It is not about issuing tokens or engaging in token speculation, but rather about transforming AI capabilities into measurable and billable global services.
When many people hear the word "Token," their immediate reaction is to think of Web3, token issuance, exchanges, and secondary markets. However, the international expansion of AI Tokens is not about these matters.
In Southeast Asia, a child hugs an AI-powered toy capable of conversation, asking it to tell stories, practice English, and answer countless questions. The toy appears to be merely a hardware terminal, but what is truly valuable is not the plastic casing, but the continuous model inference occurring behind the scenes: each activation, each follow-up question, and each segment of voice interaction consumes Tokens. These requests originate from overseas terminals, enter domestic computing power centers through pilot channels in Shantou for processing, and then return the results to overseas users. In other words, what is being sold is not a toy, but a set of AI capabilities billed per invocation and based on usage volume. What they are consuming is the new hard currency of the AI era—Tokens. One kilowatt-hour of electricity comes in at approximately RMB 0.5, is converted into Tokens, and is sold out at approximately RMB 11, representing a value increase of more than twentyfold.
The core discussion of this business has never been "how to sell a Token," but rather a positive endeavor: selling domestic AI capabilities to overseas clients through compliant Token-based metering methods.
Why is it worth doing now? The capabilities of domestic models are improving, API prices are declining, and overseas demand is genuine, with leading manufacturers already earning the majority of their revenue from overseas markets. However, regulatory oversight is also tightening: AI intermediary platforms are under criminal investigation, and data security risks are being repeatedly highlighted. In short—AI Tokens can go global, but they must not operate in a disorderly manner. If the direction is wrong, going global will become sinking; if the model is chosen incorrectly, the business will become a risk.
First, define the nature: AI Tokens are not Web3 Tokens
Before discussing the model, we must firmly establish the concepts. The difference between AI Tokens and Web3 Tokens lies not in their names, but in their functions.
Web3 Tokens are typically issued based on blockchain technology, allowing for on-chain transfers, entry into secondary markets, and market-driven price fluctuations, carrying attributes of payment, store of value, and even speculation. AI Tokens are entirely different: they have no underlying blockchain infrastructure, cannot be transferred between users, have no secondary market, and exhibit no price volatility. They are merely internal units used to measure consumption after users purchase AI services.
The most intuitive example is as follows: A user recharges USD 100 and receives a call quota of 1 million Tokens. This quota cannot be sold, transferred to others, or listed on exchanges; it can only be consumed within the platform to invoke models. This is the prerequisite for the compliant international expansion of AI Tokens.
The judgment is actually quite simple: if a Token can only be used for service consumption, it is a metering tool; once it becomes tradable, transferable, or subject to speculation, it may slide into the regulatory scope of virtual assets. Therefore, the first boundary for international expansion is—do not turn AI service quotas into financial products.
Why now: Three numbers
Looking at the timeline of the past one to two years, three numbers can explain why this business has suddenly heated up.
The first metric is usage volume. In the week surrounding this year’s Spring Festival, the top ten models by call volume on OpenRouter, the world’s largest model API aggregation platform, collectively consumed approximately 8.7 trillion tokens. Among these, Chinese-developed models accounted for approximately 5.3 trillion tokens, representing a 61% share. By the first week of April, six of the top ten models were Chinese-developed. During that week, Chinese models processed 12.96 trillion tokens, while U.S. models processed only 3.03 trillion tokens. Overseas developers are substantively engaging Chinese-developed models through paid API calls.

Figure: OpenRouter’s official Rankings page displays the actual usage rankings of models.
The second metric is pricing. The API pricing for Chinese-developed models is often only a fraction—ranging from one-tenth to one-hundredth—of that charged by leading U.S. models. The price differential for input tokens is approximately tenfold to twentyfold, with an even greater disparity for output tokens. Previously, when AI was primarily used for chat applications with low call volumes, this price difference was negligible. However, in the era of AI agents, where a single task can consume hundreds of thousands or even millions of tokens, the cost differential is significantly amplified, leading developers to vote with their feet.
The third metric is revenue. Taking MiniMax as an example, its overseas revenue accounted for 73% of its total in 2025, whereas this figure was only 19% in 2023. This indicates that Chinese AI companies are not merely “being called upon,” but are genuinely generating revenue in the global market.
Expansion, price reductions, and successful overseas expansion constitute the positive aspects; however, the latter half is equally critical—compliance is becoming a key variable determining how far an enterprise can go. The divergence in the following three paths lies precisely herein.
Model One: Official Direct Connection
The most orthodox, clear, and compliance-certain path is for model providers to expand overseas independently.
Under this approach, providers establish their own nodes overseas or leverage international cloud services such as AWS or Azure to offer official APIs. Cross-border data transfer, model licensing, and local operations are conducted in strict accordance with international cloud rules and the laws of the target markets. With a complete authorization chain, clearly defined service entities, and assumed liability, customers know exactly whose model they are calling. This eliminates issues such as unclear intermediate-layer sublicensing, unidentified interface sources, model substitution, and account-pool arbitrage.
