There are major security concerns and risks with all open-weight AI models deployed within your environment, and the following is just one example of a scenario with concerns of espionage, rogue agents and censorship. 

In January 2025, a Chinese technology company released an AI model called DeepSeek that, on paper, went toe-to-toe with OpenAI's best reasoning models for a fraction of the reported training cost. This caused NVIDIA to lose roughly $600 billion in market cap in a single day. At the same time, Microsoft's security team and researchers had reportedly flagged large volumes of data leaving OpenAI's API through an account they believed was tied to DeepSeek.[1] OpenAI confirmed days later it was "aware of and reviewing indications" that DeepSeek had "inappropriately distilled" its models.[2]

That story has generally been told as a business headline — cheaper AI, disrupted valuations, a new startup out-innovating Silicon Valley. It's a more significant story than that. It's a story about how a foreign adversary can legally, technically, and repeatedly extract the intellectual output of American AI labs, wrap it in a free download, and hand it back to the world as an "open" model. Once that model is sitting inside your enterprise, the questions aren't about who trained it. The questions are about what it can see, what it can send home, what it can do in/to your environment and whether you'd even know. 

Let's walk through how we got here and why governance must be the first standing pillar in your AI security program.

What Are Open-Weight AI Models?

Open-weight means the trained parameters, the weights, are public. Anyone can download the model, run it locally, fine-tune it. That's not open source. Open source also requires the training code and enough data transparency to reproduce how the model was built, plus a license that lets you use, modify, and redistribute it freely. Meta's Llama, for example, is Open-Weight; it ships weights and inference code, but the license restricts commercial use, so the Open Source Initiative won't call it open source.[3] [4]

Closed models sit at the other end: Some examples are OpenAI's GPT family, Anthropic's Claude and Google's Gemini. You get an API and a product. The weights never get revealed.

Open-weight is everywhere now: examples include Llama, Mistral, Qwen, Gemma and DeepSeek. Even OpenAI has gpt-oss.[5] None of that is inherently good or bad, it's just a distribution model.

What Is Model Distillation?

Model distillation is a well-established machine learning technique, and most major labs use some version of it internally. The idea is to train a smaller "student" model to mimic the behavior of a larger, more capable "teacher" model. Classically, that means giving the student access to the teacher's full output, not just the final answer, but the underlying probability distribution behind it, so the student can absorb the teacher's reasoning patterns far more efficiently than training from scratch.

When distilling from another model, the lab will ask the model thousands or even millions of questions, then feed those questions and the output into their own model to train, but lacking the safeguards built into the original model. No breach required and no weights or code stolen. Just a lot of API calls as normal usage. That's the technique OpenAI has publicly said it believes DeepSeek used against its models.[6]

How China Is Distilling U.S. AI Models

In January 2025, OpenAI said it was looking into signs that DeepSeek had distilled its models.[7] Microsoft had reportedly already caught a DeepSeek-linked account pulling huge volumes of data through OpenAI's API months before that.[8] The White House's AI czar called the evidence "substantial."[9] Then in April 2025, a bipartisan House committee published OpenAI's own account of it: DeepSeek employees got around OpenAI's guardrails to pull reasoning outputs, using fake names and third-party payment channels to stay under the radar.[10]

This is an Espionage and Cyber Security Problem.

China's 2017 National Intelligence Law requires every organization and citizen to "support, assist, and cooperate with" the state's intelligence work.[11] It applies to every private company, including AI labs. Layer on top of that Beijing's Military-Civil Fusion strategy, a documented national policy (per the U.S. State Department and Congressional Research Service) to erase the line between civilian commercial research and military application, with AI explicitly named as a priority technology alongside quantum computing and semiconductors.[12] Add "Made in China 2025," the industrial policy aimed at domestic dominance across advanced tech sectors.[13] This means that when a Chinese AI company hands you a free, best-in-class model, "free" comes with a cost paid by you.

