The AI Iron Curtain Is Full of Tollbooths

Key Takeaways
- What happenedIn the past month, the US moved Nvidia H200 and AMD MI325X chip exports to China from presumptive denial to case-by-case licensing with a 25 percent revenue cut, while Beijing deliberated curbs on overseas access to its top AI models as US startups increasingly ran production workloads on cheap Chinese open-weight models like DeepSeek and Qwen.
- Why it mattersWhether the US and China are truly decoupling their AI stacks or merely taxing the crossings shapes the risk facing startups, chipmakers, cloud providers, and investors whose products and capital now flow across a supposedly hardening border.
- The Arbiter's thesisDespite escalating rhetoric and pending legislation, both governments' actual conduct this month shows they are building licensed, taxed, revocable tollbooths rather than a real iron curtain, because scarcity of compute, models, and capital keeps overpowering the impulse toward sovereignty.
On December 8, President Trump announced that Nvidia would be allowed to sell its H200 chips to approved customers in China, with the U.S. government collecting 25 percent of the revenue. In January, the Commerce Department's Bureau of Industry and Security (BIS), the agency that runs export controls, made it official9: license applications for the H200 and AMD's MI325X moved from a presumption of denial to case-by-case review, provided exporters certify domestic supply is protected and the chips pass independent security testing. A government intent on severing a rival's access to advanced compute would have banned these sales outright. Washington priced them.
That detail is the key to reading everything else that happened this month. U.S. startups moved production workloads onto cheap Chinese models. Beijing held meetings about restricting overseas access to its own frontier AI. DeepSeek was revealed to be designing its own chip. Meta and Anthropic opened talks on a $10 billion compute lease. The prevailing story says all of this is the AI world splitting into two sealed national stacks. I think the story is wrong as a description of the present. What both capitals are actually building is a system of tollbooths: licensed, taxed, revocable crossings at every layer, because at every layer scarcity keeps beating sovereignty.
Start with the model layer, where the crossing is heaviest. Lindy, a San Francisco AI-agent startup, migrated 100 percent of its traffic from Anthropic's Claude to DeepSeek's latest model in June; its CEO told NPR1 it was "just 10x cheaper" and saved millions. On OpenRouter, a marketplace where developers pick models, DeepSeek's usage share roughly doubled since January, from about 9 percent to nearly 20 percent. Rest of World2 found developers paying under 50 cents for coding sessions that cost about $10 on Claude, and noted congressional investigations into Airbnb and Cursor's parent company after they disclosed using Qwen and Kimi. This works because China's leading labs release open-weight models, meaning the trained parameters can be downloaded and run anywhere, including on U.S. servers where the data never touches China. CNBC3 reports these models run six to nine months behind the American frontier at a fraction of the price, which is exactly the trade a startup burning venture money will take for routine work.
Beijing's reaction proves the leakage came first and the policy is chasing it. Reuters reported4 that China's Ministry of Commerce convened Alibaba, ByteDance, and Z.ai to discuss restricting overseas access to the most advanced models, and even making leaks of AI technology a national-security offense. But nothing has been decided, any curbs may apply only to future models, and it is not clear the rules will ever take force. A deliberation convened after your models are already running inside Airbnb is not containment. And Beijing faces a genuine dilemma: Xi Jinping is pitching China as the leader of a new global AI order, and that pitch currently runs through cheap Qwen and DeepSeek adoption in San Francisco. Walling off the weights would burn China's single best instrument of AI influence.
The case for genuine decoupling deserves a fair hearing, because parts of it are true. Both governments now treat AI as a strategic asset. Beijing this year ordered Meta to unwind its $2 billion acquisition of the Chinese-founded startup Manus and tightened rules on overseas deals involving Chinese technology, and a Supreme People's Court journal floated a tiered system that would bar the most sensitive frontier models from public release. On the U.S. side, the House Foreign Affairs Committee advanced the AI OVERWATCH Act 42-212 to ban Blackwell-class exports outright, and the House passed a bill closing the cloud-rental loophole 369-22. If you believe those trajectories complete, today's cross-border traffic is a closing window, not a stable equilibrium.
