Pioneers Insight Method Research Author
23. The Prohibition 2.0 Era: DeepSeek—The End of Compute Supremacy, or Just Another Beginning?
Back to Episodes

23. The Prohibition 2.0 Era: DeepSeek—The End of Compute Supremacy, or Just Another Beginning?

Summary

  • DeepSeek R1 challenges the policy assumption that a compute chokehold is enough to slow China’s AI progress. Against a backdrop of US restrictions on advanced GPUs, it was widely seen as delivering performance comparable to—or better than—OpenAI o1 on certain dimensions with less compute; its timing, immediately after the US unveiled its first AI export-control rule, amounted to a point-blank provocation. 洪佳杨 believes this is unlikely to make Washington ease up and may instead lead to tighter controls on chips, model weights, APIs, investment and US-based deployment, each on its own track.

  • The US is expanding its “small yard, high fence” into a tiered quota system covering global compute flows. Roughly 17-18 core allies can in principle access advanced GPUs freely, while more than 140 “neutral countries” receive annual quotas of around 50,000 units and China, Russia and others face a presumption of license denial; the quotas target gray-market transshippers through countries such as Malaysia while also giving Washington leverage over third countries. The other value 卫诗婕 highlights is surveillance: companies registering, explaining and self-certifying to secure more quota effectively let the US “turn over every fish in the pond.”

  • The controls have moved beyond physical GPUs to the models themselves, making closed-source weights and cloud providers new chokepoints. The January 13, 2025 rule brings closed-source model weights trained with more than 10²⁶ computational operations under control, and requires US cloud providers to stop Chinese companies from obtaining them through US subsidiaries and transferring them back to China. Nvidia and Oracle’s objection is not just about compliance costs but global market share: if US models and compute cannot diffuse first, cheaper Chinese alternatives may win the market.

  • The most immediate post-DeepSeek policy risk is that the US will push the performance threshold down to H20 and try to regulate distillation and API access. The hawkish logic is that if “cut-down” chips can train powerful models, the export threshold should be lowered again; the host’s analogy is that after banning oil-painting brushes and fountain pens, Washington discovers Chinese researchers can draw with pencils and then bans pencils—even pencil leads. 洪佳杨 sees no natural endpoint to this whack-a-mole expansion, while industry resistance will only grow: “Nvidia will be the first not to accept it.”

  • Model distillation will be politicized, but both its enforceability and its intellectual-property basis are plainly questionable. Some US politicians describe DeepSeek as fishing directly from OpenAI’s bucket and attribute its breakthrough to theft; 卫诗婕 says she is not an IP expert but leans toward viewing distillation, at most, as a potential civil dispute between OpenAI, DeepSeek and other companies. 洪佳杨 emphasizes that platforms cannot easily tell whether an API user is training a student model on the outputs, while the politicians involved may have little interest in distinguishing distillation from IP infringement.

  • The investment choke point is no longer a forecast but a live compliance variable effective January 2, 2025. Reverse CFIUS requires US companies, dollar funds and relevant US persons to review investments in regulated Chinese AI businesses, with outcomes ranging from notification to prohibition; even when a target stays below the technical threshold, complex exemptions and reporting requirements consume both sides’ time. For financing and valuation, the key question is not merely whether a transaction can close, but how much additional diligence friction beyond the LPA and side letter—and what risk discount on dollar capital—it creates.

  • 洪佳杨 uses US Prohibition to frame the contest: a blockade can stop the main river, but may not keep smaller tributaries from joining into a force. Global enforcement, allied cooperation and the cost to US industry make comprehensive containment increasingly expensive, while scarce compute may push China toward low-compute architectural innovation; he also acknowledges that Chinese chips still face unresolved bottlenecks and that domestic substitution cannot be declared a success by fiat. His conclusion is neither that containment is useless nor that a breakthrough is inevitable, but that “life finds a way.”

  • For Chinese companies, the most actionable response is neither blind compliance nor ignoring the rules, but mapping their own risk exposure and recognizing judicial review as one tool. 洪佳杨 recommends clarifying, rule by rule, what applies, where the obligations end, how likely enforcement is and what the business consequences would be before making a corporate decision; the growing number of US overseas enforcement partners means the room for wishful thinking is shrinking. At the same time, litigation by Hesai Technology, AMEC and TikTok shows that federal judicial review can force similar legislation to confront constitutional questions even when the plaintiff loses, while “technology neutrality” should anchor Chinese AI’s case for global markets.

