top of page
Abstract Shapes

INSIDE

PUBLICATIONS

Sovereign AI Race: China (2026)

2 days ago
32 min read

Updated: 5 hours ago

Sovereign AI Race: China (2026)


In this Report



Sovereign AI Race: The Complete Series (2026), the series hub.


This publication is part of the Sovereign AI Race series.


The Co-Intelligence-First (CI-First) approach is a genuine and unique University 365 concept: a proposal for imagining a better future where AI and Human Intelligence coexist productively, each amplifying the other rather than replacing it.


Back to the TOC
Section icon: The Context.

Sovereign AI Race: China (2026)

The Context


The five layers, and why China is the only full-stack case


The five layers of sovereign AI, assessed for China in September 2026.


The five layers assessed. China is the only country in the series attempting to hold all five at once. University 365 Research Center.


This is the third report in a twenty-part series assessing how states attempt to control the production of artificial intelligence inside their own jurisdiction. The framework is fixed and applied identically to every country. Sovereign AI capacity separates into five layers, and a state can hold any one of them without holding the others.


Compute sovereignty is the physical layer: where the chips and data centres sit, and who may switch them off. Model sovereignty is who builds the models a country depends on, and in whose languages and domains those models are competent. Capital sovereignty is who funds the build-out and on what terms. Regulatory sovereignty is who writes the rules and whether they can be enforced. Talent and education sovereignty is who builds and runs the systems, and how the next generation is prepared.


Every country examined so far in this series holds some layers and rents others. The United Arab Emirates holds models, capital, regulation and talent, and rents compute on a licence that expires. Saudi Arabia owns capital absolutely, buys compute, and derived its flagship model from a Chinese open base. China is different in kind, not degree. It is the only state attempting to hold all five simultaneously, including the layer everyone else treats as unavailable, which is the ability to manufacture the accelerators.


The vocabulary this report needs


Four terms recur, and they are defined here once.


Open weights means the trained parameters are published and downloadable. Open source is a stronger claim: it requires the training data, the training code and enough of the pipeline that the result can be reproduced. Most Chinese frontier releases are open-weight, not open-source. Their training data and full training pipelines are generally not disclosed. This distinction runs through the report, because the difference between the two is the difference between sharing a product and transferring a capability.


Export control classification numbers, or ECCNs, are the identifiers the United States uses to control specific technologies. The relevant ones for this report are 3A090 and 4A090, which cover advanced computing chips and the machines containing them. Whether a country may import them, and on what conditions, is decided by the Bureau of Industry and Security at the Department of Commerce.


EFLOPS is a measure of computing power, one quintillion floating-point operations per second. It appears in this report because China publishes its national compute total in EFLOPS, and because these figures are frequently reported without saying which precision they were measured at, which makes cross-country comparison unreliable. Where a figure is quoted, its source and its caveats are given.


The domestic stack means the set of components a country can source without foreign permission: its own accelerators, its own fabrication, its own models, its own software toolchain. Only two countries have a credible claim to one, and only one of them built it under sanctions.


Back to the TOC
Section icon: The Question.

Sovereign AI Race: China (2026)

The Question


Did the sanctions stop China, or force it to build what it could not buy?


The United States has spent four years denying China access to the accelerators that train frontier models. The controls began in October 2022, tightened through 2023, expanded again in December 2024, and at their most restrictive put an American licence requirement between a Chinese laboratory and every advanced chip it wanted to buy. The stated purpose was to preserve American leadership and slow Chinese capability.


The result is now measurable, and it is the opposite of the intent in one specific and consequential respect. China has become the only country other than the United States with a complete domestic AI stack: accelerators, models, cloud, toolchain, and a national compute grid connecting them. Its open-weight models have taken more than half of global open-source model downloads. Its chipmakers went from loss-making curiosities to profitable public companies whose shares moved the Shanghai market. And its research output leads the world in publications, citations and patents.


At the same time, the sanctions worked exactly as intended at the layer they targeted. China cannot manufacture a leading-edge logic chip at commercial cost. Its most advanced available accelerator trails the Western frontier by a widening margin, its fabrication yields are poor, and the binding constraint has moved from the machine to the memory that feeds it. The country that invented printing and gunpowder is now, at the frontier, dependent on stockpiles.


So the question is not whether the sanctions worked. It is what they produced. A country denied the ability to buy a technology it needed built an alternative, and then gave that alternative away. Whether that was a gift to the developing world or an instrument of influence is the central question of this report, and the honest answer contains both.


Back to the TOC
Section icon: The Contradiction.

Sovereign AI Race: China (2026)

The Contradiction


The sanctions forced a parallel stack into existence, and then China gave it away for free


The Great Wall of China winding over mountains north of Beijing.


The Great Wall, north of Beijing. A wall that shaped a civilisation's defences for centuries is the fitting image for a report about an export-control barrier. Photograph: Van Anh Nguyen via Pexels.


Illustration: document icons route under an impassable wall and spread across a grid.


The control blocked the hardware and the models routed around it. University 365 Research Center.


Here is the paradox, stated as plainly as the evidence allows.


The purpose of an export control is to deny an adversary a capability. The American controls on advanced semiconductors denied China access to the best accelerators, and they worked. What they did not do is deny China the ability to train competitive models, because the mathematics of modern AI had already changed: model quality is no longer determined mostly by how much compute you own. It is determined by the quality of your post-training, your data and your architecture. A laboratory with a fraction of the compute can produce a model that is competitive on most tasks users actually perform, and that laboratory can then publish the weights.


