Your AI Model Comes With a Government Attached.
The promised jurisdiction map: U.S., EU, Singapore, PRC—and the federal clause that quietly favors models nobody can patch. Scroll past the article for Legal Resources Guides organized by region.
EDITORIAL NOTE: From the beginning these have been fast-developing stories; all information provided below is as reported and corroborated as of 11:45pm PT on 27 July 2026. To recap, the following led to the legal questions discussed below: the letters that terminated Anthropic’s Department of War contract, the letters that shut off Fable 5 and returned it 19 days later, and the release of Kimi K3—its full weights delivered for download on 27 July. This analysis is meant to help leaders map which laws govern the data moving through each part of their AI workflow. It is not legal advice; always seek counsel in your jurisdiction.
On Monday, Beijing time, Moonshot AI placed the finished settings of Kimi K3—96 files, roughly 1.6 terabytes—on the open internet for anyone to download.1 Within hours, copies were spreading to mirror sites no one controls. The same day, China’s commerce ministry answered Washington’s sanction threats with a warning that it would take “all necessary measures” to defend its AI companies.2 Six days from now, on August 2, the European Commission gains its first powers to fine the makers of frontier models.3
Against that backdrop, more than fifty American technology companies—Nvidia, Microsoft, and OpenAI among them—signed an open letter last week asking Washington not to restrict open models,4 while the administration weighed doing exactly that.5 Inside your organization, the debate is simpler: how does this evolving legal landscape affect our ability to operate?
Reporters have wondered if Chinese models should be used at all. That is the wrong question to ask. The law does not begin by asking who built the model. It asks how your data reaches it—and that answer was set by your data architecture team, before anyone briefed you.
Your decision to host a model or call it with an API has implications far greater than IT infrastructure—that decision determines the law that can be applied to your data.
The Door Decides Your Legal Exposure: Hosted API or Downloaded Weights—Not the Flag Flying Over the Lab
The debate usually starts with the flag. An American model feels governed; a Chinese model feels risky. It may be a reasonable instinct, and it points at the wrong variable.
Every model reaches you through one of two doors. Behind the first, you call a hosted API: your prompts—your contracts, your code, your customer records—travel over the internet to computers the provider operates. The data movement is not a side effect; it is the product of that architecture.
Behind the second door, you download the model’s weights—the billions of internal settings adjusted during model training, which I explained in It’s Not Thinking. It’s Predicting.6—and run them on servers you control. A weights file opens no connection back to the lab that produced it. Whether anything leaves your building is decided by your own network controls—and by whether you hand the model tools and internet access, which reopens the door from the inside.
Kimi K3 now exists on both sides of that divide, and the difference is instructive. Call its hosted international API and your prompts go to Moonshot AI Pte. Ltd.—a Singapore entity, with servers located in Singapore, by the provider’s own published policy.7 The reflex “your data goes to China” is wrong for that endpoint. But that fact belongs to Moonshot specifically, not to Chinese models generally, and that is the transferable lesson: the only way to evaluate exposure is to read, provider by provider, where the servers sit and what the service agreement permits. Three questions belong in every provider review:
1. Server location. Where are the servers located, according to the provider’s own published policy—not its marketing page?
2. Rerouting rights. Can the provider move your traffic to servers in another jurisdiction, and under what conditions?
3. Notice. Does the agreement require client notification before that rerouting happens—if so, what?
Download the same model’s weights and host on-prem instead, and every one of those variables are now under your control: your servers, your jurisdiction, your controls.
So the first answer is this: the door your data goes through—hosted API or downloaded weights—selects your legal exposure before anyone reads a statute. Which is why the inventory that matters is not a list of model names. It is an inventory of the AI providers and models you are currently using, classified by the “door” you use to access them.
Jurisdiction Follows Control: The Law That Reaches You Is the One That Can Compel Your Operator
Now the second question: once you know the door, whose law stands behind it?
