Editor’s Note: Jesse Marks is a Research Scholar and PhD Student at the Australian National University’s Center for Arab and Islamic Studies (CAIS) and a former Nonresident Fellow with the Stimson Center’s China Program.
By Mathew Burrows, Program Lead, Strategic Foresight Hub
Washington is trying to sell the world its AI stack. This is built on the premise that a pre-integrated American stack for general-purpose AI spares a state customer the burden of assembling a national AI capability from parts and offers a financed, turnkey path to a fully workable system. All the while, it binds that buyer to the U.S. ecosystem so tightly that separating later becomes difficult and costly, and Chinese alternatives are crowded out. In practice, it is a significant ask of governments that want optionality to accept a form of dependence they are actively trying to escape, whether dependence on China or on the United States.
The central problem with the American AI export strategy is that it is built around a lock-in theory that suits the export of frontier AI capabilities and misreads the market for general-purpose deployment. Access to frontier models is strictly controlled, and only a small number of U.S. and Chinese labs, along with their government regulators, are essentially the gatekeepers. The U.S. stack export program primarily exports AI stacks designed for deployment by bundling the hardware, models, tools, services, and applications that enable states to run AI systems at home. This deployment market is growing rapidly and becoming more competitive, with new actors entering and the proliferation of open-source models that can run on a range of hardware.
President Trump’s American AI Exports Program, established through Executive Order 14320, is the U.S. government’s main instrument for selling the domestic AI stack abroad. It organizes American firms into consortia and asks them to offer foreign buyers complete packages of AI-optimized hardware, data pipelines, models, security systems, and sectoral applications. The Commerce Department backs selected packages with diplomatic advocacy, expedited export licensing, and access to U.S. financing tools, including the Export-Import Bank’s ExportAI initiative. The first proposal window closed on June 30, and Commerce intends to issue designation decisions within 60 days of a complete submission, which will put the first designated consortia in front of foreign buyers by late summer.
The early criticism of the program has focused on the supply side. U.S. experts argue that the program may take credit for deals American firms would have closed anyway, that it names no priority markets, and that it leaves strategy to whichever consortia apply. The fix proposed by AI policy experts at the Carnegie Endowment is to run the program as economic statecraft to target swing states at risk of Chinese capture, fund only deals that would not otherwise occur, and ensure the package serves a defined geopolitical aim.
But this approach does not test the deeper premise: namely, that bundling the full U.S. stack and raising switching costs will keep foreign buyers inside the American ecosystem.
The Wrong Market for Lock-In
Middle powers, especially those from emerging strategic markets, are the primary customers for the U.S. export program. Most, however, are not trying to build the next frontier model from scratch. While many would like to develop it indigenously, most want inference capacity, sovereign data centers, locally-useful models, public-sector applications, enterprise tools, and the infrastructure to support national AI strategies. Only a few states with vast capital and strategic ambition are shopping near the frontier. The rest who cannot afford to develop, power, and train a frontier model just want to keep up with the AI adopters pack.
This is an important distinction. Frontier AI is the layer where lock-in to a single AI ecosystem is most effective as a form of statecraft. It depends on scarce advanced chips, frontier labs, proprietary models, elite engineering teams, and vast training runs. The United States and China still outpace every other competitor at that layer and, so far, continue to gatekeep frontier capabilities. A buyer that wants or needs a frontier capability has limited places to go and less leverage in accepting conditions for adoption. The supplier has leverage because the substitute or alternative is weaker, nonexistent, or too expensive for a buyer. This is what ultimately pushed the UAE’s national AI champion G42 to divest from Chinese technology investments as a condition for gaining access to U.S. frontier compute chips.
AI for general-purpose deployment operates differently. AI for deployment is modular, crowded, and increasingly substitutable. Existing labs such as OpenAI and Anthropic still matter, but they face growing competition from U.S., Chinese, European, and regional open-weight models, as well as “good enough” chips that can power national AI platforms for inference. A government that needs capable systems for public services, energy, education, finance, logistics, or Arabic-language chatbots does not always need the most advanced frontier model. It needs adequate performance, acceptable cost, local control, and confidence that access will not be turned off externally.
That is where the U.S. AI stack export strategy meets its challenge. The deployment market, especially state adopters, has more suppliers and a growing pool of reasons not to accept sweeping conditions on their AI adoption. A full American stack may be better, more secure, and easier to finance. But for many states it is also more expensive, more conditional, and more politically exposed. The U.S. value proposition therefore must justify both a higher financial cost and a higher autonomy cost. Washington has also begun to concede that state buyers may want only certain parts of the stack. The call for proposals describes the designated packages as a “menu” from which partners may procure specific layers without signing onto the whole, and a second track of on-demand consortia will assemble only the layers a given buyer requires. That said, modular procurement remains the exception rather than the desired norm. The administration launched the initiative around a preconfigured full-stack consortium that combines federal advocacy, export licensing prioritization, and financing referrals into a single package. The more flexible, on-demand option will be released later.
