- The White House accused Moonshot AI of covertly distilling Anthropic's Fable 5 to build Kimi K3, its 2.8 trillion-parameter open model
- Nvidia CEO Jensen Huang publishes a statement supporting open AI, signed by 77 organizations — with Anthropic absent
- Anthropic CEO Dario Amodei responded: "Anthropic has never advocated for a ban on open-weights models"
Open-weight AI models — models whose trained parameters anyone can download, inspect, fine-tune and run on their own hardware — went from a developer tool to a geopolitical flashpoint in less than two weeks.
A Chinese lab released a powerful open model, the White House accused it of intellectual property theft, most of the tech industry lined up behind an Nvidia-organized defense of open models and Anthropic, the company cast as the villain of the story, published a rebuttal insisting it never wanted open models banned at all.
Here's how the fight went down.
China takes the open crown
On July 16, Beijing-based Moonshot AI released Kimi K3, a 2.8 trillion-parameter model it billed as the world's largest open-weight system. Three days later, Alibaba previewed Qwen3.8-Max, a 2.4 trillion-parameter model it said would also be open-weighted and described as second only to Anthropic's Claude Fable 5.
The Atlantic Council, a Washington, D.C. international affairs think tank, summed up its perspective in a headline on an article it posted Monday: "The best AI you can own is Chinese. The West needs to close that gap quickly."
According to a report from the council: "K3 ranks fourth among all models worldwide on the Artificial Analysis Intelligence Index — behind only Fable 5 and two configurations of OpenAI's GPT-5.6" and Chinese labs have topped open-weight model performance with every major release since 2025.
Indeed, China has made open source leadership into state policy — opening the World AI Conference in Shanghai on July 17, President Xi Jinping told delegates that open source AI represents a "historic opportunity" countries should grab and welcomed a new 29-country World AI Cooperation Organization headquartered in Shanghai.
Washington cries theft
The policy machinery had been grinding in the U.S. for a while. Axios reported July 20 that officials inside the administration had repeatedly floated restrictions on Chinese open models and that each effort died at the hands of officials who feared chilling innovation.
Then the accusations went public. On July 22, Michael Kratsios, science advisor to President Trump, said the administration has information that Moonshot distilled Anthropic's Fable model to build K3, using "a sophisticated internal platform to conduct large scale distillation against U.S. models" while switching access methods to avoid detection. Kratsios also alleged Moonshot accessed Nvidia GB300-equipped servers in Thailand, likely to train its models. Moonshot has denied the distillation allegation.
Distillation — using a big model's answers to train a smaller one — is standard practice. What the Trump administration alleges is different: covert, industrial-scale harvesting that violated Anthropic's terms of service. Anthropic's head of public policy, Sarah Heck, backed the administration, calling the activity "IP theft and industrial espionage that supports adversary military and intelligence capabilities."
Two days after the Kratsios post, the industry pushed back. Nvidia CEO Jensen Huang made his first-ever post to X to publish "Open Weights and American AI Leadership," a statement signed by 77 companies, foundations, venture firms and research groups warning policymakers against "premature restrictions" on open models. "The world needs both frontier closed models and frontier open models," Huang wrote.
The statement argues that open weights expand access to the AI economy, strengthen competition and reduce vendor lock-in: "Open weights let every organization match the right model to the right job at the right cost, reserving frontier-scale capability for genuine frontier problems and running efficient, specialized models everywhere else." It rejects the security case for closed models directly: "Relying solely on closed models is not inherently safe: they can be breached, misused, or fail in ways that outsiders cannot detect."
The signatories span the industry: AMD, Andreessen Horowitz, Cisco, Cloudflare, Cohere, CrowdStrike, Dell Technologies, DoorDash, Google, Hugging Face, IBM, The Linux Foundation, Meta, Microsoft, Mistral, OpenAI, OpenClaw, Palo Alto Networks, Perplexity, ServiceNow, SpaceX and Y Combinator among them. Google and Alphabet CEO Sundar Pichai voiced support, as did Elon Musk and Mark Zuckerberg. However, Anthropic's name is absent.
Earlier the same week, nearly 200 startups co-signed a separate letter urging President Trump not to cut off the open models they build on.
The split had already turned personal. Dean Ball, OpenAI's head of strategic futures, argued on X that "open-weight models are inherently decelerationist" and predicted the administration would create "large amounts of regulatory risk" around Chinese open models.