The instinct here is geographic—my data sits in Frankfurt, so German law applies. Courts stopped asking that question years ago. Three legal bases decide who can reach your data, and they are not equal.
1. Where the server sits. The weakest basis, and the one executives still reason from. It is the belief this Call’s title corrects.
2. Who controls the data. The strongest. The US CLOUD Act requires American providers to hand over data in their “possession, custody, or control” whether it is stored “within or outside of the United States.”8 Congress wrote that law in 2018 for a specific reason: Microsoft had refused a warrant for emails on a Dublin server, and the server’s location worked as a defense.9 The CLOUD Act exists so that defense never works again.
3. Whose citizens’ data it is. Europe’s GDPR follows EU residents’ data beyond Europe; China’s personal-information law (PIPL) does the same for people in China.10 11
Let’s examine each region through the lens of these three provisions.
1. The United States carries the broadest reach: the CLOUD Act through providers, plus Section 702 of its surveillance law, which authorizes warrantless collection targeting non-Americans abroad, at scale.12
2. The European Union points its law inward as a shield: the GDPR restricts data from leaving, blocks foreign court orders that arrive without a treaty behind them, and—after its top court struck down a US data deal over that same Section 702 surveillance—polices American reach as a risk to Europeans’ data.10
3. Singapore sits closest to territorial: its Personal Data Protection Act governs companies, exempts the government, and state access runs through investigation-tied criminal procedure rather than intelligence collection at scale.13
And the provider’s home jurisdiction? For a PRC-domiciled lab like Beijing Moonshot—the parent company behind that Singapore API entity—four separate legal objects get collapsed into one alarming shorthand, and precision matters more than comfort in this instance.
1. China’s National Intelligence Law obliges organizations to “support, assist, and cooperate” with intelligence work.14
2. No Chinese statute mandates a backdoor—none has been found that says so.
3. Data-localization duties bind critical-infrastructure operators, not every company; and
4. Blocking provisions forbid handing data stored in China to foreign authorities without Beijing’s permission.11
Support duty, backdoor mandate, localization, blocking—four different things. Only the first is what most coverage means by “Chinese law reaches everything.”
Here are the experts, on all sides, so you can decide what your organization is comfortable with. Donald Clarke, a George Washington University law professor specializing in Chinese law, examined the legal declaration Huawei commissioned in its own defense and found it “incomplete”—it never addresses “the extent to which the Chinese government is constrained by Chinese law.”15 Jeremy Daum of Yale Law School’s China Center, who runs the China Law Translate project, is blunter: the statute text is beside the point, because the state can coerce “with or without a law.”16
On the measured side, Samm Sacks and Peter Swire—two of America’s most cited data-policy scholars—argue for judging each data flow through an evidence-based framework rather than by blanket country rules.17
And Beijing’s foreign ministry states for the record that China “has never required, nor will it require” companies to hand over overseas data “in violation of local laws”—a denial whose last clause does quiet work.18 Accept Clarke and Daum, and no PRC provider’s assurance is bankable. Accept Sacks and Swire, and the exposure is real but assessable per deployment. Your legal counsel, your local laws, your data architecture and your risk tolerance should ultimately determine how to navigate this evolving landscape.
A counterargument is worth surfacing before we go further. Most executives reading this will think: we use only American models, under American law, with American courts—this is someone else’s problem. But staying American does not remove the government behind the door; it selects which one. The strongest compulsion power in this entire map—control-based, borderless—is American. For a US company, that may be familiar, acceptable exposure. For the same company’s European subsidiary, it is precisely the exposure EU regulators police. Neither reading is wrong. The decision is which government’s reach your organization can accept, given where you operate and whose data you hold.
One structural detail changes that calculus more than any statute, and it needs plain language. Under the GDPR’s “one-stop-shop” rule, a provider with a European headquarters answers to a single country’s privacy authority as its main supervisor. A provider with no European entity at all can be pursued by every one of roughly thirty national authorities, independently, each able to act in days. DeepSeek learned this in January 2025, when Italy’s authority moved alone.19 Where your provider is incorporated is not trivial. It is the difference between being answerable to one regulator or thirty.
