Anthropic Position on Open-Weights Models

Anthropic has explicitly stated that it does not advocate for a ban on open-weights models. CEO Dario Amodei asserts that open-weights models without dangerous capabilities serve as a public good by providing value to researchers, developers, and businesses without cost beyond the required compute.

National Security Concerns and the Limitations of Bans

Anthropic identifies two primary national security risks that protectionist bans on open-weights models would fail to address:

1. Authoritarian Military and Surveillance Superiority

The primary concern is that authoritarian governments—specifically the Chinese Communist Party (CCP)—could develop AI models more powerful than those in the US to achieve permanent military superiority or implement deep internal repression. Amodei notes that the most dangerous models are likely those trained in secret and reserved for state security and military use (such as drones), making the open-weights status or the use of these models by US businesses irrelevant to this specific threat.

2. Misuse for Cyber and Biological Attacks

The secondary concern involves the risk of powerful AI models being misused for cyberattacks, biological attacks, or suffering from serious alignment problems. While open-weights models may present a higher risk than closed models because guardrails are harder to apply and weights cannot be withdrawn once released, banning their use by US businesses does not mitigate this risk, as bad actors are unlikely to be legitimate US businesses.

Proposed Policy Measures for AI Safety and Security

Rather than a blanket ban on open-weights models, Anthropic advocates for three specific strategic measures:

Restricted Access to Hardware

Anthropic supports prohibiting the sale of powerful chips and chipmaking equipment to China and cracking down on smuggling and workarounds. Because of scaling laws, China cannot build models more powerful than the US without access to these chips, making this the most direct way to block the development of superior authoritarian AI.

Deterring Industrial-Scale Distillation

Anthropic calls for policy interventions to deter industrial-scale distillation operations. Distillation allows authoritarian states to build better models than their available hardware would normally permit, potentially bringing the Chinese frontier within a few months of the US frontier. Amodei clarifies that while some companies performing distillation release open-weights models, the core issue is the state-backed effort to overtake the US frontier, not the open nature of the weights.

Mandatory Safety Testing for Capable Models

Anthropic proposes that all sufficiently capable models, regardless of whether they are open or closed weights or their country of origin, undergo mandatory safety testing for biological, cyber, and alignment risks before release. Amodei suggests that limited global cooperation, including with China, may be possible regarding the prevention of AI-driven biological weapons, as it is in China's own interest to avoid such outcomes.

Perspective on the Open-Weights Debate

In response to an open letter supporting open-weights models, Amodei agrees that open weights expand economic access and strengthen competition. However, he disputes the claim that open-weights models necessarily make it easier to develop safeguards or that they benefit defenders more than attackers.

Amodei highlights a specific "attacker-defender asymmetry" in biology, where a capable model could quickly weaponize a virus, while the defense (such as vaccine development) is a multi-year operational task. He argues that these risks should be determined through empirical pre-release testing rather than assumed in advance.

Sources

Related

  • Dispatch
  • Dispatch
  • Dispatch
  • Dispatch
  • Dispatch