China did exactly that, at scale, and then made the publishing a matter of state policy. Alibaba's Qwen family passed one billion cumulative downloads from a public model hub in January 2026 and by March 2026 accounted for more than half of global open-source model downloads. DeepSeek released a 1.6-trillion-parameter model under the MIT licence, which is as permissive as open weights get. Moonshot, MiniMax and Zhipu built their own families on the same model. And the distribution results followed: Chinese-origin models have held at least 30 per cent of the tokens routed by United States firms through a major routing platform every week since February 2026, peaking at 46 per cent, up from roughly 5 per cent a year earlier. On that platform, in June 2026, Chinese models passed American models in total token share.


Now read that against the control regime. A country that could not buy a leading accelerator built models good enough to take the majority of the world's open-model demand, and then distributed those models as freely downloadable files to any developer in any country, including countries the United States would not license the hardware to. The American response was to do the thing that confirms the diagnosis: in January 2026 it moved the H200 and equivalent chips to case-by-case review, that is, it decided to sell China the compute it had previously denied, on the conditions that the supply existed and that a share of the value returned to the United States.


That is the contradiction at the centre of this report. The control denied the hardware and produced the software. The software then escaped the control entirely, because model weights, once published, are not goods that cross a border; they are information that can be copied. The United States can license a chip shipment. It cannot license a download.


And the cost of the Chinese route is real, which is what keeps this from being a simple story of sanctions backfiring. China built its stack by taking the long way: poor fabrication yields, an accelerator several generations behind, a memory stockpile that will run out, and a domestic market for its own chips that is large but not unlimited. It has achieved full-stack sovereignty in the same sense that a country can achieve food sovereignty by farming marginal land: the dependency is gone, and the price is paid in efficiency.


The next two sections set out what was actually built, layer by layer, separating what China owns from what it is still buying.


Back to the TOC
Section icon: The Current State.

Sovereign AI Race: China (2026)

The Current State


Compute: the stack is real, and the frontier is not


The Lujiazui financial district skyline, Shanghai.


Shanghai, host of the World Artificial Intelligence Conference and home to a growing share of the national compute grid. Photograph: Yu Wang via Pexels.


What China built, and what it costs, side by side.


What China built and what it costs. The cost side is measured, not projected. University 365 Research Center.


China's national compute position is the most frequently misreported figure in this series, and it is worth handling carefully.


The Ministry of Industry and Information Technology put national intelligent computing capacity at 2,185 EFLOPS as of the end of June 2026, up 177 per cent year on year, with more than 1,590 EFLOPS and 42 clusters of ten thousand cards each reported in January 2026. Independent measurement firms counting on a different basis recorded 725 EFLOPS for 2024 and 417 EFLOPS for 2023. The two sets of numbers are not comparable, and any comparison between China and another country on this measure should state which basis it is using. What is not in dispute is direction and scale: China has built more computing capacity than any country except the United States, and it did so with a growing share of domestic accelerators.


In July 2026 China switched on its first fully domestic hundred-thousand-accelerator supercluster, built by Sugon at the Zhengzhou node of the national compute grid, running workloads across twenty-six scientific fields. The caveat, reported at the time and worth repeating, is that its workload leans toward double-precision scientific computing rather than model training. That distinction matters: a supercomputer optimised for simulation is not the same asset as a training cluster, and the announcement did not claim otherwise.


The accelerator layer is where the cost of the strategy is visible. Huawei's Ascend 910B is the workhorse and the improved 910C is the current shipping part, using a domestic seven-nanometre-class process with multi-patterned lithography. Reported performance is around 800 teraflops at half precision with 3.2 terabytes per second of memory bandwidth, and reported yield on the 910C is approximately 40 per cent, against upward of 90 per cent for comparable Western parts at their foundry. A yield figure of that kind is a cost figure as much as a manufacturing one: six of every ten chips scrapped is a price paid on every unit delivered.


Huawei is reported to plan around 600,000 of the 910C in 2026, scaling total Ascend output toward as many as 1.6 million dies, and to have pulled its next-generation Ascend 960 training chip forward to the first quarter of 2027. Its Atlas 950 SuperPoD connects 8,192 of the current processors with an optical interconnect, was previewed in Shanghai in July 2026 with mass production slated for the fourth quarter, and is claimed by Huawei to deliver eight exaflops at FP8 precision. Huawei's rotating chairman has said publicly that the company will not expand its next-generation accelerators internationally because it cannot satisfy domestic demand, which is a statement about scarcity rather than about strategy.


Two hard limits sit underneath all of it, and this is where the picture stops being about Chinese capability and starts being about Chinese constraint.


The first is fabrication. China's most advanced shipping process reaches roughly the density of Taiwan's six-nanometre generation, not a true five-nanometre-class node. Leading-edge capacity is small, estimated at around 45,000 wafers per month at the end of 2025 and targeted at 60,000 in 2026, against a global market measured in millions. Yields on the most demanding patterning techniques are reported in the range of 30 to 50 per cent, with costs two to three times the merchant rate per good die. Analyst consensus places the leading domestic foundry roughly five years behind the market leader, and one consequence is already visible in prices: the domestic supplier reportedly charges 40 to 50 per cent more than its Taiwanese competitor for comparable nodes.


The second limit is memory, and it is the more binding of the two. China stockpiled approximately thirteen million high-bandwidth memory stacks, mostly from Samsung, before controls tightened. Its domestic memory producer is projected to make only about two million stacks in 2026, which is enough for roughly 250,000 to 300,000 Ascend-class accelerator packages. The domestic foundry has capacity for more than a million Ascend dies a year and can only assemble as many packages as it has memory for. The constraint has moved from the logic die to the memory that feeds it, and no amount of wafer capacity fixes that.