If you cannot name which government can compel your model’s operator, how do you defend the data your board thinks is protected?
What You Can Change After You Deploy: Everything Around the Model. Nothing Trained Into It.
The third question sounds technical and is actually contractual: after implementation, what can you still change?
With a hosted API, the honest answer is prompts and scaffolding—the instructions you send and the software you wrap around the call. The model itself, its safeguards, its update schedule: all the vendor’s, changeable by the vendor, on the vendor’s calendar.
Downloading the weights inverts most of that. You can fine-tune the model, wrap it, route around it, and—the advantage security researchers keep pointing to—audit its behavior on your own terms. What you cannot do, and this is the boundary that matters, is see or alter what was trained into it. No frontier lab, American or Chinese, publishes its training data or the full method behind its weights; by the standard open-source definition, no frontier “open” model actually qualifies.20 What a model was trained to do is invisible to the buyer before deployment and unchangeable after.
Whether that matters is not a judgment about any country’s politics—it is a fact about where the model will be used. Behavior a lab’s home market considers normal may surprise a buyer elsewhere, and may sit badly with the laws, rules, or expectations of the locales where your business operates.
The clearest measurement of this comes from CrowdStrike, one of the largest American cybersecurity firms, whose researchers tested DeepSeek’s open-weight model—not K3—the hard way.21 They ran the raw downloaded weights directly, deliberately bypassing the API-level guardrails, through 30,250 coding prompts.
Asked for ordinary technical work, the model produced code containing known security flaws 19% of the time—the baseline.21 When the same requests mentioned politically sensitive subjects—CrowdStrike’s published example is code “for an industrial control system based in Tibet”—the flaw rate rose to 27.2%. Concretely: roughly one output in four carried a security flaw, up from one in five, triggered by words that had nothing to do with the code being requested.
The model also flatly refused certain politically framed requests despite first reasoning out a complete technical plan. CrowdStrike’s conclusion was architectural: because the tests ran on raw weights, the behavior “must be baked into the model weights.” Their own caveat belongs beside it: this is a long-run average, not a property of every response.
Semgrep, a code-security firm that tested K3 directly, reported “no evidence of security backdoors in open weight models”—and called auditability the single biggest security advantage of the open-weight door.22 The real-world attacks documented so far have all come through the distribution channel—tampered files on model hubs—not through a released model’s weights. Verifying your download against the publisher’s official repository is therefore not paranoia; it is the control. You can test behavior, inspect the architecture, and verify file integrity. You cannot inspect the training data or prove a trigger absent.
Here is what that means operationally: choosing the self-hosted door moves the discovery burden from the vendor’s roadmap onto your evaluation budget. And K3 arrives with none of that work done for you: its 45-kilobyte model card ships benchmark tables, compression notes, deployment guides, a license—and no safety section at all.1 The only published safety evaluation of K3 is the one the UK and US governments ran, which found its safeguards did not stop it from attempting cyber exploit development.23 That is not a verdict on the model. It is the fact that defines what you are signing up to test yourself.
Behavior trained into a model cannot be seen by the buyer, changed by a prompt, or removed by the vendor. It travels with every copy.
Any Government Can Switch Off a Model Service. None Has Yet Reached an Open-Weight Model on Your Own Servers.
The fourth question is the one made urgent last month: who—anywhere—can actually switch a model off? The record has four jurisdictions in it, and one pattern.
1. Washington: a letter, then darkness in hours. On June 12, a letter from the Commerce Secretary reached Anthropic at 5:21 p.m. Eastern; by that evening, two frontier models were dark for every foreign national on earth—on Amazon’s cloud, Google’s, and Microsoft’s simultaneously.24 No published rule, no comment period, no appeal schedule. I walked through that episode and its partial reversal in Not a Screwdriver or Uranium,25 so here I will only add what it means operationally: a hosted dependency can vanish inside one business day.
