Machine translation · the Chinese original is authoritative · View original

Dario Amodei: Our Position on Open-Weights Models

1# · OP Author:反賊文摘 Published:2026-07-28 22:34 Replies:0 Views:9 Permalink:fanzei.net/d_22252t

Our position on open-weights models July 27, 2026 A post by Dario Amodei, CEO of Anthropic

Over the past few days, there has been a great deal of discussion regarding open-weights models—particularly those originating from China. Reports have emerged suggesting that some U.S. officials are considering banning U.S. companies from using Chinese open-weights models. In response, a number of tech companies signed an open letter supporting open-weights models, and some even accused Anthropic of attempting to ban open-weights models to protect its own commercial interests. Anyone who has read my past writings should know that I do not believe such bans are an effective measure, but I want to state my position clearly here to leave no room for doubt: Anthropic has never advocated for a ban on open-weights models.

Open-weights models that lack dangerous capabilities are a public good: aside from the compute required to run them, they incur almost no other costs while creating value for businesses, developers, and researchers.

Protectionist bans do not solve the national security issues that concern me most. Specifically, I am worried about two nightmare scenarios. Six months ago, I outlined both points in an article titled "The Adolescence of Technology"¹, and my stance on this has remained consistent over the years:

My primary concern is that authoritarian governments—not just the Chinese Communist Party (CCP), though the CCP is clearly the most capable threat—might build AI models more powerful than those of the United States, thereby securing a permanent military advantage or inflicting profound oppression on their own people. This concern is widely shared within the U.S. government: Vice President Vance warned in Paris last year that "authoritarian regimes have stolen and utilized AI to enhance their military, intelligence, and surveillance capabilities"; the U.S. Intelligence Community's Annual Threat Assessment for 2026 also noted that "strong progress in AI by other global powers is challenging U.S. economic competitiveness and national security advantages." Whether these models are released in open-weights form does not matter, nor does it matter whether they are used by U.S. companies. In fact, the most dangerous models are likely those trained in secrecy and delivered solely to the People's Liberation Army for drones, or to the Ministry of State Security for surveillance and repression. My second concern is that powerful AI models could be misused to launch cyberattacks or bioweapon attacks, and that they may suffer from severe alignment issues. Open-weights models—whether from China or anywhere else—may indeed carry higher risks than closed-source models because it is difficult to apply guardrails or monitor their usage, and weights cannot be recalled once released². However, prohibiting U.S. companies from using these models does not solve this risk, as bad actors are unlikely to be legitimate U.S. companies. Such a ban would merely shield U.S. AI companies from competition, but that has never been my goal.

To address these issues, I do support the following three measures, which I and Anthropic have consistently advocated for:

We should not sell advanced chips or chip-making equipment to China, and we should crack down on the currently rampant smuggling³ and various workarounds used to acquire such chips. China's domestic capacity is limited, so according to scaling laws, without U.S. chips China cannot build models more powerful than those of the United States. This is the most effective and direct way to stop the first threat; at the same time, because it hinders the training of models beyond the reach of U.S. law, this measure also indirectly helps address the second threat. We should crack down on industrial-scale distillation operations. Compared to training models from scratch, distillation is a much more computationally efficient method that allows China to build models far more powerful than its chip count would otherwise support, thereby partially circumventing chip bans. Distillation will not grant the CCP AI capabilities comparable to or surpassing those of the United States, but it can narrow China's frontier gap to just a few months behind the U.S. Admittedly, many companies engaging in such distillation operations do release open-weights models—but compared to the fact that these operations are backed by an authoritarian state attempting to surpass the U.S. at the frontier, the open weights themselves are much less relevant. We should enact policy interventions to curb this behavior. A blanket ban on open-weights models is neither the right solution nor what we advocate for⁴. All models reaching a certain capability threshold, whether open or closed, should be subject to mandatory safety testing. The best way to address the second threat is to directly test models for cybersecurity, biosecurity, and alignment risks before they are released. I believe this idea is actually nearing a consensus: on the one hand, I am encouraged that the Trump administration has moved in this direction in recent months; on the other hand, I am also gratified that the industry has recently put forward proposals arguing that regardless of which country a model comes from, and whether it is open or closed, any model belonging to the most capable tier should be subject to such testing (while completely exempting less capable models, such as those from startups and academia). Whether open models actually pose higher risks, and whether those risks can be mitigated, should be determined through testing rather than presupposition—furthermore, promising methods may already exist to enhance the security of open-weights models, including recent collaborative research between AE Studio and Anthropic on modular training strategies. It should be noted that for testing to be truly effective, it must be implemented globally, meaning even the CCP would need to participate. I believe this is actually achievable: as I wrote in "The Adolescence of Technology," limited cooperation around preventing AI bioweapons is possible because it aligns with China's own interests.

This brings us to the open letter. I agree with many of the points in the letter: open weights broaden access to the AI economy, enhance competition at least in certain use cases, and give customers greater autonomy. Concerns regarding distillation should be addressed through targeted legal and commercial frameworks—the very measure I mentioned above. However, I do not agree with the letter's assertion that open-weights models are inherently more favorable for developing guardrails, or that the widespread accessibility of capabilities necessarily favors the defender over the attacker. In my view, it is at least equally likely that the opposite is true. For example, I am concerned about a severe offense-defense asymmetry in the biology domain: a sufficiently powerful model might be able to use widely available materials to rapidly weaponize a pandemic-tier virus, whereas defending against such pathogens, even under the best of circumstances, is an endeavor that takes years (as we saw with Operation Warp Speed)⁵. Issues like these should be answered through rigorous empirical testing prior to release, rather than by presupposing the answer.

To summarize the position of myself and Anthropic: we have not in the past, and will not now, advocate for a blanket ban on the category of open-weights models as a whole. Instead, we should focus on: preventing advanced chips from falling into the hands of authoritarian governments, curbing industrial-scale distillation operations, and requiring all models that reach a certain capability threshold—whether open or closed—to undergo safety testing.

*Editor's Note (Updated July 28): Updated to clarify that the research on modular training strategies mentioned in the text was a collaboration between Anthropic and AE Studio.

Replies (0)

No replies yet — be the first to comment

Post a reply