A post by Dario Amodei, Anthropic CEO
Amid recent debate about open-weights models-particularly those originating from China-reports indicate that some US officials are considering banning Chinese open-weights models from use by American companies. In response, a number of tech companies signed a letter in support of open-weights models, and some have even accused Anthropic of wanting to ban them to shield its business. As Amodei notes, anyone familiar with his past writing should recognize that he does not view such bans as useful. He states unequivocally: Anthropic has never advocated for a ban on open-weights models.
Open-weights models lacking dangerous capabilities are a public good-they cost nothing beyond the compute required to run them and deliver value to businesses, developers, and researchers.
Protectionist bans would not address Amodei's most serious national security concerns. He identifies two nightmare scenarios, previously outlined in his essay The Adolescence of Technology six months prior, positions he says he has held consistently for years:
The primary concern is that authoritarian governments-not exclusively the Chinese Communist Party (CCP), though it represents the most capable threat-could build AI models surpassing those made in the US and leverage them for permanent military superiority or deep repression of their own citizens. This worry is broadly shared in the US government: Vice President Vance warned in Paris that "authoritarian regimes have stolen and used AI to strengthen their military, intelligence, and surveillance capabilities," and the Intelligence Community's 2026 Annual Threat Assessment found that other global powers' AI progress is challenging US competitiveness and security advantages. Whether these models use open weights is irrelevant, and it certainly does not matter whether US businesses use them. The most dangerous model might be one trained secretly and provided only to the People's Liberation Army for drones or the Ministry of State Security for surveillance and repression.
The secondary concern involves powerful AI models being misused for cyberattacks or biological attacks, along with serious alignment problems. Open-weights models-regardless of origin-do carry a potentially higher risk than closed models because applying guardrails and monitoring usage is very difficult, and once weights are released they cannot be recalled[^2]. However, banning US businesses from using these models does nothing to mitigate this risk, since bad actors are unlikely to be legitimate US companies. Such a ban would protect US AI companies from competition, but that has never been Anthropic's objective.
To address these concerns, Amodei supports three measures that he and Anthropic have consistently advocated:
Restricting sales of powerful chips and chipmaking equipment to China, and cracking down on rampant smuggling[^3] and workarounds used to access such chips. China's limited domestic production capacity means that, due to scaling laws, it cannot build more powerful models than the US without US chips. This is the most efficient and direct way to block the first threat, and by hampering the training of models beyond the reach of US law, it also indirectly helps with the second threat.
Cracking down on industrial-scale distillation operations. Distillation is far more compute-efficient than training models from scratch, allowing China to build much better models than its chip supply would ordinarily permit, thus partially evading chip bans. Distillation does not enable the CCP to match or surpass US AI capabilities, but it can bring the Chinese frontier to within a few months of the US frontier. While many companies conducting these operations release open-weights models, the open weights matter far less than the fact that these operations are backed by an authoritarian state seeking to overtake the US at the frontier. Targeted policy interventions should deter this behavior. A blanket ban on open-weights models is neither the right remedy nor something Anthropic has called for[^4].
Mandatory safety testing for all sufficiently capable models, open and closed. The best way to address the second threat is to directly test models for cyber, biological, and alignment risks before release. Amodei believes this idea is close to consensus and has been encouraged that the Trump administration has moved in this direction in recent months, as well as by recent industry proposals that would apply testing to the most capable models regardless of origin or openness, while exempting less capable models from startups and academia entirely. Whether open models pose an increased risk, and whether that risk can be mitigated, should emerge from testing rather than be assumed-and promising methods for improving open-weights model safety exist, including recent Anthropic research on modular training strategies. For testing to be effective, it would need to be global, including CCP participation. Amodei believes this may actually be achievable: as he wrote in The Adolescence of Technology, limited cooperation around preventing AI-enabled biological weapons may be possible because it serves China's interest too.
Regarding the open letter, Amodei agrees with much of it: open weights broaden access to the AI economy, strengthen competition for certain use cases, and give customers greater control. Concerns about distillation should be addressed through targeted legal and commercial frameworks-the same measure described above. However, he disagrees with the letter's assertions that open-weights models necessarily make safeguard development easier or that broad access to capabilities necessarily advantages defenders over attackers. The opposite may well be true. For instance, biology may exhibit a strong attacker-defender asymmetry, where sufficiently capable models could quickly weaponize pandemic-level viruses using widely available materials, while defense against such agents is a multi-year operational challenge at best (as demonstrated by Operation Warp Speed)[^5]. Such questions should be empirically answered through rigorous pre-release testing, not assumed in advance.
In summary, Anthropic has not and is not advocating for a ban on open-weights models as a category. The focus should instead be on keeping powerful chips out of authoritarian hands, stopping industrial-scale distillation, and requiring safety testing for all sufficiently capable models, whether open or closed.
[^2]: See this report from the UK AI Security Institute, specifically: "The same openness underpinning these benefits precludes many of the safety measures that closed model developers can use to detect and disrupt misuse, iterate on safeguards as vulnerabilities emerge, control user access and withdraw models. Once open-weight models are released, these options are lost permanently: safeguards can be removed, and copies can be downloaded, redistributed, and run on private systems beyond monitoring. For models with dangerous capabilities – including highly cyber-capable models – open weight release therefore creates a persistent and irreversible risk of misuse."
[^3]: See also here, here, and here for additional US Department of Justice reports.
[^4]: Anthropic is committed to cracking down on industrial-scale distillation through its own practices, including identifying and banning accounts that use its models in this way. This is challenging-relevant accounts can often only be identified after substantial distillation has occurred, and distillation frequently involves creating large numbers of fake accounts that form a moving target. No individual company's practices can entirely solve the problem, which is why Anthropic has called for policy intervention on this issue.
[^5]: See Section 2 of The Adolescence of Technology.