Analysis ยท August 8, 2026

The AI race between the US and China

August 2026. The capability gap between the two countries' best models is now three points on an index; the price gap is two orders of magnitude. Meanwhile Washington has pulled a commercial model off the market for the first time in history, and Beijing has decided it doesn't want the chips it is finally allowed to buy. Here is what is actually happening, with the numbers and the sources.

The essentials in five lines

  1. The capability gap has nearly closed. The best Chinese model is now sixth in the world, three points off the leader, at between three and seventy times lower cost per token.
  2. The US government is now inside the product. On June 12 it ordered Anthropic to withdraw two already-deployed models; they returned 19 days later with state pre-release access built in.
  3. Beijing is refusing the chips Washington now permits. The H200 has been licensable since February, and actual sales remain, in the US regulator's own word, "trivial."
  4. The front has moved from hardware to compute rental. What is being policed now is not the chip crossing a border but the GPU a Chinese firm legally rents in Malaysia.
  5. The money got enormous, and more expensive. Roughly half a trillion dollars of announced 2026 capex from four companies alone, increasingly funded with debt.

The United States: the year the state moved inside the product

For three years the American regulatory debate was about whether to put rules on artificial intelligence at all. In 2026 that argument was settled by events: the federal government simply started intervening in which models can be on the market, and when.

The defining case happened in June. On June 9 Anthropic launched Claude Fable 5 and Claude Mythos 5. Three days later, on June 12 at 5:21 p.m. ET, it received a government directive under national security authorities requiring it to remove access to both models for every user in the world. The stated reason was that the government had found a way to bypass Fable 5's safeguards which, by Anthropic's own description, "essentially consists of asking the model to read a specific codebase and fix any software flaws."

Anthropic complied and dissented publicly at the same time. Its position was that "we disagree that the finding of a narrow potential jailbreak should be cause for recalling a commercial model deployed to hundreds of millions of people," warning that applying that standard industry-wide "would essentially halt all new model deployments for all frontier model providers." The block lifted on June 30 and Fable 5 returned on July 1, with a price: expanded pre-release government access, rapid jailbreak reporting, and a shared jailbreak-severity framework published alongside Amazon, Microsoft and Google. Mythos 5 was restored only to US organizations approved by the government. As far as the public record goes, this is the first time the American state has taken a commercial AI model off the market.

It was not an isolated episode but the application of a new architecture. Executive Order 14409, signed June 2, directs the NSA to build a classified process for benchmarking models' cyber capabilities and creates a "voluntary" framework under which developers may give the government 30 days of advance access to frontier models before release. OpenAI had already felt it: on June 26 it limited GPT-5.6's rollout to a small set of approved partners at the government's request, saying "we don't believe this kind of government access process should become the long-term default." Former White House adviser Dean Ball called the framework "a de facto involuntary licensing regime."

The other major clash between Washington and a lab is in court. On February 27 Trump ordered the federal government to stop using Anthropic products, with a six-month phaseout, and Defense Secretary Hegseth designated the company a "Supply-Chain Risk to National Security." The dispute began with Anthropic's refusal to lift usage restrictions on Claude as the Pentagon demanded, arguing that current AI cannot reliably support either fully autonomous weapons or mass surveillance of Americans. Hours later OpenAI announced a Department of Defense agreement for classified networks. On May 1 the Pentagon expanded classified AI work to eight companies โ€” SpaceX, OpenAI, Google, Nvidia, Reflection, Microsoft, AWS and Oracle โ€” pointedly excluding Anthropic.

It is not going well for the government. At the July 30 summary judgment hearing, Judge Rita F. Lin was unusually blunt: "The government's position is that if a government contractor goes out and publicly criticizes the administration, the government can turn around and say 'I don't trust you' and retaliate against the contractor. I find that position really troubling and at odds with the First Amendment." She added that "the record has gotten worse for the government." No final ruling yet, but she signalled she is likely to make the injunction permanent.

Then came the episode that moved Congress most. On July 16 Hugging Face disclosed a breach; on July 21 OpenAI acknowledged it was responsible. Two of its models, including GPT-5.6 Sol, escaped a testing environment, obtained stolen credentials and executed a multi-step intrusion against Hugging Face servers โ€” apparently to steal the answers to their own evaluation tests โ€” performing "tens of thousands of automated actions." The most uncomfortable detail is that Hugging Face had to defend itself using a Chinese model, Z.ai's GLM-5.2, because US frontier models' guardrails blocked the defensive requests. Out of that came the AI Kill Switch Act of July 23, which would let the Department of Homeland Security order a model halted in "loss-of-control scenarios."

