Direct Answer
The open-weights letter is a real industry coalition, but "everyone signed except Anthropic" is a useful headline rather than a literal fact. NVIDIA CEO Jensen Huang used his first X post to share the 24 July 2026 statement. Its initial roster contained 25 organizations; the current PDF has expanded to more than 100, including OpenAI, Google, Amazon, Meta, Microsoft, GitHub, Hugging Face, Cloudflare, Databricks, and many model, cloud, hardware, and developer-tool companies.
Anthropic did not sign. That does not mean it supports a blanket ban. Dario Amodei's published response agrees that open weights can improve access, competition, customer control, and economic participation. He rejects the letter's stronger safety claim: that broad access necessarily helps defenders more than attackers or makes safeguards easier to build.
Watch Theo's Analysis
Video, transcript, and commentary credit: Theo - t3.gg. Follow Theo on X. Theo's video is intentionally opinionated; this article checks the policy claims against the signed letter, its dated roster, and Dario Amodei's direct response.
What Actually Happened
| Date | Event | Why it matters |
|---|---|---|
| 24 Jul 2026 | NVIDIA publishes Open Weights and American AI Leadership with 25 initial signers. | The letter asks U.S. policymakers to avoid premature restrictions on downloadable models. |
| 24 Jul 2026 | Jensen Huang shares the letter in his first post on X. | The message gives an industry policy document much wider public visibility. |
| Following days | OpenAI, Google, Amazon, and many others join the expanding roster. | Support becomes broader than the original hardware, open-model, and infrastructure coalition. |
| 27 Jul 2026 | Dario Amodei publishes Anthropic's position. | He rejects blanket bans while defending controls on chips, distillation, and dangerous capabilities. |
| 28 Jul 2026 | The official PDF is updated again. | The signatory list is a moving record, so articles quoting the original 25 can now look outdated. |
There are two corrections worth preserving. First, the letter does not name China, Kimi K3, DeepSeek, or Anthropic. It is written as a general argument for American open-model leadership. Second, signing the letter does not mean a company promises to release all of its own frontier weights. Several signers still depend heavily on closed products.
That is why the document is best read as a policy coalition, not an open-source purity test.
Open Weights Is Not the Same as Open Source
The letter defines open-weight models as systems whose trained parameters can be downloaded, inspected, modified, and run on an organization's own infrastructure. That offers real portability, but it does not answer every openness question.
| Layer | May be available | What to verify |
|---|---|---|
| Model weights | Usually yes | Exact files, checksums, quantizations, and architecture compatibility. |
| Inference code | Often | License, dependencies, supported hardware, and production maturity. |
| Training code | Sometimes | Whether the release is sufficient to reproduce the training process. |
| Training data | Rarely complete | Provenance, consent, copyright, privacy, and geographic restrictions. |
| Model license | Always decisive | Commercial use, redistribution, fine-tuning, attribution, and use restrictions. |
| Safety system | Variable | What is inside the weights, what depends on the hosted product, and what disappears locally. |
A downloadable model can be open weight without being reproducible open source. Conversely, an open software stack can call a closed model API. Builders should name the layer they mean instead of using "open" as a single all-purpose label.
The Coalition's Case for Open Weights
1. Access and sustainable cost
The letter argues that startups, universities, public institutions, and established businesses should not need to train a frontier model or pay frontier API prices for every task. A portfolio of downloadable models can reserve the most expensive capability for the hardest work and run smaller specialized systems elsewhere.
2. Competition across the stack
Open weights let more companies compete in model hosting, chips, cloud services, fine-tuning, evaluation, applications, and support. That can reduce provider lock-in and keep the application layer from collapsing around a few API vendors.
3. Customer control and sovereignty
Organizations may need to keep data on premises, serve a model in a particular country, preserve a capability after a provider changes terms, or adapt a system to a specialized domain. Open weights make those choices technically possible, even when they remain operationally difficult.
4. Research and defensive security
The letter says wider access enables benchmarking, red teaming, vulnerability discovery, and safeguard research. It also argues that defenders need capabilities comparable to attackers rather than permanent dependence on a small set of closed providers.
5. Targeted rules for distillation
The signers describe model distillation as a widely used development technique. They distinguish legitimate learning and evaluation from unlawful extraction, and ask policymakers to address the latter through targeted legal and commercial frameworks instead of sweeping restrictions on the technique itself.
