Recently, a Chinese artificial intelligence model called Kimi K3 sent shockwaves through global markets. Nvidia’s stock fell. Taiwan’s markets dropped more than 6% in a single day.
What rattled investors wasn’t simply that China released another AI model. It was growing evidence that Chinese companies may be narrowing the capability gap while dramatically lowering the cost of building and running frontier AI. That shift could reshape markets and potentially geopolitics.
I spent 25 years building software before serving as Indiana’s State Treasurer, and currently lead the State Financial Officers Foundation’s Digital Assets Task Force. So I usually can’t help reading the news like an engineer who codes.
A few years ago, Indiana became the first state in the nation to require our public pension system to divest from companies based in or controlled by Communist China. We completed that divestment four years ahead of schedule. We did not wait for Washington. We looked at the risk and acted.
Selling a Chinese stock out of a pension fund is simple. Finding foreign AI embedded inside the software your government depends on is a different problem.
America has spent decades learning that supply chains matter. Dependence on foreign steel, semiconductors, energy, and manufacturing capacity can become a strategic vulnerability. This new supply chain is different. It isn’t made of steel. It’s made of code.
Frontier models aren’t just answering questions anymore. They’re writing software, calling APIs (Application Programming Interface), analyzing data, and executing multi-step tasks with limited human direction. They’re becoming part of the software that manages financial systems, supports emergency communications, and touches nearly every piece of critical infrastructure.
Most people using those systems will never know which AI model is operating underneath. They won’t know who built it, where it came from, or what laws govern it. And that’s the problem.
I grew up in rural Indiana, where you learn to fix the fence before the cows get out. Cybersecurity and AI governance require the same mindset. You don’t wait for a failure to tell you where the gap was.
China’s National Intelligence Law requires organizations to “support, assist, and cooperate” with the country’s intelligence work. That means Chinese authorities can compel any company under their jurisdiction, including AI companies, to hand over data or assistance.
When another Chinese model, DeepSeek, drew global attention last year, researchers and governments raised privacy concerns about exposed data and security practices. The U.S. Navy outright restricted its use.
I’m not saying Kimi K3 contains a hidden backdoor. But I am saying the documented risks are serious enough that we need to ask questions before they become deeply embedded in our critical infrastructure.
Open weights can be a real strength. Open source can lower costs, give wider access and allow anyone to audit the code. But that same openness can hide a Chinese controlled model inside other software, masking who controls the code and its data. A government agency could buy from a U.S. vendor without ever knowing the model was built by a foreign adversary.
Training a frontier model still takes enormous compute. Inference, running it day to day, keeps getting cheaper. That’s exactly why foreign models can spread through AI supply chains faster than most policymakers realize.
Washington is still debating chatbots but the real issue is the AI supply chain.
Government shouldn't have to guess what AI is inside the software it buys. When agencies sign a contract, the vendor should have to say which frontier models power the product, where they were built, and whether data ever leaves the customer's environment, call it model provenance disclosure.
This isn’t about banning technology, picking winners and losers, or slowing AI development. It’s the same due diligence conservatives have expected for years when government spends taxpayer dollars.
America should lead the world in artificial intelligence. We should build the best models, attract the best talent, and out-innovate every competitor. But leadership means more than innovation. It means never handing control of those systems to a government that answers to Beijing.
We should not have to wait for another wake-up call before recognizing the risks in the software increasingly running our economy and our government.
America has always paid a price when we ignored strategic supply chains. We shouldn’t wait until a crisis reveals that we outsourced trust itself. Because the next supply chain isn’t made of steel. It’s made of code.