Deep dive

1. DeepSeek Turned a Technical Launch into a Stress Test for Export Controls

  • The episode opens by noting that, against the backdrop of the US compute chokehold, DeepSeek R1 achieved performance comparable to or better than OpenAI o1 on certain dimensions with less compute; discussion on US social platforms was even more intense than in China, with pressure, threat perception and urgency outweighing admiration.

  • The timing was particularly provocative for Washington: the US had just issued what 洪佳杨 calls “the first export-control policy for artificial intelligence in human history,” and less than a week later DeepSeek went viral globally. He described it as a point-blank provocation, making an official response of “the controls have failed” less likely than another round of restrictions.

  • On January 31, Anthropic CEO Dario Amodei posted a long essay on X arguing that using chips and compute to hold back China’s AI development remains necessary and urgent. 洪佳杨’s core view is that controls will move beyond advanced chips into models, investment, services and US-based deployment, creating a more complete blockade of the AI value chain.

2. EAR’s Power Lies Not Only in Banning Exports, but in Turning US Technology into a Long-Arm Jurisdictional Tool

  • 洪佳杨 first clarifies the Export Administration Regulations, or EAR: in the ordinary sense, an export is a good moving from one country to another, but US rules also cover US-origin items and products made overseas with US technology when they are transferred again abroad. “It may not look like it was exported from the United States, but it is still governed by the United States.”

  • The long-arm principle works because the US still holds advantages across many high-tech links. Chips, semiconductor equipment and overseas products made with related technology can all serve as interfaces for global enforcement; export controls are therefore not merely a border regime, but a tool for Washington to manage high-tech supply chains worldwide.

  • China’s treatment under the US country-tier system is only marginally better than that of fully embargoed countries such as Cuba, Iran and North Korea. Exports of large volumes of high-end chips, semiconductor-manufacturing equipment and certain nuclear materials to China require licenses, while approval for advanced products is extraordinarily difficult in practice.

3. From Huawei to HBM, Chip Controls Have Worked Their Way Down the Entire Value Chain

  • 洪佳杨 dates the recent campaign’s starting point to the first Trump administration. In 2020, the US launched broad sanctions against Huawei-related companies and designed a special rule to prevent them from obtaining advanced chips of US origin—or made overseas with US technology—through offshore supply chains.

  • The Biden administration expanded the scope 3 times, in 2022, 2023 and 2024. In October 2022, he says, the control threshold “should have been” Nvidia A100 and H100, while the US also sought to prevent Americans from participating in the development of advanced integrated circuits inside China; in 2023, the threshold fell to A800 and H800 and extended to “equipment used to manufacture semiconductor-manufacturing equipment,” bringing even the pathway to lithography-machine capability into view.

  • In December 2024, a group of Chinese semiconductor-equipment companies including NAURA were added to sanctions lists, while HBM, whose role in boosting compute makes it strategically important, faced new restrictions. The “small yard, high fence” kept moving outward from a handful of frontier chips to equipment, memory and other parts of the stack.

  • In January 2025, the US also restricted Chinese chip designers from taping out at foundries such as TSMC and Samsung, with the threshold set not directly by AI compute but as low as the 14/16nm process nodes. 洪佳杨 warns that this also hits non-AI uses such as Bitcoin mining machines and forces companies to prove their innocence to overseas foundries.

4. The Three-Tier Global GPU System Bundles Quotas, Surveillance and Diplomacy

  • On December 9, 2024, the White House released its AI export-control framework. About a month later, on January 13, 2025, the Commerce Department for the first time made AI an explicit export-control target through an interim final rule. The hardware provisions did not completely rewrite the existing compute thresholds, but they divided global destinations into 3 categories.

  • The first tier comprises roughly 17-18 core allies, including the US, UK and Australia from the Five Eyes group, along with Japan and South Korea. They can in principle acquire advanced products relatively freely as long as they can demonstrate that GPUs will not flow onward to countries outside the system. 洪佳杨 notes that Israel and many traditional NATO allies were not included on this top-tier list.

  • The second tier covers more than 140 “neutral countries,” including Malaysia, Saudi Arabia and some NATO members. Each receives an annual quota of roughly 50,000 advanced GPUs; once that ceiling is exceeded, the buyer must apply to the Commerce Department, explain the business and commit not to supply embargoed countries. 洪佳杨 bluntly calls it something close to “a rationing system from the planned-economy era.”