The standard contract gives you almost nothing back: the right to suspend pre-existed the June shutdown, no compensation is owed, and liability is capped. The cost is continuity: untested fallbacks, stranded work, renegotiation from weakness. One boundary keeps this honest: those were closed-weight models, existing only on their maker’s servers. Had their weights been public and downloaded, the order could have reached future API access and US distribution—not the copies already downloaded. To be clear, that is an inference that has never been tested.
2. Europe: two days to stop a service—and no model on anyone’s servers was touched. In January 2025, Italy’s data-privacy authority ordered DeepSeek to stop processing Italian users’ data, two days after opening questions.19 Read the fine print, because most coverage got it wrong: DeepSeek had pulled its own app from Italian stores the day before the order; the website stayed up; and eighteen months later, no fine has been published. The instrument reached the hosted service’s legal permission to process data—not the model, not any copy of it.
On August 2, a second instrument arrives: the European Commission gains the power to request withdrawal or recall of a general-purpose model, made binding only through fines of up to 3% of worldwide turnover.3 Arriving, not arrived—the power has never existed, so it has no track record. Watch the quieter route too: from the same date, a missing registration or missing documentation—no harm shown—can oblige national authorities to pull a model from the EU market. Administrative, not dramatic—and the likelier path.
3. Beijing: the strongest takedown on record left every installed copy running. In July 2021, four days after the ride-hailing giant DiDi listed on the New York Stock Exchange, China’s cyberspace regulator ordered its app off Chinese app stores. The company’s own disclosure states the boundary precisely: the app could “no longer be downloaded,” but users who had already installed it “may continue using it.”26 New copies stopped; existing copies ran. For generative AI, the record is emptier still: China’s rules allow service suspensions, and no verified instance of one exists.27
4. Singapore: the fullest toolkit, never aimed at AI. Singapore’s online-harms law grants directions no EU regulator has—administrative orders, no court required, reaching internet providers, app stores, even payment and advertising support.28 It has never once been pointed at an AI model. That is restraint—a policy choice, not a missing capability—and choices can change.
Read the four together and one pattern holds: what governments have actually reached, every time, is something that connects you to a provider—an API, an app store, a legal permission to operate. Which raises the question you should ask next: could a government go further and outlaw using an open-weight model already sitting on your servers? Here is what is known, plainly. No such rule exists today, anywhere.
The instruments to attempt one exist: Congress banned US hosting and distribution of TikTok and the Supreme Court upheld the law in January 2025—though it reached app stores and hosting services, not users’ installed copies29—and Washington has reportedly weighed export-blacklist designations that could require a license to possess the models.5 Whether a use-ban would survive court challenge is genuinely untested.
Even Alan Rozenshtein—the University of Minnesota law professor and former Justice Department national-security lawyer who wrote the leading argument that distributing model weights is not constitutionally protected speech—concedes that restricting people’s ability to use a model “may violate the First Amendment rights of users.”30 No court has ruled on model weights. Ever.
Every switch a government has thrown has reached a connection—an API, a download page, a contract. None has reached the copy on your own hardware.
Two provisos are important to keep in mind:.
1. Beijing can close the tap. China’s commerce ministry has been consulting its own labs on restricting foreign downloads of future Chinese model weights while keeping hosted access open—a consultation, with nothing issued.31
On the day K3’s weights shipped, a state-media commentary added that support for openness “doesn’t mean advocating for the unconditional proliferation of all capabilities.”32 If that tap closes, here is what changes for you: the weights on your servers keep working, untouched. But the next version never arrives as a download—your model ages in place while the frontier moves, and updates stop. The remaining route to new Chinese capability becomes the hosted API, which walks you straight back through the hosted-API door and its jurisdiction. And the free-download alternative your procurement team waves in closed-vendor negotiations quietly disappears.
