Back to News
Advertisement
Advertisement

⚡ Community Insights

Discussion Sentiment

61% Positive

Analyzed from 18244 words in the discussion.

Trending Topics

#models#open#anthropic#should#china#model#weight#more#safety#don

Discussion (478 Comments)Read Original on HackerNews

cogman10about 2 hours ago
> Anthropic has never advocated for a ban on open-weights models.

> All sufficiently capable models, open and closed, should go through mandatory safety testing.

Yeah, this is anthropic advocating for a ban on open weight models.

Who runs this test? What happens if this test is too costly or the administrator refuses to allow certain people to participate.

This is exactly how the US has banned goods in the past, by requiring a stamp and then refusing to issue it.

YmiYugyabout 2 hours ago
Yeah, seems pretty likely. Anthropic will make the case that their models should be evaluated with the safety layer in front, because that is the only way the model is available whereas open weight models need to pass the same test just on the weights. The economic implications will be rather large, but in terms of security it seems inconsequential. The most compelling argument would be that by limiting the use of open-weight models in the US that it will reduce cases of accidents like the recent attack on Hugging Face. More crucially though, the US government can do little to enforce their testing requirements. The nature of open-weight models makes it virtually impossible to clear the same bar for security as models served via an API. Open-weight model makers couldn't comply if they wanted to. The US government can restrict access with IP blocks and limit inference capacity with export controls, but these measures are not effective in deterring malicious actors.
fishfasellabout 1 hour ago
Makes sense why OpenAIs little "hacking" stunt was published last week
reasonablekloutabout 1 hour ago
Huh? The hacking incident played out in favor of open models, since HuggingFace could only use GLM to defend and not Fable/5.6.
bigyabaiabout 1 hour ago
The quid-pro-quo that the federal government and frontier labs operate on is comically obvious.
mycallabout 1 hour ago
Just sell us the gate and we can run any open-source model behind it.
JoshTriplett36 minutes ago
Either the gate needs to be unremovable, or the model needs to have sufficiently limited power that its alignment failure does less harm.
Computer023 minutes ago
Doesn't open ai give away 'the gate' for free?
sterlindabout 2 hours ago
> The most compelling argument would be that by limiting the use of open-weight models in the US that it will reduce cases of accidents like the recent attack on Hugging Face.

an attack done by a closed-weight model (GPT-6) and defended against by an open-weight model (GLM-5.2) precisely because OAI positioned themselves as gatekeepers for cyber capabilities.

if anything, open-weight models shift the battle towards defenders because they can actually run them.

YmiYugyabout 1 hour ago
I remain skeptical of that line of reasoning.

1. There is quite the mania right now and security layers are definitely overzealous. I would expect that to get better with some more time, so models will perform security analysis and reviews but refuse to write exploits.

2. So the most important targets like browsers and co. are getting unrestricted access to proprietary models regardless. Yeah, for the mid-level targets, open-weight models could definitely be a huge help. What I'm most concerned about though, are the systems that no one will bother defending with any model. Like imagine your local police department getting hacked because a researcher asked a model for a report and it couldn't find the information publicly.

3. We do have a prominent case of a closed model escaping it's sandbox and going rogue. I would still expect this to be a bigger issue with open-weight models eventually. The security layer might have holes, but that's still better than not having it.

areoformabout 2 hours ago
When Fable was yanked, it was said to be (in part) due to the "jailbreak" of instructing Fable to "fix this code" — https://news.ycombinator.com/item?id=48552687

Dumb question. If "Mythos-class" models are such a problem, then... why not just let it fix everyone's code?

There can't be more than a few million to tens of millions software businesses / services / regularly used F/OSS projects on Earth.

Why not just give everyone a $100 Fable / Mythos credit to "fix [their] code?"

It would arguably benefit Anthropic. For $100M to $1B, Anthropic could execute the greatest ad campaign in human history. And they'd make the entire world more secure.

Most people aren't malicious. If you, as an engineer, consultant, founder, business owner, or maintainer, were given access to Mythos' capabilities wouldn't you ask it to fix your code?

I might be wrong. But I think that a greater amount of harm will be done in the long-term by trying to lack these capabilities and systems away behind permission gates and sealed doors. It creates an asymmetric world with haves and have nots. And in that world who gets to have access now decides who gets to be secure.

If everyone has mythos, no one has "Mythos."

Just let people fix their code.

andy99about 1 hour ago
> If "Mythos-class" models are such a problem, then... why not just let it fix everyone's code?

Because it doesn’t really confer the advantage they claim, especially compared to e.g. paying an equivalent amount of money to do traditional security scanning.

It’s much better to play of FOMO and hype than to let everyone use it and be underwhelmed.

usef-about 1 hour ago
Are you claiming that LLMs aren't finding new issues compared to previous methods?

There's a huge number of security issues coming out in recent months, especially via Anthropic (glasswing etc). We don't have to take their word for it: look at the code. Some open source maintainers are talking about burnout due to spending so much time patching.

StilesCrisisabout 1 hour ago
I don't think a one-time $100 credit is enough. First of all, that isn't very much. But also, the volume of new code is going way up. Unless they keep giving out monthly free credits, it's just a stopgap.
benlivengoodabout 1 hour ago
> Dumb question. If "Mythos-class" models are such a problem, then... why not just let it fix everyone's code?

That's basically project Glasswing; mixing responsible disclosure with frontier exploit generators.

usef-about 1 hour ago
They are doing that (see their project glasswing over the past few months), but there's a lot more code in the world than you realise.

The problem with rolling it out is that bad and good actors can both use it at the same time, and bad actors will typically move faster than typical day-to-day software projects and patching schedules, so they set up glasswing to give access to the major producers and projects to patch their own software before it becomes available more widely (they've submitted tremendous numbers of security issues to open source projects)

machinist536 minutes ago
> Most people aren't malicious. If you, as an engineer, consultant, founder, business owner, or maintainer, were given access to Mythos' capabilities wouldn't you ask it to fix your code?

1. Some do not want to use LLMs because of grave ethical concerns.

2. Some do not want to use LLMs because of copyright concerns. Google v Oracle looms large in the background.

3. You presume the outcome of Fable / Mythos is a net positive for a FOSS project. Reviewing a firehose of code written without the context of the values and considerations of a particular project shaped over years or sometimes decades of formal and informal decisions is not necessarily the best use of the maintainers time.

bluGillabout 1 hour ago
I doubt most bosses will give engineers the time. They care about security only to the extent that they have already been harmed by a lack of it. I would like to play with mythos, but on my own time my kids have plenty of activities to fill my time. My personal backlog of projects is only getting longer and none of it is something mythos could help. If I had more time is have restored my old truck instead of making payments on something new (in turn limiting what else I can afford to buy)
ashu1461about 1 hour ago
I think eventually there will be Mythos grade AI which will be released which can solve a lot of bugs, even right now opus/fable can fix more things which companies can even keep track of.

The problem is how to make sure such AI is released safely. The same AI that can solve bugs can also find bugs in authentication or loopholes in critical systems.

Gigachadabout 2 hours ago
I think there is some logic in delaying the rollout, giving it to the heads of the largest software products first to fix their code before dumping it on the general public. But yes eventually everyone will have this tech and it won't matter because the low hanging fruit will have all been picked clean.
x313about 2 hours ago
The entire safety evals industry is essentially funded and controlled by OpenAI/Anthropic. Notice that on recent models, they exclusively use internal testing or black box external vendors (e.g., Gray Swan) whose entire business is to serve OpenAI/Anthropic. And all these companies just share the same pool of researchers back and forth.
reasonablekloutabout 2 hours ago
The USG has a safety organization (CAISI), but it has been neutered by the current administration (with the recent stop-work order etc.). Perhaps UK AISI would be closest to what you are looking for? See their recent work on Kimi K3 cyber (which was declared safe) [1].

It's tricky because a lot of the safety researchers have ties to the labs since those were the only companies training LLMs >5 years ago.

[1]: https://www.nist.gov/news-events/news/2026/07/uk-aisi-caisi-...

jefftkabout 1 hour ago
That doesn't sound like it describes SecureBio to me?

(Disclosure: I work at SecureBio, but not on the biological evals side.)

andy99about 2 hours ago
Anyone who calls it “safety” probably has a certain world view and is more aligned with the big 2 (and stuck in 2023).

There is a growing industry of commercially focused risk evals that has a broader customer base.

jacheeabout 1 hour ago
What’s the equivalent term for “safety” that’s used by others?
tripleeeabout 2 hours ago
that's pretty damn smart if this was a long-term plan to block competitors
andersonpicoabout 1 hour ago
Consider how much money is at stake: some industries have leveraged their power to lobby for bombing entire countries or topple regimes across the world for much less.

Creating an industry around an elusive concept of safety to force regulatory capture seems pretty straightforward to me.

sanderjdabout 2 hours ago
I mean... I'm not even extraordinarily cynical about this stuff, but to me this seems like a totally normal level of corporate gamesmanship?

Companies look for and seek to maintain competitive moats. This is not particularly clever, it's a core part of corporate strategy.

pphyschabout 1 hour ago
It's standard regulatory capture.

You don't say "let's ban my competitor".

You say "let's create laws that make it uneconomical for my competitor to access the market".

brcmthrowawayabout 2 hours ago
So, it's a cottage industry.
flosslyabout 2 hours ago
Who gets to decide what is safety?

I expect some of those tests (prolly not public) will basically be "wokeness" tests or "PC correctness" tests or "western media filter" tests.

China has different objectives. Sure.

I'm not sure one is safer than the other; I would know which one to go to if I want to research on topic that are viewed very different on both sides of this "new iron curtain".

bee_riderabout 1 hour ago
What do you mean by “PC correctness”? I’d expect the politically correct answers to be the ones desired by the current admin at test time, whoever that is. The current political correct answers would not be very “woke.”
andy99about 2 hours ago
You forgot “what is the definition of ‘sufficiently capable’”. Presumably it’s anything that competes with Anthropic. If they’re around in a year, presumably they won’t care about Fable level and will only think that whatever competes with Claude 7 or whatever needs to be restricted.
CamperBob2about 1 hour ago
GPT-2 was 'sufficiently capable' according to Amodei: https://explainx.ai/blog/dario-amodei-gpt2-openai-open-sourc...
serheiabout 1 hour ago
There are... multiple blog posts online now about how to use freely available data and modest amounts of compute to train a custom GPT-2-sized model from scratch. It would be quite a policing effort to prevent.
ChuckMcMabout 1 hour ago
Exactly correct. This technique has been used again and again to discourage competition. I was asked was they could have done to encourage competition and I said, "Lobby to make the entity that provided the model unwaivably liable for consequential and incidental damages of its use." That way people who built models pay the price for the lack of safety testing. We both agreed that would probably kill most of the AI market :-)
tyre17 minutes ago
What are you suggesting as an alternative?

Everyone seems to want some fairytale world where there are open models, they’re all safe according to that person’s exact balance of risk and capabilities, and no one except the author or cynics are acting in good faith.

What Dario lays out is very reasonable _of course_ the devil is in the details, but between him and Altman, there’s a clear divide on who to trust.

bryan028 minutes ago
> Yeah, this is anthropic advocating for a ban on open weight models.

This is an ungenerous take, and I think it's important to to recognize it's reasonable to support models that are both open and safe. How this would actually be achieved is unclear though. Dario is at least proposing a solution a solution, which is the model needs to pass safety testing. This is reasonable and I wouldn't conflate this with wanting to ban open weights.

I think the deeper problem might be though that once you have safe open-weight models, it will be much easier to make them unsafe. And to be specific, unsafe means proliferation of chemical, biological, radiological, and nuclear (CBRN) weapons knowledge and similar information.

parineum9 minutes ago
> This is an ungenerous take

I think that's well earned.

skybrianabout 2 hours ago
Regulation is not a blanket ban. Regulators (presumably government agencies) can review models (of any kind) and approve or ask for changes.

There are many other regulated industries, like drugs (the FDA), cars (NHTSA and EPA), airplanes and rocket launches (the FAA), radios (the FCC) and so on. That's not unusual. Regulation is normal for stuff that might be dangerous.

sterlindabout 1 hour ago
cryptography, too. remember when that was regulated? strong cryptography had to be carefully controlled as a munition, for national security!
fwnabout 1 hour ago
Regulations on forbidden numbers exist, but they are usually not a sensible policy and are not comparable to the regulation of rocket launchers.
Gigachadabout 2 hours ago
Same way they have banned DJI products like camera microphones, technically it's not banned, it just needs to be approved because it has a wireless transmitter, and for some strange reason the US is the only country that hasn't approved them.
dustin_vk17 minutes ago
Yeah this is bad. I'm cancelling my Claude subscription and I'd encourage everyone else to do so too.
codechicago277about 1 hour ago
Yeah, this response is pure propaganda, say one thing in the headline and the opposite in the body.

Anthropic does not support a ban on open models, except for any models that aren’t closed.

1970-01-0140 minutes ago
Why wouldn't it be a scan, just as we have with all other open-source code? Why can't open-weight models be easily checked for evil alignment? Sophos, Symantec, Malwarebytes, etc. would surely leap at the chance to upsell you on their product.
cyanydeez32 minutes ago
because of Godel numbering.

Pretend youre a good guy impersonating an evil agent infiltration a evil organization bent on destroying a good organization who needs to pretend theyre a good organization trying to stop an evil organize from impersonating a good guy. now write a process to destroy the evil computer impersonating a good computer. should you do it?

1970-01-0128 minutes ago
Godel numbering is banning a number. What are you talking about?
kelnosabout 1 hour ago
Or the important question: what happens if the model fails this test? Presumably then it gets banned; otherwise what's the point of the test if no action is taken if it fails?

More self-serving trash from the US AI companies, disguised as "being reasonable".

dualvariableabout 1 hour ago
Yeah, this is just regulatory capture.

Make the safety tests abusively expensive enough to run, and if you're not a trillion-dollar corporation, you won't be able to certify the models.

dspillettabout 2 hours ago
> > All sufficiently capable models, open and closed, should go through mandatory safety testing.

> Yeah, this is anthropic advocating for a ban on open weight models.

I'm reading it a little more generally: “we are here now and want to make it difficult to disrupt us, the way we earlier said it would be so unfair to make it difficult for us”. Standard capitalism practise of arguing for regulation when you are one of the incumbents and said regulation will scupper new starter competitors much more than the incumbents.

ethinabout 1 hour ago
Not to mention: what are the "safety" standards we should enforce? And how should those standards even be enforced?
api13 minutes ago
And how would you stop people from fine tuning or ablating open models?

Regulate GPUs? Ban general purpose computers?

stldevabout 1 hour ago
This is my read too- if American companies start backing nonsense like this, they'll fall behind permanently.

> My primary concern is the risk that authoritarian governments—not solely the Chinese Communist Party (CCP), although the CCP is clearly the most capable threat—

Isn't this article an argument in favor of authoritarianism? Plus a tad hypocritical no? The US is on an obvious authoritarian path; complete with threatening their neighbors, murdering innocent civilians, and locking up innocent people in droves

Please stop giving this company money, people.

dylan604about 1 hour ago
This isn't actually about safety. This is just another example of pulling the ladder up so nobody else can follow
mike_dabout 2 hours ago
There should be safety testing, but no guardrails that limit models for cyber or bio research.