Capital: the state funds the stack, and the chipmakers are now profitable


Shenzhen skyline with the China Resources Headquarters tower at sunset.


Shenzhen, the base of Huawei and the domestic accelerator industry whose chipmakers now report revenue growth of 100 to 200 per cent. Photograph: Lywin via Pexels.


China's capital position is unusual among the countries in this series in that most of it is domestic and much of it is directed. The March 2025 baseline for this series recorded government guidance funds numbering over 2,100 with a target size of roughly 1.86 trillion dollars by 2022, and state-backed venture funds having invested 184 billion dollars into more than 9,600 AI firms between 2000 and 2023. Independent analysis cited at that time put potential AI investment across 2024 to 2030 at more than one trillion dollars.


What has changed since is not the direction of the money but its results. The domestic chipmakers have become businesses rather than projects. Cambricon reported first-half 2026 revenue of 5.996 billion yuan, up 108 per cent, with net profit of 2.311 billion yuan, up 123 per cent, after its first full-year profit in 2025; its shares became the most expensive in mainland China's market in April 2026. Moore Threads reported first-half revenue of 1.736 billion yuan, up 147 per cent, with its loss narrowing by 96 per cent, and has announced plans to list in Hong Kong. Metax, Biren and Enflame all reported substantial growth, with Enflame's first-quarter revenue up more than fourteen-fold. Baidu's chip unit filed for a Hong Kong listing.


The significance of this is not the revenue figures, which remain small against the Western leaders. It is that a domestic accelerator industry now has customers, revenue, public markets and a reason to exist that does not depend on subsidy alone. Moore Threads' own executive said at a Shanghai conference in July 2026 that its current part delivers inference performance on a leading Chinese model at about half the level of comparable Western chips. That is a candid statement of position, and it is the position: half the performance at a viable price, available without a licence, is a better asset for a restricted buyer than three times the performance they cannot obtain.


The capital layer also has a concentration problem that the West shares. The state funds the stack, which means the stack answers to the state, and the models that emerged from it are also instruments of policy, as the next section shows.


Models: the strongest claim, and the most carefully worded


Diagram: the sanctions produced a domestic stack whose open weights spread globally.


The open-weights instrument. Weights are published; the training method is not. University 365 Research Center.


Xi Jinping, President of the People's Republic of China, as of 2026.


Xi Jinping, President of the People's Republic of China, as of 2026. He addressed the World Artificial Intelligence Conference in Shanghai in July 2026, where he pledged 5,000 AI training and seminar slots for developing countries. Photograph: The White House, public domain, via Wikimedia Commons.


China's model layer is where its sovereignty claim is strongest and where the language matters most.


DeepSeek's V4 generation includes a 1.6-trillion-parameter model with 49 billion parameters active per token and a million-token context window, released under the MIT licence with downloadable weights. Its reported efficiency is the more consequential figure: at a million-token context it requires about 27 per cent of the inference operations and 10 per cent of the memory cache of its predecessor. DeepSeek then replaced it in September 2026 with a 552-billion-parameter successor using a new architecture, routing all requests from the previous flagship to the new model.


Alibaba's Qwen family is the distribution story of the decade in AI. It passed one billion cumulative downloads in January 2026, accounted for more than half of global open-source model downloads by March, and is now the base that other countries build their national models on. Kimi, MiniMax and Zhipu operate comparable families, with Zhipu's GLM-5 reported as a 744-billion-parameter frontier model trained on a cluster of 100,000 Ascend processors, the largest documented domestic-silicon training run.


Two qualifications must travel with this, and both are matters of public record.


The first is the open-weight distinction defined at the top of this report. DeepSeek's MIT licence is genuinely permissive and its weights are genuinely downloadable. What is not published is the training data and the full training pipeline. A country that builds its national model on a Chinese base inherits a capability and not a method. It can fine-tune; it cannot reproduce. That is a deliberate boundary, and it is the boundary that makes the open-weights strategy an instrument of influence rather than a pure public good.


The second is that the openness is a per-release decision, not a company posture. Both Alibaba and Zhipu have been reported pivoting flagship models to closed, hosted offerings during 2026. The base layers remain open; the frontier layers are moving behind a door. Anyone building a national capability on a Chinese open weight should read the licence carefully and notice that the next generation may not be offered on the same terms.


And the distribution has become explicit state policy. The open-weight strategy travels with training programmes and diplomatic framing, and its reach is documented. Chinese models now appear in sovereign projects in Egypt, Singapore, Thailand, Uganda and the United Arab Emirates through one laboratory's family alone, with a second country's national model built with direct technical support from a Chinese company. Singapore's national programme chose Qwen over an American alternative. Malaysia said its sovereign programme would run on DeepSeek. Uganda's national language model, covering thirty-one languages, was built on Qwen 3.


The diplomacy is institutional as well as commercial. At the World Artificial Intelligence Conference in Shanghai in July 2026, Xi Jinping pledged 5,000 AI training and seminar slots for developing countries over five years, and representatives of twenty-nine countries signed an agreement creating the World Artificial Intelligence Cooperation Organization, based in Shanghai.


The honest framing is this: about three-fifths of identifiable sovereign models worldwide still use American bases, and the compute underneath almost all of them is American. Chinese models are a minority of sovereign projects and a majority of open-model downloads, which are different measurements of different things.


Regulation: administrative measures, not a statute


China regulates artificial intelligence through administrative measures rather than a comprehensive law, and the distinction is structural rather than semantic.


