There are genuine data export and security risks with Chinese-based models that cannot be easily dismissed, and claiming on-prem hosting solves all concerns is insufficient for most enterprise CIOs.
Jason argues that despite libertarian arguments against banning Chinese models, the legitimate data export risks — based on both technical complexity and historical precedent with Chinese tech products — mean most CIOs and enterprises will remain cautious, limiting how deeply these models can penetrate US enterprise markets regardless of policy. ✦ AI generated
Jason · 20VC · 2026-07-23 · original ↗
starts at this moment · 11:22
I don't think you're going to convince me there aren't some data export risks with China based models. You're just not going to convince me based on what I've done with all our agents in building. And if you're not going to convince me, I don't think you're going to convince 99% of the world that there isn't some security leakage issue. It's already scary how much of our data we put into these closed source models in the US. It is scary. Here's Elon saying scam altman every day to create distrust. Right? I there are we cannot understand what these models do. They are connected to the internet. We cannot even even if we have fable read it and have it read it itself. I don't think you're going to convince most of us there isn't data export risk. And so I think that's going to lead to tighter constriction than this you know leave everything open so we can compete in my portfolio company's benefit uh argument. I think every CIO is being told right now, oh don't worry if you hosted onrem, you remove any security risks and the back door then is removed that could potentially be there. Why would you not be alleviated by that reassurance of onrem would solve that solution? Why would you not be reassured? Rory's more of a historian here than me. You can you can mock our regulatory bottles bodies, but they're here to answer those questions for us. Is it safe to drink that cup of coffee? The American Heart Association, I think, just said six cups are safe now, right? This week, now I know. Now I'm cool. Right. I was a little worried about my caffeine consumption when we did. No, no, seriously. I mean, I'm not sure they're right. Who has said my data is not being exported through the most complicated, borderline self-aware software of our lifetimes? Who who can say that? Especially, and I and I I I admit there this is can be triggering. There is a history of data export risk with Chinese products. These are companies that are arguably run by the PLA. I'm not I'm just saying my lifetime of experience says I'm not confident there is and and just the internet telling a CIO I don't think is good enough and if I were a CIO it wouldn't be good enough to me unless as long as if I thought my job was on the line.
verbatim transcript · starts at 11:22
11:22convince me there aren't some data export risks with China based models. You're just not going to convince me based on what I've done with all our agents in building. And if you're not going to convince me, I don't think you're going to convince 99% of the world that there isn't some security leakage issue. It's already scary how much of our data we put into these closed source models in the US. It is
11:40scary. Here's Elon saying scam altman every day to create distrust. Right? I there are we cannot understand what these models do. They are connected to the internet. We cannot even even if we have fable read it and have it read it itself. I don't think you're going to convince most of us there isn't data export risk. And so I think that's going to lead to tighter constriction than
12:00this you know leave everything open so we can compete in my portfolio company's benefit uh argument. I think every CIO is being told right now, oh don't worry if you hosted onrem, you remove any security risks and the back door then is removed that could potentially be there. Why would you not be alleviated by that reassurance of onrem would solve that solution? Why would you not be
12:25reassured? Rory's more of a historian here than me. You can you can mock our regulatory bottles bodies, but they're here to answer those questions for us. Is it safe to drink that cup of coffee? The American Heart Association, I think, just said six cups are safe now, right? This week, now I know. Now I'm cool. Right. I was a little worried about my caffeine consumption when we did. No,
12:42no, seriously. I mean, I'm not sure they're right. Who has said my data is not being exported through the most complicated, borderline self-aware software of our lifetimes? Who who can say that? Especially, and I and I I I admit there this is can be triggering. There is a history of data export risk with Chinese products. These are companies that are arguably run by the PLA. I'm not I'm just saying my lifetime
13:06of experience says I'm not confident there is and and just the internet telling a CIO I don't think is good enough and if I were a CIO it wouldn't be good enough to me unless as long as if I thought my job was on the line. I don't want to take this risk CIO of some Fortune 500 global 2000 company unless everyone I don't I don't know man.
13:24>> I don't think it's triggering to say that there are IP risks in this. I mean I gen at the risk of being kind of level-headed here the data is very clear that you know technically important US companies Boeing for example suffer continual cyber attacks many of which are attributable sovereign state actors including China it's a thing so we're not being you know we're not being sensationalist or alarmist you know
13:50it'll be naive not not to put it on the table you're right both comments second companies I do I'm thinking about can you the problem proving a negative is can you know if you have an remember these are open I occasionally say open source incorrectly they are open weight which means you can see the weights but and you can run it yourself but you don't have technically the full
- ·CIOs will not be convinced these models lack security leakage
- ·Closed-source US models already raise data concerns
- ·Chinese models are connected to the internet and opaque
- ·Historical precedent with Chinese tech products reinforces risk
- ·CIOs are told on-prem removes all backdoor risk
- ·But no one can certify data is not being exported
- ·Software is too complex — borderline self-aware — to audit
- ·Regulatory bodies exist precisely for this uncertainty