Anthropic says it never sought a ban on open-weights models
Responding to months of speculation, Anthropic published its open-weights position: no bans, but mandatory pre-release safety testing for any sufficiently capable model.
Setting the record straight
Anthropic published a formal statement of its position on open-weights models late on July 27, opening with an explicit denial from chief executive Dario Amodei that the company has ever advocated banning them. The post follows sustained speculation — amplified by the current Washington fight over open model policy — that Anthropic's safety advocacy amounted to a push against downloadable weights.
The company's stated view is that open models without dangerous capabilities are a public good: they widen access, give users more control over their own deployments, and add competitive pressure in a market otherwise concentrated among a few API providers.
Where the concern sits
Amodei names two risks he considers serious: authoritarian states fielding more capable AI for military advantage or domestic repression, and highly capable models being turned to cyberattacks or biological harm. His argument is that a ban on open weights is a poor instrument against either.
In place of restrictions on release format, the post proposes three measures. First, continued semiconductor export controls, on the reasoning that compute access — not weight availability — determines who can train frontier systems. Second, enforcement against industrial-scale distillation operations, particularly those backed by state actors; Anthropic commits to identifying and banning accounts using its own models for such copying, while conceding that unilateral action by any single vendor cannot solve the problem. Third, mandatory pre-release safety testing for cyber, biological and alignment risks applied to any sufficiently capable model — open or closed alike.
The post contains no announcement that Anthropic will itself release open weights.
Why it matters
The third proposal is the substantive one. Applying a testing mandate on the basis of capability rather than distribution model would land hardest on open-weight releases, since testing obligations are simpler to attach to an API endpoint than to a checkpoint already mirrored across the internet. Anthropic is effectively arguing for a capability threshold instead of a release-format rule — a position that lets it sidestep the ban framing while still supporting regulation that many open-source developers regard as functionally restrictive. It arrives the same day most of the enterprise security industry organized a consortium around open models without Anthropic in it.