AI Industry · 15 min read

The Open Weights Fight: What NVIDIA, Anthropic, and Meta Are Really Arguing About

On July 24, Jensen Huang published his first post on X. It was not about chips.

He was sharing an open letter asking Washington not to restrict AI models that anyone can download and run. Behind it sat a report that US officials were weighing a ban on Chinese open-weight models inside American companies.

Within a day OpenAI had signed. Within three, Anthropic's chief executive answered his critics in public. Within four, Mark Zuckerberg moved the argument somewhere else entirely.

Five days, three documents, and a question that none of them asked.

Executive Summary

  • The trigger was narrow: reports that US officials were considering banning American companies from using Chinese open-weight models, not a ban on open models as a category.
  • NVIDIA published “Open Weights and American AI Leadership” on July 24 with a reported 25 signatories; the list reached 133 names by the afternoon of July 30 and 231 by that evening, including Amazon, Google, Meta, Microsoft and OpenAI.
  • Dario Amodei answered on July 27 that “Anthropic has never advocated for a ban on open-weights models,” and argued for chip controls, a distillation crackdown, and mandatory safety testing of every capable model, open and closed.
  • The real disagreement is one point wide: whether openness helps defenders more than attackers, which Amodei says should be settled by pre-release testing rather than assumed.
  • Mark Zuckerberg's op-ed argues the question is who gets access to superintelligence, and both he and Amodei quietly carve out biology as the exception to their own positions.
  • None of the three documents addresses what happens to the files an individual feeds a model, which is the gap Elephas was built for: a privacy-friendly AI knowledge assistant for Mac with Smart Redaction and built-in local LLM models, free to try and starting at $19 a month.

What set this off

Jensen Huang's first X post, sharing the Open Weights and American AI Leadership letter
Jensen Huang's first X post, sharing the Open Weights and American AI Leadership letter

The fight did not begin with the letter. It began in Washington. As Amodei described it a few days later, “Reports suggest that some US officials are considering banning the use of Chinese open-weights models by US companies.”

That proposal is narrower than the argument it set off. It would not outlaw open models as a category. It would stop American businesses from running a particular set of foreign ones, from the Chinese labs whose downloadable models have been closing on the US frontier.

The industry response went far wider than the proposal itself. The letter NVIDIA published on July 24 defends open weights in general, and treats restriction of any kind as a risk to American competitiveness.

Accusations followed fast. Some people, Amodei wrote, “have even accused Anthropic of wanting to ban open-weights models as a means of protecting our business.” That charge is what eventually pulled him into print.

Sam Altman quote-posting the open weights letter the day after it was published, saying he wants the US to win in both open source and proprietary models
Sam Altman quote-posting the open weights letter the day after it was published, saying he wants the US to win in both open source and proprietary models

The case the letter makes

First page of Open Weights and American AI Leadership, the letter NVIDIA published on July 24, 2026, opening with the 1980s open-source software pioneers
First page of Open Weights and American AI Leadership, the letter NVIDIA published on July 24, 2026, opening with the 1980s open-source software pioneers

The letter opens in the 1980s, with open-source pioneers who challenged “the prevailing belief that software would advance only if companies kept tight control over their code.” That community's software now runs most of the internet, plus systems used by the US military and federal agencies.

It draws a pointed conclusion from that history. Open source “did more than lower the cost of software.” It created a shared foundation of knowledge on which American engineers and entrepreneurs “built their institutional sovereignty.”

The central claim is about spread rather than supremacy. US leadership “will be judged not by one frontier AI model, but by whether the United States builds a strong, open ecosystem that diffuses into every sector.”

It does not pretend the risks are imaginary. Once released, weights are “beyond the original developer's control, and modified versions are difficult to trace or reverse.” Prohibition is still the wrong answer, it says, because defenders need models that can “detect, simulate, and respond to emerging threats.”

The company that did not sign

Amjad Masad asking publicly whether Anthropic will sign the open weights letter
Amjad Masad asking publicly whether Anthropic will sign the open weights letter

Anthropic's absence became its own story. On July 25, Replit's Amjad Masad put the question in public: “Will Anthropic sign?” He suggested people working there ask leadership whether the company favored banning open weight models.

