# Nathan Lambert on China's AI Ecosystem and the Open Model Gap

A 24-minute talk followed by 24 minutes of audience questions, given at The Curve in Berkeley (October 3-5, 2025) and uploaded seven weeks later. Lambert, a research scientist at AI2 and the author of [[interconnects|Interconnects]], opens by saying this is not his day job and he is tired of being the one who carries it. His case is that 2025 is the year Chinese labs became the default source of open models, that [[deepseek|DeepSeek]] R1 started the process rather than being a one-off, and that the US will not win back the position without real money spent on fully open models. The [[open-source-ai-reading-list]] lists it as the summary of how open models went in 2025.

## The argument

### How 2025 went

In 2024 the names were Llama, Mistral, DeepSeek as the interesting research lab, and Qwen as the smaller alternative to Llama ([00:08](https://youtu.be/VpYU4VOicI0?t=8)). Lambert treats R1 as the moment things started moving: Chinese companies woke up to what an open release could do, and the American side recalibrated around it. His pivot point is April, when Llama 4 and Qwen 3 came out within weeks of each other. He calls Llama 4 a flop, and says that if it had gone better the summer's arguments about the gap would have looked very different ([01:48](https://youtu.be/VpYU4VOicI0?t=108)). By summer the "AI tigers" were shipping: MiniMax, Baidu releasing open models, Kimi K2 from Moonshot, GLM-4.5 from [[z-ai|Z.ai]], StepFun. OpenAI's gpt-oss in August he calls a step in the right direction that he does not expect to change much, since he sees no sign [[openai|OpenAI]] wants it as a recurring line ([03:15](https://youtu.be/VpYU4VOicI0?t=195), [04:22](https://youtu.be/VpYU4VOicI0?t=262)).

He separates the two big Chinese labs by what they are for. DeepSeek is a single-minded research team chasing frontier use cases and got adopted by enterprises. Qwen puts Alibaba's resources behind a full-stack offering, closer to what Llama used to be, and has become the default model for researchers ([04:22](https://youtu.be/VpYU4VOicI0?t=262)).

### Where Llama went

[[meta-platforms|Meta]]'s public statements a year apart show the company flipping on open source, which Lambert reads as a corporation doing what corporations do once the ideological and recruiting reasons fade. He thinks it was a strategic mistake, since releasing some models is cheap. Google's Gemma was never as prominent as Llama, and NVIDIA is starting to release more, including some pre-training data ([05:34](https://youtu.be/VpYU4VOicI0?t=334)). Zuckerberg still talks about new Llama models, but the trust has moved on, and trust decides what people build on ([07:38](https://youtu.be/VpYU4VOicI0?t=458)).

### Qwen's pace

Alibaba alone, through Qwen, releases as many useful models as the whole Western open ecosystem, covering text, speech, image editing, agentic coding and vision-language models ([07:38](https://youtu.be/VpYU4VOicI0?t=458)). The effort goes into distribution as well as training: the main Alibaba account on Twitter, with 400,000 followers, messages Lambert on every release hoping for coverage, and he knows of no American company doing that for open models ([09:12](https://youtu.be/VpYU4VOicI0?t=552)). An Alibaba Cloud conference slide that week pitched the model as an operating system ([10:30](https://youtu.be/VpYU4VOicI0?t=630)).

### The data and its flaws

Hugging Face downloads show Qwen passing Llama, but a download there is any web request to the repository, so a `curl` counts. Lambert filters anomalies and still calls it only the best proxy available ([09:12](https://youtu.be/VpYU4VOicI0?t=552)). Benchmarks from Artificial Analysis and LMArena show Chinese open models going from slightly behind the best US open models about 18 months earlier to ahead, and gpt-oss would be a step for the US without reversing that ([10:30](https://youtu.be/VpYU4VOicI0?t=630), [11:34](https://youtu.be/VpYU4VOicI0?t=694)). Counting new fine-tunes on Hugging Face by month tells the same story. He points out that a CAISI report on DeepSeek had missed one person uploading thousands of models, which is the kind of mess this data needs cleaned. Mistral held a real share early on simply by being early, which to him shows the trend moves when someone releases models people care about. Summed as top Chinese labs against all US labs, cumulative adoption tipped to China over summer 2025 and the margin is growing ([14:19](https://youtu.be/VpYU4VOicI0?t=859)).

### More than two labs

Had DeepSeek and Qwen not existed, Moonshot's Kimi or Z.ai's GLM would have set off the news cycle R1 set off in January, only in the summer instead. Behind them sit Tencent, ByteDance, small startups, research labs with government funding and closer ties to academia, and Meituan, the Chinese DoorDash, which had just shipped a strong model. With that many groups trying, Lambert expects China to find the business models that make open releases pay before the US does ([11:34](https://youtu.be/VpYU4VOicI0?t=694), [12:52](https://youtu.be/VpYU4VOicI0?t=772)). The labs now care about Western coverage, and some have written to ask why they are not better represented in his.

