Insights Business| SaaS| Technology The US-China AI Stack Split and How to Manage Supplier Risk
Business
|
SaaS
|
Technology
Aug 18, 2026

The US-China AI Stack Split and How to Manage Supplier Risk

AUTHOR

James A. Wondrasek James A. Wondrasek
The US-China AI Stack Split and How to Manage Supplier Risk

The AI market has split into two ecosystems. A vendor choice made for cost today can harden into a strategic dependency as the stacks drift apart. By the end you’ll hold a four-layer model of the split and a way to score geopolitical and export-control risk, so sourcing is defensible.

What are the US and China AI stacks, and why are they becoming incompatible?

BCG’s “The Great Divide” frames it plainly: each country is building an AI stack designed to reduce dependence on the other, which makes the two stacks increasingly incompatible. Think of four layers: chips, cloud and compute, models, applications, with a governance overlay of data rules and export controls.

The US stack runs on NVIDIA chips and CUDA, US hyperscaler cloud, and closed frontier models from OpenAI, Anthropic and Google. China’s stack runs on Huawei Ascend and CANN, domestic clouds, and open-weight models from DeepSeek, Alibaba’s Qwen and Moonshot Kimi.

The split is most pronounced at the chip layer, where code written for CUDA does not port to CANN without rewrites. Stanford HAI’s DigiChina brief tracks China’s open-weight ecosystem alongside the bifurcation.

The trade-off is US capability plus access risk versus Chinese cost plus adoption. That gap is why the cheap Chinese model layer matters and why distillation became a security question.

How do US export controls shape Chinese AI lab strategy?

That decoupling was engineered by export controls. US Commerce and BIS restrict AI chips, chipmaking equipment and, increasingly, frontier-model access to China. Compute became scarce, so Chinese labs adapted with efficiency-first design.

Look at Mixture-of-Experts architectures, sparse attention and aggressive quantization. It also pushed toward domestic silicon: Huawei Ascend, SMIC and Cambricon are scaling as foundries trail on advanced-node fabrication. Controls leak too, with Epoch AI estimating roughly 660,000 H100-equivalents smuggled into China through 2025.

That scarcity is the direct reason Chinese open-weight models became so cheap, a cost gap feeding the wider open-source AI story. The “AI+” initiative then acts as the demand signal pulling that capacity into real deployments.

What is China’s “AI+” initiative, and what does it mean for AI adoption?

“AI+” is China’s state-led push to embed AI across manufacturing, health, finance, government and everyday life. It subsidises adoption and channels home-grown models and Huawei chips into real projects, a flywheel of adoption, data and better models.

BCG tracks over 70% penetration of AI-enabled devices and software agents by 2027 and over 90% by 2030. CSIS notes the money behind it: an $8 billion National AI Investment Fund in 2025 and a $295 billion infrastructure plan in 2026.

For you, the signal is that Chinese models will keep improving fast on domestic data, and the bifurcation sustains itself.

NVIDIA CUDA versus Huawei Ascend: how big is the gap for real-world AI workloads?

The bifurcation becomes concrete at the hardware layer. Most production AI code is written for CUDA, and Huawei’s CANN toolchain is not a drop-in replacement. Moving between them means code rewrites.

Ascend still trails NVIDIA on raw performance, memory and bandwidth, likely staying well behind Blackwell and Rubin GPUs at the single-chip level, though Huawei clusters chips into larger systems to compensate, per Brookings. It is improving and delivers cheaper per-token economics for some workloads.

DeepSeek’s V4, released in April 2026, is optimised for inference on Huawei’s Ascend chips, a signal that the Chinese model layer is being tuned for domestic silicon.

The takeaway is portability: design for stack mobility, because switching is re-engineering, and keep portability in your evaluation framework.

How do I assess geopolitical and export-control risk when selecting an AI model vendor?

Geopolitics is a scoring layer you add on top of technical fit. You can score each vendor on five factors: lab jurisdiction, chip supply chain, US compliance exposure, secondary-sanction exposure, and continuity of model access.

