China's AI Gambit: How DeepSeek and Qwen Are Rewriting the Rules

Return to Part 0: Table of ContentsPrevious Article: Part 9 — Digital Sovereignty in 2026: Your Data, Their Rules


GEN AI TUESDAYPart 10 | Chapter 2.2 | Section II: The Splinternet



In December 2025, a Chinese AI lab published a benchmark result that stopped Silicon Valley mid-sentence. According to DeepSeek's technical report, its V3.2-Speciale variant scored 96.0% on the American Invitational Mathematics Examination, against a reported 94.6% for GPT-5 High and comparable performance to Gemini 3.0 Pro across elite reasoning tasks [1]. The model that achieved this had been trained on hardware that US export controls classified as below the threshold for frontier AI development. Not smuggled frontier chips. Not an academic exercise. Legally available hardware, used with unusual ingenuity.

The United States has spent three years restricting China's access to advanced AI chips. The theory was clean: no frontier silicon, no competitive models. The result is more complicated. Forced to work within constraints, Chinese AI labs developed architectural innovations that now give them structural cost advantages that persist even when chip restrictions ease. Alibaba's Qwen 3.5 flagship, released in February 2026, packs 397 billion parameters while activating only 17 billion per inference, decodes 19 times faster than its predecessor at long contexts, and costs approximately one-eighteenth of Google's Gemini 3 Pro to run [2]. These are not incremental gains. They reflect a fundamentally different design philosophy.

This is the China AI gambit. Not cheap imitation, but constraint-driven engineering that has reshaped the competitive landscape in ways that US export policy did not intend.


The Efficiency Paradox

Understanding why requires looking at the architecture, not the geopolitics.

Dense neural networks, the kind that dominated AI development through 2023, activate every parameter for every token they process. Running a 100-billion-parameter dense model means 100 billion parameters doing work on every single word, every single time. That is computationally expensive. It requires enormous GPU clusters. It demands the kind of high-bandwidth memory that US export controls specifically targeted.

Chinese labs, blocked from the most advanced hardware, needed another way. The answer was mixture-of-experts architecture applied with surgical discipline. DeepSeek V3.2 contains 685 billion total parameters, but only 37 billion activate for any given inference [1]. The model has the knowledge capacity of a 685-billion-parameter system with the computational cost of a 37-billion-parameter one. Alibaba's Qwen 3.5 takes this further: 397 billion total parameters, 17 billion active per token, running on hardware that many organisations already own [2].

The result is that DeepSeek's API starts at approximately $0.27 per million tokens for inputs, against $2.50 for GPT-5.4 and $15.00 for Claude Opus 4.6 [3]. That is not a small pricing gap. At scale, it changes the unit economics of AI deployment entirely.

There is a paradox buried in here. DeepSeek's CEO, Liang Wenfeng, stated publicly that export restrictions were the central problem his team faced [4]. The export control regime intended to prevent China from reaching frontier AI capability. Instead, it pushed Chinese labs to optimise so aggressively that they now produce frontier results with less compute than anyone expected was possible. The engineers at DeepSeek and Alibaba solved a resource constraint problem and produced an architectural advantage in the process.

This does not mean export controls failed entirely. DeepSeek is reportedly still constrained by hardware access; roughly 75% of AI training chips in Chinese data centres run on Nvidia's CUDA platform, and Chinese domestic alternatives cannot yet sustain frontier-level model development without access to Nvidia hardware [5]. The gap has not closed. But it has narrowed in ways that change what enterprise leaders need to think about.


What Chinese AI Looks Like in March 2026

The Chinese open-weight ecosystem has matured significantly since DeepSeek-R1 arrived in January 2025 and briefly crashed Nvidia's stock price.

DeepSeek V3.2 is the current general-purpose workhorse: 685 billion total parameters, 37 billion active, strong on reasoning and coding. According to DeepSeek's benchmarks, the V3.2-Speciale variant achieves gold-medal-equivalent performance at the International Mathematical Olympiad (35 out of 42 points) and 96.0% on AIME [1]. The architecture uses Multi-Head Latent Attention alongside mixture-of-experts, which reduces memory pressure at long contexts. A dedicated reasoning model successor, reportedly designated R2, was in progress as of March 2026, though no release date has been confirmed [6].

