Foreign open-weight AI models have moved from a technical curiosity to a recurring boardroom question. In client conversation after client conversation, the discussion arrives at the same point: a Chinese open-weight model (Moonshot AI's Kimi K3 or Zhipu's GLM-5.2, for example) is outperforming or undercutting whatever the organization had budgeted for, and someone asks why it isn't in use. The performance gap to frontier closed models has narrowed to under a year, licensing terms are often more permissive, and the cost per token is a fraction of what established providers charge. On pure economics, ignoring these models is increasingly the more expensive choice.
The instinct in the boardroom is to frame this as a binary: are foreign open-weight models safe for the enterprise, or not? That framing is the wrong one, and it is precisely what leaves executives stuck. The more useful question, the one a Chief Information Security Officer should already be asking, is this: what has to hold true about how an organization deploys one of these models before its country of origin stops being the dominant variable in the risk calculation? This paper sets out to answer that question.
The Board Question on Foreign Open-Weight AI Models