Here are the concerns and real-world problems being observed:

  • Security researchers at NowSecure and Feroot Security independently found DeepSeek's mobile app transmitting data with weak, hardcoded encryption to Volcengine (ByteDance's cloud),[14] and identified code linking DeepSeek's login infrastructure to China Mobile — a carrier the FCC banned from U.S. operations in 2019 and the Department of Defense designated a "Chinese military company" in 2022.[15]
  • DeepSeek's censorship is easy to reproduce and well documented — it deflects or refuses to answer questions about Tiananmen Square, Taiwan, Xi Jinping, and the treatment of Uyghurs.[16]
  • CrowdStrike researchers found in November 2025 that DeepSeek-R1 generates significantly more vulnerable code — in some tests, up to 50% more — when a prompt simply mentions politically sensitive terms like "Tibet" or "Uyghurs." CrowdStrike's read is that this is emergent bias from politically filtered training data rather than a deliberately engineered trigger, but the effect is the same either way: the model's behavior changes based on politically loaded input, and it can ship you a security hole.[17]

Add to that a security concept you should be aware of: the neural backdoor — a trigger phrase or pattern baked into a model that activates undetectable hidden behavior on demand, whether that's exfiltrating data, degrading output, or opening a door into whatever environment the model is plugged into. It's the AI-era version of a concern the U.S. government has raised for years about Huawei telecom hardware, as an example, potentially serving as a vector for adversary-state access.[18] Because it is difficult, and often impossible to see agent reasoning, or "thinking", at this point is it theory and has not yet been observed. However, it is a concept that is viable, can happen and should be on your radar.

Because of this, the U.S. Commerce Department, the Navy, and both chambers of Congress have banned DeepSeek from government devices,[19] and several states have followed suit.[20] There's no federal ban on DeepSeek in law today, but there are pending bills to take this further.[21]

Where WWT's ARMOR Framework Comes In

This is how WWT's ARMOR framework can help, the AI Readiness Model for Operational Resilience. ARMOR is a vendor-agnostic framework co-developed with NVIDIA that secures AI deployments from planning through day-to-day operations.[22] It covers seven domains: Governance, Risk and Compliance; Model Protection; Secure AI Operations; Secure Software Development Lifecycle; Infrastructure Security; Identity Security; and Data Security; with Cyber Resilience being a wrapper domain around all. All seven matter here, but I want to focus on two things: governing the decision to bring a model in (Governance), and the ability to see what it does once it's there (Observability).

The default answer on downloading and running an open-weight model should be no. Pulling a black box of trained behavior into your environment, from a source you can't audit, built by a company operating under laws that require it to cooperate with state intelligence should be sufficient danger signals to justify the decision. There are legitimate use cases, air-gapped research, controlled testing, and workloads where data sovereignty leaves you no other option. But if you're going to do it, you need to go in with eyes open and controls in place. Here's what that looks like.

Start with governance. Nothing about DeepSeek requires a sophisticated attack. It requires an employee finding a capable model on Hugging Face, downloading it, and standing it up because it was free and it worked. That's not a security failure; it's a governance gap. If you don't have a policy that says "here's how we evaluate a foundation model before it touches our data," someone in your organization will make that decision for you, and they won't be thinking about Volcengine, China Mobile, or neural backdoors when they do it. It's Shadow IT from the early 2000s, now turned into Shadow AI. ARMOR's Governance, Risk and Compliance domain closes that gap: a documented model selection process, an AI Bill of Materials (AI-BOM) so you know every model running in your environment, who built it, and what it was trained on, and a maturity model that grades you from ad hoc to fully integrated with recurring audits and named owners.

Scan the model before it goes anywhere near production. ARMOR's Model Protection domain calls for scanning every model, open-weight or not, for vulnerabilities, backdoors, adversarial susceptibility, and bias. Treat model weights like any other artifact in your software supply chain. Most traditional scanners can't read them, so make sure the tooling you're using can.

Assume the model will try to phone home, and build so you'd catch it. This is where most organizations are exposed. A model doesn't need a deliberate backdoor to exfiltrate data. It needs a network path. So the questions are simple: Do you have observability into the traffic your AI workloads generate? Can you see the difference between normal inference traffic and a model, or the stack around it, opening a connection it shouldn't? Can you quickly identify a connection heading to an IP or domain in an adversarial country, and shut it down? If any of those are a no, that's a gap to close before you bring in an open-weight model from anyone, let alone from China. ARMOR's Secure AI Operations domain is where this lives: threat detection and security operations built for AI workloads. In practice, WWT recommends network detection and response (NDR) on the segments where models run, egress filtering with deny-by-default and geo-based blocking, and DNS monitoring so a model can't quietly resolve its way out. Additionally, in this new world of AI, your Security Operations Center (SOC) should have the capability of alerting on AI workload traffic the same way it alerts on a domain controller talking to a country it has no business talking to.