Alibaba Qwen 3.5, released 16 February 2026, is the more enterprise-ready family. The flagship 397B-A17B model ships under Apache 2.0, meaning it is genuinely open for commercial deployment. Eight model sizes span from 0.8 billion parameters (running on a phone) to 397 billion. Every model in the family handles 201 languages and dialects, up from 119 in the previous generation [2]. According to analysis cited by ChinaTalk drawing on Stanford HAI data, Qwen surpassed Meta's Llama to become the most-downloaded model family on Hugging Face in late 2025, with over 385 million downloads [9]. For organisations looking to build private, on-premise AI deployments, Qwen 3.5 offers a credible option at every hardware tier.

One development worth monitoring: Qwen's lead researcher, Lin Junyang, resigned from Alibaba on 4 March 2026, following an internal reorganisation. Multiple Qwen team members also expressed concern about the change in leadership. Lin posted a message on WeChat signalling continuity for the team, but his return was unconfirmed at write time [8]. The future development trajectory of the Qwen family carries that uncertainty. Verify current status before publishing.

Beyond DeepSeek and Qwen, the broader Chinese open-source ecosystem is active. ByteDance, Baidu, Moonshot AI (Kimi), and Zhipu AI are all producing competitive models. In March 2025, a Chinese startup named Butterfly Effect launched Manus, described as the first general-purpose AI agent. China does not dominate every benchmark. It does dominate the open-weight space, particularly in cost efficiency and multilingual coverage.


The Data Residency Fork

Part 9 of this series established that your data is always somewhere, and somewhere means subject to specific laws. The same principle applies to the models you use.

When you call DeepSeek's API or use Alibaba Cloud's Qwen3.5-Plus, your prompts, outputs, and potentially your data travel to servers in China. DeepSeek's own privacy policy acknowledges that it collects chat histories, device identifiers, keystroke patterns, and IP addresses, storing them on servers in China [10]. China's 2017 National Intelligence Law requires organisations operating in China to "support, assist, and cooperate with national intelligence efforts" on request [11]. That is not a conspiracy theory. It is the statutory text.

This is the same jurisdictional reality that triggered government bans in Australia, Italy, Taiwan, South Korea, the Czech Republic, the Netherlands, and multiple US federal agencies within weeks of DeepSeek's January 2025 release [12]. New Zealand's NCSC stated in early 2025 that it was continuing to develop its position on this application in conjunction with other government officials, and reminded organisations that by installing any application or interacting with any interface, users may be agreeing that their data will be subject to the legal and privacy requirements of the nation that the company operates under, which can differ substantially from New Zealand's laws and protections [13].

There are two distinct ways to use Chinese open-weight models that carry very different risk profiles. Conflating them is the most common mistake enterprise leaders make.

Via managed API: Your data flows to Chinese cloud infrastructure. For personal queries or non-sensitive tasks, the risk is low. For anything involving client data, internal intellectual property, or regulated information, the data residency and jurisdiction implications are material. This is the configuration that triggered government bans.

Via self-hosted deployment: You download the model weights (typically from Hugging Face under Apache 2.0 or MIT licence), run inference on your own infrastructure, and never send a query to Chinese servers. No data flows to China. The jurisdictional risk of the managed API does not apply. Qwen 3.5's smallest models run on a modern laptop. The 27B variant runs on a server with a single consumer-grade GPU. The 397B flagship requires eight GPUs but is well within reach for a mid-sized technology team.

Self-hosting resolves the data residency problem. It does not resolve the training data provenance question. When you run a Chinese open-weight model on your infrastructure, you are running a system whose training data, fine-tuning decisions, and safety alignment were made by a lab operating under Chinese law, subject to Chinese content restrictions, and not subject to independent external audit. DeepSeek models reportedly implement content filters that refuse certain topics with historical and political sensitivity [14]. Alibaba's Qwen models carry similar restrictions. For most enterprise use cases, this is not a material concern. For use cases involving information integrity, legal analysis, or any domain where completeness matters, it deserves explicit evaluation.

Self-hosting also introduces a supply chain trust dimension. Open-weight models are open in the sense that the weights are published. They are not open in the sense that training data and full training pipelines are disclosed. The weights you download are the output of a process you cannot independently verify. This is the same concern that applies to any proprietary model, but it sits alongside the additional context of operating under a national legal regime with different obligations to the state.

