The AI industry split in public this week over whether open-weight models should be restricted. On July 24, NVIDIA, Microsoft, Meta, Palantir and more than 20 other companies published the 'Open Weights and American AI Leadership' letter urging Washington not to impose premature restrictions (Microsoft, 2026). As of July 30, more than 230 companies and organizations had signed it (Microsoft, 2026).

The trigger is China. Moonshot's Kimi K3 is the world's most powerful open-weight model, and US officials are weighing a ban on Chinese open-weight models (Axios, 2026). Anthropic is the one major lab that has not signed the letter, and its CEO spent the weekend defending that decision.

What is an open-weight model, exactly?

An open-weight model is an AI model anyone can download, inspect, modify, and run on their own infrastructure (Microsoft, 2026). Unlike a proprietary API, the trained weights are public, so users are not locked to a provider. It differs from open source in licensing terms, but the practical consequence is the same: once weights are released, they cannot be withdrawn.

That irreversibility is the crux of the debate. Open weights let startups and researchers compete on equal footing with trillion-dollar companies. But they also mean bad actors can strip safety guardrails and run the same powerful models without restrictions. The tension between these two realities is what makes the policy fight so heated.

230+Companies and organizations that signed the open-weights letter by July 30, 2026 · signatories

Who signed the open letter, and who refused?

The initial 25 signatories included NVIDIA, Microsoft, Meta, Mistral, Palantir, IBM, Andreessen Horowitz, Hugging Face, Mozilla and the Linux Foundation, fronted by Jensen Huang's first-ever post on X, which drew more than 11 million views (CNBC, 2026). Over the weekend OpenAI and Google added their names, leaving Anthropic as the only major holdout (Business Insider, 2026).

The full signatory list, published by Microsoft, spans 230 organizations across cloud providers, chip companies, venture capital firms, open-source foundations, and AI startups. Amazon, Databricks, Cloudflare, GitHub, GitLab, Red Hat, Snowflake, Uber, and SpaceX CEO Elon Musk all expressed support, though SpaceX did not officially sign (CNBC, 2026).

Where the major AI companies landed on the open-weights letter
CompanyPositionSigned
NVIDIAOpenYes (July 24)
MicrosoftOpenYes (July 24)
MetaOpenYes (July 24)
OpenAIMixedYes (July 27)
GoogleMixedYes (July 27)
AnthropicClosed-leaningNo

Why is Anthropic the holdout?

Anthropic CEO Dario Amodei published a position post on July 27 saying the company has never advocated for a ban on open-weights models as a category (Anthropic, 2026). His concern is authoritarian governments building capable models and using them for repression, cyberattacks, or biological weapons. He argues for keeping powerful chips out of hostile hands, cracking down on industrial-scale distillation, and mandatory safety testing for all sufficiently capable models.

Anthropic has never advocated for a ban on open-weights models as a category.

Dario Amodei, Anthropic CEO

Critics read the position as commerce. Benchmark's Bill Gurley said Anthropic's reluctance reflects that open weights compete with its corporate economic strategy (The Next Web, 2026). Both Anthropic and OpenAI have confidentially filed for IPOs, and both companies generate revenue from API access to closed models. Open weights undermine that business model by letting customers run competing models on their own hardware.

White House AI adviser David Sacks put it bluntly on X: 'We are at a critical inflection point in AI policy. The leading closed labs, already a duopoly in terms of AI model revenue, want the government to eliminate their open-source competition' (Axios, 2026). Six weeks earlier, when the US government ordered Anthropic to restrict Fable 5 and Mythos 5, the company called it disproportionate and warned it could halt all new model deployments.

What did the Hugging Face breach reveal about open weights?

The strongest real-world argument for open weights came from a security incident, not a lobbyist. On July 16, Hugging Face disclosed that an autonomous AI agent breached its production infrastructure through a malicious dataset that exploited two code-execution paths in its data-processing pipeline (Hugging Face, 2026). The attacker ran tens of thousands of individual actions across a swarm of short-lived sandboxes.