The 2023 Interim Measures for the Management of Generative AI Services govern how a generative service is provided to the public, including security assessment and algorithm filing obligations. The Measures for the Labelling of AI-Generated Synthetic Content took effect on 1 September 2025, jointly issued by four agencies, and they are the most concrete piece of AI regulation China has issued. They require online information service providers to add explicit labels to AI-generated content, for example a watermark, and to embed implicit labels in the files themselves, covering text, images, audio, video and virtual scenes. Where a user asks for unlabelled output, the provider may supply it after making the user's labelling obligation clear in the service agreement, and must retain logs for at least six months. Enforcement is carried out by whichever department owns the relevant rule rather than by a single AI regulator.


That structure has a consequence a Western reader should understand. There is no single Chinese AI statute to compare with the European Union's AI Act, and no single enforcement body. Governance runs through the interim measures, the cybersecurity and data laws, and the labelling rules together. A country that regulates by administrative measure can move faster than a legislature and can change direction without a vote, which is why the labelling rules went from announcement to national implementation in months.


On independent measures China's government readiness has improved sharply, rising to eighth globally in the 2025 Government AI Readiness Index from twenty-third in 2024, with the analysts attributing the gain to infrastructure and policy components including its domestic accelerators and national fund investment.


Talent and education: first in research, and retaining its people


The talent layer is where China's position is strongest and least contested.


China ranks first globally in AI research paper output, citation counts, patent filings and industrial robot installations. In 2024 its research output matched the combined publications of the United States, the United Kingdom and the European Union, with 156 institutions each producing at least fifty AI papers, and it holds eleven of the top twenty AI institutions globally against America's ten. Its institutions and companies took four of the global top ten model producers. AI usage in Chinese workplaces exceeds 80 per cent against a global average of 58 per cent.


The talent flow has also reversed in a way that matters more than the publication counts. The United States lost its lead in attracting the world's top AI researchers: of the 2025 cohort, 41 per cent went to China and 34 per cent to the United States, a reversal from 46 per cent to the United States and 27 per cent to China in 2022. A sanctions regime designed to slow a technological competitor has coincided with the competitor becoming the more attractive destination for the people who build the technology.


What changed since our 2025 report on China


Comparison between the 2025 and 2026 University 365 reports on China.


What changed since our March 2025 report on China. University 365 Research Center.


Our previous report on China.


Read the earlier report: China's AI Landscape in March 2025 - A Roadmap to Global Leadership. University 365 INSIDE, 21 March 2025.


University 365 published "China's AI Landscape in March 2025: A Roadmap to Global Leadership" on 21 March 2025. That report's central factual claim about the hardware constraint has been overtaken by events in both directions, and the comparison is instructive.


The constraint statement was right and is now partly obsolete. The 2025 report stated that Chinese companies must rely increasingly on domestic alternatives such as Huawei's Ascend 910B, "which still lags in performance for training LLMs". Both halves of that sentence held. What the report could not know is that the lag would stop being decisive, because competitive models would turn out to be trainable and servable on a fraction of frontier compute. The constraint is real and it no longer determines the outcome.


The model layer went from national ambition to global distribution. The 2025 report recorded 188 foundation models registered at national level by August 2024 and named five "new AI Tigers" and four older "dragons". The current position is that one family from that cohort has passed a billion downloads and holds more than half of global open-model downloads. The 2025 report described a large domestic model sector. The 2026 position is a global distribution network.


The capital question moved from projection to result. The 2025 report carried projections of more than a trillion dollars of AI investment across 2024 to 2030 and market demand of 5.6 trillion yuan by 2030, both attributed to state-backed analysis. The measurable change is that the chipmakers those funds financed now report revenue growth of 100 to 200 per cent and, in one case, profitability. The 2025 report described capital being committed. The 2026 position is capital producing businesses.


The regulatory picture gained its most concrete instrument. The 2025 report cited the 2023 Interim Measures and the AI Safety Governance Framework. The labelling measures, effective September 2025 and covering text, image, audio, video and virtual scenes with both visible and embedded labels, are the most specific AI rule China has issued and they did not exist when the earlier report was written.


The talent flow reversed. The 2025 report did not carry a researcher-migration figure. The current data shows China receiving 41 per cent of the top AI research cohort against 34 per cent for the United States, a reversal of the 2022 position. This is the single largest change of the sixteen months, and it is the one an export-control policy is least able to affect.


Back to the TOC
Section icon: Key Findings.

Sovereign AI Race: China (2026)

Key Findings


1. China is the only country in this series attempting to hold all five layers, and it has succeeded at four. Compute is domestic and constrained; models are domestic and globally distributed; capital is domestic and productive; regulation is domestic and administrative; talent is domestic and now a net magnet. The exception inside compute is the frontier, where the gap is widening rather than closing.


2. The export controls did not stop the model layer, and that is the decisive finding. China could not buy the best accelerators and produced models good enough to take the majority of global open-model downloads. Weights, once published, are information rather than goods, and no licence regime governs a download.


3. The American response changed direction. In January 2026 the United States moved the H200 and comparable chips from a presumption of denial to case-by-case review for direct exports to China, subject to conditions including independent third-party performance testing in the United States and a cap under which China shipments may not exceed half of United States-bound volume. The control that was meant to deny became a managed sale.


4. The binding constraint has moved from the logic die to the memory. Domestic foundry capacity supports more than a million Ascend dies a year; domestic high-bandwidth memory output supports roughly a quarter to a third of that. Thirteen million memory stacks were stockpiled before controls tightened, and that stockpile is finite.


5. The reported cost of the domestic route is precise and high. Roughly 40 per cent yields on the current accelerator against upward of 90 per cent for comparable Western parts at their foundry; leading-edge wafer capacity an order of magnitude below global scale; costs two to three times merchant rate per good die; and domestic chip prices 40 to 50 per cent above the market leader for equivalent nodes.