### How long it lasts

Chinese companies often chase market share over profit, and open source fits that, so the default is that the strategy continues. The one exception he sees is political: if fast AI progress spreads through China on open models, the government may find the open ecosystem at odds with its domestic control, and might keep text models open while closing off multimodal ones ([15:56](https://youtu.be/VpYU4VOicI0?t=956)).

### Running Chinese models in American products

A benign question to R1 gets a line about core socialist values, so in practice "censored" mostly means odd propaganda turning up in a startup's app. The long-term worries, such as whether DeepSeek with tool use writes vulnerable code on purpose, cannot be proven either way. Lambert believes there is no backdoor today but calls the concern reasonable. The result is a split: large American companies avoid Chinese models and startups use them for the edge, and he expects those two positions to collide ([17:11](https://youtu.be/VpYU4VOicI0?t=1031)). That split is what [[us-scrutiny-of-chinese-model-use]] follows.

### Open models arrive regardless

The talent and resources to train good models are spreading. If twenty Chinese companies can do it, more will appear elsewhere, so the ecosystem has to be designed on that assumption and the US should lead rather than react ([18:59](https://youtu.be/VpYU4VOicI0?t=1139)). He uses Epoch AI's chart of the time lag between local and frontier models, and is more worried about multimodal models than text: within two years he expects an uncensored Sora 2 equivalent that runs on a MacBook ([20:17](https://youtu.be/VpYU4VOicI0?t=1217)).

### The ask

His reasons for open models are innovation, since American companies can adopt American open research quickly, and a hedge against concentration of power. The alternative he sketches is research moving to China and Huawei, papers written in Chinese, and NVIDIA falling behind ([21:20](https://youtu.be/VpYU4VOicI0?t=1280)). AI2's NSF grant, the largest computer science award NSF has made, was roughly $100 million over four years. Lambert says the field needs that much per year at minimum, because the frontier models' agentic abilities, tool use and long context are a different class from what open research models can do, and academics studying models from a couple of years ago risk becoming irrelevant ([22:27](https://youtu.be/VpYU4VOicI0?t=1347), [24:08](https://youtu.be/VpYU4VOicI0?t=1448)). His answer is the [[atom-project-american-truly-open-models|ATOM Project]], first called the American DeepSeek project until that name proved unfriendly in Washington: a push for a few funded centers that train scaled-up, fully open models. Most of the adoption and benchmark data in the talk was collected for it.

## Questions

On gpt-oss, the model was broken at launch, partly from complexity, and Lambert reads OpenAI's culture as not committed to it ([25:13](https://youtu.be/VpYU4VOicI0?t=1513)). Asked later what OpenAI should do, he says release often, because users drift to whatever newer model is supposedly better within months, and do the dull developer-relations work of making the model run everywhere, shipping demos and listening to users. A historically secretive company finds that culture hard ([33:54](https://youtu.be/VpYU4VOicI0?t=2034)).

On safety, he treats the lag as the protection. Open models sit months behind the frontier, years behind in the US case, and that buffer lowers the urgency of tamper-resistance work for now ([25:13](https://youtu.be/VpYU4VOicI0?t=1513)). He does not see safety and openness as strongly opposed. Basic refusal behavior is easy to train, US models tend to beat Qwen on harm benchmarks, and he would expect bio-risk work on open models to start once OpenAI's and Anthropic's frontier models raise the alarm first ([26:55](https://youtu.be/VpYU4VOicI0?t=1615), [28:37](https://youtu.be/VpYU4VOicI0?t=1717)). A questioner who had measured a 100% attack success rate on some Chinese models for some techniques got agreement, plus the remark that open models are a fourth priority for most people: they say they care and do nothing ([37:50](https://youtu.be/VpYU4VOicI0?t=2270)).

On why Chinese labs release openly at all, Lambert's guess is global influence over a powerful technology, especially in the parts of the world outside the US and China that will come to AI later and would otherwise be covered in Chinese models ([28:37](https://youtu.be/VpYU4VOicI0?t=1717)). An audience member added that DeepSeek is owned by a hedge fund that held short positions when R1 crashed the market ([33:54](https://youtu.be/VpYU4VOicI0?t=2034)).