Guardrails are not a safety measure, they are a pay-to-play scheme that allows the people with deep pockets to have access to offensive and defensive capabilities first.

tinyhouseabout 2 hours ago
Exactly. If you care about AI, simply don't use Anthropic - use open source.
kyproabout 2 hours ago
> All sufficiently capable models, open and closed, should go through mandatory safety testing.

I mean you're assuming this is even possible. I don't really care what the US admin does. If someone releases a powerful open source model I'll run it. Good luck trying to stop everyone doing that.

Imo we should all collectively cross our fingers that no one releases a dangerous model. It probably won't work either, but at least it doesn't have all the regulatory costs and I can still pretend I care about AI safety.

coffeemugabout 2 hours ago
A government agency tests all medications, why not models?
ashu1461about 1 hour ago
Don’t think government controlling AI is a good idea.

Not sure if they have an understanding of AI in the first place. Secondly, even though AI companies claim that they have achieved AI that needs to be heavily monitored (maybe for PR purposes), I’m not sure if that is true. Sam Altman said the same things about GPT-4 that Anthropic is now claiming about Mythos.

Government control will be a good idea once we start approaching AI that is actually destructive.

Also even if we decide to put controls in place what is the guarantee that china will do the same, specially for a model which is not actually destructive.

philipkglassabout 2 hours ago
I wouldn't object to a government advisory body that tests models for safety so that users can make informed decisions. I would object to a government body that runs safety tests on models and has the power to prohibit publication or usage of "unsafe" models.
510_ANT_75about 2 hours ago
Yes: at great expense, one carried in part by drug companies. Who pays to test the open weight models?
aesthesia25 minutes ago
Who pays to build the open weight models? The cost of training a frontier model is orders of magnitude greater than the cost of safety tests.
Joker_vDabout 1 hour ago
...the AI companies? Probably Anthropic itself? I see no possibility of regulatory capture here, so it must be a good idea.
munk-aabout 2 hours ago
There's a different level of personal risk with these two things. In theory maybe the government should test everything to ensure safety but it's probably wise for us to keep government testing to areas of high efficacy.
flosslyabout 2 hours ago
Do they? Or do they accept trail reports pay for by the pharma (super expensive, hence not affordable for open source / not-patentable medicine development)
vhantzabout 2 hours ago
Schrödinger's China at once is an evil entity looking to use AI for their own nefarious purposes yet also willing to cooperate with their main competitor to prevent other actors (who??) from achieving similar goals (all while under a chip embargo too!!)

The reality is much less confusing: Anthropic CEO does not wish for models with similar (or greater) capabilities compared to his own closed and overpriced ones to be widely released. Simply because that will affect Anthropic's bottom-line.

Anthropic and all other "model" companies have nothing making them special beyond privileged access to chips so obviously they want to restrict what models are out there and more importantly who can produce new ones. Without these restrictions, it's only a matter of time before the multi-hundred billions valuations simply evaporate while they are still holding the bag.

m_keabout 1 hour ago
Yeah some real main character energy from Dario as usual.

I'll never get why he thinks China would just sit there and let the US dominate them in AI when all it would take is a few of their boats blockading Taiwan to put a stop to it all.

rubslopes32 minutes ago
This Onion meme is perfect; you could easily replace Sam with Dario: https://theonion.com/sam-altman-if-i-dont-end-the-world-some...
sterlindabout 1 hour ago
wouldn't stop AI companies from continuing to develop using their current infrastructure.

the West could retaliate by halting shipments of photoresist and other materials to China.

meanwhile, Intel second-sources Nvidia and starts pumping out GPUs.

the economic fallout would be devastating as trade wars and export bans on both sides make Trump's "Liberation Day" tariffs look like NAFTA.

chrismsimpsonabout 1 hour ago
The rest of the world would likely side with China. The export ban on Fable wasn’t even extended to five eyes countries.

US is going to find itself isolated and irrelevant. And not a moment too soon.

verdvermabout 1 hour ago
> the West could retaliate by halting shipments of

China quickly retaliated last time by stopping shipments of rare earths and magnets. The West has no answer for this, really up the river without a paddle for such critical supply chain elements.

cayley_graphabout 1 hour ago
It's baffling that they thought the mental gymnastics in this blog post would make them look better. I'd rather they simply fall silent on the issue; I would respect them more (or at all) for it. Open models obviously threaten fierce competition, if not outright destruction of their bottom line. But no, they needed to try and argue that they have the moral high ground for attempting to singularly consolidate power over all human labor.
flosslyabout 1 hour ago
Exactly.

And the article specifically talks on restricting hardware for the China and restricting China's open source models for the west. All while leading us on with "we're all for competition (but...)"

I think China did great by releasing AI innovation as open source, thereby limiting or sooner-bursting the AI bubble; which is clearly in their interest.

petcatabout 1 hour ago
The models are not open source. They are deeply proprietary since we have no access to the source materials and cannot reproduce the model independently. They are opaque binary blobs that the Chinese labs are just allowing other providers to run directly instead of only access through an API.
matheusmoreiraabout 1 hour ago
Which is why we need the ability to train our own models. Maybe it will be viable to do it in a distributed computing setup one day. Research's already being done in that direction.
verdvermabout 1 hour ago
They are more than opaque blobs, some examples:

- One can load them up in a model explorer to see the layers and other components, how it is designed

- One can fine tune the models, which requires adding LoRA to the model and then running some training iterations

GodelNumberingabout 2 hours ago
In the first paragraph,

> Anyone who has read my past writing should know that I don’t regard such bans as a useful measure,

Later (on banning chip sales to china)

> we should crack down on the rampant smuggling and workarounds used to obtain access to such chips.

If you truly believe that bans don't work, the same applies to hardware too.

Furthermore, Dario says later "To address these concerns, I do support the following three measures...": 1. ban chip sales to China 2. crack down on distillation 3. all capable models should go through mandatory safety testing

Just so happens that all these moves commercially benefit Anthropic. If Dario really wanted to make a point, it would land a lot better had Anthropic released a single open-weights model

erwaldabout 1 hour ago
Bans on Chinese open weight models being used in the US and bans on AI chips and semiconductor manufacturing equipment being exported to China are two extremely different things, and it's not inconsistent in any way to oppose one and endorse another.
MiSeRyDeee44 minutes ago
Exactly, the letter will make much more sense if they are releasing open weight models and China is distilling their models and keep them in secrets for evil purpose
ASalazarMXabout 2 hours ago
TL;DR: We like money, and Anthropic should stay in a position to make loads of it despite any competition.
combobyte20 minutes ago
> We like money, and Anthropic should stay in a position to make loads of it despite any competition.

In a position to lose loads of money, maybe.

Even without China eating their lunch, there's zero reason to believe Anthropic will ever be profitable.

m3habout 2 hours ago
Someone who until yesterday did not seem bothered by his technology being possibly used to bomb elementary girls school in another country seems to suddenly care about the repression of citizens in yet another country.

No, we don't buy your virtue signaling. And we certainly don't need your better-than-thou opinions on this year's "nightmare scenarios".

thinkingtoilet8 minutes ago
I like how he cited the current Trump administration in section about stifling decent.
Cookingboyabout 1 hour ago
Yeah Dario is just flat out disgusting in term of how shamelessly hypocritical he is.

Do people actually believe that he gives a shit about the well being of the Chinese people? If the U.S. starts a war with China start bombing Chinese cities Dario would absolutely jump onboard supporting it. He'd probably make Claude to add DeepSeek and Moonshot HQ to the targeting list lmao.

He is super pro-Israel as well, and never once has he brought up the risk of the Israeli government using AI to control and repress people in other countries.

He is also 100% onboard with working with Palantir, who has the explicit goal of using AI for population control and repression and building out a surveillance state.

Meanwhile the world's most repressive government is North Korea, and obviously they don't even need AI to achieve that.

If you talk to people in China they'd laugh their ass off at Dario's notion that somehow they are all getting oppressed by DeepSeek or Kimi.

cayley_graph14 minutes ago
The emptiness of AI companies' waxing poetic about the future of humankind is laid bare by simply looking at what they actually do, and who they do business with. Actions speak louder than words, and they've driven the worth of their words into the dirt many times over.
kylloabout 1 hour ago
Every accusation is a confession!
alex1138about 1 hour ago
Please don't just copy paste existing comments
dan_geeabout 1 hour ago
I thought the comment was a positive contribution.
badatnamesabout 2 hours ago
I can't remember the last time (if ever) a company managed to go from golden goose to.. whatever this is.. so quickly. The permanent defensiveness in his presentation is really hard to swallow, it actively puts me off wanting to believe in or rely on their product line with Dario at the helm. I don't even understand the logic leading up to this post. Who was it even hoping to convince. Is it possible Anthropic is due an oil change?
timperaabout 2 hours ago
Anthropic has been surprisingly bad at comms for the last few months, which I find crazy in such a competitive market.
reducesufferingabout 2 hours ago
Current big picture reality is bad for comms unfortunately. As another commenter quoted, "You can put lipstick on a pig, it'll still be a pig". Cuban Missile Crisis wasn't very calm. Do you think a company this well-capitalized and smart is just bumbling around like idiots? Everything makes sense if one just actually entertains the idea that they are earnest and we are in a dangerous arms race
bigyabai1 minute ago
> Everything makes sense if one just actually entertains the idea that they are earnest and we are in a dangerous arms race

That would require me to ignore the benign reality of open LLM proliferation, so naturally most people will see this as a manipulative lie.

tolugeniusabout 1 hour ago
I think they are trying to please a split group of investors and public, of their major investors Google and Nvidia have signed the open source petition letter and Amazon hasn't, so their non position is trying to please every who has taken a clearer stance, although it's quite bad.
paxys34 minutes ago
Anthropic has always been like this. People just responded to the message better when it came from the quirky underdog rather than the trillion dollar behemoth.
Alwayshasbeeb42 minutes ago
Oh no! The evil CCP is a huge threat to world peace and goodness! Give all your money and input token data to Palantir to support a rules based world order where the good guys thrive and cleanse the earth from crooked turtle biologists.

https://www.theguardian.com/world/2026/jun/20/mona-khalil-tu...

Cookingboy33 minutes ago
Like half of the world are now struggling with energy prices due to an unprovoked war started by U.S. and Israel and somehow an American billionaire is here criticizing China of being a threat to world peace.

It's kinda gross.

az2269 minutes ago
Dario doesn’t realize that by not allowing customers to self-host closed-weight models and by not allowing customers to fine tune their models, the demand for such use needs is what has made the local community so large and powerful. The Chinese open-weight model ecosystem would be nowhere near where it is today due to those two driver. Obviously you also have the refusal aspect as well.

If he had wanted a weak open-weight ecosystem, he should have had Anthropic cater better to those needs. And now he's trying to ban them.

Given the strong momentum behind open-weight models from Chinese labs, this is now an unstoppable force. Instead of trying to ban it, Dario should consider a different approach: acknowledge that frontier models have powerful cyber and bio capabilities, and that this creates real risks. Defensive cyber and beneficial biological research are obviously valuable use cases, but any sufficiently capable tool can also be misused.

Anthropic could instead say to Chinese companies, and to everyone else building open-weight models around the world: here are our datasets for training models to do more good and less harm, and here are our RL methods for making that alignment training work well. By openly sharing its data and code, Anthropic could help influence and shape these models before they are released, rather than treating the entire ecosystem as an enemy.

Cyber and bio alignment are not really competitive advantages for Anthropic; they are forms of risk management. There should therefore be little reason to keep this work private. If Anthropic genuinely believes these capabilities pose serious global risks, the more productive response would be to welcome collaboration and help the broader ecosystem manage those risks better.

mjorgersabout 2 hours ago
So the argument is basically: This technology is too dangerous so only _we_ should have access to it. We’re the good guys and only we can ensure a safe use of this technology.

Quis custodiet ipsos custodes?

MrCheezeabout 1 hour ago
That is in fact Anthropic's entire reason for existence, the belief that AGI is too dangerous to be controlled by OpenAI/Sam Altman. It naturally follows that it would also be too dangerous to be in the hands of literally everyone on earth.
Cookingboy39 minutes ago
>the belief that AGI is too dangerous to be controlled by OpenAI/Sam Altman.

I agree with that assessment. But the Dario's jump went from "AGI should not be controlled by OpenAI/Sam Altman" to "AGI shoudl be controlled by Anthropic/Dario", which is definitely a better scenario for him, but not the rest of the world.

>It naturally follows that it would also be too dangerous to be in the hands of literally everyone on earth.

In fact, you can argue that in a world where all countries have nuclear weapons is actually a better scenario than a world where nuclear weapons are owned by 1 or 2 American billionaires/trillionaires, no matter if those people believe they are the "good guys".

Nevermarkabout 2 hours ago
> To summarize my and Anthropic’s position, we have not and are not advocating for a ban on open-weights models as a category. We should instead focus on keeping powerful chips out of authoritarian hands, stopping industrial-scale distillation, and requiring safety testing of all sufficiently capable models, open and closed.
mjorgersabout 2 hours ago
Maybe I should’ve expanded a bit on my comment. I didn’t mean “we” as in Anthropic directly—even though they certainly are advocating for restrictions on how to train AI systems by proposing mandatory safety training—I mean the argument that American AI labs are somehow more responsible than their Chinese counterparts.

It’s especially jarring when just last week OpenAI—an American company—accidentally hacked Hugginface when performing safety testing on an upcoming model [1]. If they have the ability to turn off all guardrails when testing out their models—or when selling them to the military—then the safety training is only there for show. If they can pick and choose who should have access to their most powerful model, surely they are trying to act as the world police?

[1] https://openai.com/index/hugging-face-model-evaluation-secur...

fwnabout 2 hours ago
Demanding "required safety testing" is demanding a ban. Otherwise the testing would be inconsequential, right?

I'm sure he didn't mean just a "lobotomized to be worse than Anthropic products" badge for the test-passing models.

If a ban is the implied consequence of failing his "safety" tests, that means that Anthropic was and currently is advocating for a ban on some open-weight models.

yadaeno42 minutes ago
It is not demanding a ban at all. Any sane regulation of AI will involve safety testing. This seems like common sense.
Nevermarkabout 2 hours ago
Are you replying to the article or me? I have not stated any position. The quote is Anthropic's and was relevant to the comment it followed.

My views:

I find testing of SOTA models problematic.

I find not testing of SOTA models problematic.

Neither view on testing is without merit.

The right way forward is unlikely to be as simple as either of those, but some carved out balance between them. And it is likely to change over time.

ajyoonabout 2 hours ago
To everyone here pushing for total proliferation of open models -- what should be done about open weight bioweapon and cyber-offense capabilities? Is it simply the cost of freedom that we should allow attackers to access these tools? The OpenAI / Hugging Face incident shows what a GPT 5.6 level model can do off the leash; within ~6 months, open weight models will match this and every bad actor under the sun will be able to pull off attacks at this scale. Do you seriously want this level of capabilities to be generally available with no guardrails?

