Shenzhen has added an unusual item to its AI export agenda. Its new 2026–2028 artificial-intelligence action plan, dated August 28 and published September 4, calls for exploring a “Token export” model through Qianhai's inbound-data-processing pilot. The same clause also promotes Chinese hardware, software, standards, models, public technical services, and training abroad. In that context, Token export appears to point to a different route to market: sell the work performed by a model in China, not necessarily the model weights or the machine running them.[1][6]
That could turn domestic computing capacity, electricity, models, engineering, and secure network access into an exportable service. It could also become a vanity counter. A token is only a unit used inside model processing; it does not reveal whether the output was useful, whether the data made a lawful round trip, whether the customer returned, or whether revenue covered the compute and compliance bill.
The important change is therefore not that Shenzhen has found a new commodity. It is that a city with a dense AI supply chain is trying to package cross-border model execution as digital trade. The commercial product will be the whole round trip: authorized data in, controlled processing, inspectable output out, and a contract that survives every border it crosses.
“Token export” is a policy label, not yet a product definition
The Shenzhen plan capitalizes Token but does not define the term, specify whether it counts input or output, or say which models and workloads qualify. It does not distinguish text inference from image or video generation, model training, data labeling, retrieval, or conventional cloud processing. Nor does it publish a price, revenue baseline, customer count, or service-level target.[1]
The document does provide the interpretive key: it links Token export directly to 来数加工, literally “incoming-data processing.” In that model, data generated abroad is transmitted to a controlled computing or service zone in China, processed or enriched there, and returned to an overseas customer. The exported value is the transformation rather than the raw data or physical server.
An operating example predates Shenzhen's new wording. In Shanghai's Lingang free-trade area, engineers processed foreign road footage for use in adapting driving systems to overseas conditions, then sent the resulting data products back to an automaker abroad. Another company worked on 3.5 million authorized scans from an Italian museum database and returned three-dimensional digital products to Italy. Lingang said more than 20 companies conducted inbound-data-processing business in the first half of 2025, using dedicated links, isolated business zones, and electronic fences.[5]
Those examples are broader than tokens. Some work is annotation, rendering, data engineering, or training rather than an API returning a stream of language-model output. Shenzhen's phrasing appears to narrow that older service-export idea around AI computation, but this is an inference from the plan's linkage, not a technical definition the city has published. Until contracts or implementation rules draw the boundary, “Token export” should be read as an industrial-policy direction, not a standardized trade category.
The legal hinge is narrow—and commercially useful
China's March 2024 cross-border-data rules contain a provision that fits the round trip unusually well. Article 4 says personal information collected and generated outside China may be transmitted into China for processing and then provided abroad without a data-export security assessment, a standard personal-information export contract, or personal-information protection certification—provided the processing does not introduce personal information collected in China or important data.[2]
That is a procedural exemption, not a borderless-data promise. Article 10 preserves duties such as notice, separate consent, and a personal-information protection impact assessment where the law requires them. Article 11 still requires data-security safeguards and incident response. The exemption also says nothing about whether the source country permits its data to leave, whether a customer owns the input, or whether a model provider may retain prompts and outputs. Each workload still carries the laws and contractual rights of its origin and destination.[2]
Free-trade zones provide a second lane. Article 6 lets them publish negative lists identifying data that remains subject to the three transfer mechanisms; data outside a valid list can use the streamlined route. Guangdong's May 2026 implementation covers the Qianhai-Shekou area and currently names two fields, seven business scenarios, and 67 data items across intelligent-equipment manufacturing and personal-credit services. Its “use first, report afterward” process may reduce delay, but only for qualifying entities and data. Industries outside the listed scope still fall back to national rules, and local authorities retain inspection and suspension powers.[2][3]
This distinction matters for the market. A foreign-language content job built entirely from licensed overseas material is not the same compliance object as a robot trained on Chinese factory footage, a health assistant using local patient records, or a mixed dataset whose provenance cannot be reconstructed. Cheap inference cannot rescue an input that never had permission to travel.
Qianhai has a lane; it has not yet disclosed a Token-export ledger
Qianhai already possesses much of the substrate that makes the proposal plausible. In May, its administration said the Greater Bay Area integrated computing platform aggregated 16,000P of capacity; the Qianhai Shenzhen–Hong Kong AI computing center was operating; and a 424G international dedicated data channel connected through the National (Shenzhen–Qianhai) New Internet Exchange Center. The same account put network latency from Qianhai to Hong Kong below 80 milliseconds.[4]
It also reported an institutional layer: more than 4,196 data companies in the cluster, a cross-border data service center that had served over 167 enterprises, a compliance laboratory, and a Guangdong negative-list process. These figures show a concentration of suppliers, compute, connectivity, and compliance services. They do not show how many foreign customers bought model execution, how many tokens crossed a billing meter, what workloads ran, or how much export revenue resulted.[4]
Even the network number needs a boundary. Sub-80-millisecond Qianhai-to-Hong Kong latency measures one transport segment, not an end-to-end model response. Queueing, preprocessing, model execution, safety checks, retries, and the customer's own network all add time. The first durable export workloads may therefore look less like a voice agent that must answer instantly and more like batch localization, document processing, media generation, evaluation, or offline data enrichment, where throughput and auditability matter more than conversational speed.