On competing, a US open model should do what Qwen does with more transparency, because nobody knows what is in Qwen's data and so nobody fully trusts its eval numbers. A nonprofit is less exposed to lawsuits over its data than OpenAI. The cost is performance: Chinese labs can train on whatever data is best, and a transparent lab cannot use the datasets industry trains on without saying so ([30:39](https://youtu.be/VpYU4VOicI0?t=1839)). The quiet US usage he sees is well-funded, less visible American labs building on Qwen, and startups starting from Qwen by default, a habit he expects to be hard to break ([32:41](https://youtu.be/VpYU4VOicI0?t=1961)).

On [[llm-distillation|distillation]], if frontier labs clamped down on it, Chinese labs would face a delay and not a change of course. Distillation helps a lab get started, but most of the synthetic data that matters is high-volume token processing or LLM-as-judge work that other models, including local ones, can do ([41:01](https://youtu.be/VpYU4VOicI0?t=2461)). [[how-much-does-distillation-matter-for-chinese-llms]] goes further into that question.

On the shift toward RL training, he expects RL to look more like pre-training over time, with its own systems complexity. The base model still decides whether RL works, so pre-training is no longer the focus but is still essential, and the trends do not change ([35:24](https://youtu.be/VpYU4VOicI0?t=2124), [36:43](https://youtu.be/VpYU4VOicI0?t=2203)).

Asked whether he uses open models himself, he mostly does not. A local transcription model in 8 GB of RAM is the exception; for real work he sends a lot of queries to GPT-5 Pro, preferring more capability to less where his career is concerned ([45:28](https://youtu.be/VpYU4VOicI0?t=2728)).

Asked what would put open source ahead of closed models, he names a low-probability architecture change: a [[mixture-of-experts]] whose experts really are separable modules, so someone can train one on private data and others can swap it in, possibly across modalities. Better orchestration of many small specialist models is the other route, and he is not optimistic about either ([46:32](https://youtu.be/VpYU4VOicI0?t=2792), [47:47](https://youtu.be/VpYU4VOicI0?t=2867)). He also doubts adoption can ever be measured well: power users download a model once onto their own infrastructure, and seeing past that would take oversight nobody should want.

## Quotes

- "trust is actually very important when people are selecting which models to build on" ([07:38](https://youtu.be/VpYU4VOicI0?t=458))
- "a download on hugging face is essentially any web request" ([09:12](https://youtu.be/VpYU4VOicI0?t=552))
- "you need to think of open models as something that will be here no matter whether or not we are in control" ([18:59](https://youtu.be/VpYU4VOicI0?t=1139))
- "within two years we are going to have a Sora 2 equivalent that is uncensored and runnable on a MacBook" ([20:17](https://youtu.be/VpYU4VOicI0?t=1217))
- "These distillations are really good for getting off the ground" ([41:01](https://youtu.be/VpYU4VOicI0?t=2461))
- "I'm not an absolutist." ([45:28](https://youtu.be/VpYU4VOicI0?t=2728))

## Relation to other pages

The talk is the spoken version of what Lambert writes on [[interconnects|Interconnects]], and the ATOM Project it closes on has its own page at [[atom-project-american-truly-open-models]]. [[why-i-build-open-language-models]] gives his personal reasons at more length, and [[olmo]] is the model line he means when he says AI2's models are far from the frontier. The gap he describes, with open models months behind closed ones and Chinese open models ahead of American ones, is the subject of [[open-closed-model-gap]] and [[open-models-in-perpetual-catch-up]].

For the Chinese side, [[chinas-structural-advantage-in-open-source-ai]] and [[notes-from-inside-chinas-ai-labs]] take up his point that many labs trying many business models will find the ones that work. [[deepseek]] covers the R1 moment this talk builds on. The talk predates the models the reading list pairs it with: [[kimi-k3]] and [[kimi-k3-open-weights-escalation]] show the Moonshot line he mentions at the K2 stage, a year on.

His safety answers, where the lag behind the frontier works as a buffer and basic refusals are a solved problem, sit near the marginal-risk argument in [[societal-impact-of-open-foundation-models]] and the incident survey in [[myth-of-unsafe-open-source-ai]]. [[arguments-against-open-source-ai]] argues against the frontier-lab objections from the policy side, while Lambert argues from adoption numbers and national position.

Every quote above comes from YouTube's automatic captions in [[sources/lambert-china-ai-ecosystem-open-model-gap]] and has not been checked against the audio. The captions misspell most names, and this page silently corrects the ones that are unambiguous: Qwen, Kimi, OLMo, gpt-oss, Llama 4, StepFun, Meituan, LMArena, CAISI, GPT-5 Pro. "BYU" is read as Baidu, since the captions describe a company whose open releases that summer surprised people and changed its tone. The transcript groups captions into paragraphs of about a minute, so each timestamp points to the start of the paragraph containing the moment, not to the exact second.
