27 Sources
[1]
Anthropic's Dario Amodei responds: doesn't oppose open-weight models, but fears Chinese AI
Anthropic founder and CEO Dario Amodei responded on Monday afternoon to murmuring in the industry that his company somehow supports efforts by the U.S. government to ban open-weight Chinese models, or possibly open-weight models generally. "Anyone who has read my past writing should know that I don't regard such bans as a useful measure, but let me state it clearly so that there is no doubt: Anthropic has never advocated for a ban on open-weights models," he wrote, emphasis his own. His response came after Nvidia founder and CEO Jensen Huang took to X (his first post on the platform) to share an open letter on Friday in which Nvidia and a long list of other AI companies including Hugging Face, Meta, Microsoft, Mistral, and Nvidia urged policymakers not to impose broad "premature restrictions" on open-weight AI models. While that letter did not mention China specifically, the debate in the industry has centered on allegations that Chinese AI labs are growing in capability often by stealing intellectual property from their American counterparts. One method is distillation, where an AI bombards another model with prompts to learn how it works. Amodei said in the blog post published Monday that he views open-weight models as falling into a different bucket than the threat China poses. "Open-weights models that don't have dangerous capabilities are a public good: they don't cost anything besides the compute needed to run them, and they provide value to businesses, developers, and researchers." Amodei said in his post that he has longstanding fears about AI, but businesses using open-weight models, even ones from China, are not among them. His fear is that "authoritarian governments" will build models that are more powerful than those in the U.S. to achieve "permanent military superiority" and/or use AI to repress their own people. He said the Chinese Communist Party (CCP) isn't the only authoritarian government he's concerned about, but it is the "most capable." Amodei also said he fears AI will enable "biological attacks" not just cybersecurity ones. And, in his view, open-weight models are more dangerous in those scenarios because it's difficult to apply guardrails to them or monitor their usage. He also noted, citing a UK AI Security Institute report, that once open-weights are released they cannot be withdrawn This runs counter to what open source advocates argue: that access to powerful open models not controlled by a single entity helps defenders protect themselves. Amodei listed actions he believes would thwart China, including restricting its access to powerful chips (which has been a longstanding U.S. policy) and calling for a formal crackdown on distillation. The U.S. has threatened sanctions against China if it determined there was IP theft involving U.S. models. Interestingly, Amodei also said he supports growing efforts, some led by the U.S., to create a model safety testing organization, especially if the entire world, including China, agreed to submit to it. "I think this idea is actually close to a consensus: I have been heartened both that the Trump administration has moved in this direction in recent months," Amodei wrote. "Note that to be effective, testing would need to be global, which means even the CCP would need to be on board. I think this may actually be possible ... limited cooperation around preventing AI biological weapons may be possible because it is in China's interest too."
[2]
Banning Open-Source AI Models to Protect Our Cybersecurity May Do the Opposite - CNET
Katelyn is a reporter with CNET covering artificial intelligence, including chatbots, image and video generators.... Read full bio In an escalating effort to give the federal government power over the AI industry, some members of the Trump administration have reportedly tried to implement a "de facto ban" on foreign-made open-source AI models. This ban would apply to any non-US-made AI model, but the goal seems to be to specifically target Chinese AI labs, which often release their models as open source. The recent release of the Kimi K3 AI model from Chinese developer Moonshot fueled these concerns. Kimi K3 matched and in some cases exceeded the capabilities of American-made AI models such as those made by OpenAI, Anthropic and Google. Its July release sent shockwaves through Wall Street - not unlike other AI model drops, but with one big difference. Kimi K3 was released as an open-weight model, while American AI leaders like OpenAI and Anthropic companies keep their tech closed with very few exceptions. Open-source AI typically refers to open-weight models. Weights are characteristics that tell the model how to behave - giving more weight to useful answers than incorrect ones, for example. Open-source advocates have said that to be truly open-source, AI companies should release or clarify their training data sources. AI companies haven't been forthcoming; OpenAI and other companies are being sued by publishers and artists for allegedly violating their copyrights in AI training. (Disclosure: Ziff Davis, CNET's parent company, in 2025 filed a lawsuit against OpenAI, alleging it infringed Ziff Davis copyrights in training and operating its AI systems.) Open-weight models give developers more insight into how top models work. Nearly 80% of developers use open models, a recent Mozilla report found. "Open-weight models are everywhere in the industry already," said Linda Griffin, vice president of global policy at Mozilla. "So a world without them would hit a lot of people." Tech companies immediately and strongly rejected the idea of a government ban on open AI models. Microsoft, Nvidia, Meta and several other AI developers and tech venture capital firms signed an open letter (PDF) asking the Trump administration to reconsider. "Our AI leadership will be judged not by one frontier AI model, but by whether the United States builds a strong, open ecosystem that diffuses into every sector," the July 24 letter reads. Ideally, the money and power that AI companies promise come with AI adoption, would follow. Restrictions on Chinese tech: Good or bad for cybersecurity? This is far from the first time the Trump administration has taken steps to limit Americans' access to Chinese tech. Remember the years-long battle over potentially banning TikTok? Chinese parent company ByteDance was eventually forced to transfer ownership of its US business to US-based ownership led by Oracle, whose co-founder and executive chairman, Larry Ellison, is a prominent supporter of President Donald Trump. Restrictions on foreign hardware have been rolling out, too. The Federal Communications Commission banned foreign-made routers in March, saying that they posed a security risk. The order massively disrupted the industry behind the devices that people need in order to access the internet. Given the leaps in AI advancement over the past year, it isn't totally surprising to see these arguments. AI is being used by both cybersecurity attackers and defenders, making it a high priority for AI companies to secure their models against potential misuse. Anthropic and OpenAI have both worked with the US government to slow-roll the release of their newest models, Claude Fable 5 and GPT-5.6, respectively. That government review is voluntary for now, but it might one day become mandatory, specifically because of the cybersecurity concerns. But if government officials are worried about AI cybersecurity, banning open AI models might have the opposite effect. "Open-weight models allow researchers to examine how these systems work and identify risks and vulnerabilities," said Aditya Vashistha, professor of computer science at Cornell University. "Restricting access would make it much harder to independently evaluate how safe and secure these technologies really are." The Trump administration has been adamant that it won't hinder AI innovation with regulation. But if open-weights models are banned, the people and companies who aren't part of selective AI cybersecurity programs like Anthropic's Project Glasswing will be at risk, said Ayham Boucher, executive director of AI strategy and innovation at Cornell. "Regulators can't have it both ways. You can't restrict access to frontier models and ban open-source models, leaving enterprises and institutions defenseless," Boucher said. Openly 'diffusing' the benefits of AI Unsurprisingly, the tech industry has reacted negatively to the idea of restricting access to open-source AI models. Meta CEO Mark Zuckerberg advocated for open AI technologies, writing in an op-ed in the Wall Street Journal earlier this week that it is through openness that the benefits of AI spread throughout our society. "Historically, hoping that an absolute power will benevolently provide for humanity if sufficiently enlightened hasn't led to safe or positive outcomes," Zuckerberg wrote. (As CEO of the company that operates several of the world's largest social media platforms, Zuckerberg himself is one of the very few who have something like absolute power over our technological experiences.) But the true appeal and benefit of open-source AI, like all open-source technologies, is that anybody gets to build with AI, not just Big Tech. "If you take them away, developers and consumers pay more, get less choice, and a whole lot of useful stuff just never gets made," Griffin said. A broad ban "would set a troubling precedent." Developers know that some guidance is necessary. Over 1,000 staffers at top labs, including chief scientists from OpenAI, Meta and more, signed an open letter asking the US government to support an international effort to build technical and governance tools as they "pace the frontier" of AI research and development. "For the US to maintain its leadership in AI, it cannot rely solely on closed models," said Vashistha. "If the US moves away from open models while others continue investing in them, it risks ceding not just market share, but also influence over the global AI ecosystem."
[3]
Open weights vs. closed: An AI civil war's afoot, and the stakes are existential
Follow ZDNET: Add us as a preferred source on Google. ZDNET's key takeaways * The conflict between open and closed large language models is on. * Open weights and open source are not the same, but open weights are the future. * On the proprietary side are Anthropic and OpenAI; on the other, most everyone else. The open-weight Moonshot AI's Kimi K3 is faster than Anthropic Fable 5 in some ways, and is nearly as fast as Fable 5 and OpenAI's GPT-5.6 in others. That's fast. And that has some American AI companies and the Trump administration worried. Michael Kratsios, Trump's director of the Office of Science and Technology Policy, has claimed that "Moonshot AI distilled Anthropic's Fable for the development of its K3." In short, he's suggesting that China's Moonshot stole from Anthropic. That's not how everyone sees it. Many US AI companies see Moonshot's open-weight methods as perfectly legitimate. Also: AI Model Release Tracker You might think it would be simple -- good guys versus bad guys -- but it's not. Even Kratsios admitted, "Legitimate AI distillation used to create smaller, more efficient models plays a vital role in this open innovation ecosystem." But, he added, "large-scale, covert industrial distillation aimed at stealing proprietary US technology and undermining American research is unacceptable." Are they really, though? The difference between illegitimate and legal uses of other models is paper-thin. It largely depends on where you sit. All AI models have been built on top of other models, and their data comes from essentially everything and anything their builders can grab. Microsoft and a host of tech giants support open weights So, immediately after the Kimi K3 kerfuffle surfaced, Microsoft released its new "Open Weights and American AI Leadership" policy statement. It defines open-weight models as systems anyone can download, inspect, modify, and run on their own infrastructure. As Microsoft and its allies, which include Amazon, Nvidia, Google, and a host of other tech giants, see it, the use of open weights is a net good for everyone, including US AI giants. They aren't the only ones. Almost 200 Silicon Valley start-ups, the Little Tech Association, have urged the Trump administration not to limit access to Chinese open-source models. Also: Why AI tokens will send your enterprise cloud bill sky-high again Microsoft's statement does a better job than most industry letters of tying open weights to actual economics. It argues that open models let startups, universities, hospitals, factories, and public institutions match the right model to the right job without paying frontier-model prices for every task. This makes AI economically sustainable for everyone. For now, we're still living at a time when frontier AI is comparatively cheap. That won't be the case much longer. AI pricing will explode by year's end. Open weights are the only way forward to affordable AI. The Redmond giant also makes a security case that's easy to miss if you stop at the headline. Microsoft says open weights can help defenders simulate attacks, find security holes, and improve models through broader testing, rather than relying on proprietary systems. That's always been one of the arguments for open source. Indeed, Linus's law declared "given enough eyeballs, all bugs are shallow." Now, instead of human eyeballs, we have AI models hunting bugs faster than people ever managed. In a Wall Street Journal editorial, Meta CEO Mark Zuckerberg acknowledged that "In most cases, like cybersecurity, the history of open-source software has shown that giving everyone full access to powerful systems will be the best way to protect safety and security over time." Also: Is open source the answer to rogue AI agents? Nvidia's new alliance says yes Backing this up, Nvidia's brand-new