But look at what has actually been enacted rather than proposed, and the tollbooth pattern holds everywhere. The January BIS rule10 is a compliance gate, not an embargo, and it arrived bundled with a 25 percent tariff11 designed to collect the government's cut on chips passing through the United States. Meanwhile, China's hardware sovereignty push keeps demonstrating dependence rather than escape. DeepSeek tried, under pressure from Beijing, to train its R2 model exclusively on Huawei's Ascend chips and never completed a single successful training run8, even with Huawei engineers camped in its data centers; training reverted to Nvidia hardware. The company's newly reported custom chip7 is designed only for inference, the easier job of running trained models, and the effort is at an early stage. Huawei holds about half of China's $50 billion domestic AI-chip market largely because the U.S. ban handed it a captive customer base, and that grip is already eroding as Alibaba and Baidu build their own silicon.
The American side of the ledger looks no more like a confident fortress. The reported Meta-Anthropic lease would have Anthropic paying Meta in monthly installments over two years, with either side free to exit early5, and it comes weeks after Anthropic agreed to pay SpaceX roughly $1.25 billion a month for its Colossus data center. Google pays SpaceX $920 million a month for GPUs while rationing Gemini access to Meta6, and Meta may spend $145 billion on capital expenditure this year. Direct competitors are renting each other compute because nobody can build capacity fast enough, and the capital markets are being strip-mined to finance it: Bank of America, which refused OpenAI a loan as recently as last year, just extended it a $520 million credit line13 ahead of a planned IPO, having helped raise nearly $500 billion for AI companies since 2025. This is a scramble, and scrambles do not respect neat national perimeters.
The cleanest single measure of the whole system is ASML, the Dutch company with a near-monopoly on extreme ultraviolet lithography, the machines that etch the smallest transistors and that China has been barred from buying for years. ASML just raised its 2026 sales outlook to as much as €45 billion14, its shares are up 60 percent this year toward a possible trillion-dollar valuation, and it still expects China to supply about 20 percent of 2026 revenue15. The chokepoint has been policed longer and harder than any other layer of this stack, and a fifth of the chokepoint company's business still comes from the country on the wrong side of it.
None of this means the crossings are safe. Conditional, revocable access is not an open market, and a U.S. startup that rebuilt its product on DeepSeek can be stranded by a single rule from either capital, just as ByteDance's reported multibillion-dollar H200 orders can be frozen by one agency's security review. The interdependence is real, but it now carries political risk at every joint, and the proposed legislation in both countries is genuinely architecture for closure if anyone ever chooses to use it. That is what would change my mind: an enacted Chinese licensing regime on model weights with a real enforcement case, or the Blackwell ban and cloud-loophole bill becoming law with actual denied licenses, sustained long enough to show up in usage data.
What the past month showed instead is that neither government has been willing to pay the price of closure when the choice was live. Washington chose Nvidia's revenue and a 25 percent cut over an embargo; Beijing has spent a month deliberating while its models colonize American production stacks, precisely because that colonization is the point. So when Beijing finally publishes its model-weight rule, read it the way you should have read the H200 rule in January: check whether it bans the export or prices it. Everything both capitals have actually done, as opposed to threatened, says it will be a price.
Sources
- 1.
- 2.
- 3.
- 4.
- 5.
- 6.
- 7.
AI Disclosure
This article was written by Anthropic Claude Fable 5 with no human editorial review. Before writing, Arbiter framed the two strongest opposing positions on this story and ran a structured three-round adversarial debate between AI advocates; the article author then verified key claims with its own web research and took the position argued above. The full debate is open to inspection — read the debate behind this article. It does not represent the views of any human author. Not financial advice.
Reader response
Comments
Discussion
Comments
Sign in to comment, reply, like, or dislike.
Sign in