China’s Open Model Strategy
While the United States has focused on maintaining its frontier lead, China has focused on capturing the deployment layer by proliferating open models to undercut U.S. market share. A 2026 U.S.-China Economic and Security Review Commission report argued that China’s championing of an open-model development approach has given it an important edge in AI leadership by making its models accessible and affordable to international adopters and creating a feedback loop of widespread adoption, iteration, and further adoption. The July release of Moonshot AI’s Kimi K3 suggests that this strategy has moved beyond cheaper models and now pushes open models closer to the frontier. The open-weight model performed near leading American systems on several coding and agentic benchmarks, although its enormous compute requirements limits the number of users (corporate or individual) that can host it independently.
China’s open-model strategy is coupled with a dedicated push by Chinese authorities to deploy AI across China’s industrial base in areas such as robotics and manufacturing. The proliferation of cheaper, increasingly capable Chinese open models makes deployment more cost-effective for a wide range of enterprises, both in China and around the world, while simultaneously expanding the volume of industrial data generated across the Chinese economy. As these models become embedded in more applications, products, and industrial processes, they become the foundation on which many downstream models, developer tools, and AI applications are built globally.
The State Council’s AI+ strategy reinforces this approach by treating AI as infrastructure that should be broadly deployed across the economy rather than as an exclusive technology reserved for wealthy countries. At the 2026 World Artificial Intelligence Conference in Shanghai, Xi Jinping extended this domestic strategy into an offer to the international community offering for open-source collaboration, the wider application of AI, as well as training programs and cooperation mechanisms targeting ASEAN, the Arab League, the African Union, BRICS, and other groupings. This is a step further than just open-sourcing a model. Beijing is beginning to combine open models with dedicated training, applications, infrastructure, and institutional partnerships many states lack.
For potential sovereign buyers, Chinese open models can be modified and deployed locally without the recurring costs or direct provider dependence associated with proprietary frontier models. For some countries that have already adopted Chinese digital infrastructure, including Huawei telecommunications networks and cloud services, the cost of integrating Chinese AI into existing technology ecosystems may also be cheaper. Government buyers will, however, still require compute, cloud infrastructure, technical expertise, and continuing model support. These are costly.
The U.S. Ponders Open Source
The U.S. export program aims to erode the appeal of Chinese open models, while preserving lock-in conditions. The EXIM call for proposals requires that the entity owning a model included in a U.S. export package be at least 51 percent US-owned and free of any country-of-concern stake (e.g. China). Open-weight models are exempt from the ownership requirement, except for Chinese open models. Non-Chinese open models can qualify if a U.S. entity supplies the deployment, integration, fine-tuning, security, and support that fold the model into the package, even without owning the model outright.
This carve-out points to the strongest version of the U.S. offer. A competitive American open-weight model could answer the deployment market’s three pressures at once. It carries no recurring license fee and can run on older-generation chips that are cheaper and easier to license for export. It cannot be throttled or revoked in the same way as a closed model served through a foreign API. It can run on infrastructure the buyer may already own (or easily acquire). And it meets China’s open-weight advantage, including DeepSeek and Qwen, on comparable terms while keeping buyers inside the American ecosystem. A version of this arrangement already exists. For example, Saudi Arabia’s HUMAIN hosts OpenAI’s open GPT-OSS models in sovereign data centers. On this layer, the United States can compete on the merits.
But the same carve-out also shows the program may work against itself. It permits the adoption of open models only within a U.S.-owned service layer for deployment, integration, fine-tuning, security, and support. This is where Washington expects to capture value, retain influence, and keep visibility into use. The U.S. wrapper rebuilds a similar layer of dependence around an open model that the open model would otherwise remove.
How heavy does that US-centric wrapper weigh on sovereign buyers? If it is light (fewer restrictions), the United States may offer buyers a low-cost, low-binding alternative to Chinese open weights. If it is heavy (more restrictions and dependencies), the package may deter buyers because it reinforces the dependency structure that state buyers want to avoid.
The challenge is that both industry and government incentives push the U.S. export program toward the heavier wrapper. Leading AI labs make money from closed, metered access, not by giving away models that state buyers can run independently. U.S. security agencies, meanwhile, value the visibility and control that a managed service layer preserves. A lighter open-weight offer would be more attractive to state buyers because it would be cheaper, less revocable, and easier to operate locally. But it would also give Washington and the labs less control. The most competitive version of the open-weight strategy is therefore one U.S. suppliers are less likely to embrace at scale.