None of this is a reason to refuse engagement with Chinese AI. It is a reason to distinguish clearly between deployment configurations before you deploy.


The Security Governance Reality

The security concerns around Chinese AI models are real but frequently mischaracterised. The managed API risks, outlined above, are structural and worth taking seriously. The code quality of the models themselves is a different question.

Security researchers have documented legitimate infrastructure vulnerabilities in DeepSeek's cloud services. Researchers at Wiz discovered a publicly accessible database exposing over one million records including chat histories and API keys, with no authentication controls [15]. NowSecure found hardcoded encryption keys and unencrypted data transmissions in the mobile applications [16]. Security researchers at Feroot Security identified hidden code linking DeepSeek's web platform to an authentication registry operated by a Chinese telecommunications company [17]. These are genuine cloud security failures at the infrastructure level.

They are distinct from the model weights themselves. A self-hosted DeepSeek or Qwen model does not carry these infrastructure vulnerabilities. The concerns above are about DeepSeek's cloud operations, not the architecture of the neural network.

The model-level concern worth taking seriously is alignment robustness. Independent security testing has documented significantly higher jailbreak success rates for DeepSeek models under adversarial prompting compared with leading Western models [18]. For use cases where output reliability and resistance to manipulation matter, this is worth factoring into your deployment decision. For general productivity and analysis tasks in a governed environment, it is less material. If you are deploying for sensitive use cases, test alignment characteristics before committing.

Organisations operating in New Zealand's public sector, under the Government Chief Digital Officer's Responsible AI Guidance for the Public Service [19], face specific obligations around security, procurement, and governance that make the deployment configuration decision more than a cost question. The guidance identifies security as a foundational consideration; agencies need to assess the security implications of any AI system they deploy. The data residency framing from Part 9 applies directly: where is inference happening, under whose law, and who is reviewing the outputs?

For organisations in New Zealand's private sector, IPP 3A takes effect on 1 May 2026. It requires notification when personal information is collected from third parties. If your AI deployment routes prompts containing personal information through Chinese cloud infrastructure, your notification obligations under the updated Privacy Act are worth reviewing in the next six weeks [20].


The Gutenberg Fork, Again

The original Gutenberg parallel in this series framed the democratisation question as whether AI capability would distribute broadly or concentrate in the hands of a few. Chinese open-weight models represent a specific answer to that question: the capability is distributing, and it is distributing in a way that Western frontier labs did not anticipate or welcome.

But the democratisation story has a complication. The models most effectively democratising access to frontier AI capability are products of a state-backed technology ecosystem with specific policy obligations and content restrictions. When DeepSeek becomes the model powering educational chatbots in Tamil Nadu, health information services in Lagos, and software development tools in Wellington, it brings with it the training decisions and content constraints of the lab that built it.

The Gutenberg press democratised the written word. It also enabled the rapid spread of propaganda, misinformation, and religious conflict alongside science, commerce, and humanism. The technology was agnostic; the social consequences were not. Chinese open-weight models are in a similar position. They are genuinely broadening access to sophisticated AI capability. They are also carrying the governance assumptions and regulatory context of their origin.

This is not an argument against using them. It is an argument for using them with clarity about what they are. The distinction between "an open-weight model I run on my own infrastructure, understanding its training origins" and "a managed cloud service routed through Chinese data centres" is the distinction between informed deployment and uninformed exposure.

Enterprise leaders who navigate this best will treat model selection as an architectural decision, not a procurement one. As the AI-EA Model's Agent Personas thesis establishes: what capability do I need? What data will it process? Where will inference run? Whose law governs that inference? What are the alignment and content assumptions in the model? These are architecture questions. They deserve the same rigour you would apply to choosing a database or a cloud provider.


What This Means for Enterprise Leaders

The practical decision framework is cleaner than the geopolitical noise suggests.

Step 1: Classify your data. If the use case involves no personal information, no intellectual property, and no regulated data, managed API access to Chinese models is a reasonable cost-performance choice. If it involves any of those categories, self-hosting is the appropriate configuration.

Step 2: Evaluate the capability fit. Qwen 3.5 and DeepSeek V3.2 perform strongly on coding, mathematical reasoning, and multilingual tasks. They perform less strongly than specialist Western models on tasks requiring broad world knowledge, nuanced English prose, or alignment with Western legal and regulatory frameworks. Match the model to the task.

