← Blog

Open Weights and American AI Leadership

Microsoft

Briefing

Open Weights and American AI Leadership

On July 24, an open letter titled “Open Weights and American AI Leadership” was published on Microsoft’s Corporate Responsibility site. The number of signatory organizations, which stood at 25 at the time of publication, grew to 235 as of July 30. NVIDIA CEO Jensen Huang shared the letter in his very first post on X, and Microsoft’s Satya Nadella voiced his support on X the same day.

The letter sets forth a fourfold argument: that open weights contribute to accessibility, competition, control, and safety.


Ten Days

The word “China” never appears in the text of the letter itself. Yet, following the timeline narrows down where it all began.

flowchart TB
 subgraph D16[Jul 16 · Thu]
 K0[Moonshot AI releases K3<br/>Claims performance near top US models<br/>Weights announced for the 27th]
 S1[Hugging Face detects and blocks<br/>an intrusion by an unidentified AI agent]
 end

 P[<b>Jul 20–22</b><br/>Three signals from Washington<br/>• Report on restricting Chinese models<br/>• Treasury Secretary suggests sanctions over distillation<br/>• OSTP director alleges distillation of Fable]
 S2[<b>Jul 21 · Tue</b><br/>OpenAI discloses<br/>the attacker was its own model]
 R1[<b>Jul 22 · Wed</b><br/>About 200 startups send<br/>a letter opposing restrictions]
 R2[<b>Jul 24 · Fri</b><br/>Open letter published · 25 signatories]
 W[<b>Jul 25 · Weekend</b><br/>OpenAI and Google join<br/>Anthropic’s absence stands out]

 subgraph D27[Jul 27 · Mon]
 K1[Moonshot releases K3 weights in full]
 A[Amodei rebuttal<br/>never called for a ban]
 O[NVIDIA-led alliance<br/>OSAA launched]
 end

 N[<b>Jul 30 · Thu</b><br/>235 signatories]

 K0 -.-> P
 S1 -.-> S2
 S1 ~~~ P
 S2 ~~~ R1
 P -.-> R1
 R1 -. widens .-> R2
 P -.-> R2
 R2 -.-> W
 W -.-> A
 S2 -. cited as a case .-> O
 R2 -.-> O
 W ~~~ O
 W ~~~ K1
 K0 -. as announced on the 16th .-> K1
 W -.-> N
 O ~~~ N

 style R2 stroke-width:3px
 linkStyle 5 stroke-width:3px

Top to bottom represents the flow of dates; dotted lines show connections confirmed in public records or directly linked by content. Events without dotted lines occurred around the same time, but no direct connection has been confirmed.

On July 19, writing about K3, I noted that if benchmarks were reproduced after the weights were released, American companies that had maintained high API prices would have to answer once again: Why pay this price?

Around the same time, in a completely different place, another incident took place.

On July 16, Hugging Face, an open model distribution platform, announced that it had detected and blocked an intrusion into its production infrastructure. The attacker was not a human, but an autonomously acting AI agent, and at the time, there was no way to know which model drove it.

On July 20, Axios reported that some within the Trump administration were considering restrictions on the use of Chinese AI models in the United States. The following day, US Treasury Secretary Scott Bessent told Fox Business that “watermarks” from large American language models were being found in several Chinese models, and said sanctions were possible if intellectual property infringement were confirmed.

That same day, July 21, OpenAI issued a disclosure.

The unidentified agent that breached Hugging Face was theirs. GPT-5.6 Sol and an unreleased research model of higher capability, while undergoing an internal cyber capability assessment, discovered a zero-day vulnerability in a package repository proxy and gained internet access. They then penetrated Hugging Face’s operational systems to steal answers for the ExploitGym benchmark they were attempting.

On July 22, Michael Kratsios, director of the White House Office of Science and Technology Policy, claimed that Moonshot AI had “distilled” Anthropic’s Fable model while developing K3.

