Western coverage of Chinese artificial intelligence still tends to treat the competition as a model contest: can a Chinese company match the best American system? China is certainly in that race.

But it is also pursuing a quieter route. Chinese companies are putting AI into cars, robots, cameras, smartphones, appliances, and industrial equipment already manufactured at an enormous scale.

“Made in China” once meant where the hardware was assembled. Increasingly, origin also involves who wrote the software, where the data travels, and who can update the product after it has been sold. The product’s identity is no longer settled when it leaves the factory. Software provenance is becoming a second country of origin.

The border has moved inside the machine.

From model to machine

Before examining China’s strategy, it helps to make a brief distinction. Most people encounter AI through a website or an app. They type a question into a chatbot, which sends their query to a distant data center, where a large model processes it and returns an answer. This is cloud-based AI: the intelligence lives elsewhere, and the device is only a window.

Embedded AI is different. Here, the intelligence travels inside the product itself. A car’s voice assistant, a factory robot’s vision system or a smartphone’s camera software all process data locally, on the device. Embedded AI can still connect to the cloud for updates or complex tasks, but its core functions run onboard.

Embedded AI will increasingly control and regulate the physical world.

Why does this distinction matter? Because embedded AI turns software into a physical presence.

A chatbot can be replaced by switching apps. A car’s AI layer, once integrated into the vehicle’s sensors, diagnostics and update systems, is much harder to change. The software becomes part of the machine — and whoever controls that software gains a degree of control over the machine itself.

Since DeepSeek released R1 in early 2025, Chinese developers have competed on price, efficiency, availability, and performance. DeepSeek and Alibaba have released open-weight models that firms can download and adapt without depending entirely on a proprietary cloud service.

Open-weight does not necessarily mean open-source. Training data, code, and development methods may remain undisclosed. But downloadable models are easier for manufacturers to adapt to specific products.

Large models do not enter cars or robots unchanged. Manufacturers compress them to run on smaller onboard processors, sometimes combining local operation with cloud services. This reduces delay, keeps a machine functioning when its network connection fails and may allow sensitive information to remain on the device.

There are important limits. Embedded AI still depends on processors, operating systems, development tools and safety certification. Despite years of investment in domestic alternatives, much Chinese equipment still incorporates foreign technology. A compressed model inside a vehicle is not equivalent to a frontier model running in a data center.

Nor should a language model control every function. AI may interpret a spoken command or help a robot plan a task. Brakes and emergency stops require predictable, independently tested controls. DeepSeek will not drive the car. But model families such as DeepSeek and Alibaba’s Qwen can become one layer in a larger industrial architecture.

That architecture is China’s distinctive advantage. It includes sensors, cameras, communications equipment, data centers, power systems and the technicians who bind software to metal.

The International Federation of Robotics recorded 295,000 industrial-robot installations in China in 2024, representing 54% of the world total. These figures measure manufacturing depth, not the international spread of Chinese foundation models. Most of the machines are robotic arms, mobile platforms, vision systems, and inspection equipment, not humanoids.

Manufacturing scale can reduce component costs. It does not by itself solve the hardest problems in robotics, including dexterous movement, safe operation around people, and reliability over thousands of hours. China’s earlier advantage is therefore more likely to emerge in specialized factory and warehouse systems than in general-purpose humanoids.

The border moves inside

The first clear examples are appearing in vehicle cabins. In 2025, Geely’s Zeekr and Dongfeng’s Voyah announced DeepSeek integrations. Xiaomi developed vehicle voice services using Chinese model technology. Tesla has used DeepSeek and ByteDance’s Doubao for voice and command functions in vehicles sold in China.

These systems do not control the brakes. Their significance is more immediate: they show how an AI layer can enter a product through a supplier, a regional adaptation, or an over-the-air update without changing the badge on the hood. An American-branded car sold in China can carry Chinese intelligence in its cabin.

The same layering is appearing in drones, camera networks, smartphones, appliances and warehouse equipment. Huawei’s HarmonyOS is intended to connect multiple devices within a shared environment, although its overseas reach remains uneven and concentrated in Huawei’s ecosystem. Port and factory packages increasingly combine machinery, cameras, communications networks, and management software.

