Anthropic says it does not want to ban open weights and nobody believes them
Dario Amodei posted Anthropic's position on open-weights models on July 28, and it immediately became the biggest story on Hacker News. 761 points. 1,075 comments in eight hours. The headline claim is blunt: "Anthropic has never advocated for a ban on open-weights models." The reaction is even blunter: almost nobody in the thread believes him.
I have read the full post twice. The position is more careful than the HN thread credits, and the HN thread is more right than Anthropic would like to admit. Both things are true at once, which is probably the most honest way into this.
What the post actually says
Amodei opens by responding to reports that US officials are considering banning Chinese open-weights models. He says Anthropic was accused of wanting this ban to protect its business. He denies it flatly.
Then he lays out two nightmare scenarios he actually worries about. The first is authoritarian governments building AI models more powerful than what the US has, and using them for military superiority or mass repression. He says this has nothing to do with whether the models have open weights. The most dangerous model, he argues, might be one trained in secret and handed only to a military. The second concern is misuse for cyberattacks or biological attacks, where open-weights models do present higher risk because you cannot apply guardrails or monitor usage once the weights are out.
The post then proposes three measures Anthropic does support, framed as alternatives to a blanket ban:
Keep powerful chips out of authoritarian hands. Crack down on industrial-scale distillation that lets Chinese labs build better models than their chip supply would normally allow. Require mandatory safety testing of all sufficiently capable models, open and closed.
That is the whole position. No ban. Three targeted measures. Safety testing for everything above a capability threshold.
Why nobody is buying it
The top comment on HN calls it "Schrödinger's China": simultaneously an evil entity that will use AI for nefarious purposes, but also willing to cooperate with the US on global safety testing, all while under a chip embargo. The commenter's read is simpler: the CEO of a closed-model company does not want models with similar capabilities to his own widely released, because that affects the bottom line.
That comment has the most upvotes in the thread. Whether it is fair or not, it is the temperature of the room.
Several commenters make a point that is hard to dismiss: the "safety" narrative has been there since Anthropic's founding. One person puts it bluntly: "The best setup is when a true belief aligns with a competitive moat." The argument is that Amodei genuinely believes in safety, but it is also convenient that the safety framing creates a regulatory moat that protects Anthropic's market position. Both can be true. The HN thread does a better job than the post acknowledges of separating the two.
Others point to the regulatory capture angle. You do not say "let's ban my competitor." You say "let's create laws that make it uneconomical for my competitor to access the market." Chip export controls and mandatory safety testing regimes both raise the cost of entry. That is not the same as a ban. It is also not the same as a level playing field.
The part where the post is more right than the comments
Here is where I think the HN thread is being unfair. Amodei explicitly says that a ban on US businesses using Chinese open-weights models "would protect US AI companies from competition, but that has never been my goal." He also says the most dangerous model is one trained in secret for military use, not an open-weight model used by a US startup. That is a real argument, not a dodge.
The three measures he proposes are also narrower than "ban open weights." Chip export controls target the hardware. Distillation crackdowns target the training pipeline. Safety testing targets the models themselves, regardless of whether they are open or closed. You can disagree with any of these, but they are not a blanket ban dressed up in different language.
Amodei also concedes ground the HN thread does not credit him for. He agrees with the open letter that open weights expand access to the AI economy and give customers more control. He says concerns about distillation should be addressed through targeted frameworks. He even says he does not agree with the letter's claim that open weights necessarily make it easier to develop safeguards, but frames that as an empirical question to be tested, not a settled view.
That is not the posture of someone trying to ban open weights. It is the posture of someone trying to set the terms of the debate so that the policies they do want look like the reasonable middle ground.
The biology argument that nobody resolves
The longest and most heated subthread in the HN comments is about biological risk. Amodei says he worries that sufficiently capable models could weaponize pandemic-level viruses, and that defense is a multi-year operational task while offense might be a single prompt. He calls this an "attacker-defender asymmetry."