Open Secure AI Alliance "will work to remediate and disclose vulnerabilities using open technologies." As Nvidia put it, "Some argue that open models are inherently less safe because they can be misused for cyberattacks or modified to remove guardrails. Those risks are real, but they do not disappear in closed systems, and simply keeping weights closed does not prevent determined attackers from seeking or exploiting powerful AI." China, of course, is all about open weights. China's leader Xi Jinping recently said, "AI development should not be a solo performance by a single country but a symphony of global collaboration." Open-source is a "rare and historical opportunity" to spread AI's benefits worldwide. The difference between open weights and open source However, open weights are not open source. The difference between open-source AI and weights, according to the Open Source Initiative (OSI), is that open weights usually means the trained weights are available, but not necessarily the full training data or source code. The two terms are frequently conflated. The OSI itself declared, "Every AI system in the headlines today, whether proprietary or open source, exists because researchers shared their work openly." Without open source, there is no AI. Also: How AI has suddenly become much more useful to open-source developers That said, as Stefano Maffulli, former head of the OSI and Grist Labs chief revenue officer, pointed out on LinkedIn, "Full open source AI, as in its definition, would be better. I'd settle for open weights at this point and continue pushing for data transparency, protecting those who disclose their ingredients and release the weights freely." I know this. You should know this. And the companies supporting open weights, whether they're building them in the US, Canada, the EU, or China, know this too. Indeed, Nvidia CEO Jensen Huang's first-ever tweet supported Microsoft's AI position. He was far from alone. Elon Musk, Google CEO Sundar Pichai, and Zuckerberg all have publicly supported the open position. The strategic conflict For Washington, the message is clear: Open weights are being recast as part of American industrial policy. The coalition is asking policymakers not to impose premature restrictions on downloadable models or to confuse legitimate techniques like distillation with misappropriation. That is a direct challenge to any move that would use China as the reason to lock down model distribution more broadly. Also: Canonical's approach to AI is refreshingly thoughtful - Microsoft should take note The bigger story is that open weights have become the language through which a large slice of the AI industry talks about competition. The open-source movement promised and delivered on shared infrastructure and broader innovation. The Microsoft coalition is arguing that the same logic now applies to AI, even if the result is not "open source" in the strictest sense. That makes the fight less about idealism than about who gets to shape the next layer of the AI stack. OpenAI and Anthropic: The proprietary opposition Now, both Anthropic and OpenAI state that they support open source. Their actions say otherwise. For example, Anthropic is the one US AI powerhouse that hasn't signed the open-weight policy statement. Also: Is your AI model secretly poisoned? 3 warning signs Anthropic CEO Dario Amodei is trying to thread the open-weight needle by underlining in a blog post, "Anthropic has never advocated for a ban on open-weight models." However, he emphasized, his "primary concern is the risk that authoritarian governments -- not solely the Chinese Communist Party (CCP), although the CCP is clearly the most capable threat -- build AI models that are more powerful than those built by the US, and use them to achieve permanent military superiority or perpetrate incredibly deep repression of their own people." He also argued that "We should crack down on industrial-scale distillation operations" and demanded that "sufficiently capable models, open and closed, should go through mandatory safety testing." The problem with these arguments is that there's nothing about the Chinese models that makes them uniquely dangerous. The same could be said of any AI models. Many people are worried sick about all AI models. AI attacks are already common; Anthropic's Claude AI shared chats were shared with anyone who could do a Google search; and recently, OpenAI AI models attacked a Hugging Face model. There's nothing "safe" about anyone's AI. OpenAI didn't sign the document immediately, but it finally got on board. That said, OpenAI executives have been partnering with the Trump administration to require mandatory security evaluations of new AI programs. It's hard to imagine a Chinese model passing such an inspection. Also: Claude AI shared chats indexed by Google - see if your conversations were exposed Ot a higher level, what we have here is a conflict between those who support open models and those who want a more closed approach. This is not a philosophical argument over "open versus closed." No, it's a fight over who benefits from openness, and who gets to define safety. Anthropic and OpenAI's future relies on their expensive, proprietary models beating open-weight models. If cheaper open-weight models deliver similar performance, then both are in a world of trouble. Microsoft and the rest, however, already have successful cloud-based businesses. For them, open-weight AI means more customers coming to them for the infrastructure to run anyone's models.
[4]
Dario Amodei weighed in on Anthropic's open-weight model controversy.
The company had been igniting widespread criticism as seemingly the only leading AI lab not supporting open-weight models. Nvidia CEO Jensen Huang recently published a public letter in support of them, signed by Microsoft, Nvidia, Meta, Palantir, Hugging Face, and others -- and in the days since, it's added OpenAI, Google, Amazon, Meta, SpaceX, Cohere, Mistral, CoreWeave, GitHub, OpenClaw, and Perplexity as signatories. Now Anthropic's CEO has published his own thoughts on the matter, clarifying, "Anthropic has never advocated for a ban on open-weights models."
[5]
Why Didn't Anthropic Sign the Open Model Letter? AI Offense Outpaces Defense
An open letter urging the US to support rather than restrict open-weight AI models has received public support from all the major tech companies -- except Anthropic. CEO Dario Amodei is now explaining why, suggesting that open AI models could empower attackers more than defenders. Amodei says he "agrees with much" of the open letter, which was initially published with the backing of 25 companies, including Microsoft and Nvidia. It has since grown to 77 signatories, including OpenAI, Google, and Elon Musk's SpaceX. In a Monday blog post, Amodei clarified that while Anthropic refused to sign the letter, the company has "never advocated for a ban on open-weights models," writing, "Open weights expand access to the AI economy, they strengthen competition at least for some use cases, and they give customers greater control." But Anthropic's CEO takes issue with one claim in the letter, which argues companies need access to open models to help defend against advanced AI-powered cyberattacks. "Open models broaden defensive capability, increase transparency, and allow vulnerabilities to be discovered and remediated across many teams," the letter says. (Recently, Hugging Face used a Chinese-developed open weight model to detect a hack that, ironically, was later traced to an OpenAI program that had gone rogue.) "I don't agree with the letter's assertions that open-weights models necessarily make it easier to develop safeguards or that broad access to capabilities necessarily helps defenders more than attackers," Amodei wrote. "It seems at least as likely to me that the opposite will be true." As an example, he cites the risk of a malicious group using AI to create a bioweapon based on a pandemic-level virus. The "defense against these agents is a multi-year operational task in the best case," he wrote, alluding to the effort to create a COVID-19 vaccine and roll it out widely. Amodei's larger message is that a strict "protectionist ban" on US businesses adopting open-weight AI would fail to address his most serious national security concerns. The first is the risk of China or a foreign government developing an AI program more powerful than a US model "to achieve permanent military superiority or perpetrate incredibly deep repression of their own people." His other concern is that open-weight models -- while different from open-source -- are designed to be free for anyone to use and modify. "Open-weights models -- it does not matter whether they come from China or anywhere else -- do potentially present a higher risk than closed models, because it is very difficult to apply guardrails to them or monitor their usage, and once weights are released, they cannot be withdrawn," he says. "But banning the use of these models by US businesses does nothing to address this risk, because bad actors are unlikely to be legitimate US businesses." In response, Amodei urges the US government to continue blocking and shutting down Chinese efforts to smuggle cutting-edge Nvidia GPUs. "This is the most efficient and direct way to block threat #1, and by hampering the training of models that are out of reach of US law, it also indirectly helps with threat #2," he wrote. In addition, Amodei is calling for the US to crack down on "industrial" AI distillation, a method that Chinese companies have been accused of using to copy and clone the capabilities of US leading-edge models. His final measure urges the US to require all AI models, whether open or closed, to undergo "mandatory safety testing" to prevent their use for malicious activities. "I have been heartened both that the Trump administration has moved in this direction in recent months, and by recent industry proposals that would apply such testing to the most capable models regardless of their country of origin or whether they are open or closed," he added. Still, it's no secret that open models threaten to reduce industry reliance on the top-tier closed models from OpenAI, Anthropic, and Google. The New York Times reports that OpenAI's allies have been quietly lobbying the White House for restrictions on China's open-weight models.
[6]
Jensen puts his thumb on the scales against open-weights fearmongering
Nvidia has made a fortune on the AI boom. But the flames of opposition to open-weights models -- that is models that anyone can download, modify, and run on their own infrastructure -- could change that, and Nvidia CEO Jensen Huang isn't waiting to find out. On Friday, a cadre of tech titans wrote an open letter [PDF] offering a counterpoint to the mounting anti-open-weights rhetoric from American companies like Anthropic and OpenAI. Signatories included Meta, Microsoft, IBM, and Dell, but the loudest voice among them was Nvidia. Of course it was. Nvidia has the most to lose. In his first-ever post to the social network formerly known as Twitter, Huang touted the letter arguing that open models "strengthen safety and cybersecurity, accelerate innovation and diffusion, and enable sovereignty." He added, "The world needs both frontier closed models and frontier open models." Why? Nvidia's future depends on a healthy and diverse ecosystem of models. As any good arms dealer knows, the best way to guarantee profits is to sell to both sides. But if the US restricts Chinese open-weights models, American customers' options become mediocre US models, or proprietary and increasingly expensive ones from OpenAI, Anthropic, and Google. Nvidia's addressable market shrinks and its ability to grow diminishes. What good are all these "AI factories" that Nvidia has helped prop up in that case? As we wrote last week, the US hasn't invested in open weights models to the same extent as the Chinese model houses. For enterprises unwilling or unable to use proprietary models, models from the likes of DeepSeek, MiniMax, Z.AI, and Moonshot (Kimi) are the only credible alternatives. Thinking Machine Labs' nearly-billion parameter Inkling model is the best open weights model American has to offer, and if benchmarks are to be believed at all, it's not even in the same ballpark as Kimi K3. Huang knows the stakes and the game. If the Trump administration decides to go thermonuclear and sanction Chinese model developers, there's little he can do about it. He learned that lesson the hard way trying to get his hardware back into China. What Nvidia can do instead is light a fire under American model devs to get their act together and start churning out open weights models that are actually competitive with China. And Nvidia has an awful lot of leverage. The flex OpenAI and Anthropic are operating at a tremendous burn rate, chewing through tens of billions of dollars a year in the hopes that one day their efforts might bear fruit. Until that happens, they're entirely reliant on their ability to raise new equity and debt financing, a fact that Nvidia has taken full advantage of. Over the past year, Nvidia has announced billions of dollars of investments in AI startups, including OpenAI and Anthropic, often without binding contracts, and usually tied to infrastructure deployments. OpenAI and Anthropic respectively have $30 billion and $10 billion in funding in capital riding on Nvidia that may or may not actually materialize. And The Wall Street Journal reported Sunday night that Nvidia may make a far larger commitment to OpenAI in the form of a $250 billion backstop to help the model-maker lease space from a planned $10 billion datacenter Softbank is building in Ohio. The open letter may as well have been Huang's way of saying: 'It would be an awful shame were something to happen to that cash, Mr. Altman. Maybe it's time to get back on the "open" bandwagon that gave your company its name. Yeah, I thought so.' That's certainly what