Step 3: Test the alignment assumptions. If your use case involves any topic where completeness and neutrality are material, test the Chinese model's response characteristics against your requirements before deployment. Content filters are not a binary risk; they are a specificity question. Know what your model will and will not engage with.

Step 4: Implement supply chain governance. Self-hosted models require the same governance discipline as any other enterprise software component: version pinning, security scanning of downloaded weights, change management for model updates, and documentation of training provenance for compliance purposes. Treat model weights as you would treat a software dependency.

For organisations operating under the GCDO's Responsible AI framework, the security and procurement sections provide governance scaffolding for Steps 3 and 4. For private-sector organisations, the IPP 3A compliance window is the practical forcing function to clarify Steps 1 and 2.

The Chinese AI ecosystem is not going away. DeepSeek and Qwen are serious engineering achievements from serious engineering teams operating under significant constraints. The appropriate enterprise response is not paranoia and not naivety. It is the same thing it always is in architecture: clarity about what you are deploying, where it runs, and who is responsible for what.


Executive Takeaway

The China efficiency story is structural, not transient. Mixture-of-experts architecture, developed under hardware constraints, gives Chinese labs cost-performance advantages that are likely to persist even as chip restrictions evolve. Factor this into your model selection approach.

Open-weight is not the same as open-source. DeepSeek and Qwen publish model weights; they do not publish training data or full training pipelines. Self-hosted deployment bypasses data residency risk but not training provenance questions.

The deployment configuration matters more than the model brand. Self-hosted Chinese models and Chinese managed APIs are fundamentally different propositions from a data sovereignty and governance perspective. Treat them as separate decisions.

IPP 3A arrives on 1 May 2026. If your AI deployment routes personal information to cloud infrastructure under foreign jurisdiction, review your notification obligations under the updated Privacy Act within the next six weeks.

Model selection is an architecture decision. The right question is not "are Chinese models safe?" The right question is "what data, at what risk level, in what deployment configuration, for what capability requirement?" The answer will differ by use case.

New Zealand's NCSC has not issued a formal ban. At time of publication, there is no formal prohibition on Chinese AI models in New Zealand. The GCDO Responsible AI Guidance applies to public sector deployments. Private-sector organisations should document their deployment configuration decisions now, before the regulatory position clarifies.


What would change about your current AI procurement decisions if you treated model origin, training data jurisdiction, and inference infrastructure as architectural variables with the same weight you give to cloud provider selection?

Next week in Part 11: Europe's AI Act, Africa's Leapfrog, and What They Mean for Your Strategy.


The views expressed in this article are entirely my own, informed by more than 30 years of professional experience in architecture, security, and technology leadership in New Zealand. They do not represent the views of my employer, any government agency, or the New Zealand government. My commentary on legislation and policy is analytical, drawing on publicly available sources and my professional expertise in architecture, security, and AI governance. I follow the Public Service Commissioner's Code of Conduct for the Public Sector and social media guidance.


Andreas Hamberger is a New Zealand leader in Architecture & Security and Associate Member of the Institute of Directors. The Hamberger Report: Generative AI 2026 provides enterprise leaders with evidence-based analysis of the AI landscape.


I use AI tools, including Sudowrite, Claude, Perplexity AI, DeepSeek AI, ChatGPT, Grok, Copilot, Openart and Gemini, as deliberate production tools, not ghostwriters. This is consistent with my position: AI amplifies human judgement; it does not replace it. The frameworks, arguments, and editorial decisions in this series are original work. AI accelerated the process. The thinking is mine.


[1] DeepSeek. "DeepSeek V3.2 Technical Report." December 2025. https://www.deepseek.com; confirmed by InfoQ, January 2026. https://www.infoq.com/news/2026/01/deepseek-v32/

[2] Alibaba Qwen Team. "Qwen 3.5 Model Family Release." February 2026. https://qwen.ai/blog; VentureBeat. "Alibaba's Qwen 3.5 397B-A17B." February 2026. https://venturebeat.com/technology/alibabas-qwen-3-5-397b-a17-beats-its-larger-trillion-parameter-model

[3] DeepSeek API Pricing. Accessed March 2026. https://platform.deepseek.com/api-docs/pricing; OpenAI Pricing Page. Accessed March 2026. https://openai.com/pricing; Anthropic Pricing. Accessed March 2026. https://www.anthropic.com/pricing (Note: Claude is both writing tool and referenced product in this article; attribution language applied throughout.)

