Author: Nita Farahany Source: https://nitafarahany.substack.com/p/chinas-ai-governance-inside-my-ai Published: November 30, 2025
The twenty-fifth class in Nita Farahany's AI law and policy course examines China's approach to AI governance and competition. Farahany frames the class around two announcements made the same week in July 2025 — the Trump administration's "Winning the AI Race" summit on July 23 and Premier Li Qiang's proposal for a Shanghai-based World AI Cooperation Organization on July 26 — which she presents as the same technology being approached with different visions. The organizing question she poses is whether China is attempting to catch up in the race the United States is running, or attempting to change which race matters.
China's three strategic countermoves
Farahany describes three moves through which she argues China responds to US technological and export-control advantages.
The first is to compensate, prioritizing quantity and efficiency over raw per-chip power. She cites Huawei's CloudMatrix 384 system, which networks 384 domestic Ascend 910C chips to reach roughly 300 petaflops — comparable to about 300 H100s — through architectural design rather than leading-edge chips. She also cites DeepSeek-R1, reportedly trained for roughly $5.6 million against the hundreds of millions she attributes to US frontier models.
The second is to control inputs, which she frames as rare-earth leverage. China processes roughly 90% of the world's rare earths and produces roughly 70%. Permanent magnets, about 94% of which are produced in China, are described as essential for data-center cooling, precision-guided weapons, and electric-vehicle motors. October 2025 Announcement No. 61 added rare-earth processing technologies to the Chinese export-control list with a foreign-direct-product rule, which Farahany characterizes as a mirror image of US chip controls.
The third is to redirect the race toward embodied AI rather than artificial general intelligence. While she describes American discourse as focused on AGI, she presents China as investing in robots, autonomous vehicles, and smart manufacturing. China's Ministry of Industry and Information Technology (MIIT) estimates that more than 60% of large Chinese manufacturers had "AI + Manufacturing" integration by the end of 2025, and the 14th Five-Year Plan sets targets for "comprehensive intelligent transformation" of 70% by 2027, 90% by 2030, and 100% by 2035. She notes that China installed more than 295,000 industrial robots in 2024, roughly half of all global installations, against 50,100 in the United States.
Domestic control alongside global openness
Farahany frames a paradox between China's domestic content controls and its global open-source releases. Domestically, she describes stringent content control: the 2023 Generative AI Interim Measures require outputs to "embody core socialist values," and every public-facing model must register with the Cyberspace Administration of China (CAC). Globally, she points to Alibaba's Qwen, from which she says more than 100,000 derivative models have been produced on Hugging Face, and to DeepSeek, which she states captured roughly 24% market share on OpenRouter in early 2025.
She offers four partial explanations for the combination: different rules for different contexts; an effort to undermine the US business model, since free and capable models remove the reason to pay for paid alternatives; ecosystem capture, in which a free model acts as a hook and infrastructure provides lock-in; and what she calls an "inverse Brussels Effect," in which standards spread through technological adoption and influence accrues through ubiquity.
The security question
Farahany separates the security concerns around Chinese models into what is known, what is embedded, and what is alleged. As known findings, she cites a NIST CAISI evaluation that found DeepSeek roughly 12 times more susceptible to agent hijacking than leading US models, and a CrowdStrike finding of an approximately 50% increase in security vulnerabilities when Chinese models were prompted on politically sensitive topics. As embedded behavior, she notes DeepSeek showing roughly 45% refusal rates for Falun Gong queries against near-zero rates for US models. As alleged but unconfirmed, she raises "sleeper agent" backdoors, characterizing the capability as proven while the intent remains debated.
China's regulatory architecture
Farahany describes the China AI Security Governance Framework 2.0, issued by TC260 in September 2025, which organizes risk by lifecycle stage rather than by EU-style application tiers. Its three categories are technical endogenous risks (bias, hallucination, lack of interpretability); technical application risks (supply-chain vulnerabilities, integration failures); and application-derived risks (labor displacement, social instability, cognitive degradation).
She presents the broader regime as a three-layer architecture. The foundational layer comprises the Cybersecurity Law (2017, amended 2025), the Data Security Law (2021), and the Personal Information Protection Law (PIPL, 2021). The second layer is targeted administrative regulations covering algorithmic recommendation, deep synthesis, and the generative AI interim measures. The third layer is technical standards such as Framework 2.0, which she describes as non-binding but influential. She characterizes the overall approach as "small-incision regulation" and "agile governance" — targeted rules for specific technologies with iterative learning, faster than the EU but producing more uncertainty for companies.
Three theories of victory
The class advances a framework Farahany uses to synthesize the EU, US, and China comparison, which she terms three theories of victory. The EU, which she argues probably cannot win the technology race, has a theory of victory of setting the floor everyone must meet, drawing on the Brussels Effect on standards. The US bets on continued technological leadership, with a theory of victory of being the frontier everyone depends on. China seeks to make itself unavoidable across multiple dimensions — rare earths, embodied AI, an open-source flood, and Global South infrastructure relationships — with a theory of victory of being unavoidable across dimensions.
Relationships
- part-of: Nita Farahany intro course series (Class 25a of 27)
- related: Chinese AI Policy, Embodied AI vs AGI (China's Race Redirect), Three Theories of Victory (US / EU / China AI Governance), DeepSeek, Huawei — Ascend AI Accelerators, US-China AI Competition: Different Races, Different Metrics
- previous: Inside My AI Law & Policy Class 23: When Silicon Valley's Effective Altruists Meet Washington's Export Controls (Farahany / Hamilton, November 2025) next: Inside My AI Law & Policy Class 25 (Special Edition): The Executive Order That Could Kill State AI Laws (Farahany, December 2025)