← BACK TO HOME — Anthropic News — 进阶
行业观点 · ANALYSIS · IMPACT 7/10

Our position on open-weights models

Anthropic CEO Dario Amodei clarifies the company has never advocated for banning open-weights models, and warns that the real national security nightmares—authoritarian military AI and model misuse—can't be solved by protectionist bans.

KEY POINTS
  • Anthropic has never advocated for a ban on open-weights models; those without dangerous capabilities are a public good.
  • The two nightmare scenarios: authoritarian regimes achieving military AI superiority (independent of open weights), and the misuse or alignment risks of powerful models (exacerbated by open weights but unaddressed by bans).
  • Once released, open-weight models cannot be withdrawn, making malicious use harder to control, but banning legitimate U.S. businesses from using them does nothing to stop bad actors.
  • The most dangerous models may be those trained in secret and handed directly to the military, completely invisible to the public.
ANALYSIS

Why this statement matters

A recent wave of discussion around open-weights models—especially those from China—has triggered a policy debate in the US. Some officials are reportedly considering banning American companies from using Chinese open-weights models. Many tech firms have signed a letter in support of open models, and in the crossfire, Anthropic was accused of secretly pushing for a ban to protect its own business. In response, CEO Dario Amodei stepped in with a detailed clarification that goes far beyond mere damage control.

The two nightmares—and why bans won't help

Dario starts with an unequivocal statement: Anthropic has never advocated for banning open-weights models. Those without dangerous capabilities are a public good, providing value to businesses, developers, and researchers. This directly rebukes the “selfish closed-source company” narrative.

But he quickly turns to the real dangers keeping him up at night—and explains why protectionist bans fail to address them.

His first nightmare is at the national-security level: authoritarian regimes (not only but especially the CCP) could build AI models that surpass US capabilities, using them to achieve permanent military superiority or perpetrate deep repression. Crucially, he stresses that “it is irrelevant whether these models are released with open weights, and certainly irrelevant whether they are used by US businesses.” The most dangerous model could be one trained in secret and handed exclusively to the People’s Liberation Army or the Ministry of State Security—completely invisible to the world.

The second nightmare involves misuse and alignment risks: powerful AI models might enable cyberattacks, biological attacks, or exhibit serious alignment problems. Open-weights models do amplify this risk—once weights are public, anyone can run them locally, making guardrails and monitoring nearly impossible, and releases cannot be recalled. Yet, barring US companies from using them does nothing to mitigate the threat, because bad actors are unlikely to be legitimate US firms.

An apt analogy: the first nightmare is “your enemy gets a nuclear bomb, while you’re debating whether to publish the blueprint”; the second is “terrorists could build a bomb from public blueprints, but banning law-abiding companies from using them doesn’t stop terrorists.”

A deeper trend: AI safety’s shifting battleground

Dario’s post signals a maturation of the AI safety discourse, pushing it beyond simplistic binaries.

  1. Fractured safety narratives: The “open vs. closed” debate has often been reduced to “innovation vs. safety.” Dario highlights that the most severe threats originate not from open-source communities, but from state actors and covert projects. This reframes the question from “should we open-source?” to “how do we control the proliferation and use of cutting-edge models?”

  2. The arms-racing of US-China AI competition: The repeated references to China, alongside quotes from Vice President Vance and the 2026 Annual Threat Assessment, make it clear that AI has become a central tool of great-power rivalry. Open-weights models may only be the visible tip of the iceberg; the real danger lurks in unseen military-grade systems.

  3. The irrevocability of open weights: Once published, model weights can never be taken back. This poses a novel policy challenge—traditional export controls or corporate bans may prove utterly futile in the software age.

What this means for developers

For developers and enterprises, especially those outside the US, several takeaways emerge:

  • Resist the “open vs. locked-down” binary. Open models hold immense value, but be mindful of provenance and legal risks, particularly if your business has US ties or customers.
  • Model supply-chain security is looming. Just as with semiconductors, we may see “model export control” zones. If you rely on foreign open-source models, evaluate the risk of supply disruption.
  • Engage in governance conversations. Dario’s stance proves that safety and openness are not opposites. Developers everywhere can demonstrate responsible open-model use and help shape a more nuanced global consensus.

The counterintuitive twist: closed-source company defends openness, warns of invisible threats

Many expected Anthropic to push for banning open models to protect its business. Instead, the CEO calls harmless open models a public good—a reminder that commercial rivalry isn’t the whole story. More counterintuitively, Dario argues that the most terrifying AI might be completely closed, secretly run by militaries. These are the models you never see and can’t debate. While public attention fixates on the “dangers” of open weights, the systems that could truly upset geopolitical balances may already be growing in the shadows.

In the end, this is more than a PR exercise. It’s a sobering call for the industry: if we truly care about safety, we must focus on the highest-risk scenarios, rather than placing arbitrary limits on the democratizing force of open innovation.

Analysis by BitByAI · Read original

Originally from Anthropic News · Analyzed by BitByAI