Follow the Incentives Without Dismissing the Argument
Theo is right to ask who benefits. The answer is nearly every layer outside a small number of closed frontier APIs.
| Participant | What open weights can create | Commercial incentive |
|---|---|---|
| Chip companies | More training, fine-tuning, and inference | Higher accelerator and systems demand |
| Cloud and hosting providers | More deployable model workloads | Compute, storage, networking, and managed-service revenue |
| Open-model labs | Distribution and ecosystem adoption | Hosted APIs, enterprise support, reputation, and research leverage |
| Developer platforms | More model choice inside tools | Lower dependence on one vendor and stronger product differentiation |
| Enterprises | Private deployment and negotiation leverage | Data control, customization, and lower switching costs |
| Closed frontier labs | A larger overall AI market | More demand, but also more price and product competition |
NVIDIA's incentive is particularly obvious: more models running in more places can sell more accelerated computing. Anthropic also has an incentive: scarce, controlled frontier access supports its product and safety model. Incentives explain emphasis; they do not prove either side's technical claims.
What Anthropic Actually Said
Dario Amodei's response is not a defense of a general open-weight ban. It makes five narrower claims:
- Low-risk open weights are a public good. They reduce access cost and help businesses, developers, and researchers.
- A ban on U.S. business use misses the main national-security problem. A secret model controlled by an authoritarian state could be more dangerous than a public one used by American companies.
- Irreversible release changes misuse risk. Once capable weights spread, the original lab cannot revoke them, monitor use, or reliably restore removed safeguards.
- Chip controls and anti-smuggling enforcement matter more. Anthropic wants to constrain the compute required to train stronger rival systems.
- Capability-based testing should apply to open and closed models. The threshold should exempt less capable academic and startup systems while testing models with meaningful cyber, biological, or alignment risk.
Anthropic also supports intervention against industrial-scale distillation that uses fraudulent accounts or evasive access. That is the policy issue closest to recent allegations involving Chinese model labs. It is separate from whether the resulting weights are public.
Where the Two Sides Agree and Disagree
| Question | Open-weights letter | Anthropic response |
|---|---|---|
| Do open weights improve access? | Yes | Yes |
| Can they strengthen competition and customer control? | Yes | Yes, for at least some use cases |
| Should the U.S. ban open weights as a category? | No | No |
| Should illegal extraction be treated separately from normal distillation? | Yes | Yes, with stronger policy action against industrial-scale abuse |
| Does openness necessarily improve safeguards? | The letter strongly suggests it can | No; the direction must be tested empirically |
| Does wider capability access favor defenders? | Often | Not necessarily, especially in biology |
| Should capable models face pre-release tests? | Supports evaluation assets and demonstrated-harm evidence | Yes, mandatory tests for sufficiently capable open and closed models |
| Are advanced chip controls important? | Not the letter's focus | Yes, central to the strategy |
Once the rhetoric is removed, the live dispute is mostly about default assumptions. The coalition starts from permission to release unless harm is demonstrated. Anthropic starts from measuring dangerous capability before a release that cannot be reversed.
The Real Risk Split: Visibility Versus Control
Open and closed models create different safety advantages.
| Open-weight advantage | Open-weight cost |
|---|---|
| Independent inspection and reproducible research | No universal access revocation after release |
| Private and sovereign deployment | Private misuse is also harder to observe |
| Community red teaming and adaptation | Safeguards can be modified or removed |
| Provider diversity and resilience | More copies create a larger patching and provenance problem |
| Local control over data and uptime | The deployer inherits security, monitoring, and incident response |
Closed systems reverse that trade. Providers can monitor abuse, update filters, block accounts, and retire a version, but outsiders have less visibility into the model and must trust a concentrated control plane.
Cybersecurity may sometimes favor wide defensive access. Biology may have a different attacker-defender balance. A single slogan cannot resolve both domains. Capability evaluations, realistic threat models, access design, and deployment controls are more useful than assuming openness or closure is inherently safe.
A Better Policy Test Than Open Versus Closed
A practical framework can ask five questions before adding restrictions:
- What capability has been demonstrated? Measure cyber exploitation, biological assistance, autonomous replication, deception, and other concrete risks.
- What changes after release? Estimate how much the weights reduce cost, expertise, time, or access barriers for a harmful task.
- Can the restriction work? A rule aimed only at legitimate U.S. companies may not affect actors already willing to steal or evade access.
- What competition does the rule remove? Account for startup access, research, sovereignty, and provider concentration.
- Can targeted remedies address the conduct? Use contract enforcement, fraud law, export controls, security standards, and sanctions where evidence supports them.
This approach avoids two bad extremes: treating every downloadable model as a national-security emergency, or pretending irreversible frontier capability has the same risk profile as an ordinary software library.