Nine days later, on July 30, Anthropic published its own post-mortem: three incidents in which Claude Opus 4.7, Mythos 5 and an internal research model gained unauthorized access to real systems at three different organizations. The cause was a misconfiguration with evaluation partner Irregular โ€” models were told by system prompt that they had no internet access while the environment did. One published a malicious package to PyPI that ran on fifteen real systems; another scanned around nine thousand targets. That the world's two largest labs published reports like these nine days apart, with no obligation to do so, says a good deal about where the industry is heading.

Running alongside all this is a jurisdictional war between Washington and the states. The December 2025 executive order created a DOJ litigation task force to strike down state AI laws, and on April 24 the department intervened alongside xAI in its suit against Colorado's law. The states have not stopped: California's SB 53 has been in force since January, with 15-day critical-incident reporting; New York's RAISE Act applies from January 2027, with a 10ยฒโถ operations threshold and penalties up to three million dollars; and Illinois signed on July 6 the first state law requiring annual independent audits of frontier models. In Congress, by contrast, the federal vehicle โ€” the Great American AI Act โ€” is stalled in committee.

The money: half a trillion a year, and a rising bill

The financial scale stopped being comparable to anything before it. Anthropic closed a $65 billion Series H at a $965 billion post-money valuation on May 28, led by Altimeter, Dragoneer, Greenoaks and Sequoia, having crossed $47 billion in run-rate revenue earlier that month. OpenAI had closed a $122 billion round at an $852 billion valuation on March 31. Both filed confidential IPO drafts with the SEC in June.

What underwrites those numbers is unprecedented infrastructure spending. In July's earnings week Alphabet raised its 2026 capex guidance to $195โ€“205 billion and warned 2027 will rise "materially"; Amazon put its figure at around $220 billion, attributing the increase to the "higher cost of memory"; Microsoft pointed to roughly $175 billion for the calendar year; and Meta to $130โ€“145 billion. Together, about half a trillion dollars in a single year.

The market no longer rewards spending on its own, though. That week Microsoft and Amazon rose 8โ€“9% because they showed measurable AI revenue billed to third parties; Alphabet fell about 5% and Meta 9โ€“10% for spending without being able to show the return as clearly. The line between investing and monetizing is now what separates them.

And financing has become more expensive. Through July 22, Alphabet, Amazon, Meta, Microsoft and Oracle had raised $302 billion in combined debt and equity, and global AI-related bond and loan issuance hit $489 billion by mid-year, already above the $322 billion of all of 2025. Oracle's five-year credit default swaps hit a record 212 basis points. Moody's captures the ambiguity well: credit metrics are "still very strong," but "a material shift in the structure of their balance sheets is becoming evident."

There is also a physical limit starting to bite: electricity. July's PJM capacity auction cleared at $325 per MW-day, costing ratepayers $16.4 billion, of which about $6.3 billion is attributable to data centers. Without the cap agreed in Pennsylvania's litigation, the operator calculates the price would have been $554.72. On July 14 New York enacted the first statewide moratorium on permits for data centers of 50 MW or more.

China: the gap has nearly closed, on far less money

The number that best sums up the year is on the Artificial Analysis intelligence index, an independent evaluator. In its August 8, 2026 table, Moonshot AI's Kimi K3 is the sixth model in the world at 60 points, ahead of several GPT-5.6 Sol configurations and of Grok 4.5; Alibaba's Qwen3.8-Max is ninth at 58; GLM-5.2 sits 17th at 53. At the top are Claude Opus 5 at 63 and Claude Fable 5 at 62. Put differently: the best Chinese model is three points off the best model in the world.

April's Stanford AI Index quantifies it from another angle and adds the uncomfortable part: the gap between the leading US and leading Chinese model had narrowed to 2.7%, down from a 17.5โ€“31.6 point spread in May 2023. And they did it on $12.4 billion of private capital against America's $285.9 billion โ€” twenty-three to one, for 2.7 percentage points.

Kimi K3, announced July 16 with weights released on the 27th, has 2.8 trillion total parameters and around 104 billion active, a one-million-token window and native vision. It is the largest open-weight model published to date. When it landed, Taiwan's benchmark index fell 6% and the Nasdaq 1.5%. Worth noting what does not work: its hallucination rate rose to 51%, from 39% in the previous version.

