In an article published on Anthropic’s website, CEO Dario Amodei clarified the company’s position on open-weights models, especially Chinese ones. According to Amodei, reports indicate that some US officials are considering banning the use of Chinese open models by American companies. In response, many tech companies signed a letter supporting open models, and some accused Anthropic of wanting to ban these models to protect its business.
Amodei states that Anthropic has never advocated a ban on open-weights models. ‘Open-weights models that do not have dangerous capabilities are a public good: they cost nothing beyond the compute needed to run them and provide value to businesses, developers, and researchers,’ he wrote.
The CEO details two main national security concerns. The first is the risk of authoritarian governments—not just the Chinese Communist Party (CCP), although it is the most capable threat—building AI models more powerful than those of the US and using them for permanent military superiority or deep repression. Amodei cites Vice President Vance, who warned in Paris last year that ‘authoritarian regimes have stolen and used AI to strengthen their military, intelligence, and surveillance capabilities,’ and the 2026 Annual Threat Assessment of the Intelligence Community, which concluded that ‘the robust progress of other global powers in AI is challenging US economic competitiveness and national security advantages.’
The second concern is the misuse of powerful models for cyberattacks or biological attacks, as well as alignment issues. Open-weights models, regardless of origin, pose a greater risk than closed models because it is difficult to apply safeguards or monitor their use, and once released, the weights cannot be retrieved. However, banning the use of these models by American companies does not solve the risk, since malicious actors are unlikely to be legitimate companies.
To address these threats, Amodei supports three measures. First, do not sell powerful chips or chip manufacturing equipment to China, and crack down on smuggling and loopholes used to obtain these chips. China has limited domestic production capacity and, due to economies of scale, cannot build models more powerful than those of the US without American chips.
Second, crack down on industrial-scale distillation operations. Distillation is a much more computationally efficient process than training models from scratch, allowing China to build better models than its number of chips would normally permit, partially circumventing embargoes. Although it does not allow achieving capabilities equivalent to or superior to those of the US, it can bring the Chinese frontier within a few months of the American frontier.
Third, all sufficiently capable models, open or closed, must undergo mandatory safety testing. Amodei highlights that the Trump administration has advanced in this direction in recent months, and that industry proposals suggest applying tests to the most capable models, regardless of country of origin or whether they are open or closed, while exempting less capable models.
Regarding the open letter supporting open models, Amodei agrees that open weights expand access to the AI economy, strengthen competition, and give customers more control. However, he disagrees with the claim that open models necessarily facilitate the development of safeguards or that broad access to capabilities helps defenders more than attackers. He cites the example of biology, where sufficiently capable models can quickly turn pandemic viruses into weapons with widely available materials, while defense is a multi-year operational task.
In summary, Anthropic does not advocate banning open-weights models as a category. The company focuses on keeping powerful chips out of authoritarian hands, cracking down on industrial distillation, and requiring safety testing for all sufficiently capable models, open or closed.