Anthropic did not sign the industry letter against restricting open models — but Dario Amodei says the company has never asked for a ban, and wants mandatory testing of the most capable models instead.
Anthropic chief executive Dario Amodei said in a post on Monday that his company does not want models with openly published weights outlawed, and has never asked for that.
The post answers reports that US officials are weighing a ban on Chinese open-weight models for use by American companies, and an open letter that Nvidia chief executive Jensen Huang put into circulation on Friday, in the first post he had ever made on X. Nvidia, Hugging Face, Meta, Microsoft, Mistral and other AI firms signed it, urging policymakers to hold off on sweeping curbs on openly released models rather than impose them too soon. OpenAI added its name afterwards. Anthropic did not sign.
In place of a ban, Amodei set out three measures. The first, restricting China's access to powerful chips, is already long-standing US policy; the second targets distillation carried out at industrial scale — one model flooding another with prompts to work out how it operates. That technique is one of the methods invoked in the industry's argument that Chinese labs are gaining capability in part by taking intellectual property from US firms.
The third, mandatory testing, is by his account close to agreed on all sides. He took encouragement from steps Trump's administration has taken along those lines over the past few months and from industry plans that would put the most capable models through such testing whatever country built them and whether or not their weights are public, while leaving weaker models — those from startups and academic labs, for instance — outside the requirement.
Open-weight models that carry no dangerous capabilities are a public good, he wrote, costing nothing beyond the computing power needed to run them and useful to companies, developers and researchers. What worries him is not businesses using open models, Chinese ones included, but authoritarian governments building models more powerful than those in the US and using them to secure military superiority or to repress their own populations — the Chinese Communist Party being the most capable of them, though not the only one that worries him.
None of that puts him with the open-source case that publishing weights makes defenses easier to build, or that broad access to AI capability helps defenders more than attackers. His concern is that AI could enable biological attacks on top of cyber threats, and that open-weight models are particularly dangerous in those scenarios, because safeguards and monitoring of how a model is used are hard to attach to them. Citing a report from the UK AI Security Institute, he noted that weights, once released, cannot be withdrawn.
Mandatory testing would only do its job if it operated worldwide, he wrote, which means even the Chinese Communist Party would have to take part. He thinks narrow cooperation on heading off AI-enabled biological weapons could be within reach, because China's own interests are served by it too.