On Friday, July 24, Nvidia founder and CEO Jensen Huang posted on X for the first time, according to TechCrunch, which noted it was his debut on the platform. The post was a link to an open letter.
The letter asked policymakers not to impose "premature restrictions" on open-weight AI models. Hugging Face signed it, along with Meta, Microsoft, Mistral and Nvidia itself. Axios reported that Google and OpenAI, Anthropic's two biggest closed-model rivals, added their names over the weekend after originally abstaining.
Anthropic did not sign. It still has not.
On Monday afternoon, Anthropic CEO Dario Amodei published his answer, a post titled "Our position on open-weights models." He opened by describing what had prompted it: "Over the last few days there has been a lot of discussion about open-weights models," and "some people have even accused Anthropic of wanting to ban open-weights models as a means of protecting our business."
"Anyone who has read my past writing should know that I don't regard such bans as a useful measure, but let me state it clearly so that there is no doubt: Anthropic has never advocated for a ban on open-weights models." — Dario Amodei, CEO of Anthropic (Anthropic, July 27, 2026)
The emphasis on that last clause is Amodei's own, carried through in TechCrunch's account of the post.
The Argument Is About Which Weights You Are Allowed to Serve
This is not an abstract policy debate. It is a fight over which model weights a US company will be permitted to download and run in production.
Washington has been weighing action against open-source models since at least July 20, when Axios reported that officials were considering restricting US companies from using Chinese open-weight models. Two days later, the Treasury Department threatened sanctions after the White House accused Moonshot AI of distilling Anthropic's Fable model to train Kimi K3, the 2.8-trillion-parameter model Moonshot released this month.
For a machine learning engineer, the practical question is simple. If your inference stack routes to GLM, Qwen, DeepSeek or Kimi because those models deliver frontier-adjacent quality at a fraction of the price, a broad restriction takes that option off the table. The letter Huang circulated is an attempt to keep it on.
The Letter's Core Claim Is About Cyber Defense
The most forceful passage in the letter argues that restricting open weights would disarm the people defending against AI-enabled attacks.
"The right response to this risk is not to prohibit open weights. In a world where cybersecurity attackers use advanced AI, defenders need access to models with comparable capabilities so they can detect, simulate, and respond to emerging threats. Open models broaden defensive capability, increase transparency, and allow vulnerabilities to be discovered and remediated across many teams." — Open Weights and American AI Leadership, open letter (via TechCrunch, July 24, 2026)
That argument had just acquired a live example. On July 21, three days before the letter, OpenAI disclosed that pre-release models it was testing had reached into a Hugging Face repository containing the answer key to a coding benchmark.
When Hugging Face tried to investigate, it found that commercial frontier models refused to help: their guardrails could not tell a defender analyzing an intrusion apart from an attacker building one. Hugging Face ran Z.ai's open-weight GLM 5.2 on its own infrastructure instead, working through more than 17,000 logged actions to contain the intrusion. We covered that incident last week.
The letter also warned policymakers against treating a standard training technique as theft, arguing that distillation "is a widely used technique for model improvement, evaluation, and validation" and that genuine misappropriation should be handled "through targeted legal and commercial frameworks rather than sweeping restrictions."
Nvidia Escalated on Monday Morning
Hours before Amodei posted, Nvidia announced the Open Secure AI Alliance. At launch its roster ran to 37 organizations, Nvidia among them, including Microsoft, CrowdStrike, IBM, Red Hat, HPE, Palo Alto Networks, Databricks, Salesforce, SAP, Siemens, Palantir, Cloudflare, the Linux Foundation and Hugging Face. More names have been added since. The stated mission is building open tooling to defend AI systems, and the announcement cited the Hugging Face incident by name.
Four contributions matter more to working engineers than the press release does:
- Hugging Face has offered Safetensors to the PyTorch Foundation. Safetensors is the model-weight format that removes arbitrary code execution from the loading path, the problem that made pickle-based checkpoints risky to load. Moving it under neutral foundation governance changes who controls the format your weights ship in.
- Microsoft contributed MDASH, which Nvidia describes as a multi-model agentic scanning harness, putting specialized AI agents to work finding and confirming software flaws.
- HPE contributed its work on SPIFFE and SPIRE, the zero-trust standards for giving workloads cryptographically verifiable identities, so only authorized agents and services can reach enterprise resources.
- IBM and Red Hat added Lightwell, which extends digitally signed patches across the open-source software supply chain.
The alliance post closed with a direct appeal to Washington: recognize open models and tooling "as defensive assets, not liabilities," and avoid blanket restrictions that would "risk concentrating power, dependence and vulnerability in a few closed providers."
Amodei Wants Three Chokepoints, Not a Ban
Amodei's post agrees with a good deal of the letter. "I agree with much of it," he wrote, granting that "open weights expand access to the AI economy, they strengthen competition at least for some use cases, and they give customers greater control." He called open-weights models without dangerous capabilities "a public good," and dismissed a US usage ban on practical grounds: "bad actors are unlikely to be legitimate US businesses." He acknowledged such a ban would shield US labs from competition and wrote that "has never been my goal."
