A Chinese model quotes a fraction of what you pay now, the benchmark tables look credible, and somebody senior wants to know whether you are allowed to use it. The price gap is too small to decide anything at mid-market volume: what decides is the legal entity you contract with, where it processes your data, and whether you need its API at all. Two vendors that get named in the same breath give different answers to the first two, and the third question can remove both. What follows is what the published prices, privacy policies, terms and licenses actually say, read on 25 September 2026, in the order we work through them.
The saving is real, and smaller than the meeting about it
Start with the number that starts the argument, and line the tiers up before you line the vendors up. Z.ai’s pricing page lists its flagship GLM-5.3 at 1.40 dollars per million input tokens and 4.40 per million output tokens. DeepSeek’s models and pricing table lists two: deepseek-v4-pro at 1.32 and 3.96 at peak hours, and the smaller deepseek-flash at 0.30 and 1.20, with off-peak rates at half of both. Anthropic’s pricing documentation lists Claude Sonnet 5 at 2 and 10. Most of the comparisons you will be shown pair one vendor’s small model against another’s flagship, which is where the dramatic multiples come from.
Now put a workload through it. Take a support triage agent that reads a ticket, its history and one knowledge base article, then drafts a reply, at 40 million input tokens and 8 million output tokens a month. That is a busy team rather than a pilot. Flagship against flagship at the published peak rates, the monthly bill is 160 dollars on Claude Sonnet 5, 91.20 on GLM-5.3 and 84.48 on deepseek-v4-pro, so the widest annual gap is 906.24 dollars. Drop to deepseek-flash and the bill is 21.60 a month, but you have changed the size of the model as well as its nationality.
A frontier Chinese model saves a mid-sized company roughly the price of one laptop a year.
That is the entire commercial case at this volume, and it is smaller than the cost of the meetings you will hold about it. The arithmetic only turns serious an order of magnitude up: at 400 million input and 80 million output tokens a month the same gap is 9,062.40 dollars a year, which is worth engineering for. Below that, anyone arguing model choice on price is optimizing the wrong line. We run this calculation before the jurisdiction conversation starts, because at mid-market volumes it usually ends it. Where the market’s volume actually flows at these prices is measurable, and we walk the usage data in the 10 most used AI models in 2026.
The model is Chinese; the company you contract with may not be
Z.ai and DeepSeek get filed under the same heading and they are not in the same legal position.
Z.ai’s privacy policy names the controller as JINGSHENG HENGXING TECHNOLOGY PTE. LTD., registered on Anson Road in Singapore. Read its scope line before its location line: “This Privacy Policy only applies to individual users and does not apply to content that we process on behalf of customers of our business offerings.” If you are calling the API, the document that governs you is the Data Processing Addendum further down that same page, and it lands in the same place: “As a result, Customer Data is generally processed in Singapore.” Same jurisdiction, different contract, and only one of the two is yours. DeepSeek’s open platform terms put you somewhere else. Disputes under them “shall be governed by the laws of the People’s Republic of China in the mainland”, and either party may file in a court covering the registered office of Hangzhou DeepSeek Artificial Intelligence Co., Ltd. Its privacy policy is equally plain about location: “To provide you with our services, we directly collect, process and store your Personal Data in People’s Republic of China.” That policy also scopes itself carefully. It covers DeepSeek’s own apps and services, and it says that personal data collected from end users of an application you build on the open platform falls outside it, with you as the controller. The duty moves to you; it does not disappear.
Read the content clauses with the same eye for scope. Z.ai’s terms of use reserve, for individual users, the right to improve the service from user content, and to process and store that content outside the jurisdiction where the service is accessed. Whether that clause reaches you again depends on which agreement you are on. That is the whole lesson of this section: on these platforms, the document a search engine hands you and the document you are actually bound by are rarely the same file, and the scope line is usually the first paragraph.
No adequacy decision covers either country, so the transfer work is yours
The European Commission publishes the list of jurisdictions it has recognized as providing adequate protection for personal data: Andorra, Argentina, Brazil, Canada for commercial organizations, the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, the Republic of Korea, Switzerland, the United Kingdom, the United States for commercial organizations participating in the EU-US Data Privacy Framework, Uruguay and the European Patent Organisation. Neither China nor Singapore is on it.
That is not a prohibition, and treating it as one is the most common mistake in the room. It means a transfer of personal data needs one of the GDPR’s other tools, usually standard contractual clauses, plus an assessment of whether those clauses hold up against the local law of the destination. The work is ordinary and the paperwork is broadly the same for both vendors. What it is not is free, and it is the cost that every price comparison leaves out. The asymmetry is worth naming out loud: a US vendor certified under the Data Privacy Framework sits inside an adequacy decision, so if that is where your workload runs today, moving it to either of these vendors adds a step you do not currently have.
