Europe currently lacks a frontier closed model at GPT or Claude parity; its strongest open-weight champion, Mistral, is competitive but not at the absolute frontier . So the realistic short-term choice for most European businesses is between a US proprietary model and a Chinese open-weight one, not a European alternative.
This is where deployment mode creates a legal chasm. The Sovereign AI Registry rates DeepSeek R1 as "EU Procurement Ready" when self-hosted, noting: "Data flows pass entirely — same weights, zero PRC data flow" . The GDPR risk attaches to the hosted service, not the open weights themselves
.
Using Chinese open-weight models creates a downstream dependency on Chinese AI labs for updates, security patches, and future model versions. CNBC noted the risk that "American companies become dependent on Chinese technology" — the same logic applies to Europe . The Centre for European Policy warns that Chinese models may contain "backdoors that cannot be removed even through intensive safety training procedures" and that political control is "deeply embedded in the training data architecture"
.
However, both options ultimately depend on US-designed chips (Nvidia, AMD) or Chinese alternatives subject to export controls. A Chinese model running on European hardware still depends on a global semiconductor supply chain.
Using US models ties the business to US cloud providers and single-vendor API pricing. As US AI costs have risen, global businesses are actively pivoting to cheaper alternatives . Goldman Sachs noted that Chinese open-weight models "are reaching a critical point of intelligence that makes them viable alternatives"
.
Chinese open-weight models are 60–90% cheaper than flagship US proprietary models . DeepSeek V4 Flash lists at $0.14 per million input tokens, compared to GPT-5.2 at $1.75 . A workflow costing $10,000 per month on a leading US model might run at $1,000 to $4,000 using a Chinese open-weight alternative .
By July 2026, US companies were routing more than 30% of their OpenRouter tokens to Chinese open models, up from just 4.5% in the first half of 2025 . Coinbase announced in June 2026 that it had redirected routine engineering workloads from OpenAI to open-weight Chinese models from Zhipu AI and DeepSeek .
Many European firms are adopting a "workload routing" strategy: using cheaper open-weight models for non-sensitive tasks and premium models for high-stakes ones, reducing reliance on any single provider . This hybrid approach allows businesses to balance cost, risk, and performance.
A defensible model-selection strategy involves four steps, according to The National Law Review: map which workflows touch which models; identify where export-controlled technology enters those workflows; set a model-and-deployment posture for each workload; and document the diligence thoroughly .
Open weights are "unrecallable" — once released, safety guardrails can be removed with minimal effort, and thousands of safety-stripped variants already circulate freely . The equalizing potential of open-weight models and the security risks that accompany them are inseparable
.
The EU AI Act, which applies to general-purpose AI models placed on the EU market as of August 2025, presumes that models trained above 10²⁵ floating-point operations carry systemic risk and must meet heightened safety and transparency duties . Both Chinese open-weight and US proprietary models will need to comply.
Bottom line: The choice for European businesses is not between "Chinese" and "US" as monolithic categories. Self-hosting a Chinese open-weight model on European infrastructure can deliver better data control and operational sovereignty than relying on a US proprietary API — but it introduces different supply-chain dependencies, safety risks, and political concerns. The most practical path for many firms is a hybrid strategy that routes sensitive workloads to self-hosted open models and reserves US proprietary APIs for less sensitive, high-performance tasks .