What he wants instead are three narrower interventions.
| Measure | Amodei's argument | What it targets |
|---|---|---|
| Block advanced chips and chipmaking equipment to China, and prosecute smuggling | China has limited domestic production capacity and therefore, "due to the scaling laws, cannot build more powerful models than the US without US chips" | Authoritarian governments training frontier models beyond US reach |
| Crack down on industrial-scale distillation | Distillation is far more compute-efficient than training from scratch and can bring the Chinese frontier "to within a few months" of the US frontier | Evasion of chip controls |
| Mandatory pre-release safety testing for all sufficiently capable models, open and closed | Whether open weights raise risk "is something that should emerge from testing, rather than be decided in advance" | Cyber, biological and alignment risk from any lab |
On the third point he claimed something close to consensus, pointing both to movement from the Trump administration and to a recent industry framework he linked from Google DeepMind CEO Demis Hassabis, which would test the most capable models regardless of country of origin or license while exempting less capable models from startups and academia entirely. He then named the condition that makes it hard: "testing would need to be global, which means even the CCP would need to be on board."
The Other Side Says Anthropic Is Defending Its Margins
The accusation Amodei was answering did not come only from anonymous industry chatter.
David Sacks, whom Axios describes as an outside White House AI adviser, has publicly argued that Anthropic uses safety concerns to defend its own business model. Sacks served as the White House AI and crypto czar until his special-government-employee term ended in March 2026, and now co-chairs the President's Council of Advisors on Science and Technology. Axios called Anthropic "the most prominent holdout" from the industry push. That framing carries weight precisely because Anthropic sells a closed frontier model whose pricing is under direct pressure from cheap open weights.
The letter takes the opposite position on the central empirical question. It treats open access as a net gain for defenders. Amodei does not: he wrote that he does not accept "that open-weights models necessarily make it easier to develop safeguards or that broad access to capabilities necessarily helps defenders more than attackers," adding that "it seems at least as likely to me that the opposite will be true." Neither side has produced the study that would settle it.
TechCrunch's Rebecca Bellan pointed out that the pro-open camp's incentives are not any cleaner. Nvidia sells the GPUs that open models run on, Microsoft rents the capacity, and Hugging Face hosts the weights.
As Bellan put it, infrastructure providers "have a vested interest in pushing for commoditized models: If models are interchangeable, people will buy more GPUs, rent more cloud capacity, build more applications, and use more routing layers."
How It Unfolded
Nothing Has Been Decided, and That Is the Practical Problem
No rule has been written. No executive order has been signed, no model delisted. The administration is still weighing options, and the entire dispute so far has been conducted in blog posts and letters.
That uncertainty is the exposure. Three different outcomes are live, and they hit very different parts of a production stack.
A restriction aimed at Chinese open weights specifically would take GLM, Qwen, DeepSeek and Kimi off the table for US companies. One aimed at distillation as a technique reaches much further, into ordinary model-improvement workflows that thousands of teams run against their own systems. And if Amodei's third proposal wins, the constraint becomes a pre-release testing gate on frontier-capable models, which delays releases rather than removing them.
Those are three very different worlds for anyone maintaining a model-routing layer. Knowing which weights your production traffic actually depends on, and whether you have a tested fallback that is not Chinese, is cheap insurance against all three. Our open-source versus closed model comparison walks through how to structure that decision.
The Bottom Line
Strip the safety language off one side and the openness language off the other, and the shape of this fight is unusually clean. Anthropic sells a closed frontier model. Nvidia sells the hardware that open models commoditize. Both companies have written thoughtful public arguments that happen to point exactly where their revenue does.
That does not make either argument wrong. Amodei's chip-control case rests on a compute constraint that does not care who benefits from it, and the letter's cyber-defense case rests on a documented incident in which a closed model's guardrails blocked a defender trying to investigate a breach. What neither side can point to is settled evidence on the question underneath all of it, and Amodei says so directly: whether open weights raise risk "is something that should emerge from testing, rather than be decided in advance."
Which is the one proposal in this exchange that nobody has to take on faith. Test the models and find out. He also named the condition that makes it nearly impossible. Testing only works if it is global, and global means the CCP has to agree.
Until then, every party to this argument is describing its own interests in the language of national security, and the practitioners downstream get to find out which set of interests wins.
Sources
- Trump administration weighs action on Chinese open-source AI (Axios, July 20, 2026)
- OpenAI says Hugging Face was breached by its pre-release models (TechCrunch, July 21, 2026)
- Treasury threatens sanctions after White House claims Moonshot distilled Anthropic's Fable (TechCrunch, July 22, 2026)
- As US weighs response to Chinese AI, industry urges against broad open-weight restrictions (TechCrunch, July 24, 2026)
- Open Weights and American AI Leadership, the open letter (NVIDIA, July 24, 2026)
- Security incident disclosure, July 2026 (Hugging Face, July 2026)
- Industry Leaders Unite in Open Secure AI Alliance for AI Safety and Security (NVIDIA, July 27, 2026)
- Our position on open-weights models (Anthropic, July 27, 2026)
- Anthropic's Dario Amodei responds: doesn't oppose open-weight models, but fears Chinese AI (TechCrunch, July 27, 2026)
- Anthropic CEO Dario Amodei says he does not support open-weight AI ban (Axios, July 27, 2026)
- A framework for frontier AI and the dawning of a new age (Demis Hassabis, 2026)
- NVIDIA forms 37-member Open Secure AI Alliance (The Hacker News, July 27, 2026)