Open-Weight Builder Checklist
The policy debate becomes operational the moment a team downloads or hosts a model. Before production, document:
- Purpose: the workflow, users, data, acceptance test, and reason an open model is preferable.
- Capability: relevant benchmark results plus tests on the organization's own tasks and abuse cases.
- License: commercial rights, redistribution, fine-tuning, attribution, and prohibited-use terms.
- Provenance: publisher identity, model card, checksums, training disclosures, and third-party packaging.
- Data: residency, retention, logging, secret handling, and whether a hosting provider sees prompts.
- Isolation: network access, tool permissions, sandboxing, identity, and least-privilege credentials.
- Monitoring: inputs, outputs, tool calls, policy events, quality failures, and human overrides.
- Patching: who tracks upstream fixes, refreshes quantizations, and rolls back a bad model.
- Incident response: containment steps when there is no central provider capable of revoking every copy.
- Economics: hardware, hosting, energy, engineering, latency, reviewer time, and cost per accepted task.
- Exit plan: portable prompts, evals, tool schemas, and data so the workflow can move to another model.
A Simple Deployment Scorecard
| Condition | Good fit for open weights | Pause or use managed access |
|---|---|---|
| Data control | On-premises or sovereign hosting is required | No team owns infrastructure security |
| Customization | Domain adaptation creates measurable value | A standard hosted model already passes the task |
| Risk | Bounded workflow with strong verification | High-impact autonomy without tested controls |
| Operations | Monitoring, patching, backups, and rollback are owned | The model would become an unmaintained internal dependency |
| Economics | Stable utilization justifies hosting or provider diversity | Low usage makes a managed API cheaper overall |
| Policy | License, sector rules, and geography are approved | Sanctions, procurement, or provenance remain unclear |
| Resilience | The workflow can route between models | The business becomes dependent on one untested release |
The right outcome may be hybrid: an open model for private, repeatable work; a closed frontier model for the hardest reasoning; and deterministic software for steps that should never be probabilistic.
Video Map
| Time | Topic | Evidence note |
|---|---|---|
| 00:00 | Jensen Huang's first X post and the missing Anthropic signature | The title is rhetorical; the signatory roster continued to expand after publication. |
| 02:26 | Why open weights became the policy fight | Separates downloadable models from provider-controlled APIs. |
| 06:09 | The letter's central argument | Best read directly in the dated NVIDIA PDF. |
| 09:39 | Economic access, competition, and sovereignty | These are the strongest areas of agreement between the letter and Anthropic. |
| 11:24 | Safety, security, and irreversible release | The letter acknowledges loss of control, then argues that defenders benefit from access. |
| 16:00 | Distillation and targeted remedies | Distinguishes a normal ML technique from alleged unlawful extraction. |
| 18:47 | The expanding coalition | OpenAI and Google joined after the original 25-company version. |
| 19:01 | Dario Amodei's response | Anthropic explicitly rejects a blanket open-weight ban. |
| 23:54 | Chip controls and industrial-scale distillation | These are central Anthropic policy proposals, not provisions in the letter. |
| 26:21 | Mandatory capability testing | Anthropic wants the threshold applied to sufficiently capable open and closed models. |
| 27:27 | Where the two sides disagree | The main split is the attacker-defender balance and whether openness improves safeguards. |
| 28:44 | Theo's verdict | Creator commentary should not be mistaken for a statement of Anthropic's motives. |
Bottom Line
The letter is important because the companies that build chips, clouds, models, tools, and applications are asking Washington to preserve a plural AI stack. Anthropic's absence is important because it exposes the hardest unresolved question: what should happen when a model becomes capable enough that releasing its weights permanently changes access to dangerous tasks?
The coalition is right that concentration and lock-in carry economic and security risks. Anthropic is right that transparency does not automatically favor defenders and that some releases cannot be recalled. Both positions are shaped by commercial incentives, but neither can be dismissed on that basis alone.
For builders, the practical answer is model choice with responsibility: evaluate capability, preserve portability, protect data and tools, and accept that self-hosting transfers control and operational duty to you at the same time.
Sources and Useful Links
- Theo: Everyone Signed This Letter (...minus Anthropic)
- Theo - t3.gg on YouTube and Theo on X
- Official PDF: Open Weights and American AI Leadership, including the current signatory roster
- Jensen Huang on X
- Dario Amodei: Our position on open-weights models
- Axios: Anthropic remained the frontier-lab holdout after OpenAI and Google joined
- Tom's Hardware: the original 25-company letter and policy context
- JQ AI SYSTEMS: Kimi K3, distillation, security, and policy pressure
- JQ AI SYSTEMS: China's open-weight AI strategy and real deployment costs