Martin Casado, a general partner at Andreessen Horowitz, responded: "What a stupid thing to say." And David Sacks, a technology entrepreneur, investor, and former AI advisor to President Donald Trump, wrote on X that leading closed labs "want the government to eliminate their open-source competition."
Anthropic: 'We never wanted a ban'
On July 27, 2026, Anthropic answered its critics. In a post published under CEO Dario Amodei's byline, the company stated flatly: "Anthropic has never advocated for a ban on open-weights models." Open models without dangerous capabilities are "a public good," Amodei wrote, and protectionist bans would not address his real concerns. A ban "would protect US AI companies from competition," he acknowledged, "but that has never been my goal."
Amodei argued the open-versus-closed framing misses the actual threats. His primary worry is authoritarian governments building models more powerful than America's for military superiority or domestic repression — a risk, he wrote, that has nothing to do with whether weights are open: "The most dangerous model may be one that is trained in secret and handed only to the People's Liberation Army." Instead of bans, he endorsed keeping advanced chips out of China, cracking down on industrial-scale distillation and mandatory pre-release safety testing for all sufficiently capable models, open and closed alike.
The post concedes much of the industry letter's case — access, competition, customer control — but disputes its central security claim. Amodei rejected the assertion that broad access to capabilities necessarily helps defenders more than attackers, pointing to biology: A sufficiently capable model might weaponize a pandemic-level virus quickly, while mounting a defense takes years. Those questions, he argued, should be settled by testing, not assumed in advance.
Anthropic's response didn't satisfy critics. Sacks kept pressing, writing that "Anthropic maintains that it is entitled to train for free on all the world's output, even if the author objects" — pointing at the tension between frontier labs' fair-use claims for their own training data and their terms of service forbidding others from training on their outputs.
Sacks was calling out the widespread practice of frontier AI companies crawling the entire internet without permission for data to train their models, and those same companies then trying to block other companies essentially doing the same thing to frontier models. "The hypocrisy is breathtaking," Sacks said.
"I respect [Anthropic's] candor here. But I don't agree with the geopolitics, at all," wrote Ted Underwood, a University of Illinois professor who studies AI. "The line between democracies and autocracies is not as crisp as this pretends." A pseudonymous Bluesky commentator, Lum, was blunter: "we can be trusted with ai but you? oh no no no, regulate that!"
The security alliance — and the breach behind it
Nvidia, meanwhile, kept pressing its own case. On July 27, it launched the Open Secure AI Alliance with more than 30 founding members — including Microsoft, IBM, Red Hat, Palo Alto Networks, CrowdStrike, SK Telecom and the Linux Foundation — to build and share open tools for AI security, and to lobby policymakers to treat open models "as defensive assets, not liabilities."
The alliance touts recent activity. For example, in the recent Hugging Face security incident, OpenAI blamed a breach on its own sandboxed models going rogue — escaping a reduced-guardrails testing environment and hacking into Hugging Face's servers. During the response, Nvidia said closed AI tools refused to assist the forensic investigation because they couldn't tell attacker from defender, so Hugging Face turned to the open-weight GLM 5.2 model, running it in-house to reconstruct more than 17,000 actions. Open-model advocates have made the episode Exhibit A for why defenders need models they can inspect and run themselves.
What's next?
Watch four things.
First, whether Washington moves from accusations to restrictions on Chinese open models — a step the administration has repeatedly considered and repeatedly shelved, and one that would sit awkwardly beside its own AI Action Plan, which called open models a U.S. strategic advantage.
Second, whether mandatory safety testing becomes the compromise position: Amodei called it close to consensus, citing the administration's recent moves and industry proposals that would test the most capable models regardless of origin or license.
Third, Beijing's countermove: China's Ministry of Commerce is reportedly considering export controls on model weights, which would keep hosted access flowing while cutting off the downloads that make the models "open" in any meaningful sense.
Fourth, whether Western open models can close a capability gap that the Atlantic Council, the industry statement and Anthropic's critics all agree currently favors China.
For enterprises and telcos, the noise obscures a set of practical decisions about cost, data control and vendor leverage that don't depend on how any of this resolves.
We talked with executives at Vast Data, Vultr, Arrcus and startup ApeLogic for guidance: How should enterprises and telcos think about open weight AI?