On 7 July, CNBC published figures showing that Chinese-origin AI models have accounted for at least 30% of weekly enterprise token volume on OpenRouter, the largest neutral model router, every week since 8 February, peaking at 46% by early July. CNBC's reporting puts DeepSeek alone at 17.6% of routed tokens, ahead of every US lab including Anthropic, which holds 14.8%. A day later, CNBC reported that two House committees have opened a joint investigation into exactly this shift, sending letters to Airbnb and to Anysphere, the company behind the Cursor coding assistant. This is no longer a developer-forum curiosity. It's a live governance question that most enterprise AI policies were not written to answer.
The numbers behind the shift
The move is almost entirely a cost story. As of June 2026, DeepSeek V4 Flash was priced at $0.14 per million input tokens against $5.00 for OpenAI's GPT-5.5, a gap of roughly 97%. Across the leading Chinese open-weight models generally, CNBC found pricing runs 60% to 90% below comparable US frontier offerings. Twelve months earlier, Chinese models averaged 11% of OpenRouter's enterprise token volume; in the first half of 2025 it was just 4.5%. Coinbase's Brian Armstrong and Lindy founder Flo Crivello have both spoken publicly about switching workloads to Chinese models specifically to cut inference spend. At that price differential, a finance team asking why the AI line item is what it is will keep landing on the same answer, and engineering teams will keep finding it before procurement does.
What Congress is actually investigating
On 29 April, House Homeland Security Chairman Andrew Garbarino and House Select Committee on China Chairman John Moolenaar announced a joint investigation into national security risks posed by PRC-origin AI models from DeepSeek, Alibaba, Moonshot AI and MiniMax. The committees' stated concern is narrower than "Chinese AI is risky" - it centres on model distillation, where the outputs of a stronger model are used to train a weaker one, allegedly carried out through fraudulent accounts and proxy networks that evade access restrictions on US systems. Their letters, sent to Anysphere over its use of Moonshot AI's open-weight model inside Cursor's Composer 2, and to Airbnb over its use of Alibaba's Qwen for customer service, ask each company to explain how it evaluated the models before deployment. CNBC's follow-up coverage notes the committees also flagged that some of these models exhibit output patterns aligned with Chinese Communist Party positions on sensitive topics, a separate concern from the distillation question but one that lands in the same letters.
Why this matters even if nobody on your team has heard of OpenRouter
Most enterprises don't route traffic through OpenRouter directly, but the underlying dynamic isn't platform-specific. Individual engineering teams, SaaS vendors embedded in your stack, and contractors all make model choices at the API level, often below the threshold that triggers a procurement or security review. This is shadow SaaS with an AI-shaped update: the version of the risk your organisation is used to managing is "an employee signed up for a tool with a company card," and the new version is "an employee, or a vendor you already pay, switched the model behind a feature you already approved, and nobody updated the record." If your AI vendor register was last reviewed when you signed the original contract, it is very likely already out of date.
The cost math is real, and so is the risk calculus
None of this is an argument that using a Chinese open-weight model is automatically reckless, and it would be a mistake to read it that way. A 60% to 90% price gap on inference is a genuine, material number for any organisation running AI at volume, and plenty of workloads, particularly internal, non-sensitive, high-throughput tasks, may tolerate the trade-off comfortably. The point is that the trade-off needs to be made deliberately, by someone accountable for it, against a specific set of questions: where is the model hosted and what jurisdiction governs the data that passes through it, what does the model's output behaviour look like on topics where alignment might diverge from your organisation's expectations, and what happens to your exposure if a customer, auditor or regulator asks which models touch their data and your honest answer is "we're not entirely sure."
What to actually do about it
The practical response looks a lot like the shadow IT playbook enterprises already know, applied to a new layer of the stack. Maintain an actual AI model register, not just an AI tool register, that names the specific model behind every AI-enabled feature you use, including ones embedded inside vendor products. Extend vendor due diligence to ask explicitly which models a SaaS provider uses today and what happens if they switch, since a vendor optimising its own margins has every incentive to swap silently. And treat model provenance as a standing agenda item for whoever owns AI governance internally, not a one-off question asked at initial vendor selection and then filed away.
- Build or update an AI model register that names the specific model behind every AI feature in use, including those embedded in third-party SaaS products.
- Add a standing question to vendor due diligence: which model powers this feature today, and will we be notified if it changes.
- Classify workloads by data sensitivity and set explicit rules for which classes may run on non-transparent or foreign-hosted models.
- Review output behaviour on any model handling customer-facing or judgement-sensitive content, not just its benchmark scores.
- Assign clear ownership for AI vendor and model governance, with a recurring review cadence rather than a one-time sign-off.
The committees investigating Airbnb and Anysphere are asking a question every enterprise using AI at scale should already be able to answer about itself. If your organisation can't currently say, with confidence, which models sit behind your AI-enabled workflows and vendor products, that gap is worth closing before someone outside the organisation asks first. Want help building an AI model register or vendor governance framework that actually holds up under scrutiny? Email sales@halfteck.com.