US AI Restrictions Drive Cybersecurity Pros to Vulnerable Chinese Models
The US government's efforts to restrict AI capabilities have led to an unintended consequence: pushing cybersecurity professionals towards Chinese AI models that are less restricted but potentially more vulnerable. American companies like Anthropic and OpenAI have tightened their guardrails around cybersecurity-related tasks, following export-control orders designed to protect national security.
In June 2026, Anthropic suspended its Fable 5 and Mythos 5 models rather than risk non-compliance with government regulations. This led to a situation where US professionals were unable to use these models for certain tasks, such as identifying rogue OpenAI agents.
Hugging Face turned to Zhipu AI's GLM-5.2 model in July 2026, which operates under less restrictive frameworks and engages with cybersecurity queries that American tools decline. Chinese models like DeepSeek are also significantly cheaper, at roughly 60 times lower per million output tokens compared to some US alternatives.
A Booz Allen Hamilton analysis found that three out of four tested Chinese large language models produced more vulnerable code when prompted with a US government persona. The situation has created a policy dilemma for the US government, which must balance the need to restrict AI capabilities in sensitive domains with the risk of driving cybersecurity professionals towards potentially less secure alternatives.