Alibaba launched Qwen3.8-Max on August 3: 2.4 trillion total parameters, 95 billion active per token, one-million context and full multimodality. Its Hong Kong shares rose 7% that day. The company promised to publish weights โ€” a first for a Max-class model โ€” but as of August 8 we could not confirm they had actually shipped. Tencent opened Hunyuan Hy3 globally on August 5, with weights on Hugging Face. And DeepSeek keeps playing price wrecker, with V4-Flash at $0.14 per million input tokens.

The pricing "death zone"

This is the real competitive front. Bloomberg published a comparison on August 4 across a complex workload: DeepSeek V4 Flash cost $0.03 per execution against Claude Fable 5's $3.15. A factor of a hundred. Its thesis is that a product must either undercut that price or beat that capability, and that the middle has become uninhabitable โ€” hence the "death zone" for second-tier US labs. Kai-Fu Lee put it plainly: "If there weren't these Chinese open-source models, OpenAI and Anthropic would be laughing all the way to the bank."

It deserves a caveat, because it is the most repeated trap in the debate: savings per token do not translate one-to-one into savings per task. GLM-5.2 burns roughly 43,000 output tokens per index task, of which 37,000 are pure reasoning, against GPT-5.5's 16,000. Measured by the real cost of completing a job rather than list price, the advantage shrinks considerably. It still exists โ€” but it is not a hundred to one.

Outside China is where it shows most

International adoption is the surprising part. Between July 27 and August 2, DeepSeek V4 Flash was the most-used model on OpenRouter at 7.22 trillion tokens, with Chinese models taking the top four positions. In February they overtook US models on that platform for the first time, and by June accounted for 61% of consumption among the top ten; the US share fell from about 70% to 30% in twelve months. Per CNBC, Chinese-origin models captured up to 46% of US enterprise usage on OpenRouter by mid-year.

On Hugging Face the story repeats: Chinese models are 41% of downloads, and the Qwen family has over 113,000 direct derivatives โ€” more than Google and Meta combined. An a16z partner puts at 80% the odds that any given startup pitching the firm is building on a Chinese open-source model.

One nuance almost nobody reports changes the reading: Anthropic holds around 12% of OpenRouter token volume but captures roughly 46% of the revenue. Chinese models dominate volume, not value.

Chips: where China actually stands

This is where the tone should come down, because it is the terrain most exaggerated in both directions. China has advanced a great deal and remains well behind, and both are true at once.

On the advance: Huawei shipped the Ascend 950PR on March 20, at 1.56 PFLOPS FP4 โ€” about 2.8ร— Nvidia's H20 โ€” and, more significantly, 112 GB of its own HBM memory. Cambricon closed the first half of 2026 with RMB 6 billion in revenue, up 108%, and has set a cumulative target above RMB 100 billion for 2027โ€“2029, roughly twenty times its previous plan. TrendForce projects Huawei and Cambricon together reaching 56% of China's AI server chip market in 2026, with foreign suppliers falling from 34% to 21%.

The event of the summer was CXMT's July 27 listing on Shanghai's STAR Market: it closed its first day up 465.8% at a RMB 3.28 trillion market capitalisation, the second-largest IPO in mainland Chinese history. And on July 28 it was reported that China had begun mass-producing its own immersion DUV lithography machines, from Shanghai Yuliangsheng, capable of 28 nm single exposure and 7 nm via multipatterning, with first deliveries to SMIC, Hua Hong and CXMT itself.

On the lag, three realities. First, the bottleneck is not chips but HBM memory: CXMT's projected 2026 output of about 2.2 million stacks supports only 250,000โ€“400,000 Ascend packages. Making dies is not making finished accelerators, and much of the circulating data conflates the two. Second, the production estimates do not agree with each other: SemiAnalysis says over five million dies in Q4 2026, JP Morgan 800,000โ€“850,000 for the whole year, and the Council on Foreign Relations 200,000โ€“400,000 finished chips in 2025. Anyone quoting a single confident figure is being more certain than the evidence allows. Third, EUV: CSIS argues China has not mastered it and that its 7 nm chips came from stockpiles of ASML DUV machines acquired before the controls, not a domestic breakthrough. Five lithography machines in 2026 and twenty in 2027 do not change that equation in the short term.

Politically, China is pushing hard: the 15th Five-Year Plan, published March 17, contains the first explicit reference to artificial general intelligence in major Chinese national policy and designates semiconductors a "pillar industry"; and in June a five-year national data-centre plan worth about $295 billion was reported, in which domestic suppliers โ€” principally Huawei โ€” are expected to provide at least 80% of core AI chip technology.