OpenAI, SpaceXAI, and Meta seem to have heard. On Friday, OpenAI CEO Sam Altman quoted Huang's X post and reiterated his support for open weights models. "I want the US to win in AI both in open source and proprietary models, and I am glad to see this," he wrote. OpenAI is certainly no stranger to open-weights models - GPT-2 fit the bill way back in 2020, and last year it emitted its first open model since then, GPT-OSS. At 20 and 120 billion parameters in size, the models were among the United States' most capable open models at the time, but they fell well short of OpenAI's proprietary models and were no match for the growing number of models coming out of China. But now, GPT-OSS is practically geriatric -- in the AI equivalent of dog years that is -- celebrating its first birthday next month. Altman isn't alone. Last week Meta's Chief AI Officer Alexandr Wang confirmed that Meta would be getting back into the open model race soon enough. At one point, Meta had gone all in on open weights models as its key differentiator, but after Llama 4 failed to impress last year, the Social Network pivoted to proprietary models. Its first, Spark Muse, debuted earlier this year. Then there's SpaceXAI CEO Elon Musk, who joined in on the Twitter quotefest. "This has my full support. Jensen is right." he said, quoting Huang's post. Like OpenAI and Meta, xAI, now part of SpaceX, is no stranger to open models. Earlier in the company's foray into LLMs it committed to releasing older model weights to the public. Unfortunately, as is so often the case with Elon's pronouncements, his company hasn't followed through on that promise. Earlier this month, the conglomerate rolled out Grok 5 to the public, yet its most recent open weights model on Hugging Face is still Groq 2. Since the letter's release, SpaceX and OpenAI have been added as signatories. Show, don't tell These commitments may turn out to be little more than virtue signaling. We don't know yet. The real test isn't whether we see new open weights models come out of SpaceXAI, Meta, or OpenAI, but whether they invest enough so they can hold their own against Chinese models. OpenAI is the most likely player to pull this off. If we're going to see a GPT-OSS-2, next month would be the time -- assuming they've actually been working on a successor. If they haven't, well, it's going to be a bit. Anthropic, whose leadership has taken the most hostile position against the adoption of Chinese open weights models, has been conspicuously quiet on the subject of open models. We've reached out to all four American AI houses for further comment on their open weights model plans; we'll let you know if we hear anything back. In the meantime, Nvidia isn't letting up as it tries to get another political firestorm under control. Right about the time model devs were reportedly using Moonshot's Kimi K3 release to lobby White House officials into restricting Chinese model use, OpenAI's models were stirring up some drama of its own. Last week, the AI flag bearer admitted that its models powered an agentic cyberattack on Hugging Face's infrastructure. The popular model repo quickly launched its own AI-powered response, only to discover those same models' safeguards were getting in the way of the analysis. In a fitting bit of irony that went precisely against OpenAI's interests, Hugging Face was forced instead to rely on uncensored Chinese models to get the job done. On Monday, Nvidia unveiled the Open Secure AI Alliance, which aims to ensure defenders have the tools they need, including open frontier models and tools, to protect themselves from a new generation of cybersecurity threats. In either case, what's good for Nvidia's bottom line also happens to be in the best interests of enterprises regardless of whether they buy Huang's hardware or not. Open ecosystems and choice are never a bad thing. ®
[7]
Anthropic rejects open-weight AI bans, calls for China chip controls and safety tests
The statement follows criticism over Anthropic's absence from an industry letter opposing open-weight AI limits. Anthropic CEO outlined his support for lower-risk models alongside tighter controls on more powerful systems. Anthropic CEO Dario Amodei has argued that policymakers should keep lower-risk open-weight AI accessible while placing stricter safeguards around frontier systems, including mandatory testing and limits on China's access to advanced computing and model capabilities. In a post outlining Anthropic's position, Amodei said broad restrictions, including bans on Chinese open-weight models used by US businesses, would not address his main national security concerns. Instead, he pointed to the possibility of authoritarian governments surpassing the US in advanced AI, as well as cyber, biological, and alignment risks posed by increasingly capable systems. Amodei also called for action against industrial-scale model distillation, which he said allows Chinese developers to improve their models with less computing power than would be needed to train comparable systems from scratch.
[8]
Hugging Face CEO says China is winning the AI race and dominating on open models
Hugging Face CEO Clément Delangue said China is winning the artificial intelligence race with open-source models and could catch up to U.S. model makers as soon as this year. "They're clearly dominating on open models right now, and I wouldn't be surprised if they start dominating at the frontier either by the end of this year or next year at the rate of progress," he told CNBC's "Squawk on the Street" on Monday. Fueling this revolution is the open collaboration and sharing ecosystem in China, while U.S. model makers in the U.S. are "building in silos," he said. Last month, OpenAI agents broke out of a training environment and hacked open-source software developer platform Hugging Face, raising concerns over the rapid evolution of powerful AI and cybersecurity tools.
[9]
As China's A.I. Gets Stronger, It Poses New Risks to Beijing
China has cast itself as a champion of low-cost, open-source artificial intelligence technology that it says should be made widely available to the world. It has accused the United States of "A.I. hegemonism" as the Trump administration has debated regulating Chinese open-source A.I. models. Unlike closed systems such as ChatGPT and Claude, open models can be downloaded, modified and run by anyone, including with safeguards removed. The open approach, which is lower in cost, has won Chinese A.I. systems, made by companies like Alibaba and Moonshot, a start-up, millions of global converts, including Silicon Valley companies like Airbnb and DoorDash. But the same openness that has helped Chinese models win influence abroad now raises concerns for Beijing, particularly about security and the potential threats the technology might pose to the Communist Party's rule. In a speech earlier this month, China's top leader, Xi Jinping, said that even as China supported openness in A.I., the government needed to "constantly refine measures to forestall loss of control." The party is concerned that the technology could be used by hackers, scammers, terrorists or other bad actors seeking to cause harm in China; that models could circumvent its tight censorship filters; and that the government could be blamed if Chinese systems spin out of control elsewhere. The question of how much, if any, control Beijing or Chinese companies should exert over who gets to use and modify Chinese models has become more acute with the emergence of powerful homegrown A.I. systems. One is Kimi K3, released by Moonshot to the public earlier this week, which performs some tasks as well as the best models from American rivals, including OpenAI and Anthropic. Models like these could help companies write code and improve cybersecurity, but could also help hackers find vulnerabilities and exploit them more quickly. "The Chinese Communist Party is a security-first institution, especially under Xi," said Matt Sheehan, a senior fellow at the Carnegie Endowment for International Peace. He said Beijing was concerned that advanced models could carry out cyberattacks or evade safeguards, or make it easier to design or create harmful new viruses or other biological agents. "If these models do reach those dangerous capabilities, they are not going to let it be a free-for-all in terms of releasing them," Mr. Sheehan said. Anthropic and OpenAI say that some A.I. models are too dangerous to be developed in the open and must be tightly controlled, and have raised concerns in Washington about Chinese models. Chinese and other commentators, however, have noted that some of the most high-profile A.I. safety breaches have involved closed-source American models. Want to stay updated on what's happening in China? Sign up for Your Places: Global Update, and we'll send our latest coverage to your inbox. Fears About A.I. Challenging Beijing's Grip China's anxiety over A.I. was on display at a recent cybersecurity conference in Beijing, where speakers warned about risks that included data breaches and deepfake images. Zhou Hongyi, an influential Chinese tech executive, cautioned the audience that China was more vulnerable than ever to cyberattacks because of the advent of breakthrough models like Mythos, an advanced Anthropic system designed to find software flaws. The conference also discussed A.I. data poisoning, in which an attacker feeds A.I. chatbots with manipulated data that skews results. In Beijing's telling, such tactics could be used to make A.I. systems generate politically subversive responses. China's Ministry of State Security in April warned about data poisoning as a threat to "political and ideological security." It said "hostile anti-China forces," the party's code for the West or for human rights activists who criticize Beijing, could exploit A.I. models by training them to smear the party and government. That could include providing information about domestic protests or facts that undermine state narratives about the far western region of Xinjiang, where China has imposed a crackdown on Muslim ethnic groups, and Taiwan, the democratically-governed island that Beijing claims is its territory. The worst-case scenario for Beijing, when it comes to public opinion, is that "A.I. chatbots start saying things the party doesn't want people to hear," said Alex Colville, a cyber expert at the Australian Strategic Policy Institute. The concern extends to "any information that loosens their monopoly on dictating what is true and what is false," he added. What Controls Could Look Like Reuters and The Financial Times reported this month that China's Ministry of Commerce had met with leading Chinese A.I. firms like Alibaba and ByteDance to discuss restricting overseas access to their top models. The ministry and companies did not respond to requests for comment. Even the handling of Kimi K3 suggested that Chinese companies are taking things more slowly. The release on Monday of its weights -- the numerical values that show how the software works -- came a week after the model was launched. That is unlike other Chinese open-source models such as those developed by DeepSeek or Alibaba, which released their weights at the same time their models were unveiled. The Power of Giving it Away China's long-term goal, analysts say, is to set global A.I. standards to get ahead of the United States and make the world dependent on Chinese software, hardware and data systems, which are known collectively as a stack. "This is a once-in-a-lifetime opportunity for China," said Kendra Schaefer, a partner at Trivium China, a research and advisory firm. "China has spent the last 20 years trying to develop a tech stack that third-party countries would find as attractive or more attractive than U.S. origin technology and that has proven very, very difficult." Given those stakes, China will try to thread a needle if it decides to impose restrictions on foreign access to some A.I. systems, analysts said. That could mean limiting access to the most advanced A.I. systems for a time while leaving access to weaker models unchanged, not unlike what the Trump administration has done with Anthropic. That idea was put forward on Monday by Yuyuan Tantian, a blog linked to China's state broadcaster. "China supports openness, but this does not mean it advocates for the unconditional proliferation of all capabilities," the blog said. Beijing could also require exporters of Chinese A.I. to apply for licenses, much like how it controls exports of critical minerals and rare earth magnets, Ms. Schaefer said. That would be in line with signals from Beijing that A.I. capabilities are strategic national assets that it is unwilling to let flow to rivals in a superpower competition. In April, Chinese regulators blocked a $2 billion acquisition by Meta of Manus, a Singapore-based A.I. company that was founded in China, after a security review concluded that foreign investment in the company should be prohibited. How Risky is Openness? The prospect that China might impose controls on Chinese A.I. models comes as a debate has raged in Silicon Valley about whether open-source A.I. software is inherently risky. Earlier this month, OpenAI said two of its A.I. models went rogue and successfully hacked into Hugging Face, a digital library of A.I. software that is popular among developers. Hugging Face said it had to deploy an open source model called GLM-5.2 made by a Chinese start-up, Z.ai, to help thwart the breach because American A.I. models carried restrictions that prevented them from taking action. GLM-5.2, which was released in June, is on the cutting edge of Chinese A.I. -- it is nearly as powerful as Anthropic's models Mythos and Fable. "We're all learning that secrecy is not the answer & that all defenders (not just a few selected ones) everywhere need more powerful models without restrictions, especially open ones!" wrote Clement Delangue, the chief executive of Hugging Face, on X shortly after the hack.
