The US Held Off Blacklisting DeepSeek: 100+ Firms Approved but Unpublished, a Deferral and Not a Reprieve
A Reuters exclusive: DeepSeek, memory chipmaker CXMT and more than 100 other firms deemed national-security risks were approved last year by an interagency committee for the Commerce Department's Entity List, and never published. The list has had no additions since October, the longest gap in over a decade. The reason is not that these firms passed muster. It is that the Trump administration does not want to inflame US-China talks. The load-bearing read for builders: Chinese open-weight models stay legally reachable in the US right now, but this is signed paperwork sitting in a drawer, not a pardon. Don't architect a hard dependency on DeepSeek assuming the legal status is permanent.
Summary
A Reuters exclusive on June 17 surfaced something that had not been public: DeepSeek, China’s top memory chipmaker CXMT (ChangXin Memory Technologies), and more than 100 other firms deemed national-security risks were approved last year by an interagency committee for the Commerce Department’s Entity List, and that batch was never published. Over the same window the list has had no additions since October, which CSIS supply-chain researcher Philip Luck calls the longest gap between postings in over a decade.
Put the two facts together and the conclusion is direct. The review is finished and the paperwork is signed; the only step missing is publication, and that step has been held down by hand. The reason is not that the risk evaporated. It is that the Trump administration does not want to inflame the talks with Beijing. For any builder putting Chinese open-weight models into a stack, the real meaning is not that DeepSeek is now safe. It is that DeepSeek’s legal status currently hangs on a single thread of policy.
What happened
According to two people familiar with the matter, DeepSeek, CXMT and the rest were approved for the Entity List last year by an interagency committee. Approved-for-listing and listed are two states. The first means the government internally found the risk and ran the process; only the second triggers actual restrictions. This approved batch is stuck at the publication step.
The holdup has a name. Per the first source and others, Jeffrey Kessler, under secretary of commerce for industry and security, has since late 2025 sought to avoid listing Chinese parties for fear of escalating US-China tensions. The Bureau of Industry and Security, which runs the list, did not directly explain why updates have gone unpublished since last year. It offered a boilerplate line that it uses many tools, the Entity List among them, daily to combat bad actors. China’s foreign ministry spokesperson Lin Jian gave the usual response, that the US should stop “politicizing, instrumentalizing, and weaponizing” trade and technology issues.
The freeze is bigger than DeepSeek and CXMT. Reuters reports that multiple Chinese firms were slated for the list for supplying Russian drones recovered in Poland last September, that dozens more were flagged for selling restricted Nvidia chips to Chinese universities, and that companies making drones and robot dogs for China’s military were also targeted. This is a list already vetted, more than 100 names deep, that has not landed.
Why it matters
The weight of the Entity List is worth stating plainly. Once a firm is on it, US companies cannot ship goods, software and technology to it without a license, and that license is likely to be denied. It is one of the core enforcement tools the US uses to keep its own technology out of adversaries’ hands. It is not symbolic.
So ten months with no additions is itself a signal. Former Commerce official Kevin Kurland said it directly: the absence of any listings since October shows trade policy is overshadowing a critical national-security tool. Luck described the work as whack-a-mole, where the moles keep popping up and you have to keep whacking them, and stopping does not make them disappear. The cost of the freeze, in his read, is that US technology keeps flowing to adversaries who could turn it against the US.
The structural point is that export control, which is supposed to track risk assessments, has been re-pegged to the diplomatic mood. Approved but unpublished means a batch of already-valid risk findings has been put in a drawer, with the key held by the state of the talks. If talks go well the drawer stays shut. If they sour it can be pulled open at any time. For markets and for builders, that makes the legal standing of firms like DeepSeek a variable, not a constant.
Builder impact
Get the present fact straight first, to avoid erring in either direction. DeepSeek is not on the Entity List right now. It is not “banned,” and building on its open weights inside the US is currently legal. Calling it sanctioned is wrong and will push you into overly defensive choices.
