U.S.-China AI Race Escalates, Chip Bans Aren’t Working, and a Lesson from Nuclear Proliferation
Sebastian Mallaby, who backed the US chip export controls in a 2022 Washington Post essay, now has doubts — and puts them to Chris McGuire, one of the policy’s insider architects at the Biden National Security Council. The debate runs along a timeline: the 2022 bet that compute would be the choke point in an AI race, how that bet reads in 2026 after DeepSeek, and whether a nuclear-style non-proliferation treaty could govern AI two or three years from now.
Key ideas
-
The 2022 bet was scaling laws plus a supply chain China lacks. The Biden team wagered that AI would grow exponentially with compute, making chips the strategic bottleneck. The cutting-edge supply chain — NVIDIA design, TSMC fabrication, ASML lithography, plus Applied Materials, KLA, Lam and Tokyo Electron for equipment — is controlled by the US and its allies. The regulatory lever is the ‘US-tech hook’ (the foreign direct product rule): any chip made with US technology is controllable, and US tech cannot be designed out of the advanced supply chain. First used against Huawei in 2020, the Biden team widened it from one firm to a whole country. The controls landed one month before ChatGPT — foresight, since scaling laws were believed inside the labs but not widely outside.
-
DeepSeek did not surprise the architects. A moderately advanced model is achievable on relatively few chips, and McGuire reckons DeepSeek’s true cost was nearer $500m than its headline figure — well within reach of a state-backed campaign. The controls were always a ‘boiling the frog’ play: as the exponential grows more punishing and frontier training gets hungrier for compute, the cost of being six months behind rises with it. Chinese firms — DeepSeek, Alibaba, the national leadership — all say the same thing: they are compute-constrained, and would scale massively without the controls.
-
The cloud loophole is bigger than the smuggling it dwarfs. Beyond chip smuggling, nothing in law stops a Chinese company training on US cloud: ‘DeepSeek could train DeepSeek v4 100% on Microsoft or Amazon or Google Cloud, and no one would be violating the law.’ Mallaby presses that this negates the enforcement regime. McGuire’s reply: better on our cloud, where a US provider obeys US law and the training could in principle be switched off, than in a Chinese data centre beyond reach. Late-Biden restrictions on this activity were pulled down by the Trump administration and not replaced.
-
The Trump administration’s swings are ‘incoherent’. It first tightened by blocking NVIDIA’s H20 workaround chip (April 2025), reversed in July 2025, then agreed to sell H200s to China in December 2025. Meanwhile every US company reports being compute-constrained — so acutely that memory diverted to AI chips is raising consumer prices for phones, TVs and computers. The AI action plan calls compute a strategic resource to deny adversaries even as the US sells them chips.
-
Huawei can stack chips but sits at ~4% of NVIDIA, and the gap is widening. In a data centre you can aggregate many chips (unlike in a phone), but Huawei’s most generous 2026 output is about 4% of NVIDIA’s AI compute. Its best chip is roughly 5x worse than NVIDIA’s today; on Huawei’s own internal roadmap that becomes 17x in two years. Higher failure rates cap how many 7nm chips China can make, and as frontier training runs demand ever more compute, China may lack enough by 2027–28 to train a frontier model in any reasonable time.
-
Distillation lets China fast-follow, so the lead won’t just go vertical. Rather than a clean intelligence explosion — AI writing code to improve AI until progress goes vertical and ‘game over’ — the real world imposes deployment friction, and China can reverse-engineer frontier models cheaply. A follower queries a strong US model to generate training data (no army of PhD physicists needed), and the benefit from distillation rises exponentially alongside the frontier. The counter is to tighten the rest of the regime, not to assume the lead compounds untouched.
-
The core disagreement: was making China the enemy the right call? Mallaby’s counterfactual: by choosing to deprive China of chips, the US foreclosed recruiting it into a non-proliferation alliance against the graver threat — open-weight models that let rogue actors build bioweapons or run cyberattacks, which cannot be switched off once downloaded (unlike Anthropic and OpenAI cutting off a hosted model mid-attack, as in a recent Mexican cyberattack). McGuire holds that jointly managing the technology with an adversary who reads arms control as a Cold War trap is ‘profoundly more risky’, and that the US would end up giving away its lead. Both note the NPT precedent — China did not accede until 1992, twenty-four years after ratification — and the civilian-nuclear bargain: supply AI to all who want it, but not in open-source-dangerous form.