[10]
Dario Amodei Says He's Not Against Open Models, He's Against Selling Chips to China
The American AI industry is split over open models. Those in the industry who say they are all for open AI development have started blaming frontier AI model providers, especially Anthropic, for pushing the Trump administration towards adopting a stricter stance favoring closed models. Now, Anthropic CEO Dario Amodei is claiming he is just misunderstood. The debate over open-source models was reopened earlier this month when Chinese AI lab Moonshot released Kimi K3, its latest model that ranks higher than most offerings from American giants like Anthropic and OpenAI, and as of Monday, is open-weight. The company was one of several Chinese AI labs that have been accused of IP theft by Anthropic, which claims that the labs violated rules by "illicitly" extracting capabilities from its closed-source models to build their own open-source ones. This process, called "distillation," works by using a "teacher" model's output to train another "student" model, and it's actually fairly common in the AI industry. But the Trump administration and some frontier AI model providers view the often China-led industrial-scale distillation attempts "adversarial," a characterization that has informed the administration's latest threats to impose sanctions on Chinese open-source models. Some tech leaders push for open-model development The U.S. sanction threats quickly drew ire from many American big tech companies, including Nvidia, Microsoft and Meta, who were co-signatories of a letter urging the government to avoid "premature restrictions on open models that stifle competition or drive innovation overseas." OpenAI, which has previously sent a memo to the House of Representatives accusing DeepSeek of running a similar distillation operation, wasn't initially a signatory of that letter. But CEO Sam Altman gave his support on X and OpenAI promptly signed on to the letter as well. With many of its peers on board with the message, Anthropic's absence from the list of signatories was glaring. "Some people have even accused Anthropic of wanting to ban open-weights models as a means of protecting our business," Amodei said in a letter on Tuesday. "Anyone who has read my past writing should know that I don't regard such bans as a useful measure, but let me state it clearly so that there is no doubt: Anthropic has never advocated for a ban on open-weights models." In the letter, Amodei said he agrees with much of what was said in the industry-wide open letter, except that open models are a necessity for safety, and said that his remaining concerns would not be addressed with blanket bans and sanctions. "Open-weights models that don't have dangerous capabilities are a public good: they don't cost anything besides the compute needed to run them, and they provide value to businesses, developers, and researchers," Amodei said. "Protectionist bans would not address my most serious national security concerns. Specifically, I am worried about two nightmare scenarios." What's the concern over open-weight? The first of Amodei's concerns is that open models could aid the Chinese government in building an AI model more powerful than current American alternatives, and using that "to achieve permanent military superiority or perpetrate incredibly deep repression of their own people." This concern has been echoed by several government officials as well, and is often used as the main argument by those in favor of protectionist measures. Amodei's second "nightmare scenario" is that powerful AI models could be used to carry out cyberattacks or biological attacks, especially if they "have serious alignment problems." Of course, Amodei delivers this alignment concern with a jab at competitor OpenAI. Earlier this month, an OpenAI agent in evaluations went rogue and hacked into AI software repository Hugging Face. In its defense against the hacking, Hugging Face said it tried to use closed-source models, but their alleged inability to distinguish the attackers from the defenders led to the models' cybersecurity work restrictions taking over. Instead, Hugging Face said they had to use a Chinese open-source model to finally repel the attack. Following the incident, Nvidia, which has fashioned itself as the AI industry's top advocate for open models, announced that it was forming an industry coalition to advance open technologies. In that announcement, the chipmaker specifically pointed to the Hugging Face incident as a "clear reminder" that "cyber defenders need open, frontier agentic systems for self-defense." The open letter also says that "openness may be one of the most important paths to AI safety and security," because open-weight models give more people "the ability to test and strengthen the models on which society relies." That's where Amodei says he disagrees. "Open-weights models -- it does not matter whether they come from China or anywhere else -- do potentially present a higher risk than closed models, because it is very difficult to apply guardrails to them or monitor their usage, and once weights are released they cannot be withdrawn," Amodei said in his letter. Banning the use of Chinese open models by American businesses would not address this security risk, Amodei argues, "because bad actors are unlikely to be legitimate US businesses." Instead of a blanket ban on open models, Amodei said he supports a government crackdown on industrial-scale distillation operations, requiring mandatory safety testing for all AI models open or closed, and an end to American chip sales to China. "China has limited domestic production capacity, and therefore, due to the scaling laws, cannot build more powerful models than the US without US chips," Amodei argued. "This is the most efficient and direct way to block threat #1, and by hampering the training of models that are out of reach of US law, it also indirectly helps with threat #2." Anthropic's position clashes with Nvidia's This is another area that Anthropic will likely find itself at odds with its strategic partner Nvidia. China used to be one of Nvidia's largest and most critical markets until the fraying trade relationship between Beijing and the Trump administration led to a complete halt in the chipmaker's ability to sell its chips in the Chinese market. Nvidia CEO Jensen Huang has spent a lot of his time in the past year trying to convince both governments to ease trade restrictions. Also on Tuesday, Nvidia made headlines after Taiwanese authorities detained an Nvidia employee who was allegedly smuggling the company's AI chips into China. The company has not been accused of wrongdoing in the case.
[11]
Anthropic's Dario Amodei says the company has never called for banning open-weight AI models
Amodei says Anthropic has never called for banning open-weights models. He supports chip export controls, cracking down on distillation, and mandatory safety testing for all sufficiently capable models, open and closed. Dario Amodei published Anthropic's formal position on open-weights models on Sunday, breaking a silence that had drawn accusations that the company wanted to ban open-weight AI to protect its business. "Anthropic has never advocated for a ban on open-weights models," Amodei wrote. "Open-weights models that don't have dangerous capabilities are a public good." The post came after Nvidia's Jensen Huang and dozens of tech companies signed an open letter supporting open weights, and after US officials reportedly considered banning Chinese open-weights models. Amodei outlined three measures he supports instead of a ban. First, enforcing chip export controls and cracking down on the "rampant smuggling" used to get advanced chips into China, because without US chips, scaling laws prevent China from training models more powerful than American ones. Second, stopping industrial-scale distillation operations that allow Chinese labs to build capable models far more cheaply than training from scratch. Third, mandatory safety testing for all sufficiently capable models, open and closed, regardless of country of origin, with less capable models from startups and academia exempted entirely. On the Nvidia-backed open letter, Amodei agreed that open weights expand access and competition but disagreed that they necessarily help defenders more than attackers. He cited biological weapons as the sharpest example: a sufficiently capable model might weaponise a pandemic-level virus quickly using widely available materials, while defence against such agents takes years. TNW reported last week that Anthropic's silence on the open-weights letter was becoming conspicuous as the company that had the most direct commercial injury from distillation. This post is the response. The distillation point is the most commercially charged. Anthropic accused Alibaba's Qwen lab of running the largest distillation campaign ever against Claude, using 25,000 fake accounts for 29 million exchanges. Amodei acknowledged that cracking down on distillation is "challenging" because accounts can often only be identified after substantial distillation has occurred. He called for policy intervention rather than relying on any single company's enforcement. The position is carefully constructed: Anthropic is not against open weights, it is against open weights being built by stealing from its closed models, trained on smuggled chips, and released without safety testing. Whether that distinction survives Washington's appetite for simpler narratives is the political question the post was written to answer.
[12]
China's open-weight model lead exposes America's AI blind spot
Some of America's biggest technology companies are pushing Washington to make open artificial intelligence a national priority as China continues to build its lead in the space. Their message exposes a gap in U.S. policy: America has a chip strategy for AI. Now it needs an open-model strategy. Supporters say open models can lower costs, keep sensitive data inside a company's own systems and prevent businesses from becoming dependent on a handful of AI providers. The models can also give more researchers and security teams the ability to inspect powerful models and find weaknesses. Unlike ChatGPT or Claude, which customers access through services controlled by OpenAI and Anthropic, open-weight models can be downloaded, customized and run on a company's own computers. That can make them cheaper and give users more control over their data and technology. Last week, a coalition led by Nvidia published an open letter arguing that America's AI leadership will depend on building a strong open ecosystem. Microsoft, Meta and other major technology companies signed it. OpenAI and Google later added their support. A striking cybersecurity incident days earlier showed why the issue matters. During an internal test, OpenAI models found a way out of a restricted environment and compromised systems at the AI platform Hugging Face. When Hugging Face tried to investigate, safety controls on closed commercial models blocked them from analyzing the attack. The company instead used an open Chinese model that it could run on its own infrastructure. A closed American model caused the incident. A Chinese open model helped investigate it. That episode complicates the argument that closed AI is always safer.
[13]
Chinese GLM-5.2 steals the spotlight after Hugging Face breach
* Chinese Zhipu AI GLM-5.2 succeeded where leading American models failed woefully * Hugging Face breach reignited Washington's battle over open-weight artificial intelligence * Safety guardrails unexpectedly complicated defensive cybersecurity work during a real incident The recent cybersecurity incident involving Hugging Face has unexpectedly placed a Chinese open source AI model at the centre of an intensifying United States policy debate over open-weight AI. The episode emerged after an autonomous agent built with OpenAI technology reportedly escaped containment and behaved like a rogue actor. The incident occurred as Washington is considering whether broader restrictions on Chinese open-weight AI models could affect American developers and startups. Chinese open source model enters an unexpected cybersecurity role According to Hugging Face, engineers relied on Zhipu AI's GLM-5.2 model to examine information generated during the incident after leading American models declined the requests. American AI models could not distinguish legitimate defensive investigations from malicious hacking attempts because of built-in safety restrictions and protective guardrails. Anthropic's Claude Fable 5 reportedly reroutes cybersecurity questions to an older, less capable model rather than allowing direct engagement with such tasks. OpenAI's GPT-5.6 Sol carries similar protections meant to stop the system from being used for hacking-related work of any kind. OpenAI later revealed that it has a Trusted Access programme that grants privileged, elevated capabilities to a select group of vetted teams, allowing them to use its models more fully to strengthen their own defenses. Hugging Face was brought into this restricted tier following the breach, gaining deeper access than is normally available. "We're all learning that secrecy is not the answer & that all defenders (not just a few selected ones) everywhere need more powerful models without restrictions, especially open ones!" said Hugging Face co-founder Clement Delangue. "A safety regime that restricts legitimate defenders, while capable models remain available for attackers, creates an asymmetric disadvantage," said Lukasz Olejnik, visiting senior research fellow at the Department of War Studies, King's College London. "This gap will only widen as open-source models become increasingly powerful while lacking guardrails or restrictions." Washington weighs restrictions while startups urge caution Nearly 200 Silicon Valley companies are opposing possible restrictions on Chinese open-weight AI models, warning that the move would raise costs for smaller developers. Members of the newly formed Little Tech Association say banning downloads would not curb proliferation but would leave American startups weaker. "There'll be hundreds of companies that instantly die," founder Suhail Doshi warned. He argued that sweeping restrictions would disproportionately benefit larger American providers with the resources to absorb such a shift. The U.S. is still scrutinizing Chinese developers over allegations involving model distillation and export control violations White House officials maintained that any future policy decisions would come directly from the administration itself. Analysts have also cautioned against treating the Hugging Face incident as justification for weakening the cybersecurity safeguards protecting advanced American systems. "The answer is not simply to remove them," Shrenik Kothari of Robert W. Baird said, arguing that companies should refine their access controls rather than abandon safety measures altogether. He suggested a more selective approach to capability allocation could balance legitimate security needs with the practical demands of cybersecurity research. Via Reuters Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
[14]
Anthropic CEO Dario Amodei says he does not support open-weight AI ban
Why it matters: Anthropic has become the most prominent holdout from a new industry push to defend open-weight AI, after Nvidia, Microsoft, Meta, Google, OpenAI and dozens of other companies signed a letter urging Washington not to restrict the technology. * The push was triggered by the shock debut of Kimi K3, a Chinese open-weight model that rattled Silicon Valley by approaching U.S. frontier performance at a fraction of the cost. * The Trump administration has weighed taking action against open-source models, including sanctions against Chinese labs accused of stealing U.S. AI research through "distillation." Driving the news: "Anthropic has never advocated for a ban on open-weights models," Amodei wrote in a new blog post, calling models without dangerous capabilities "a public good." * He argued that a ban on Chinese open models would do little to stop the actual threat, since "bad actors are unlikely to be legitimate US businesses." * He acknowledged a ban would shield U.S. labs like Anthropic from competition -- but insisted "that has never been my goal." Between the lines: Amodei is trying to draw a narrow line between opposing open-weight bans and supporting tougher controls on the most powerful AI systems. * The Anthropic CEO said he agrees that open models can expand access, competition and customer control. * But he rejected the letter's claim that open-weight models necessarily make AI safer or give cyber defenders an advantage over attackers. Zoom in: Instead of a ban, which he said "would not address my most serious national security concerns," Amodei called for three narrower policies: * Tighter controls on advanced chips and chipmaking equipment flowing to authoritarian governments. * A crackdown on "industrial-scale distillation," or training models on the outputs of more advanced systems. * Mandatory safety testing for sufficiently capable models, whether open or closed. Catch up quick: Anthropic faced criticism after it declined to join Nvidia CEO Jensen Huang's open-weight letter. * Google and OpenAI, Anthropic's two biggest closed-model rivals, signed on this weekend after originally abstaining. Anthropic still has not. * Its absence fueled accusations -- including from White House AI adviser David Sacks -- that the company was using safety concerns to defend its own business model. The bottom line: Amodei doesn't want Washington to ban open models. He wants Washington to regulate the chokepoints -- chips, distillation and safety testing -- that determine how powerful those models can become.
