When Xi Jinping sits down with Donald Trump in Washington on September 24, the American side plans to raise AI-directed cyberattacks and accusations that Chinese labs copied U.S. models. Less than two weeks earlier in New Delhi, Xi offered the BRICS bloc something incredibly valuable and low-cost: an open-source AI zone , a digital industry cloud platform, and a BRICS engineer-training alliance .
The two agendas describe different contests. Washington is arguing over who gets to hold the best model. Most of the world is asking for something plainer: can a health ministry in Jakarta or Pretoria download a model, run it on its own servers, retrain it in its own languages, and keep it running when relations with Washington sour?
The market answered before the diplomats did. Alibaba’s Qwen suite of AI applications passed three billion downloads in August, ahead of Meta and Google. Inside the U.S. market, Chinese models have taken more than 30 percent of weekly token usage—by U.S. customers on OpenRouter since February— peaking at 46 percent . American developers are not choosing DeepSeek or Kimi out of solidarity with the Global South. The license is permissive, and the bill is smaller.
Southeast Asia has run this experiment for three years without calling it geopolitics. Singapore’s AI model SEA-LION , trained across 13 regional languages, is built on open foundations including Qwen and Llama. Indonesia adapted it into Sahabat-AI for citizen services. Neither program would survive per-token billing in dollars at a national scale.
Africa holds roughly 0.6 percent of global data center capacity. A closed model reaches Lagos as a metered service, priced and hosted abroad, and terminable by officials no Nigerian voter elected. An open-weight model arrives as a file. Once downloaded, it stays downloaded.
Beijing gains from this. Every ministry that builds on Qwen inherits a tokenizer, an evaluation suite, and engineering habits made in Hangzhou. The training alliance extends that reach at low cost: pedagogy is cheaper to export than silicon and far harder to sanction. The offer has gaps too. Serving a model to millions of citizens still takes accelerators, cooling, and power that most members lack, so the cloud platform carries the weight of the package and is the piece least likely to arrive on time. The bloc’s own New Delhi Declaration says nothing about free download and adaptation—without the code and data sets, it’s open weight rather than open source—and India has model ambitions of its own.
Washington’s response so far has been to talk about theft and ceilings. Anthropic published a report on September 10 alleging nearly 200 million exchanges of unauthorized distillation by Chinese labs, 151 million of them attributed to Alibaba. The evidence is the company’s own telemetry, unaudited. China’s Commerce Ministry had already rejected a similar charge from U.S. agencies. Days later, Dario Amodei proposed that frontier labs in democracies agree on common capability limits under an antitrust carve-out, while the United States stops selling China powerful chips and chipmaking equipment, all to “widen America’s lead significantly.”
Read that from Nairobi. A company that paid $1.5 billion in July to settle claims over piracy now proposes limits drawn by the field’s leaders, which countries with no frontier lab would have to live under without having negotiated them. Chip policy offers no steadier ground. In January, the Trump administration approved H200 sales to China with a 25 percent fee attached. Access granted for a fee can be withdrawn, however, and summit host Narendra Modi warned that weaponizing technology and critical minerals hinders shared progress.
American industry is split. The open-weights letter signed in July by Microsoft, Nvidia, Meta, Hugging Face, and IBM called distillation a standard technique rather than a theft, and warned that premature restriction would hand the default to someone else. Signatories have since passed 270 organizations , including Google and OpenAI. Anthropic has not signed.
Treasury Secretary Scott Bessent meets Vice Premier He Lifeng this weekend to prepare the summit, with AI safety on the list. A channel on AI-enabled cyberattacks is worth building. But if the United States treats AI only as a matter of stolen models and export lists, it ignores the question most governments are asking for Beijing to answer. A better American position would keep the cyber channel, drop the idea of a capability cartel, back permissively licensed US open-weight releases, and pay for computer and engineering training in poorer countries through multilateral channels rather than as privileges revocable in Washington.
China should face its own tests. Do the licenses stay permissive once dependence sets in? Do the cloud platform and training alliance come with compute allocations and engineering cohorts, or only memoranda? Beijing already runs the Shanghai-based World AI Cooperation Organization, launched in July with 29 founding members , and it takes the BRICS chairship for 2027.
That leaves roughly fifteen months to turn an announcement into downloads, trained engineers, and running deployments. If it succeeds, Washington’s fight over who may release the best AI models will be about a distribution already settled elsewhere.
The post Before Trump Meets Xi, Look at What China Just Gave BRICS appeared first on Foreign Policy In Focus .
Before Trump Meets Xi, Look at What China Just Gave BRICS
Aggregated summary from an independent source. Read the original at FPIP.