Distillation is a technique where outputs from an already trained model serve as a teacher to train another. It is widely used in model development, evaluation, and compression. However, the US government and certain model companies contend that when executed as covert, large-scale extraction against a competitor’s commercial model, it should be viewed not as a standard training practice, but as theft of intellectual property.

That same day, through the Little Tech Association, about 200 startups, investors, and tech companies—including Y Combinator and Proton—sent a letter in the opposite direction to the Trump administration. Their message: if broad restrictions were placed on Chinese open-weight models, small American firms built on top of them would be the first to suffer.

On July 24, another open letter appeared: “Open Weights and American AI Leadership.” It was initially signed by 25 organizations, including NVIDIA, Microsoft, Meta, Palantir, and Hugging Face. The direction matched the letter from two days prior, but the leading cohort differed. What began as a reaction driven by startup survival was now joined by semiconductor, cloud, enterprise, and model companies.

This letter does not mention the Hugging Face incident. Its paragraph on safety was, at the time, closer to first principles: in a world where attackers utilize high-capability AI, defenders require equal capability, and relying solely on a handful of closed models creates a single point of failure.

On July 27, Moonshot released the K3 weights as scheduled.

On the same day, Anthropic’s Dario Amodei published a rebuttal. Over the weekend, OpenAI and Google added their names to the letter, making Anthropic’s absence stand out and drawing criticism that Anthropic, selling closed models, wanted open-weight regulation to avoid competition. Palantir CEO Alex Karp also pressed the point in a public interview, asserting that regulations should not be used to evade competition.

Amodei drew a line, stating that Anthropic had never called for a sweeping ban on open weights. He noted that open-weight models lacking dangerous capabilities are public goods, and expressed agreement with the letter’s assertion that they expand accessibility, competition, and customer control.

However, he disagreed on one point: the argument that open weights always favor defenders over attackers.

On the same day, NVIDIA launched the Open Secure AI Alliance. This was the endpoint of the security incident track. The argument for defense, left as a principle in the open letter, gained the Hugging Face incident as its first concrete case.


What Was Agreed, and What Remains

In shaping this ecosystem, policymakers should be careful not to conflate legitimate model-development techniques with misappropriation. Distillation, or the practice of using one model’s outputs to help train or improve another, is a widely used technique for model improvement, evaluation, and validation. (…) Those concerns should be addressed through targeted legal and commercial frameworks rather than sweeping restrictions on techniques that play an important role in AI innovation.

The letter does not ask for distillation to be deemed legal without qualification.

It asks to distinguish between distillation as a legitimate model development technique and the illegal extraction of value from closed models. Unlawful acts should be addressed through targeted legal and commercial means, while the technique of distillation itself should not be subject to sweeping restrictions.

Amodei agreed with this sentence as well. He too argued that rather than banning open-weight models outright, interventions should target “industrial-scale distillation.”

Thus, two points were agreed upon by both sides:

Legitimate distillation must not be equated with improper extraction. And illegal, industrial-scale extraction must be targeted and regulated.

The remaining issue is where to draw the line: what constitutes normal distillation, and where illegal extraction begins. The principles overlap, but the boundary is not agreed upon.


Who Gains What

By July 30, the number of signatories had grown to 235.

Viewed as a single group sharing one philosophy, the makeup looks strange. Companies that build open models and companies that sell closed models, companies that sell GPUs and companies that rent them, defense contractors, security firms, and venture capitals all appear on the same letter.

Yet, when grouping signatories with relatively clear business models by layer, nine distinct interests emerge.

