Layer3Labs warns Chinese AI models now handle much of U.S. traffic
Layer3Labs says Chinese-developed AI models are now processing as much as 46% of token traffic on a major U.S. model router, up from about 30% a year ago. The Miami firm says the shift is often hidden inside vendor products and shadow AI, creating data-sovereignty and compliance risks for businesses.
Why it matters: - Layer3Labs says a growing share of U.S. business AI traffic is being processed by Chinese-developed models, often without the customer’s knowledge. - The firm says that creates exposure for sensitive data, especially in healthcare, legal and finance. - Layer3Labs says firms with high shadow AI exposure face an estimated $670,000 breach premium per incident.
What happened: - Layer3Labs said as much as 46% of token traffic on the largest U.S.-based AI model router is now routed to Chinese models. - The company said U.S. models handled roughly 70% of that traffic a year ago and now handle closer to 30%. - The Miami-based AI implementation firm released the warning on July 22, 2026.
The details: - Layer3Labs said business owners often buy an AI feature without knowing which model processes the data underneath. - Cost-optimizing routers can send prompts to the cheapest available provider, which Layer3Labs said is increasingly a Chinese endpoint because inference can run 60% to 90% cheaper. - Andreessen Horowitz has estimated that 80% of U.S. startups build on Chinese base models, with Airbnb, Uber and Cursor named as adopters. - Research cited by Layer3Labs says 70% of enterprise AI activity sits outside IT oversight, including models small enough to run on a laptop. - Layer3Labs said any prompt processed by a Chinese-provider endpoint can fall under China’s National Intelligence Law, which can compel data disclosure to the state. - In July 2026, the House Select Committee on the CCP opened a probe into U.S. firms’ use of these models. - The NDAA already bars DeepSeek from Defense Department systems. - Layer3Labs said its review of dozens of small- and mid-sized business AI stacks found 70% contained at least one Chinese model the company had not knowingly approved.
Between the lines: - The issue is not just model choice. It is also routing, resale and white-labeling, which can hide the model behind a business-facing product. - That makes AI governance harder because companies may not know where customer data is actually processed or which jurisdiction applies. - The warning also suggests a widening gap between what businesses think they bought and what their vendors are actually using.
What's next: - Layer3Labs is urging businesses to run a provenance check on every AI tool that touches customer data. - The firm says regulated businesses should treat model visibility as a compliance step, not just an IT task. - Layer3Labs is offering a free AI Stack Sovereignty Check to identify which models are processing company data and to flag data-sovereignty and compliance risk. - Jonathan Teplitsky said business owners should ask whose jurisdiction their customer data lives under. - Mark Boyhous said companies cannot govern what they cannot see and should first find out what is in the stack.
The bottom line: - Layer3Labs says U.S. businesses may be relying on Chinese AI models far more than they realize, and the biggest risk is hidden exposure.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
Asia Healthcare Industry Digest
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.