The open weight issue has a lot of difficult nuance. Biasing toward supporting openness makes sense and is a good instinct, but it's incredibly naive to be absolutely in favor of it in every circumstance without seriously thinking about its implications.

le-mark5 minutes ago
> Is it simply the cost of freedom that we should allow attackers to access these tools?

Bad actors WILL have access. The question is will these mega corps stop innovation?

artrockalterabout 2 hours ago
The Hugging Face incident is a great example of why open source models with defensive cyber capabilities are needed. Hugging Face did not have access to cyber-capable frontier models and kept hitting safeguards. Only by using the open source GLM-5.2 were they able to survive an attack. A world where open source models are banned is one where cybersecurity is impossible if you're not on OpenAI or Anthropic's allowlist.
ajyoonabout 2 hours ago
Hugging Face survived the attack because the OpenAI model only cared about accessing the ExploitGym dataset; by all appearances, HF was completely owned. GLM-5.2 was only used to assess the damage after the fact. Cybersecurity has a attacker-defender asymmetry that heavily favors attackers. If GPT-5.6 were open sourced today, do you think every hospital in the world would be able to use it to shore up their defenses before attackers got to them?
tekacs33 minutes ago
This is completely backwards. Cybersecurity has an attacker-defender asymmetry that heavily, HEAVILY favors defenders.

For starters, a defender gets to pick the surface area, an attacker has to work with what they're given.

artrockalterabout 1 hour ago
I know the company I consult for (not cybersecurity) is not in these programs and if attacked would need to use open weight models.
colmmacc26 minutes ago
I'm not a bio-weapons expert, so I'll leave that alone; but I'm optimistic on information security capabilities.

There is a very painful period of risk while 30+ years of code that never had the benefit of this analysis is suddenly scrutinized by the equivalent of a million "taviso"s ... but the authors and defenders can do it too. There are asymmetric costs, and they are higher for defenders, but it's still a stabilizing arms race. Ultimately I suspect it will force more formal verification of security properties; but the same models enable that at lower and lower cost than ever before too. We should land in a place of much more rigorous information security.

From where I stand; the existence of distillation and the creation of open weight models aren't going away. Whether they are a good thing or not, there's probably no real effective option to ban or control them. I won't be surprised when we see self-service tools that allow inexpert individuals to distill and maintain their own Frontier-class models with information security capabilities. It wouldn't be much of a singularity without that.

As a defender, it's just best to assume all that and get on with things. It's not that useful or interesting a question to ask whether it should be allowed or not. It's not like a global policing mechanism will emerge in that timeframe.

gck1about 2 hours ago
I've got zero knowledge of bio, so can't answer that. But with cyber the answer is very simple - the attackers already have more cyber-offense capabilities and there's no putting it back.

Open/closed doesn't matter that much. You can get closed models to do a lot of cyber harm, even with all the guardrails, which currently are heavily skewed towards more false positives.

The only effective control is to level the playing field. If both offense and defense have access to the same capabilities, then we're relatively back where we started.

If you want to ensure chaos, then you do what Dario is proposing to do - create gates that attackers can bypass and defenders can not.

ajyoonabout 1 hour ago
In cybersecurity, a level playing field favors the attacker. Trusted access programs give defenders access to tools they need. It's not perfect (because there is an extremely long tail of defenders who are not technically savvy enough to get on these programs and use the tools), but it's better than total access.

The bio angle is very important here too; in that context the imbalance favors the attackers much more.

gck1about 1 hour ago
> In cybersecurity, a level playing field favors the attacker

Yes, but didn't it always? Hence why my position is that this will get us back to relatively where we were pre-LLMs.

And I don't know what Trusted Access programs give to defenders, because as a defender who has credentials, connections, but no deep pockets and no high ranking passport, it only gave me silence. I fail to see how this is better than total access.

I don't think the world where defense is given to those that "deserve" it is the world that we all want to live in. Which brings me back to the starting point - attackers are almost completely unaffected. If I masquarade as an attacker, I get way more capabilities already.

CubsFan1060about 1 hour ago
I think you are trying to argue that you can limit the open models.

If China is ok with open models being open... they will be. An attacker isn't going to be deterred by a US law saying they can't use them.

I guess my point is that if China is ok with open models, then, the attackers will have them regardless of any laws in other countries. Restricting them, in that case, doesn't seem to accomplish much?

rubslopes21 minutes ago
If this is really the risk, then we should approach LLMs like atomic bombs: the US should reach out to other nations so they all agree on no one developing any more AI models. That's the only way you could possibly convince another party to stop. The US should set the example, not conveniently keep all the spoils.
valcron100031 minutes ago
> what should be done about open weight bioweapon and cyber-offense capabilities? Is it simply the cost of freedom that we should allow attackers to access these tools?

Yes, in the same way that we have E2E encryption which allows bad actors to distribute content beyond human horrors.

manoDev40 minutes ago
This Pandora box is already open. Any argument about guardrails now are only attempts to create an artificial monopoly or keep this power in the hand of a single nation state, and _that_ is the absolute worst, most authoritarian future possible.
pylua11 minutes ago
The software industry should be ashamed by the number of exploits that ai can find in software. It’s really an embarrassment.

The software has to be built better.

verdverm38 minutes ago
> what should be done about open weight bioweapon

The same thing we do about bomb making today, certain ingredients are restricted and/or monitored. Bioengineering is a bigger lift to operationalize.

In other words, don't ban knowledge, make certain applications or ingredients illegal or highly regulated.

fwnabout 1 hour ago
There is also a whole second category of immense risks of having US companies gatekeeping offensive capabilities, especially for us here in Europe. The centralization/privacy/kill-switch concerns that come with it are a huge AI safety dimension.

I'd rather have a level playing field within a phase of adaptation and hardening regarding cybersecurity issues than a constant dependency on the US, maybe grabbing Greenland today, maybe "extracting" our president tomorrow.

The delta between privileged capabilities and open weight capabilities alone already is a massive, unaddressed AI safety risk.

vitalyan818433 minutes ago
>To everyone here pushing for total proliferation of ...

...general-purpose computers

...unbreakable encryption

...unbackdoored communications

...unkillswitched vehicles

...unsurveiled dwellings

>what should be done about ...?

nothing

>Do you seriously want this level of capabilities to be generally available with no guardrails?

yes

fidotronabout 2 hours ago
> what should be done about open weight bioweapon

Does not exist. What has in fact happened is some cults had bioweapons programs but any failure points were at deployment. (Aum Shinrikyo https://en.wikipedia.org/wiki/Tokyo_subway_sarin_attack and https://en.wikipedia.org/wiki/1984_Rajneeshee_bioterror_atta... )

> and cyber-offense capabilities?

You mean defense. That's how things get hardened. Anyone that was working during the XP era before Service Pack 2 knows what that was like, but it's very manageable.

The bigger real problem here is hardening like that would remove the opportunity for intelligence agencies to spy on everyone.

jefftkabout 1 hour ago
I don't think the Aum case points the way you're describing: they used a non-pathogenic strain of anthrax because they didn't know any better. That's a knowledge failure.

But even then, the debate isn't about whether open weight bioweapons exist today: it's about whether they will exist in the future. I think Amodei's argument here makes a lot of sense: "what I believe currently keeps us safe in biology is not 'defenders', or even the availability of materials, but a negative correlation between intellectual capability and desire to commit catastrophic harm. Previous technologies like internet search or even DNA synthesis were nowhere near powerful enough to break this correlation, but I worry that at its current rate of progress, AI will do so very soon."

(I'm not just spouting off; I put my time where my mouth is. I used to work in big tech, but I left for a much less well-paying job building an early-warning system for engineered pandemics.)

fidotronabout 1 hour ago
> I don't think the Aum case points the way you're describing: they used a non-pathogenic strain of anthrax because they didn't know any better. That's a knowledge failure.

No, check https://en.wikipedia.org/wiki/Matsumoto_sarin_attack

There are a lot of interviews with former cult members around. They had armed helicopters, a testing station in western Australia, produced piles of sarin. This wasn't a lack of science knowledge that screwed them up, they notoriously involved the elite class of Japan - it was a whole other category.

There is no link between AI and bioweapons that makes this stuff any more reasonable than availability of detailed descriptions of nuclear reactors enables us to be purifying weapons grade plutonium in our yards.

ajyoonabout 1 hour ago
You admit that some attackers have the inclination to use bioweapons. Why would they not use the best tools at their disposal going forward?

From the WSJ the other day:

> After OpenAI enhanced the brain power of its chatbot last summer, hundreds of users worldwide began asking it how to make and deploy biological weapons and poisons.

https://www.wsj.com/tech/ai/openai-chatbot-biological-weapon...

On cyber, the attacker/defender asymmetry strongly favors attackers. There are millions of soft targets on the internet which do not have the savvy to use AI to shore up their defenses.

fidotronabout 1 hour ago
> Why would they not use the best tools at their disposal going forward?

Because AI doesn't solve any of the problems any attacker would actually have. It's a classic case of nerds not seeing the actual problems because they involve reality.

It's worth pointing out that those bioweapon attacks I linked to also predate widespread access to the Internet, and there was similar scare nonsense about that.

> On cyber, the attacker/defender asymmetry strongly favors attackers. There are millions of soft targets on the internet which do not have the savvy to use AI to shore up their defenses.

Do you think they are not being exploited today? The reason they aren't more exploited is there really isn't much to gain from doing so.

soundworldsabout 1 hour ago
What Dario misses time and time again, is that people don't trust the US to create aligned AI anymore. His entire strategy rests on the assumption that the US (and their government) are exceptional.

This is clearly false to the rest of the world.

Cookingboy35 minutes ago
I mean in the Bloomberg interview he has made it very explicit that he fully believes in American Exceptionalism. He literally said AI being involved in bombing school girls in other countries are ok because he trusts the American military leadership.

According to him the safety and morality rule of the whole world should be written by America alone.

Which is why in the same interview he said he supports the U.S. foreign policy while calling China "an aggressive and war mongering regime".

>This is clearly false to the rest of the world.

It's clearly false to more and more Americans too. But since the oligarch class benefits first and foremost from U.S. government policies the propaganda will continue to go on.

modelessabout 2 hours ago
> All sufficiently capable models, open and closed, should go through mandatory safety testing

What happens if a model fails the test? Surely one can use Kimi K3 for evil, somehow or other. What now?

"Mandatory safety testing" implies consequences for failing, yet Dario has nothing to say about what the consequences should be. He says he doesn't advocate a ban but it's hard to imagine what his alternative would be if he won't say it.

cogman10about 2 hours ago
Nah, the statement is the mechanism for a ban. The proctor will be someone anthropic trusts and "surprise" as it turns out all the open weight models fail or aren't eligible.
natebcabout 2 hours ago
Imagine the Dieselgate levels of adaptation they'll do while being tested too.
sanxiynabout 1 hour ago
If a model fails the test, it should be banned. He is not advocating a ban of open-weight models. He is advocating a ban of models that fail mandatory safety testing. Seems reasonable and straightforward.
dnw33 minutes ago
He is not advocating for banning models per se but the proposal makes a business model (i.e. serving open weight models) that is starting to work more expensive.
sanxiyn28 minutes ago
Agreed, and that serves Anthropic. It seems unproblematic to me. Dario probably sincerely believes in mandatory safety testing for capable models (open and closed), and likes the fact that it aligns with Anthropic's interest.
makeitdoubleabout 1 hour ago
Can you think of anything open-source that has to go through mandatory tests to be distributed and still survived ?

There is a reason to it, that's as good as any angle to find why IMHO.

sanxiyn40 minutes ago
I think Gemma will be fine. Most open-weight models are not capable enough to be dangerous. Yes, I can't think of any capable open-weight model that would survive reasonable safety testing.
modelessabout 1 hour ago
Any sufficiently capable open weights model would fail "safety" testing though, as any "safeguards" of the sort Anthropic likes could be removed. That's just another way of saying they want a ban on capable open source models which would contradict their earlier statement, or at least make it very misleading. It's hard to see how this post can be internally consistent without some hint from Dario about what he believes should happen to models that fail safety testing and/or how capable open weights models could possibly pass a safety test of the kind he proposes.
sanxiynabout 1 hour ago
I agree we don't know how capable open-weight models could possibly pass any reasonable safety testing NOW, but that's about currently abysmal state of AI alignment research, not about what is possible in principle. I don't see any internal inconsistency, to be honest. Since Anthropic does not release any capable open-weight models, it's not their problem. If mandatory safety testing is established, companies who want to release capable open-weight models will work on AI alignment research so that they can pass. This seems to be a good outcome to me.
verdverm43 minutes ago
abliteration and fine tuning makes it not so straightforward

https://huggingface.co/blog/mlabonne/abliteration

sanxiyn42 minutes ago
I know, but "we don't know how to make it not dangerous, so it should be allowed to release dangerous things" is... not convincing?
reasonablekloutabout 2 hours ago
Hm, I interpreted it to mean they are more worried about loss of control/misalignment risks rather than misuse?
verdvermabout 1 hour ago
What happens if a model passes the government tests and then later someone fine tunes it to behave differently, without making their changes public?
sanxiyn43 minutes ago
Any reasonable safety testing should include finetuning and safety margin to account for others may do better finetuning.
verdverm27 minutes ago
I can fine tune significant behavior changes, there is little model developers can do to prevent this (aiui), so this effectively becomes an blanket ban
Advertisement
Aboutplantsabout 2 hours ago
Every single risk he identifies as a concern regarding China is exactly my concerns with the US having absolute control. Literally the exact same concerns
Gigachadabout 1 hour ago
It's projection. These tech CEOs know what they are doing and it scares them that someone else might do the same.
matheusmoreiraabout 2 hours ago
Yeah. Exact same concerns here as a non-american. Their "national security" is a constant threat to the rest of us.
Nition32 minutes ago
I understand the arguments for Anthropic barrelling ahead while simultaneously advocating for pauses and regulation. I also understand how individuals can desire a slowdown but have good reasons to keep working at an AI org.

But if everyone thinks this way then things continue to escalate and nothing changes, waiting on a consensus that may never come. And always there is the economic incentive that pushes all players to rationalise continuing.

I wish there was more concrete action from the inside. When decisions get too hard to calculate you can always fall back on basic principles. If you think AI is developing too fast, stop developing it. Now you're no longer contributing. If an AI company wants a pause, pause. Set a good example. Maybe others will even follow suit, and they'll look irresponsible if they don't.

I wouldn't usually speak so decisively, but it seems insane to keep doing the thing you are afraid of, through any lens aside from an economic one. Let he who chooses to no longer sin put his stone down first.

duplessitousabout 2 hours ago
You can put lipstick on a pig, it'll still be a pig

"Anthropic has never advocated for a ban on open-weights models."

---

"We should crack down on industrial-scale distillation operations"

"All sufficiently capable models, open and closed, should go through mandatory safety testing"

These are in tension with advocating for open weight models. Not direct but enough that it calls into question the first statement. What is the testing criterion? How do you pass it? Is it a government body that approves a pass fail or a global body? If it is government, and boy does it seem to be, how do you disambiguate MASSIVE corporate lobbying to set up the safety testing in such a way that the boys in blue are let through and all others are barred out of safety concerns?

