Product1 publisher3 min readPublished
Beijing's commerce ministry spent a month weighing limits on overseas access to Qwen, Doubao and GLM
Xi is recruiting BRICS members into a Beijing-founded AI body headquartered in Shanghai while his own government decides how much of China's open-model stack outsiders get to keep using.
The Product Desk · Product desk

What happened
- Xi Jinping proposed a China-led community for open-source AI at the BRICS summit in New Delhi on Sunday, offering seminars and training courses alongside model cooperation, Bloomberg reported.
- A day earlier he invited BRICS members into the World AI Cooperation Organization, which Beijing founded in July with 29 signatories and a Shanghai headquarters. No EU member state is on the list.
- The joint declaration issued on Saturday asked for international cooperation on access to AI resources with safety, security, inclusiveness and reliability, and did not mention the proposal.
- China's ministry of commerce spent a month this summer discussing whether to curb overseas access to the Qwen, Doubao and GLM model families.
- The EU AI Act's exemption for genuinely free and open-source general purpose models stops at systemic risk, where a model has to comply in full whatever its licence permits.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- exposure A product standing on Qwen, Doubao or GLM has its supply governed by an unpublished decision in Beijing. The cost of a curb lands on a release date the team already committed to.
- constraint The open-licence exemption ends at systemic risk, so once a model is classed that way the documentation and evaluation budget has to exist whether or not the weights are public.
- decision Teams have to say out loud which side of the licence test their fine-tuned model sits on, because monetising a modified checkpoint can pull them into duties the base model avoided.
- precedent With 29 signatures, all of them from outside the EU, the Shanghai body gives model-sharing terms a second venue. Procurement will be reading it alongside Brussels.
The person who has to answer for this is whoever pulled a set of Chinese open weights this summer and shipped them into a product with European customers. Two governments now have a say in whether that keeps working.
The European side can be checked line by line. Commission guidelines free providers of genuinely free and open-source general purpose models from keeping technical documentation for regulators, from supplying it downstream and from appointing an EU representative [9]. Qualifying is specific: weights, parameters and architecture public, and a licence that permits use and modification without monetisation [10]. A training data summary and a copyright policy are due from every provider, open licence or not [12]. Since 2 August the Commission can demand evaluations, restrict market access and fine 3% of global turnover [13].
The Chinese side is still being decided. Xi told China's own AI summit in July that development and security have to be balanced [14]. A social media account used to signal policy thinking has said the most powerful model features should be restricted [15]. The Next Web's report draws the contrast bluntly: Europe published its limit and can be sued over it, while Beijing is still deciding what its own is [18].
On Saturday, the same day the BRICS declaration came out, state security minister Chen Yixin published a journal article. It accused unnamed countries of using blacklists and closed ecosystems to "sever global AI industrial chains and supply chains" [16] [20]. A day later in New Delhi, Xi said his proposed community would "support the cooperation in developing and applying large language models" [2] [3].
The founding roster is only partly public. Five signatories are named in the account: Russia, Pakistan, Kazakhstan, Indonesia and Brazil [6]. The other 24 of the 29 remain unnamed [19], so for now a team can only guess whether the markets it sells into sit inside this body or outside it.
What to do on Monday depends on whether the dependency is a checkpoint you hold on disk or a live endpoint operated by someone else. It also depends on whether the model you picked falls in the systemic risk tier, because a model in that tier complies with everything whatever its licence says [11]. A held checkpoint below that line is the cheapest place to stand. The ministry's deliberation was about overseas access [17]. So ask what a curb would actually reach: the endpoint you call today, or the next release you planned to download. A live endpoint puts that question into production the day a rule appears. In the systemic risk tier the licence stops mattering, and the documentation, evaluation and market-access obligations apply anyway.
What to watch
- Whether the commerce ministry's deliberation turns into a published rule naming Qwen, Doubao or GLM, and what it says about weights already downloaded abroad.
- Whether the World AI Cooperation Organization publishes its full 29-country signatory list, or signs a BRICS member after New Delhi.
- The first time the Commission uses its 2 August powers against a provider claiming the open-source exemption.