Protect the data the model can see. ARMOR's Data Security domain covers classification, data loss prevention (DLP), and lifecycle controls sized for AI-scale ingestion and inference. The exfiltration risk isn't just the model sending data to a foreign server. It's also your data leaking out through prompts, outputs, or a model quietly memorizing what you feed it. Know what data the model can reach and make sure it's only what it needs.

Contain the blast radius. ARMOR's Identity Security domain (zero standing privilege, least-privilege access, machine identities for models) and Infrastructure Security domain (network segmentation for AI workloads) work together so that if a model attempts to do something it shouldn't, it can't reach much. An AI workload should never sit on a flat network with your crown jewels.

You don't necessarily have to ban open-weight models. Outright bans may push people toward shadow AI you can't see at all. What you must do is govern the decision to adopt one, then watch it like you'd watch any untrusted system on your network. The DeepSeek story isn't really about DeepSeek. It's a preview of what happens to any organization that treats "it's free and it's good enough" as a security clearance.

If you want to know where you stand, whether you can see every model running in your environment, and whether you'd catch one reaching out to somewhere it shouldn't, that's a conversation WWT is ready to have.


 


[1] TechCrunch — "Microsoft probing whether DeepSeek improperly used OpenAI APIs" (January 29, 2025). https://techcrunch.com/2025/01/29/microsoft-probing-whether-deepseek-improperly-used-openais-api/

[2] Axios — "OpenAI says DeepSeek may have 'inappropriately' used its models' output" (January 29, 2025). https://www.axios.com/2025/01/29/openai-deepseek-ai-models-data-training

[3] Open Source Initiative — "Open Weights: not quite what you've been told" (January 29, 2025). https://opensource.org/ai/open-weights

[4] Open Source Initiative — "Meta's LLaMa license is still not Open Source" (February 18, 2025). https://opensource.org/blog/metas-llama-license-is-still-not-open-source

[5] OpenAI — "Introducing gpt-oss" (August 5, 2025). https://openai.com/index/introducing-gpt-oss/

[6] Axios — "OpenAI says DeepSeek may have 'inappropriately' used its models' output" (January 29, 2025). https://www.axios.com/2025/01/29/openai-deepseek-ai-models-data-training

[7] Axios — "OpenAI says DeepSeek may have 'inappropriately' used its models' output" (January 29, 2025). https://www.axios.com/2025/01/29/openai-deepseek-ai-models-data-training

[8] TechCrunch — "Microsoft probing whether DeepSeek improperly used OpenAI APIs" (January 29, 2025). https://techcrunch.com/2025/01/29/microsoft-probing-whether-deepseek-improperly-used-openais-api/

[9] Fortune — "DeepSeek used OpenAI's model to train its competitor using 'distillation,' White House AI czar says" (January 29, 2025). https://fortune.com/2025/01/29/deepseek-openais-what-is-distillation-david-sacks/

[10] U.S. House Select Committee on the CCP — "DeepSeek Unmasked: Exposing the CCP's Latest Tool for Spying, Stealing, and Subverting U.S. Export Control Restrictions" (April 16, 2025). https://chinaselectcommittee.house.gov/sites/evo-subsites/selectcommitteeontheccp.house.gov/files/evo-media-document/DeepSeek%20Final.pdf

[11] China Law Translate — "PRC National Intelligence Law (2017, as amended 2018), Article 7" (June 27, 2017). https://www.chinalawtranslate.com/en/national-intelligence-law-of-the-p-r-c-2017/

[12] U.S. Department of State — "The Chinese Communist Party's Military-Civil Fusion Policy" (2020, archived). https://2017-2021.state.gov/military-civil-fusion/

[13] Congressional Research Service — "'Made in China 2025' Industrial Policies: Issues for Congress (IF10964)" (updated August 11, 2020). https://www.congress.gov/crs-product/IF10964