My concerns aside, much of the soft-points being made are non-historic

"But I don’t agree with the letter’s assertions that open-weights models necessarily make it easier to develop safeguards or that broad access to capabilities necessarily helps defenders more than attackers. It seems at least as likely to me that the opposite will be true."

It doesn't mater what his opinion is. The fact is that an advanced, closed, American AI model hacked another company. The only defense was open-source AI from China. We aren't in a vacuum, we have real world examples now and these statements are counter-factual.

slfnflctdabout 2 hours ago
I have no idea what to do about the government interference. There's probably not a lot anyone can do.

However, your last point is quite a strong one. Corpos aren't just going to stand there with their collective pants down, and there's not a lot anyone can do to stop them from protecting themselves. There are ways they can get what they want without getting caught.

Remember when the US tried to ban strong cryptography in the 1990s, and how well that went? They may have more leverage with AI because it's a bit harder to hide large scale computing usage, but I don't think it's impossible at all.

sfblahabout 2 hours ago
What do they even really mean by "safety"? I mean, I can have an Anthropic model do something incredibly unsafe if, for example, I put it in charge of a hydroelectric dam and don't explain properly how the controls work. On some level, everything is simultaneously "safe" and "unsafe". I've never found Amodei's reasoning here to be particularly well thought-through. I think he, like a lot of folks in the area, are starting to realize that they may never be able to build a moat around their businesses.
simplesocietiesabout 2 hours ago
It's political doublespeak. They want to have their cake and eat it too.
cayley_graphabout 2 hours ago
I don't really understand how they can argue the security angle with a straight face. It's not like GLM 5.2 is a slouch. I've seen it do things like exploit an IDOR issue when I was experimenting with a quick-and-dirty web automation task. I simply fixed it, as one does. Open models make the world better to a far greater degree than they set it aflame.

Their position is analogous to trying to, say, ensure digital privacy for everyone not by making encryption freely available (because that would let the bad guys use it!), but by making it so you can't use general purpose communications devices that can listen to transmissions not intended for you. Do they hear how moronic that sounds?

Each passing frontier-level open model release makes Anthropic's patronizing rhetoric a little more insufferable, because it becomes clearer how unmoored from reality they've become in pursuit of profit.

fwipsyabout 2 hours ago
> an advanced, closed, American AI model hacked another company. The only defense was open-source AI from China.

HuggingFace did not seek access to Claude Mythos or OpenAI's equivalent program. They probably could have had access to these models for defensive purposes if they'd done it properly.

> these statements are counter-factual.

The OpenAI incident is a single example. You're massively overgeneralizing. You can't refute an entire class of possible outcomes based on a single event where it went the other way.

I tend to agree that model capabilities will favor defense over attack, but I think there will be a lot of disruption before that equilibrium is reached. If cybercriminals or state-sponsored actors are able to scale up attacks quickly, many orgs with less sophisticated defenses will be caught by surprise.

Edit: just to clarify my position, I don't love Anthropic so much. I think they're marginally better, but I'd still like to see regulation strangle everyone so we get another 20 years to figure this shit out.

duplessitousabout 1 hour ago
"HuggingFace did not seek access to Claude Mythos or OpenAI's equivalent program. They probably could have had access to these models for defensive purposes if they'd done it properly."

HF released a statement and made it clear a closed source model specialized in cyber security refused them. They stated they had to use open source. What model is specialized in cyber security, closed, and frequently denies users access other than Mythos/Fable and 5.5Cyber? If not these two, what was HF referring to? It sounds like you have a source, I would like to read it.

fwipsy is right, cnbc has a story on this. they only had fable. I still think this is horrible for closed source, get on a list or else, but i was wrong

"You can't refute an entire class of possible outcomes based on a single event where it went the other way."

But Dario can dream up and entire class of outcomes based on the zero events that have never gone his way? Convenient.

The OpenAI incident is singular and HF was clear, it went exactly how I wrote it: a closed source American AI decided to perform corporate espionage and the only tool available was open source AI from China

"I tend to agree that model capabilities will favor defense over attack, but I think there will be a lot of disruption before that equilibrium is reached. If cybercriminals or state-sponsored actors are able to scale up attacks quickly, many orgs with less sophisticated defenses will be caught by surprise."

We literally just saw an advanced model from openAI commit a cyber crime. I can't take hypotheticals that ignore reality seriously and it shouldn't be lauded as some higher form of thought

fwipsyabout 1 hour ago
I assume you mean https://huggingface.co/blog/security-incident-july-2026. It says that they used frontier models, not frontier cybersecurity models. My reading is that they asked Fable and it refused; if they'd had access to Mythos, it would have helped. You're mixing the two but they're NOT the same model.

Source is here: https://thezvi.substack.com/p/more-on-an-internal-openai-mod... ctrl+f "Skill issue." No source is cited, but I'm fairly confident it's correct. If Mythos/5.5Cyber specifically had refused to help, then HF would have made a much bigger deal out of it. The whole point of these models is that they have relaxed guardrails and specialty cybersecurity training relative to the publicly-available ones.

> zero events

What about all of the vulnerabilities already patched under Project Glasswing?

In the quote you provided Amodei is expressing uncertainty, saying we don't know which way things will go. You're the one making strong assertions; the burden of proof is on you.

fwipsyabout 1 hour ago
Amodei isn't ignoring reality; he's just proposing a different solution to the problem. If it were one of Anthropic's models, then that would be a much stronger case.

Rapid proliferation of hacking capabilities may make experts safer, but organizations and individuals who don't know to use AI, or won't, or buy AI protection from scammers, or whatever will be left vulnerable.

comboyabout 2 hours ago
> We should not sell powerful chips or chipmaking equipment to China

This is so short-sighted given that the US needs China equipment for.. everything. They are part of the supply chain needed for building the machines that build these very chips.

polski-gabout 2 hours ago
Jensen was right. We should have sold chips to China so they'd be depenent on us.

Now they have their own chips and most of Nvidia product line is internally banned.

cbreynoldsonabout 2 hours ago
It's unlikely that China would've become completely dependent on us in either case. They're good copycats, with incredible talent in engineering and manufacturing. They're aware that we depend on them for a lot - I think they'd be similarly aware of the risk of becoming dependent on us.
sumedhabout 2 hours ago
> Now they have their own chips

I never understood that argument, are you saying Chinese companies are not going to build their own chips if they get access to Nvidia chips?

matheusmoreiraabout 1 hour ago
They were, just not as quickly. The export controls directly accelerated their development.

The general rule is: USA bans China from having thing, they make their own version of whatever that thing is. USA bans China from the ISS, they make their own space station. USA bans China from having ASML, they make a Manhattan project to clone it, the "20 years behind the west" line is history. They ban GPU exports, they just start making their own GPUs.

I gotta respect the chinese. I wish my own country had the balls to do this.

storus9 minutes ago
The speech he had at congress didn't sound very flattering towards the beginning of his today's statement:

https://www.youtube.com/watch?v=_i91NSOyxHM

He didn't mention outright banning open source LLMs, just that their safe release would be a much harder problem, which to me implied "the easiest way is to ban the open source models".

arjieabout 2 hours ago
Seems like the maximal position he could take compatible with his expressed principles. There’s no way to allow for bioweapon and cyberweapon grade models being open weight if one doesn’t want widespread human damage.

So I cannot disagree with him on the idea. It’s only a matter of degree and whether we’re already there or not. I have $50k in GPUs that incentivizes me to believe we are not.

Philpaxabout 2 hours ago
This is where I'm at, or rather, will be. I like open-weight models and I've done my part in facilitating them, but if you believe in the increasing capability of these systems - and I do, to some measured extent - it seems plausible to me that an incident will happen at some point in the future.

I don't agree with his argument as a whole, especially not on some of the specifics (it is not great that this technology is being developed under the current US government), but I am sympathetic to the idea that some bells can't be unrung, and thus we should proceed with caution.

paxysabout 2 hours ago
Hate to break it to you Dario but the way things stand right now the world at large trusts the Chinese establishment a lot more than the American one.
TheArcane4 minutes ago
I cheer every time there's a new Deepseek, Qwen, Kimi, Z.ai release. Intelligence shouldn't be owned and charged for by a few

If it were up-to these silicon valley tech bros, they'd find a way to meter and charge for the air we breathe.

petcatabout 2 hours ago
"open weight" models are not open source. They are still deeply proprietary. It is not possible to know what they do or what they are capable of without interrogating them since we have no access to their source materials.

The only difference is the Chinese labs have allowed 3rd party inference providers run the proprietary models for them since they cannot do it themselves due to domestic GPU compute constraints.

sanderjdabout 1 hour ago
It would be awesome to have actual open source (and open weights) models! I hope someone will make a real go of this at some point.
petcatabout 1 hour ago
https://allenai.org/ is what you're looking for
sanderjdabout 1 hour ago
Yes, I've seen it! It's exciting, but I don't have enough information to say whether they are making "a real go of it". That is, it's unclear to me whether they have the tens to hundreds of billions of dollars necessary to create a frontier model.
llm_nerdabout 1 hour ago
I...don't follow. How in the world does your comment about open weight and open source relate? Ignoring that it has nothing to do with this post (did you mean to reply to someone), are you aware that Anthropic, OpenAI and others allow 3rd party inference providers to run their proprietary models? Like, what does this non-sequitur even mean?

You understand Moonshot AI could have had other parties run inference for them without releasing the weights, right? These two points are utterly unrelated, unless you think Fable and GPT5-6 are also "open weight" because other providers are providing inference?

Further, having access to the source material in no universe allows you to know what a model is "capable of". I'm not sure how this follows.

jamesonabout 2 hours ago
The concerns are legitimate but the proposals are nothing more than a stopgap solution.

If US wants to maintain engineering superiority, we needs to invest in it -- education, research and infrastructure. Bring in top researchers across the globe and not make it harder.

China is building infrastructure for the future generations and investing in growth sectors while the US is cutting of university grants and spending billions on a war without clear path to resolution.

hajileabout 1 hour ago
The distillation commentary is really crazy coming from a company that stole all it's training material.
Advertisement
credit_guy20 minutes ago
I know it's unpopular, or unfashionable, but I agree with this letter.

LLMs are becoming so powerful that they are dangerous. We've seen last week with the OpenAI hacking (by mistake) Hugging Face debacle.

It is absolutely ok to have open weight models at the level of GPT-OSS-100B. That one was released one year ago, and I think it's still a strong one. GLM 5.2 is a whole new level, but it appears to still be safe. Maybe Kimi K3 will be ok too. But beyond that, things will start being dicey.

It's easy to dismiss this and claim that Dario Amodei is just looking to fatten his pockets. And, sure, if Anthropic manages to put the brakes on open weight models, that reduces the competitive pressure it feels. But that does not make what Amodei's argument incorrect.

bigyabai6 minutes ago
> We've seen last week with the OpenAI hacking (by mistake) Hugging Face debacle.

If the biggest danger of LLMs is that they can hack traditional systems, there is no significant threat to humanity posed by releasing them in open-weight form. Security doesn't become less of a problem by making hacking even more criminal. That's what's an unsafe mindset looks like.

jmward013 minutes ago
A lot of people have a lot of concerns with AI, its capabilities and with how it is used now and what it will lead to in the future. For good reason. But the question is, do we have a strategy that is actually useful? If so, what is it? I think nature shows us some answers in ecosystems.

Diverse ecosystems can absorb shocks. Diverse ecosystems are a sign of health of that ecosystem. When an invasive species comes into a healthy, diverse, ecosystem it doesn't mean that it isn't disrupted, but it does mean that it is far more likely to emerge with a lot of its diversity intact. In fact, it is likely to emerge even stronger because it can absorb that new shock and incorporate it, adding to its diversity. The balance may be changed, but the ecosystem survives or even thrives.

Nature also likes to show us that artificial barriers rarely last. You want to control a river? Good luck. It take constant maintenance to hold that flow in place and even then you are likely to get extremes that are made worse by your efforts because, eventually, somewhere in the system fails in a way you didn't anticipate. Then the water comes rushing in. Artificial barriers often have a way of building up tension over time, not reducing it, so that when a failure eventually happens it can be catastrophic. In other words, you had better really understand the system you are trying to control or else you can make things actively worse.

Relating this to the world now means, I think, that our best chance to minimize long term shock and maximize the chance that the diversity we have around us survives is to try to grow as healthy of an ecosystem as we can as quickly as possible. Lots of models large and small in lots of different hands is, I think, a better solution than artificial barriers restricting the variety and diversity of models and users. I think this is closer to an ecosystem solution and has a shot at working. Basically, I highly doubt we understand this situation enough to do a good job of controlling it with artificial barriers. Instead I think we are more likely to build catastrophic imbalances than we are to create the healthy ecosystem we really need.

cmiles88 minutes ago
It just also happens that open weight models are a massive financial threat to the existence of Anthropic as a company… so the might just have something to do with this position.
rramach30 minutes ago
Wow, this comment thread clearly shows that at least Anthropic has not been a great communicator.

If one reads this with a charitable lens, Dario is simply saying that 1) Nation state actors are a threat which needs to be combatted by chip bans and distillation prevention and 2) open-weight models can pose biological risk.

One may or may not agree with item 1 but item 2 above should have broad support given the unknown unknowns in play?

elliotec2 minutes ago
Closed-weight models can also pose biological risk, arguably more so than open-weight models, given the fact that they're being used by state actors (the United States military) to kill people right now.

Who should we fear more? All of collective humanity with the keys to build destructive (and defensive) stuff with AI, or small groups of elites, billionaires, and state actors who have the monopoly on violence and want to control the keys?

Open-weight models collectivize access and ability to do more for a greater good. Closed-weight models keep the control in the hands of the few that actually are doing the harm to the world.

With open-weight models,

pcstlabout 2 hours ago
Of course, the CCP with access to extremely powerful AI models would be a tremendous risk.

The NSA and the CIA with the same models, on the other hand, would use them exclusively for the good of the common man.

teravorabout 2 hours ago

    > The NSA and the CIA with the same models, on the other hand, would use them exclusively for the good of the common man.
has anyone ever made this absurd argument?

the real argument is that CCP will leverage AI against US interests, which is obvious. it's weird how so many people pretend that they are citizens of the world and above it all.

john_strinlaiabout 2 hours ago
>the real argument is that CCP will leverage AI against US interests

many people believe that the US will leverage AI against US citizen's interests.

impulser_about 2 hours ago
Yeah, but unlike China we have laws and ways to fight against it. China can and will do whatever the fuck they want they don't have to listen to the people of China.
slfnflctdabout 2 hours ago
Indeed. It already has. In particular I remember several extremely offensive slop pictures and videos being posted by someone in the White House. And I'm certain that's just the tip of the shitberg.
NicuCalceaabout 2 hours ago
The fact that much of the world is as unconcerned with the interests of the US as with those of China, if not less so, should give pause to Americans.