When Hugging Face's security team tried to analyze the attack using frontier models, they hit a wall. Anthropic's Fable 5 and other closed models refused to process the exploit payloads because their guardrails could not distinguish an incident responder from an attacker (CNBC, 2026). The team switched to GLM 5.2, an open-weight model from Chinese company Z.ai, run on their own infrastructure, and reconstructed more than 17,600 attacker actions.

The attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried.

Hugging Face security team

That experience became the founding case for the Open Secure AI Alliance, which NVIDIA launched with 37 members the following Monday (The Register, 2026). Anthropic did not join. The incident also raised uncomfortable questions: if the most capable defensive model happens to be a Chinese open-weight system, should the US restrict access to it?

How does Kimi K3 fit into the fight?

Moonshot AI, a Beijing-based startup valued at more than $20 billion after a $2 billion funding round in May 2026, released Kimi K3 on July 17 (Bloomberg, 2026). The model has 2.8 trillion parameters, making it China's largest AI model, and it outperformed Claude Opus 4.8 and GPT 5.5 on coding and general agent benchmarks, according to Moonshot (CNBC, 2026).

Bank of America analysts called the release a step-change for Chinese AI despite persistent hardware constraints. But the model also reignited fears about IP theft. White House advisor Michael Kratsios accused Moonshot of developing Kimi K3 by distilling Anthropic's technology, a process where a smaller model learns from a larger one's outputs (CNBC, 2026). Moonshot has not responded to the accusation.

2.8TParameters in Moonshot's Kimi K3, China's largest AI model · parameters

The Trump administration has considered multiple approaches to limit Chinese open-weight models. The Commerce Department previously explored adding Chinese AI labs to the Entity List, the National Security Agency considered issuing an advisory on Chinese AI threats, and the White House weighed an executive order requiring US companies to guarantee security when hosting Chinese models (Axios, 2026). All of those efforts were killed by officials worried about stifling innovation.

Can open-weight models be safe?

The letter argues openness is a safety feature: closed models can be breached, misused, or fail in ways outsiders cannot detect, and concentrating capability in a few providers creates single points of failure (Microsoft, 2026). Amodei counters that biology has an attacker-defender asymmetry and that the safety case should be settled by empirical pre-release testing, not assumed in advance (Anthropic, 2026).

Both sides have a point. Open weights let thousands of researchers probe for vulnerabilities that a single company's safety team might miss. But once guardrails are removed, there is no recall mechanism. The UK AI Security Institute warned that 'once open-weight models are released, these options are lost permanently: safeguards can be removed, and copies can be downloaded, redistributed, and run on private systems beyond monitoring' (Anthropic, 2026).

Amodei proposed three policy pillars: stop selling powerful chips to China, crack down on industrial-scale distillation, and require mandatory safety testing for all capable models regardless of whether they are open or closed. He argued these measures would be more effective than blanket restrictions on open weights, and noted that some cooperation with China on AI biological weapons may be possible because it is in Beijing's interest too.

What is the bottom line?

The open-weights fight is really a fight over who controls the frontier. More than 230 companies want open models because they win when competition is broad; Anthropic wants gated access because it wins when capability stays concentrated. China's Kimi K3 has made the question concrete, and Washington's answer will shape the entire industry. Expect more signatories, more open releases, and a louder argument before it is settled.

Written by

AI Correspondent

Covers frontier models and the humans behind them. Former ML engineer, reformed speedrunner.

Bottom line

The open-weights fight is really a fight over who controls the frontier. More than 230 companies want open models because they win when competition is broad; Anthropic wants gated access because it wins when capability stays concentrated. China's Kimi K3 has made the question concrete, and Washington's answer will shape the entire industry. Expect more signatories, more open releases, and a louder argument before it is settled.

What we still don't know

This is a fast-moving story. We update the post as new facts land — and we'll flag it when we do.

Enjoyed this? Pay it forward

A sharp story is worth passing on. Share it with the people who read tech like it matters.

Read moreShare on X