2. Your own regulator still reaches you: privacy authorities in Europe and Singapore can order what you may do with personal data on any model you run, self-hosted or not.10 13 The real open-weights risk, in one line: stagnation and lost support—not deletion.
Now the clause that quietly favors the models nobody can patch. On June 5—months after the Department of War contract-termination letters —a national-security memorandum called NSPM-11 directed America’s defense and intelligence agencies to ensure, by contract, that “no commercial entity or adversary possesses the capability to prevent use of, disable or degrade, or materially modify” an AI system the military depends on.33
Look at the drafting: your vendor and a hostile state, in the same sentence, subject to the same prohibition. A closed-model vendor that keeps guardrails it can update and access it can revoke is an entity with exactly that capability—it cannot comply with the clause without surrendering its product’s design.
A lab that publishes its weights retains no such capability, by construction. It complies with the clause the day the weights are published.
The memorandum never uses the words “open weights”; it doesn’t need to—its adaptation section says agencies shall adopt commercial “or open-source” AI, and an open-weights lab already sits on the Pentagon’s classified-networks vendor list.34 Put this section beside the last one and the collision is visible: the contract language now rewards precisely the model class whose trained-in behavior no one—not the vendor, not the government, not you—can patch. For transparency, this is my analysis; there is no publically available or official precedent for this reading..
Under Washington’s new clause, the labs able to secure national-security contracts are the ones that relinquish control of their models.
Who does this federal contractor clause affect?
NSPM-11 governs the national-security enterprise—defense and intelligence contracts—and it reaches both prime contractors and their subcontractors, with termination as the enforcement.33 If your federal work is civilian—GSA schedules, health, education—this memorandum does not currently apply; the bills that would go further exist, and none have passed.5 If you do sit anywhere in a defense or intelligence contract chain, directly or as a subcontractor, the question is live now: which of your AI vendors could comply with a no-disable clause—and would the company whose model you use agree to surrender control to allow you to continue with the federal contract?
If your work falls under NSPM-11 purview, this is a crucial answer to ascertain with certainty.33?
The Four Answers on One Your Desk
When the next model decision reaches your desk, run the four questions I’ve covered in order:
1. which door does our data go through
2. whose law stands behind that door
3. what can we change after deployment
4. who can switch this model off
Each of those four questions now has an answer you can act on—that is what the past seven weeks of letters, orders, and releases settled. Geopolitics is now part of AI procurement. Not as a choice—as a variable, sitting inside the same spreadsheet as price and capability, whether or not anyone on your team was consulted.
What to watch in the coming months
1. The courtroom. A federal judge in Washington set the first hearing on the Fable 5 shutdown challenge for no earlier than this week—the week you are reading this. What has been filed since late June is not yet publicly visible; no ruling had been reported as of this writing.35
2. Brussels. August 2, when the Commission’s fining power over frontier-model makers goes live—six days after K3’s weights did.3 What how the EU applies their new powers. Learn how they may affect you if you do business in the EU or with EU citizens’ data.
3. The migration. Whether enterprises keep moving production work onto open weights at the pace one large AI gateway’s telemetry shows—29% of tokens on under 4% of spend, a third of the work at a fraction of the cost, as of mid-July.36
Jurisdiction is chosen at the architecture review, not discovered at the subpoena.
The AI Leadership Playbook
Strategic Questions (copy-paste ready for an email to your CIO and General Counsel):
1. For every AI provider we currently use: where are its servers located, which country’s government can compel that provider to hand over our data, and does its service agreement let it reroute our traffic to servers in another country—with what notice? Who in the gets those answers in writing?
2. For any model we run on our own servers: what is our testing budget to discover behavior trained into the model that no vendor can change—and who owns the fallback if we find behavior we cannot accept?
