Skip to content
💡 Innovation Ecosystem

AI model availability by region is now set by lawyers, not benchmarks

Francis Okafor Francis Okafor
9 min read
AI policy export controls open weights model licensing EU AI Act China tech enterprise AI
AI model availability by region is now set by lawyers, not benchmarks
On this page
  1. The gate moved from capability to paperwork
  2. The device stays, the intelligence is rented
  3. Three Tencent licences and a hole in the map
  4. The chip border closed from both sides in the same week
  5. Open weights are the strongest case that all of this is porous
  6. What a two-jurisdiction business actually has to build
  7. Nobody is holding the master list
  8. Tools referenced
  9. Sources

Two stacks of the same phone at Huaqiangbei, one marked 国行 and one marked 港版. Identical chassis. Identical chip. The stall owner explained the gap in about six words: different assistant, different account, different price. He was describing AI model availability by region more accurately than most vendor decks I have read. The hardware does not change across that border. What the hardware is permitted to call does.

Sovereignty over AI stopped being a panel topic and became a procurement fact. You can roughly date the shift. Somewhere between 2 August 2025, when the EU AI Act's obligations for general-purpose model providers took effect, and mid-January 2026, when Chinese customs turned back Nvidia H200 shipments that Washington had approved days earlier. Which models a company or a country may use is now decided by filings, export licences, data residency rules and licence text.

Nobody announced it. It arrived as paperwork.

The gate moved from capability to paperwork

In China, a generative AI service offered to the public has to be filed with the Cyberspace Administration of China before it ships. This is not something you tidy up afterwards. The CAC published a cumulative figure of 346 filed generative AI services as of 31 March 2025, and the register has kept growing since. The filing attaches to the service, not to the model underneath it. Swap your backend and you are back in the queue.

In the EU the mechanism differs but the effect rhymes. Obligations for providers of general-purpose AI models applied from 2 August 2025: technical documentation, a public summary of training content on the Commission's own template, a copyright policy. Providers then got a one-year window. The Commission's enforcement powers arrived on 2 August 2026, four weeks ago. The Digital Omnibus pushed the high-risk system deadlines back by up to sixteen months for standalone systems and twelve for AI embedded in regulated products. It did not push back GPAI enforcement.

Read the two regimes side by side and the shape is obvious. Neither asks how good the model is. Both ask who filed what, and where.

Every gate between a released model and a served user is legal or physical rather than technical; a model can top every benchmark and still fail at any one of these five.
Every gate between a released model and a served user is legal or physical rather than technical; a model can top every benchmark and still fail at any one of these five.
Two governments now hold a veto over the same shipment, and neither veto is written down in a form you can plan against.

The device stays, the intelligence is rented

On 15 July 2026 China's cyberspace regulator registered Apple Intelligence. Alibaba confirmed that its Qwen model will power the version shipping to iPhone, iPad, Mac and Vision Pro in China. Baidu is also involved, in a role Apple has not detailed publicly. No launch date came with the approval. Apple Intelligence had already been live in the United States for roughly two years.

Same device. Same silicon. Different brain, chosen from a regulator's list rather than by an evaluation harness.

Samsung got there earlier and more quietly. The Galaxy S24 shipped Circle to Search in China backed by Baidu's Ernie rather than Google, because Google's mobile services are not available in that market. Samsung's China R&D group has worked with Baidu and with Meitu on features built for that country alone.

The pattern deserves a plain name, because it is spreading. The hardware company keeps the hardware and rents the intelligence, per region, on terms it does not fully control. The bill of materials stays global. The model becomes a supplier relationship: swappable, jurisdiction-scoped, renegotiated on someone else's schedule. Anyone who has spent time in Shenzhen supply chains has seen this move before with connectivity modules and payment stacks. The novelty is that the swapped component is now the one users think of as the product.

Three Tencent licences and a hole in the map

Open the LICENSE file in the Hunyuan3D-2.1 repository. Before any grant language, in capitals, sits a statement that the agreement does not apply in the European Union, United Kingdom and South Korea. The definitions section then defines Territory as the worldwide territory minus exactly those three. Release date 13 June 2025.

HunyuanVideo carries the same construction. So does HY-Motion 1.0. On 30 April 2026 someone opened issue #49 on the HY-Motion repository asking whether the exclusion bars non-commercial academic research in those regions, and who to contact for permission. The issue closed without a public answer.

There is a scale clause underneath it too. Cross one million monthly active users and the community licence stops covering you, at which point you need written commercial terms from Tencent.