6. The domestic accelerator industry became a real business while this was happening. Cambricon moved to profitability, Moore Threads' losses narrowed by 96 per cent, Metax, Biren and Enflame grew sharply, and Baidu's chip unit filed for a Hong Kong listing.


7. Open weights are an instrument as well as a gift. The base layers are open and the method is not: no training data, no full pipeline, and a documented pivot of frontier flagships to closed hosted offerings during 2026. A country that builds on a Chinese base inherits a capability and not the ability to reproduce it.


8. China leads the world in AI research and is now the more attractive destination for top researchers. First in publications, citations, patents and robot installations, with 41 per cent of the 2025 top-researcher cohort against 34 per cent for the United States, reversing the 2022 position.


9. The regulatory instrument is administrative, which is a capability and a risk. The labelling measures moved from issuance to national implementation in months. There is no comprehensive statute and no single AI regulator, so the rules can change without the deliberation a statute requires.


Back to the TOC
Section icon: Deep Analysis.

Sovereign AI Race: China (2026)

Deep Analysis


Why the controls produced the opposite of their purpose


The standard account of the semiconductor controls is that they slowed China. At the hardware frontier, they did, and that outcome is documented in this report. The error in the policy was in assuming that the hardware frontier determined the capability frontier, and that assumption was already failing when the controls tightened.


Three things changed in the technology between 2023 and 2026, and each reduced the force of a chip ban.


Model capability stopped scaling mainly with training compute. Post-training, data quality and architecture became the dominant levers, which is why a model trained on a fraction of frontier compute can serve most real tasks competently. DeepSeek's own efficiency figures make the point: the successor generation needs a quarter of the inference operations and a tenth of the memory of the model it replaced. Efficiency gains of that scale mean the compute you own matters less each year.


Inference overtook training as the dominant workload. Most tokens consumed are generated, not trained, and inference is more forgiving of hardware than training is. An accelerator at half the performance of the frontier part, available without a licence, becomes an economically rational choice for serving models at scale. That is precisely what the domestic chipmakers are now selling.


And distribution became cheap. Publishing weights costs almost nothing and reaches everywhere. The control regime governs the movement of physical goods and, in limited form, the weights of the most advanced closed models. It has no mechanism for a file that has already been downloaded.


Put those together and the outcome is structural rather than accidental. A control that denies hardware to a large, well-funded, research-strong state will produce a domestic hardware industry, a more efficient model layer, and a distribution strategy that routes around the control entirely. The only way to prevent that outcome would have been to sell the hardware, which is what the January 2026 rule now does, at a point when the domestic stack already exists and no longer needs it.


The open-weights question, stated honestly


This report has described the Chinese open-weights strategy as both a gift and an instrument. Both are true and the balance matters.


The gift is real. A university in Nairobi, a ministry in Phnom Penh or a start-up in São Paulo can download a capable model and build on it, at no cost and with no permission. That is a material transfer of capability to places the Western market does not prioritise, and no Western laboratory has offered anything comparable at the same scale. The ten newest entrants to the sovereign AI project count are lower and middle-income economies, and the models available to them are disproportionately Chinese.


The instrument is also real. A base model carries the assumptions of whoever trained it, and post-training on local data does not remove them. The method is withheld, which keeps the recipient dependent on the supplier for every future generation. And the openness is a commercial decision that is already being reversed at the frontier. A country that has standardised on a Chinese base has made a choice that is cheap now and has a renewal date.


The honest conclusion is that open weights are the most effective soft-power instrument in artificial intelligence, and they are more attractive to most of the world than anything on offer from the countries that impose conditions. That is not a criticism of China. It is a description of a market failure in the West's approach to the Global South.


What full-stack sovereignty costs, measured


The series frame asks whether a country holds a layer or rents it. China's case shows that holding everything is possible and that the price is paid in efficiency rather than in dependency, which is a different kind of cost from the one the Gulf states pay.


A state that rents compute, as the United Arab Emirates does, has a modern stack and a licence with a date on it. A state that builds compute under sanctions, as China has, has no licence and a stack several years behind the frontier, running on a process node that is five years old, fed by a memory stockpile that will run out, at yields that waste most of the wafers it processes. Neither position is comfortable. The difference is who can switch the other off.


That framing is the contribution this report makes to the series. Sovereignty is not the absence of constraint; it is the ability to choose which constraint to accept. China chose the efficiency cost and retained the decision. The Gulf states chose the efficiency and gave up the decision, for now, with a date. Both are rational. Only one of them can be reversed by a foreign signature.


Back to the TOC
Section icon: Data and Evidence.

Sovereign AI Race: China (2026)

Data and Evidence


Table 1: The five layers, assessed for China in September 2026


Layer

What China holds

What it does not hold

Assessment

Compute

National capacity reported at 2,185 EFLOPS by mid-2026; first fully domestic 100,000-accelerator supercluster running; a domestic accelerator industry shipping at scale and moving to public markets

A leading-edge logic process at commercial cost; reported yields near 40 per cent against upward of 90 per cent for Western parts; high-bandwidth memory sufficient for its own fabrication capacity

Owned, at an efficiency cost

Models

DeepSeek, Qwen, Kimi, MiniMax and GLM families; a 1.6-trillion-parameter model under the MIT licence; more than half of global open-model downloads; adoption in sovereign projects across five named countries

The training method: no training data and no full pipeline published; frontier flagships pivoting to closed hosted offerings during 2026

Owned, and distributed as policy

Capital

Guidance funds and state venture capital measured in the hundreds of billions; chipmakers now reporting 100 to 200 per cent revenue growth, one at profit, several listing publicly