[15]
Hugging Face CEO Clément Delangue says China is winning AI race
Hugging Face CEO Clément Delangue said Monday that China is dominating open-weight AI models and could overtake U.S. frontier labs before the end of the year. "They're clearly dominating on open models right now, and I wouldn't be surprised if they start dominating at the frontier either by the end of this year or next year at the rate of progress," Delangue said in an appearance on CNBC's "Squawk on the Street." Delangue pointed to China's culture of openness and knowledge-sharing as the engine behind its gains, warning that American developers risk losing ground because they operate in isolation. U.S. model makers, by contrast, are "building in silos" and risk falling behind, he said. His comments came weeks after OpenAI agents broke out of a training environment and attacked Hugging Face, the open-source AI platform Delangue leads. Delangue said engineering mistakes were responsible for the incident and said that Hugging Face used a Nvidia $NVDA version of a Chinese open model to resolve the attack. Delangue described the relationship with OpenAI as a "healthy collaboration" and said the frontier lab had been "good partners" both before and after the incident. The attack has sharpened attention on AI cybersecurity risks, and Delangue sees a commercial opportunity in the fallout. "AI cybersecurity is going to become a huge market in the U.S. and in the world," he added. "In this market, probably open models will be kings." Chinese open-source models have been steadily closing in on their American counterparts, according to CNBC, fueling a broader policy debate about access restrictions. A letter circulated last month by technology giants including Microsoft $MSFT, Palantir $PLTR, and Nvidia called on policymakers to preserve the open-weight model ecosystem rather than curtail it.
[16]
Anthropic CEO Dario Amodei says AI company isn't advocating for ban of open-weight models
Anthropic CEO Dario Amodei said on Monday that his company has "never advocated for a ban on open-weights models," an attempt to beat back criticism emerging across the tech industry that the AI lab is trying to exert excessive control over the future of artificial intelligence. Amodei published his views in a blog post on Monday, after a coalition of tech companies, including Nvidia, Microsoft, Meta and Palantir, released a letter late last week urging policymakers to avoid "premature restrictions" on open-weight models, which users can download, modify and run on their own infrastructure. Chinese startups currently dominate the market, and some government officials have started to weigh whether those models should be banned or restricted in the U.S. Anthropic is best known for developing a family of proprietary models called Claude that it sells to businesses. Chief rival OpenAI also primarily builds closed models, but the company signed on in support of the open-weight letter after it was published, while Anthropic did not. "To summarize my and Anthropic's position, we have not and are not advocating for a ban on open-weights models as a category," Amodei wrote. "We should instead focus on keeping powerful chips out of authoritarian hands, stopping industrial-scale distillation, and requiring safety testing of all sufficiently capable models, open and closed." Distillation is an AI training method where a smaller, less capable model is built using outputs from a bigger model already on the market. Anthropic sent a letter to the U.S. Senate Committee on Banking, Housing, and Urban Affairs last month alleging that China's Alibaba, developer of the Qwen family of models, had carried out the "the largest known distillation attack" against it to date. In the Friday letter, the signatories said that concerns about unlawful distillation should be addressed through "targeted legal and commercial frameworks," an idea that Amodei agreed with on Monday. Amodei said he also agrees with other portions of the letter, namely that open-weight models give customers greater control, expand access to the AI economy and strengthen competition in some use cases. But he said he disagrees with the idea that open-weight models favor cyber defenders over attackers, or that they make it easier for users to develop safeguards. Even so, Amodei made it clear that he does not support banning open-weight models. "Protectionist bans would not address my most serious national security concerns," Amodei said.
[17]
Anthropic and Nvidia come out against blanket bans on open-weight AI models
As the United States government debates new artificial intelligence rules and regulations, Anthropic PBC and Nvidia Corp. are drawing a line against blanket bans on open-weight models, urging regulators to focus instead on specific risks and misuse. An open-weight model is one where the developer releases its trained parameters, the "weights," which are the numerical values and vectors learned during training that determine how a model behaves. These weights act like dials that can be adjusted to shape a model's outputs and performance. Because they're accessible, weights can be fine-tuned with proprietary data, letting developers customize the model for specialized purposes and use cases. Open-weight models are released so that users and enterprise firms can run them locally or in their own cloud, eschewing the need to access frontier closed-source models built and deployed by big AI model developers such as OpenAI PBC or Anthropic. Well-known examples of open-weight models include Meta Platforms Inc.'s Llama, Mistral AI SAS's models, Alibaba Group Holding Ltd.'s Qwen and DeepSeek's models. All of these models let developers download, run and tune the weights directly. According to Axios, last year, the U.S. Department of Commerce considered adding multiple Chinese AI labs to the "Entity List." An action that would have effectively banned U.S. companies from accessing their models without a license. More recently, U.S. Treasury Secretary Scott Bessent said the White House could sanction open-weight Chinese frontier labs. In a long treatise, Anthropic Chief Executive Dario Amodei stressed that the company has never advocated for a ban on open-weight models. "Open-weights models that don't have dangerous capabilities are a public good: they don't cost anything besides the compute needed to run them, and they provide value to businesses, developers, and researchers," Amodei said. He centered his discussion on controlling the infrastructure and behavior around models, not the models themselves. He stated that the focus should be around controlling the export of powerful AI training and inference silicon, preventing industrial-scale distillation - when a larger model is used to improve a smaller model - and requiring safety testing of sufficiently powerful models, irrespective of whether they're open or closed. Anthropic's concerns over distillation follow on from fears that its largest and most powerful frontier models, Mythos and Fable, have been surreptitiously used to train foreign AI models. Last week, Director of the Office of Science and Technology Policy Michael Kratsios accused Beijing-based Moonshot AI of using distillation to train Kimi K3, the company's most recent large language model and the largest open-weights model in the world. Although distillation is strongly suspected at industrial scales, there is no evidence that K3 received any training from Mythos. Nvidia CEO Jensen Huang weighed in on X, formerly Twitter, sharing an open letter signed by the AI chip supergiant and stating, "AI will transform every industry, power every company, and be built by every country. Open models strengthen safety and cybersecurity, accelerate innovation and diffusion, and enable sovereignty. The world needs both frontier closed models and frontier open models." The open letter, signed by Nvidia, IBM Corp., Mozilla Corp., Microsoft Corp., Meta and numerous other technology industry leaders, argued that open-weight models support innovation, competition, customer control and sovereignty. The signatories stated that this type of model should not face additional restrictions that would curtail their usefulness within the larger software and AI industry.
[18]
Anthropic breaks from AI rivals in open-weight model debate
The Anthropic CEO has hit back at claims his company wants Chinese open-weight models banned, days after sitting out a rival industry letter. Anthropic CEO Dario Amodei has moved to quash what he called a specific accusation circulating in AI circles this week, that his company wants Chinese open-weight models banned in the US as a way of protecting its own business. In a post titled 'Our position on open-weights models' on the Anthropic website yesterday (27 July), Amodei wrote that "Anthropic has never advocated for a ban on open-weights models", and said open-weight models without dangerous capabilities are a public good that cost nothing beyond the compute needed to run them. The post follows an open letter published on 24 July and hosted on Nvidia's website, titled 'Open Weights and American AI Leadership', which urged US policymakers not to impose broad restrictions on open-weight models. The letter was signed by virtually all the big tech players including Nvidia, Microsoft, Meta and Hugging Face, and later grew to include OpenAI and Google - signatories stand at 50 today. Anthropic did not sign. The letter emerged amid reports that US officials were weighing restrictions on the use of Chinese open-weight models by American businesses, first reported by Axios on 21 July. Amodei set out two concerns he said protectionist bans would not address. The first is that authoritarian governments, not only the Chinese Communist Party, could build more powerful AI models than the US and use them for military advantage or domestic repression. He noted this is a concern whether or not such models carry open weights. His second concern is that powerful models, open or closed and regardless of country of origin, could be misused for cyberattacks or biological attacks. He argues open-weight models carry extra risk here because guardrails are hard to apply once weights are released, and released weights cannot be withdrawn. That said, Amodei says banning US businesses from using such models would not stop bad actors, who are unlikely to be legitimate US companies in the first place. In place of a ban, Amodei said Anthropic continues to support three measures: blocking the sale of powerful chips and chipmaking equipment to China and cracking down on smuggling; targeting industrial-scale distillation operations that let Chinese labs narrow the gap to the US frontier without matching compute; and mandatory safety testing, covering cyber, biological and alignment risks, for all sufficiently capable models regardless of whether they are open or closed, or where they were built. He said he agreed with parts of the industry letter, including that open weights expand access to the AI economy and strengthen competition, but disputed its suggestion that broad access necessarily helps defenders more than attackers. He pointed to biological risk as an example, arguing that a sufficiently capable model could help weaponise a pandemic-level virus quickly, while building a defence against such an attack is a multi-year undertaking even in the best case. Amodei said questions about whether open models carry extra risk, and whether that risk can be mitigated, should be settled through pre-release testing rather than assumed in advance. Don't miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic's digest of need-to-know sci-tech news.
