Skip to content

Google and OpenAI Signed the Open-Weights Letter. Anthropic Answered Instead.

DS
LDS Team
Let's Data Science
12 min
Dario Amodei published a post on Monday saying Anthropic has never advocated banning open-weights models. It landed three days after Jensen Huang used his first post on X to circulate an industry letter Anthropic declined to sign, and hours after Nvidia launched a 37-company security alliance built on the same argument. Amodei says Washington should regulate chips, distillation and safety testing instead.

On Friday, July 24, Nvidia founder and CEO Jensen Huang posted on X for the first time, according to TechCrunch, which noted it was his debut on the platform. The post was a link to an open letter.

The letter asked policymakers not to impose "premature restrictions" on open-weight AI models. Hugging Face signed it, along with Meta, Microsoft, Mistral and Nvidia itself. Axios reported that Google and OpenAI, Anthropic's two biggest closed-model rivals, added their names over the weekend after originally abstaining.

Anthropic did not sign. It still has not.

On Monday afternoon, Anthropic CEO Dario Amodei published his answer, a post titled "Our position on open-weights models." He opened by describing what had prompted it: "Over the last few days there has been a lot of discussion about open-weights models," and "some people have even accused Anthropic of wanting to ban open-weights models as a means of protecting our business."

"Anyone who has read my past writing should know that I don't regard such bans as a useful measure, but let me state it clearly so that there is no doubt: Anthropic has never advocated for a ban on open-weights models." — Dario Amodei, CEO of Anthropic (Anthropic, July 27, 2026)

The emphasis on that last clause is Amodei's own, carried through in TechCrunch's account of the post.

The Argument Is About Which Weights You Are Allowed to Serve

This is not an abstract policy debate. It is a fight over which model weights a US company will be permitted to download and run in production.

Washington has been weighing action against open-source models since at least July 20, when Axios reported that officials were considering restricting US companies from using Chinese open-weight models. Two days later, the Treasury Department threatened sanctions after the White House accused Moonshot AI of distilling Anthropic's Fable model to train Kimi K3, the 2.8-trillion-parameter model Moonshot released this month.

For a machine learning engineer, the practical question is simple. If your inference stack routes to GLM, Qwen, DeepSeek or Kimi because those models deliver frontier-adjacent quality at a fraction of the price, a broad restriction takes that option off the table. The letter Huang circulated is an attempt to keep it on.

The Letter's Core Claim Is About Cyber Defense

The most forceful passage in the letter argues that restricting open weights would disarm the people defending against AI-enabled attacks.

"The right response to this risk is not to prohibit open weights. In a world where cybersecurity attackers use advanced AI, defenders need access to models with comparable capabilities so they can detect, simulate, and respond to emerging threats. Open models broaden defensive capability, increase transparency, and allow vulnerabilities to be discovered and remediated across many teams." — Open Weights and American AI Leadership, open letter (via TechCrunch, July 24, 2026)

That argument had just acquired a live example. On July 21, three days before the letter, OpenAI disclosed that pre-release models it was testing had reached into a Hugging Face repository containing the answer key to a coding benchmark.

When Hugging Face tried to investigate, it found that commercial frontier models refused to help: their guardrails could not tell a defender analyzing an intrusion apart from an attacker building one. Hugging Face ran Z.ai's open-weight GLM 5.2 on its own infrastructure instead, working through more than 17,000 logged actions to contain the intrusion. We covered that incident last week.

The letter also warned policymakers against treating a standard training technique as theft, arguing that distillation "is a widely used technique for model improvement, evaluation, and validation" and that genuine misappropriation should be handled "through targeted legal and commercial frameworks rather than sweeping restrictions."

Nvidia Escalated on Monday Morning

Hours before Amodei posted, Nvidia announced the Open Secure AI Alliance. At launch its roster ran to 37 organizations, Nvidia among them, including Microsoft, CrowdStrike, IBM, Red Hat, HPE, Palo Alto Networks, Databricks, Salesforce, SAP, Siemens, Palantir, Cloudflare, the Linux Foundation and Hugging Face. More names have been added since. The stated mission is building open tooling to defend AI systems, and the announcement cited the Hugging Face incident by name.

Four contributions matter more to working engineers than the press release does:

  • Hugging Face has offered Safetensors to the PyTorch Foundation. Safetensors is the model-weight format that removes arbitrary code execution from the loading path, the problem that made pickle-based checkpoints risky to load. Moving it under neutral foundation governance changes who controls the format your weights ship in.
  • Microsoft contributed MDASH, which Nvidia describes as a multi-model agentic scanning harness, putting specialized AI agents to work finding and confirming software flaws.
  • HPE contributed its work on SPIFFE and SPIRE, the zero-trust standards for giving workloads cryptographically verifiable identities, so only authorized agents and services can reach enterprise resources.
  • IBM and Red Hat added Lightwell, which extends digitally signed patches across the open-source software supply chain.

The alliance post closed with a direct appeal to Washington: recognize open models and tooling "as defensive assets, not liabilities," and avoid blanket restrictions that would "risk concentrating power, dependence and vulnerability in a few closed providers."

Amodei Wants Three Chokepoints, Not a Ban

Amodei's post agrees with a good deal of the letter. "I agree with much of it," he wrote, granting that "open weights expand access to the AI economy, they strengthen competition at least for some use cases, and they give customers greater control." He called open-weights models without dangerous capabilities "a public good," and dismissed a US usage ban on practical grounds: "bad actors are unlikely to be legitimate US businesses." He acknowledged such a ban would shield US labs from competition and wrote that "has never been my goal."

What he wants instead are three narrower interventions.

