Jensen Huang, Nvidia’s CEO, recently made his first post on X (formerly Twitter) after years of having an inactive account. He shared a three-page letter titled “Open Weights and American AI Leadership,” which was also published by Microsoft. The letter, signed by 25 companies, urges the U.S. government to avoid placing early limits on access to AI models, comparing the current situation to the rise of open-source software in the 1980s. Overall, it’s a sensible and well-reasoned document.
The list of companies involved included Nvidia, Microsoft, Meta, IBM, Dell, Palantir, Mistral, Hugging Face, Mozilla, the Linux Foundation, Andreessen Horowitz, Y Combinator, CrowdStrike, and Replit, among others. Interestingly, OpenAI, Google, and Anthropic – the three companies offering access to the most advanced AI models that aren’t publicly downloadable – were not part of the group.
As an analyst, I’ve been looking at the recent statement on AI safety, and there are a couple of ways to interpret it. One possibility is that tech companies genuinely share common beliefs about how to build safe AI systems. Another, more cynical view – and frankly, the one I believe is accurate – is simply that companies have signed based on where their financial interests lie: those profiting from open-weight models supported the statement, while those benefiting from closed ones did not. It’s worth acknowledging both perspectives, but I think the latter explanation gets closer to the truth.
Nvidia provides the chips that power open-source AI models, and a surge in businesses customizing these models would mean a huge demand for their GPUs. Companies like Meta and Mistral are releasing open-source models as a way to compete with AI labs developing the most advanced technology. Hugging Face makes these models widely available, while Dell and IBM sell the necessary server infrastructure. Venture capital firms are funding startups that can’t afford the costs of using existing AI services. This doesn’t invalidate the argument for open source; it simply means this perspective comes from businesses within the AI industry – which is typical for any industry statement.
By Monday, the letter had gathered fifty signatures from major players in the AI field, including OpenAI, Google, SpaceX, AMD, Cisco, Cloudflare, GitHub, Block, and Ollama. While Amazon didn’t sign, attention wasn’t focused on them; the story quickly centered around other key companies. Anthropic also remained silent for four days after the letter circulated, leading to widespread speculation about their position.
The silence
David Sacks, a venture capitalist who recently served as an advisor on AI and crypto for the Trump administration, has voiced a strong opinion on the debate around artificial intelligence. He believes most of the tech industry – with Anthropic being the exception – supports open-source AI development. Sacks warns that these companies will actively try to hinder open-source projects and urges others in the industry to closely monitor their actions.
Bill Gurley from Benchmark agreed, but put it more simply: open-source models challenge Anthropic’s business model, and he’s right. Peter Steinberger, who founded OpenClaw and now works at OpenAI, pointed out that OpenAI *had* signed a particular agreement while Anthropic hadn’t – a detail often highlighted after a company receives positive media attention.
The central claim being made is straightforward: Anthropic appears to be urging the US government to prohibit Chinese open-source AI models, framing this as a matter of national security when it’s really about protecting their own competitive advantage. This accusation makes sense – it’s clear, suggests a calculated strategy, and comes at a particularly bad time for Anthropic, which I’ll explain shortly.
Dario Amodei addressed the discussion on Monday afternoon with a statement clarifying that Anthropic has always been against banning openly available AI models.

Anthropic has never advocated for a ban on open-weights models, source: Anthropic
What he actually said
Amodei presents a somewhat unexpected argument: he largely focuses on explaining why the policy people think he supports would actually be ineffective.
As a crypto investor, I’m keeping a close eye on the risks surrounding AI. There are two things that really concern me. First, I worry that countries like China could develop AI much faster than the US and use it to gain a military edge or to control their own citizens. Second, I’m concerned about the potential for these powerful AI systems to be used for malicious purposes – things like cyberattacks, creating biological weapons, or even just behaving in unpredictable ways that cause harm. It’s a serious consideration for any tech investment, including crypto.
He then questions how preventing American companies from using Chinese AI models would address either of these concerns. First, it wouldn’t matter – the real threat is a hidden model given directly to the Chinese military, which wouldn’t be publicly available anyway. Second, it won’t stop malicious actors because they are unlikely to be lawful US companies in the first place. Essentially, a ban only affects those who already follow rules.
Then he wrote something unexpected: he said it *would* shield American AI businesses from competitors, but emphasized that wasn’t what he was trying to achieve.
As an analyst, I find this response particularly unusual. Typically, when facing accusations of protectionism, the standard approach is to firmly deny any such intent. However, Amodei takes a different tack. He *admits* the proposed policy would offer him protection, but argues this is precisely why he opposes it – because that’s *all* it would accomplish. Whether you accept his reasoning is up to you, but it’s a remarkably strange statement to make if he secretly wanted the ban to go through. It doesn’t read like someone hoping for a specific outcome, but rather someone attempting a unique justification.
