By Jonathan West · Updated July 20, 2026

The Hidden 46%: Chinese AI Models in American Business

Nearly half of U.S. AI traffic now runs on Chinese-built models — and most business owners have no idea whose technology is reading their data.

By Jonathan West · Updated July 20, 2026

A fast-growing share of the artificial intelligence powering American businesses is being processed by Chinese-developed models — as much as 46% of token traffic on OpenRouter, the largest AI model router. A year ago, U.S. models held roughly 70% of that traffic; today it is closer to 30%. Most owners never chose a Chinese model. They bought "an AI feature" — and the model underneath can be routed, resold, or white-labeled without notice.

46%
of U.S. AI traffic on OpenRouter, the largest AI router, now runs on Chinese-built models
80%
of U.S. startups build on Chinese base models, per Andreessen Horowitz
63%
of all new fine-tuned AI models are built on Chinese foundation models
70%
of enterprise AI activity runs outside IT oversight — "shadow AI"

The traffic has already flipped

In under two years, Chinese-built models went from a rounding error to nearly half of U.S. AI usage on the largest routing platform — while the U.S. share collapsed. The driver is simple: open Chinese models are 60–90% cheaper than the leading U.S. options.

Chinese models — mid-2025~2%
Chinese models — mid-202646%
U.S. models — mid-2025~70%
U.S. models — mid-2026~30%
Share of U.S. AI model traffic on OpenRouter, mid-2025 vs mid-2026. Source: OpenRouter usage data via Dataconomy and OfficeChai.

Why your business probably can't see it

This shift is invisible because model provenance is abstracted away at every layer of the modern AI stack. Here are the five ways a Chinese model ends up processing your data without a decision ever crossing your desk.

1. Router defaults

Cost-optimizing routers send your request to the cheapest stable provider — increasingly a Chinese endpoint, because Chinese models run 60–90% cheaper.

2. White-labeled SaaS backends

If you use almost any AI feature built by a startup, there is a real chance a Qwen or DeepSeek model is under the hood. Vendors rarely advertise it.

3. Cloud marketplaces

AWS and Azure now sell DeepSeek, Qwen, and Moonshot’s Kimi directly in their model catalogs — so even a model picked through your trusted cloud console can be Chinese-origin.

4. Hidden-lineage fine-tunes

A vendor’s "proprietary" or "custom" model is often a Qwen or DeepSeek derivative. With 63% of new fine-tunes built on Chinese bases, provenance depends on vendor honesty.

5. Shadow AI

Employees adopt these models through personal devices, browser tools, and local installs that never pass a security review — and most security teams lose visibility entirely.

The most recognizable example: Cursor, one of the hottest U.S. AI companies, disclosed that its coding model was built on top of Moonshot's Kimi K2.5 — a fact many developers learned only after they were already using it.

Why companies switch: the cost gap

The pull is almost entirely price. For a business processing millions of API calls a month, the difference is the kind of number that makes a procurement team overrule a security objection.

Leading U.S. model~$10.00
DeepSeek (China)under $0.50
Approximate cost of one hour-long coding session. Source: CNBC. Figures are illustrative of the 60–90% cost gap between leading U.S. models and DeepSeek.

Why it matters — and it's no longer hypothetical

Any prompt processed by a Chinese-provider endpoint falls under China's National Intelligence Law, which can compel data disclosure to the state. The exposure is now regulatory, not theoretical: in July 2026 the House Select Committee on the CCP opened a probe into U.S. firms using these models, and the FY2026 NDAA already bars DeepSeek from Defense Department systems. Firms with high shadow-AI exposure pay an estimated $670,000 breach premium per incident.

This lands hardest in regulated fields. If you run a legal or medical practice, an undisclosed Chinese model in your stack is a compliance failure waiting to be discovered.

The fix isn't "ban Chinese AI." It's knowing your stack.

You cannot govern what you cannot see. Because most Chinese models are open-weight, the answer is rarely a blanket ban — it is visibility and control. Self-hosting open weights, for example, keeps prompts inside your own infrastructure and neutralizes the jurisdiction risk entirely; see our self-hosted AI models guide. To see how each major model scores on data-sovereignty risk, use our AI models by country & business safety index.

Step one is simply finding out what is in your stack. Most owners are surprised by the answer.

Is There a Chinese Model in Your AI Stack?

Book a free AI Stack Sovereignty Check. We map which models actually process your data — across your vendors, routers, and tools — and flag any data-sovereignty or compliance risk.

Get your free stack check

Frequently Asked Questions

Are U.S. businesses really using Chinese AI models?

Yes. As of mid-2026, up to 46% of U.S. AI token traffic on OpenRouter — the largest AI model router — runs on Chinese-built models such as DeepSeek and Qwen, up from under 2% a year earlier. Andreessen Horowitz estimates 80% of U.S. startups build on Chinese base models.

How would my business be using a Chinese AI model without knowing?

Five common ways: your AI vendor routes requests to the cheapest provider (often Chinese); a SaaS tool is quietly built on a Chinese model; your cloud marketplace sells Chinese models directly; a "custom" model is a Chinese fine-tune; or employees use Chinese tools without IT review. You rarely choose the model directly — you buy an AI feature, and the model underneath can change without notice.

Why does it matter if a Chinese model processes my data?

Any prompt processed by a Chinese-provider endpoint falls under China’s National Intelligence Law, which can compel data disclosure to the state. In July 2026 the House Select Committee on the CCP opened a probe into U.S. firms using these models, and the FY2026 NDAA already bars DeepSeek from Defense Department systems. For regulated industries, an undisclosed Chinese model is a compliance exposure.

Is there a safe way to use Chinese open-weight models?

Often, yes. Because most Chinese models are open-weight, self-hosting them on your own infrastructure keeps prompts inside your environment — which neutralizes the data-jurisdiction risk regardless of where the model was built. The risk is the China-hosted API, not the weights you run yourself.

How do I find out which AI models my business is actually using?

Start with a provenance audit of every tool that touches customer data: check each vendor’s model disclosure, look at router and API settings, and inventory employee AI tools. Layer3Labs offers a free AI Stack Sovereignty Check that maps which models process your data and flags data-sovereignty risk.

Sources

Researched by Jonathan West, Founder of Layer3Labs. Figures reflect third-party reporting current as of July 2026; the AI landscape moves quickly, so verify current data before acting.