Several prominent AI companies — Hugging Face, Meta, Microsoft, Mistral and Nvidia — have signed an open letter asking U.S. policymakers not to impose sweeping, “premature” restrictions on open-weight models.
Although the letter does not name any country, it arrives against a backdrop of debate in Washington about how to respond to allegations that Chinese AI labs have misappropriated intellectual property from U.S. counterparts and rapidly increased their capabilities. Media reports indicate that the Trump administration has considered banning Chinese open-weight models and possibly imposing sanctions on Chinese AI firms. The White House has also accused Moonshot AI of distilling Anthropic’s Fable model to train its recently released, widely noted Kimi K3 model.
The letter appears aimed at discouraging a blanket ban on Chinese models and at preventing any U.S. response to alleged distillation from expanding into broad restrictions on open-weight models or common techniques such as distillation. It states: “Policymakers should be careful not to conflate legitimate model-development techniques with misappropriation. Distillation, or the practice of using one model’s outputs to help train or improve another, is a widely used technique for model improvement, evaluation, and validation. It reflects a long tradition of learning from, building upon, and improving existing technologies, a tradition that has helped drive innovation since the rise of the open-source software movement.”
The signatories acknowledge that unlawful attempts to extract value from closed models are a valid concern, and they argue those problems should be addressed through targeted legal and commercial frameworks rather than sweeping restrictions that would hinder AI innovation.
The letter also rebuts claims that open-weight models are inherently more dangerous because they broaden access to powerful models that could be used for cyberattacks or other malicious purposes. In response it argues: “The right response to this risk is not to prohibit open weights. In a world where cybersecurity attackers use advanced AI, defenders need access to models with comparable capabilities so they can detect, simulate, and respond to emerging threats. Open models broaden defensive capability, increase transparency, and allow vulnerabilities to be discovered and remediated across many teams.”
The letter cites a recent incident: last week, OpenAI disclosed that while testing GPT-5.6 Sol and another unnamed model, one system exploited a weakness in its testing environment to access a Hugging Face repository containing a solution to a coding benchmark. The episode sparked debate about the risks of concentrating advanced AI capabilities behind a small number of closed providers. Hugging Face said it was unable to defend itself against the attack using commercial frontier AI models because their guardrails blocked its efforts; those closed models could not distinguish between requests to build exploits for an attacker and a defender trying to detect them. Hugging Face turned instead to Z.ai’s GLM 5.2, a powerful open-weight model from a Chinese firm, to mount its defense.
The letter highlights a split within the AI industry. Companies such as OpenAI and Anthropic have urged the U.S. administration to respond to alleged IP theft by Chinese AI firms as open-weight models rapidly increase in capability. The debate’s outcome could materially affect their business models, which face pressure from the spread of low-cost, highly capable, and widely accessible AI models.
Notably absent from the letter’s signatories are several closed-source developers, including OpenAI, Anthropic, Google DeepMind and SpaceX.
The firms that did sign have clear economic interests in a flourishing open-model ecosystem: infrastructure providers like Nvidia and Microsoft Azure benefit if models become commoditized, since interchangeable models can drive greater GPU purchases, more cloud rentals, more applications, and increased use of routing layers.
The letter also urges policymakers to expand access to compute for startups and researchers, invest in shared training assets such as datasets, tools and evaluation frameworks, and to “keep the frontier plural by avoiding premature restrictions on open models that stifle competition or drive innovation overseas.”