Content
The choke-point logic
The policy rests on a chain of judgements made in 2021–22: scaling laws would hold, so more compute means better AI; the chips that provide that compute run through a supply chain — NVIDIA, TSMC, ASML and a handful of equipment makers — that China does not own and cannot quickly build. McGuire is candid that not everyone inside the administration was fully convinced the scaling laws would hold; he put himself among those who thought it a strong possibility rather than a certainty. What unified them was an asymmetric bet: in the world where AI chips matter enormously, the controls are obviously right; in the world where they matter less, little is lost. The regulatory mechanism is the US-tech hook — because US technology is an unremovable input to advanced chipmaking, Washington can control any chip made anywhere. The Trump administration had discovered the device against Huawei in 2020; the Biden team scaled it from a single entity to an entire country.
Enforceability and the cloud loophole
Four years on, the objections cluster into three. First, enforceability: smuggling persists, and only a handful of US officials police goods flowing into China. Second, and larger, the cloud — no law stops a disguised Chinese account training a frontier model on American compute. Mallaby treats this as close to a negation of the whole scheme; McGuire concedes the loophole but reframes the aim. The controls still swing a bigger share of global compute onto US soil, where the provider obeys US law and, in principle, a training run could be halted. There is a lag either way — chips already exported cannot be recalled, cloud access can at least be cut — so hosting the adversary’s training is, on his account, a form of leverage rather than pure leakage. The late-Biden restrictions that gestured at this were rescinded and left unreplaced.
The intelligence-explosion critique and distillation
Mallaby’s second-guess targets an assumption he now thinks too simple: that whoever first reaches recursive self-improvement wins outright as progress goes vertical. In practice, deploying AI into a law firm’s workflow or a defence system takes contracts, client consent and security sign-off — friction that blunts any vertical takeoff. McGuire says the Biden thinking never hinged on a literal intelligence explosion; the North Star was simply to hold as large a lead over China as possible. He grants the picture is more complicated, and points to distillation as the mechanism working against a compounding US lead: China uses advanced US models to generate training data cheaply, fast-following without the compute or the hired expertise the frontier lab needed. The lead may still widen as self-improvement kicks in, but China does not stay flat — all the more reason, he argues, to tighten every other part of the regime.
The non-proliferation question: open source and an AI-NPT
The sharpest disagreement is about the road not taken. Mallaby argues the US had to choose which national-security threat to prioritise — a strong China, or general proliferation to rogue states and terrorists — and that choosing to make China the adversary killed any chance of recruiting it against the second threat. His central worry is open weights: a downloaded model can have its safeguards stripped and cannot be switched off mid-attack. If the two AI superpowers agreed that dangerous open source is in no government’s interest, they could impose constraints on the rest of the world, which depends on US (and only potentially Chinese) compute — mirroring the civilian-nuclear bargain, where non-weapon states got reactors on condition they built no bomb. McGuire agrees open source is dangerous and that China, home to the best open-weight models, is the first-order problem — but resists the carrot. The Chinese government sees arms control as a tool the US used to win the Cold War; it combats the US in cyberspace and intelligence operations; and a deal that hands an adversary the key inputs, when that adversary may deploy faster and hold more data and energy, risks giving away the lead and trusting them to keep their end. The NPT can inform the design, he allows — but competition and a bargain need not be mutually exclusive, and the bargain does not require supplying China with the world’s most advanced technology.
Related
- Sebastian Mallaby — host
- Chris McGuire — guest; CFR senior fellow and the policy’s insider architect
- Compute Export Controls — the concept this episode centres on
- Scaling Laws — the empirical bet the 2022 policy rests on
- Sebastian Mallaby on OpenAI's Cash Crunch, the AI Bubble Debate, and the China AI Race — Mallaby develops the same China / non-proliferation frame
- The AI Bubble, the Productivity Paradox, and India's AI Summit — companion Spillover on AI governance