3 min read

Anthropic rejects an open-weight AI ban but still wants a capability threshold

Dario Amodei rejects an open-weight AI ban, but wants capability-based safety testing, tighter chip controls, and cites a new Alibaba distillation claim.
Anthropic rejects an open-weight AI ban but still wants a capability threshold
Anthropic open-weight AI policy banner showing a capability threshold applied to open and closed models, alongside its alleged 28.8 million-exchange Alibaba/Qwen distillation campaign.

Anthropic CEO Dario Amodei said on July 27 that the company has never advocated banning open-weight AI models as a category. The statement came after Anthropic declined to join a large industry coalition defending open weights, leaving it as the most prominent frontier-lab holdout after OpenAI and Google added their names.

The immediate catalyst was Kimi K3. The Chinese model from Moonshot AI approached leading US systems on several benchmarks at a lower cost, supporting White House AI adviser David Sacks's argument that American regulation could leave Chinese labs ahead. Nvidia, Microsoft, Meta, OpenAI, Google, Hugging Face, Mistral, Palantir, and more than a hundred other organizations then signed the July 24 Open Weights and American AI Leadership letter.

Anthropic's absence fed accusations that its safety position would protect its closed-model business. Amodei's post is partly an answer to that pressure. He calls models without dangerous capabilities a public good, but rejects the coalition's argument that open weights necessarily make AI safer. Anthropic instead wants sufficiently capable models tested for cyber, biological, and alignment risks before release, whether open or closed.

Open weights are not the risk Anthropic wants to regulate first

Anthropic is not saying downloadable models are harmless. Once weights are released, safeguards can be removed, copies can spread, and access cannot be withdrawn. A highly capable open model may therefore create risks that a hosted provider can at least monitor or restrict.

At the same time, a US ban would do little to stop hostile governments or criminal groups from using weights already available elsewhere. It would mostly constrain businesses willing to follow the rule. Amodei acknowledges that it would also protect American model providers from competition.

Instead, he proposes keeping powerful chips and chipmaking equipment out of China, disrupting industrial-scale distillation, and testing frontier-capability models before release. The unresolved part is the threshold: regulators would still need to decide when testing becomes mandatory, which capabilities matter, and who measures them.

Distillation is becoming a separate policy target

Distillation uses a stronger model's outputs to improve another model. Anthropic says industrial-scale operations can help Chinese labs progress with less training compute, partially working around chip-export controls.

Anthropic's most recent allegation is considerably larger than its earlier disclosures. In a June 10 letter to the Senate Banking Committee, the company alleged that operators affiliated with Alibaba and its Qwen lab generated more than 28.8 million Claude exchanges through almost 25,000 fraudulent accounts between April 22 and June 5. Anthropic called it the largest distillation attack it had detected. By comparison, its February campaigns attributed to DeepSeek, Moonshot, and MiniMax involved more than 16 million exchanges combined.

Those figures describe traffic Anthropic says it attributed to the labs. They do not establish how much Qwen, Kimi, or any released model improved because of it. Researchers have disputed whether distillation alone explains the progress of recent Chinese models.

Amodei avoids treating open weights as proof that improper distillation occurred. He argues that legal and commercial measures should target the operation itself. That is more defensible than restricting resulting weights simply because they came from a Chinese company, though enforcement would still require evidence outsiders can examine.

The major labs also want an option to slow the frontier

This position sits alongside a broader warning from people inside competing AI labs. Amodei and several other Anthropic leaders have signed Pacing the Frontier, a July 28 statement asking the US government to support international mechanisms for deliberately slowing automated AI development if necessary. Its signatories also include OpenAI chief scientist Jakub Pachocki, Meta chief scientist Shengjia Zhao, and senior researchers from Google and Thinking Machines.

The employee signatures were personal, but Reuters reported that Anthropic and OpenAI subsequently issued corporate statements supporting the initiative. The letter does not call for an immediate pause or target open weights. It asks governments to prepare an option for coordinated pacing before automated AI research outruns existing oversight.

That reinforces the underlying policy argument: the relevant boundary should be frontier capability and emerging risk rather than whether weights are open or closed.

The response on Hacker News and Reddit's LocalLLaMA community shows why that remains contentious. Developers value the control and lower costs of open models, while critics worry that a capability threshold could let incumbent labs shape which competitors may release models.

Anthropic has now made its stated boundary clearer. The unresolved part is whether governments can define and enforce a capability threshold without turning safety testing into a market-access decision controlled by the largest model companies.