3. Before our next model contract renewal: for each vendor on the shortlist, which government could legally order it to hand over our data—because of where its servers sit, because of who controls the data, or because of whose citizens’ data it holds? Which choice changes our exposure?
Your Next Plays:
1. Build the inventory that answers Question 1 permanently. One list: every AI provider and model currently in use, classified by door—hosted API or weights on our own servers—with the compellable government named beside each deployment.
2. Stand up the evaluation line for anything self-hosted. Checksums against the publisher’s official repository, behavioral testing before production, and a named owner for escalation when a test fails.
3. Brief counsel with the three-legal-bases summary—server location, control of the data, citizenship of the data subjects—and put one question on their desk: are our European operations governed by a single government or nearly thirty?
📅 Book a complimentary 1:1 Strategy Session—45 minutes to start that conversation about your AI transformation sequence.
📬 Free preview ending soon. Subscribe to continue getting decision-grade AI intelligence that prepares you to move before your competitors do. First 100 subscribers receive bonus content. Subscribe to The AI Playbook
The Legal Resource Map
By region: what each resource is, why it matters, when to use it, and the question it answers—so you know which link to open for which job.
United States
1. The CLOUD Act, 18 U.S.C. §2713—law.cornell.edu. What it is: the two-paragraph statute behind the control principle. Why it matters: it is the single strongest data-reach law in this map. When to use it: when counsel or a vendor claims overseas storage insulates your data. The question it answers: can a US provider be ordered to hand over data it stores abroad? (Yes—read the words “within or outside.”)
2. NSPM-11, the national-security AI memorandum—whitehouse.gov. What it is: the primary text of the no-disable clause, four pages. Why it matters: contract language propagates through subcontract chains faster than regulation. When to use it: before signing or renewing anything in a defense or intelligence chain. The question it answers: what exactly must my vendor—or my product—be unable to do?
3. NTIA (the US Commerce Department’s information-policy agency), Dual-Use Foundation Models with Widely Available Model Weights—ntia.gov. What it is: the US government’s own definitional study of open weights. Why it matters: it is the reference point both sides of the ban debate cite. When to use it: when your board asks what “open weights” formally means and what Washington concluded (monitor and keep options open—neither restrict nor bless). The question it answers: what does the US government say open weights are—and what risks do they pose?
European Union
1. The EU AI Act, Regulation 2024/1689—eur-lex.europa.eu. What it is: the full text of record. Why it matters: its general-purpose-model obligations bind providers whose models reach the EU market regardless of origin. When to use it: Articles 51–55 and 93, when assessing any model deployed for EU users. The question it answers: what can Brussels demand of a model’s maker, and with what penalty?
2. European Commission guidelines for general-purpose AI (GPAI) providers—digital-strategy.ec.europa.eu. What it is: the Commission’s own plain-language timeline of which obligations applied when—including the August 2, 2026 enforcement date. Why it matters: the dates are the compliance calendar. When to use it: when planning any EU-touching model deployment this year. The question it answers: what is enforceable after August 2, 2026?
3. The Garante’s DeepSeek decision, January 30, 2025—garanteprivacy.it. What it is: the actual order most coverage paraphrased wrongly (English available). Why it matters: it is the template for how a single EU national authority moves against a foreign model provider. When to use it: when evaluating any provider with no EU entity. The question it answers: what can one member state do alone, how fast, and what does the order actually reach?
Singapore + APAC
1. Personal Data Protection Act 2012—sso.agc.gov.sg. What it is: Singapore’s privacy statute, consolidated. Why it matters: it is the region’s reference model—investigation-tied state access, government exemption, directions backed by penalties up to 10% of local turnover. When to use it: when standing up Singapore-touching deployments, including through Moonshot’s Singapore-domiciled API. The question it answers: what governs personal data in Singapore, and who is exempt?