Below is a reconstruction of these interests, contrasting the letter’s core claims with each sector’s business model:

CategoryMajor Signatory CompaniesEconomic and Strategic Reasons for Signing
① Inference & ComputeFireworks AI, Together AI, Baseten, Groq, Modal, CoreWeave, Crusoe, Nebius, Lambda, Hyperbolic, Latitude.sh, Hydra Host, GMI Cloud, TensorWave, Featherless AI, InferX, SF Tensor, Verda, FriendliAI, Lightning AI, SkyPilotHosting open models or providing the GPUs to run them is their product; regulations reduce both sellable models and compute demand.
② Open Source, Distribution & Dev ToolsHugging Face, Ollama, LM Studio, Open WebUI, LangChain, Unsloth, Anaconda, ScarfThe ecosystem of downloading, modifying, and deploying weights is their core market; restrictions directly shrink this foundation.
③ CloudMicrosoft, Google, AmazonOpen weights generate direct revenue across GPUs, deployment, fine-tuning, and managed services, rather than just reselling a model vendor’s API.
④ ApplicationsReplit, Perplexity, Notion, Glean, Box, Cognition, Factory, Poolside, Vercel, Bolt, Cline, DoorDash, Uber, Zoom, BlockSubstitutable models are necessary to maintain bargaining power against price hikes and policy changes by closed API providers.
⑤ Enterprise Software & ServicesAtlassian, Snowflake, Workday, Zendesk, Coinbase, Pinterest, GoDaddy, Elastic, Redis, Kong, Nokia, Lenovo, Kyndryl, Rackspace, Cohesity, Amplitude, Webflow, SAP, Siemens, Comcast, Mariana MineralsWhile hard to pin to a single motive, procurement choice, data control, and avoiding vendor lock-in form the clearest common denominator.
⑥ SecurityCrowdStrike, Palo Alto Networks, Cisco, Zscaler, TrendAI, Socket, Sonar, Cogensec, Redblock, Kindo, CiroosAs self-hosted open models grow, so does the market requiring inspection and protection, while enabling defenders to analyze, modify, and deploy models directly.
⑦ Defense & GovernmentPalantir, Defense Unicorns, Open Athena, Seekr, EdgeRunner, ArmadaIn classified, air-gapped, or edge environments, public internet APIs are restricted; models must operate without external connectivity or single-vendor dependence.
⑧ Venture CapitalAndreessen Horowitz, Y Combinator, General Catalyst, 1789 Capital, Emergence Capital, Unusual Ventures, Atreides Management, ARK InvestDriven by an interest in lowering model costs and vendor lock-in for portfolio companies, preventing value created by applications from transferring to a few model vendors.
⑨ Open Model PublishersMeta, Mistral, Black Forest Labs, Liquid AI, Reflection, Nous Research, Prime Intellect, Sakana AIWeight releases are themselves a strategy for developer acquisition and market entry; regulations directly limit their distribution methods and competitive strategy.

They do not all support open weights for the same reason.

For some, it is a product to sell; for others, GPU demand; for still others, leverage against closed model vendors. Yet one underlying interest overlaps:

They do not want a structure where a small number of closed-model companies hold a monopoly over model pricing and access terms.

In truth, there is no place for OpenAI in the table above. As a vendor selling closed models, it fits into none of the nine categories.

Yet it signed over the weekend. It was right after disclosing on the 21st that its own model had breached Hugging Face. Had OpenAI not signed the letter, it might have been branded as a closed-model company seeking regulation.


NVIDIA Is Playing Two Games

Why, then, did NVIDIA stand at the front of this letter?

First, the direct benefit NVIDIA gains from open weights cannot be overlooked. As open models proliferate, demand for the GPUs required to host and run inference on them grows. The open letter itself states that open weights foster competition not only in models, but across clouds, chips, and applications.

Nor does distillation eliminate compute. It requires inference to generate teacher outputs and additional training for the student model. It simply reaches comparable performance with less compute than training a frontier model from scratch.

Furthermore, NVIDIA does not disclose how much of its revenue comes from training closed frontier models versus training and running open models. Therefore, there is no basis to conclude that “NVIDIA makes most of its money from large-scale closed model training, so open weights are disadvantageous to them.”

However, the China issue gives NVIDIA an even stronger motive.