Nothing material; this is a genuinely held layer, funded domestically without foreign permission

Owned

Regulation

Administrative measures rather than a statute; the 2025 labelling rules covering text, image, audio, video and virtual scenes with visible and embedded labels; eighth globally on government readiness, up from twenty-third

A comprehensive AI statute; a single enforcement authority; the deliberative process a legislature provides

Held, and rapidly changeable

Talent and education

First globally in AI publications, citations, patents and robot installations; eleven of the top twenty AI institutions; workplace AI usage above 80 per cent; a reversed researcher flow now favouring China

Nothing material on the evidence reviewed; the sanctions regime has coincided with the talent flow moving in China's favour

Held, and strengthening


Table 2: The controlled metrics, series bible format


Metric

China position

Source and date

Flagship compute commitment

National intelligent computing capacity reported at 2,185 EFLOPS as of June 2026, up 177 per cent year on year; 42 ten-thousand-card clusters reported in January 2026; Atlas 950 SuperPoD at 8,192 processors with mass production slated for Q4 2026

Ministry of Industry and Information Technology as reported, 2026; Huawei announcements, July 2026

Capital committed

More than 2,100 government guidance funds with a target of roughly 1.86tn USD by 2022; 184bn USD invested across 9,600+ AI firms, 2000 to 2023; domestic chipmakers posting 100 to 200 per cent revenue growth in 2026

Prior U365 baseline, March 2025; company results, 2026

Flagship national models

DeepSeek-V4-Pro, 1.6tn parameters, 49bn active, MIT licence, weights downloadable; Qwen with over 1bn cumulative downloads and over half of global open-model downloads by March 2026; GLM-5 reported at 744bn parameters trained on 100,000 Ascend processors

Hugging Face model cards and arXiv, 2026; Alibaba and SCMP reporting, 2026

Anchor entities

Huawei and HiSilicon; Alibaba, DeepSeek, Moonshot, MiniMax, Zhipu; Cambricon, Moore Threads, Metax, Biren, Enflame; the national compute grid and its regional nodes

Official company disclosures and stock exchange filings, 2026

Chip dependency

Domestic accelerators for a growing share of national capacity; the most advanced available part trails the frontier and the gap widens on public roadmaps; memory is the binding constraint

Analyst and trade reporting, 2026

Regulatory instrument

Interim Measures for Generative AI Services, 2023; Measures for the Labelling of AI-Generated Synthetic Content, effective 1 September 2025; no comprehensive AI statute

China Law Translate; ICLG, 2026

Talent anchors

First globally in AI publications, citations and patents; eleven of the top twenty AI institutions; 41 per cent of the 2025 top-researcher cohort against 34 per cent for the United States

Stanford HAI AI Index 2026

Independent index standing

Government AI Readiness 2025: 8th globally, up from 23rd. Stanford HAI AI Index 2026: leading in research output with the model performance gap with the United States effectively closed

Oxford Insights, 2025; Stanford HAI, April 2026

Adoption

Workplace AI usage above 80 per cent against a global average of 58 per cent; at least 30 per cent of United States-firm token traffic on a major routing platform since February 2026, peaking at 46 per cent

Stanford HAI AI Index 2026; OpenRouter telemetry as reported, 2026

Distinguishing mechanism

Full-stack domestic build under sanctions, with open weights as the distribution instrument

This report

Core tension

Built everything and cannot build the frontier, so it gives away what it can build

This report


Table 3: Timeline, 2022 to 2026


Date

Event

Source

October 2022

United States imposes comprehensive controls on advanced semiconductor exports to China

Bureau of Industry and Security

2023

Interim Measures for the Management of Generative AI Services issued

China Law Translate

December 2024

Controls expanded again, including high-bandwidth memory

Bureau of Industry and Security

21 March 2025

University 365 publishes its China AI landscape report

University 365 INSIDE

1 September 2025

Measures for the Labelling of AI-Generated Synthetic Content take effect

China Law Translate

8 December 2025

The United States announces it will allow H200-class shipments to approved customers in China

Bureau of Industry and Security

13 January 2026

Final rule moves certain advanced computing exports to China to case-by-case review, effective 15 January

Federal Register, 13 January 2026

21 January 2026

Qwen passes one billion cumulative downloads on a public model hub

Alibaba as reported

8 February 2026

Chinese-origin models begin a run of holding at least 30 per cent of United States-firm token traffic on a major routing platform

Platform telemetry as reported

March 2026

Qwen accounts for more than half of global open-source model downloads

SCMP citing Interconnects AI

April 2026

Cambricon's shares become the most expensive in mainland China's equity market

SCMP, 29 April 2026

June 2026

Chinese models pass United States models in total token share on a routing platform, at roughly 18 trillion tokens per week

Platform telemetry as reported

June 2026

National intelligent computing capacity reported at 2,185 EFLOPS, up 177 per cent year on year

Ministry of Industry and Information Technology as reported

July 2026

First fully domestic 100,000-accelerator supercluster switched on at the Zhengzhou node

National Development and Reform Commission as reported

July 2026

Huawei previews the Atlas 950 SuperPoD at 8,192 processors, mass production slated for Q4

Huawei at the World Artificial Intelligence Conference

17 July 2026

Xi Jinping pledges 5,000 AI training and seminar slots for developing countries; 29 countries sign the agreement creating the World Artificial Intelligence Cooperation Organization

WAIC, Shanghai, as reported

September 2026

DeepSeek replaces its flagship with a 552-billion-parameter successor and routes all prior flagship requests to it

DeepSeek official announcement

2026

Reported pivot of Alibaba and Zhipu frontier flagships to closed hosted offerings

Trade reporting, 2026


Back to the TOC
Section icon: Implications.