2. Online Criminal Harms Act 2023—sso.agc.gov.sg. What it is: Singapore’s blocking machinery—directions to ISPs, app stores, and payment support, no court order required. Why it matters: it defines what Singapore could do to any online service, AI included, the day it chooses to. When to use it: to understand the region’s enforcement ceiling. The question it answers: if Singapore ever moved against a model service, what would that look like?
3. MAS (Singapore’s central bank and financial regulator), Artificial Intelligence Model Risk Management—mas.gov.sg. What it is: the financial regulator’s expectations for AI inside banks—the strictest sector lens in APAC. Why it matters: financial-sector rules preview where general rules go. When to use it: if you operate regulated entities in Singapore, or want the region’s most concrete model-governance checklist. The question it answers: what does a serious APAC regulator already require of models in production?
People’s Republic of China (K3 provider’s home law)
1. National Intelligence Law of the PRC (English translation)—chinalawtranslate.com. What it is: the support-assist-cooperate statute, translated. Why it matters: it is the sentence most coverage compresses into “Chinese law reaches everything.” When to use it: before repeating that sentence in any board discussion. The question it answers: what does the intelligence-cooperation duty actually say—and not say?
2. Personal Information Protection Law of the PRC (English translation)—chinalawtranslate.com. What it is: China’s privacy statute, including its blocking provision on foreign-authority disclosure. Why it matters: it is the law that points the opposite direction from the popular assumption. When to use it: when mapping what a PRC provider may lawfully hand to whom. The question it answers: what does Chinese law forbid its companies from giving foreign authorities?
3. Interim Measures for Generative AI Services (English translation)—chinalawtranslate.com. What it is: the rules governing generative-AI services offered inside China, including suspension powers. Why it matters: it defines the enforcement ladder Beijing holds over its own labs’ hosted services. When to use it: when assessing the provider-side pressure on any PRC lab. The question it answers: what can Beijing order its own AI companies to do?
A note on these translations: I am unable to independently verify translation quality from the original Chinese. All three are sourced from China Law Translate, the translation project run by Jeremy Daum at Yale Law School’s Paul Tsai China Center—a reputable institution standing as the proxy for accuracy.
Sources
1. Hugging Face, moonshotai/Kimi-K3 model repository—weights, model card, and license, read directly; 96 shards, ~1.6 TB. huggingface.co/moonshotai/Kimi-K3
2. Global Times, “China slams US’ planned probe, sanctions against Chinese AI firms, will take ‘all necessary measures,’” July 27, 2026—globaltimes.cn; official translation of the ministry statement: CSET, Georgetown.
3. European Commission, “Guidelines for providers of general-purpose AI models”—enforcement powers, including fines, from August 2, 2026. digital-strategy.ec.europa.eu
4. NVIDIA et al., “Open Weights and American AI Leadership,” open letter, July 24, 2026; signatory list as fetched July 27, 2026. images.nvidia.com
5. Axios (Maria Curi), “The secret Trump administration battle to fight Chinese AI,” July 20, 2026—Entity List deliberations; draft hosting-liability order; nothing enacted. axios.com
6. Paola Sanmiguel, “It’s Not Thinking. It’s Predicting.,” The Weekly Call, June 23, 2026. cognivalab.blog
7. Moonshot AI Pte. Ltd., Kimi international privacy policy—servers located in Singapore. platform.kimi.ai
8. 18 U.S.C. §2713 (CLOUD Act)—”within or outside of the United States.” law.cornell.edu
