Radar · 28/07/2026 · happened on 27/07/2026

Anthropic clarifies its position on open-weight models: mandatory testing, chip controls

Dario Amodei has published an official statement clarifying Anthropic’s position on open-weight models, following weeks of debate over targeted bans on open Chinese models and accusations that the company is seeking to protect its own market.

The direct message: Anthropic has never called for banning open-weight models. Open models without dangerous capabilities are a public good, requiring only compute to run and delivering value to enterprises, developers, and researchers.

Amodei identifies two concrete concerns. First: authoritarian governments training models more powerful than those from the USA for military superiority or internal repression (it matters little whether these are open or closed). Second: use of powerful models for cyber or biological attacks, where open-weight models present higher risk because it’s difficult to apply safeguards and, once released, weights cannot be recalled.

Three measures Anthropic supports: block advanced chip exports to China and suppress smuggling; target large-scale distillation operations; mandatory safety testing for all sufficiently capable models, whether open or closed.

For those building with open models, the landscape is the same as we outlined on July 23: pressure concentrates on individual at-risk models, and choosing a model remains a bet on the political survival of the tool.

In detail

The document arrives at a critical moment. On July 26, the White House was evaluating targeted bans on individual open Chinese models, and on July 27, Moonshot released Kimi K3, an open model competitive with US frontier systems that alarmed regulators. Some tech companies have signed a letter supporting open-weight models, and Anthropic has been accused of wanting to ban them to protect its business.

Amodei distinguishes between the two concerns with precision. The first, strategic threat, concerns models trained in secret and delivered directly to the Chinese military or security services. In that case, open weights are largely irrelevant: the most dangerous model might be one never publicly released. The second, malicious use of open models for cyber or biological attacks, is where open-weight models objectively present higher risk. Once weights are public, you cannot recall them, cannot update safeguards, cannot monitor who uses them.

Anthropics response on the three measures shifts focus from the model to compute. The argument on chips is straightforward: China has limited domestic production capacity, and without American chips it cannot scale according to scaling laws. Export controls are the most effective lever to block the strategic threat. On distillation, Amodei acknowledges it allows China to build better models than its chips would otherwise permit, closing the gap to just months behind the US frontier. Companies pursuing these operations often release open-weight models, but what matters is the operation itself, backed by an authoritarian state, not the open weights.

The third point, mandatory safety testing, is where Anthropic finds alignment. Amodei notes the Trump administration is moving in this direction, and industry proposals call for testing on the most capable models regardless of country of origin or whether open or closed, exempting less capable models from startups and academia. Global testing requires China to participate, and Amodei sees limited cooperation possible on biological weapons prevention because it serves Beijing’s interests.

What remains open. The document is a policy position, not an operational plan. It doesn’t say who determines the threshold of “sufficiently capable” for mandatory testing, or how global testing is enforced. The proposal for China cooperation on biological weapons is plausible on paper, but the document doesn’t reckon with current geopolitical reality. And the acknowledgment that open-weight models carry objectively higher risk for malicious use, even if it doesn’t lead to calling for their ban, remains an argument proprietary labs can use to justify closed models.

For those using open models in their work, Amodei’s distinction between “models without dangerous capabilities, a public good” and “models with dangerous capabilities, mandatory testing” is the criterion to watch. The line will be drawn where regulators place it.

Type to search across course, playbooks, skills, papers…