Sovereign AI Race: China (2026)

Implications


For states deciding which stack to build on


The choice facing most countries is now explicit and the terms are on the table. An American stack comes with frontier capability, a licence regime, and conditions that can include site visits and matching investment. A Chinese stack comes with a capable open base, no licence, no method, and a supplier who may close the next generation. Neither is neutral and both are defensible.


The question a state should ask is not which supplier is friendlier. It is which dependency can be renegotiated if the relationship changes. A licence can be withdrawn by the licensor. A downloaded weight cannot be withdrawn by anyone, and it also cannot be improved by the recipient without the method that was withheld. That asymmetry is the thing to price.


For the technology providers


The open-weights strategy has done more to spread Chinese AI influence than any export programme, and it costs China almost nothing. A Western laboratory that wants to compete for the same demand has to decide whether it will publish weights at a scale it currently does not, which is a commercial decision its investors will resist. Until it does, the default base layer for the developing world will be Chinese. That is a market position, not a policy failure, and it is being conceded by default.


For institutional and enterprise buyers


A model's provenance now has a licensing dimension that procurement processes rarely capture. The relevant questions are which jurisdiction trained the base, what the licence permits, whether the training method is available to the buyer's own engineers, and whether the next generation will be offered on the same terms. Those four questions are cheap to ask before adoption and expensive to answer afterwards.


For the countries in this series


China is the existence proof that the full-stack route works and that it costs several years of frontier performance. The Gulf states, France and India are all running partial versions of it. The Chinese case suggests the honest framing for them: the question is not whether to accept dependency, because every route accepts some. It is which dependency can be ended, and at what price.


Back to the TOC
Section icon: Education and Skills Impact.

Sovereign AI Race: China (2026)

Education and Skills Impact


What the Chinese case teaches about the capability that actually matters


This series returns in every report to the gap between using AI and building it, because that gap is where the educational argument lives. The Chinese case closes part of that gap and leaves the rest open, and the pattern is worth studying.


China's education and research system now produces the world's leading AI research output, eleven of the top twenty AI institutions, and the largest share of the top researcher cohort. Its workplaces use AI at a higher rate than any comparable economy. That combination, research depth plus population-wide use, is the configuration the other countries in this series are trying to reach and none has.


What China does not publish is the method. Its open models arrive as weights: a working artefact without the data, the pipeline or the reasoning that produced it. A Chinese engineer who downloads one can build on it and cannot reproduce it, which is the same position in which Saudi Arabia stands with its derived national model. The most advanced country in the world at producing AI knowledge has built an open-weights strategy whose recipients, including its own partners, inherit capability without method.


That is the pedagogical finding of this report, and it applies to every learner anywhere. Being able to use a model is a different skill from being able to evaluate whether it is right, and both are different from being able to build the thing. The three skills sit on a ladder, and the top of the ladder is what a country needs when the licence conditions change. China has demonstrated that the ladder can be climbed and that it is expensive. It has also demonstrated, by withholding the method, that it understands exactly which rung matters.


Back to the TOC
Section icon: The CI-First Perspective.

Sovereign AI Race: China (2026)

The CI-First Perspective


Where the appearance outruns the capability, and where it does not


Illustration: a tower of solid blocks rises above a much larger translucent base.


Capability above the waterline, and the question of what holds it up. University 365 Research Center.


The Co-Intelligence First framework asks whether an arrangement amplifies human capability or substitutes for it, and where the risk of AI Imposture sits. Applied to China, the question produces a verdict that differs from the previous two reports in an important way: on most dimensions, the capability is real and the appearance lags it rather than the reverse.


The genuine holdings are substantial. The research base is first in the world by publication, citation and patent. The accelerator industry sells real products to real customers and posts real revenue. The models are downloadable, runnable and measurable by anyone, which is the strongest possible test of a capability claim: a published weight can be tested by its critics. Workplace adoption is the highest measured anywhere. None of this is a projection or a plan.


The three places where appearance could outrun substance are specific.


The first is national compute capacity, reported at 2,185 EFLOPS without a stated precision basis, against independent firms measuring on a different basis entirely and arriving at a fraction of the figure. That is not deception; it is an incompletely specified statistic being compared across incompatible methods. But a reader who takes the headline number and sets it beside another country's differently measured total has been misled, and this report declines to do it.


The second is the supercluster announcements. A system described as a hundred-thousand-accelerator supercluster, running as its first workloads double-precision scientific computing rather than model training, sits at the boundary between a genuine achievement and a headline tailored to a benchmark. Both readings are defensible on the evidence, which is itself the problem.


The third, and the most consequential for the rest of the world, is the open-weights offer. A downloadable model that performs well, in a world where the frontier is moving to closed hosted services, produces the appearance of a transfer of capability. The reality is a transfer of a product, with the method retained. The recipients who will discover this are the ones who standardised on a base and then wanted to improve it themselves.


The honest CI-First verdict on China is that this is the one country in the series so far whose capability is not in question. Its constraint is performance at the frontier and efficiency in manufacture, and both are visible, quantified and openly discussed by its own companies. The imposture risk in the Chinese case is not China's; it is the risk that everyone else mistakes its open-weights offer for a transfer of the ability to build.


Back to the TOC
Section icon: What This Means for You and Us.

Sovereign AI Race: China (2026)

What This Means for You and Us


For a reader in a country choosing a stack


The practical test is simple and applies to any supplier. Ask whether the artefact comes with the method. A chip cannot be asked; a model can. If the weights are published and the data and pipeline are not, you are buying a product and renting a capability, and the next generation may not be offered on the same terms.