Instead of a complete ban, he proposes three key actions. First, prevent China from accessing cutting-edge computer chips and the equipment used to make them, and aggressively prosecute anyone who tries to bypass these restrictions, based on the idea that China can’t surpass US technological advancements without American silicon. Second, stop the practice of ‘industrial-scale distillation,’ where companies pay to train their AI models to mimic others. Finally, require thorough safety testing – covering cybersecurity, biological risks, and alignment – for all powerful AI models, regardless of whether they’re open-source or proprietary, developed domestically or abroad. Smaller models created by startups and universities would be exempt from this testing requirement.
In his response, he largely agrees with the points made in the original letter. He acknowledges that open-weight models increase access, foster competition, empower users, and that safe models benefit everyone. However, he disputes the claim that openness enhances safety. He argues that open access could actually *increase* risks, using the example of biology: a powerful model could potentially weaponize a dangerous pathogen quickly using readily available information, and defending against such a threat would be a long and difficult process, even with significant resources like those used in Operation Warp Speed. He doesn’t claim to have *proven* this is possible, but points out that no one has actually tested it, and that testing—not just assertions—is needed to determine the truth.
The awkward part
So here is why the timing is bad.
As a researcher in this field, I’ve been closely following the developments with large language models. Recently, on July 16th, Moonshot AI released Kimi K3 – it’s a massive model with 2.8 trillion parameters! What’s really interesting is how it works; it selectively uses only 16 out of its 896 specialized components (‘experts’) for each piece of text it processes. It can also handle incredibly long inputs, up to a million tokens. The cost is quite competitive too – just $3-15 per million tokens used for both input and output. In fact, Kimi K3 immediately jumped to the top spot on the Arena’s Frontend Code leaderboard, surpassing even Claude Fable 5. The model weights were updated as of July 27th. This release is particularly noteworthy because Anthropic, a highly valued private company reportedly preparing for an IPO, might find it challenging to compete with such an affordable and powerful downloadable model.

Anthropic claims Moonshot built its AI by essentially copying Claude through over 3.4 million conversations. This accusation was echoed by Michael Kratsios, director of the White House Office of Science and Technology Policy, and even prompted Treasury Secretary Scott Bessent to suggest potential sanctions. Anthropic is now urging Washington to take action against this specific method – just eleven days after Moonshot released its product. Considering these events, a skeptical perspective seems justified.
The situation became complicated when, in June, the Commerce Department told Anthropic to limit foreign countries’ ability to use its Fable 5 and Mythos 5 AI models. Anthropic protested this decision, claiming it was too strict and that similar technology was already available in other models, like OpenAI’s GPT-5.5. They also warned that setting this precedent could stop all AI companies from releasing new models. Around 100 cybersecurity experts, including Alex Stamos, Katie Moussouris, and Rachel Tobac, signed a letter asking the Commerce Department to reconsider. The restrictions were then lifted on June 30th, and access was restored on July 1st.
Anthropic pointed out in June that limiting access to powerful AI doesn’t eliminate the technology itself, it just puts it into the hands of those who aren’t constrained by regulations. This is essentially the same point Nvidia made in July and Amodei reiterated on Monday regarding models developed in China. A company focused solely on complying with rules wouldn’t waste time arguing that a government decision to restrict AI was misguided.
The actual disagreement, which is small
If we set aside the debate about *why* people are releasing these models, the core question becomes surprisingly simple: does making the model weights publicly available actually increase or decrease global safety?
As a researcher, I’ve been following the debate around AI model safety, and it’s striking how much relies on claims rather than concrete evidence. One side argues that releasing model weights is inherently safer, citing increased scrutiny and existing security practices. However, the UK AI Security Institute counters that once those weights are public, safeguards can be removed from copies, and the model is essentially unrecoverable. It’s important to note that both positions are currently assertions – strong opinions, but not yet supported by definitive findings.
Instead of simply claiming what AI can do, Amodei suggests we rigorously test its capabilities, setting the standards based on performance, not where the AI was created or who owns it. This approach is less restrictive than banning open-source AI, aligns with proposals from Demis Hassabis, and interestingly, would likely mean the company pushing for these tests would be tested most often – as their AI models are currently the most powerful. This situation is a surprisingly self-regulating dynamic, unlike typical regulatory capture.
Anthropic unnecessarily prolonged a disagreement they could have resolved quickly, and their final statement doesn’t even reflect what the original dispute was about. This kind of thing happens all the time – the idea that ultimately gains traction isn’t usually the one initially presented in writing.
2026-07-28 08:21