In a world of AI agents and open source models, can government censorship and internet firewalls exist?

Firewalls were built for the browser era, centralized servers, DNS blocks, and IP lists. In a world of open-weight models running locally and AI agents that automatically learn to evade, can government censorship still work? Short answer: not the way it used to.

Share
In a world of AI agents and open source models, can government censorship and internet firewalls exist?

The Great Firewall worked because the old internet was easy to gatekeep. You control the pipe, you control the DNS, you control the search box.

Open source AI breaks all three assumptions.

We are entering a world where intelligence is not a website you visit. It is a file you download. An agent you run. A weight you cannot recall. That changes censorship forever.

1. Firewalls Were Built for the Old Internet

The classic firewall model is centralized:

Client -> ISP -> Firewall -> Cloud Model -> Filtered Answer.

It assumes the intelligence lives on the other side of the wall, and you can block access to it.

AI agents invert this. The model lives with you.

And decentralized frameworks are explicitly building censorship-resistant infrastructure, like ORA’s ChatOLM which leverages decentralized and distributed GPUs and because it’s built on the blockchain it’s also censorship-resistant, showcasing how decentralized AI applications can better support free speech, or Venice.ai attempting to get around the guardrails and censorship of centralized AI by enabling a totally private way to access unfiltered, open-source models. 

You cannot firewall math.

Once weights are released, they replicate like BitTorrent.

As one infrastructure piece put it: Open-weight models deployed on your own infrastructure cannot be shut down by government directive. 

2. AI That Learns to Evade

Censorship used to be a cat-and-mouse game humans played manually. Now the mouse has AI.

Researchers developed an Artificial Intelligence-based system that automatically learns to evade censorship in India, China and Kazakhstan.

The tool, called Geneva (short for Genetic Evasion), found dozens of ways to circumvent censorship by exploiting gaps in censors' logic and finding bugs that researchers said would have been virtually impossible for humans to find manually. 

The project seeks to automate the censorship circumvention process, training AI to quickly test and learn viable circumvention techniques.

Through testing against real-world censors, Geneva was able to discover dozens of previously unknown strategies to defeat state-level censorship. 

This is the new dynamic: censors patch one hole, an AI agent finds twelve more overnight. It is not a human hacker vs. a firewall.

It is a genetic algorithm vs. a firewall. The firewall loses on time.

3. Open Source Makes Censorship Non-Transferable

China’s approach was to bake censorship into the model itself.

Its open-source DeepSeek-R1 model was found to censor topics considered sensitive by the Chinese government, refusing to answer questions about the Great Firewall. A leaked database even reveals China has developed an AI system that supercharges its already formidable censorship machine, extending far beyond traditional taboos. 

That worked until the model was open-sourced.

Two things happen when you open-source a censored model:

1. People strip the censorship. Users of Chinese open-source models can tweak the models to bypass most censorship, though some say they can’t fully undo the influence of biases built into the training data. 

2. Censorship does not survive distillation. A hands-on experiment showed that distilling DeepSeek into GPT-OSS doesn't transfer censorship.

The community treated it as a useful, slightly mischievous data point in the open-model and alignment debate. 

Perplexity proved it by releasing R1-1776, explicitly advertised as removing Chinese Communist Party censorship. an uncensored R1 with system prompt rewrite that directly locates and modifies the internal features responsible for censorship.

As one WSJ op-ed argued: even China's heavily censored chatbots have proved difficult to contain within the party's ideological boundaries.

Optimistically, American frontier models, running without those constraints and deployed inside China, would be more potent still. 

In other words: you can put the filter in the weights, but you cannot stop someone from removing it from the weights if they have the weights.

And once it's removed, opensource models cannot be remotely disabled or pressured to comply with government demands. 

4. So Can Firewalls Exist?

Yes, but not as a wall. As a constantly retraining AI vs. AI battle.

Governments will not give up.

They are turbocharging censorship with AI too, unlike traditional censorship mechanisms, which rely on human labor for keyword-based filtering and manual review, an LLM trained on such instructions would significantly improve the efficiency and granularity of state-led information control.

And China is exporting this:

The US-China AI war heats up, with reports that internet censorship tools are being exported along Belt and Road, turning each customer into both a consumer and a contributor to a global censorship threat-intelligence pool centered on PRC-developed infrastructure.

So we get two simultaneous futures:

Future 1: Supercharged Censorship. 

Governments use AI to process much larger volumes of content, with leaked databases, embedded kill switches, and centralized models you must use.

Future 2: Unstoppable Evasion. Individuals run local, uncensored, open-weight agents that talk to decentralized networks, auto-discover evasion tactics, and distill out any political filter.

There is no platform liability shield, but also no threat of censorship. 

My take: The second future wins in the long run because of physics.

A firewall requires you to control all copies.

Open source ensures you cannot. The cost of copying a 70B model is $0.

The cost of blocking every copy is infinite.

Firewalls will not disappear, they will mutate from IP blocklists into model alignment mandates, from DNS poison into app store bans, from Great Firewall into Great Fine-Tune.

But in a world where a teenager in Istanbul can run an uncensored frontier model on a laptop with no kill switch, government censorship as we knew it is already over.

The question is no longer “can they block it?” It is “can they make the uncensored alternative less convenient than the censored default for 80% of people?”

For now, the answer is yes. For the next decade, the answer trends to no.