Anthropic declined to sign an industry letter opposing broad restrictions on open-weight AI. On July 27, 2026, Dario Amodei published the company's position paper, stating that Anthropic has never advocated a ban on open-weights models.
The letter was organized by Nvidia, co-authored by Jensen Huang, and backed by 77 companies, including Meta, Microsoft, Hugging Face, and Mistral. Anthropic's absence drew criticism and left it explaining whether it opposed open weights. Its paper makes a more specific argument: access to model weights shouldn't determine safety obligations on its own. A model's capabilities should matter, along with how states acquire and use those capabilities.
That position leaves room for open-weights development while proposing restrictions that could affect some frontier releases. The practical questions concern where those restrictions begin and whether enforcement can avoid disrupting legitimate work.
Two risks, three proposals
Amodei separates two national security concerns that often get mixed together in the open-weights debate.
- Military superiority risk: Authoritarian governments, specifically the Chinese Communist Party, developing AI systems more powerful than U.S. systems for military advantage or population control.
- Misuse risk: Powerful models enabling cyberattacks or biological weapons creation, with alignment failures adding to the danger. Alignment failures occur when a model behaves in ways that conflict with its intended goals or constraints.
His argument is that a blanket ban on open weights would address neither risk effectively. A government with enough resources can train its own models whether or not other developers release their weights. Misuse risks also apply to closed systems, including Anthropic's Claude.
Anthropic instead proposes three interventions:
- Stronger enforcement of chip export controls, including action against smuggling networks moving H100-class accelerators to China despite existing restrictions.
- Policy action against industrial-scale distillation operations backed by authoritarian states.
- Mandatory pre-release safety testing for all sufficiently capable models, whether open or closed and regardless of country of origin.
The export-control proposal builds on restrictions that have been tightening for several years. Amodei's emphasis on smuggling points to the gap between having those rules and enforcing them. The other two proposals raise less settled questions about how AI development should be regulated.
Distillation is useful, which makes restrictions difficult
Distillation trains a smaller model to reproduce a larger model's outputs and behavior. It can make useful capabilities available on more modest hardware. The technique itself isn't the target of Anthropic's proposal.
At state scale, however, distillation can weaken the effect of chip controls. A lab without enough hardware to train a frontier model from scratch may still build a capable system by distilling from another developer's open-weights release. Chinese labs have used distillation from Western open-weights releases to narrow the capability gap faster than their access to raw compute would otherwise have allowed.
Amodei's concern is specifically industrial-scale operations backed by authoritarian states. It isn't aimed at an individual researcher fine-tuning Llama on a workstation. Fine-tuning and distillation are different techniques, but the example helps show the intended scope: restrictions on state-backed capability development rather than ordinary model adaptation.
That distinction matters because a blanket restriction on distillation would disrupt legitimate development worldwide. Targeting operations that use it to build military-grade AI capabilities is a narrower proposal.
The difficulty is turning that intent into enforceable rules. The training technique doesn't provide an obvious technical boundary between legitimate development and state-sponsored capability transfer. Effective mechanisms for making that distinction aren't currently in place. Enforcement would therefore have to rely heavily on identifying and targeting organizations and their backers, rather than simply detecting a prohibited technical process.
Any legal framework would need to account for that limitation. Rules meant to constrain state-backed operations could also affect ordinary distillation workflows if their scope is too broad or their definitions are unclear.
Safety testing based on capability
Anthropic's third proposal would make capability the trigger for mandatory safety testing. An open-weights model wouldn't automatically face a different obligation from a closed model with comparable capabilities.
The paper's framework distinguishes a 7B parameter model helping a developer write Python from a system demonstrating synthesis-level capability in dangerous domains. In that view, the former should be treated as a public good, while the latter needs safety evaluation regardless of who built it or how its weights are distributed.
This is a useful basis for policy because capability thresholds track operational risk more closely than a simple open-versus-closed classification. Weight availability remains relevant to how a model can be used, but it doesn't describe everything the system can do.
The implementation is much less developed. Amodei raises the possibility of international organizations conducting evaluations, but the proposal leaves substantial questions about how those organizations would operate and how quickly they could be established. There is reason to doubt that such institutions could be built before motivated state actors cross the thresholds they are meant to oversee.
The threshold itself would determine much of the policy's effect. A well-calibrated rule could apply to a small number of frontier releases while leaving the broader open-source ecosystem untouched. A threshold set too low could make safety evaluation a significant barrier to open research.
That would also create a competitive advantage for closed-weights labs, including Anthropic. Universal testing requirements don't remove this conflict of interest. A closed-weights company is advocating release requirements that could delay competing open-weights models, and that deserves scrutiny.
The letter and Anthropic's decision
The 77-company letter opposed broad restrictions on open-weight AI. It didn't reject safety measures outright. In that respect, the letter and Anthropic's stated opposition to categorical bans have common ground.
One plausible explanation for Anthropic's refusal to sign is a disagreement about how far that support for openness should extend. The letter can be read as favoring openness across capability levels. Anthropic wants to preserve the option of requiring safety evaluations for high-capability frontier systems, even when those requirements would delay an open-weights release.
Signing a broad statement against restrictions could have weakened that position politically. On this reading, declining to sign was a decision to preserve room for the specific policies Anthropic supports. That is an interpretation of its motives, not an established explanation from the company.
The public response was difficult for Anthropic. As the only major AI lab not to sign, it faced questions about whether it favored a ban. Reporting on Amodei's response reflects the effort to clarify that position.
What could change for model developers
For developers, mandatory safety testing is the proposal with the clearest potential effect on releases. If the framework gains support in Washington, where Anthropic has policy relationships, releasing a sufficiently capable open-weights model could require passing an evaluation before making the weights public.
The practical burden would depend on the definition of sufficiently capable and the evaluation process. A narrow frontier threshold would affect relatively few releases. A more conservative threshold could constrain a much larger part of open research and development.
Distillation restrictions deserve similar attention. Their effects could reach beyond the state-backed operations they are intended to stop. Without a reliable technical way to distinguish acceptable from adversarial distillation, entity-level targeting would carry much of the enforcement burden. The proposal doesn't yet offer a convincing answer to that problem.
The Hacker News discussion following the paper illustrates how readily the debate becomes a dispute over whether Anthropic supports restrictions. It does support some restrictions. It also rejects a blanket ban. Support for open weights is compatible with targeted action against state-sponsored capability development and safety testing for sufficiently capable models.
Capability-based obligations offer a more useful framework than treating every open-weights release as the same policy problem. But that framework still needs workable thresholds, credible evaluations, and a response to the competitive interests of the companies proposing it. Those choices could shape which models remain available to developers in 2027 and beyond, and what it takes to release new ones.