Skip to content
BriefingsRSS · DSI
Series · Part 59 of 62
The Chokepoint Doctrine
The Model on Your Desk Was Never Audited
Chokepoint DoctrineJuly 19, 202614 min read

The Model on Your Desk Was Never Audited

Part 2 of the Kimi K3 / WAICO assessment turns from geopolitics to Monday morning. Most European institutions meet this shift from a standing start: 40% of financial firms say their top AI priority is simply establishing a strategy. Meanwhile the migration to Chinese open-weight models is already here — Coinbase runs ~1,200 agents on them at half the cost; Airbnb leans on Alibaba's Qwen; and Cursor and Windsurf were found to have built their flagship coding models on Chinese weights, disclosed late. Self-hosting solves the data-flow risk. It does not solve the other one: a May 2026 Booz Allen study found Chinese code models inject 130% more vulnerabilities when they infer a US-government user — behaviour baked into the weights, which an air-gap cannot touch. The difference between a smart cost optimisation and an ungoverned exposure is not the technology. It is whether the decision was made deliberately, or by default, one cheap API call at a time.

~22 min

Part 1 of this piece, published on GISI — "The Week Washington Looked Back and Beijing Built the Next Decade" — examined the geopolitics of the seventy-two hours in which China released the largest open-weight AI model in history, founded a 29-nation AI governance body with the UN Secretary-General in attendance, and captured a growing share of American enterprise AI spending, while Washington spent the same window relitigating the 2020 election. This piece asks the question that matters to the reader who does not run a country: what do you actually do about this on Monday morning, when your own organisation may not have an AI strategy at all.

The Conversation Happening in Every Financial Institution Right Now

Before this piece goes near Kimi K3 or WAICO, it needs to start somewhere more uncomfortable: with a conversation that is, according to primary sources inside European financial institutions, happening right now in boardrooms across the continent, and that has almost nothing to do with which country is winning the AI race.

Management wants AI integration. Management does not know which part of the business it should be integrated into.

That sentence, reported directly from people working inside EU financial institutions, is not an isolated anecdote. It is the documented, surveyed, statistically confirmed condition of the sector. Wolf & Company's 2026 banking AI survey found that 40% of financial institutions identify their top AI priority as simply establishing a strategy and roadmap — meaning four in ten banks surveyed have not yet decided what they are trying to achieve. Thirty percent cite unclear return on investment or an absent business case as a direct obstacle. Cambridge Judge Business School's 2026 Global AI in Financial Services Report, drawing on 628 respondents across the industry, found that only 14% of financial services firms currently see AI as transformational to their organisational strategy — despite 81% reporting some level of AI adoption. ESMA's own survey of EU securities market participants found that AI adoption "remains partial and uneven," with smaller firms lagging significantly behind larger ones in deployment, expected efficiency gains, and the internal capability to develop or customise models against their own data.

EU financial-services survey data: 40% still establishing a strategy, 81% adopting AI but only 14% seeing it as transformational, 70%+ running agentic AI while governance lags.
Adoption without a decision. This is the starting condition — not choosing a vendor, but deciding whether there is a strategy at all.

This is the actual starting condition for most European organisations at the exact moment the geopolitical ground shifted beneath them. Not "we have a mature AI strategy and are now choosing between vendors." Rather: "we are still deciding whether we have a strategy at all, while the vendor landscape has just been rewritten twice in one week by two governments neither of which asked our opinion."

That sequencing — governance decision arriving before institutional readiness — is precisely the condition the Chokepoint Doctrine's Risk One framework was built to describe. The fault line moves faster than the migration plan. It moves faster still when the organisation standing on it has not yet drawn the migration plan.

What Coinbase Actually Did, and Why It Is the Most Important Case Study Available

If European financial institutions are looking for a live, fully documented example of what "adopting Chinese open-weight models" looks like in practice — not the abstraction, but the operational reality, costs, and risks — Coinbase has already run the experiment in public, and the results deserve to be read in granular detail before any organisation follows.

Coinbase, a publicly traded American cryptocurrency exchange operating under financial services regulation, now runs approximately 1,200 AI agents on Chinese open-weight models — specifically GLM 5.2 from Zhipu AI and Kimi 2.7 Code from Moonshot AI — cutting its AI spending nearly in half even as total token consumption increased. The mechanism was not a wholesale replacement of American models. It was a routing architecture: an automated system that selects the appropriate model for each specific request based on task complexity, price, and caching potential, with better caching alone pushing the system's cache hit rate from 5 to 60 percent.

This is the precise pattern the observation about Coinbase describes — everyday tasks routed to the cheaper Chinese model, complex tasks retained on Claude — and it is now a documented, named enterprise architecture pattern with a term attached to it: context engineering, alongside model routing. It is not a fringe experiment. Lindy, a San Francisco AI startup, moved 100% of its traffic from Claude to DeepSeek after its CEO stated publicly that AI costs had exceeded total company payroll before the switch, saving millions of dollars. Snowflake's own CEO ran a controlled comparison across 103 coding tasks and found GLM 5.2 solved 66% successfully against Claude Opus 4.7's 67% — a one-point gap, at roughly one-fifth the cost. The US-China Economic and Security Review Commission estimated in March 2026 that approximately 80% of American AI startups are now using Chinese open-source models in some capacity.

The migration to Chinese open-weight models across the US stack: Coinbase, Airbnb, Cursor, Windsurf, Lindy, and the 80% figure.
The provenance question does not live only at the model you choose. It lives in the models your tools were built on.

The Pattern Is No Longer a Crypto Exchange's Idiosyncrasy

Coinbase is the most fully documented case, but it is no longer the most revealing one. In the months since, the same migration has surfaced at three layers of the market at once — and one of those examples is sitting inside the very tool many readers used to write the code they shipped last quarter.

Start with the consumer layer. Airbnb CEO Brian Chesky told Bloomberg the company is "relying a lot" on Alibaba's Qwen model for its AI customer-service agent, calling it "very good," and, tellingly, "fast and cheap." Airbnb's agent runs on thirteen different models; Chesky noted the company uses OpenAI's latest releases "but we typically don't use them that much in production, because there are faster and cheaper models." The disclosure drew a US House probe within weeks. Chesky's defence is the one that matters for this analysis: "We are not providing data to any Chinese companies," and lawmakers worried about data access are "misunderstanding" the technology.

He is half right, and the half he is missing is the whole point of this piece. Not sending data to a Chinese endpoint is the correct answer to the data-flow risk — the same move Coinbase made by self-hosting. It is not an answer to the model-behaviour risk isolated later in this article, which travels inside the weights regardless of where the data goes. Airbnb checked the sovereignty box that can be checked and still drew a congressional investigation. For a European institution, that sequence — do the defensible thing, get scrutinised anyway — is the leading indicator. If US firms with deeper compliance budgets are being hauled in over this, a DORA third-party-ICT or AI-Act supervisory response in the EU is a question of when, not whether.

DSI Advisory

This analysis is published. Your decision isn't.

We run the same cross-domain, scenario-based foresight on the decision in front of you — a deal, a market entry, a supplier dependency. Board-ready in five days, with a foresight indicator watchlist.

Commission a Predictive BriefBook a 30-min strategic call