All insights
AI & Digital4 August 20269 min

The Chinese AI model is not the decision. The hosting is.

DeepSeek, Qwen, Kimi and GLM can be accessed as China-hosted services or deployed under a company's own controls. The model may be similar; the compliance position is not.

Recently, several clients have asked me a version of the same question: which Chinese AI model should we be using?

It is a fair thing to wonder about. DeepSeek, Alibaba's Qwen, Moonshot's Kimi and Z.ai's GLM are no longer interesting only because they are cheaper than American models. They are credible systems in their own right. But choosing among them is not the first decision a European company needs to make.

The model matters. Where and how you run it matters more.

That is the part many buyers miss. They treat Chinese AI as a shopping exercise: compare a leaderboard, pick a name and connect an API. In practice, the same model family can sit inside very different technical and legal arrangements. One route sends prompts to a provider's service in China. Another runs published weights through a European cloud platform. A third keeps the model in a company's own environment.

Those are not three versions of the same procurement decision. They are three different risk decisions that happen to use related technology.

Open weights split the model from the service

Several leading Chinese model families publish weights that can be deployed independently of the developer's consumer service. DeepSeek-V3 supports commercial use, Kimi K2 releases its code and weights under a modified MIT licence, and the Qwen and GLM families both have downloadable variants.

The licence still needs reading model by model. Kimi's modification, for example, adds an attribution requirement above specified user or revenue thresholds. Qwen3's open-weight releases use Apache 2.0, while GLM separates the repository's code licence from the licence applying to particular model weights. "Open weights" means the model can be deployed elsewhere; it does not mean every release carries identical rights or obligations.

It also does not guarantee identical output. A hosted provider may use a different model revision, quantisation, system prompt, safety layer or inference configuration. The useful point is narrower: the model developer does not have to be the organisation processing your prompts.

That creates a fork that does not exist in the same way with a closed model. A company can evaluate a Chinese-developed model while choosing a European processor, a private cloud deployment or its own hardware. The origin of the weights and the destination of the data become separate questions.

The European issue is the data path

China does not have an EU adequacy decision. That does not make every transfer of personal data to China automatically unlawful, but it means a company cannot treat the transfer like one within the European Economic Area. The European Commission's rules on international transfers require another valid mechanism and appropriate safeguards, such as standard contractual clauses where they are available and sufficient for the circumstances.

The recent DeepSeek enforcement record shows why procurement cannot stop at model quality.

On 30 January 2025, Italy's data protection authority ordered an immediate limitation on the processing of Italian users' data by the Chinese companies providing the DeepSeek chatbot. In June 2025, the Berlin Commissioner for Data Protection notified Apple and Google that the app was unlawful content, citing transfers of user prompts, files and other personal data to processors and servers in China without convincing evidence of equivalent protection. The European Data Protection Board then expanded its AI enforcement coordination to include DeepSeek as national authorities examined the service.

These actions concerned the service and its processing of personal data. The measures described by the regulators did not address model weights running in an environment with a different data path.

That distinction is doing a great deal of work. It is also why saying "we use DeepSeek" tells a compliance officer almost nothing useful. The next questions are:

  • Who operates the endpoint?
  • In which country are prompts, outputs, logs and backups processed?
  • Which subprocessors and support teams can access them?
  • Are prompts retained or used for training?
  • What contractual transfer mechanism applies?
  • Can the organisation enforce deletion, audit and incident-response requirements?
  • Does any telemetry or remote support create a transfer outside the approved region?

The server location is the beginning of that review, not the end. A Frankfurt label does not help if logs are copied elsewhere or administrators outside the region can routinely access the system.

The practical answer is an operating model, not a model name

For most European firms, a sensible policy has several lanes.

General internal work. Drafting, translation, reporting, coding and document analysis can be good candidates for Chinese open-weight models, provided the company uses an approved enterprise environment and keeps confidential or personal data within the controls set for that environment. This is where price competition becomes commercially useful. The published API price cards from DeepSeek illustrate why buyers are interested, although list prices are volatile and do not include hosting, integration, security or governance costs.

Personal data. Do not put European personal data into a China-hosted consumer chatbot as a default business practice. If a proposed service transfers data outside the EEA, legal and security teams need to approve the transfer mechanism, contractual protections, technical measures and use case before deployment. For many routine workloads, an EEA-operated endpoint can avoid creating that transfer, provided subprocessors, support access, logs and backups stay within the approved boundary too.

Sensitive or regulated data. Where client confidentiality, trade secrets, health information or regulated records are involved, self-hosting or a tightly controlled private deployment is the stronger starting point. Open weights make that possible, but self-hosting is not automatically safe: the company becomes responsible for patching, identity controls, logging, model access, output handling and the surrounding software supply chain.

Consumer chat services. These should not become an enterprise architecture by accident. A public chatbot can be useful for low-risk experimentation, but its privacy notice and consumer terms are not a substitute for a data processing agreement and an assessed deployment.

The model evaluation comes after those lanes are defined. Then it becomes worth testing Chinese and non-Chinese models against the company's actual tasks: Chinese and European language quality, retrieval accuracy, tool use, latency, hallucination rate, security behaviour, licensing and total operating cost. A leaderboard cannot answer those questions for you.

Asia needs a different policy, but not an absence of policy

There is a second layer for companies operating across regions. In Singapore and Hong Kong, direct access to Chinese AI services is often more commercially familiar than it is in Europe. Clients may expect their partners to understand these tools, and a policy designed only around Frankfurt can become needlessly restrictive in an Asian operation.

But the alternative is not to copy casual consumer habits into the business. Singapore's Transfer Limitation Obligation requires comparable protection when personal data is transferred outside Singapore. Hong Kong's privacy regulator has issued both recommended clauses for cross-border transfers and an AI personal-data protection framework for organisations procuring and using AI.

So the honest answer to "what is our Chinese AI strategy?" may be that a company needs more than one deployment profile. The European profile may prioritise EEA processing and tightly documented transfers. A Singapore or Hong Kong profile may permit different providers and locations under local rules and contracts. The applications can still share evaluation methods, security standards and governance.

The mistake is assuming that one regional habit travels safely everywhere: applying a Frankfurt policy unchanged in Singapore may block useful adoption; applying Singapore habits unchanged in Frankfurt may create a regulatory problem.

What this means if you are on the European side

Do not begin with the model shortlist. Begin with the data classification, permitted locations, processor requirements and access controls. That architecture will remove some options before a benchmark begins.

Separate origin from operation. A Chinese-developed model running under a European company's own controls is not the same service as the developer's China-hosted chatbot. Procurement language should name the model, operator, region and data terms rather than collapsing all four into "Chinese AI".

Treat open weights as leverage, not a compliance certificate. They give buyers more choice over who processes the data and where. They do not remove licence review, cybersecurity work, model evaluation or accountability for the deployment.

Build regional policies deliberately. Europe, Singapore and Hong Kong do not present the same transfer rules or market expectations. A company operating across them should design those differences rather than discover them through an incident.

The firms that come out ahead will not be the ones with the cleverest access to a particular model. Model access is being commoditised quickly. The advantage will belong to those that understood early that "Chinese AI" was never one decision. It was at least two: what to run, and where and under whose control to run it.

The second question is where both the savings and the risk live.

This is a general view of the market as of August 2026, not legal or regulatory advice. Any deployment involving personal data should be reviewed by qualified counsel and the organisation's data protection and security teams.

Sources

Discuss this topic

Want to go deeper on this?

Send a note and it reaches our advisory team directly.

Have a question not covered above?

Leave a note and it reaches our advisory team directly.