The regulator went after the app, not the API
On 30 January 2025 the Italian data protection authority ordered an urgent limitation on the processing of Italian users’ data by Hangzhou DeepSeek Artificial Intelligence and Beijing DeepSeek Artificial Intelligence. The authority’s own statement records what tipped it: “the companies declared that they do not operate in Italy and that European legislation does not apply to them”.
What that decision is and is not: it concerns the consumer chatbot service and the companies’ stated position on European law. It is not a finding about the weights, the benchmarks or the output quality. Those are separate questions with separate answers.
The buyer’s reading of it is narrow and it is still the most useful sentence in this post. A vendor that tells a European regulator that European law does not apply to it has told you how a data subject request, an audit clause or a breach notification is likely to go. That is a procurement fact rather than a technology fact, and no evaluation harness will ever surface it.
The open weights are what makes the question optional
Here is the part these discussions usually skip. The models are published. Z.ai’s GLM-5.3 weights are on Hugging Face, the same generation it sells through its API. DeepSeek publishes DeepSeek-V3.2 under an MIT license. Alibaba’s Qwen3.5-397B-A17B is published under Apache 2.0, and Alibaba Cloud sells hosted access to its Qwen models through the Model Studio catalog. These are genuine open weights rather than a demo tier, and they change the shape of the decision, because a file you download is not a transfer of anything to anybody.
You do not need your own accelerators to use them. Scaleway, a French provider, lists GLM-5.2, DeepSeek-V4-Flash and several Qwen models among its supported models, and its data privacy documentation states the data residency position in one line: “Your personal data may be stored in the following region: Paris, France.” The same page sets a zero data retention policy by default, with aggregated and anonymized usage data kept for up to six months. Your counterparty is then a French company under French law, the model is a file it happens to be serving, and the vendor’s nationality has stopped being a contractual question at all.
Read the license for the generation you are actually deploying
Open weights are a family of licenses rather than one license, and the terms move between generations of the same model. GLM-4.6 shipped under MIT. GLM-5.3 ships under its own GLM-5.3 License, which grants the same broad rights to use, modify, distribute and sell, then adds a single condition: a licensee that operates a model as a service business, and whose group revenue exceeds 10 billion US dollars over any consecutive 12 months, must pass a Z.AI security review before any commercial use.
Read that clause against your own revenue rather than against its tone. For a mid-sized company it is inert. It will still appear in a legal review as a custom license with a commercial condition attached, and sit there for two weeks, unless somebody reads the number. The generation matters as much as the vendor: an internal note saying “GLM is MIT licensed” was accurate for 4.6 and is wrong for 5.3, and that drift will happen again on the next release of something else.
Residency has a price tag on the Western side too
One more calibration, from the other direction. Anthropic’s pricing documentation states that for Claude 4.6 and later models, specifying US-only inference through the inference_geo parameter incurs a 1.1x multiplier on all token pricing categories, with global routing as the default. A Western vendor charges ten percent to pin where inference happens.
That is useful for two reasons. It puts a price on a property you probably assumed came free, and it shows the property is separable from the model: where inference runs is a parameter, not an attribute of a vendor’s nationality. Design your stack so the model sits behind your own gateway, with residency and vendor as configuration, and this decision stops being a one-way door. That is worth more than any of the price differences in this post.
The takeaway
“Chinese AI model” is not a unit you can make a decision about. Decide three things instead: the legal entity on your contract, the jurisdiction it processes in, and whether you need that vendor’s API at all. Price is not one of them at mid-market volume, because the annual saving is smaller than the assessment it triggers. If the workload touches personal data, the open weights on a European host answer all three questions at once and leave you with an ordinary vendor review. If it touches no personal data, take the cheapest option and put it behind a gateway so the answer stays cheap to change. The layer worth owning is the one that lets you swap the model without swapping your product, which is the same argument as in AI framework vs custom stack.
Sources
- Z.AI pricing, Z.AI developer documentation: the published per-million token rates for the GLM family.
- Models and pricing, DeepSeek API docs: the deepseek-flash and deepseek-v4-pro rates, and the peak and off-peak split.
- DeepSeek privacy policy: the controlling entity, where personal data is stored, and what the policy does not cover.
- The Italian Data Protection Authority blocks DeepSeek, Garante per la protezione dei dati personali: the January 2025 limitation order and the companies’ position on European law.
- Adequacy decisions, European Commission: the full list of recognized jurisdictions.
- Generative APIs data privacy, Scaleway documentation: the Paris storage region and the default zero data retention policy.