  • The third tier consists mainly of embargoed or near-embargoed countries such as China and Russia. Licenses can nominally still be requested, but the practical policy is “presumption of denial.” Quotas both block gray-market transshippers routing equipment through third countries and allow Washington to raise or lower allocations according to the level of cooperation, turning commercial supply into a diplomatic bargaining chip.

5. Quota Negotiations Also Produce a Global Map of AI Capacity

  • 卫诗婕 asks whether the 3-tier classification also functions as a system for monitoring global AI development. 洪佳杨 agrees: countries and companies seeking additional quota must register, undergo verification and disclose their businesses, compute capacity and end demand, giving the US access to information that would otherwise be difficult to assemble centrally.

  • He returns to the fishpond analogy: the system does not focus only on a small number of targets, but “turns over every fish in the pond to take a look.” Its clever—or “cunning”—feature is that a license is not merely an access document; it is also a mechanism for collecting supply-chain intelligence.

  • For neutral countries, a quota is not a stable entitlement. The US wants to keep selling GPUs while requiring those countries to guarantee that they will not transship them to China. Compute supply, end-customer screening and diplomatic alignment are therefore folded into the same round of “negotiation—or, more precisely, horse-trading.”

6. Model Weights Become a More Stringent Control Target Than GPUs

  • The second innovation in the new rule is its direct treatment of model weights. 洪佳杨 explains that a GPU is a visible, tangible good whose resale still requires a logistics process; weights are essentially data, and once exported “only once,” they can be copied and transferred across borders at minimal cost.

  • The final technical threshold was set at more than 10²⁶ computational operations: weights from closed-source models trained above that level are controlled, with a presumption of denial for destinations including China and Russia. The rule extends America’s AI advantage from a hardware product into a data asset that must also be protected.

  • US cloud providers face heavier investigation duties at the same time. Even when the customer is a Chinese company’s US subsidiary, a provider must block the transaction if it has reasonable grounds to know that the weights could be transferred back to the Chinese parent. The control regime thus moves from “who is buying” to tracking ultimate control and potential onward transfer.

  • Oracle and Nvidia strongly opposed the framework at the proposal stage, calling it a serious government overreach and warning that it could constrain US AI leadership globally. The 2 companies represent the cloud and GPU suppliers with the most to lose from foregone global market share; their compliance positions also reflect direct revenue and market-share incentives.

7. Washington’s Dispute Is Not Whether to Compete, but How to Contain China

  • 洪佳杨 divides the US debate into 3 camps. The control camp, led by hawkish lawmakers on China, believes in “control, control, control”: US GPUs, model weights and related technologies should not flow into China, and tighter government bans remain the primary answer.

  • The diffusion camp includes Oracle executives and may include Nvidia. Its argument is to let US models, cloud services and GPUs capture global markets first; once ecosystems and customer lock-in are established, Chinese AI will struggle to displace them even if it becomes more advanced or cheaper. That policy preference is closely tied to continuing to sell products and earn profits.

  • The balancing camp supports controls in principle but does not believe the US can seal the supply chain acting alone. It wants to use GPUs and model weights as bargaining chips with more than 140 middle countries and coordinate with “friendly nations” to contain China. Its objective is close to that of the control camp, but it places more weight on alliances and commercial exchange.

  • 卫诗婕’s inference is that persistent third-country transshipment, combined with DeepSeek’s demonstration that innovation remains possible under low-compute conditions, validates the balancing camp’s doubts about unilateral containment. 洪佳杨 agrees: controls can raise costs, but it is difficult to guarantee that China will be unable to obtain “even a single GPU.”

8. All 3 US Explanations for DeepSeek Ultimately Point to More Restrictions

  • 洪佳杨 summarizes the post-DeepSeek reaction in 3 categories. The first is “sour grapes”: if China trained a powerful model under a blockade, hawks reason backward that it must have obtained chips illegally. Even without public evidence, the logic is: “How could he score 99? He must have cheated.”

  • The second is the “independent-thinking” camp, which includes some technologists. They do not necessarily deny the competitive pressure, but recognize that simply lowering the GPU performance threshold may not work and have begun considering new ways to constrain China in light of conditions at home.

  • The third is what he calls the “blame-shifting camp”: it describes DeepSeek’s possible use of distillation as theft of US intellectual property and demands a broader US-China AI decoupling. 卫诗婕 explains that distillation allows a smaller student model to learn from a larger model’s outputs and intermediate representations; the technology itself is not the same question as whether it infringes IP.

  • A cartoon circulated by a US lawmaker captures the mindset: OpenAI fishes its fish into a bucket, while DeepSeek fishes directly from OpenAI’s bucket. 洪佳杨 believes that whether the explanation is “illicit chips,” “policy failure” or “IP theft,” the political conclusion from all 3 camps is the same: tighten the chokehold further.

9. H20 Is the Next Red Line, but Whack-a-Mole Has No Natural Endpoint

  • The most immediate move would be to lower the chip threshold again. Hawkish lawmaker John Moolenaar wrote to the Commerce Department and national security adviser Mike Waltz, arguing that if DeepSeek could produce a powerful model using a low-compute “cut-down” chip such as H20, the previous consensus that H20 was not a serious concern had already failed.

  • 洪佳杨 calls this a game of whack-a-mole: after A100 and H100, the US restricted A800 and H800, then moved toward H20 and could eventually cover even lower-performance products. 卫诗婕’s analogy is more vivid: Washington refuses to sell oil-painting brushes and fountain pens, discovers that Chinese researchers can draw with pencils, then bans pencils and asks whether pencil leads should be banned too.

  • This slide toward ever-broader controls will hit an industrial boundary. If Nvidia’s downgraded chips designed specifically for the Chinese market still cannot be sold, its R&D and compliance spending becomes “busywork”; supply-chain participants in Taiwan, South Korea, the Netherlands and Japan also have businesses of their own and will not accept indefinite US expansion of the standard.

  • 卫诗婕 suggests that once the red line falls to an “absurd” level, business cooperation may actually weaken. 洪佳杨 allows for that possibility but is clear that the broader the scope, the higher the costs borne by enforcement agencies, allies and US domestic industry.

10. Distillation and APIs Are Easy to Target Politically but Extremely Difficult to Ban Technically

  • The US could require AI companies to report distillation by Chinese customers and might even try to impose a ban. 洪佳杨 believes implementation would be extremely difficult. An API provider can observe calls but “has no way of knowing” whether the customer is using the outputs to train a smaller student model.

  • His analogy is automotive reverse engineering: after buying a car, a company can dismantle the engine, study the components and improve its own product; regulators “cannot crawl into someone else’s garage” to stop the research. As long as API access remains open, a platform cannot stand guard over how a customer learns from the output or trains a model.

  • 卫诗婕 first says she is not an IP expert, but leans toward the view that model distillation does not automatically create an IP issue. Even if infringement occurred, it would more likely be a civil dispute between OpenAI, DeepSeek and other companies than a sufficient basis for direct government intervention. 洪佳杨 adds that lawmakers in the control camp understand neither the technology nor IP law particularly well and may have little interest in making that distinction.

  • Targeting and cutting off API access already has a precedent in the making. Zhipu was placed on the Entity List when the AI export rules were introduced, meaning products and services subject to US jurisdiction are in principle barred from supplying it. The rule therefore need not identify every instance of distillation; adding a specific Chinese company to the list can effectively sever its access to US model services.

11. From the Entity List to ICTS, Sanctions Intensity Depends on Political Blowback

  • 洪佳杨 uses Kaspersky to illustrate the more aggressive route. Around June 2024, the US barred it from operating and receiving services in the country, arguing that the Russian software had been deeply penetrated by the Russian government and could affect US election security. 卫诗婕 notes that the rationale closely resembles the dispute over TikTok.

  • ICTS national-security reviews target information and communications technology and services hardware and software controlled by “foreign adversaries.” Once a sector is deemed risky, agencies including the Commerce Department or Justice Department can issue rules prohibiting Americans from buying, using or receiving the service. Objects already covered or under review include Kaspersky and Chinese connected vehicles, as well as TP-Link routers and DJI drones.

  • A White House spokesperson said the US could review DeepSeek, with a possible outcome being a ban on its deployment or use inside the United States. 洪佳杨 nevertheless believes that imposing Kaspersky-level sanctions in the short term would create a rupture-level shock in US-China relations, because DeepSeek’s technological impact is already far greater than Kaspersky’s.

  • 卫诗婕 does not fully accept that inference. Zhipu has closer ties to the government, government and enterprise customers, and the Beijing municipal government, while DeepSeek is more private-sector-oriented and not especially large; whether the government would necessarily mount a forceful retaliation for it remains open. 洪佳杨 maintains that ownership is not the only issue: the key is whether a company represents China’s core technology interests and whether the punch will come back after sanctions.

