, including those based in the People’s Republic of China.”
However, that seems to miss the full scope of what makes Chinese AI alternatives so enticing to consumers and businesses in the first place, said Sam Bresnick, a research fellow at Georgetown’s Center for Security and Emerging Technology. “I see the desire to use these Chinese models more as a function of the premium that Anthropic, OpenAI, Google are charging for their most capable models.”
“Cost and fine-tunability are the drivers of Chinese AI adoption. You can download the weights, and your engineers can fine-tune the model for whatever specific application you want. For a lot of companies, that’s easier than paying top dollar for a closed, proprietary model they don’t need.”
‘Helter-skelter approach’
While he sees cost as the largest reason for companies to move their AI usage to foreign companies, Bresnick agreed the administration’s unpredictability compounds the problem. “Trump’s helter-skelter approach to AI regulation has a chilling effect on the industry here,” he said. “It plays into China’s general narrative that they are the responsible actor, providing public goods—cheap, open-weight AI models that can help countries develop and help enterprises all over the world do their business better.”
Frontier models can strengthen U.S. cyber defenses and military readiness, but sudden, opaque restrictions on access risk undermining trust in American systems and creating “an opening for the PRC,” wrote the senators. If leading U.S. models can be throttled or pulled with little notice, Gillibrand warned, global customers “will plan around that uncertainty” by delaying deployment, avoiding integration of U.S. models into critical workflows and hedging by adopting Chinese or other foreign systems instead.
The cheapness of foreign AI, coupled with the perceived safety of domestic AI, is already being seen in how companies divide their workloads. DoorDash’s leadership has said it plans to keep its most sensitive, proprietary tasks with a U.S. provider while off-loading more routine, non-critical analytics to Chinese open-weight models because they are dramatically cheaper. Bresnick expects more large companies to follow that pattern—and he worries even more about cash-strapped startups quietly plugging sensitive data into foreign models with less scrutiny.
Cheaper AI gets even more attractive when you look at how Chinese AI labs have addressed surface-level security concerns. Chinese AI companies have pushed open-weight systems that can be downloaded and run locally, almost as a proactive answer to what the senators’ letter warned as a “black-box U.S. Government process” that may leave American models with the perception that they can be subject to sudden shutdowns.
China is also unpredictable
Beijing has a history of using economic coercion, like cutting off rare-earth exports or restricting market access, as a tool of foreign policy. Bresnick says there are early signs that Chinese officials are debating whether to block foreign users from the most advanced models.
“China also is unpredictable,” he said. “There’s already scuttlebutt about disallowing foreign access to their most advanced models. If you’re DoorDash or Airbnb and you’ve built parts of your software stack around Chinese AI, expecting those models to continuously improve, you could wake up one day and find that China has decided you don’t get the updates anymore. Then you’re stuck with an ecosystem you counted on that’s no longer evolving the way you thought it would.”
That leaves U.S. firms facing risk on both sides: sudden, opaque restrictions at home, and possible economic coercion abroad. Gillibrand’s letter asks the administration to name its standards for judging a model a national-security risk, the legal authority behind export-control orders, which agencies decide, and what recourse companies have. It also asks how officials will avoid cutting off access for U.S. customers, allied users, critical infrastructure operators and foreign employees who pose no real risk.
“Part of what needs to happen here is a concerted effort to figure out how the U.S. can compete on these open-weight models,” Bresnick said. “The proprietary or closed model approach of the three main AI companies is not serving the needs of the broader tech ecosystem. If the U.S. wants to be present in the tech stacks of countries across the world, it’s going to have to figure out how to be more competitive with the Chinese models on openness and cost.”











