A coalition of major technology companies—including Microsoft, NVIDIA, and Palantir—has signed an open letter calling for continued development and access to open-weight artificial intelligence models, arguing that openness benefits innovation and competition. Anthropic CEO Dario Amodei has publicly disagreed with the framing, challenging what he characterises as an overstated security argument for keeping models open while not opposing openness itself in absolute terms.
The distinction between open-weight and closed-weight AI models is central to this debate. An open-weight model is one in which the trained numerical parameters—the billions of “weights” that encode the model’s learned capabilities—are made publicly available for anyone to download, run, and modify. A closed-weight model, by contrast, is accessed only through an API or interface controlled by the company that built it; the underlying weights are proprietary. Meta’s Llama models, Mistral AI’s models, and others in the open-weight ecosystem have demonstrated that publicly available models can match or approach the performance of closed commercial systems on many tasks.
Proponents of open-weight models make several arguments. First, that open access enables independent safety research: academics and security researchers can study the model’s actual behaviour rather than inferring it from external observations. Second, that open models foster competition, preventing a small number of well-resourced companies from monopolising advanced AI capabilities. Third, that developers in smaller organisations and less wealthy countries can build AI-powered applications without incurring API access costs or depending on the continued commercial viability of a private vendor.
The security argument for restricting open-weight access centres on what researchers call “dual-use” capability: the concern that a sufficiently capable open model could be used—or fine-tuned—to assist with cyberattacks, the creation of disinformation at scale, or, in the most serious scenarios, the development of biological or chemical weapons by actors who would not otherwise have access to the relevant technical knowledge. The Cybersecurity and Infrastructure Security Agency and similar bodies in other countries have published assessments of AI-related security risks, though expert opinion on how much open-weight models specifically increase those risks—compared to what determined bad actors could accomplish without them—remains divided.
Amodei’s public position, as reported, does not amount to an endorsement of restrictions on all open models. Rather, it challenges the specific claim that open-weight access is a primary driver of cybersecurity risk. Anthropic has built its business model around closed, safety-focused AI systems—its Claude models are not open-weight—but Amodei’s objection appears to be methodological: that advocates of openness are making cybersecurity arguments without adequate empirical grounding, while simultaneously understating what openness actually contributes to safety research and competitive dynamics.
The policy stakes are significant. The White House Office of Science and Technology Policy, the EU AI Act, and AI governance frameworks under development in multiple countries are all grappling with how to treat open-weight models. Classification decisions—whether a model counts as “general purpose,” “high risk,” or something else—trigger different regulatory requirements. How open-weight models are treated under these frameworks will affect everything from what safety evaluations companies must conduct before release, to whether national security agencies can require advance notification or access.
The geopolitical dimension is also real. Chinese AI development has produced both open and closed models. U.S. export controls on semiconductor hardware already constrain Chinese access to the most advanced chips needed to train frontier models. Whether open-weight model restrictions would add meaningfully to that constraint—or primarily disadvantage non-Chinese open-source developers—is a question the policy debate has not fully resolved.
The disagreement between signatories to the open letter and Amodei reflects a genuine technical and empirical uncertainty: how much does open-weight model access actually increase the capability of malicious actors, compared to what those actors could achieve through other means? Until that question has better empirical answers, the policy debate will remain shaped as much by commercial interests and ideological priors as by evidence.