Shantou shows how the vocabulary can move from plan to a tiny reported transaction. On May 18, a user in Singapore sent five story requests through an AI toy to an isolated computing zone in Shantou. The government account says the job consumed about 100,000 tokens, billed at RMB 2 per million tokens, and produced a settled payment. On those figures, the token charge was just RMB 0.20. Its significance was proof of the plumbing—a foreign request, domestic inference, metering, return, and payment—not meaningful export revenue.[6]
The same report says daily use rose from 100 million to 10 billion tokens in less than a month and cites customer retention above 70%. Those are provider- and official-reported operating claims, not an audited market series. No customer cohort, paid-versus-test split, model mix, recognized revenue, uptime history, or margin is disclosed. Shantou demonstrates a reported commercial loop that Shenzhen can study; it does not prove that Qianhai already has one or that Token export is a scaled industry.[6]
Tokens are not interchangeable cargo
Counting exported containers works because a container is a reasonably stable physical unit, even though its contents vary. Model tokens are less comparable. Different tokenization rules can divide the same sentence differently.[8] Alibaba Cloud's own Model Studio price sheet, for example, separates input from output, discounts cache hits, varies rates by model, and sometimes changes unit prices by request length.[9] A raw total can rise because the product improved—or because prompts became wasteful.
The economically meaningful unit is closer to a verified service transaction. It should identify the customer jurisdiction, permitted data class, processing location, model and version, retention rule, output type, latency or completion window, quality threshold, incident process, billing basis, and settlement. Only then can token volume be connected to export revenue, compute utilization, energy use, and repeat demand.
That service wrapper is where Shenzhen could have an advantage. Qianhai combines proximity to Hong Kong, international connectivity, a free-trade-zone rule set, compliance services, and access to a much larger regional supply of models and computing systems.[3][4] A buyer that can purchase a documented round trip—rather than separately negotiate a carrier, compute host, model vendor, data processor, evaluator, and legal review—may accept a higher unit price for lower execution risk.
The counterweight is trust. Some customers will prefer a model running where their data already resides, even if Chinese inference is cheaper. Others will prohibit transfer by law or contract. Interactive services may not tolerate the added network path. Suppliers may discover that isolation, deletion attestations, security audits, insurance, and multilingual support consume the apparent compute-cost advantage. These are not edge cases; they determine which portion of global AI demand is actually addressable.
Five receipts to watch
The first is a published definition. Shenzhen should say whether Token export covers inference only, how multimodal work is converted, whether cached tokens count, and how training or human data work is separated. A metric that changes with each vendor's tokenizer cannot support a citywide market claim.
The second is customer evidence. Report paying foreign customers by cohort and jurisdiction, then show renewal or expansion after a pilot. Event signings and registered demand are weaker than invoices paid for repeated work.
The third is service evidence. Batch completion time, end-to-end latency, error and retry rates, accepted-output rates, availability, and model-version changes would reveal whether cheap computation becomes dependable delivery.
The fourth is compliance evidence. Useful records would include input provenance, legal basis, permitted purpose, segregation from domestic personal information and important data, retention, deletion or return, subprocessors, audit results, and incidents. A customer needs proof that the round trip stayed in its declared lane.
The fifth is export economics. Publish recognized service revenue alongside token volume, customer concentration, compute utilization, power consumption, and the cost of connectivity and compliance. Otherwise a subsidized or internally generated call count can masquerade as trade.
The thesis has a straightforward falsifier. If Shenzhen cannot show recurring third-party foreign revenue after pilots—especially when customers pay the full network, compute, support, and compliance cost—then Token export is a capacity-utilization slogan rather than a new export market. If it can show repeat purchases across lawful data classes, stable service levels, and auditable deletion and settlement, the policy will have identified something more durable than a cheaper API.
Shenzhen's plan is notable because it places AI output inside the machinery of trade. The city is not merely asking whether Chinese models can serve overseas users; it is asking whether overseas work can enter a controlled domestic production lane and leave as a higher-value digital service. In that business, the token is the smallest visible unit. The real export is confidence that the entire journey can happen again.
Sources
- Shenzhen Municipal Industry and Information Technology Bureau, Shenzhen Development and Reform Commission, and Shenzhen Science, Technology and Innovation Commission, “Shenzhen Action Plan for Promoting Artificial Intelligence and Applications (2026–2028)” (dated August 28 and published September 4, 2026; official plan and Token-export clause; in Chinese).
- Cyberspace Administration of China, “Provisions on Promoting and Regulating Cross-Border Data Flows,” Order No. 16 (March 22, 2024; Articles 4, 6, 10, and 11 on offshore-origin data, free-trade-zone negative lists, and continuing safeguards; in Chinese).
- Cyberspace Administration of Guangdong, “Policy interpretation of the China (Guangdong) Pilot Free Trade Zone negative list for data exports” (May 15, 2026; scope, fields, scenarios, reporting process, and regulatory boundaries; in Chinese).
- Qianhai Authority via Shenzhen Government Online, “Qianhai releases pilot results for the national data-industry cluster and launches a compliant battery-passport export project” (May 20, 2026; compute, network, latency, enterprise, and compliance-service figures; in Chinese).
- Jiefang Daily via the Shanghai Municipal Commission of Commerce, “Lingang builds an international data-processing hub and digital-trade gateway” (government repost dated August 18, 2025; operational definition, overseas road and museum-data workflows, participating firms, dedicated links, and isolation controls; in Chinese).
- Shantou Investment Promotion Bureau, “People’s Daily focuses on Shantou Token export: computing services accelerate toward global markets” (June 5, 2026; official republication covering the Singapore AI-toy transaction, isolated processing lane, token metering, settlement, volume, latency, and operator-reported retention; in Chinese).
- schneider+schumacher, “Qianhai Telecommunication Center” (project record for the completed 2018–2024 Shenzhen data center and source for the article photograph).
- Hugging Face Transformers documentation, “Summary of the tokenizers” (technical explanation of BPE, WordPiece, SentencePiece, and why different tokenization rules produce different outputs for the same text).
- Alibaba Cloud Model Studio, “Model pricing” (official inference-pricing documentation covering separate input and output rates, context-cache discounts, model differences, and request-length tiers).