Regulation

Anthropic opposes blanket bans on open-weight models, urges stricter controls on chips, distillation and mandatory testing

Anthropic CEO Dario Amodei said on July 27, 2026 that the company does not support categorical bans on open-weights AI models, while urging stronger, targeted measures to reduce national-security and misuse risks.

Anthropic opposes blanket bans on open-weight models, urges stricter controls on chips, distillation and mandatory testing

On July 27, 2026, Anthropic CEO Dario Amodei published a post clarifying the company’s stance on open-weights models. He stated explicitly that Anthropic has never advocated banning open-weights models and does not view such bans as an effective way to address the most serious national-security concerns.

Why the debate matters

Recent days saw heightened debate over open-weights models, especially those originating from China. Reports indicated some U.S. officials are considering banning U.S. companies from using Chinese open-weights models. In reaction, numerous tech firms signed a letter supporting open weights, and some commentators accused Anthropic of seeking a ban to protect its business — an accusation Amodei rejected.

Anthropic’s baseline view on open weights

Amodei argued that open-weights models that lack dangerous capabilities are a public good: their only cost is the compute required to run them, and they can benefit businesses, developers, and researchers. At the same time, he warned that protectionist bans would shield U.S. AI firms from competition without addressing the underlying security risks.

Two central national-security worries

Amodei identified two “nightmare” scenarios he has previously described in his essay The Adolescence of Technology (published about six months earlier):

  • Primary concern: authoritarian governments — not only the Chinese Communist Party, though Amodei singles it out as the most capable threat — could develop AI models more powerful than those made in the U.S. and use them to secure lasting military superiority or to intensify domestic repression. He noted this worry is shared inside the U.S. government: Vice President Vance warned in Paris that “authoritarian regimes have stolen and used AI to strengthen their military, intelligence, and surveillance capabilities,” and the Intelligence Community’s 2026 Annual Threat Assessment observed that other global powers’ rapid progress in AI challenges U.S. economic competitiveness and national-security advantages. Amodei emphasized that whether such models are released with open weights is irrelevant; the most dangerous model might be one trained secretly and deployed only to military and security agencies.

  • Secondary concern: powerful AI models could be misused for cyberattacks or biological attacks and could present serious alignment failures. Open-weights models may pose increased risk relative to closed models because guardrails are harder to apply and use is harder to monitor — and weights, once released, cannot be retracted. However, Amodei argued that banning their use by U.S. businesses does not mitigate these risks, since malicious actors are unlikely to be legitimate U.S. firms.

Three policy measures Anthropic supports

To address these threats, Amodei and Anthropic advocate three targeted interventions they have consistently promoted:

  1. Do not sell advanced chips or chipmaking equipment to China, and crack down on smuggling and workarounds. Amodei noted China’s limited domestic chip production capacity means, per scaling laws, it cannot train models more powerful than U.S. models without U.S. chips. Blocking access to chips is therefore the most direct and efficient way to blunt the primary threat, and it also indirectly helps reduce the secondary risk by limiting training capacity.

  2. Crack down on industrial-scale distillation operations. Distillation is far more compute-efficient than training from scratch and can enable stronger models than chip counts alone would suggest, allowing actors to partially evade chip restrictions. While distillation does not necessarily give the CCP capabilities equivalent to or exceeding U.S. frontier models, it can bring a Chinese frontier within a few months of the U.S. frontier. Amodei stressed that many distillation operations do release open weights, but that the larger issue is state-backed scale. Anthropic also said it is taking company-level steps to identify and ban accounts that use its models for large-scale distillation, although Amodei acknowledged corporate practices alone cannot fully solve the problem and policy is needed.

  3. Require mandatory safety testing for all sufficiently capable models, whether open or closed. Amodei argued the best way to address misuse and alignment risks is to test models for cyber, biological, and alignment hazards prior to release. He suggested this idea is close to consensus; he welcomed steps in that direction by the prior U.S. administration and referenced recent industry proposals to apply pre-release testing to the most capable models regardless of origin, while exempting lower-capability models from startups and academia. He added that the question of whether open models pose greater risk should be determined empirically via testing, and pointed to research (including Anthropic’s work on modular training strategies) that might improve open-weights safety. Effective testing would need to be global in scope, which implies participation by China would be required — Amodei judged such limited cooperation possible in areas like preventing AI-enabled biological weapons because of shared incentives.

The open letter and remaining disagreements

Amodei said he agrees with much of the open letter supporting open weights: open weights expand access to the AI economy, can strengthen competition for some use cases, and give customers more control. However, he disagreed with claims in the letter that open weights necessarily make it easier to develop safeguards or that broad access necessarily helps defenders more than attackers. He warned that biology may present a strong attacker-defender asymmetry: highly capable models could rapidly weaponize pandemic-level agents from widely available materials, while developing defensive countermeasures can be a multi-year operational effort.

Conclusion

Anthropic’s position is that it does not support a categorical ban on open-weights models. Instead, the company urges focused measures: preventing export of powerful chips and equipment to authoritarian states, deterring industrial-scale distillation, and mandating safety testing for all sufficiently capable models, open or closed. Amodei argued these targeted policies are more practical and effective responses to the articulated national-security and misuse concerns than a blanket prohibition.


Notes: Amodei’s post references his essay The Adolescence of Technology (about six months earlier), Vice President Vance’s Paris remarks, and the Intelligence Community’s 2026 Annual Threat Assessment, as well as reports from the UK AI Security Institute and other U.S. Department of Justice materials regarding openness and distillation practices.