Anthropic CEO Dario Amodei pushed back Monday against accusations that his company has sought to restrict open-weight artificial intelligence models, while laying out a narrower set of policies he does support — including mandatory safety testing for all capable AI systems, open or closed.
"Let me state it clearly so that there is no doubt: Anthropic has never advocated for a ban on open-weights models," Amodei wrote in a blog post. He called open-weight models without dangerous capabilities "a public good" and said protectionist bans "would not address my most serious national security concerns."
Anthropic had come under pressure after declining to sign an industry letter, released last Friday, urging policymakers to avoid restricting open-weight models. The letter was backed by Nvidia $NVDA, Microsoft $MSFT, Meta $META, and Palantir $PLTR, among others. Google $GOOGL and OpenAI, which initially did not sign, added their names over the weekend, according to Axios. Anthropic still has not signed. The letter's release was triggered in part by the debut of Kimi K3, a Chinese open-weight model from Moonshot AI that approached frontier performance from U.S. competitors at lower cost.
Former White House AI adviser David Sacks had suggested Anthropic was using safety concerns to shield its closed-model business from competition, according to Bloomberg. Amodei denied that characterization and acknowledged that a ban "would protect U.S. AI companies from competition, but that has never been my goal."
Instead of a ban, Amodei outlined three policies he said would better address his concerns. First, he called for tighter controls on advanced chips and chipmaking equipment flowing to authoritarian governments, arguing that chip restrictions are the most direct way to prevent rival states from building more powerful AI. Second, he called for a crackdown on what he described as industrial-scale distillation — a process in which a smaller model is trained using outputs from a larger, more capable one. Amodei argued that distillation gives China a way to extract capability from American frontier models, reducing the effectiveness of export controls on chips. Last month, Anthropic sent a letter to the U.S. Senate alleging that Alibaba had carried out "the largest known distillation attack" against it, according to CNBC.
Third, Amodei said all sufficiently capable models — regardless of origin or whether they are open or closed — should undergo mandatory safety testing before release, with less capable models from startups and academia exempted. He said the purpose of such testing would be to evaluate the actual risk profile of open-weight models through evidence, not to treat restriction as a foregone conclusion.
Amodei said he agrees with portions of the industry letter, including its view that open-weight models expand access to the AI economy and give customers greater control. He said he disagrees, however, with the letter's assertion that open-weight models make it easier to develop safeguards or that broad access to AI capabilities favors cyber defenders over attackers. He cited biological threats as a case where attackers may hold a structural advantage that a sufficiently powerful AI model could exploit.