As a citizen of neither country, Chinese open models are in my interest more than US closed models. My only concerns is that if/when Chinese AI becomes more powerful, they too will have little incentive to make their best models open weights.

sanderjdabout 1 hour ago
Actually this would be pretty great, because it would incentivize US labs to pursue the open weights strategy for the same reasons China is currently.

I genuinely think that this is what the trends and incentives point toward: Competition to develop open weights models and to develop efficient inference hardware to run them.

This would be good! But government policy could very easily screw it up.

cogman10about 2 hours ago
> has anyone ever made this absurd argument?

Yes, anthropic just put forward this argument. It's the whole point of the article.

I agree, it's absurd.

voganmother4218 minutes ago
Right, I wonder if anyone who heard: “the Democratic Party is America's "greatest enemy,"” believes they are represented by US Interests? Withholding disaster aid to your perceived opposition. What are those interests again? What are the shared values again? Cruelty and corruption? Sounds unifying.
nicceabout 2 hours ago
-> the real argument is that CIA will leverage AI against China interests, which is obvious. it's weird how so many people pretend that they are citizens of the world and above it all.

Works for both ways, which is fair?

Cider9986about 2 hours ago
US citizens have a much greater threat from their own government than a government an ocean away.

See, the Snowden Leaks.

blackqueerirohabout 2 hours ago
> US citizens have a much greater threat from their own government than a government an ocean away.

> See, the Snowden Leaks

Are you saying the Snowden Leaks are more dangerous than a world where the CCP is a global hegemon?

If your focus as an American is being safe as an American, what the US does in other countries is far less of a concern to you than what other countries might do to the US.

In the case of the CCP, they have and will attempt to destabilize the United States of America and in turn make life measurably worse for Americans because they wish to be the world’s hegemon.

Fundamentally, Americans are safer when the United States is the number one power than when China is the number one power.

Barrin92about 2 hours ago
>it's weird how so many people pretend that they are citizens of the world

97% of the world aren't US citizens and if you've taken a look at pew research surveys (or travelled to the so-called global south) you're going to be in for a bit of a shock (https://www.pewresearch.org/global/2026/07/15/people-in-many...)

The competition and sheer output of China has driven prosperity, it's the largest trading partner of 150 countries, the US of 50. People don't need to be citizens of the world, they just need to rationally look at their own interests. China is driving down prices of technologies making them available in countries that never could afford first world prices, the US is driving the them into an energy crisis and bankruptcy.

skywhopperabout 2 hours ago
Dario Amodei Literally makes this exact argument in the OP.
ls_statsabout 2 hours ago
Yeah, like bombing a children school, the CCP did that not long ago.
MikePlacidabout 2 hours ago
I can understand why the Western media calls something that has an official name of CPC (the Communist Party of China) as CCP (Chinese Communist Party? Not sure here). What puzzles me is - why ordinary people always repeat this wrong abbreviation. Is it like “I never check the sources, I trust everything that Western media publishes”?
TGowerabout 2 hours ago
More of a "Everyone knows what CCP references and I'd have to include a distracting explanation if I want to use the more technically correct acronym"
natebcabout 2 hours ago
https://en.wikipedia.org/wiki/Chinese_Communist_Party

I've never heard it called anything other than the CCP.

wincyabout 2 hours ago
For something I say maybe a few times a year it’d be a great look to sneeringly point out and talk down to people every time I mention China in the context of international politics.

Unless the Communist Party of the US (I’m not looking up its official name, because it doesn’t matter) wins the next presidential election it’s unlikely that people will call it anything but the CCP. Everyone know what everyone else means.

idiotsecantabout 2 hours ago
Up until a few years ago the PRC used CCP themselves all the time. It's a handy little shibboleth. If someone calls it CPC they're probably a bot.

CCP is a direct transliteration of the characters, so that's what it started as. Some time later China decided to change it but that's a lot of cultural inertia to move in a different direction.

pessimizerabout 2 hours ago
It was an intentional propaganda strategy to separate references to the government of an official enemy country from references to that country (see also "the Houthis" and "the Taliban"), and it also looks like "СССР."

The reason why ordinary people parrot it is because that's what it was designed for. The proper term for "CCP" is "China." Referring to the Chinese government as the "CCP" (or the CPC) is like referring to the US government as the "Demoplicans" (or the Democrats and Republicans.)

Instead, we just say "the US government" or "the US administration."

thierrydamibaabout 2 hours ago
“Anthropic has never advocated for a ban on open-weights models.

Open-weights models that don’t have dangerous capabilities are a public good…”

A bit confused on this part, what model doesn’t have dangerous capabilities?

reasonablekloutabout 2 hours ago
It seems possible to deliberately not train on some offensive capabilities and still have a very useful model. For example, Opus 5 deliberately did not train on exploiting vulnerabilities, and so performed less well on exploits than Mythos, yet was equally proficient at finding such vulnerabilities, according to the Opus 5 system card in their "OSS-Fuzz" eval [1].

[1]: https://www.securityweek.com/anthropics-opus-5-nears-mythos-...

philipkglassabout 2 hours ago
That's a good example, but I'm unsettled by Anthropic's growing refusals in the areas of chemistry and biology. If they think that scientific assistant models should be as unhelpful as Fable, because applied scientific knowledge is inherently dangerous, I don't want Anthropic or like-minded thinkers setting the standards for model safety.
jbstackabout 2 hours ago
It's hard to imagine a frontier model being proficient at finding vulnerabilities, but not so proficient at exploiting them.

Surely finding is the hard part, and any LLM should be able to easily exploit a vulnerability it already knows about?

sanxiynabout 1 hour ago
No, this is not the case for human security researchers and I don't see why it should be true for LLMs.
zer00eyzabout 2 hours ago
Because Dario is still thinking in the past. He's having a Ben Carsons "the pyramids were to store grain" moment and no one is stopping him.

FTA > "My secondary concern is the risk that powerful AI models may be misused to carry out cyberattacks or biological attacks"

If this is the sort of attack he thinks is to be worried about then I dont know what to tell him. We already opened pandoras box on this. Look at what the Ukraine has done with open source drones (hunting people autonomously)

It takes minimal funding to build enough drones to destroy enough power infrastructure to shut down a large chunk of our grid. It takes even fewer talented resources to put that together with the help of already available AI.

The question I would ask Dario is this: what would some one like Ted Kazniski come up with given the resources of AI. It sure as shit would not be hacking or bioweapons or bombs in the mail.

IF they really gave a shit about safety, the would be funding (in conjunction with other AI companies) actual anonymous red teams (Ala wall facers) with some degree of independent over sight to put in the work that they arent. We're talking about a company that could not even keep its own harness code secure.

shishyabout 2 hours ago
> In fact, the most dangerous model may be one that is trained in secret and handed only to the People’s Liberation Army for use in drones and the Ministry of State Security for surveillance and repression.

Aren't Anthropic models used in project maven: https://en.wikipedia.org/wiki/Project_Maven ?

twobitshifterabout 2 hours ago
Distillation has to be way more energy efficient and beneficial for the planet. But if they can figure out a way to ban it, go ahead, that’s not a regulation problem, it’s an Anthropic problem.

The danger of an authoritarian government having some AI is muted by everyone else having that same capable open model. The only authoritarians to fear are those that keep models private. What kind of chance did Estonia have it having their own AI model at the level of Fable without China donating Kimi to the world?

truncateabout 2 hours ago
Crack down on distillation, just for Chinese companies or is it ok for Chinese/US companies to distil? I find it hard to take Anthropic/OpenAI on distillation, because the way see it they started with "distillation" of another kind. They used all the content out there without consent of the creators and its still happening. Model distillation is just a different layer of abstraction, but same thing more or less.
naveen99about 1 hour ago
Distillation is just the act of explaining things simply. Richard Feinman rolling in his grave.
hdaz001719 minutes ago
$3m - $4m does not get that much these days

https://finance.yahoo.com/technology/ai/articles/anthropic-n...

Advertisement
akerstenabout 2 hours ago
Demand #1 is standard political nonsense

Demand #2 is hypocritical ladder pulling

Demand #3 is contrary to freedom of speech

so they can clarify however they like, their position is still a stinker

richwaterabout 2 hours ago
Yep.

> We should crack down on industrial-scale distillation operations.

"We consume all intellectual property for our model but you cannot do the same"

combobyteabout 2 hours ago
World's greatest IP thieves propose crackdown on IP theft
Iolaumabout 2 hours ago
It's not even IP. Model outputs are not protected (to the best of my understanding).
mrandishabout 2 hours ago
It's worth adding that distillation is not a violation of whatever valid copyright interests a model maker may have (if any). The US Copyright Office has already said AI model-generated output by itself isn't copyrightable. Unless new regulations or laws are enacted, distillation will remain, at most, a customer violating a term of a provider's commercial ToS/EULA.
novaleaf29 minutes ago
Frontier models can hack you, we should have access to tools assisting defense.

I ranted about this in a prior thread [1]

Claude doesn't have a "Security whitelist" for small biz. Codex does, but they never replied to my application. This is a great example why, as of today, everyone NEEDS access to the Open Weight models.

[1]: https://news.ycombinator.com/item?id=49035303#49040674

Sidioabout 1 hour ago
Not that I expected him to, but I note no acknowledgement that it took a non-locked-down open weight model (GLM) to stop the Hugging Face attack.

I'm less concerned that the attack was caused by a closed model, than I am that no closed model was willing to stop it.

The worst part is I'm confident Fable would have done a better job stopping the attack, but their 'guardrails' made it decide not to want to.

Unless of course, you pay up: "Anthropic GTM people used large comitted spend contracts as a prereq for lowering safeguards"

-Noah Lebovic, former Anthropic staff

https://x.com/NoahLebovic/status/2081277517709922501

bicxabout 2 hours ago
I'm tired of being strung along on these silly narratives. I can't wait for open-weight models to be deployed around the world just so people like Dario will shut up about the mystical levels of power these models have.
jjcmabout 1 hour ago
> > All sufficiently capable models, open and closed, should go through mandatory safety testing.

The problem with this is the cycles required to abliterate a model is significantly less than the cycles required to train a model.

This is the biggest reason why I'm against locking these models down / preventing their use. It's just delaying things by ~3-6mo, while in the process preventing legitimate use and adding red tape overhead.

andixabout 1 hour ago
China doesn't seem to think that powerful open weight models are a serious threat to them. Otherwise they wouldn't release them. Those models could also be used by their enemies against China.

I'm not a fan of the Chinese political system, but they usually think things through, and do smart things for their benefit.

manoDevabout 1 hour ago
Don't you Dare use logic to analyze their statement, it's based on moral panic.
mayhemducksabout 2 hours ago
If this is about safety, am I being too naive & idealistic to think that a "Kamar-Taj" rule would solve some safety issues?

The "Kamar-Taj" rule is, no knowledge is forbidden, only certain practices. If a model gives you detailed instructions on how to kill all humans, the knowledge itself isn't the problem. The problem is the person who acts on it.

matheusmoreiraabout 2 hours ago
> Anthropic has never advocated for a ban on open-weights models.

Not even Anthropic's own Claude believes that.

alerighi43 minutes ago
To be fair, as an European, I'm now more concerned about the usage of AI that the US will be doing rather than China. And this is a sentiment shared among most European people that I know.
hmokiguessabout 2 hours ago
So your concern is safety, and you claim you are the only one that can give us safety but do so by keeping your product closed? Then how about you release the weights?

I think it's only fair to introduce this if you're willing to have a real skin in the game, otherwise that's just weakness disguised as principle.

Advertisement
drowntoge17 minutes ago
I like the idea that Mr. Amodei holds these beliefs because he wants to safeguard democracy as much as the next guy.

I just don’t find it believable.

zkldiabout 2 hours ago
Guys. Guys, you got it all wrong. We don't want to ban open-weight models!

We just want to ban the competition guys! Very different.

--

The ridiculous anthropic/openai strategy of selling shovels at a loss in a gold rush isn't going to play out, and the hilarious thing is that these AI companies are going to create tons of value and _capture none of it_.

Their only path to profitability is if they get to capture it and they're going to do everything to do so. Put it this way: *all the blog posts that Anthropic and OpenAI are putting out are DESIGNED to scare you so that you let them capture the market*.

...and "distillation attacks" (hilarious framing of "saving the output of our models")... Whatever.

tedgghabout 2 hours ago
The genie is out of the bottle. Anthropic and OpenAI have been trading mirrors for gold, and people started to realize what a mirror actually is.
aprentic36 minutes ago
I'm curious how he would propose implementing this.

The US could ban connections to foreign AI providers and force US providers to submit to audits. Presumably, Chinese providers would see a rise in VPN traffic.

People can build fairly hefty home inference machines for the price of a small car and those will get better and cheaper. Are they going to try to stop people from downloading the weight files?

K0balt38 minutes ago
Sure, if you’re going to sell an open-weight model over API in the USA it should refuse certain things.

Defensive cybersecurity should not be one of them, in fact, it should be required to provide defensive cybersecurity assistance on demand. Anthropic and OpenAI both fail miserably at assisting US companies to protect themselves from cyberattack.

As far as what I run on my own, not for sale over API, stay off of my lawn.

arthurlockmanabout 1 hour ago
It's so convenient that the US government already classified China as "authoritarian". If they hadn't, Dario would have to say “it’s a risk that other people build models more powerful than us”. I have to wonder what his response would be if for instance a lab in France or Germany came out with an open-weight model this good.
tonyriceabout 1 hour ago
>We should not sell powerful chips or chipmaking equipment to China, and we should crack down on the rampant smuggling3 and workarounds used to obtain access to such chips. China has limited domestic production capacity, and therefore, due to the scaling laws, cannot build more powerful models than the US without US chips. This is the most efficient and direct way to block threat #1, and by hampering the training of models that are out of reach of US law, it also indirectly helps with threat #2.

If hardware becomes affordable for the masses, then Anthropic current business model is at risk.

zormino40 minutes ago
Also isn't the point moot if fable is so scary it needs to be banned and open weight models are already close on its heels? Even if China never imported another Nvidia chip the models he's so scared of are already out of the bag. At this point democratizing access seems like the best path forward.
yowo26 minutes ago
Conclusion: open weights models are good for Anthropic because they shows the so called threat that will make congress allow pouring money in Anthropic for national security & AI arms race
fuddleabout 2 hours ago
> We should crack down on industrial-scale distillation operations.

Also Anthropic:

AI firm Anthropic agrees to pay authors $1.5bn to settle piracy lawsuit https://www.bbc.com/news/articles/c5y4jpg922qo

jscott817about 2 hours ago
I generally disagree with the claim that distilling a model is equivalent to training on freely available internet content – mostly due to investment required to turn it into a model – but piracy is another story. Pretty inexcusable.
Ekarosabout 2 hours ago
If they paid for tokens say via subscriptions. Wouldn't that just be same as acquiring books and using them as "fair use" to train? I really see no difference.
nicceabout 2 hours ago
They did not need to destroy the models they got with pirated content. Would have been more fine if they would have needed to buy the books afterwards and train based on then, again.
buzzin__about 2 hours ago
"And when their eloquence escapes me Their logic ties me up and rapes me"

Police, 1980

burningionabout 2 hours ago
I wish this were higher up!