12. The Investment Chokehold Brings AI Competition into Every Transaction Document

  • Within a week of DeepSeek’s emergence, Josh Hawley introduced the “US-China Artificial Intelligence Decoupling Act,” which would bar AI technology imports and exports, US companies from conducting research in China or working with Chinese companies, and US companies from investing in Chinese AI. 卫诗婕 sees the bill as hastily drafted and designed partly to capitalize on the news cycle, with little chance of producing results in the short term; 洪佳杨 explains that repetitive bills are common in Congress and that lawmakers are sometimes primarily signaling to voters.

  • Investment restrictions, however, already have an institutional foundation. Reverse CFIUS took effect on January 2, 2025, flipping the traditional framework of reviewing Chinese investment into the US into one that also reviews US investment into China. 卫诗婕 summarizes it as “blocking both directions.” The regime covers US companies, dollar funds and relevant US persons, and applies to Chinese AI companies that meet specified thresholds or use cases.

  • One outcome is that a transaction can proceed but must be reported to the Treasury Department; another is a transaction ban. The more opaque effect comes from the complexity of technical standards, exemptions and reporting procedures: even when a target has not crossed the line, investors must add compliance analysis beyond the LPA and side letter, while both sides absorb more time and advisory costs.

  • 卫诗婕 describes this as the third choke point after compute and models: “investment chokehold.” It may not immediately cut off all dollar funding, but through uncertainty, delays and potential enforcement liability, it can reduce the willingness of US capital to enter China’s advanced AI sector.

13. Prohibition 2.0 Can Block the Main River, but May Create New Tributaries

  • 洪佳杨 believes the US is not seriously expecting to stop every GPU flowing into China. The more realistic goal is to cut off bulk supply and materially raise the cost of obtaining chips. That resembles Prohibition in the 1920s: it could not make everyone stop drinking, but it could block large-scale inflows.

  • Prohibition also reveals the policy’s time limit. Tracking transshipment and smuggling requires the Commerce Department, Treasury Department and other agencies to commit enforcement resources on an ongoing basis, while US chip companies and allied suppliers lose revenue. The lower the threshold, the higher the political and economic cost of maintaining global coordination.

  • 洪佳杨’s favorite counterexample is the Scotch whisky Cutty Sark: it continued entering the US despite the risks of Prohibition and later became the best-selling whisky in the US—and remains so today. The policy may control the “main river,” but “small tributaries may still converge into a force that cannot be ignored,” eventually making the controls difficult to sustain.

  • The analogy does not mean the blockade has no effect. 洪佳杨 acknowledges that Chinese chips still face bottlenecks and that tens of thousands of imported units do not amount to unlimited compute; his conclusion is that restrictions may slow progress and raise costs, but can also force innovation in low-compute models: “life finds a way.”

14. Chinese Companies Need to Prepare for Technical Workarounds, Risk Quantification and Judicial Pushback

  • 卫诗婕 asks whether 4-5 years of compute restrictions have genuinely produced domestic substitution. 洪佳杨 offers no simple victory narrative: the industry still faces unresolved bottlenecks; Huawei’s new phones and Kirin chips can be viewed as evidence of progress, but based only on public interviews, he cannot verify whether the claimed “fully domestic” supply chain is entirely free of US technology.

  • The technical escape route is to stop playing the cat-and-mouse game forever. He compares it with the split between vacuum tubes and transistors during the US-Soviet Cold War: China’s AI industry could start from low-compute GPUs and pursue innovations in model architecture. He makes clear that he is not an expert in the field; this is an avenue worth exploring, not a firm prediction.

  • On the legal front, he rejects treating compliance as blindly implementing every China restriction. Companies should first map their risk exposure: which rules apply, where the obligations end, how likely enforcement is and what the consequences of a violation would be. They can then decide how to proceed; as the US adds more overseas enforcement partners, simply ignoring the risk is becoming increasingly dangerous.

  • US lawmakers are willing to name Chinese companies partly because they are betting those companies will not go to federal court. Hesai Technology and AMEC successfully sued the Defense Department over their inclusion on a military-linked list; TikTok lost its case but still forced the US government to confront constitutional review when pursuing similar legislation in the future. After the Chevron doctrine was overturned, administrative agencies have less protection, potentially giving Chinese companies more room to challenge US federal administrative action.

  • 洪佳杨’s final argument is to move beyond Western narratives of “democratic AI versus nondemocratic AI” and “China building a data empire.” The underlying principle is “technology neutrality”: technology is like a kitchen knife or any other tool and carries no inherent democratic or autocratic attribute. For companies, technology should return to its basic purpose of serving human development rather than accepting political labels imposed by an adversary.