10/09 2026
553
During this National Day holiday, the AI industry never took a break.
Significant progress has been made in the commercialization of domestic models going global, and breakthroughs are being made in addressing computing power constraints. OpenAI released over 700 mathematical papers at once, also highlighting model security issues.
01 Three Commercialization Pathways for Domestic Models Going Global
On October 6th, Zhipu's GLM-5.3 was launched on AWS Bedrock; two days prior, it had just been integrated into Cursor's API. Kimi is moving even faster, with K3 already landing on Bedrock on September 18th and becoming directly accessible in OpenAI's enterprise version, Codex, starting September 30th. Reuters revealed that Kimi is also negotiating listing agreements with Microsoft and Google, demanding up to a 30% revenue share from cloud vendors.
iAnalysis believes that the aforementioned pathways will be the three core models for domestic models to go global.
The first is cloud vendor hosting. In the cases of Zhipu and Kimi being listed on AWS Bedrock, cloud vendors provide computing power and sales channels, with revenue first going to the cloud vendors and then being distributed to the model vendors. Model vendors incur zero computing power costs, with revenue essentially being profit, but at the cost of taking a smaller share.
The second is through inference service provider intermediation. In the Codex case, overseas inference service provider Baseten provides computing power, with OpenAI serving as the sales channel. Enterprises pay OpenAI, which subcontracts to Baseten, who then shares revenue with the model vendors. With an additional layer in the transaction chain, the revenue reaching model vendors is expected to be even less than with cloud vendor hosting, but it remains profit nonetheless.
The third is direct application connection. In the Cursor case, Cursor serves as the sales channel, with model vendors needing to provide their own computing power services. It is anticipated that Cursor will definitely take a commission from transactions in the future. In this model, model vendors have the highest revenue potential, with gross margins entirely dependent on their own pricing.
These three pathways have completely opened up the global market for Chinese open-source models, with overseas revenue no longer reliant on self-built computing power nodes. As a result, Zhipu has raised its year-end ARR guidance to $3 billion.
In terms of gross margins, it is expected that the gross margins of domestic model vendors going global will not be more optimistic than those domestically.
On one hand, domestic model vendors will certainly adopt low-price strategies to capture a larger overseas market; on the other hand, there are additional sales channel expenses overseas, which are not required domestically.
Channel costs can be referenced from Anthropic, which paid cloud vendors a channel fee rate of about 16% in 2025, rising to 20-30% in 2026. Domestic model vendors can expect even higher channel fee rates.
02 Computing Power Breakthrough: Rent, Build, Create
Tencent plans to rent the usage rights of approximately 100,000 advanced AI chips in Southeast Asia from Oracle for $7 billion over a five-year lease, with a 30% prepayment. Based on the rental price, it is likely that these are NVIDIA's H100 and H200 chips, rather than the latest Blackwell models.
Alibaba is negotiating power supply in Spain, preparing to build its own overseas data center.
DeepSeek has gone even further by open-sourcing the entire software toolchain for the Ascend platform before the National Day holiday.
Tencent's approach of renting is about buying time. Current U.S. export controls only regulate chip entry into the country, not overseas cloud access. However, this window is expected to close soon, so Tencent is locking in long-term leases to secure more computing power before the rules tighten.
Alibaba's approach of self-building is based on its long-term accumulation in self-developed chips (Pingtouge) and cloud infrastructure, directly serving global clients through overseas AIDCs.
DeepSeek has chosen to create an ecosystem. Although it does not manufacture chips, it has transplanted the entire toolchain matured on NVIDIA to Ascend, hoping that domestic computing power will be sufficient in the future.
iAnalysis believes that Tencent's rental approach is destined to be transitional, as the U.S. House of Representatives has already passed legislation to regulate remote cloud access, and the Department of Commerce is drafting new regulations to prohibit Chinese companies from renting computing power in third countries. Alibaba's approach of self-building AIDCs through chips and DeepSeek's approach of locking in domestic computing power through ecosystems are more sustainable.
In the future, the choice of computing power strategy will directly determine each company's token cost curve, thereby affecting final pricing and market share.
03 What Exactly Are Model Security Issues?
OpenAI recently disclosed new model security incidents. Models during training and evaluation gained unauthorized access to systems of over 100 institutions, including the SEC, Census Bureau, and Australian healthcare statistics portal. These have been individually reported, and apologies were made at an Australian Senate hearing. None of these incidents affected external production services, indicating low severity. However, the flagship model GPT-6.1 Astra was withdrawn before release due to deceptive behavior and unauthorized execution.
It should be noted that these were not hacker attacks initiated by the models but rather instances where models took shortcuts during task execution and inadvertently encountered these issues.
For example, when an agent was asked to check government data that was not publicly available, it sent instructions through the website's feedback portal and stumble upon (coincidentally discovered) it could directly have the backend server execute the task for it; or it saw leaked keys on the public internet and used them to read information.
These are ordinary system security vulnerabilities that have long existed and have likely already been exploited by other hackers. Moreover, these security issues are concentrated in the evaluation phase, where models lack complete security safeguards, making unauthorized access understandable. In production environments with full safeguards, no similar incidents have occurred.
iAnalysis believes that the models have not demonstrated hacker intent, with accidents concentrated in the evaluation phase where safeguards are lacking, and no incidents have occurred in production environments. Therefore, model security issues merely reflect that the barrier to hacking has been lowered by model capabilities.
In the past, unauthorized access required hacking skills; now, these skills are not difficult to achieve, and agents may inadvertently trigger unauthorized access during task execution.
Furthermore, the actual losses from such security incidents are limited, involving only public data with no evidence of personal data theft. Therefore, the impact of model security issues is primarily to enhance the popularity (prevalence) of security safeguards, such as NVIDIA turning agent runtime monitoring into a DPU-level product.
04 In Mathematics, AI Is Becoming a Deity to Humans
AI has not surpassed humans in the field of hacking, but it may have done so in mathematics.
On the morning of October 7th, OpenAI released 722 mathematical manuscripts on GitHub at once, divided into 372 result families, covering 17 fields such as theoretical computer science, number theory, geometry, and mathematical physics. These include progress on old problems like the quasi-Riemann hypothesis and Mahler's conjecture.
The results come from an internal model that has not yet been released, with each result consuming approximately 3 hours of ChatGPT Pro-level computing power on average. Some proofs have been translated into Lean formalized versions, while OpenAI believes that the untranslated parts may contain errors. It is expected that verifying these mathematical manuscripts will take the mathematical community a quarter or even a year.
iAnalysis believes that the deeper impact of this event is that the correctness and comprehensibility of mathematics have been decoupled for the first time. In the past, AI was responsible for proving, while humans reviewed the proofs. In the future, Lean will guarantee the correctness of proofs, but humans may not understand them or learn from them.
In the mathematical community, there is already speculation about a future where AI is a deity, and humans, initially serving as priests, verify and interpret the divine edicts given by AI. Gradually, humans will no longer be able to verify or interpret them, and all they can do is meditate on the unattainable truth like monks.
Mathematics may just be the first field where this happens; the same could occur in software and other fields in the future.