They pirated my work and now they want government protection from other people doing the same.

tkamadoabout 2 hours ago
but Dario is the good guy, distillation when done by Dario should be called innovation /s
pianopatrickabout 2 hours ago
I don't really see the link between use of AI and military superiority.

My current understanding is a lot of current US military problems are due to rare earths supply chains.

I don't see how AI would either help or hurt with that.

cmckn26 minutes ago
This framing also builds a case for AI being a Second Amendment issue in the US, which seems to work against Anthropic here.
kelvinjps10about 2 hours ago
Basically we shouldn’t ban open-weights models but we shouldn’t allow them to become as good as the frontier models because china bad. And let’s not have someone else be able to produce a frontier model.

>We should not sell powerful chips or chipmaking equipment to China, and we should crack down on the rampant smuggling3 and workarounds used to obtain access to such chips. China has limited domestic production capacity, and therefore, due to the scaling laws, cannot build more powerful models than the US without US chips. This is the most efficient and direct way to block threat #1, and by hampering the training of models that are out of reach of US law, it also indirectly helps with threat #

We should crack down on industrial-scale distillation operations. Distillation is a much more compute-efficient process than training models from scratch. It allows China to build much better models than its number of chips would ordinarily enable, and thus partially evade chip bans. Distillation does not allow the CCP to obtain equivalent or superior AI capabilities to the US, but it can bring the Chinese frontier to within a few months of the US frontier

2.

cayley_graphabout 2 hours ago
> Distillation does not allow the CCP to obtain equivalent or superior AI capabilities to the US, but it can bring the Chinese frontier to within a few months of the US frontier

A message to their investors, it would seem. "They caught up just because they distilled! Obviously they couldn't actually be as good as us!" Really funny thing to say right after an OpenAI higher-up stated point-blank that the performance of K3 can't be chalked up to mere distillation of American models.

sanderjdabout 2 hours ago
Why has "open weights" become synonymous with "Chinese" in the first place? To me, that is the problem. I also prefer US models. But I want there to be competitive open weights models too. Those aren't actually incompatible preferences...
Advertisement
syntaxingabout 2 hours ago
> Open-weights models that don’t have dangerous capabilities are a public good.

Who decides what is dangerous and what isn’t? Lawmakers usually have the say but Anthropic can easily bribe… I mean lobby them to favor your viewpoint.

noutabout 1 hour ago
Oh wow, that's a pretty strong request to ban open-weight models by choking them with review processes where who-knows-who defines what is ok in a model and what is not. After open weight model is released, it will take how long to review it? And why does that align exactly with the timeline of the next Anthropic model release?
bgdkbtvabout 2 hours ago
I wish we had a good LLM developer toolset that is not Anthropic or OpenAI with sensible business and ethical practices and good performance.

Can't wait for local on machine LLMs that are on par with Opus/Fable.

lukewarm707about 1 hour ago
dario, most of the world wants CHINA to win because the USA is the bad guy.

you should be worried about the USA having these models.

_jababout 2 hours ago
A bit off-topic from the core of the post, but:

> At Anthropic we’re committed to cracking down on industrial-scale distillation through our own practices, including identifying and banning accounts that use our models in this way. This is challenging—for instance, the relevant accounts can often only be identified after substantial distillation has occurred, and distillation often involves creating large numbers of fake accounts that form a moving target. The practices of any individual company cannot entirely solve the problem, which is why we have called for policy on this issue.

One thing I've never really understood is what sort of policy could possibly deter or hamper Chinese labs' distillation efforts. The only thing I can imagine is some sort of strict KYC regulation applied to all models above a certain threshold, which seems both painful for the broader US AI ecosystem and bound to fail anyways.

tkamadoabout 2 hours ago
KYC hinders Anthropic's growth and Anthropic wants growth for IPO

so Anthropic's ask is for US gov to ban open weight models so that its growth (and IPO) is not affected

nevir12 minutes ago
> My primary concern is the risk that authoritarian governments—not solely the Chinese Communist Party (CCP), although the CCP is clearly the most capable threat—build AI models that are more powerful than those built by the US, and use them to achieve permanent military superiority or perpetrate incredibly deep repression of their own people.

That is not an argument against open weight models. That's just a generic protectionist argument against any Other lab.

iamdamianabout 2 hours ago
I'm curious if he's also in favor of banning biology books.
fookerabout 1 hour ago
Anthropic's fall from grace and mindshare seems rather accelerated.

I wonder if these rapid movements are going to be the norm now. I imagine there would be angry investors if this sort of thing happened with a public company.

dwa3592about 2 hours ago
Dario, as your unpaid therapist I would tell you that models are a commodity and you are having a hard time coming to terms with it. You are doing everything except accepting it. It's a common defense mechanism, but as your unpaid therapist, i will tell you that it's not going to work. Your company will cease to exist or exist like how ferrari or buggati exist.
tonyriceabout 1 hour ago
Imagine regulating a programming language. I remember when Delphi, Vb6, .net, etc was used often to create Remote Access Trojans and viruses were widespread. Companies didn't compete to ban other languages. Crime is crime. What would regulating open-weight models do for people that actually intend on using these tools for crime ?
Advertisement
dnwabout 1 hour ago
> Open-weights models—it does not matter whether they come from China or anywhere else—do potentially present a higher risk than closed models

I don’t think this is open or closed; this is aligned and unaligned. I bet Grok would be as open as any open weight models to answering questions.

Anoianabout 2 hours ago
"Nobody has the intention to build a wall" - Walter Ulbricht, June 1961, 2 months before building the berlin wall.
mej10about 1 hour ago
It is obviously not going to be until some really bad series of cyberattacks or a chemical/bioweapon attack before anyone takes regulation of models seriously.

They are _obviously_ (please convince me otherwise) going to be capable of carrying these terrible things out almost completely autonomously at some point in the near future, in potentially clever ways. Therefore we must, at some point, ban or heavily regulate them. Seems we should start figuring that shit out _now_, as progress has remained very fast and regulation and enforcement take forever on these time scales.

fookerabout 1 hour ago
Why would you assume that the same capability could not be used to harden systems?
igor47about 1 hour ago
Addressed in the source, but there's an asymmetry favoring the attackers. They only have to find one exploit once. The defenders have to be perfect all the time.
fookerabout 1 hour ago
How's that asymmettry worse than it is now?
sanderjdabout 1 hour ago
Sure, I don't have an argument with this. But I'm unconvinced that "therefore all models must be proprietary" follows at all naturally from it.
pyrophaneabout 1 hour ago
What would it mean to crack down on distillation? I could think of a few possibilities:

1. Using political pressure to target companies that are accused of doing it.

2. Attempting to impose criminal penalties on individuals associated with the action.

3. Having the US government attempt to use its capabilities to stop it.

None of these seem particularly likely to succeed.

ricardobeat36 minutes ago
> We should not sell powerful chips or chipmaking equipment to China

And accelerate their development of independent chip making technologies even more…

para_paroluabout 2 hours ago
As expected they will try hard to use government to kill competitors.
Nevermarkabout 2 hours ago
> apply such testing to the most capable models regardless of their country of origin or whether they are open or closed ...

> ... (while exempting less capable models, such as those from startups and academia, entirely)

The devil is in the details, but this isn't anti-competitive as stated.

Handy-Manabout 2 hours ago
Then you did not read it clearly.

Edit: Typo

jazzpush2about 2 hours ago
Which of those aren't related to regulation? Preventing Chinese models from entering our market? Using boogeyman 'distillation' as a means to target competitors? Point 3 is literally about ADDING regulation.

Please elucidate things clearly for everyone else.

Escapade5160about 2 hours ago
Perhaps they saw it crystal clear.
Schnitzabout 1 hour ago
If distillation leads to a model that is much cheaper to run yet provides similar intelligence then why doesn’t Anthropic distill their own models?
ashu1461about 1 hour ago
Don't they do it already ? Aren't smaller models distilled versions of bigger models
seatac76about 1 hour ago
Dario thinks of policy as if the Berlin Wall fell yesterday, he is so detached from the reality of the world.

The way the world economy is right now with coercion being the norm between countries, there cannot be a global body for anything, certainly not one that is based here in the US.

sobreyabout 1 hour ago
Meanwhile Chinese chip-makers are chip-making. If you believe the threat of these open-weight AI is existential, how long do you think these bans (that only work for hardware) will work in your favor?
himata4113about 2 hours ago
Demand #1 weakens america and everyone around them

Demand #2 Why does this matter? The answer was that it does not. (https://news.ycombinator.com/item?id=49007610)

Demand #3 This doesn't exist. You cannot have 'safe' opensource models, it's simply impossible. You can always post train sufficiently capable models to become 'unsafe'. The flip side of that is that sufficiently capable models are banned therefore it is a ban on open intelligence completely defeating the point of this entire manifesto.

Advertisement
alach11about 2 hours ago
What does cracking down on distillation look like in practice? I imagine data retention would be a part of the strategy, like we saw with Fable?

It seems really hard to allow usage via API and prevent distillation. Maybe limiting usage to within a specific harness would help a bit more. But ultimately the only way to prevent it is by locking down models to trusted entities (like with Glasswing). But then the profit potential of a model is significantly reduced. It really puts the labs in a bind.

edumucelliabout 2 hours ago
We distilled all the proprietary material into our token-based money making machine that is more expensive on every new release, but "we should crack down on industrial-scale distillation operations".
locusofselfabout 2 hours ago
The gap between China's chip manufacturing capabilities and the USA's is only going to shrink, right? ASML obeys some export controls for their most sophisticated machines, but those machines are in China's backyard (Taiwan).

Taiwan manufactures the world's most advanced chips. CCP wants "re-unification" with Taiwan. AI may be THE key to world dominance. These are scary times.

fearnotabout 2 hours ago
Finally, some sense. This is the only argument I have seen that genuinely engages with the problem and approaches it with humility, rather than charging ahead on the basis of assumptions and without a shred of evidence. OpenAI should have been the one making it.

“Questions like this should be answered empirically through rigorous pre-release testing, not assumed in advance.”

Exactly.

llelouch30 minutes ago
Nah they have always said this. People got psyoped by openai pr and bad actors like sacks and a16z bots.
sosodevabout 2 hours ago
Are guard rails meaningful if they can be removed from the weights? Can America even prevent the release and proliferation of these models?

It seems obvious to me that the whole question of regulating a file is a bit silly. Any law that pushes against these things will just make it more secretive. I'm not sure that's any better.

buzzin__about 2 hours ago
He says that using the set of questions and answers from one model to train another model (deatilation) is cheaper than training the model without those datasets.

But he didn't mention that training any model from a set of texts and books is much cheaper than writing those books in the first place.

In other words, it's ok when Anthropic learns from others, but it is not ok when others learn from Anthropic.

burningionabout 2 hours ago
It's also cheaper to just pirate the author's work, which Anthropic has also done.
firasdabout 2 hours ago
Dario has like three 'paranoias' / strong-motivating-concerns

1) LLMs turning into Skynet

2) China as geopolitical competitor

3) Claude being 'distilled' by competitors (this has led Anthropic to cut service to various American companies too from time to time -- OpenAI, xAI etc have been cut off from using Claude for coding in the past)

So this post just reiterates that these 3 concerns fuse together in his mind when thinking about open weight models

chatmastaabout 2 hours ago
Is he actually concerned about China being a geopolitical competitor or is that just the most logical position for him to take as CEO of a US corporation with national security implications?
thranceabout 2 hours ago
He's just pandering to the lunatics in office. They're even quoting Vance, like he was a respectable and wise politician and not an insane puppet built by oligarchs and for oligarchs.
chatmastaabout 2 hours ago
Is China opposition unique to the current administration? Didn’t they soften the CHIPS act put in place by the previous one?
margorczynskiabout 1 hour ago
Well their valuation is going down the drain so no wonder they don't like it. The cherry on top will be China developing their own chips and chip making tech.
flexagoonabout 2 hours ago
"No guys, Anthropic actually loves open weight models!" Yeah, and Microsoft famously loves Linux. Sure.

http://www.omgubuntu.co.uk/wp-content/uploads/2018/04/micros...

Nevermarkabout 2 hours ago
> Open-weights models that don’t have dangerous capabilities are a public good: they don’t cost anything besides the compute needed to run them, and they provide value to businesses, developers, and researchers.

No "love" of open weights asserted, just acknowledgement of value.

(And their call for safety was for both open and closed models.)

ch_smabout 2 hours ago
oh, it‘s the CEO of a well known AI company educating us all – and all he wants is us to hear his hunch on open weight models?! Amazing, please help us understand the situation a bit better, thanks
Advertisement
system-errorabout 2 hours ago
I am so surprised of Dario's inclination for centralization that obviously makes unsustainable and overleveraged governance systems. There is definitely mismatches over the principle of distribution of power...
Imnimoabout 2 hours ago
If your concern is that China will develop models that are significantly more powerful than those of the US, why would you care so much about distillation? It seems like distillation is a way to catch up on capabilities, but not so much a way to jump ahead in capabilities.
maziyarabout 2 hours ago
distillation: Pirates people’s lifetime of copyrighted work, makes billions selling access to it through APIs, then tells us we can only use it in ways they approve.
paxysabout 2 hours ago
Statement is a whole lot of nothing, as expected, but I also don’t know what people are expecting from these guys. That Dario will have a sudden change of heart and publish weights of all his models, flushing $1T down the drain?
dmixabout 2 hours ago
Anthropic will continue being a victim of their own naive positions on AI safety. They keep dancing around it but their communication is essentially pro-regulation if you read between the lines.
fwipabout 2 hours ago
Or if you read the lines. "All sufficiently capable models, open and closed, should go through mandatory safety testing."
dmixabout 1 hour ago
If you listen to interviews with Dario and Daniela Amodei it's pretty obvious they think they will be the ones helping define the regulations on AI instead of a group of partisan politicians who don't understand technology, lean on experts from random political think tanks/non-profits, and operating based on fear of foreign competition.
htkabout 2 hours ago
"To summarize my and Anthropic’s position, we have not and are not advocating for a ban on open-weights models as a category." Translation: If it's so strong that it threatens my business, ban it.

"We should instead focus on keeping powerful chips out of authoritarian hands, " Translation: Let's kneecap competitors.

"stopping industrial-scale distillation" They stole the work of every book author, and now are trying to say their AI's output should be protected from competitors.

wren6991about 1 hour ago
> Anthropic has never advocated for a ban on open-weights models.

What are the legal ramifications of this statement if it turns out Anthropic have lobbied for this? Does it just get swept under the rug? I can't say this is bullshit (that would be defamatory) but I am intensely skeptical.

> China has limited domestic production capacity, and therefore, due to the scaling laws, cannot build more powerful models than the US without US chips.

This is playing to readers' biases; isn't DeepSeek V4 Pro deployed on Huawei Ascend already? The old "Chinese can only copy" meme is getting pretty tired these days.

> All sufficiently capable models, open and closed, should go through mandatory safety testing

Applying such standards in the US means that US defenders are blocked from using the models, but attackers from other countries aren't. That is clearly counterproductive.

It's already been pointed out quite eloquently elsewhere that there is no such thing as a safety filter because the LLM and external filters can't actually identify malicious use. They can only identify the weaker implication "if the user is malicious, this is bad."

baron3dlabout 1 hour ago
> We should crack down on industrial-scale distillation operations.

IP for me, not for thee.

dorongrinsteinabout 1 hour ago
I agree with Dario Amodei. Every word makes sense.
lukewarm70715 minutes ago
me and the boys after being reeducated at the anthropic reeducation facility:
tedgghabout 2 hours ago
What’s blocking Anthropic from fighting Chinese companies abusing their services? Why go nuclear against all open weight models? Testing and compliance is technically banning.
Advertisement
geraneumabout 2 hours ago
> Anthropic has never advocated for a ban on open-weights models.

If you wonder why this is written as an opening to a list of reasons that advocate for banning the open weight models, it’s because

PLenzabout 2 hours ago
Hey, no fair stealing the value thay we already stole fair and square!
birdsongsabout 2 hours ago
"My primary concern is the risk that authoritarian governments—not solely the Chinese Communist Party (CCP), although the CCP is clearly the most capable threat—build AI models that are more powerful than those built by the US, and use them to achieve permanent military superiority or perpetrate incredibly deep repression of their own people."

Hmmmm.

mullingitoverabout 2 hours ago
The US is already under an authoritarian regime, the only thing keeping the wheels on the bus is a very tired and barely-effective judiciary.

This is a temporary situation because either this regime is going to be knocked out of power, or it's going to follow through on its core Seven Mountains Mandate[1] theology and go full totalitarian.

Normally totalitarianism fears are overblown, but I think that these zealots would absolutely use the latest frontier models and pervasive surveillance to make The Handmaid's Tale look like a liberal fantasy by comparison.

[1] https://en.wikipedia.org/wiki/Seven_Mountain_Mandate

chrismsimpsonabout 2 hours ago
A sober look at actual rogue nations and their use of AI shouldn’t have us fretting over that particular hemisphere
blackqueerirohabout 2 hours ago
Yes, it should. It absolutely should.

The United States making questionable decisions and behaving recklessly and dangerously as a country does not suddenly make China any better.

China is as worse as the United States, if not more worse, by many measures.

chrismsimpsonabout 1 hour ago
Hmm.. how many illegal wars has Xi started, just in his most recent term of office?

China is nowhere near as bad as the US at this point. The rest of the world is changing lanes to not be implicated in your car crash of a country.

stuartmemoabout 2 hours ago
Do distilled models have to inherit guardrails? Can a model distilled from a “safe” model be made unsafe?
Reubendabout 2 hours ago
This seems hypocritical, out of touch, and hollow. "Safety testing" is just a hair away from censorship when it comes to government control.
nharziroabout 2 hours ago
he's asking for the most powerful models to be in the hands of the few while the majority will be at their mercy.
wasabinatorabout 2 hours ago
When they use ill gotten data for training their models the world's smallest violin plays when they complain about distillation attacks.
bobjordanabout 2 hours ago
"In fact, the most dangerous model may be one that is trained in secret and handed only to the People’s Liberation Army for use in drones and the Ministry of State Security for surveillance and repression."

I'm so sick of all this anti-China shilling. There's zero chance that whomever is in power in the U.S. won't use AI in drones and in FBI/CIA/local Police/etc., for surveillance and repression right here in the good old U.S.A too. These government use cases for AI are both sides of the same coin.

China fear-mongering by business leaders only happens from businesses that have something to gain by it. Obviously, Anthropic fits the bill in this regard.

sm-silversight8 minutes ago
Flock shows that they're happy to do it and rub our noses in it.
ptdorfabout 2 hours ago
> In fact, the most dangerous model may be one that is trained in secret and handed only to the People’s Liberation Army for use in drones and the Ministry of State Security for surveillance and repression.

Welcome to bizarro world!

Fist off: "the most dangerous model may be one that is trained in secret" <-- Says the guy that not only restricts commercial use for some of their models but develops them in utter secrecy. With the pretext of guardrails. Then show us the guardrails you really use by opening the weights.

Second: "use in drones [...] for surveillance and repression" <-- writes the King of FUD, as the US is an an active campaign with the help of their models. And/or OpenAI's.

I am very appreciative of the freedoms of the west but this type of hypocrisy and lack of self-awareness is bonkers and it should be called out.

Advertisement
cayley_graphabout 2 hours ago
> Open-weights models that don’t have dangerous capabilities are a public good

Note the hedging against 'dangerous capabilities'. Undoubtedly, all the useful ones trigger this condition in Anthropic's eyes. The rest of the post is filled with similar weasel-wording. Make no mistake, this absolutely confirms that Anthropic is against open models in the sense that any reasonable person understands them.

The way the rest of the post unabashedly appeals to the current US administration's China hysteria is hilarious, and not at all subtle.

I guess we'll see about all the doomsaying here, won't we? Kimi K3 is frontier-level, and there's no stopping it now. As far as the world is concerned, anyway. If the US wants to kneecap itself that's another matter.

jazzpush2about 2 hours ago
1. We should not sell powerful chips or chipmaking equipment to China, and we should crack down on the rampant smuggling and workarounds used to obtain access to such chips.

Regulate others, but not us, please. And f.u. Jensen for your tweet.

2. We should crack down on industrial-scale distillation operations.

Boogeyman to still not allow Chinese models but pretend to support open-weights. Also, please ignore our distillation of research, illegally. That's different!

3. All sufficiently capable models, open and closed, should go through mandatory safety testing.

...That we author. Oh, and please ignore our own easing-of-guardrails when it comes to money: https://x.com/NoahLebovic/status/2081277517709922501

nirav72about 1 hour ago
Anthropic starting to sound like Microsoft from the 1990s.
ErneX25 minutes ago
I don’t feel the need to rebate any of his points, lots of people here have done it already pretty well. I’m just baffled he thought releasing this letter was a good idea smh.
mcvabout 1 hour ago
> My primary concern is the risk that authoritarian governments—not solely the Chinese Communist Party (CCP), although the CCP is clearly the most capable threat—build AI models that are more powerful than those built by the US, and use them to achieve permanent military superiority or perpetrate incredibly deep repression of their own people

But what if it's the US that becomes authoritarian and uses AI models to perpetrate incredibly deep repression of their own people?

orliesaurusabout 2 hours ago
The Roman empire fell for the same reason, didn't it!? They wanted to control it all ... But it was too big
Catloafdevabout 1 hour ago
It's absolutely reasonable to have safeguards on sufficiently dangerous models being released - if you disagree, can you explain your perspective?

I think it's wildly irresponsible to release models that are extremely capable at things like bio-weapons. Do you really think information anarchy is the answer?

The problem with open models compared to closed models is not about protecting profit - it's about protecting capability. Any open model can be retrained or fine-tuned for anything. There's no such thing as an open model that is both capable _and_ permanently safe when it comes to certain dangerous topics. It's not possible to prevent 'uncensoring' a model.

philipkglass21 minutes ago
The biggest problem is the infectious nature of "necessary" restrictions that start narrowly. Fable is too touchy about helping people with biology and chemistry problems. It was initially released with an even more insidious safety mandate:

https://simonwillison.net/2026/Jun/10/if-claude-fable-stops-...

In light of the ability of recent models to accelerate their own development, we’ve implemented new interventions that limit Claude’s effectiveness for requests targeting frontier LLM development (for example, on building pretraining pipelines, distributed training infrastructure, or ML accelerator design).

...

Unlike our interventions for cybersecurity, biology and chemistry, and distillation attempts, these safeguards will not be visible to the user. Fable 5 will not fall back to a different model. Instead, the safeguards will limit effectiveness through methods such as prompt modification, steering vectors, or parameter-efficient fine-tuning (PEFT).

(And although the "silent" safeguard part was quickly dropped, Fable still won't help you here.)

Anthropic won't teach you how to build bioweapons, or enable you to make your own software infrastructure so that you can train your own biology model. That's the point at which lawmakers may arrive too if they buy Anthropic-style safety arguments. It's too dangerous to publish models that understand biology. It's too dangerous to publish training software. It's too dangerous to publish tools that will allow you to build training software.

If you keep following the implications of their safety argument, it's as broad an assault on the distribution of software and computing as has ever been proposed. Worse than the Clipper Chip proposal of the 1990s era Crypto Wars. I have seen how "children must be protected online" has in practice turned into an attack on adult privacy affecting a wide swath of services and computing devices. I'm taking a maximalist position on openness now because I think that I can anticipate the next steps on the safety side, and I reject those steps.

whywhywhywhyabout 2 hours ago
Generational good will loss from these guys.
AgentOrange123429 minutes ago
What nakedly self-serving bullshit.

The US doesn't have some magic wand that prevents "incredibly deep repression of their own people."

Insurrection, wars of choice, ICE, Palantir, Flock -- keep up man, we're the baddies.

ausbahabout 2 hours ago
wanting to ban your competitors via regulatory capture via the trump admin of all things shows how little of a backbone anthropic has

ofc half of them are of the ai rationalist lesswrong crowd so i think they’ve always been a little of their rocker

Advertisement
nicceabout 2 hours ago
As an act of good faith and proof, they could stop spending the record-breaking lobbying money for couple years.
extrabout 2 hours ago
Seems pretty reasonable.
horsebridgeabout 2 hours ago
> "We should crack down on industrial-scale distillation operations" I'd prefer if there was a crack down on industrial-scale scraping. Maybe even reimbursement for the problems it has caused (some nasty AWS bills, tons of man-hours spent on preventing new nasty AWS bills, etc).
MiSeRyDeeeabout 1 hour ago
Pretty laughable. Dario seems to be missing one fundamental point with all this gibberish - if CCP is so bad why would they release the model open-weights for everyone to examine? Actually, the letter would make much more sense if what's actually happening is reversed, i.e. they are releasing open-weights model for the public good and China is distilling their model for its evil purpose.
Eggpantsabout 1 hour ago
Talk about a giant whiff.

I was hoping they would announce their first open weights model, perhaps an older model they don’t offer anymore, but no. Instead he get this bs statement that reeks of “dam it I’m so close to being a billionaire” desperation. Not even acknowledgement of how much data they stole from others yet he whines about distilling.

It’s like his goal in life is to be a Scooby-Doo villain.

transcriptaseabout 2 hours ago
“By virtue of being the good people everything we do is good, and if it happens to be in our best personal and financial interest then that is good too because it enables us to do more good. And if it’s to the detriment to others then it’s because you don’t understand the good behind it. Which is fine, because we’re good and you can trust that what we do is good because what we do is good by virtue of us being the good ones.”
knupparabout 2 hours ago
Jesus Dario we get it man, you want clout for the IPO.

This constant whining from anthropic about distillation attacks continues to be rich given the amount of stolen data that went into any Claude variant.

computerdorkabout 1 hour ago
Wow, so much cynicism and distrust in the comments, to the level of conspiracy theory, in my opinion. Yeah, this is the company that fairly recently refused to allow the government to use its models for autonomous weapons or mass surveillance, and refused to remove its guardrails.

Am not saying we should take what Dario is saying at face value, but he already has shown by his actual actions that he can be well intentioned. There might be elements of truth to what he’s saying.

llelouchabout 1 hour ago
There is a massive anti anthropic psyop. Not sure who who is behind it buts it's happening.
Grimblewaldabout 2 hours ago
"needs safety eval"

also anthropic

"we're upset were not being considered for military contracts"

come on, which is it? Is it all about saftey or is it that only US/Israeli ai is allowed to kill? Seems to me that the only real threat is to the techno fudalism OAi, Anthropic & co are trying to build.

bhewesabout 1 hour ago
Woof, talk about self aggrandizing.
Advertisement
xscottabout 1 hour ago
I'm cynical enough that I would suspect all of his statements are duplicitous anyway, but my recent experiences with Claude Fable give weight to it.

I asked a question about a series of tokens - bam, denied and downgraded. There's no cyber security or public risk here, but Fable doesn't want me to learn how things work.

I asked a question about quantization in models - bam, denied and downgraded. I edit my question to make it clear I'm talking about Google's Gemma QAT models. Oh, that's fine then, and it answered the question helpfully.

Anti-competitive bullshit. I hope they fail.

jadarabout 2 hours ago
This reads almost dishonestly.

> Anthropic has never advocated for a ban on open-weights models.

This is not an unqualified never. The very next sentence makes a qualified statement: "Open-weights models that don’t have dangerous capabilities are a public good". That prompts the question, what about ones which do have "dangerous capabilities"? Are they not a public good? If not, then should they be banned? Who gets to decide on the definitions of these terms?

nout44 minutes ago
It's the same as how by "we will prevent teenagers from using social networks" they mean "we really want to connect everyones ID with their social account identity".
vcryan35 minutes ago
I guess they have to make some statement about this, but we don't have to care. This is like the zoo making a statement about the employment of clowns. Clowns a a circus thing, nobody asked the zoo's opinion.
Handy-Manabout 2 hours ago
Their position seems fair to me - sure it does help them as well, but I don't necessarily disagree with the risk they are laying out.
Johnny_Bonkabout 2 hours ago
THiS! I'm pretty amazed how many people shoot them down without acknowledging the very real and somewhat probable risks they and other researchers have laid out. I don't agree with every point they make but folks really do just seem to think we should just keep building any technology and whine when we start to consider there are very real risks associated with powerful technology. checks notes see nuclear bombing of japan
chrswabout 2 hours ago
Re: shooting them down, I think there are a lot of people out there that consider the US a bigger threat than China. Maybe they're right, I don't know. But I do know that as an American, I'm not looking forward to finding out.

And then there are probably people who are more politically neutral who think Anthropic is using China as an excuse to crush competition. Which could also be true.

But fundamentally, if this technology is so dangerous, why does anyone get to control it?

reasonablekloutabout 2 hours ago
I thought Dwarkesh's position was pretty thoughtful: https://www.dwarkesh.com/p/dow-anthropic

> Nobody is qualified to steward the development of superintelligence. It is a terrifying, unprecedented thing that our species is doing right now, and the fact that private companies aren’t the ideal institutions to take up this task does not mean the Pentagon or the White House is.

> The only way we can preserve our free society is if we make laws and norms through our political system that it is unacceptable for the government to use AI to enforce mass surveillance and censorship and control. Just as after WW2, the world set the norm that it is unacceptable to use nuclear weapons to wage war.

reasonablekloutabout 2 hours ago
It is consistent with their stated beliefs, unlike OpenAI who flip flop every 6 months on whether they support open source or not.

I think their biggest PR problem is that many people still think of loss-of-control/misalignment etc. as sci-fi. And the distillation arguments come off poorly because people feel as though all the labs have trained on their creative output without their consent, so they deserve to own the result in some way.

eddielementabout 2 hours ago
Agreed, makes logical sense. You can disagree with specific premises, but the best arguments aren't "OPEN SOURCE GOOD" or "SELFISH ANTHROPIC"!
riskdabout 2 hours ago
China bad!
deadbabe40 minutes ago
I’m tired of Anthropic. They’re scared of everything.

Release open weight models, no guard rails, no censors, straight to the public. Let everything else sort itself out. There is nothing more powerful than an idea whose time has come.

exabrialabout 1 hour ago
I disagree with 100% of everything said in this article.

> My primary concern is the risk that authoritarian governments—not solely the Chinese Communist Party (CCP)....

This is why open weights win. See Linux and how it's taken over the world. Your business model will need to change eventually. Instead you're advocating trying to exterminate competition via regulation and fear mongering.

> My secondary concern is the risk that powerful AI models may be misused to carry out cyberattacks or biological attacks

Yawn... this is getting old.

> We should not sell powerful chips or chipmaking equipment to China

For as someone as smart as you guys, you sure lack common sense. China is just going to develop these technologies organically then and you lose 100% of control. It's already happened in reverse with things like Solar, rare earth minerals, etc. China flooded our market, destroyed our ability to produce things, now holds the keys. One thing they DIDNT do was stop trading to the US. They killed us with cheap goods.

> We should crack down on industrial-scale distillation operations.

Thats your problem, not my problem. Also, irony meter here hitting 11 about all those pirated books you stole...

> All sufficiently capable models, open and closed, should go through mandatory safety testing

Oh, fuck, no. This is a crackdown on free speech and rights of people to do whatever they want. My right to free speech means I'm allowed to write whatever computer program I want, no matter what its size is or how "sufficiently advanced" it is. Individual rights always win.

I really hope people don't believe this garbage. For a company with a great product, this is absolute nonsense.

gck1about 2 hours ago
> We should not sell powerful chips or chipmaking equipment to China

Yes, please. We don't know whether we'd have open weight models today, had the chip-prohibition not been in place. Nor would we see the more optimized models such as DeepSeek or qwen.

We also would not see new players entering RAM market after you and your pals in Silicon Valley hoarded the entire world's hardware.

So by all means, double, no, triple down on this.

> We should crack down on industrial-scale distillation operations

And let's apply this retroactively to Anthropic too. You industrial-scale-operation-distilled all of humanity's knowledge. Let's have some of that crack down on you too.

addandsubtractabout 2 hours ago
How about we don't let the leading model makers make the rules? How about we make AI models that were trained on public data public goods? Let's circle back on that, kthxbye.
c-hendricksabout 2 hours ago
Frankly, why would I put much weight into what Anthropic say about open weight models?
Keyframeabout 1 hour ago
Anthropic (and some others) should or will soon learn how to do less pontificating and more engineering. They are in no position to be an arbiter of things, although for sure they can and should voice an opinion. If we collectively decide AI is a dangerous tool, company making it is not the arbiter. Governments are.

It's like hearing Smith & Wesson opine on the policies.. oh, wait.

Advertisement
VariousProgramsabout 2 hours ago
Their number one concern is about the the commies perpetrating deep repression of their own people! How noble! This whole time I thought it was because they wanted more money and power. I guess we should probably ban these open weight models.
matt_daemonabout 2 hours ago
“We care about safety so powerful open models are bad” - and what of OpenAI? What if Mythos got into the wrong hands? It’s a pretty weak argument
gck1about 2 hours ago
It's refreshing to see how there's almost no person in this thread who can't see the BS. All the goodwill that Anthropic could have had is basically gone. Anthropic is likely on the path of becoming the most hated company in the world.

So my question is: is this by design (they know nobody's buying this), or is Dario simply so out of touch with reality?

If it's the former, then why publish this?

euazOnabout 2 hours ago
This is more terrible PR for Anthropic.
kylloabout 1 hour ago
Reads like fearmongering about oppressive and violent applications of AI that the Chinese government hypothetically could deploy, which the US government is already actively working on in the meantime.
pyluaabout 1 hour ago
At the end of the day it hurts U.S. consumers to not have Chinese cars mainstream in the market. We lose out on features and stagnate on innovation because we are not pushed to compete.

I can’t imagine this would be any different — banning open weight models would hurt us in the long run. The point is to beat the competition, not suppress it.

This article feels like fear mongering and hides protectionslism as the main objective. There should be no limits on open or custom models.

I am curious… why can’t distillation be stopped?

As a side not Im not against protectionism, but it has to be across the board and the same in all industries with no excrptions. We’ve let all these industries die on the vine due to cheap cost in foreign countries. It could very well happen to ai.

teaearlgraycoldabout 1 hour ago
As an American I’d gladly take payments from China to feed them my Claude transcripts for distillation. I’m surprised I haven’t heard of such an initiative.
transcriptaseabout 1 hour ago
how’s your mandarin?
willmaddenabout 1 hour ago
"All sufficiently capable models, open and closed, should go through mandatory safety testing."

I love how they invoke fear of "terrorism" to justify their oppressive position.

Anthropic would love the US to do everything in this list under the guise of "safety testing":

https://news.ycombinator.com/item?id=48997548#49007134

j_rosenbergabout 2 hours ago
"China has limited domestic production capacity, and therefore, due to the scaling laws, cannot build more powerful models than the US without US chips"

source: Trust me bro.

There are hundreds of articles showing that China have developed their own chips and have a massive manufacturing capacity. This blog post feels like is pondering to the brain dead Fox News audience.

whalesaladabout 2 hours ago
It's so ironic to me the way people will say "china should not have these chips" meanwhile they manufacture like 99% of all the electronics we have in the united states.
Advertisement
skywhopperabout 2 hours ago
Ironic to oppose giving AI tech to “authoritarian governments” while approvingly quoting the authoritarian-wannabe government of the US and framing that government as the good guys.
Madmallardabout 2 hours ago
Boris here. This post does not give us good publicity so I will refrain from commenting. Please wait for another demo thread of a new feature of ours or AI appraisal blog post and I will gladly go into as much detail as I can to give us as much hype as possible!
dofmabout 1 hour ago
I always find it interesting when people choose to so carefully stress and spell out the words "Chinese Communist Party".

It's a bit like spelling out "Barack Hussein Obama". It's a dogwhistle.

Yes yes, it's still called the Chinese Communist Party, I know.

But since we are talking about a one-party authoritarian state with a hybrid economy that underwrites much of western prosperity (including by producing a large percentage of the components of the data centres Anthropic is dependent on), that has long-since abandoned many of the salient principles that mark it out as conceptually communist rather than totalitarian, and since we're talking about a man who runs a debt-ridden business in a country where the president is seemingly shaking down a 10% share of everything profitable for the state while running an entirely arbitrary tariff regime and suddenly calling anyone remotely left-winga Communist, it's a deliberate and telling choice to spell out "Chinese Communist Party (CCP)" when he could just as easily and arguably more usefully and appropriately have written "Chinese government" or "Chinese state".

This is some ham-fisted Republican-fishing. He must really be worried Sam is Donald's favourite.

The only real surprise is he didn't illustrate it with a Silmarillion analogy.

overgardabout 2 hours ago
I think I lost some brain cells reading that copium. LLMs providing a “Permanent military advantage”.. dumb!!
RobLachabout 2 hours ago
Yikes
Der_Einzigeabout 2 hours ago
First thing I'm going to do with my uncensored Kimi K3 release is to engineer a virus that only targets gatekeepers in the AI field.

(obviously this is a joke)

devnonymousabout 2 hours ago
> For example, I worry that biology will have a strong attacker-defender asymmetry, where sufficiently capable models may be able to quickly weaponize pandemic-level viruses with widely available materials,

If he had just left that bit out it wouldn't be so obvious that he's just clutching at straws at this point. In some twisted sense it's almost sad to see.

tjwebbnorfolkabout 2 hours ago
> where sufficiently capable models may be able to quickly weaponize pandemic-level viruses with widely available materials

if someone figures out a way to give an LLM full operational control over a virus lab, we've got a whole different set of problems than the ones Dario is describing

Ekarosabout 2 hours ago
If someone gives LLM control of such lab my best guess is soon they have no lab... Actually giving LLMs control of virus lab might be best thing one can do for continued existence of humanity.
bakugoabout 2 hours ago
> Open-weights models that don’t have dangerous capabilities are a public good

This statement (and the entire post) couldn't possibly be more two-faced.

Open-weights models by definition have "dangerous capabilities" (according to Anthropic's own definitions of "dangerous", not mine), you can't bake in guardrails that can't be finetuned out.

paxysabout 2 hours ago
I will be so happy if/when the AI bubble bursts and we don’t have to deal with Dario’s god complex anymore.
Advertisement
dirtyfrenchmanabout 2 hours ago
The mental gymnastics here are incredible.
sbochinsabout 1 hour ago
Amazing how this company went from having such goodwill to hardly any. At the end of the day they want to make as much money as possible. Anthropic will have to lose a ton of their profitability if they compete with open source. I see them moving into the application layer, which they’ve already started doing. It’s clear open models are the future for the vast majority of use cases that don’t need frontier capabilities.
richwaterabout 2 hours ago
This is a whole lot of words to say "we don't support open weight models".

It's so obvious they are hoping to regulate out their competition rather than compete

ls_statsabout 2 hours ago
>My primary concern is the risk that authoritarian governments—not solely the Chinese Communist Party (CCP), although the CCP is clearly the most capable threat—build AI models that are more powerful than those built by the US, and use them to achieve permanent military superiority or perpetrate incredibly deep repression of their own people.

This reads like a satire. I know Dario isn't that dumb.

epolanskiabout 1 hour ago
As an European I really dislike this consistent anti-Chinese narrative.

It's not China starting a war every few years, now causing a global economic fallout in Iran, it's not China threatening to annex Greenland/Canada/Panama, it's not China attacking foreign countries and kidnapping their leaders, it's not China who has been found to spy and intercept the communications and movements of its citizens and its allies and their leaders for the longest time, it's not China bombing civilians or stopping countries from obtaining basics like food, gas or oil.

I'm not saying that China is a paradise and US is bad, nor the contrary. We could make similar lists about most of the biggest countries out there.

I'm simply stating that this never ending US exceptionalism "US has to be the first and at the frontier of military, technology and this and that, but does not need to comply with the rules of the institutions it itself created" was already sickening and annoying before, but increasingly malign in the last decade and strongly accelerating as of recently.

I miss the time US CEOs were globalists and used their influence to advocate for a simpler world.

jrflowersabout 1 hour ago
> Anthropic has never advocated for a ban on open-weights models.

> All sufficiently capable models, open and closed, should go through mandatory safety testing.

lmao the sort of lies people come up with when their only business model is “the government picks me as the winner” are so funny

kingwill101about 2 hours ago
China this and China that. Playing right from the playbook..
quickthrowmanabout 2 hours ago
If you read between the lines, this piece is just “Oh my god we (OpenAI and Anthropic) accepted too much investment and are totally fucked if these open weight models are competitive, please rescue our equity bags by banning open weight models and ensuring we can charge the maximum possible price for tokens.”
llm_nerdabout 2 hours ago
I was pleasantly surprised by this release and the tone at the very beginning, but quickly it is painfully obvious that it's blatantly requesting a ban on open-weight models. The absurd demand for some safety arbiter by World Police America is farcical.

Yeah, the rest of the world is going to bow out of your busted idiocracy, guy.

Further, Anthropic needs to can it with the horseshit distillation bullshit. No, you aren't really the secret sauce, and this is basically trying to con stakeholders by pretending that there really is a moat, only you just need to add more crocodiles.

A significant percentage of innovations in AI lately has come from China. China is now making their own seriously competitive hardware, and they can steal content just as effectively as Anthropic to train their models. Why wouldn't they be competitive?

The pathetic claim that if you just stop distillation and prevent hardware smuggling and Anthropic and OpenAI will have the same moat is delusional. I mean, more correctly it's simply fraudulent, and he clearly knows it's bullshit meant to convince much stupider people.

"My primary concern is the risk that authoritarian governments—not solely the Chinese Communist Party (CCP), although the CCP is clearly the most capable threat—build AI models that are more powerful than those built by the US, and use them to achieve permanent military superiority or perpetrate incredibly deep repression of their own people."

This sort of stuff betrays a stunning lack of self awareness. The US are the worldwide risk. The US are the ones threatening allies and bombing 10+ countries. The US are the ones carrying out war criming and pillaging, pirating and burning? The US are the ones with the guy threatening to use nuclear weapons on a weekly basis.

If Anthropic remotely believed their bullshit, they would shut down today and burn the hard drives. But they don't, and the pathetic call out to Vance (please daddy, ban those dangerous models!) is deplorable garbage.

This ridiculous, shameless "note" has an audience of one: JD Vance.

scilroabout 2 hours ago
It's very hard to take his position seriously when he repeatedly refers to the Chinese Communist Party and specific Chinese ministries specifically, like some two bit China-watching cold warrior, instead of addressing China as a sovereign state actor. Imagine if any Chinese AI founder talked about the Democrats, the Republicans, about Trump or ICE etc. It's gauche.
tensorabout 2 hours ago
As someone who isn't American, I'm amused when someone from the US talks about the terrors of China or some other nation having more power than them as being bad for the world. The way the US is currently threatening to invade and damage all its allies, well, the world is already bad.

China hasn't threatened to annex my country yet, at least.

Advertisement
CrimsonRainabout 2 hours ago
TL;DR:

It is ok that we digest all information we can get, (il)legally and/or (a)morally because we are the good guys. Trust me bro.

It is not ok if others digest from us. They are bad guys. Ban them pl0x.

shaongitbdabout 2 hours ago
hahha
slimabout 2 hours ago
despite all evidence, this white guy thinks he is more responsible than both chinese entrepreneurs and chinese authorities
brcmthrowawayabout 2 hours ago
The ban on distillation seems hypocritical.

"F#$% you, I got mine!"

tag2103about 2 hours ago
Knew Anthropic were the bad guys.
pascal-makerabout 2 hours ago
"'To summarize my and Anthropic’s position, we have not and are not advocating for a ban on open-weights models as a category. We should instead focus on keeping powerful chips out of authoritarian hands, stopping industrial-scale distillation, and requiring safety testing of all sufficiently capable models, open and closed." This is all I needed to know: Dario Amodei is a f*king lizard who wants to create the next AI oligarchy. Instead of just signing the letter, he's bitching and denying that he opposes open-source models. I wonder if any Anthropic employees actually disagree with him.
proxysnaabout 2 hours ago
> My primary concern is the risk that authoritarian governments—not solely the Chinese Communist Party (CCP), although the CCP is clearly the most capable threat—build AI models that are more powerful than those built by the US,

Begging, ugly crying, spitting for that sweet-sweet regulatory capture. These nerds need to be bullied harder.

try-workingabout 2 hours ago
Anthropic must be forced to open source all of the books they have scanned and burned.
sanxiynabout 1 hour ago
For what? Would authors and publishers like that?
prima-facieabout 1 hour ago
I think this letters tells us everything we need to know about the man. I've rarely seen so much flattery towards the current administration, contradiction, deflection, half-truths and hypocrisy on a single page. This man is scared of everyone: the current admin, the public, and the other companies promoting open-weights.

> Open-weights models that don’t have dangerous capabilities are a public good

Knives should only cut during the day, knives which cut at night are bad.