Hacker News new | ask | show | jobs
by austinthetaco 12 days ago
This is weird and reactionary. Lots of organizations are continuing to refuse to use chinese models due to security and IP concerns. Anthropic/american models aren't going anywhere anytime soon.
10 comments

> Lots of organizations are continuing to refuse to use chinese models due to security and IP concerns

This is such a common omission: the Chinese models are open, you can host them yourself on your premises. So privacy and independence.

it's well documented that models can be adversarially trained with essentially backdoors in response to special inputs

while I am skeptical that this is happening atm, there are probably many industries where the risk does not seem worthwhile

I suppose this is like when Anthropic was using “prompt modification, steering vectors, or parameter-efficient fine-tuning” to poison the work of people working in the LLM field, including academic researchers.
No, that was totally different. They were just doing that for your safety.
When the model is open weights you can even pass every token (including the chain of thought) though a fourth-party lightweight model like gpt-oss-safeguard to check that it has not become adversarial.
So it's better to trust cloud solution where not only they can do the same, but also actively use your data?

Because in 2026 we still believe USA is more trustworthy than China?

I feel like that's a threat that isn't super difficult to block. Unplug it from the internet, require it to go through an API intermediary to access web pages.

Maybe I just don't have any imagination.

It could generate code that's plausible but has intentional flaws, kind of like the defunct underhanded C contest [0], except through a LLM.

[0] https://en.wikipedia.org/wiki/Underhanded_C_Contest

It could, but exposing that would doom the company entirely, and AI doesn't generate code with near the quality needed to get a model to mass adoption, insert malicious underhanded code, ensure that consistently looks innocuous enough to never be noticed, and- most importantly- actually exfiltrate data without being noticed. Once it is noticed, it's game over across the board.
You don't even need that, all models are susceptible to prompt injection. You already need to take extreme security precautions and assume all models can essentially behave like attacker-controlled rootkits.
That's right, but this strategy only works when there are no opponents of the same level to review the generated code.
For several export controlled industries in the United States, even self-hosting a Chinese model is a non-starter.
Good luck hosting 2.8T params yourself. A box capable of this at a useful performance level is at least $100k.
More like $500k, but that's not an unreasonable price for a medium sized enterprise to pay.

I have an RF engineering background, a nice mmWave vector network analyzer can easily land in that ballpark.

If the business value is there, companies will pay for it.

Not to mention the bill you would be paying anthropic could be way higher at that scale
How much would it cost to run a 2.8T model with long context for 1000 developers, plus 30,000 non-dev employees with short session memory?
> Lots of organizations are continuing to refuse to use chinese models

Correction: Lots of organizations are refusing to use Anthropic Fable because they have forced opt-in data collection as part of their privacy policy, even for Enterprise.

Both things, and both reasons, can be true at the same time.

Not everyone's going to care about Anthropic requiring data collection (a similar debate plays out with regards to "pay or consent" on website tracking), just as not everyone cares about China with regards to security/IP issues (if they did, a lot more would be banned besides occasionally-Huawei).

> Lots of organizations are continuing to refuse to use chinese models due to security and IP concerns

These customers exist (e.g. US military) but there's not enough of them to justify a trillion dollar valuation.

Anthropic's valuation is predicated on growth. If they start going backwards and losing customers to open models, it hurts their ability to gather investment and with it the ability to train new models, leading to a death spiral.

The best they can hope for is that the US gives them state aid to compete with China, however their relationship with the current administration is not great.

Nope, but I think this is maybe the critical mass needed to finally crash the AI hype/datacenter cost problem everyones is talking about.

With Oracle being junk before this, more will follow.

I would assume the opposite is true — with an open-weight Fable-class model, doesn't demand for GPUs go up? Plenty of companies can now look at what Anthropic is offering — high per token costs for a very intelligent model — and do the math, and at some point it makes sense to just rent the GPU yourself and run Kimi on it if you get similar intelligence without paying Anthropic's margins (albeit with high upfront capital cost).

This would drive down Anthropic's margins, but drive up demand for datacenter and GPU capacity. It's not that people would be using fewer GPUs, they'd just shift demand from high priced token vendors to direct GPU rental, which benefits datacenter companies while hurting Anthropic.

Its a margins game. If its too cheap to run, its not worth the investment.
The cost to run Kimi is the cost of the GPUs (+ overhead of hiring humans for now to manage it). Kimi K3 does not change the demand curve for LLMs, it only changes the possible suppliers — and they're all competing for the same supply-constrained resource, which is GPUs in datacenters. Regardless of who is serving the model, or how, they're going to need to rent or buy GPUs in datacenters. Hence: this is great for datacenters.
That makes no sense, Terry.
Oracle is fine, it's just that they can't really expect political decisions that hindered it to accquire TikTok which will be slated to be the biggest customer if the deal went through.

Now they are betting with Project Stargate but it also seems to be crumbling down.

But don't forget that they literally hold the biggest databases, both in commercial and open source, that is, Oracle Database and MySQL. Plus Oracle Java they literally controls at least 30% of the internet's software infrastructure.

And also with a good team of attorneies enforcing the licenses, they can squeeze so much money at the cost of morality.

Also recently they downgraded the always free OCI ARM instance from 4C24G to 2C12G without telling anyone.

New enterprise java licenses are going to milk enterprise just like broadcom is doing. New license deals makes you pay for employee total number (including contractors) instead of for users of oracle java.
Even boring, slow moving companies are well on their way to eradicate the last traces of oracle java. We kicked the last of that 2 years ago, despite having >3000 different systems across the globe. (We started circa 5 years ago).
> Oracle is fine

They're drowning in debt and risk is increasing. If these US models don't keep holding up their valuation will tank further and some will recall the loans or ask for different terms.

Models need datacenters to run. It also need other services to do anything useful
The point: Fable isn't worth what Anthropic says it is, so Anthropic isn't as valuable as they make themselves out to be.

The DeepSeek incident has already shown it, this is a reminder.

The inverse is also true: many companies are refusing to use American models due to security and IP concerns. And it's more concerning here: American companies straight up say they will train on your IP; local Chinese models structurally can't. The security concern goes this way too: for American companies, you're relying on their own security infrastructure and essentially blind trust. For locally hosted Chinese models, you 100% control the security story.

The reality this demonstrates: most US companies don't give even 2 shits about their IP, and are fine willingly handing it to Anthropic et al. Those that do care largely must care contractually. For group 2, they're either using Chinese today or aren't using AI at all. Those are the only two valid options, there is no secret "use US but self host it" third option.

Cursor will rebrand it as Composer 3.0 to assuage any such concerns, as they did with the previous Kimi models.
More likely for them to use Kimi 2.7 since Grok is now the flagship product.
Musk bought it. From now on, it will only be Grok.
If it ends up being open weights, companies will use it running in US data centers.
You can run open weight models anywhere.
This is apparently Open Weights, so no reason Amazon can't serve it alongside GLM which they already do.
> continuing to refuse to use chinese models due to security and IP concerns

One can run open weights in an exclusive TEE'd GPU too, which still comes out cheaper than closed weight LLMs. Ex: https://chutes.ai/pricing