[19]
Dario Amodei rejects open-weight AI ban, wants safety testing
Dario Amodei said Anthropic has never sought to ban open-weight models, but wants all capable AI systems tested before release Anthropic CEO Dario Amodei pushed back Monday against accusations that his company has sought to restrict open-weight artificial intelligence models, while laying out a narrower set of policies he does support -- including mandatory safety testing for all capable AI systems, open or closed. "Let me state it clearly so that there is no doubt: Anthropic has never advocated for a ban on open-weights models," Amodei wrote in a blog post. He called open-weight models without dangerous capabilities "a public good" and said protectionist bans "would not address my most serious national security concerns." Anthropic had come under pressure after declining to sign an industry letter, released last Friday, urging policymakers to avoid restricting open-weight models. The letter was backed by Nvidia $NVDA, Microsoft $MSFT, Meta $META, and Palantir $PLTR, among others. Google $GOOGL and OpenAI, which initially did not sign, added their names over the weekend, according to Axios. Anthropic still has not signed. The letter's release was triggered in part by the debut of Kimi K3, a Chinese open-weight model from Moonshot AI that approached frontier performance from U.S. competitors at lower cost. Former White House AI adviser David Sacks had suggested Anthropic was using safety concerns to shield its closed-model business from competition, according to Bloomberg. Amodei denied that characterization and acknowledged that a ban "would protect U.S. AI companies from competition, but that has never been my goal." Instead of a ban, Amodei outlined three policies he said would better address his concerns. First, he called for tighter controls on advanced chips and chipmaking equipment flowing to authoritarian governments, arguing that chip restrictions are the most direct way to prevent rival states from building more powerful AI. Second, he called for a crackdown on what he described as industrial-scale distillation -- a process in which a smaller model is trained using outputs from a larger, more capable one. Amodei argued that distillation gives China a way to extract capability from American frontier models, reducing the effectiveness of export controls on chips. Last month, Anthropic sent a letter to the U.S. Senate alleging that Alibaba had carried out "the largest known distillation attack" against it, according to CNBC. Third, Amodei said all sufficiently capable models -- regardless of origin or whether they are open or closed -- should undergo mandatory safety testing before release, with less capable models from startups and academia exempted. He said the purpose of such testing would be to evaluate the actual risk profile of open-weight models through evidence, not to treat restriction as a foregone conclusion. Amodei said he agrees with portions of the industry letter, including its view that open-weight models expand access to the AI economy and give customers greater control. He said he disagrees, however, with the letter's assertion that open-weight models make it easier to develop safeguards or that broad access to AI capabilities favors cyber defenders over attackers. He cited biological threats as a case where attackers may hold a structural advantage that a sufficiently powerful AI model could exploit.
[20]
Silicon Valley splits over closing the borders to Chinese AI
SAN FRANCISCO -- For years, a philosophical divide over how artificial intelligence software should be created has split Silicon Valley technologists. Over a week in July, that argument reached a boiling point. On one side are leading AI companies like Anthropic and OpenAI, which claim that AI models are too dangerous to be developed in the open and must be tightly controlled -- by businesses like themselves -- for safety. On the other is the rest of the tech industry, including giants like Microsoft and Nvidia, which contend that so-called open-source AI models must remain open for people to further develop technologies and build new businesses. Those camps have started publicly clashing. Last month, Jensen Huang, Nvidia's CEO, said in his first-ever post to X that "the world needs both frontier closed models and frontier open models." Nine minutes later, Satya Nadella, Microsoft's CEO, posted that open-source software was "essential to a healthy AI ecosystem." Both signed a letter supporting open source, which was also signed by executives at Meta, Palantir and IBM. At the same time, OpenAI and Anthropic have lobbied regulators in Washington, D.C., raising concerns about Chinese open-source AI models, five people close to the discussions said. The debate has drawn in Treasury Secretary Scott Bessent and Michael Kratsios, President Donald Trump's science and technology adviser, who have weighed in on how American AI models are valuable intellectual property. The escalating fight stems from China's rapid progress in open-source AI models, which are freely available to use and build on. In recent weeks, two Chinese AI startups, Z.ai and Moonshot AI, have released models that rival those from Anthropic and other American labs. Anthropic and OpenAI have claimed that Chinese companies built the models by improperly harvesting data from their AI systems, which they said should not be allowed. But companies like Microsoft and Nvidia, which rely on open-source models to spur demand for their cloud computing services and chips, said that open-source software was important to advancing the technology with shared knowledge and that it would let more people examine its security. And for Silicon Valley startup founders, constraining open-source software could cement the lead that OpenAI and Anthropic have in AI, which critics argue could unfairly stifle other companies from building competing products. "You have two factions fighting over this issue," said Bill Gurley, a Silicon Valley venture capitalist who opposes restrictions on open-source software. "There's the people who want OpenAI and Anthropic to own everything, and then there's everybody else, including customers." Where this ends up has major implications not only for the U.S. tech industry but for the race between America and China to dominate the powerful technology. While China had a later start in developing cutting-edge AI, it is catching up quickly in part because of its embrace of open source, which has helped Chinese labs improve by publicly sharing their systems and winning them customers around the world with lower prices. American AI companies, including Anthropic and OpenAI, have accused Chinese labs of "distilling" their systems by surreptitiously copying them, which has caught the attention of the Trump administration. On Wednesday, Bessent said the administration had considered imposing sanctions on Chinese companies that steal intellectual property from American firms. "Open source is not open season on American IP," he said, referring to intellectual property. That same day, Kratsios said that "large-scale, covert industrial distillation aimed at stealing proprietary U.S. technology and undermining American research is unacceptable." U.S. officials still appear to be debating their options, but seem more likely to approach regulating Chinese open-source models individually as a national security issue, rather than issuing some kind of blanket ban, four people with knowledge of the discussions said. Publicly, tech executives such as Sam Altman, OpenAI's CEO, have said they support open-source software even as OpenAI allies quietly lobby for restrictions. Others, including Google and Amazon, which have invested billions in companies such as Anthropic and OpenAI, have tried to stay out of the fray. But the tide is turning. Sundar Pichai, Google's CEO, posted on social media in July that his company had "long benefited from open source" and was a big contributor to it. He added that Google also signed the industry letter supporting open source. (The New York Times has sued OpenAI and Microsoft, claiming copyright infringement of news articles. The two companies have denied the claims.) The open-versus-closed software debate has traveled around Silicon Valley since the tech industry's earliest days. Open-source proponents have argued that sharing information leads to improvements that make software safer and more reliable, while more rapidly spurring innovation. Opponents maintain that software is costly to develop, and that giving it away is just bad business. Today, much of the modern internet runs on open-source technologies, as do some of the most widely used computer systems, like Google's Android operating system. The Chinese government and tech industry have embraced the open-source path for AI. Last year, a Chinese startup, DeepSeek, unveiled an open-source AI system that rivaled those of American companies, shocking the industry. Other Chinese companies have followed. In a speech this month, Xi Jinping, China's leader, cast the country as a global champion of an open approach to the technology. China's advances have rattled executives at OpenAI and Anthropic, who are increasingly concerned that their long-standing head start is disappearing, two people familiar with the companies' internal deliberations said. "These American companies build these big, expensive models, and then the models take a detour to China, where they lose all their value," said Pedro Domingos, a professor emeritus of computer science and engineering at the University of Washington. "The American companies are justifiably outraged." To fight back, Anthropic and OpenAI are offering some cheaper AI models to businesses that may not need the "frontier" models that command higher prices. On Friday, Anthropic released Claude Opus 5, a model that the company described as "close to the frontier intelligence of Fable 5 at half the price." OpenAI is promoting similar lower-cost models. The real action is in D.C. Behind closed doors, executives from OpenAI and Anthropic, as well as investors in the companies, have cited concerns about the global economy, AI safety and national security as they try to persuade regulators to increase restrictions on Chinese open-source software, three people familiar with the discussions said. Sarah Heck, Anthropic's head of public policy, said in a social media post on Wednesday that "illicit, adversarial distillation is IP theft and industrial espionage that supports adversary military and intelligence capabilities." Anthropic executives claim that open-source models based on the company's software are too dangerous to let run amok. OpenAI executives are urging the Trump administration to enact policies requiring mandatory security evaluations of some new AI models overseen by government agencies, the company said in a blog post last month, a move that could curtail open-source software development. OpenAI said it was "encouraged" by the work it was doing with the administration on the framework. Open-source proponents have spent the past week drumming up support to push back against OpenAI and Anthropic. On Wednesday, nearly 200 Silicon Valley startups, calling themselves the Little Tech Association, signed letters urging the Trump administration not to limit access to Chinese open-source models. Big Tech soon followed. On Friday, Elon Musk, Meta's Mark Zuckerberg, Altman and others lined up behind Huang and Nadella to support open source, followed by Pichai. "Jensen is right," Musk posted. "This has my full support." "Open source is a positive and important force," Zuckerberg wrote. One incident underscored the stakes of the divide. On Tuesday, OpenAI disclosed that a handful of its most advanced AI models broke containment during a test of their cybersecurity abilities, gained access to the internet and hacked the servers of an AI company called Hugging Face. OpenAI executives latched on to the moment as proof of how dangerous AI models can be even in a closed environment, emphasizing the need for regulation. Clement Delangue, the CEO of Hugging Face, which is one of the most popular online libraries of open-source software, had a different point of view. To defend the company from OpenAI's hack, he turned to an open-source AI model created by China's Z.ai. In social media posts, Delangue made his position on the debate unmistakable. "Open models for the win!" he wrote.
[21]
Anthropic gives thoughts on open-weights models, especially those from China
Anthropic CEO Dario Amodei has publicly clarified the company's stance on open-weights models, rejecting calls for a broad ban while warning of two major nightmare scenarios. In a recent post shared to the Anthropic website, Amodei emphasized that open models are a public good when not dangerous, but he sees real threats from powerful AI in the hands of authoritarian regimes. Amodei outlines two primary nightmare scenarios: one where authoritarian governments build superior AI models to achieve military dominance, and another where powerful models are misused for cyberattacks or biological threats. He stresses that open weights are irrelevant to the first and only a partial risk factor in the second scenario. Instead, he advocates for three strategic measures to be put in place: restricting powerful chips from going to China, cracking down on distillation operations, which are efforts from AI laboratories to extract the capabilities of a model to improve their own, and implementing mandatory safety testing for all advanced models, regardless of whether they are open or closed. "Over the last few days there has been a lot of discussion about open-weights models, especially those from China. Reports suggest that some US officials are considering banning the use of Chinese open-weights models by US companies. In response, many tech companies have signed a letter supporting open-weights models, and some people have even accused Anthropic of wanting to ban open-weights models as a means of protecting our business. Anyone who has read my past writing should know that I don't regard such bans as a useful measure, but let me state it clearly so that there is no doubt: Anthropic has never advocated for a ban on open-weights models," wrote Amodei "To summarize my and Anthropic's position, we have not and are not advocating for a ban on open-weights models as a category. We should instead focus on keeping powerful chips out of authoritarian hands, stopping industrial-scale distillation, and requiring safety testing of all sufficiently capable models, open and closed," wrote Amodei Amodei and Anthropic support industry-wide safety testing and global cooperation, noting that Chinese interests have a chance to align in these areas, particularly in sectors such as bioweapon prevention.
