Not Advocating For Ban On Open Models, Says Anthropic CEO Dario Amodei After Being Isolated In Open Letter

Dario Amodei has spent the past few days watching his company get named, repeatedly, as the industry’s odd one out. First it was Anthropic and OpenAI missing from a 20-company letter backing open-weight models, shared by Jensen Huang. Then OpenAI itself signed on days later, leaving Anthropic as the lone major American AI lab sitting outside the letter. Along the way, an Anthropic researcher took a swing at NVIDIA and Microsoft over the letter, and got a pointed rebuttal back questioning why Anthropic hadn’t signed at all.

dario amodei

Now Amodei has written directly, in a post titled “Our position on open-weights models,” to knock down what he calls a specific accusation making the rounds: that Anthropic wants Chinese open-weights models banned in the US, and is dressing up its own commercial self-interest as a national security position.

“Anyone who has read my past writing should know that I don’t regard such bans as a useful measure, but let me state it clearly so that there is no doubt: Anthropic has never advocated for a ban on open-weights models,” he wrote.

The two things Amodei says actually worry him

Amodei lays out two concerns he says he has held consistently for years, pointing back to his essay The Adolescence of Technology from earlier in 2026. The first is that authoritarian governments, and specifically the Chinese Communist Party, could build AI systems more powerful than anything the US produces and use that edge for military dominance or domestic repression. He cites Vice President Vance’s Paris remarks about authoritarian regimes using stolen AI for military and surveillance purposes, along with a line from the Intelligence Community’s 2026 Annual Threat Assessment on China’s AI progress challenging US competitiveness.

His second concern is that powerful models, wherever they come from, could be misused for cyberattacks or bioweapons work, or could carry serious alignment failures of their own. He argues open-weights models raise this risk specifically because once the weights are out, there is no way to monitor how they’re used or pull them back. He leans on a UK AI Security Institute report to make the point that closed labs can restrict access and patch safeguards as problems surface, while an open release forfeits that option permanently.

Whether either of these problems has anything to do with US businesses running open models, in his framing, is beside the point. A ban on US companies using open-weights models does nothing about a model trained by a state actor and handed straight to a military or intelligence service.

What Amodei says he actually wants

In place of a ban, Amodei lists three things Anthropic has pushed for and continues to push for. Keep advanced chips and chipmaking equipment out of China, and go after the smuggling networks that get around existing export controls. Crack down on large-scale distillation operations, which he argues let Chinese labs compress the gap to the US frontier without matching US compute. And require mandatory safety testing, on cyber, biological and alignment risk, for any sufficiently capable model before release, regardless of whether it’s open or closed, or where it comes from.

That third point is where he tries to draw the sharpest distinction with critics. He argues the question of whether open models are inherently riskier than closed ones is something that should be settled through testing, not decided in advance by a blanket rule. He also flags what he describes as recent Anthropic research into modular training strategies aimed at making open-weights models safer, positioning the company as working on the problem rather than just flagging it.

The distillation point lands in the middle of an active fight. Anthropic has spent months pushing Washington on distillation by DeepSeek, Moonshot AI and MiniMax, and the timing of this post follows the White House accusing Moonshot of distilling Claude Fable 5 to build Kimi K3, with Treasury Secretary Scott Bessent floating sanctions. Amodei is careful in this post to separate that fight from the open-weights debate itself, arguing that the problem is the state backing behind the distillation campaigns, not the open license the resulting models ship under.

Where he still disagrees with the letter

Amodei doesn’t pretend the disagreement is entirely a misreading. He says he agrees with parts of the open letter, that open weights expand access, add competitive pressure, and give customers more control. Where he splits from it is on the letter’s claim that open access makes it easier to build safeguards and generally helps defenders more than attackers. He thinks the opposite could just as easily be true, and raises biology as his example: a model capable enough to help weaponize a pathogen using materials that are already available could move much faster than any realistic defensive response, pointing to Operation Warp Speed as a benchmark for how long organized defense actually takes.

It’s a deliberately narrow post. Amodei isn’t trying to win back the companies that signed the NVIDIA-led letter, and he isn’t retracting anything Anthropic has said about distillation by Chinese labs. He’s drawing a line between two things that had started to blur together in public commentary: not signing a letter that champions unrestricted open access, and calling for open models to be banned outright. Those aren’t the same position, and the post is Amodei’s attempt to make sure people stop treating them as one.

Posted in AI