DeepSeek, Zhipu AI, and Moonshot AI have all launched official APIs. Furthermore, companies such as Zhipu AI and MiniMax have deployed their models on overseas cloud platforms like AWS, where inference is performed on local physical servers, ensuring that data never leaves the respective region. This directly addresses the primary concern of overseas enterprises: whether their data will be transmitted back to China.
The logic of this path is: those who own the models expand overseas, and those who provide the services assume responsibility. It is suitable for leading providers with overseas entities and resources. Although the barriers to entry are high, it offers the greatest peace of mind once established. Conversely, if you are not a model provider, you should not position yourself as “official.”
Model Two: Compliant Aggregation / Tools
For small and medium-sized teams lacking the capacity to deploy global nodes independently, a more realistic approach is to provide aggregation and tooling services. This is currently the path with the highest number of participants.
The business model involves aggregating multiple licensed models to provide a unified gateway, a unified API, and a suite of developer tools, enabling overseas clients to access multiple models through a single interface. OpenRouter, mentioned earlier, is the global benchmark for this model—providing access to hundreds of models via one API. Revenue streams include the spread on token purchases and sales, gateway and technical service fees, tool subscriptions, and value-added services such as routing, monitoring, billing, and risk management.
This is a sector with more complex compliance requirements; it is not prohibited, but must be conducted under specific conditions. The two core issues are model provenance and data liability. Questions that must be answered include: Where do the aggregated models originate? Are there rights for resale? Does the upstream authorization cover overseas use? Are white-labeling and secondary packaging permitted? To whom is customer data ultimately routed? Will it be retained or used for training? If these questions cannot be clearly answered, so-called “compliant aggregation” will become “gray-market intermediation.”
Four types of closure must be maintained:
-
Closure of the authorization chain—from model vendors, cloud providers, and official distributors to the aggregation platform and finally to overseas clients, each layer must have written authorization; reliance on a mere verbal assurance from upstream parties that it is “permissible” is insufficient.
-
Closure of business scope—the authorization must cover actual activities, including API calls, model aggregation, external sales, white-label packaging, overseas regions, and customer types, all of which must be explicitly included in the authorization.
-
Closure of data liability—specify in the Data Processing Agreement (DPA), privacy policy, and list of sub-processors who receives customer data, whether it is retained, whether it is used for training, and whether it is transferred to third parties.
-
Closure of billing evidence—upstream procurement contracts, invoices, and payment vouchers must correspond one-to-one with downstream sales orders, usage reports, and receipt records, ensuring traceability.
Failure to achieve these four closures will cause so-called “compliant aggregation” to slide into “gray-market intermediation.” The core of aggregation is not merely “technical interoperability,” but rather “whether there is a right to sell.”
In practice, many teams believe they are engaged in aggregation but actually use personal API keys, shared accounts, educational discount quotas, account pools, reverse-engineered interfaces, or even pass off low-cost models as high-cost ones. These practices do not represent cost advantages; they are triggers for legal and operational risks.
Model Three: Special Zone Pilot Programs
Another path offering policy benefits exists, with the most closely watched current example located in Shantou.
In 2025, the national government approved the Shantou Overseas Chinese Economic and Cultural Cooperation Experimental Zone to conduct a pilot program for “incoming data processing”: overseas data may legally enter China, be processed within designated areas, and then be exported, operating under a unified policy framework without the need for case-by-case approval. This is supported by a “digital bonded zone” architecture—where the special zone is physically isolated from the domestic internet, overseas requests connect directly via international submarine cables, inference is completed within the zone, and results are returned along the same path, achieving latency to Singapore as low as approximately 32.7 milliseconds. China Mobile Guangdong established the Eastern Guangdong Data Center locally and independently operates the “Token Tongyi” platform, which centrally manages computing power scheduling, token metering, cross-border matching, and profit sharing, thereby completing the first nationwide end-to-end closed loop for token exports. A frequently cited local calculation illustrates that electricity costs approximately RMB 0.5 per kilowatt-hour upon entry, which, when converted into tokens, exits at approximately RMB 11, representing a value increase of more than twentyfold.

Figure: Nanfang Daily’s digital newspaper publishes a report titled “Shantou-Made” Tokens First Supplied to Overseas Markets
It addresses a critical issue: whether cross-border data can be imported into mainland China for processing. The regulatory mantra is: collect abroad, process domestically, and return abroad; if domestic personal information or important data are not commingled during the process, the three procedures of security assessment, standard contract filing, and protection certification may be exempted.
However, this pathway has clear boundaries. Several conditions must be met: the service targets overseas users, the data originates abroad, only technical processing is conducted within mainland China, the results are returned via the original route, no domestic data is commingled, physical or logical isolation is maintained between domestic and overseas operations, and operational maintenance logs are retained for auditability. If domestic and overseas operations share a single system, data pools are not isolated, or processed results flow back for use in domestic business, the exemption logic will fail.