Public data do not reveal how many exported Chinese vehicles or machines use Chinese foundation models rather than foreign, local or mixed systems. What can be seen is the insertion path, though not yet its global share.

There is also no single “Chinese stack.” Private companies, state enterprises and local governments pursue different goals. Exporters often care more about price, reliability and the buyer’s requirements than about implementing a unified national strategy.

Importers retain considerable leverage. Governments, fleet operators, and insurers can demand local data storage, offline operation, independent security testing and the right to disable telemetry. Some may buy Chinese hardware but require local software. Others may accept Chinese software if its data and update servers remain inside the importing country.

The likely outcome is not one global platform but a landscape of regional and dual architectures.

Software, however, is not always easy to replace. Once it becomes coupled to proprietary sensors, diagnostic tools, accumulated data, cloud services, update servers, and safety certification, substitution becomes expensive. Technicians learn one system, developers build around it, and customers accumulate compatible equipment. Lock-in lives in the surrounding architecture, not in a single file.

US regulators have begun treating that architecture as a question of origin. The Bureau of Industry and Security finalized restrictions on specified connected-vehicle software and hardware with a Chinese or Russian nexus. Software prohibitions begin with model year 2027, followed by hardware restrictions.

The rules can apply to an American-branded vehicle assembled in North America if covered technology comes from a supplier with a sufficient Chinese or Russian nexus. The badge and assembly plant no longer determine the product’s identity. Regulators also want to know who wrote the software and who can access the vehicle after its sale.

European cybersecurity, data, and product-liability rules are pushing manufacturers in a similar direction. Other importing countries can require auditable firmware, local update servers, replaceable components, and essential functions that continue working offline.

Such safeguards reduce dependence, but they also increase costs and fragment global platforms.

Stack contest

The security debate is sometimes reduced to the cinematic image of a hidden kill switch. The routine risks are less dramatic and often more important.

Connected products collect location, imagery, voice and operating data. Update channels can become entry channels. A factory or vehicle may depend on proprietary services its owner cannot inspect or replace. If thousands of machines share one software stack, a single vulnerability can spread through an entire fleet.

None of these risks is uniquely Chinese. Western products also collect data, create dependencies and contain vulnerabilities. China matters because it can put software into metal at a volume few other countries can match, and because that scale now attracts geopolitical scrutiny.

The sensible test is therefore architectural rather than simply national. Where are the data stored? Who signs and issues updates? Can the software be audited? Which functions continue working offline? Can a critical component be replaced without rebuilding the machine?

Standards will help determine the answers. China is developing standards for humanoid robots, while an ISO robotics working group is examining humanoid-robot datasets. That demonstrates ambition, not dominance.

China cannot dictate ISO decisions, and participation in a working group does not create a global installed base. But it does signal intent to shape the rules.

De facto standards emerge when enough products use the same interfaces, formats, and maintenance practices that switching becomes expensive. Chinese cameras, drones, and electric vehicles already have substantial foreign markets. If Chinese vehicles and machinery continue to spread, however, their interfaces and service systems may travel with them.

Buyers can still insist on open interfaces and replaceable software. If they do not, the company supplying the machine may also control much of the intelligence inside it.

The consequences could be greatest in emerging markets. Affordable Chinese systems may accelerate the modernization of transport, agriculture, and manufacturing. But importers will have to decide what forms of dependence they are willing to accept and what auditing, access and localization requirements they can demand in return.

The decisive AI contest is therefore not merely about a chatbot’s nationality. It concerns control of the chips, models, interfaces, and update rights inside the world’s machines.

China enters that contest with manufacturing scale, dense supply chains, and increasingly capable model developers. It remains constrained by advanced silicon, certification requirements, and overseas trust. Whether Chinese software becomes a default layer of the physical economy will likely vary by product and market.

Customs forms may continue to describe the shipments as hardware. The more important question is who controls the intelligence once it arrives.