Amodei answered two days later. His line leaves little room: “Anthropic has never advocated for a ban on open-weights models.” Open models without dangerous capabilities are “a public good,” he adds, costing nothing beyond compute and providing value to “businesses, developers, and researchers.”

He also rejects the motive attributed to him. A ban “would protect US AI companies from competition,” he writes, “but that has never been my goal.” Protectionist bans, in his account, would not even address the risks he actually cares about.

He anchors the position in his own back catalogue, pointing to his essay “The Adolescence of Technology” from six months earlier and saying he has held these views “consistently for many years.” That is his answer to the charge of convenience.

What Anthropic actually wants

Three separate free-standing arches with a single line passing through each opening, illustrating Anthropic's three targeted measures, chip controls, distillation limits and pre-release testing, in place of one blanket ban
Three separate free-standing arches with a single line passing through each opening, illustrating Anthropic's three targeted measures, chip controls, distillation limits and pre-release testing, in place of one blanket ban

His second concern is misuse for cyberattacks or biological attacks, plus serious alignment problems. Open models do carry higher risk there, he accepts, because guardrails are hard to apply and “once weights are released they cannot be withdrawn.”

Banning US businesses from using them still does nothing about it, “because bad actors are unlikely to be legitimate US businesses.” In place of a ban he proposes three measures, starting with chips. No powerful chips or chipmaking equipment sold to China, plus a crackdown on smuggling, which he footnotes to Justice Department reports.

The reasoning behind that is mechanical. China has limited domestic production capacity, so “due to the scaling laws” it cannot build more powerful models than the US without US chips. Blocking chips is his most direct route to shutting down the first nightmare.

Distillation is the loophole in that plan, and it carries the number most coverage skipped. Training on another model's outputs lets China “build much better models than its number of chips would ordinarily enable,” bringing its frontier to “within a few months” of the American one.

The disagreement is narrower than it looks

Two circles overlapping almost entirely, with only thin dark slivers left unshared at either edge, illustrating how much the letter and Anthropic agree on and how narrow the actual dispute is
Two circles overlapping almost entirely, with only thin dark slivers left unshared at either edge, illustrating how much the letter and Anthropic agree on and how narrow the actual dispute is

The gap between the two documents is far smaller than the coverage suggested. Amodei says he agrees with much of the letter and lists what: open weights expand access to the AI economy, strengthen competition for at least some use cases, and give customers greater control.

They even agree on remedies. The letter calls distillation “a widely used technique for model improvement, evaluation, and validation” and wants unlawful extraction handled through “targeted legal and commercial frameworks.” Amodei adopts that exact phrase for his own position.

The split sits on a single point. The letter argues openness “may be one of the most important paths to AI safety and security,” because many teams can inspect a model and build safeguards. Amodei will not accept that as given, and says the opposite seems “at least as likely.”

His reason is biology. A capable enough model might “quickly weaponize pandemic-level viruses with widely available materials,” while building a defense stays a multi-year task even in the best case, as Operation Warp Speed showed.

Zuckerberg's third argument

One large circle alone on the left facing many small equal circles spread across the right, illustrating Zuckerberg's argument that concentrated power is the danger and wide distribution is the safeguard
One large circle alone on the left facing many small equal circles spread across the right, illustrating Zuckerberg's argument that concentrated power is the danger and wide distribution is the safeguard

Meta signed the letter. Its chief executive then argued a different case entirely. On July 28 Zuckerberg published an op-ed in the Journal titled “The AI Future Is for Everyone,” under a subheadline about centralized power stifling human potential.

He treats the arrival as settled and close, saying that “in the next few years” people will use superintelligence beyond human capacity. The open question is ownership. “Will it be centralized and restricted to a few institutions, or will it be a tool that empowers everyone?”

From there he names three principles: individual empowerment, invention as the purpose of superintelligence, and balance of power as the foundation of safety. His answer is “delivering personal superintelligence to everyone.”

Now notice the vocabulary. Across the whole piece he never writes “open weights” once. “Open-source” appears exactly one time, and only as a historical analogy for cybersecurity, never as a description of what Meta plans to release.

What Meta actually ships

An empty speech bubble on one side and, far from it, a single app-shaped rectangle with lines converging into it from every direction, illustrating the gap between what Meta argues and where its distribution actually runs
An empty speech bubble on one side and, far from it, a single app-shaped rectangle with lines converging into it from every direction, illustrating the gap between what Meta argues and where its distribution actually runs

The op-ed is a philosophy, and philosophies are cheap. Meta's recent releases have drifted from the open Llama playbook that made the company the standard-bearer for downloadable models, even as its AI chief Alexandr Wang has said more open models are coming.

That gap explains the vocabulary. Access and personal superintelligence are promises Meta can keep whether or not it ever publishes another set of weights, because Meta already owns the distribution.

Frontier capability placed inside apps that billions of people already open every day reaches further than any weights file on a download page. It is the strongest position in the room, and it does not require openness at all.

Which lands in a familiar place. An app is a server. Wide access to a capable model through Meta's products answers Zuckerberg's question about who gets to use superintelligence, and says nothing about where the text goes once you type it in.

The one party none of these documents argues about

Three large circles clustered together in conversation while a single small sheet of paper sits alone and apart below them, illustrating the party none of the three documents addresses
Three large circles clustered together in conversation while a single small sheet of paper sits alone and apart below them, illustrating the party none of the three documents addresses

Read the three texts together and one word keeps returning: control. The letter uses it broadly at one point, calling for “giving Americans greater control over the technology they rely on.”

Then watch what happens when it defines the word. Control means organizations that do not want to be “locked into a single provider,” that want to “control their own data,” and to deploy models “wherever their business requirements demand.” That is procurement control, and it answers which vendor a company is tied to and what it pays.

Amodei's three measures are chips, distillation and pre-release testing, and each concerns how models get built and released. None concerns what happens to the sentence a person types into one. Zuckerberg's answer is reach.

Which leaves the decisions that actually reach a lawyer, a doctor, a researcher or a consultant. Those are about what gets pasted: a draft settlement agreement, a patient summary, an unpublished dataset, a client's financials. The useful question there is not open or closed. It is what left the machine.

Where this goes next

Washington still has not ruled on the proposal that started this. The answer could be chip controls, distillation rules, mandatory pre-release testing, limits aimed at specific foreign models, or nothing at all, and the signatory count will keep climbing while it gets decided.

The letter ends by saying the United States “should lead in building” an open future. One thing will not move on its own whichever way that goes.

Open or closed, American or Chinese, a model still needs your text before it can help you. Deciding which parts of it travel is the piece of this argument that stays in your hands.

Where We Stand On This

No matter which company or country wins the argument, the same thing tends to be true underneath it all. Your documents, your notes, your half-formed ideas, they get handed to someone else's servers, and you are asked to trust that it will be fine.

That is the part I have never been comfortable with, and it is honestly why Elephas exists in the form it does today.

We started as a knowledge and writing assistant. But as these models moved into everyone's daily work, I did not want to build one more tool that quietly siphons your sensitive material off to the cloud. So we changed course.

Elephas now provides built-in local LLM models, so your most private work never has to leave your Mac. And when a task genuinely needs a cloud model's horsepower, Smart Redaction removes the sensitive details before anything is sent.

The point is not to be anti-cloud or anti-anyone. It is simpler than that. You should be the one deciding what leaves your machine, rather than an AI company deciding for you. That is the control I want you to have.

If you would like to see how that works in practice, you can try Elephas with a free trial. And either way we keep a zero data retention policy, so nothing you write trains a model, sits on a vendor's server, or passes through anyone else's screen.

Thanks, as always, for being here while we build it.

Selvam Sivakumar, Founder, Elephas

Selvam Sivakumar
Written by

Selvam Sivakumar

Founder, Elephas.app

Selvam Sivakumar is the founder of Elephas and an expert in AI, Mac apps, and productivity tools. He writes about practical ways professionals can use AI to work smarter while keeping their data private.

← Back to Resources