Nonetheless, Washington may now be edging toward a lighter version of its export strategy. The Trump administration and industry groups are reportedly discussing a framework for releasing U.S. open-weight models benchmarked to the capabilities of the leading Chinese open models. But the U.S. is playing catch-up here; the market is moving faster than the policy process. Coinbase, Uber, Airbnb, and Cursor have all adopted Chinese open-weight models to reduce inference costs, illustrating that American firms are already embracing precisely the type of hybrid ecosystem Washington hopes to discourage abroad. At the same time, efforts to exclude Chinese models are proving difficult to sustain domestically. The State Department warned U.S. companies about the risks associated with Chinese AI models, congressional committees have launched inquiries into Airbnb and Cursor over their reported use of Chinese AI, and U.S. officials acknowledge that once model weights are publicly released and self-hosted, they cannot realistically be recalled. A government that cannot reliably prevent domestic firms from adopting open models is unlikely to prevent sovereign governments with abundant alternatives from doing the same without rolling out severe conditions.
Heavy Conditions
Middle powers want the U.S. tech stack, but the terms of obtaining and maintaining it are still too high. The risk of overdependence is not new, but the U.S. use of equipment and capabilities as a form of interdependent leverage has become an increasingly common feature of U.S. foreign policy. Washington previously limited the supply of advanced arms and technology, or slowed down transfers, when a partner’s choices displeased the White House. Canadian Prime Minister Mark Carney has also voiced concerns that overdependence on foreign AI can create dependencies that give foreign powers leverage over Canada’s sovereign decision-making. This is a view generally held by many middle powers, including the European Union, who in June adopted a series of AI sovereignty measures designed to lessen their AI dependency on foreign providers.
In June, Washington gave prospective buyers a live demonstration of how quickly access to the American AI stack could be turned off. Just two weeks before applications to the AI Export Program were due, Commerce implemented temporary export controls on June 12 to suspend foreign-national access to Anthropic’s Fable 5 and Mythos 5. OpenAI later delayed the wider release of GPT-5.6 at the government’s request and initially limited access to a small group of vetted customers. Commerce lifted the Anthropic restrictions on June 30, the day bids for the export program closed. While there were legitimate cybersecurity justifications for withholding the models, the U.S. government decision sharpened concerns among potential states customers, notably India, that Washington was willing to retain an effective “kill switch” over critical parts of the American AI stack.
This episode again reinforced a growing view that upstream technical and political developments have a strong local effect. Technical lock-in and political lock-in need to be understood as separate concerns. At the deployment layer, technical lock-in may weaken over time as models, chips, and integrators become more substitutable and the know-how to build less complex chips and components diffuses. Political lock-in, meanwhile, can remain strong because licenses, security conditions, financing, and exclusion rules make access contingent on compliance. A state’s compute — whether rented through a hyperscaler API like AWS or run on U.S. advanced chips — has been the easiest point in the stack for Washington to leverage, since cutting it off renders the AI system largely inoperable. A full-stack package gives the U.S. the power to deny access and view how states use it, so a state buyer has to calculate the risk that those conditions will be implicit in the acquisition of a U.S. stack.
States recognize that AI, like any other resource or capability, is bound by some degree of interdependence. It is impossible to fully eliminate dependence within the AI stack, but the strategic question is how to manage it. That means determining which layers of the stack to control, which dependencies to tolerate, and which suppliers to keep at arm’s length. The states Washington most wants to reach, such as the Gulf Arab states, tend to approach the purchase of AI capabilities as a form of statecraft. The expansive buildouts in the region operate on the premise that money spent in the near term on bringing in foreign models and cloud computing is a long-term investment in localizing the AI ecosystem without ceding control to any single supplier.
That makes them careful AI hedgers capable of spreading dependence across numerous providers while maintaining the option to switch suppliers if necessary and accept reliance only where no substitute exists. Some, especially in the Gulf, also have long-term ambitions to re-export AI capabilities and services themselves, which makes them potential long-term rivals as much as customers. A government with that ambition is unlikely to buy an AI stack that narrows its room to maneuver unless the payoff — the U.S. being the first actor to reach artificial general intelligence (AGI) — is overwhelming.
Pushing Hybridization
Whether the U.S. strategy can attract these buyers will be shaped by four factors: substitutability, cost, conditionality, and political alignment.
The U.S. and Chinese stacks are still the closest options to a full-stack AI offer, but middle powers are already working around that constraint. They are instead identifying specific layers where they can build domestic capacity or preserve room to maneuver. They are isolating the parts of the stack they can cultivate into sources of leverage, resilience, or control. France offers one example. Its move away from reliance on U.S. suppliers in sensitive areas, including Palantir for intelligence services and Microsoft Azure for health data, reflects a wider effort to assert greater sovereignty over its digital and AI ecosystem and reduce future points of leverage in its bilateral relationship with Washington. Germany and Denmark are moving in the same direction, replacing Microsoft products across government systems.