The comments split three ways. One camp says open weights are the only way to defend yourself: if only closed labs have capable models, then criminals, governments, and other bad actors use them against you with no civilian counter. Another camp says the cat is out of the bag: the dangerous knowledge is already on the internet, the model is just a faster search engine, and you cannot uninvent capability. A third camp says this is exactly like nuclear proliferation: imperfect restrictions have still bought decades of civilization, and the same approach could work here.
Nobody resolves it. The uncomfortable truth is that all three arguments have something going for them. Open weights do shift capability toward defenders in cybersecurity, where a self-hosted GLM-5.2 caught a GPT-6 attack that closed-model refusals would have blocked. But biology is not cybersecurity. A self-propagating worm can be patched. A self-propagating pathogen cannot. The asymmetry Amodei describes is real, and neither the open-weights advocates nor the safety camp has a clean answer for it.
The distillation dodge
The one part of the post I find most slippery is the distillation argument. Amodei says Chinese labs are using distillation to build models much better than their chip supply would normally allow, and that this "partially evades chip bans." He says the open weights are "far less relevant than the fact that the operations are backed by an authoritarian state seeking to overtake the US at the frontier."
This is a strange framing. Distillation is a technical process. It is how you transfer knowledge from a large model to a smaller one. If the concern is state-backed theft of proprietary model outputs, then the policy should target the theft, not the distillation technique. Distillation from open models is already legal and widely practiced. Conflating the two muddies the argument in a way that benefits closed labs.
One HN commenter put this well: the entire safety evaluation industry is funded and controlled by OpenAI and Anthropic. The testing vendors serve the big labs. The researchers move between them. If mandatory safety testing becomes law, the labs that built the testing infrastructure will be the ones defining what "sufficiently capable" means. That is not a conspiracy theory. It is how regulatory capture works. You write the standards, and the standards protect you from competition.
The First Amendment problem nobody mentions
A few comments raise a constitutional angle that the Anthropic post skips entirely. If the government bans US citizens from possessing a broad, economically significant technology, that likely requires a new act of Congress. SCOTUS would probably treat it as a "major question" subject to strict scrutiny, which is a very high bar. The export control on Claude Fable was not even extended to Five Eyes countries, which suggests the US government either does not take the threat as seriously as Amodei does, or does not believe it can defend a broader restriction in court.
This matters because Amodei's three proposed measures all require government action. Chip export controls are already in place but leak like a sieve. Distillation crackdowns require proving that a specific model was distilled from a specific proprietary model, which is technically hard and legally novel. Global safety testing requires getting the CCP to agree to test its own models, which Amodei himself calls "maybe possible" because China might also not want AI-built bioweapons. That is a lot of "maybe" resting on a lot of good faith from actors who have no particular reason to provide it.
Where I land
I think Amodei is sincere about the safety concerns. The "Adolescence of Technology" essay he references was written six months ago and is consistent with what he has said for years. People who have worked with him say the safety interest is genuine, not a strategic pose. I believe that.
I also think the HN thread is right that genuine concern and competitive self-interest can coexist without either being fake. The history of regulation is full of industries that truly believed in the public health or safety rationale for rules that also happened to raise barriers to entry. The motive does not have to be cynical for the outcome to be protectionist. Anthropic proposing the testing regime that would define the competitive bar is not a conspiracy. It is just what happens when the regulated write the regulations.
The post is more honest than its critics say. The critics are more right about the structural incentives than the post acknowledges. Open weights are a public good when the models do not have dangerous capabilities, and they are a risk when they do. The line between those two cases is the whole argument, and nobody, not Anthropic, not the HN thread, not the open letter signatories, can draw it without it moving.
The real question is not whether Anthropic wants a ban. They say they do not, and I think that is accurate. The real question is who gets to define "sufficiently capable" when mandatory testing becomes law. If that definition lives with the labs, the safety argument is real but the competitive moat is also real. If it lives with an independent body, the labs lose control of both the risk and the market. Amodei's post does not address this. The HN thread does, which is why it has a thousand comments and the post does not.