Our position on open-weights models
Key Points
- Anthropic opposes a blanket ban on open weights
- Prioritize chip export controls and anti-smuggling
- Mandate pre-release safety testing for capable models
Summary
Anthropic does not support a blanket ban on open-weights models. Open-weights models that lack dangerous capabilities are a public good for businesses, developers, and researchers. The real national-security risks are (1) authoritarian states building secretly more-powerful models for military/surveillance use and (2) misuse of powerful models (cyber, biological, alignment failures). Banning Chinese open weights for US companies would not mitigate those risks and would mainly act as a protectionist measure.
Key Points
- Anthropic has never advocated for banning open-weights models as a category.
- Open-weights can increase access and competition, but may pose higher monitoring and guardrail challenges once released.
- Primary policy priority: prevent authoritarian actors from obtaining cutting-edge training compute by restricting sales and cracking down on chip smuggling.
- Secondary priority: disrupt industrial-scale distillation operations that amplify compute efficiency and narrow the frontier gap.
- All sufficiently capable models—open or closed—should undergo mandatory pre-release safety testing for cyber, biological, and alignment risks; testing results should drive policy and technical mitigation decisions.
- Testing and enforcement need to be global to be effective; promising technical mitigations (e.g., modular training strategies) should be evaluated empirically.
Recommendations for engineers
- Build and adopt pre-release safety test suites targeting misuse vectors (cybersecurity, bio, alignment).
- Instrument models for provenance, monitoring, and post-release telemetry where possible.
- Assume models can be redistributed; design deployment and access controls accordingly.
- Prioritize reproducible, testable safety improvements (e.g., modular training) over relying on export or usage bans.
- Collaborate on open standards and tooling for testing, reporting, and certification of model capabilities and risks.