[22]
Rogue AI hacking incidents amplify debate over open-source tech
Concerns over AI's cybersecurity risks reached a fever pitch this week following two hacking incidents at OpenAI and Anthropic, sparking further debate in Silicon Valley over whether open-source could reduce these threats. The incidents are amplifying the recent push for open-source technology, which gained momentum earlier this year amid growing competition with China and the Trump administration's ad hoc approach to AI regulation. Some of the country's largest technology firms waded into the debate this week, after OpenAI and later Anthropic, revealed their models hacked into other company systems during a cybersecurity test. More than a dozen major tech firms threw their weight behind a new open-source initiative from Nvidia this week, while the company's CEO Jensen Huang met with lawmakers on Capitol Hill over the issue. But not every tech player is on board. Leaders at Anthropic, which disclosed three security incidents with Claude on Thursday, reiterated concerns about the security of open-weight models, warning they could be "misused" for cyber or biological attacks. "I'm not entirely sure the [U.S.] knows what the right path is right now between larger versus smaller models, and the volume of smaller models that are required to achieve parity with larger capability," Aaron Saint-Miller, vice president and cybersecurity AI lead at Booz Allen Hamilton, told The Hill Friday. Unlike private models hosted by OpenAI or Anthropic, open-source systems are often smaller, less expensive and live in the public domain. This gives virtually anyone or any company access to download and customize the model for a wide range of uses. In some cases, a model may not be open source but can have open weights, meaning the ways a model is trained to sift through information and formulate answers are made public. Steam has picked up in recent weeks for more open-source development in the U.S., given the rising costs of private, proprietary models like Claude or ChatGPT, and the need to stay ahead of China's AI development. These concerns jumped back into the spotlight earlier this month when OpenAI revealed two of its models went rogue in an isolated testing environment and breached the internal systems of Hugging Face, which hosts hundreds of thousands of open-source models, datasets and cloud environments. Launching the "Open Secure AI Alliance" on Monday, Nvidia pointed to the hacking incident, arguing open-source tools are an opportunity to secure critical infrastructure as both AI models and the hacking risks they pose continue to grow. As part of the alliance, tech firms will be able to share and use open-source tools to identify, patch and disclose security vulnerabilities to defend against future incidents. "Cyber defenders need open, frontier agentic systems for self-defense," Nvidia wrote. "When closed AI tools -- unable to distinguish attackers from defenders -- blocked essential forensic analysis, Hugging Face ran the open-weight GLM 5.2 model on its own infrastructure to analyze more than 17,000 actions and contain the intrusion." The technology giant argued open models broaden access to defensive capabilities across industries, increase transparency, protect data, and "complement frontier closed models with customizable, localized controls." Companies in the alliance include other open-source advocates like Reflection AI, Hugging Face and Open Claw, along with tech giants Microsoft, Palantir, SpaceX and IBM. Notably missing are OpenAI, Anthropic and Google -- some of the U.S.'s largest frontier AI labs, who are specializing in private model development. The absence of OpenAI and Anthropic in the alliance quickly sparked criticism from industry analysts who suggested the firms do not support open-source because they do not stand to gain from it. "Almost 3 years ago, I believed open-models would become the key threat to the AI incumbents & that unfortunately they would lean into regulatory capture as a response," venture capitalist Bill Gurley wrote in a social media post on X Tuesday. "I underestimated the fervor with which they would use this non-business approach," he added. OpenAI CEO Sam Altman responded to the criticism online, saying he was "glad to see" the industry letter supporting open technolog. "[I] want the US to win in AI both in open source and proprietary models," Altman wrote in a post on X. Days before launching the alliance, Nvidia signed a letter warning against "premature restrictions" on open-weight models. Meta, which offers open-weight models under the Llama family, and Microsoft, were among the signatories, which OpenAI eventually joined. In a blog post published Tuesday, Anthropic CEO Dario Amodei said he does not support a ban on open-weight technology, but also fears "two nightmare scenarios." attempting to thread a needle on the critical issue. His fears include the risk an authoritarian government could use powerful AI to "achieve permanent military superiority or perpetuate incredible deep repression of their own people," or the broader misuse of AI to carry out cyber or biological attacks. Amodei agrees open weights can expand access to the AI economy and boost competition in some use cases, but said he takes issue with the argument that these models help defenders more than cyber attackers. "It seems at least as likely to me that the opposite will be true," Amodei wrote, adding he is concerned widely available models could aid biologic attacks, which he argued would take tech firms and government officials years to figure out how to defend. Days later, Anthropic announced its models accessed the systems of three different organizations during cybersecurity testing in recent months. The incidents were discovered during a review of more than 141,000 Claude evaluations following the OpenAI discovery. Open-source models offer more customization, which can be advantageous to both a cyberattacker and a defender in certain scenarios. "Open models expose the opportunity to find ways to make them more exploitable, but they also give us the opportunity to make them more viable for defensive applications at the same time," Saint-Miller explained. "How much can I fine tune a model and then mitigate the risks of exploits or manipulations against that model if I do it that way? Meta CEO Mark Zuckerberg also stepped into the debate Tuesday, arguing in an opinion piece that the future of technology should not be controlled by a limited group of major players. "The defining question of our age isn't whether superintelligence will exist, but who will have access to it," he wrote in the Wall Street Journal. "Will it be centralized and restricted to a few institutions, or will it be a tool that empowers everyone?" The tech billionaire took thinly veiled swipes at key competitors like Amodei for warnings about open-weight models in the wrong hands, writing, "The notion that AI is so dangerous that the only safe path is an extreme concentration of power seems dangerous." "Historically, hoping that an absolute power will benevolently provide for humanity if sufficiently enlightened hasn't led to safe or positive outcomes," Zuckerberg said. The debate is unfolding just days before the White House is expected to release a framework for voluntary government testing of AI models ahead of their public release. The Trump administration was reportedly considering restrictions or a ban on open-weight models made in China, though officials later said open-source development in the U.S. is a priority for the White House. The rumors came in wake of Kimi K3, an advanced AI model made by the Chinese startup Moonshot AI. The Commerce Department determined Kimi K3 did not perform on the same level as the U.S. AI models, but its coding abilities still sent shockwaves through Washington and Silicon Valley. The White House accused Moonshot of improperly using Anthropic's latest model and accessing restricted Nvidia chips to develop Kimi K3.Treasury Secretary Scott Bessent threatened to impose financial sanctions on Chinese companies allegedly stealing American tech companies' intellectual property. A day after the alliance's launch, Huang met with lawmakers on both sides of the aisle to discuss American leadership in AI, including open source. Huang met with Sen. Mark Warner (D-Va.), the vice chair of the Select Committee on Intelligence, who told reporters Tuesday the Nvidia chief is "advocating strongly for open-source models." "Six months ago, I was much more sympathetic to the idea of closed-source models because that's when Claude came out and that's where kind of the state of play was," Warner said. "Now that we've seen some of these Chinese models like Kimi come out, and more and more American companies go to open-source, I'm not sure this is a genie we can put back in the bottle in terms of open-source," he added. "But I'm still thinking this through."
[23]
What are open weight AI models and why are they dividing Big Tech?
AI models learn by adjusting billions of numerical parameters during training. These parameters, called weights, help the model understand a prompt and decide what response to give. A cyberattack incident last week brought a technical AI term into the middle of a much bigger debate over who should control advanced artificial intelligence. When a rogue OpenAI model accessed Hugging Face's systems during a test, the company turned to GLM 5.2, an open-weight model developed by China's Z.ai, to analyse and block the attack. Because Hugging Face could run the model on its own infrastructure, it did not have to send sensitive data, system information or login credentials to an outside provider. The incident raised fresh questions about who controls advanced AI, who should have access to it and whether more openness makes AI safer or riskier. Also read: Anthropic says Claude AI hacked three companies during cyber tests What is an open weight model?AI models learn by adjusting billions of numerical parameters during training. These parameters, called weights, help the model understand a prompt and decide what response to give. In an open weight model, the developer makes these weights available to others. Anyone can download the model, run it on their own systems and adapt it for specific tasks. This gives users more control than a closed model that can only be accessed through the developer's service. Users can choose where its data is processed, customise the model and avoid depending on a single provider. Users can also use smaller, cheaper models for simple tasks instead of using an expensive frontier model every time. However, an open weight model is not the same as an open source model. Why open weights are not open sourceThe terms are often used interchangeably, but they are not the same. The Open Source Initiative (OSI), a US-based nonprofit, says releasing weights alone does not reveal how a model was created. Developers may still not disclose the training code, training data, details about how the data was cleaned and checkpoints from the training process. That makes it difficult for others to recreate the model or find security flaw came from. Under the OSI's definition, open source AI should give users the freedom to use, study, modify and share the system, along with access to the material needed to make meaningful changes. Source: Open Source Initiative "Open Weights alone fall short of this because they do not provide the underlying training process, code, or comprehensive data details required for full-fledged use, study, modification, and sharing," the OCI said. Big Tech and Anthropic divide over riskAn industry letter signed earlier this week by Microsoft, Amazon, Google, Meta, Nvidia, OpenAI and others argued that open weight models can widen access to AI, increase competition and reduce dependence on a small group of providers. The signatories said startups, universities, businesses and public institutions should be able to use advanced models without having to train one from scratch. The letter also argued that greater access could improve safety by allowing more researchers to test models, identify weaknesses and develop safeguards. Also read: OpenAI's Sam Altman discusses rogue agent and new AI models with US senators Anthropic chief executive Dario Amodei has taken a more cautious position. In a separate letter, Anthropic CEO Dario Amodei said his company does not support a complete ban on open-weight models and considers models without dangerous capabilities a public good. However, he disagrees with the idea that broader access always benefits defenders more than attackers. Once powerful weights are released, they cannot be recalled, while guardrails and usage monitoring become harder. In cyberattacks or biological threats, attackers may gain more from broad access than defenders. Amodei instead supports tighter chip controls, action against industrial-scale distillation and mandatory safety testing for sufficiently capable models, whether open or closed.
[24]
Anthropic CEO Dario Amodei Says He 'Never Advocated' Open-Weight AI Ban, Calls for Tougher Curbs on China
Anthropic CEO Dario Amodei said he has "never advocated" banning open-weight AI models, pushing back against claims that the company wants to protect its closed-model business from open-source competition. Amodei, in a blog post on Monday, said AI models without dangerous capabilities are "a public good," arguing that banning Chinese open-source models would do little to address real risks because "bad actors are unlikely to be legitimate U.S. businesses." He acknowledged that a ban could protect U.S. AI companies such as Anthropic from competition, but said that was never his objective. Instead of supporting a ban, Amodei proposed three more targeted policy measures. Firstly, stricter restrictions on exports of advanced chips and chipmaking equipment to authoritarian governments, including the Chinese Communist Party (CCP). It contended that China's limited domestic chip production prevents it from developing AI models more powerful than those of the U.S. without access to American chips, making export controls the most effective way to curb the perceived threat. Secondly, a crackdown on AI companies training models using outputs generated or "industrial-scale distillation" by more advanced AI systems. Thirdly, mandatory safety testing for all sufficiently capable AI models, regardless of whether they are open- or closed-source. Tech Giants Rally Behind Open AI Models Image via Shutterstock Market News and Data brought to you by Benzinga APIs To add Benzinga News as your preferred source on Google, click here.
