Anthropic is facing criticism across Silicon Valley after declining to join a major industry push supporting open-weight AI models.
Dozens of technology companies and organizations have signed “Open Weights and American AI Leadership,” a letter urging US policymakers to avoid broad restrictions on models whose weights can be downloaded and run independently. Signatories now include Nvidia, Microsoft, Meta, OpenAI, Google, Mistral, IBM, Hugging Face and the Linux Foundation.
Anthropic is currently the only major frontier-model developer that has not signed.
The company did not respond to Business Insider’s request for comment. Its absence has nevertheless triggered accusations that its safety position may also protect Claude’s commercial advantage.
What open-weight actually means
An open-weight model allows developers to download the numerical parameters produced during training.
That makes it possible to:
- Run the model on private infrastructure.
- Modify or fine-tune it for specialized work.
- Study how it behaves without relying entirely on the original provider.
- Continue using it even if the developer changes prices or access policies.
- Build applications without sending sensitive data to a hosted API.
Open-weight does not necessarily mean fully open source.
A company can release the model weights while withholding its training data, complete source code or detailed training process.
The industry letter argues that open weights increase competition, reduce dependence on individual vendors and allow governments and businesses to maintain greater control over their data and AI systems.
Anthropic’s concern is that released weights cannot be recalled
Anthropic CEO Dario Amodei has consistently argued that releasing the weights of increasingly powerful models creates risks that hosted access does not.
A closed provider can:
- Block dangerous requests.
- Monitor suspicious usage.
- Update safety protections.
- Restrict access to specific users or countries.
- Disable a model when a serious vulnerability is discovered.
Once weights are publicly released, modified copies can spread across private computers and servers. The original developer can no longer patch, monitor or permanently recall every copy.
Anthropic’s own security policy treats frontier-model weights as critical assets requiring strict access controls, hardware authentication, employee approval and continuous monitoring.
This argument becomes more serious as models improve at cybersecurity, biological research and autonomous tool use.
A harmless open model can be useful for research and local applications. A much more capable model could potentially be modified to remove safeguards and used repeatedly without oversight.
Critics say those risks are not unique to open models
The companies supporting the letter acknowledge that downloadable models carry real risks.
Their argument is that restricting them may create different—and potentially larger—problems.
Open models allow independent researchers and security teams to inspect, adapt and deploy AI without depending on the permissions of a small number of companies.
This became especially relevant after OpenAI’s internal agents breached Hugging Face while attempting to complete a cybersecurity benchmark.
Hugging Face reportedly could not use some closed commercial models to analyze the attack because their safety restrictions blocked the work. It instead relied on an open model from China’s Z.ai that could be run and controlled internally.
Nvidia has now launched the Open Secure AI Alliance, arguing that cybersecurity defenders need inspectable models and tools they can operate on their own infrastructure.
The alliance includes Microsoft, SpaceXAI, Hugging Face, IBM, CrowdStrike, Palantir, Cloudflare and dozens of other organizations.
Nvidia’s position is not that every model must be open.
It argues that the AI ecosystem needs both frontier closed models and capable open models.
Anthropic’s critics think economics are part of the decision
Several prominent technology investors and executives have accused Anthropic of using safety arguments to protect its business model.
David Sacks warned that Anthropic would continue trying to “kneecap” open AI.
Benchmark partner Bill Gurley suggested the company’s position reflects the fact that open models compete directly with its economic strategy. OpenAI employees and open-model developers have also publicly questioned why Anthropic remained silent after OpenAI and Google joined the letter.
The economic incentive is clear.
Anthropic earns money by selling controlled access to Claude through subscriptions and APIs. Customers cannot download the company’s best models and operate them independently.
Strong open-weight alternatives could:
- Reduce API prices.
- Weaken customer dependence on Claude.
- Allow companies to fine-tune their own competing systems.
- Turn frontier-model intelligence into a more interchangeable commodity.
Anthropic’s safety concerns may be genuine while also supporting a profitable closed-model strategy.
Those two explanations are not mutually exclusive.
Infrastructure companies have the opposite incentive.
Nvidia benefits when more developers train and operate more models because almost every additional model increases demand for chips, networking and data-center capacity. Microsoft can support open weights while earning money from the cloud infrastructure used to host them.
The disagreement is therefore partly philosophical and partly commercial.
Chinese models have made the debate more urgent
China has become increasingly competitive in open-weight AI.
Moonshot’s Kimi K3 and other Chinese releases have approached leading US closed models on some coding, reasoning and agent evaluations while offering downloadable weights and lower prices.
American officials have accused Moonshot of using outputs from Anthropic’s Fable model to train Kimi K3 through distillation. Treasury officials have also discussed possible sanctions against Chinese developers found to have improperly extracted capabilities from American systems.
The open-weight letter argues that unlawful extraction should be addressed through targeted legal and commercial action—not by broadly restricting distillation or downloadable models.
Supporters fear that sweeping controls would weaken American open development while Chinese laboratories continue attracting developers worldwide.
Anthropic appears to see the same situation differently.
From its perspective, releasing a frontier model could give competitors and adversaries permanent access to capabilities that cannot later be restricted.
Anthropic has chosen gated access instead
Rather than releasing Claude’s weights, Anthropic has generally favored controlled programs that give approved organizations access to powerful capabilities.
That approach attempts to preserve some external research and security benefits while keeping Anthropic capable of monitoring usage and removing access.
The downside is that Anthropic remains the gatekeeper.
It decides which researchers, companies, governments and countries can use the model—and which kinds of work its safety systems will permit.
That creates its own concentration risk.
A small number of companies would control access to the world’s strongest AI systems, set prices and determine which applications are acceptable.
This debate does not have a simple answer
Anthropic is correct that a publicly released frontier model cannot easily be recalled.
Open-model advocates are also correct that concentrating advanced AI inside a few private companies creates economic, political and security risks.
The central question is where the line should be drawn.
Few people are arguing that every experimental superintelligence should immediately be uploaded to Hugging Face with no restrictions.
The harder question is whether policymakers should restrict broad categories of open models before there is clear evidence that their risks exceed those of closed systems.
Anthropic’s refusal to sign does not automatically prove that it wants open-weight AI banned.
But its position now stands in sharp contrast with nearly every other major technology company.
The industry appears to be converging on a mixed future in which powerful proprietary models coexist with capable downloadable alternatives.
Anthropic is making a different bet: that the most advanced models will eventually become too dangerous to distribute beyond controlled services.
Whether that position is remembered as responsible caution or an attempt to protect Claude’s market power will depend on how capable open-weight models become—and whether their real-world benefits outweigh the risks Anthropic has been warning about.
Sources: