The Open Weights Fight: What NVIDIA, Anthropic, and Meta Are Really Arguing About
On July 24, Jensen Huang published his first post on X. It was not about chips.
He was sharing an open letter asking Washington not to restrict AI models that anyone can download and run. Behind it sat a report that US officials were weighing a ban on Chinese open-weight models inside American companies.
Within a day OpenAI had signed. Within three, Anthropic's chief executive answered his critics in public. Within four, Mark Zuckerberg moved the argument somewhere else entirely.
Five days, three documents, and a question that none of them asked.
Executive Summary
- The trigger was narrow: reports that US officials were considering banning American companies from using Chinese open-weight models, not a ban on open models as a category.
- NVIDIA published “Open Weights and American AI Leadership” on July 24 with a reported 25 signatories; the list reached 133 names by the afternoon of July 30 and 231 by that evening, including Amazon, Google, Meta, Microsoft and OpenAI.
- Dario Amodei answered on July 27 that “Anthropic has never advocated for a ban on open-weights models,” and argued for chip controls, a distillation crackdown, and mandatory safety testing of every capable model, open and closed.
- The real disagreement is one point wide: whether openness helps defenders more than attackers, which Amodei says should be settled by pre-release testing rather than assumed.
- Mark Zuckerberg's op-ed argues the question is who gets access to superintelligence, and both he and Amodei quietly carve out biology as the exception to their own positions.
- None of the three documents addresses what happens to the files an individual feeds a model, which is the gap Elephas was built for: a privacy-friendly AI knowledge assistant for Mac with Smart Redaction and built-in local LLM models, free to try and starting at $19 a month.
What set this off
The fight did not begin with the letter. It began in Washington. As Amodei described it a few days later, “Reports suggest that some US officials are considering banning the use of Chinese open-weights models by US companies.”
That proposal is narrower than the argument it set off. It would not outlaw open models as a category. It would stop American businesses from running a particular set of foreign ones, from the Chinese labs whose downloadable models have been closing on the US frontier.
The industry response went far wider than the proposal itself. The letter NVIDIA published on July 24 defends open weights in general, and treats restriction of any kind as a risk to American competitiveness.
Accusations followed fast. Some people, Amodei wrote, “have even accused Anthropic of wanting to ban open-weights models as a means of protecting our business.” That charge is what eventually pulled him into print.
- The backdrop is a set of reported accusations that Chinese labs extracted capability from American models, with Anthropic's own Fable named among them, which puts Anthropic closer to this fight than any other signatory or holdout.
- The letter never names China or the reported proposal, arguing instead against “premature restrictions on open models that stifle competition or drive innovation overseas.”
- Huang's post carried the letter past 64 million views on X, and reporting at the time put the opening signatory group at roughly 25 companies.
- The list is still moving. The version hosted on NVIDIA's servers, still dated July 24, carried 133 names on the afternoon of July 30 and 231 by that evening, among them Amazon, Google, Meta, Microsoft, OpenAI, AMD, Intel, IBM, Cisco, Dell, SAP, Siemens, SpaceX, Atlassian, Coinbase, Palantir, Y Combinator and Andreessen Horowitz.
- Sam Altman quote-posted it the next day: “i want the US to win in AI both in open source and proprietary models, and i am glad to see this.”
- Elon Musk backed it just as plainly, replying to Huang that “This has my full support. Jensen is right.” His xAI never appeared on the list, though SpaceX did, which leaves Anthropic as the one major lab still standing apart.
The case the letter makes
The letter opens in the 1980s, with open-source pioneers who challenged “the prevailing belief that software would advance only if companies kept tight control over their code.” That community's software now runs most of the internet, plus systems used by the US military and federal agencies.
It draws a pointed conclusion from that history. Open source “did more than lower the cost of software.” It created a shared foundation of knowledge on which American engineers and entrepreneurs “built their institutional sovereignty.”
The central claim is about spread rather than supremacy. US leadership “will be judged not by one frontier AI model, but by whether the United States builds a strong, open ecosystem that diffuses into every sector.”
It does not pretend the risks are imaginary. Once released, weights are “beyond the original developer's control, and modified versions are difficult to trace or reverse.” Prohibition is still the wrong answer, it says, because defenders need models that can “detect, simulate, and respond to emerging threats.”
- The prize it describes is ordinary rather than exotic: America wins the AI era “by diffusing it into the workflows of factories, hospitals, farms, classrooms, and main street businesses.”
- The economics come first: build “without training one from scratch or paying frontier-model prices for every task,” a discipline it says will make AI sustainable “as its use scales into the billions of everyday tasks.”
- Competition creates rivalry “not only among model developers but across cloud chips, applications, and services,” while concentration “results in a small number of single points of failure.”
- Its safety case is borrowed from software history: “just as open-source software demonstrated that transparency can be more secure than obscurity,” it argues for benchmarking, red teaming, and protections “tied to real and demonstrated harms rather than assuming that closed systems are safer by default.”
- Its asks: more compute for startups and researchers, shared training assets, “keeping the frontier plural,” and attention to how “strong application layers can expand sovereign use of AI across the economy.”
- Its closing promise is ownership, that organizations can “own that value through self-improving models, specialized capabilities, and accumulated knowledge that drive American sovereignty and prosperity.”
The company that did not sign
Anthropic's absence became its own story. On July 25, Replit's Amjad Masad put the question in public: “Will Anthropic sign?” He suggested people working there ask leadership whether the company favored banning open weight models.
Amodei answered two days later. His line leaves little room: “Anthropic has never advocated for a ban on open-weights models.” Open models without dangerous capabilities are “a public good,” he adds, costing nothing beyond compute and providing value to “businesses, developers, and researchers.”
He also rejects the motive attributed to him. A ban “would protect US AI companies from competition,” he writes, “but that has never been my goal.” Protectionist bans, in his account, would not even address the risks he actually cares about.
He anchors the position in his own back catalogue, pointing to his essay “The Adolescence of Technology” from six months earlier and saying he has held these views “consistently for many years.” That is his answer to the charge of convenience.
- His first concern is authoritarian governments building models more powerful than America's and using them for permanent military superiority or deep repression at home.
- He cites Vice President Vance's warning in Paris that “authoritarian regimes have stolen and used AI to strengthen their military, intelligence, and surveillance capabilities.”
- He also cites the Intelligence Community's 2026 Annual Threat Assessment, which found that “other global powers' robust progress in AI is challenging US economic competitiveness and national security advantages.”
- On that first risk he calls openness beside the point: it is “irrelevant whether these models are released with open weights, and certainly irrelevant whether they are used by US businesses.”
- The sharpest version of the reframe: “the most dangerous model may be one that is trained in secret and handed only to the People's Liberation Army for use in drones and the Ministry of State Security for surveillance and repression.”
What Anthropic actually wants
His second concern is misuse for cyberattacks or biological attacks, plus serious alignment problems. Open models do carry higher risk there, he accepts, because guardrails are hard to apply and “once weights are released they cannot be withdrawn.”
Banning US businesses from using them still does nothing about it, “because bad actors are unlikely to be legitimate US businesses.” In place of a ban he proposes three measures, starting with chips. No powerful chips or chipmaking equipment sold to China, plus a crackdown on smuggling, which he footnotes to Justice Department reports.
The reasoning behind that is mechanical. China has limited domestic production capacity, so “due to the scaling laws” it cannot build more powerful models than the US without US chips. Blocking chips is his most direct route to shutting down the first nightmare.
Distillation is the loophole in that plan, and it carries the number most coverage skipped. Training on another model's outputs lets China “build much better models than its number of chips would ordinarily enable,” bringing its frontier to “within a few months” of the American one.
- On distillation he separates the technique from the actor: “the open weights are far less relevant than the fact that the operations are backed by an authoritarian state seeking to overtake the US at the frontier.”
- His third measure is mandatory safety testing for every sufficiently capable model, open or closed, tested for cyber, biological and alignment risks before release.
- Whether open models carry extra risk “is something that should emerge from testing, rather than be decided in advance,” which is his core procedural demand.
- He notes the Trump administration “has moved in this direction in recent months,” and that industry proposals would exempt less capable models from startups and academia entirely.
- A footnote explains why company policy is not enough: Anthropic bans accounts that distill its models, but they “can often only be identified after substantial distillation has occurred,” and involve “large numbers of fake accounts that form a moving target.”
The disagreement is narrower than it looks
The gap between the two documents is far smaller than the coverage suggested. Amodei says he agrees with much of the letter and lists what: open weights expand access to the AI economy, strengthen competition for at least some use cases, and give customers greater control.
They even agree on remedies. The letter calls distillation “a widely used technique for model improvement, evaluation, and validation” and wants unlawful extraction handled through “targeted legal and commercial frameworks.” Amodei adopts that exact phrase for his own position.
The split sits on a single point. The letter argues openness “may be one of the most important paths to AI safety and security,” because many teams can inspect a model and build safeguards. Amodei will not accept that as given, and says the opposite seems “at least as likely.”
His reason is biology. A capable enough model might “quickly weaponize pandemic-level viruses with widely available materials,” while building a defense stays a multi-year task even in the best case, as Operation Warp Speed showed.
- His footnote cites the UK AI Security Institute, which warns that for models with dangerous capabilities specifically, open release “creates a persistent and irreversible risk of misuse.”
- The same report notes that once weights are out, safeguards can be removed and copies “downloaded, redistributed, and run on private systems beyond monitoring.”
- A deeper footnote states his real fear: what keeps us safe in biology is “a negative correlation between intellectual capability and desire to commit catastrophic harm,” which he expects AI to break.
- Sufficiently powerful technology, he writes, “removes all barriers and exposes whether the attacker or defender has an inherent structural advantage,” and in biology he thinks it is the attacker.
- That question got a live test in July, when an AI agent from an OpenAI evaluation breached Hugging Face. The company tried to analyse the attack with hosted frontier models and was refused, because the providers' guardrails “cannot distinguish an incident responder from an attacker.”
- It finished the forensics on GLM-5.2, an open-weight model it could run on its own hardware, which also kept the attacker's data and the exposed credentials inside its own environment instead of shipping them to a vendor.
- Anthropic updated the post on July 28 to credit AE Studio as a collaborator on the modular training research it cites as a possible route to safer open models.
Zuckerberg's third argument
Meta signed the letter. Its chief executive then argued a different case entirely. On July 28 Zuckerberg published an op-ed in the Journal titled “The AI Future Is for Everyone,” under a subheadline about centralized power stifling human potential.
He treats the arrival as settled and close, saying that “in the next few years” people will use superintelligence beyond human capacity. The open question is ownership. “Will it be centralized and restricted to a few institutions, or will it be a tool that empowers everyone?”
From there he names three principles: individual empowerment, invention as the purpose of superintelligence, and balance of power as the foundation of safety. His answer is “delivering personal superintelligence to everyone.”
Now notice the vocabulary. Across the whole piece he never writes “open weights” once. “Open-source” appears exactly one time, and only as a historical analogy for cybersecurity, never as a description of what Meta plans to release.
- The jab at his peers: “I don't understand why anyone who believes that AI will eliminate most jobs and much of humanity's relevance would rush to build that future.”
- He grounds it in the values he says got us here, “liberty, open inquiry, free enterprise and equal opportunity,” and in inventors outside institutions: the brothers in a bicycle shop, the bookbinder's apprentice, the kid in a garage.
- His thought experiment: one person with a superintelligent lawyer gains an unfair advantage even when wrong on the merits, while everyone having one makes justice fairer.
- On invention he draws a limit and a promise: the questions you can ask in a day are limited, but what superintelligence “can invent to help achieve your goals is unlimited.”
- He also carves out an exception that lands him beside Amodei. Open access protects security in most cases, he argues, but “for other risks, including biological risks,” he wants coordination between governments.
What Meta actually ships
The op-ed is a philosophy, and philosophies are cheap. Meta's recent releases have drifted from the open Llama playbook that made the company the standard-bearer for downloadable models, even as its AI chief Alexandr Wang has said more open models are coming.
That gap explains the vocabulary. Access and personal superintelligence are promises Meta can keep whether or not it ever publishes another set of weights, because Meta already owns the distribution.
Frontier capability placed inside apps that billions of people already open every day reaches further than any weights file on a download page. It is the strongest position in the room, and it does not require openness at all.
Which lands in a familiar place. An app is a server. Wide access to a capable model through Meta's products answers Zuckerberg's question about who gets to use superintelligence, and says nothing about where the text goes once you type it in.
- Meta signed a letter arguing for downloadable models while its CEO argued for distributed access, and those are not the same commitment.
- “Superintelligence will be the most profound technological advance we will see in our lifetimes,” he writes, closing with Meta “committed to building with the principles of individual empowerment, invention and balance of power.”
- On jobs he states a condition rather than a promise: if the balance leans toward automation the effect “may be negative,” and only wide distribution produces more jobs rather than fewer.
- He rejects a single aligned superintelligence because “humanity isn't a monoculture,” so any one system would rank some values above others.
- On concentration he is blunt, saying that hoping absolute power “will benevolently provide for humanity if sufficiently enlightened hasn't led to safe or positive outcomes.”
The one party none of these documents argues about
Read the three texts together and one word keeps returning: control. The letter uses it broadly at one point, calling for “giving Americans greater control over the technology they rely on.”
Then watch what happens when it defines the word. Control means organizations that do not want to be “locked into a single provider,” that want to “control their own data,” and to deploy models “wherever their business requirements demand.” That is procurement control, and it answers which vendor a company is tied to and what it pays.
Amodei's three measures are chips, distillation and pre-release testing, and each concerns how models get built and released. None concerns what happens to the sentence a person types into one. Zuckerberg's answer is reach.
Which leaves the decisions that actually reach a lawyer, a doctor, a researcher or a consultant. Those are about what gets pasted: a draft settlement agreement, a patient summary, an unpublished dataset, a client's financials. The useful question there is not open or closed. It is what left the machine.
- Beside the chipmakers and labs on that signatory list sit Notion, Box, Zoom, GitHub, Comcast, SAP, ServiceNow, Dell and Uber, much of the software layer that already holds your working files.
- Nothing in any of the three documents proposes a limit on what a deployed model may retain, log or pass onward from an ordinary user's session.
- Every proposed safeguard in all three texts operates before release, which is upstream of the moment your document actually goes somewhere.
- Open weights do not mean private by default, because most people meet open models through a hosted API rather than on their own hardware.
- Closed does not mean safe either, and the letter says so plainly: closed systems “can be breached, misused, or fail in ways that outsiders cannot detect.”
- Zero data retention is a contractual promise rather than a physical property of the connection. A model running on your own machine is the only arrangement where sensitive text never crosses a network at all, and for everything else the question is whether the identifying details can be stripped out before the request is sent.
Where this goes next
Washington still has not ruled on the proposal that started this. The answer could be chip controls, distillation rules, mandatory pre-release testing, limits aimed at specific foreign models, or nothing at all, and the signatory count will keep climbing while it gets decided.
The letter ends by saying the United States “should lead in building” an open future. One thing will not move on its own whichever way that goes.
Open or closed, American or Chinese, a model still needs your text before it can help you. Deciding which parts of it travel is the piece of this argument that stays in your hands.
Where We Stand On This
No matter which company or country wins the argument, the same thing tends to be true underneath it all. Your documents, your notes, your half-formed ideas, they get handed to someone else's servers, and you are asked to trust that it will be fine.
That is the part I have never been comfortable with, and it is honestly why Elephas exists in the form it does today.
We started as a knowledge and writing assistant. But as these models moved into everyone's daily work, I did not want to build one more tool that quietly siphons your sensitive material off to the cloud. So we changed course.
Elephas now provides built-in local LLM models, so your most private work never has to leave your Mac. And when a task genuinely needs a cloud model's horsepower, Smart Redaction removes the sensitive details before anything is sent.
The point is not to be anti-cloud or anti-anyone. It is simpler than that. You should be the one deciding what leaves your machine, rather than an AI company deciding for you. That is the control I want you to have.
If you would like to see how that works in practice, you can try Elephas with a free trial. And either way we keep a zero data retention policy, so nothing you write trains a model, sits on a vendor's server, or passes through anyone else's screen.
Thanks, as always, for being here while we build it.
Selvam Sivakumar, Founder, Elephas