This is not a Chinese quirk. Meta does the same thing pointing the other way. The Llama 4 carve-out lives in the Acceptable Use Policy rather than in the licence file, and it withholds the Section 1(a) rights for multimodal models from any individual domiciled in the European Union or any company whose principal place of business is there. End users of a product built on such a model are exempt. The developer building that product is not.

Two companies on opposite sides of a trade war reached the same conclusion independently. When the cost of being wrong in a jurisdiction exceeds the revenue available in it, you exclude the jurisdiction in the licence and move on. The border is a paragraph.

The chip border closed from both sides in the same week

January 2026 is the cleanest illustration anyone is going to get.

On 13 January the Bureau of Industry and Security published a rule moving Nvidia's H200 and AMD's MI325X from presumption of denial to case-by-case licence review for China, subject to memory and processing thresholds. The next day a presidential proclamation set a 25 percent import tariff on those chips, collected as they pass through United States testing facilities before re-export. Functionally an export fee. Volumes were capped at 50 percent of cumulative US sales per chip type, which CNAS put at roughly 850,000 H200s and 40,000 MI325X units.

This was already version two of the arrangement. In August 2025 Nvidia and AMD received licences for the H20 and MI308 in exchange for 15 percent of their China revenue going to the US government.

Then the other side moved. On 7 January, before the US rule landed, The Information reported that Beijing had told domestic firms to pause H200 orders while it decided. After the rule, Chinese customs agents were instructed not to admit H200s at all. No stated reason. No published regulatory instrument. No indication whether it was a ban, a delay or a bargaining position. Component suppliers halted production, which the Financial Times reported separately.

Two governments now hold a veto over the same shipment, and neither veto is written down in a form you can plan against. A compute roadmap that models only one of them is a roadmap with a single point of failure and a risk register that is quietly wrong.

Open weights are the strongest case that all of this is porous

The honest objection to everything above is that weights are files, and files do not respect any of it.

Qwen3-235B-A22B lists apache-2.0 on its Hugging Face card. DeepSeek-V3.2-Exp lists MIT. Those are not bespoke community licences with territory definitions bolted on. They are the two most permissive licences in common use and they carry no geography whatsoever. A checkpoint on an NVMe drive crosses any border a person crosses. Uranium enrichment needed centrifuges and a supply chain that satellites could photograph. Weights need bandwidth.

The carve-outs also erode under competitive pressure. Tencent's Hy3, a 295 billion parameter mixture-of-experts model activating around 21 billion per token, shipped its April 2026 preview under a community licence excluding the EU, UK and South Korea. The full release in July 2026 came out under Apache 2.0 with the exclusion gone. A lab that wants adoption eventually stops charging admission in legal risk.

So the objection is correct on its own terms. It is the best reason to think borders in AI are more porous than the borders around any previous strategic technology, and I would not argue with a line of it.

It answers the wrong question. Possession is not permission, and inference is not deployment. Holding Qwen3 weights in Frankfurt is lawful and useful. It does not let you put a consumer assistant in front of Chinese users, because the CAC filing attaches to the service you operate rather than the licence you hold. It does not exempt you from deployer obligations under the AI Act when you serve an EU user, whatever the weight licence says. It does not conjure GPUs, which is precisely where the enforceable border sits and precisely where the export machinery is aimed. And in the Hunyuan case the territorial restriction reached the outputs, not only the weights, which is a category almost nobody checks.

Open weights move the border from the artefact to the service. That is a real and underrated weakening of state control over this technology. It is not a removal, and building as though it were is how a product ships into a market it was never licensed for.

What a two-jurisdiction business actually has to build

The engineering consequence is unglamorous and mostly organisational.

Treat the model as a supplier and never as a dependency. Any code that hardcodes a model identifier will need rewriting under time pressure on a date chosen by someone else. A thin provider interface costs two days now and saves a quarter later.

Build a model registry where licence metadata is a first-class field rather than a wiki page somebody last touched in March. Licence name, permitted territory, MAU threshold, whether restrictions extend to outputs, filing status per jurisdiction, date last verified. Nobody wants to build this. Every company operating across two regimes ends up building it anyway, usually after a lawyer asks a question that takes a week to answer.

Route on jurisdiction and data residency first, on quality second. That ordering feels wrong to engineers and is correct. It also means accepting that your product is measurably better in one market than in another, then writing down which bar you will actually hold to.

Run the eval suite per approved model per region. The approved set differs by market and quality differs with it. Regression runs across every permitted backend, the kind Promptfoo is built for, catch the drift that a single golden model hides.

Assume access can be withdrawn with no notice, because in January it was. Design one hop of graceful degradation rather than a failover path you have never exercised.