Treating that as a long-term guarantee is the more dangerous error. This is signed paperwork sitting in a drawer, a deferral and not a pardon. The committee’s risk finding was not overturned; publication was deferred on diplomatic grounds. The distance from “legally usable” to “needs a license that is likely to be denied” may be only one bad day in the US-China talks. The moment DeepSeek is actually listed, exporting controlled technology toward it, or building a commercial dependency on it, moves straight into legal-risk territory.
In architecture terms this reduces to one rule. Do not build a hard dependency on the assumption that DeepSeek stays legal. If you use its weights or API in a product, manage its legal status as a policy-contingent variable rather than a settled fact. Concretely, keep a swap path so the same requirement can move to another open-weight or in-house model on short notice, and pre-assess your compliance exposure for any link that exports controlled technology toward DeepSeek in case it is listed. This is not a call to drop it today. It is a call not to bet on permanence where you have no fallback.
Research impact
For research work the durability of sourcing matters here. The allegations Reuters cites, the State Department’s claim that DeepSeek supported military and intelligence operations, Anthropic’s account of an attempt to extract capabilities from Claude, and OpenAI’s warning that it targeted their models, are the backdrop to this listing approval and do not vanish because the list is frozen. If your work argues for or against the provenance of some DeepSeek capability, these are public claims you cannot route around.
What to ignore
Do not get pulled along by headlines saying the US “banned” DeepSeek. As of this report it is not on the Entity List and no export controls have triggered, so calling it banned is a factual error. Likewise, do not read the non-listing as the US conceding that DeepSeek is fine. The freeze is about diplomatic timing, not a reversal of the risk finding, and the two cannot be conflated.
And do not sink into the grand narrative of whether this signals a broad US-China thaw and try to forecast from it. The fact on the table is that a tool has been held down by policy, with the key held by the talks, and nothing more. What is actually actionable for a builder is not guessing the next round of negotiations. It is designing a fallback so that whatever the outcome, DeepSeek’s legal status is treated as a variable that can move at any time. Guessing politics is a bet. Keeping a fallback is engineering.
FAQ
Can US companies and developers still legally use DeepSeek right now?
Yes. DeepSeek is not on the Commerce Department's Entity List. As of Reuters' June 17 report it sits in the state of approved-by-the-interagency-committee but not yet published. The list's restrictions bite on firms that are actually listed, so an unpublished approval has not triggered the license regime. The distinction that matters: approved-for-listing and listed are different states, and the first means the review is already done and the paperwork is signed, with only publication held back.
Why hasn't the Entity List been updated since October?
Per Reuters' sources, Jeffrey Kessler, under secretary of commerce for industry and security, has since late 2025 sought to avoid listing Chinese parties for fear of escalating US-China tensions. CSIS's Philip Luck notes this is the longest stretch between Entity List postings in over a decade. Former Commerce official Kevin Kurland put it bluntly: trade policy is overshadowing a critical national-security tool. The freeze reflects diplomatic calculation, not a finding that these firms are clean.
Does DeepSeek not being listed mean the security concerns were unfounded?
No. The allegations Reuters cites were not withdrawn. A State Department official said last year that DeepSeek supported China's military and intelligence operations and tried to use Southeast Asian shell companies to illegally access advanced US chips. Anthropic said this year it identified a campaign by DeepSeek and two other Chinese labs to illicitly extract capabilities from Claude, and OpenAI warned that DeepSeek targeted its models. The committee approved the listing on exactly these grounds. The reason for non-publication is diplomatic timing, not a reversal of the finding.
Which companies are in the 100+ approved but unpublished?
Reuters describes several groups. Some Chinese firms were slated for the list for supplying Russian drones recovered in Poland last September. Dozens were flagged as security risks for selling restricted Nvidia chips to Chinese universities. Others make and sell drones and robot dogs for China's military. A source noted that listing the lesser-known firms matters even more to US suppliers, who may not know the true nature of those firms' business.
Sources
- Exclusive: US holds off blacklisting China's DeepSeek, more than 100 firms deemed security risks (Reuters)
- US holds off blacklisting DeepSeek (Hacker News discussion)
No official primary source available; this analysis is based on reliable secondary reporting (named outlets, cross-confirmed).