[4] CSIS. "Understanding the Biden Administration's Updated Export Controls." Citing Liang Wenfeng interview. 2025. https://www.csis.org/analysis/understanding-biden-administrations-updated-export-controls

[5] Built In. "Trump Lifts AI Chip Ban; China and Nvidia." Citing Jay Dawani, Lemurian Labs. 2026. https://builtin.com/articles/trump-lifts-ai-chip-ban-china-nvidia

[6] Raschka, S. "Technical DeepSeek Analysis." Sebastian Raschka's Substack. 2025-26. https://magazine.sebastianraschka.com/p/technical-deepseek; InfoQ. January 2026. https://www.infoq.com/news/2026/01/deepseek-v32/

[7] Enclave AI. "Qwen 3.5 Complete Model Family: Local AI." March 2026. https://enclaveai.app/blog/2026/03/08/qwen-3-5-complete-model-family-local-ai/ (Alibaba benchmark; not independently replicated by third party.)

[8] Willison, S. "Lin Junyang Qwen Update." simonwillison.net. 4 March 2026. https://simonwillison.net/2026/Mar/4/qwen/ (Citing 36Kr original report.)

[9] ChinaTalk. "China AI in 2025 Wrapped." Citing Alibaba/Stanford HAI data. December 2025. https://www.chinatalk.media/p/china-ai-in-2025-wrapped

[10] Free-Codecs. "Is DeepSeek Safe? Privacy Concerns and Security Flaws Explained." Citing DeepSeek privacy policy. 2025. https://www.free-codecs.com/news/is-deepseek-safe-privacy-concerns-security-flaws-and-global-bans-explained.htm (Verify against primary DeepSeek privacy policy at https://www.deepseek.com/privacy before publication.)

[11] China National Intelligence Law 2017. Art. 7. Multiple legal analyses confirm statutory text, including EDPB analysis. See Axis Intelligence summary: https://axis-intelligence.com/is-deepseek-safe-2026-security-concerns/

[12] Insurance Journal. "DeepSeek Bans Spreading Worldwide." January 2026. https://www.insurancejournal.com/news/international/2026/01/07/853376.htm

[13] Interest.co.nz. "Chinese AI DeepSeek Copping Bans: What Is New Zealand's Position?" Citing NCSC spokesperson. 2025. https://www.interest.co.nz/technology/131817/chinese-ai-deepseek-copping-bans-official-use-around-world-what-new-zealands

[14] Axis Intelligence. "Is DeepSeek Safe 2026? Security Concerns." 2026. https://axis-intelligence.com/is-deepseek-safe-2026-security-concerns/

[15] Krebs on Security. "Experts Flag Security, Privacy Risks in DeepSeek AI App." February 2025. Citing Wiz Security research. https://krebsonsecurity.com/2025/02/experts-flag-security-privacy-risks-in-deepseek-ai-app/

[16] Krebs on Security. "Experts Flag Security, Privacy Risks in DeepSeek AI App." February 2025. Citing NowSecure research. https://krebsonsecurity.com/2025/02/experts-flag-security-privacy-risks-in-deepseek-ai-app/

[17] Introl. "DeepSeek Government Bans Spreading Worldwide 2026." Citing Feroot Security analysis. 2026. https://introl.com/blog/deepseek-government-bans-spreading-worldwide-2026 (Verify from Feroot Security primary publication before use.)

[18] Axis Intelligence. "Is DeepSeek Safe 2026?" Citing independent security testing. 2026. https://axis-intelligence.com/is-deepseek-safe-2026-security-concerns/ (Primary source for jailbreak testing methodology not confirmed; directional language used throughout article. Verify primary source before publication.)

[19] Government Chief Digital Officer. "Responsible AI Guidance for the Public Service (GenAI)." February 2025. https://www.digital.govt.nz

[20] Office of the Privacy Commissioner. "Privacy Amendment Act 2025 / IPP 3A Guidance." Commencement: 1 May 2026. https://www.legislation.govt.nz

Previous
Previous

EU AI Act, Africa's Leapfrog, and What They Mean for Your Strategy

Next
Next

The Heaven Vector: When AI Actually Works for People