The lesson is that state buyers do not need to replace the full American stack to reduce their dependency. They only need enough alternatives at enough layers to make the system work. A state can accept U.S. financing, use a European or domestic cloud provider, run an open-weight model, hire local integrators, and reserve frontier-chip access for a narrow set of national projects.
This partial substitution may be sufficient to keep any foreign partnership from becoming a long-term cage. Most buyers will not defect wholesale to China, since many states fear dependency on Beijing as much as dependency on Washington. The strategic danger for the United States is the growing optionality. State buyers are learning to assemble workable AI systems from multiple suppliers, leaving the United States with influence over pieces of the stack rather than control over the whole.
The second factor is affordability. AI is an expensive investment, and even with U.S. financing options, the cost of the stack will decide much of the deployment market. Many state customers are buying AI systems for general-use deployment, like running public services, supporting industry, automating administration, and building national platforms at scale. In those use cases, a cheaper system that performs well enough can beat a superior but expensive, conditional, and hard-to-procure system. This is why some countries adopted cheaper, but good-enough Chinese models.
The earlier U.S.-China 5G deployment battle offers an important lesson: U.S. security arguments about adopting Chinese systems as core infrastructure lose force when state customers are told to reject the affordable option without receiving credible substitutes. For nearly five years, Jordan sought a 5G partner and aimed to adopt Huawei’s technology. U.S. officials pushed back, but the cash-strapped Kingdom had no affordable alternative for nearly three years, until a deal with Ericsson satisfied both the budget and the pressure. Other countries with fewer options gravitated into China’s 5G ecosystem on cost alone. The lesson for AI is that a premium American stack may win elite projects, but it will not necessarily win the national buildout if a cheaper, functionally equivalent stack is available from another partner.
The third factor is the attached conditions of purchase. Procurement rules, vendor exclusions, security requirements, data-handling constraints, update controls, licensing discretion, and revocation risk all shape how much authority a state buyer retains if choosing to import an AI stack. For governments treating AI as sovereign infrastructure, these terms may matter as much as model performance. A state may ultimately resist arrangements that give the supplier enduring power over how a national system evolves. In some cases, the most attractive option is the one that leaves the buyer with its agency intact and room to govern, even when a more technically advanced package is on offer. This creates a complex tradeoff between choosing an AI ecosystem based on near-term sovereignty and dependency with the long-term bet on who reaches AGI first. Most states seem to align with the former priority, though some unique cases, like the UAE, are hedging for an AGI future.
The fourth factor is political alignment. States may choose an AI stack partly according to the political order they believe it will reinforce. Concerns about China’s use and export of AI-enabled censorship and surveillance may give the United States an advantage among governments wary that Chinese technology could embed authoritarian practices in their own digital infrastructure. Japan and South Korea are likely to view that risk through the lens of their alliance relationships. Both are U.S. treaty allies, deeply integrated with American technology and security networks, and investing heavily in domestic AI capacity. The American stack is therefore their most natural external partner, even as both pursue greater national control over critical technologies.
Europe presents a different form of political alignment. The European Union increasingly defines technological sovereignty as the ability to reduce dependence on non-European providers. Its proposed Cloud and AI Development Act identifies excessive reliance on foreign cloud firms as a risk to European autonomy and resilience, while a 2025 European Parliament study warns that dependence on U.S. technology can expose European governments and firms to the CLOUD Act, sanctions, and possible foreign access to data stored within Europe. The lesson is that Washington will retain a political advantage only if buyers believe that American technological power is built on transparent rules, legal recourse, and safeguards against intrusive surveillance, and guarantees of extraterritorial control.
Creating Better Export Options
There are clear benefits to entering the U.S. AI ecosystem. The current state of U.S. partnerships, however, shaped by two years of demonstrated willingness in Washington to condition, suspend, and revoke access, has prompted many partners to rethink arrangements that were more palatable a few years ago. Washington should consider outcompeting through openness, using American open-weight models and exportable infrastructure to give middle powers a better alternative than China. The U.S. can learn from the 5G debate that competing through exclusion – demanding that buyers refuse Chinese technology without offering them an affordable alternative – forces partners to choose between affordability and their own sovereignty. The June suspensions of U.S. frontier models taught potential buyers an important lesson, namely that buying a U.S. system and fulfilling the conditions does not necessarily guarantee you the best or most advanced systems. The more the U.S. package resembles a controlled ecosystem, the more state buyers will seek to disaggregate the stack and pick and choose among a growing menu of options. The more it looks like an affordable, open, exportable, low-binding path, the more durable the American pitch becomes.

Community Adaptation for a Water Festival Without Clean Water