179 startups warn a Chinese AI ban would help incumbents, not America
The Little Tech Association on July 22 sent a letter to OSTP Director Michael Kratsios and Commerce Secretary Howard Lutnick, copying President Trump, Vice President JD Vance, and National Cyber Director Sean Cairncross. It asked the US government not to cut American developers off from open-weight AI models released abroad.
The letter was signed by 179 founders and member companies, including Y Combinator, Proton, Vivaldi, ParadeDB, Mem0, and a long list of smaller AI companies. It arrived on the same day that White House science adviser Michael Kratsios made a specific allegation against Moonshot AI. He said the company had built an internal platform for large-scale distillation against American models, including Anthropic's Fable, switched between access methods to avoid detection, and acquired or accessed servers using export-controlled Nvidia GB300 chips, including infrastructure in Thailand. Kratsios did not publish the evidence behind those claims, and Moonshot did not respond to questions from TechCrunch.
The founders are not arguing that every model should be usable everywhere without restrictions. Their narrower point is that controls should follow specific risks, including who is operating the model, where it is deployed, and what capabilities it has, rather than blocking American companies from downloading weights that remain available elsewhere.
That distinction matters. A restriction that China and other countries do not follow may constrain US developers without meaningfully containing the model.
Model access is becoming a startup dependency
Open weights give a company more options than a hosted API. A team can switch inference providers, run the model inside a customer's network, examine its behavior, fine-tune it for a specialized task, or continue operating if a vendor changes its prices.
The association's letter says that "nearly half of responding companies" in a recent Y Combinator founder survey run most of their production workloads on open-weight models. It says those deployments overwhelmingly use American inference providers or the companies' own hardware. The letter does not provide the number of respondents, survey questions, or methodology, so the figure is useful as the coalition's evidence of dependency rather than a measurement of the wider startup market.
This is the practical concern behind the letter. A startup may use a Chinese model without sending production data to a Chinese service. It can download the weights and run them through a US provider or on infrastructure it controls.
A blanket access restriction would remove that option. It would not merely affect researchers experimenting with models on local GPUs. It could change the cost structure of products already built around cheaper open models.
Politico reported that a blanket ban was not seriously discussed inside the administration. Still, the industry's concern is understandable because sanctions, model-provenance rules, or restrictions on providers could create much the same result without being described as a download ban.
Open weights make conventional controls awkward
Once model weights are published, they can be copied between hosting providers and across borders. A rule aimed at the original developer does not make every copy disappear.
The letter therefore proposes concentrating controls where the government can observe and enforce them: frontier-scale hosted inference, access to controlled computing infrastructure, prohibited users, government procurement, and sensitive deployments. It also supports stronger requirements when a model remains remotely operated by a company under a foreign adversary's jurisdiction.
This is not a complete answer to the security problem. Open-weight models can be modified to remove safeguards, and their developers cannot revoke access after release. Anthropic has repeatedly emphasized this point. OpenAI and Anthropic are now both urging Washington to take the risks of powerful Chinese open models seriously.
But restrictions also have a market effect. Closed-model providers benefit when developers have fewer alternatives. That does not make their security concerns false, but it means policymakers should ask whether a proposed control reduces a measurable risk or mainly redirects customers toward a small group of approved vendors.
The HN debate gets to the enforcement problem
The Hacker News discussion around the letter is unusually active. Much of it focuses on a basic enforcement question: how does a government prevent the movement of files that have already been distributed globally?
Some commenters argue that restrictions would mostly bind US companies willing to comply, while independent developers and foreign competitors would continue obtaining the same models. Others support limits for defense, critical infrastructure, and other settings where model provenance or foreign control creates a more concrete risk.
There is also considerable skepticism around describing model distillation as intellectual-property theft when leading AI systems were themselves trained on large quantities of material without conventional licensing. The technical claim is disputed too. Braden Hancock of the Laude Institute told TechCrunch that Fable had been publicly available only since July 1, leaving too little time to distill enough data, train K3, and release it two weeks later. AI researcher Nathan Lambert argued that simple supervised fine-tuning cannot explain the capabilities of current frontier models and that reinforcement-learning distillation at that scale would be slow and extremely expensive.
Neither argument proves that Moonshot did no distillation. Anthropic had previously said it detected millions of unusual exchanges associated with Moonshot and other Chinese labs. But no public evidence currently shows how much, if any, of K3's performance came from Fable. That uncertainty matters when the allegation is being used in a debate about restricting access to the resulting model.
The useful question is not whether Chinese open-weight models are entirely safe. They are not. It is whether restricting access to the weights would reduce those risks enough to justify leaving American startups with fewer and more expensive model choices. The government has not proposed a blanket ban, but if it moves in that direction, it will need a better answer than assuming published weights can be contained like access to a hosted service.
Member discussion