Anthropic’s Position on Open-Weights Models

Anthropic CEO Dario Amodei clarifies that the company has never advocated for a ban on open-weights models, despite recent discussions and an open letter suggesting otherwise. He notes that open-weights models without dangerous capabilities are a public good, providing value at low cost.

Amodei identifies two primary national security concerns. The first is the risk that authoritarian governments, particularly China, build AI models more powerful than those of the US and use them for military superiority or deep repression. He argues this threat is independent of whether models are open-weights or used by US businesses, as the most dangerous model might be trained in secret for military and surveillance use. The second concern is that powerful AI models could be misused for cyber or biological attacks, with open-weights models presenting higher risk due to difficulty in applying guardrails. However, he states that banning their use by US businesses does not address this, as bad actors are not legitimate US businesses.

Instead, Amodei supports three specific measures. First, blocking sales of powerful chips and chipmaking equipment to China and cracking down on smuggling, as China cannot build more powerful models without US chips due to scaling laws. Second, stopping industrial-scale distillation operations, which allow China to build better models than its chip count would normally enable, partially evading chip bans. He stresses a blanket ban on open-weights models is neither the correct remedy nor something Anthropic has called for. Third, requiring mandatory safety testing for all sufficiently capable models, both open and closed, testing for cyber, biological, and alignment risks before release. He believes such testing should be global and could be possible with China’s cooperation on biological weapons prevention.

Amodei agrees with parts of the open letter supporting open-weights models—expanding access, strengthening competition, and giving customers control—but disagrees that open-weights models necessarily aid defenders more than attackers, citing potential attacker-defender asymmetry in biology. He concludes by reiterating his position: no ban on open-weights models as a category, but a focus on keeping chips from authoritarian states, stopping distillation, and requiring safety testing for capable models.

Our position on open-weights models

View Original