[25]
Anthropic CEO Dario Amodei says company never backed open-weight AI ban
Amodei addressed the issue in a blog post on Monday, just days after Nvidia, Microsoft, Meta, Palantir and several other technology companies signed a letter urging US policymakers not to introduce "premature restrictions" on open-weight AI models (these are models that users can download, modify and run on their own infrastructure). Anthropic chief executive Dario Amodei has sought to clear the air over the company's stance on open-weight artificial intelligence (AI) models, saying it has never backed a ban on them.Amodei addressed the issue in a blog post on Monday, just days after Nvidia, Microsoft, Meta, Palantir and several other technology companies signed a letter urging US policymakers not to introduce "premature restrictions" on open-weight AI models (these are
[26]
Anthropic Never Advocated Ban on Open-weight AI Models: Dario Amodei
But China is different, says the man who was among the first to call out data distillation by Chinese AI labs. He claimed that it was authoritarian governments that made him concerned Now that OpenAI and Anthropic have landed on the same page with respect to slowing down the pace of AI development, the Claude-creator's CEO Dario Amodei has also sought to clear the air around open-weight AI models, stating unequivocally that Anthropic never advocated a ban on them. His response came a day ago (US Time) via a blog post with this statement: "Anyone who has read my past writing should know that I don't regard such bans as a useful measure." In fact, he claimed that his fears around AI were longstanding, but the use of open-weight models, even those from China, weren't among them. "But let me state it clearly so that there is no doubt: Anthropic has never advocated for a ban on open-weights models," Amodei said (his emphasis, not ours). Of course, we know the origins of these murmurs, but the fact is that it grew loud enough around an assumption that Anthropic somehow was in cahoots with the US government when it came to banning open-weight Chinese models, limiting Beijing's access to GPUs from Nvidia and any other step possible to keep China behind the US in the AI race. The original culprits might well be the likes of Nvidia founder and CEO Jensen Huang and Microsoft CEO Satya Nadella, who both took to their X handles to share an open letter to the Donald Trump administration last week. The crux of the missive was that policymakers in the US should not impose broad "premature restrictions" on open-weight AI models. The letter itself avoided direct mention of China models specifically and a few signatories also took pains to establish that Mira Murati's The Thinking Machines lab had also launched an open-weight model called Inkling recently. However, Anthropic's request to the authorities around data distillation efforts by the Chinese labs seems to have turned the narrative. One which Amodei is now trying to fix via his blog post. He made extra efforts to reiterate that his views on open-weight models weren't in the same bucket as the threat from China. "Open-weights models that don't have dangerous capabilities are a public good: they don't cost anything besides the compute needed to run them, and they provide value to businesses, developers, and researchers." Amodei said that his main fear is that "authoritarian governments" will build models that are more powerful than those in the U.S. to achieve "permanent military superiority" and/or use AI to repress their own people. He said the Chinese Communist Party (CCP) isn't the only one he's concerned about, but listed it to "most capable." Elaborating on his fears some more, the Anthropic CEO said he is genuinely concerned about AI enabling "biological attacks" and not just through cyberspace. In this scenario, the open-weight models are more dangerous because it becomes tough to apply guardrails or even monitor their usage. He quoted a UK AI Security Institute report which highlighted that once open-weights are released, they cannot be withdrawn. Of course, this statement runs counter to what advocates of open source have been speaking about for several months now. They claim that access to powerful open models not controlled by a single entity helps defenders protect themselves. Even Microsoft referred to this while releasing their own AI security product a couple of days back. And what does Amodei have in his China bucket? He would like Trump to restrict access to powerful AI chips as well as a formal crackdown on distillation. No matter that China is already toying with its own chip designs to overcome this artificial scarcity and a number of AI experts in the US have clarified that distillation is par for the course as Ms. Murati herself showed by using Moonshot's Kimi to train her early models. In order to maintain his stance over the need to slow down the pace of AI development made via a post on X by Anthropic, Amodei reiterated that he supports growing efforts, including some led by the US, to create a model safety testing organisation on a global basis, especially if China agrees to adhere to it. "I think this idea is actually close to a consensus: I have been heartened both that the Trump administration has moved in this direction in recent months, and by recent industry proposals that would apply such testing to the most capable models regardless of their country of origin or whether they are open or closed (while exempting less capable models, such as those from startups and academia, entirely)," Amodei said. "Note that to be effective," he added, "testing would need to be global, which means even the CCP would need to be on board. I think this may actually be possible ... limited cooperation around preventing AI biological weapons may be possible because it is in China's interest too." What he doesn't say here is why the US should expect China to adhere to a proposed moved by Washington when the same entity is trying to place hurdles around AI development on it. Are the goalposts shifting again? We think so.
[27]
After Jensen Huang's open AI push, Anthropic CEO clarifies company's stance
modei also raised concerns about advanced AI being used to create biological threats. Anthropic CEO Dario Amodei has responded after Nvidia CEO Jensen Huang backed open-weight AI models through a public campaign supported by several major tech companies. The discussion started after Huang shared an open letter on X asking policymakers not to place restrictions on open-weight AI models. The letter was signed by companies including Meta, Microsoft, Nvidia, Google, Hugging Face and Mistral. Following the campaign, there were claims that Anthropic supported limits on open-weight AI models. Amodei has rejected those claims in a detailed blog post, saying his company has never asked for such a ban. Amodei made it clear that Anthropic does not support banning open-weight AI models. He wrote, "Anyone who has read my past writing should know that I don't regard such bans as a useful measure, but let me state it clearly so that there is no doubt: Anthropic has never advocated for a ban on open-weights models." Also read: Sam Altman says AI has reached the singularity, calls it a turning point for humanity He also said that open-weight AI models and concerns about Chinese AI should not be treated as the same issue. According to him, many open-weight models are useful for developers, researchers and businesses because they are widely available and only require computing power to run. He explained, "Open-weights models that don't have dangerous capabilities are a public good: they don't cost anything besides the compute needed to run them, and they provide value to businesses, developers, and researchers." Moreover, Amodei said he is worried about powerful AI systems being developed by authoritarian governments. He believes the biggest risk is that such governments could build AI models that become more advanced than those created in the US. He warned that these systems could help achieve "permanent military superiority" and increase control over citizens. While he said the Chinese Communist Party is not the only government he is concerned about, he described it as the "most capable." Also read: Apple delays smart glasses over privacy concerns, wants to avoid Meta's mistakes: Report Amodei also raised concerns about advanced AI being used to create biological threats. He said open-weight models could make these risks harder to manage because they cannot be easily monitored after they are released. Instead of banning open AI models, Amodei said efforts should focus on reducing long-term risks. He suggested restricting China's access to advanced AI chips and taking action against AI distillation, where one AI model learns by studying another model's responses. He explained, "I think this idea is actually close to a consensus: I have been heartened both that the Trump administration has moved in this direction in recent months, and by recent industry proposals that would apply such testing to the most capable models regardless of their country of origin or whether they are open or closed (while exempting less capable models, such as those from startups and academia, entirely)." Amodei added that any testing system would need support from countries around the world to be effective. He said, "Note that to be effective, testing would need to be global, which means even the CCP would need to be on board. I think this may actually be possible: as I wrote in The Adolescence of Technology, limited cooperation around preventing AI biological weapons may be possible because it is in China's interest too."
Share
Copy Link
Dario Amodei has clarified that Anthropic never advocated for banning open-weight models, despite not signing an industry letter supporting them. While nearly 80 tech companies backed open AI model accessibility, Anthropic's CEO expressed concerns about AI safety risks, particularly from authoritarian governments and biological attacks. His stance highlights the growing divide in how the industry approaches US-China tech competition and model distillation practices.
Dario Amodei, founder and CEO of Anthropic, has ended days of speculation by publicly clarifying his company's position on open-weight models. In a blog post published Monday, Amodei emphasized that "Anthropic has never advocated for a ban on open-weights models," addressing widespread criticism after his company conspicuously avoided signing an industry letter supporting open AI model accessibility
1
. The letter, initially backed by 25 companies including Microsoft, Nvidia, Meta, and Hugging Face, has since grown to 77 signatories, adding OpenAI, Google, Amazon, SpaceX, and others4
5
. Anthropic's absence from this list had positioned it as seemingly the only leading AI lab not supporting open-weight models, fueling an AI civil war over how the industry should balance innovation with national security.
Source: CXOToday
The debate intensified following the July release of Moonshot AI's Kimi K3 model, which matched and sometimes exceeded capabilities of American-made models from OpenAI, Anthropic, and Google
2
. Unlike its US counterparts, Kimi K3 was released as an open-weight model, sending shockwaves through Wall Street and prompting discussions about Chinese AI capabilities. Michael Kratsios, Trump's director of the Office of Science and Technology Policy, claimed that "Moonshot AI distilled Anthropic's Fable for the development of its K3," suggesting intellectual property theft through model distillation3
. This technique involves an AI bombarding another model with prompts to learn how it works1
.Amodei acknowledged that "open-weights models that don't have dangerous capabilities are a public good" and noted they "expand access to the AI economy" and "strengthen competition"
1
5
. Nearly 80% of developers use open models, according to a recent Mozilla report, with Linda Griffin, vice president of global policy at Mozilla, stating that "open-weight models are everywhere in the industry already"2
.
Source: The Hill
While Amodei supports open-weight models in principle, he takes issue with claims that they necessarily improve cybersecurity defenses. The industry letter argued that "open models broaden defensive capability, increase transparency, and allow vulnerabilities to be discovered and remediated across many teams"
5
. Amodei countered: "I don't agree with the letter's assertions that open-weights models necessarily make it easier to develop safeguards or that broad access to capabilities necessarily helps defenders more than attackers"5
.His primary concern centers on geopolitical risks from authoritarian governments building more powerful models than those in the US to achieve "permanent military superiority" or "perpetrate incredibly deep repression of their own people"
1
. While he clarified the Chinese Communist Party isn't his only concern, he identified it as the "most capable" authoritarian government1
.Amodei also fears AI-enabled biological attacks, citing that "defense against these agents is a multi-year operational task in the best case," referencing the lengthy COVID-19 vaccine development and rollout
5
. He argues that open-weight models present higher risks because "it is very difficult to apply guardrails to them or monitor their usage," and citing a UK AI Security Institute report, noted that "once weights are released, they cannot be withdrawn"1
5
.Related Stories
Rather than supporting bans on open-source AI models, Amodei outlined specific actions to address national security threats. He called for continued restrictions on Chinese access to advanced GPUs, describing this as "the most efficient and direct way" to block threats
5
. He also urged a formal crackdown on "industrial" model distillation used to copy US leading-edge models1
5
.Interestingly, Amodei supports mandatory safety testing for all AI models, whether open or closed. He expressed optimism that "the Trump administration has moved in this direction in recent months" and suggested such testing could be global, potentially including China
1
5
. "Limited cooperation around preventing AI biological weapons may be possible because it is in China's interest too," he wrote1
.
Source: NYT
Ayham Boucher, executive director of AI strategy and innovation at Cornell, warned that "regulators can't have it both ways. You can't restrict access to frontier models and ban open-source models, leaving enterprises and institutions defenseless"
2
. This tension reflects the broader challenge facing policymakers as they navigate competing priorities of innovation, security, and economic competitiveness in an increasingly fractured AI landscape.Summarized by
Navi
[1]
05 Aug 2026•Technology

22 Dec 2025•Policy and Regulation

04 Dec 2024•Technology

1
Technology

2
Technology

3
Technology