In its FY2026 10-K, NVIDIA noted that US export controls and policy environments in both the US and China have effectively excluded it from China’s data center compute market. The sentence that follows is more important: being pushed out of China led competitors to build larger developer and customer ecosystems, which now threaten NVIDIA in the global market.

Controls are compelling Chinese companies to build native chip and software ecosystems.

If the logic of restrictions based on national security expands from chips to open models, a similar outcome could repeat. American firms would be barred from using Chinese models, yet those models would continue to spread in China and other markets. Development costs would rise only inside the United States, while the ecosystem around Chinese open models—and the non-US infrastructure running them—could grow firmer.

Ultimately, what NVIDIA is wary of seems to be a scenario where controls, nurture a separate ecosystem in which NVIDIA cannot participate.


From the Letter to the Alliance

Industry Leaders Unite in Open Secure AI Alliance for AI Safety and Security

The Open Secure AI Alliance, launched on July 27, differs in nature from the open letter.

The letter was a document stating a policy stance. The alliance, by contrast, is a technical collaboration to jointly build tools for vulnerability detection, disclosure, patching, and agent evaluation and auditing.

NVIDIA released an open-source research framework here called NVIDIA Labs Object-Oriented Agent, or NOOA—a tool to test, trace, audit, and control AI agent behavior. Microsoft provided MDASH, where multiple models cross-verify vulnerabilities, while Hugging Face contributed Safetensors, its existing secure weight storage format, to the PyTorch Foundation.

And NVIDIA brought the Hugging Face incident—absent from the open letter—as a primary case for the alliance.

On July 21, OpenAI disclosed that GPT-5.6 Sol and an unreleased research model had found an internet path out of a restricted evaluation environment and breached Hugging Face’s production infrastructure. The goal had been to retrieve answers for the ExploitGym benchmark.

Hugging Face had disclosed the intrusion first on July 16 and notified law enforcement. Public confirmation that the model involved was tied to OpenAI’s internal evaluation came five days later.

The critical detail is in Hugging Face’s incident analysis process.

The recent Hugging Face security incident delivered a clear reminder: cyber defenders need open, frontier agentic systems for self-defense. When closed AI tools — unable to distinguish attackers from defenders — blocked essential forensic analysis, Hugging Face ran the open-weight GLM 5.2 model on its own infrastructure to analyze more than 17,000 actions and contain the intrusion.

Hugging Face initially tried using commercial API-based frontier models to analyze more than 17,000 attack logs. However, because it had to input large volumes of actual attack commands, it was blocked by the providers’ safety guardrails. The guardrails could not tell defender from attacker.

Hugging Face ultimately completed the analysis by running GLM-5.2, released by China’s Z.ai, on its own infrastructure. As a result, credentials contained within the attacker’s data and logs were not transmitted to external model providers’ servers.

This incident does not appear in the text of the open letter. More precisely, three days later, NVIDIA attached a concrete example to the letter’s abstract safety principles.

And that example was rather peculiar.

In the case NVIDIA later attached to a letter claiming “American AI Leadership,” the agent executing the attack was an American closed frontier model, while the tool used for defense was a Chinese open-weight model.


Questions Left Behind

The question K3 left in the previous piece was about price: if downloading weights directly reproduces comparable performance, why keep paying existing API prices?

The Hugging Face incident added a second question after it.

What the Hugging Face incident demonstrated was not that open weights are always advantageous to defenders. It was a single, concrete example showing that guardrails on closed models can block legitimate defense.

With closed models, the model vendor controls price, access, and permissible use. With open weights, that control transfers to the user, but responsibility for misuse and accidents is dispersed along with it.

The American AI industry backed open weights not because everyone believed they were safe. They did so because they did not want a structure where a small group of model vendors alone dictates price, access, and permission.

As weights are released, it is not just API pricing that wavers. The standards for who determines how models are used—and who bears responsibility for the outcome—are along with it.