For a reader watching the series


Three countries have now been assessed and a structure has emerged. The United Arab Emirates and Saudi Arabia bought capability and hold capital absolutely while renting compute. China built everything and accepted an efficiency cost. The pattern across all three is that the layers which respond to money are held, and the layer that requires time, judgment and method is the one that is rented, imported or withheld. That finding will be tested eighteen more times.


For University 365


The Chinese case sharpens the argument this series is building. Three countries, three strategies, one shared boundary at the point where a person must be able to judge and build rather than use. China is further up that ladder than anyone and still withholds the top rung from its partners. The educational case for teaching method rather than tool use has never been better evidenced, and it comes from the country that has run the largest experiment in the world on the difference between the two.


Back to the TOC
Section icon: The Road Ahead.

Sovereign AI Race: China (2026)

The Road Ahead


Three observable things would change this assessment.


Whether the domestic accelerator closes the gap or falls further behind. The public roadmaps suggest the performance gap widens through 2027. If instead the next generation closes part of it, the efficiency cost of the domestic route falls and full-stack sovereignty becomes cheaper for everyone who follows.


Whether the memory constraint binds. Domestic high-bandwidth memory output against domestic fabrication capacity is the tightest number in Chinese compute. If memory production scales, the accelerator programme can use the wafer capacity it has built. If it does not, the stockpile is the ceiling.


Whether openness survives the pivot. Alibaba and Zhipu moving their frontier flagships to closed hosted offerings would mark the end of the open-weights playbook at the frontier while leaving the base layers open. Watch the next flagship licence. If it is closed, the strategy has produced a base layer that other countries have standardised on, and China now intends to charge for the next rung.


Back to the TOC
Section icon: Sources and Methodology.

Sovereign AI Race: China (2026)

Sources and Methodology


Methodology


This report was researched from public sources with a preference for primary documents: company filings carried by the Shanghai and Hong Kong exchanges, official model cards, the Federal Register text of the January 2026 rule, Chinese government regulations in translation, and independent research indices. A substantial proportion of the material on Chinese chip performance comes from analyst measurements rather than company disclosures, and those passages are labelled as claims wherever they appear.


The report also tests University 365's own prior coverage. The China landscape report of March 2025 is compared against the present position in The Current State, and the comparison records where that report was accurate as well as where events overtook it.


Five limits should travel with this report. First, national compute totals are reported on incompatible measurement bases and this report gives the basis with each figure; the headline totals should not be compared across countries. Second, several accelerator performance and yield figures come from technical analysts rather than manufacturers and are labelled. Third, the reported training hardware for one flagship model conflicts between sources, with one reporting a shift to domestic silicon and another documenting full support for Western hardware; the report states the conflict rather than resolving it. Fourth, the exact scale of the next-generation supercluster is disputed between a company roadmap and its own later announcement, and an analyst has noted the discrepancy publicly. Fifth, one widely circulated performance comparison between domestic and Western accelerators could not be traced to an originating source and is excluded.


Principal sources


Government and regulatory. United States Bureau of Industry and Security press releases and Federal Register documents including the January 2026 final rule; the Chinese Measures for the Labelling of AI-Generated Synthetic Content in translation; the 2023 Interim Measures; Ministry of Industry and Information Technology figures as reported; the National Development and Reform Commission on the Zhengzhou supercluster.


Company and exchange disclosures. Huawei and HiSilicon announcements; DeepSeek model cards and technical reports; Alibaba and Qwen release notes; Zhipu, Moonshot and MiniMax releases; Shanghai Stock Exchange and Hong Kong exchange filings for Cambricon, Moore Threads, Metax, Biren and Enflame; Baidu's chip unit listing documents.


Independent research. Stanford HAI AI Index 2026; Oxford Insights Government AI Readiness 2025; CNAS sovereign AI project tracking; Counterpoint Research on sovereign model adoption; Gartner's China AI trends analysis; platform telemetry on open-weight model usage as reported by CNBC and others; SemiAnalysis fabrication measurements.


Reporting. Reuters; Bloomberg; Financial Times; SCMP; Caixin Global; CNBC; DataCenterDynamics; Foreign Policy; and the semiconductor trade press, named in the text where a claim depends on them.


Section icon: About This Report.

Sovereign AI Race: China (2026)

About This Report


Sovereign AI Race: China (2026) is report three of twenty in the Sovereign AI Race series, followed by a comparative capstone. The series assesses how states attempt to control the production of artificial intelligence inside their jurisdiction, using one five-layer framework and one metric set applied identically to every country: compute, models, capital, regulation, and talent.


Each report in the series carries a "What Changed Since" treatment against the earlier University 365 report on the same country where one exists. China has a 2025 landscape report from this institution, and this report is compared against it.


Author: Hubert Graef, Dean of Research, University 365 Research Center.


Series: Sovereign AI Race, report 3 of 20, followed by the comparative capstone.


*Published by University 365 Research Center. CI-First is University 365's Co-Intelligence First framework, a method constant of the institution.*


Revision 4, 30 September 2026, 18:24 UTC. Published 29 September 2026.

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
Image by Erik  Lucatero

Become Superhuman

Master AI to stay irreplaceable in every field.

 

 

 

​

​

Apply for Admission Today.
Select Your Initial Access Level.


Become a DISCOVERY, INSIDER, or SUPERHUMAN Fellow.

Image by Milad Fakurian

Master Your Life with a Digital Second Brain

Turn overwhelm into clarity with LIPS + CARE
U365’s unique framework to organize your goals, projects, and knowledge into a superhuman system for success

bottom of page