The kill-switch question is the one to weigh first: can the provider, or a government, revoke access to the model or the compute it runs on? In June 2026, export controls forced Anthropic to pull its Mythos and Fable models for all customers, as PIIE documents.

US closed APIs concentrate access risk; Chinese models carry sanctions and compliance exposure in the other direction. Mistral and the EU sit outside both poles as a de-risking leg, though with a smaller ecosystem. This matches the vendor risk-assessment logic for open and closed models.

Outside both blocs, neither pole is automatically safe. CAPRI’s read: the risk has to be assessed, not assumed.

How do I decide between self-hosting open-weight models and depending on closed-model APIs?

It’s a control-versus-convenience decision. A closed API gives you leading performance with minimal operations, but the provider can change terms or cut you off. Self-hosting an open-weight model removes the remote kill switch, but you own security, updates and infrastructure.

Per-token prices understate the real cost. BCG’s comparison puts Kimi K2.6 at $1.71 per million tokens against GPT-5.5 at $11.25, but once you count people and operations, an API is often cheaper for small workloads. Those figures will age quickly.

Regulated or data-sensitive workloads lean toward self-hosting; low-risk, fast-moving work can sit on an API. A hybrid position is usually the better option: a US frontier API paired with a self-hosted open-weight fallback, plus a clear read on the licence and governance terms.

How do I evaluate Chinese-origin models against data-residency and compliance constraints?

The decisive questions are where inference runs, who can see the data, and what your client contracts and regulators require. You can map data flow and inference location against Australian and APAC privacy law and health and finance sector rules.

Client contracts may prohibit certain jurisdictions or sub-processors. Self-hosting a Chinese open-weight model can keep data in your own Australian infrastructure, but it raises governance questions. A model registry, verified provenance and an AI bill of materials belong in place, per the supply-chain due-diligence guidance. Self-hosting is not automatic compliance.

The Huawei ecosystem warrants caution because sanctions exposure can ripple into downstream contracting. And check whether a “sovereign cloud” label reflects real independence.

The split has become a supplier-selection discipline. You can now locate where the decoupling bites by layer and score vendors on the same factors.

The response is a non-aligned, evidence-based posture: self-hosted open weights where data control matters, a hybrid multi-vendor setup for resilience, and a standing habit of re-scoring suppliers. That is the evaluation framework in one sentence. For buyers outside both blocs, that measured playbook is the defensible position: neither superpower’s stack is automatically safe, but a dependency you understand and plan around is different from one you walked into.

Frequently Asked Questions

Is Chinese AI actually behind the United States?

No, not across the whole stack. The US leads on chips and closed frontier models, while China leads on open-weight diffusion, cost and domestic adoption. “Behind” is the wrong frame because the gap is uneven by layer. Export controls slowed China’s chip supply but redirected labs toward efficiency-first design, which is precisely why Chinese open-weight models became cheap and widely adopted.

Do I need to pick a side between the US and China?

No. Australia sits outside both blocs, so the defensible position is a non-aligned, evidence-based sourcing playbook rather than a bet on either pole. The task is to score each vendor on jurisdiction, chip supply, compliance exposure and continuity of access, then match your posture to your actual exposure. Neither superpower’s stack is automatically safe for an Australian or APAC buyer.

What does “secondary-sanction exposure” actually mean?

It means risk that reaches you through a vendor’s own connections, even when your direct activity is legal. If a supplier depends on sanctioned chips, entities or financing, your contract can inherit that exposure, and downstream clients or partners may decline to work with you. In vendor scoring it is a separate factor from primary US compliance exposure, because the risk travels through the supply chain.

Can I switch AI vendors later if the stacks split further?

Yes, but only if you design for portability now. The real friction is software inertia: code optimised for CUDA does not move to Huawei’s CANN toolchain without rewrites. Treat switching as re-engineering rather than re-provisioning and you can price the real cost. Portability and multi-vendor evaluation belong in the initial selection, not as an afterthought.