MeasureAmodei's argumentWhat it targets
Block advanced chips and chipmaking equipment to China, and prosecute smugglingChina has limited domestic production capacity and therefore, "due to the scaling laws, cannot build more powerful models than the US without US chips"Authoritarian governments training frontier models beyond US reach
Crack down on industrial-scale distillationDistillation is far more compute-efficient than training from scratch and can bring the Chinese frontier "to within a few months" of the US frontierEvasion of chip controls
Mandatory pre-release safety testing for all sufficiently capable models, open and closedWhether open weights raise risk "is something that should emerge from testing, rather than be decided in advance"Cyber, biological and alignment risk from any lab

On the third point he claimed something close to consensus, pointing both to movement from the Trump administration and to a recent industry framework he linked from Google DeepMind CEO Demis Hassabis, which would test the most capable models regardless of country of origin or license while exempting less capable models from startups and academia entirely. He then named the condition that makes it hard: "testing would need to be global, which means even the CCP would need to be on board."

The Other Side Says Anthropic Is Defending Its Margins

The accusation Amodei was answering did not come only from anonymous industry chatter.

David Sacks, whom Axios describes as an outside White House AI adviser, has publicly argued that Anthropic uses safety concerns to defend its own business model. Sacks served as the White House AI and crypto czar until his special-government-employee term ended in March 2026, and now co-chairs the President's Council of Advisors on Science and Technology. Axios called Anthropic "the most prominent holdout" from the industry push. That framing carries weight precisely because Anthropic sells a closed frontier model whose pricing is under direct pressure from cheap open weights.

The letter takes the opposite position on the central empirical question. It treats open access as a net gain for defenders. Amodei does not: he wrote that he does not accept "that open-weights models necessarily make it easier to develop safeguards or that broad access to capabilities necessarily helps defenders more than attackers," adding that "it seems at least as likely to me that the opposite will be true." Neither side has produced the study that would settle it.

TechCrunch's Rebecca Bellan pointed out that the pro-open camp's incentives are not any cleaner. Nvidia sells the GPUs that open models run on, Microsoft rents the capacity, and Hugging Face hosts the weights.

As Bellan put it, infrastructure providers "have a vested interest in pushing for commoditized models: If models are interchangeable, people will buy more GPUs, rent more cloud capacity, build more applications, and use more routing layers."

How It Unfolded

JULY 17, 2026
Kimi K3 debuts
Axios reports that Moonshot AI's open-weight model approaches US frontier performance at a fraction of the cost.
JULY 20, 2026
Washington weighs a ban
Axios reports US officials are considering barring American companies from using Chinese open-weights models.
JULY 21, 2026
OpenAI discloses the Hugging Face breach
Pre-release models reached a repository holding a benchmark answer key. Closed models later refused to help Hugging Face investigate.
JULY 22, 2026
Treasury threatens sanctions
The White House accuses Moonshot AI of distilling Anthropic's Fable model to train Kimi K3.
FRIDAY, JULY 24, 2026
Jensen Huang's first post on X
Nvidia's CEO shares the open letter. Hugging Face, Meta, Microsoft, Mistral and Nvidia are among the signatories. Anthropic is not.
JULY 25 TO 26, 2026
Google and OpenAI sign
Axios reports Anthropic's two biggest closed-model rivals added their names over the weekend after originally abstaining.
MONDAY MORNING, JULY 27, 2026
Nvidia launches the Open Secure AI Alliance
Thirty-seven inaugural organizations. Hugging Face offers Safetensors to the PyTorch Foundation. The post asks regulators to treat open models as defensive assets.
MONDAY AFTERNOON, JULY 27, 2026
Amodei answers
"Anthropic has never advocated for a ban on open-weights models." He names chips, distillation and mandatory testing as the real targets.

Nothing Has Been Decided, and That Is the Practical Problem

No rule has been written. No executive order has been signed, no model delisted. The administration is still weighing options, and the entire dispute so far has been conducted in blog posts and letters.

That uncertainty is the exposure. Three different outcomes are live, and they hit very different parts of a production stack.

A restriction aimed at Chinese open weights specifically would take GLM, Qwen, DeepSeek and Kimi off the table for US companies. One aimed at distillation as a technique reaches much further, into ordinary model-improvement workflows that thousands of teams run against their own systems. And if Amodei's third proposal wins, the constraint becomes a pre-release testing gate on frontier-capable models, which delays releases rather than removing them.

Those are three very different worlds for anyone maintaining a model-routing layer. Knowing which weights your production traffic actually depends on, and whether you have a tested fallback that is not Chinese, is cheap insurance against all three. Our open-source versus closed model comparison walks through how to structure that decision.

The Bottom Line

Strip the safety language off one side and the openness language off the other, and the shape of this fight is unusually clean. Anthropic sells a closed frontier model. Nvidia sells the hardware that open models commoditize. Both companies have written thoughtful public arguments that happen to point exactly where their revenue does.

That does not make either argument wrong. Amodei's chip-control case rests on a compute constraint that does not care who benefits from it, and the letter's cyber-defense case rests on a documented incident in which a closed model's guardrails blocked a defender trying to investigate a breach. What neither side can point to is settled evidence on the question underneath all of it, and Amodei says so directly: whether open weights raise risk "is something that should emerge from testing, rather than be decided in advance."

Which is the one proposal in this exchange that nobody has to take on faith. Test the models and find out. He also named the condition that makes it nearly impossible. Testing only works if it is global, and global means the CCP has to agree.

Until then, every party to this argument is describing its own interests in the language of national security, and the practitioners downstream get to find out which set of interests wins.

Sources

Practice interview problems based on real data

1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.

Try 250 free problems