More importantly, pilot programs do not constitute a nationwide universal exemption. They rely on specific regions, specific policies, and specific facilities, and cannot be simply replicated as “I can find any server room in mainland China to accept overseas data for processing.” Moreover, due to local regulatory constraints, such services are currently primarily oriented toward Southeast Asia; for Europe, the United States, and Japan, strict data localization and export control requirements often necessitate local deployment. It is more akin to a test field with real benefits but which cannot be blindly copied.
III. A Negative Example That Must Be Avoided: Tokens Entering the Domestic Market
Having outlined the three legitimate pathways, we must highlight a negative example often mistaken for a “fourth approach”: gray-market intermediation, namely, tokens entering the domestic market. This is the opposite of going global—whereas going global involves selling mainland China-based AI capabilities to overseas clients, entering the domestic market involves packaging overseas model services that have not completed domestic compliance and circumventing regulations to sell them to users within mainland China.
The typical modus operandi involves three steps: first, obtaining access to overseas model interfaces through bulk registration, shared accounts, or even reverse engineering and cracking; second, encapsulating such access via reverse proxies into Chinese-language webpages or API top-up platforms; and finally, selling access to the domestic public through communities, e-commerce platforms, and mini-programs on a membership or token basis.
The issue is not merely minor licensing defects, but that the entire chain is legally untenable: the source may lack authorization, the models have not completed domestic compliance, fees are charged to the domestic public, user data is transferred abroad, and the platform lacks required qualifications such as ICP/EDI licenses. If the interfaces are obtained through cracking and fraudulent use, criminal liability may arise. In short: tokens entering the domestic market are not a fourth mode of going global, but rather the prime negative example that overseas-bound businesses must avoid.

Figure: CCTV.com publishes the Ministry of State Security’s risk warning regarding “AI Intermediary Stations”
Conclusion: Compliance Is Meaningful Only When the Business Model Is Correct
The three pathways are not ranked by superiority, but by suitability. If you have your own models, computing power, brand, and overseas infrastructure, prioritize official direct connections. If you have technical integration capabilities and customer channels but lack self-developed large language models, the most realistic option is compliant aggregation or tooling. If you intend to leverage domestic computing power to process overseas data and can access policy-supported zones and isolation facilities, you may explore special zone pilots. However, packaging overseas interfaces and selling them to domestic users—whether called intermediation, mirroring, or gateways—is not going global; it is entering the domestic market.
Regardless of the chosen pathway, four lifelines cannot be bypassed: model sourcing, cross-border data transfer, target markets, and fund repatriation:
If the origin of the model is unclear, the token is not an asset but a liability; if the data flows are unclear, the platform is not a tool but a black box; if the target market is unclear, going global is not growth but an intrusion into another jurisdiction’s regulatory regime; if the fund flows are unclear, revenue is not profit but explanation costs that will sooner or later have to be repaid.
The AI token projects that succeed in going global do so not through low prices, packaging, or rhetoric, but through a business chain that can withstand scrutiny. A token is merely a unit of account; what is sold globally is always AI capability—where it comes from, who buys it, how data flows, how funds are repatriated, and who bears responsibility when issues arise. If these questions are answered clearly, the token serves as a tool for global expansion; if they are not, it becomes another gray entry point.
This article is an industry compliance observation, compiled based on public rules and practical experience, and does not constitute legal advice for any specific project.
Author
Shao Jiadian,Partner at Mankun Law Firm (Shenzhen). He graduated from the National University of Singapore and has served as a lawyer, head of compliance and risk control, and Vice President of Legal Affairs at institutions including a leading red-circle law firm, a cross-border investment platform of a central state-owned enterprise, and a mother fund with assets under management exceeding RMB 100 billion. He focuses on new economy sectors such as Web3 and excels at creatively providing clients with one-stop solutions for legal and compliance needs, including global structure setup for Web3 projects, license applications, project financing, real-world assets (RWA), and crypto fund establishment.
About Mankun
Mankun Law Firm was established in 2015. It is a boutique law firm dedicated to serving Web3.0 and the next-generation internet, with deep expertise in new economy sectors such as blockchain, artificial intelligence, and tech finance.
Headquartered in Shanghai, the firm has branches in Hong Kong, Shenzhen, Silicon Valley, and other locations. Its core members come from renowned law firms, judicial authorities, technology companies, and digital asset institutions. Leveraging unique multi-dimensional perspectives spanning law, industry, and regulation, the firm provides high-quality legal services that combine depth in China with global breadth.
Based on a profound understanding of the new economy, continuous attention to and research on regulatory policies, and extensive practical experience, the Mankun team is adept at providing comprehensive legal services from the perspectives of business models and legal practice. These services cater to clients in new economy sectors such as Web3.0 blockchain, artificial intelligence (AI), encrypted payment infrastructure (PayFi), decentralized finance (DeFi), tokenization of real-world assets (RWA), NFT digital collectibles, and crypto funds. The services include business structure design, project investment and financing, operational compliance, commercial disputes, anti-money laundering (AML) compliance system construction, collaboration with global law enforcement investigations, digital asset tracing and recovery, criminal risk prevention and control, and criminal defense.

