Operational notes Observatory

Google Sells AI to Alibaba, Baidu and Tencent Units: It's Legal, and That's the Problem

5 min read

A data centre corridor lined with rows of server racks
The line between “legal” and “under control” often runs through a corridor just like this one.

On 10 July 2026 the Financial Times revealed that Google and OpenAI supply advanced artificial intelligence services to the Singapore subsidiaries of three Chinese companies — Alibaba, Baidu and Tencent — whose parent companies appear on the Pentagon’s “1260H” list, reserved for firms deemed linked to the Chinese military apparatus. Both companies confirmed this directly to the newspaper. The transaction is perfectly legal. And that is precisely the point that should give pause to anyone in Europe buying AI services from a global supplier.

The facts, in order

  • 10 July 2026 — The Financial Times reveals that Google and OpenAI sell AI models and services to the Singapore subsidiaries of Alibaba, Baidu and Tencent, all parent companies included on the Pentagon’s 1260H list.
  • The mechanism is geographic, not corporate. US export controls restrict access from mainland China; they do not restrict access by a subsidiary registered elsewhere. A Singapore subsidiary of a blacklisted company is, on paper, a Singaporean company, and can sign contracts its parent company could not.
  • Google’s position. The company told the Financial Times that its services in Singapore and Hong Kong are governed by policies that prohibit distillation and misuse. It admitted, however, that “geographic boundaries do little to stop a sophisticated actor determined to circumvent them.”
  • OpenAI’s position. It blocks direct access from mainland China but allows some Chinese-controlled companies to operate from jurisdictions “where it believes it can enforce safeguards and monitor abuse.” In June it suspended API access for accounts linked to Alibaba after detecting a suspected distillation attempt, reporting it to US authorities.
  • The precedent that lit the fuse. On 10 June 2026 Anthropic wrote to the US Senate Banking Committee (chaired by Tim Scott, with Elizabeth Warren as ranking minority member) accusing operators linked to Alibaba and its Qwen lab of conducting 28.8 million interactions with Claude through roughly 25,000 fraudulent accounts between 22 April and 5 June: the largest illicit capability-extraction campaign the company has ever documented, according to Reuters and CNBC.
  • The most restrictive stance. Anthropic does not allow any Chinese company, nor its subsidiaries wherever incorporated, to access its flagship models — regardless of formal jurisdiction.
  • Alibaba’s response. The company rejects the accusations, stating that it does not use other providers’ model outputs to train its own systems and that it complies with intellectual property rules. Since 10 July it has banned its employees from using Anthropic tools, citing alleged security risks; commentators close to Beijing have dismissed Anthropic’s accusations as baseless.
  • The side effect. The revelation has reignited debate in Washington over whether AI export controls should follow corporate ownership rather than geography alone — following the model already used for semiconductors.

Google and OpenAI have broken no rules. That is exactly what makes the case instructive. A supplier can comply to the letter with every sanctions list and every geographic restriction, and still not know — or not be able to guarantee — who, in practice, accesses the shared infrastructure behind its API. For anyone buying AI technology, the question “does my supplier comply with sanctions?” is no longer enough. The useful question is a different one: who else, today, uses the same model my processes are built on, and under what real constraints? It is a matter of compliance that begins long before the contract is signed.

Lesson 2 — Clauses are only as good as their enforcement

Google has admitted, in black and white, that its own anti-abuse policies “do little” against a determined actor. This is the same crack we already saw in the tug-of-war between the Pentagon and its AI supplier: a usage clause without a technical verification mechanism is a statement of intent, not a control. Any company adopting AI should ask whether its own contractual clauses — on data use, re-export, and sharing with third parties — are monitored with concrete tools, or merely written into a document nobody ever checks.

Lesson 3 — Where a model comes from matters as much as where it goes

This saga involves American models sold to Asian subsidiaries of Chinese companies. But the same logic applies in reverse, for every European company now evaluating AI models of foreign origin, including Chinese open-source ones: knowing where data flows and who else shares the infrastructure is not a technical detail. It is the foundation of any digital sovereignty decision, every bit as much as knowing where your own data is processed.

What to do

  • Ask your AI supplier for the list of jurisdictions in which it delivers the service, and who else accesses it through the same shared infrastructure.
  • Check whether anti-abuse clauses (distillation, misuse, re-export) are monitored with technical tools, or merely declared.
  • Map the corporate control chain of suppliers and subcontractors; do not stop at the registered office named in the contract.
  • Include in the specification a clause requiring periodic verification and mandatory notification in the event of violations detected by the supplier itself.
  • For your most sensitive data, favour architectures in which access control is verifiable by you, not merely promised by whoever sells you the service.

Do you really know who else, in practice, accesses your AI supplier’s infrastructure? It is a question worth asking before you sign, not after the next journalistic investigation. Let’s talk about it in a thirty-minute session.

Sources