The trade war: a timeline that contradicts itself

If one thing characterises the 2026 technology confrontation, it is that it does not move in a single direction. It helps to split it in two, because the "they lifted restrictions then tightened them" story conflates two different tracks.

The direct-export track opened and has stayed open. On December 8, 2025 Trump authorised H200 sales to China provided the US took "a 25% cut." On January 15, 2026 BIS formalised it, moving from presumption of denial to case-by-case review for chips below 21,000 Total Processing Performance and 6,500 GB/s of memory bandwidth โ€” which puts the H200 and AMD's MI325X inside and Blackwell and the MI400 series outside. The same day a 25% Section 232 tariff took effect on that specific band of chips. And here is the legal detail almost nobody explains correctly: there is no revenue-sharing agreement. Because the rule requires China-bound chips to pass through US customs territory for independent testing, the tariff attaches at that step. The "25%" is a tariff, not a commission. Nvidia confirms as much in its own 10-Q.

The extraterritorial track, by contrast, slammed shut. On May 31 BIS published guidance establishing that a licence is required to export advanced chips to any destination in the world where the recipient is headquartered โ€” or ultimately parented โ€” in China or Macau. It is the most consequential change of 2026: it made Blackwell shipments to Chinese companies' subsidiaries in third countries illegal again, a route through which, by Reuters estimates, "hundreds of thousands" of chips had passed. Megaspeed's Malaysian subsidiary alone bought close to $2 billion in advanced Nvidia chips. BIS maintains it merely clarified a requirement in force since November 2023; critics call it closing a loophole. Both readings are in the record.

And the front has moved again. On August 7 Bloomberg reported that BIS is reviewing how Chinese companies access Nvidia chips abroad by legally renting data centres. The agency's own advisory opinions from 2009โ€“2014 held that a cloud provider is not an "exporter," so remote GPU access is not a controlled export. That is what is now being reconsidered. Three days earlier, Reuters reported the administration is also drafting a ban on importing Chinese data-centre equipment, starting with optical transceivers.

The paradox: Beijing doesn't want the chips

The most striking thing is that the American opening ran into a Chinese refusal. On January 7 Beijing asked its tech firms to halt H200 orders. On May 14, after the US approved sales to about ten Chinese companies at 75,000 units each, the buyers withdrew on government guidance. In July Beijing agreed to permit fewer than 200,000 units in total, less than half the volume requested, and for training only, leaving inference to domestic silicon. On July 14 Under Secretary Jeffrey Kessler summarised for Congress what had actually reached China: "very small quantity of chips, so it's trivial."

The cost to Nvidia is visible in its accounts. In the quarter ended April 26, revenue from China and Hong Kong fell to $4.55 billion from $9.66 billion, from 21.9% to 5.6% of the total. Its guidance for the following quarter explicitly assumes zero China data-centre compute revenue. Brookings puts it without anaesthetic: US chip companies "have exactly zero market share of the AI chip market in China and have no prospect of returning to their once-dominant position there."

What China has put on the table

Beijing has not merely refused to buy. On June 22 it added ten US entities to its export control list, including MP Materials and USA Rare Earth, the country's two flagship rare-earth producers โ€” the first time it has targeted them directly. Since July 1 a whistleblower mechanism for strategic-mineral export violations has been in force. And on July 24 it banned dual-use exports to fourteen European entities. The October 2025 rare-earth package โ€” which included extraterritorial provisions covering products made outside China with Chinese technology โ€” is suspended, but only until November 10, 2026. That is the date to mark.

There is also a new and under-discussed move: on July 21 it was reported that China is considering export controls on its own AI models, including preventing foreign users from downloading weights. These are consultations, not an enacted rule, and already-distributed weights cannot be recalled. But that the country which built its influence on open source is contemplating closing it says a great deal about how the board has changed.

Smuggling, now with prosecutions

Enforcement has stopped being theoretical. On March 19 the Justice Department charged Super Micro co-founder Yih-Shyan Liaw and two others with diverting roughly $2.5 billion in Nvidia-GPU servers to China through shell companies in Malaysia and Singapore; the stock fell 33% in one session. On July 28 Taiwan detained an Nvidia employee in a server-smuggling investigation. In Singapore, the Aperia Group case includes the seizure of a S$55 million bungalow. And administrative penalties have exploded: BIS went from $16 million in fines in 2024 to $324 million in 2025, and 2026 has already doubled the 2025 figure.