Is Mistral really a viable third option for an Australian company?

It can be, as a de-risking path rather than a full substitute. Mistral and the broader EU ecosystem sit outside the two poles and offer a partial third route for open-weight and sovereignty-minded deployments. The trade-off is a smaller ecosystem and less frontier polish. For non-aligned buyers it works best as one leg of a multi-vendor posture, not a total replacement.

What does “open-weight” actually mean, and is it the same as open source?

Not exactly. Open-weight models publish the trained weights so you can self-host and modify them, but the licence and training data may still be restricted. Open source is a stricter standard covering code, data and reuse rights. For supplier risk, the practical difference is control: open weights remove the remote cutoff, but you still need to review the licence, provenance and governance conditions.

Do US export controls apply to an Australian company using Chinese models?

They can, indirectly. The controls target chips, manufacturing equipment and some frontier-model access flowing to China, but the ripple effects reach downstream contracting. Using a Chinese model is not itself prohibited, yet sanctions exposure around the Huawei ecosystem or certain labs can complicate your client and partner agreements. Treat it as a compliance exposure to check, not to assume away.

Is self-hosting open-weight models actually cheaper than using closed APIs?

Not always. Open-weight models can offer lower per-token costs, but you take on infrastructure, security, updates and engineering. For small or sporadic workloads an API is often cheaper once you count people and operations, not just tokens. Self-hosting pays off where data sensitivity, scale or control outweighs that operational burden.

What should a smaller business with no in-house AI team do?

Start with scoring and the kill-switch question, not infrastructure. Even without engineers, you can score vendors on jurisdiction, chip supply, compliance exposure and access continuity, and prefer providers with clear data-residency terms. A managed open-weight or EU option can offer some control without a full platform team. Match the complexity to your actual exposure.

Can I keep data in Australia and still use a US or Chinese model?

Yes, but only where inference and storage actually stay in Australian or approved locations. A US closed API often processes data in overseas regions unless the provider offers local residency, while a self-hosted open-weight model can run inside your own Australian infrastructure. Confirm where data flows and where control sits before relying on a provider’s marketing.

How often should I re-score my AI vendors?

At least when anything material changes, and at a set review cadence rather than once at purchase. Re-run the score when a vendor changes terms, when export controls or sanctions shift, when a model is deprecated, or when your data or clients move into a regulated sector. Geopolitical risk is a living input, so treat the score as a standing discipline, not a one-off.

AUTHOR

James A. Wondrasek James A. Wondrasek

SHARE ARTICLE

Share
Copy Link

Related Articles

Need a reliable team to help achieve your software goals?

Drop us a line! We'd love to discuss your project.

Offices Dots
Offices

BUSINESS HOURS

Monday - Friday
9 AM - 9 PM (Sydney Time)
9 AM - 5 PM (Yogyakarta Time)

Monday - Friday
9 AM - 9 PM (Sydney Time)
9 AM - 5 PM (Yogyakarta Time)

Sydney

SYDNEY

55 Pyrmont Bridge Road
Pyrmont, NSW, 2009
Australia

55 Pyrmont Bridge Road, Pyrmont, NSW, 2009, Australia

+61 2-8123-0997

Yogyakarta

YOGYAKARTA

Unit A & B
Jl. Prof. Herman Yohanes No.1125, Terban, Gondokusuman, Yogyakarta,
Daerah Istimewa Yogyakarta 55223
Indonesia

Unit A & B Jl. Prof. Herman Yohanes No.1125, Yogyakarta, Daerah Istimewa Yogyakarta 55223, Indonesia

+62 274-4539660
Bandung

BANDUNG

JL. Banda No. 30
Bandung 40115
Indonesia

JL. Banda No. 30, Bandung 40115, Indonesia

+62 858-6514-9577

Subscribe to our newsletter