[14] NowSecure — "NowSecure Uncovers Multiple Security and Privacy Flaws in DeepSeek iOS Mobile App" (February 6, 2025). https://www.nowsecure.com/blog/2025/02/06/nowsecure-uncovers-multiple-security-and-privacy-flaws-in-deepseek-ios-mobile-app/

[15] Associated Press (via PBS News) — "Researchers link DeepSeek's chatbot to Chinese telecom banned from operating in U.S." (February 5, 2025). https://www.pbs.org/newshour/world/researchers-link-deepseeks-chatbot-to-chinese-mobile-telecom-banned-from-operating-in-u-s

Feroot Security — "Feroot Security Research Reveals DeepSeek AI's Hidden Data Pipeline to China" (February 5, 2025). https://www.feroot.com/news/feroot-security-research-reveals-deepseek-ais-hidden-data-pipeline-to-china/

U.S. House Select Committee on the CCP — "DeepSeek Unmasked: Exposing the CCP's Latest Tool for Spying, Stealing, and Subverting U.S. Export Control Restrictions" (April 16, 2025). https://chinaselectcommittee.house.gov/sites/evo-subsites/selectcommitteeontheccp.house.gov/files/evo-media-document/DeepSeek%20Final.pdf

[16] Promptfoo — "1,156 Questions Censored by DeepSeek" (January 28, 2025). https://www.promptfoo.dev/blog/deepseek-censorship/

U.S. House Select Committee on the CCP — "DeepSeek Unmasked: Exposing the CCP's Latest Tool for Spying, Stealing, and Subverting U.S. Export Control Restrictions" (April 16, 2025). https://chinaselectcommittee.house.gov/sites/evo-subsites/selectcommitteeontheccp.house.gov/files/evo-media-document/DeepSeek%20Final.pdf

[17] CrowdStrike — "CrowdStrike Research: Security Flaws in DeepSeek-Generated Code Linked to Political Triggers" (November 20, 2025). https://www.crowdstrike.com/en-us/blog/crowdstrike-researchers-identify-hidden-vulnerabilities-ai-coded-software/

[18] Federal Communications Commission — "Covered List — communications equipment and services deemed an unacceptable risk to national security (includes Huawei)" (updated September 3, 2024). https://www.fcc.gov/supplychain/coveredlist

[19] Reuters (via U.S. News & World Report) — "US Commerce Department Bureaus Ban China's DeepSeek on Government Devices, Sources Say" (March 17, 2025). https://www.usnews.com/news/top-news/articles/2025-03-17/us-commerce-department-bureaus-ban-chinas-deepseek-on-government-devices-sources-say

CNBC — "U.S. Navy bans use of DeepSeek due to 'security and ethical concerns'" (January 28, 2025). https://www.cnbc.com/2025/01/28/us-navy-restricts-use-of-deepseek-ai-imperative-to-avoid-using.html

Axios — "Scoop: Congress bans staff use of DeepSeek" (January 30, 2025). https://www.axios.com/2025/01/30/house-congress-bans-deepseek-ai

Axios — "Scoop: DeepSeek banned on Senate devices" (February 10, 2025). https://www.axios.com/pro/tech-policy/2025/02/10/deepseek-banned-on-senate-devices

[20] Office of Governor Kathy Hochul — "Governor Hochul Issues Statewide Ban on DeepSeek Artificial Intelligence for Government Devices and Networks" (February 10, 2025). https://www.governor.ny.gov/news/governor-hochul-issues-statewide-ban-deepseek-artificial-intelligence-government-devices-and

Office of the Texas Governor — "Governor Abbott Announces Ban on Chinese AI, Social Media Apps" (January 31, 2025). https://gov.texas.gov/news/post/governor-abbott-announces-ban-on-chinese-ai-social-media-apps

[21] Congress.gov — "H.R. 1121 — No DeepSeek on Government Devices Act (119th Congress)" (introduced February 7, 2025). https://www.congress.gov/bill/119th-congress/house-bill/1121

[22] World Wide Technology — "AI Readiness Model for Operational Resilience (ARMOR) — Overview" (n.d.). https://www.wwt.com/atc-capabilities/ai-readiness-model-for-operational-resilience/overview