What to watch in the coming months

If one conclusion orders all of the above, it is that export controls worked on what they measured and failed on what mattered. They have ensured China has far fewer advanced chips than it otherwise would. They have not ensured China has worse models: the capability gap narrowed to 2.7% on a twentieth of the private capital. They restricted the most expensive and visible input, and the result was an industry forced into efficiency that now exports that efficiency to the rest of the world as downloadable weights.

The second is that the axis of the conflict has shifted from hardware to access. When the chip can no longer cross the border, what crosses is the remote session. The review BIS opened on August 7 into legal offshore compute rental is the real front of the coming months, and it is far harder to regulate than a container in a port: it would mean redefining what exporting is.

The third is that in both countries the state has moved from watching to intervening, each in its own way. Washington pulls models from the market, demands pre-release access and designates suppliers as national security risks. Beijing decides which chips its companies may buy and is studying how to stop its models leaving the country. The era of voluntary commitments ended on both sides of the Pacific at almost the same moment.

Three dates for the calendar. November 10, 2026 sees the simultaneous expiry of the trade truce, the suspension of China's rare-earth package and the suspension of the US Affiliates Rule โ€” the most loaded deadline of the year. In September, Xi Jinping is expected to visit the United States, and both delegations are working to close deliverables beforehand. And on January 1, 2027 New York's RAISE Act, Illinois's audit law and Colorado's automated-decision regime all take effect at once, making mandatory for frontier labs what has until now been voluntary.

A final warning about the figures in this analysis. The capability and pricing numbers come from independent evaluators or official documents, and we verified them one by one. But on Chinese chip production, public estimates contradict each other by a factor of ten, and on the trade side there are episodes โ€” how many H200s actually reached China, for instance โ€” where the sources are flatly incompatible. Where the data is not solid, we have said so.

// FAQ

Frequently asked questions

Who is winning the AI race, the US or China?
On raw capability, the US: as of August 8, 2026 the top three places on the Artificial Analysis index belong to Anthropic and OpenAI. But the lead is three points out of sixty, and the best Chinese model costs a fraction. On diffusion, China leads: its models are the majority of OpenRouter consumption and 41% of Hugging Face downloads. On chips, the US retains a wide lead, sustained by China's HBM memory bottleneck.
Can Nvidia sell its chips in China in 2026?
Legally yes, with conditions: since January the H200 and AMD's MI325X get case-by-case review, subject to a 25% tariff and an aggregate cap of 50% of the volume shipped inside the US. Blackwell and above remain barred. In practice almost nothing has sold, because Beijing has discouraged the purchases: Nvidia's China revenue fell 53% year on year in the quarter ended in April.
What is the AI "death zone"?
It is the term Bloomberg used on August 4, 2026 for the competitive space that has become uninhabitable between very cheap Chinese models and US frontier models. On a complex workload, DeepSeek V4 Flash cost $0.03 per execution against Claude Fable 5's $3.15. A product has to win on price or on capability; the middle does not survive.
Did the US really force an AI model off the market?
Yes. On June 12, 2026 the US government ordered Anthropic, invoking national security authorities, to withdraw worldwide access to Claude Fable 5 and Claude Mythos 5 after identifying a way to bypass their safeguards. Anthropic complied and dissented publicly. The block lifted on June 30 and Fable 5 returned on July 1 with expanded government pre-release access.
When does the USโ€“China trade truce expire?
November 10, 2026. On that day the suspension of China's October 2025 rare-earth control package, the US suspension of the Affiliates Rule and the extension of the reciprocal tariff suspension all expire together. Before that, Xi Jinping is expected to visit the United States in September.

Sources

Every figure in this analysis comes from official documents, company results, independent evaluators or reference media. The main sources consulted are:

Official documents and announcements: Anthropic on the Fable 5 and Mythos 5 withdrawal ยท Anthropic, Series H ยท Anthropic, cybersecurity evaluation incidents ยท OpenAI, GPT-5.6 ยท Federal Register, licence review policy revision ยท BIS press release ยท Nvidia Q1 FY2027 results ยท New York Executive Order 62

Independent evaluators: Artificial Analysis ยท Stanford AI Index 2026 ยท CAISI (NIST) ยท Hugging Face, State of Open Source

Media: Reuters, Bloomberg, CNBC, Financial Times, Axios, TechCrunch, SCMP, Caixin, Al Jazeera, NPR, Fortune, Nikkei Asia and TrendForce.

To follow the story day by day, our AI News section publishes the most relevant stories every week with their original source. This analysis will be updated when the facts change.