One correction to an assumption I hear constantly. Operating into Nigeria is usually easier than teams expect. The Nigeria Data Protection Act 2023 permits cross-border transfer where the recipient is covered by a law, binding corporate rules, contractual clauses, a code of conduct or a certification affording adequate protection, and the NDPC holds the adequacy determination. The constraints I have watched actually bite on Lagos deployments are latency to the nearest inference region and card rails declining foreign AI subscriptions, not the statute. The legal border there is softer than the infrastructure one. That inverts the China and EU picture entirely, and teams keep planning as if it did not.

Nobody is holding the master list

There is no combined map. No regulator publishes one. The information exists as fragments: a LICENSE file in a public repository, a filing register on a government website, a BIS rule in the Federal Register, a customs instruction with no published text at all. Engineers and lawyers assemble the picture by hand, per product, per quarter, and it is stale before it is finished.

That Hunyuan3D licence has been sitting in a public repository since June 2025 telling European developers in capital letters that they are not licensed. Someone eventually asked what that means for academic research. The issue closed without an answer.

That is the border. Not a wall and not a checkpoint. A text file, and no clear sense of who enforces it.

Tools referenced

DeepSeek, reviewed here: DeepSeek review.

Mistral AI, reviewed here: Mistral AI review.

vLLM, reviewed here: vLLM review.

Ollama, reviewed here: Ollama review.

llama.cpp, reviewed here: llama.cpp review.

LMDeploy, reviewed here: LMDeploy review.

Sources

Tencent Hunyuan 3D 2.1 Community License Agreement (Territory clause, 13 June 2025): https://github.com/Tencent-Hunyuan/Hunyuan3D-2.1/blob/main/LICENSE

HY-Motion 1.0 issue #49: clarification on EU, UK and South Korea exclusion: https://github.com/Tencent-Hunyuan/HY-Motion-1.0/issues/49

Llama 4 Acceptable Use Policy (EU multimodal carve-out): https://github.com/meta-llama/llama-models/blob/main/models/llama4/USE_POLICY.md

CNAS: Unpacking the H200 Export Policy (BIS rule, 25% proclamation, volume caps): https://www.cnas.org/publications/cnas-insights/cnas-insights-unpacking-the-h200-export-policy

Reuters via Yahoo Finance: China asks tech firms to halt orders for Nvidia's H200 chips: https://finance.yahoo.com/news/china-asks-tech-firms-halt-155153074.html

Engadget: Apple Intelligence gets regulatory approval in China with Alibaba's Qwen: https://www.engadget.com/2215606/apple-intelligence-finally-gets-regulatory-approval-in-china/

European Commission AI Act Service Desk FAQ (GPAI obligations and enforcement dates): https://ai-act-service-desk.ec.europa.eu/en/faq

Qwen3-235B-A22B model card, licence apache-2.0: https://huggingface.co/Qwen/Qwen3-235B-A22B

Frequently Asked Questions

Why does Apple Intelligence use a different AI model in China?

China requires generative AI services offered to the public to be registered with the Cyberspace Administration of China before launch, and foreign frontier models generally cannot clear that bar on their own. Apple Intelligence was added to the CAC's list on 15 July 2026, with Alibaba confirming that its Qwen model will power the Chinese version on iPhone, iPad, Mac and Vision Pro. Baidu is also working on features for the Chinese release. By that point Apple Intelligence had already been available in the United States for roughly two years.

Can I use Tencent Hunyuan models in the EU, UK or South Korea?

Several Tencent Hunyuan releases use a community licence whose Territory is defined as worldwide excluding the European Union, United Kingdom and South Korea, with an opening statement in capitals that the agreement does not apply in those places. Hunyuan3D-2.1, released 13 June 2025, and HunyuanVideo both use that construction, and in some cases the restriction covers model outputs as well as the weights. Not every Tencent release does this: the full Hy3 model shipped under Apache 2.0 in July 2026 with no geographic restriction at all. Check the LICENSE file for the specific model, because terms differ between releases from the same lab.

Do open-weight models like Qwen and DeepSeek avoid regional AI restrictions?

Only partly. Qwen3-235B-A22B is published under Apache 2.0 and DeepSeek-V3.2-Exp under MIT, and neither licence contains any territorial restriction, so downloading and running the weights is unrestricted. Regulation still attaches to the service you operate rather than the file you hold. Serving Chinese users a public generative AI product still requires a CAC filing, serving EU users still triggers AI Act deployer obligations, and running large models still requires GPUs that export controls do reach. Open weights move the enforcement point from the model to the deployment.