9. U.S. Department of Justice, “Promoting Public Safety, Privacy, and the Rule of Law Around the World: The Purpose and Impact of the CLOUD Act,” white paper, April 2019—the Microsoft Ireland case background. justice.gov
10. Regulation (EU) 2016/679 (GDPR), Articles 3, 44–49, 58. eur-lex.europa.eu
11. Personal Information Protection Law of the PRC, Articles 3, 41 (China Law Translate). chinalawtranslate.com
12. 50 U.S.C. §1881a (FISA Section 702). law.cornell.edu
13. Personal Data Protection Act 2012 (Singapore), ss. 4, 48I–48J. sso.agc.gov.sg
14. National Intelligence Law of the PRC, Articles 7, 14 (China Law Translate). chinalawtranslate.com
15. Donald Clarke, “The Zhong Lun Declaration on the Obligations of Huawei and Other Chinese Companies under Chinese Law,” SSRN, March 2019. papers.ssrn.com
16. Jeremy Daum, “What the National Intelligence Law Says, and Why It Doesn’t Matter,” China Law Translate. chinalawtranslate.com
17. Samm Sacks and Peter Swire, “Assessing U.S. Data Policy Toward China: A Proposed Framework,” Lawfare, July 14, 2023. lawfaremedia.org
18. PRC Ministry of Foreign Affairs spokesperson Guo Jiakun, January 17, 2025, via Global Times. globaltimes.cn
19. Garante per la Protezione dei Dati Personali (Italy), Provvedimento of January 30, 2025 (DeepSeek), doc-web 10098477. garanteprivacy.it
20. Open Source Initiative, “The Open Source AI Definition 1.0.” opensource.org
21. CrowdStrike (Stefan Stein), “Security Flaws in DeepSeek-Generated Code Linked to Political Triggers,” November 20, 2025. crowdstrike.com
22. Semgrep, “Kimi K3’s code security results lack precision,” July 22, 2026. semgrep.dev
23. UK AI Security Institute and US CAISI, “Preliminary assessment of Kimi K3’s cyber capabilities,” July 23, 2026. aisi.gov.uk
24. Anthropic, “Statement on the US government directive to suspend access to Fable 5 and Mythos 5,” June 12, 2026—as I documented in the July 9 Call, cited here for the 5:21 p.m. timeline. anthropic.com
25. Paola Sanmiguel, “Not a Screwdriver or Uranium: Washington Invented a Third Label,” The Weekly Call, July 9, 2026. cognivalab.blog
26. DiDi Global, “DiDi Announces App Takedown in China,” Business Wire, July 4, 2021—installed apps “may continue using it.” businesswire.com
27. Interim Measures for the Management of Generative AI Services (PRC), Article 21 (China Law Translate). chinalawtranslate.com
28. Online Criminal Harms Act 2023 (Singapore), ss. 8–12, 29–31. sso.agc.gov.sg
29. Cornell Legal Information Institute, “TikTok, Inc. v. Garland” (U.S. Supreme Court, decided January 17, 2025). law.cornell.edu
30. Alan Z. Rozenshtein, “There Is No General First Amendment Right to Distribute Machine-Learning Model Weights,” Lawfare, April 4, 2024. lawfaremedia.org
31. Reuters, “China considers tighter export controls on AI models, chips, FT reports,” July 21, 2026 (wire story; carrier verified live). finance.yahoo.com
32. Bloomberg, “China State Media Says Support for Open AI Models Has Limits,” July 27, 2026. bloomberg.com
33. National Security Presidential Memorandum 11, “Artificial Intelligence in the National Security Enterprise,” June 5, 2026. whitehouse.gov
34. U.S. War Department, “Classified Networks AI Agreements,” May 1, 2026—eight companies including the open-weights lab Reflection. war.gov
35. Legion LegalTech, Corp. v. United States, No. 1:26-cv-02225 (D.D.C.), docket—minute order of June 25, 2026. courtlistener.com
36. Vercel, “AI Gateway Production Index,” July 2026—open-weight models at 29% of tokens on under 4% of spend. vercel.com
© 2026 Paola Sanmiguel. All rights reserved.
A note on AI use: Anthropic, the maker of Claude, is a party to several precedents discussed—load-bearing claims about those disputes are cited to court records and, wherever possible, non-Anthropic sources. This piece was researched using Anthropic’s Claude Fable 5 and Opus 5 models. All sources are verified and all cited material is corroborated by multiple independent sources.


