The warning that came first

On July 12 Nathan Lambert wrote that open models had about six months before policy made them permanently second tier. His argument was that two conversations in Washington were converging, one about distillation, framed as Chinese labs training on American model outputs, and one about restricting frontier capabilities, and that the natural compromise between them was a rule that only closed models could sit at the frontier. He put the threshold at the level of GPT 5.5, Claude Opus 4.8 or GLM-5.2.

Lambert was blunt about who he thought benefited. He called the distillation debate closer to regulatory capture than a safety response, argued that there are no good solutions to distillation with the information we have other than letting labs self-enforce, and said the idea that only open weights are insecure while APIs are safe has been very overblown. His prescription was for American companies to release competitive open models and change the subject. Two weeks later the letters started.

July 24: open weights and American leadership

The first letter, shepherded by Microsoft and signed by 235 organisations including NVIDIA, Amazon, Y Combinator and the Linux Foundation, with OpenAI joining later, argued the safety case for openness. Open weight models allow a broad community of researchers and developers to examine their behaviour, identify vulnerabilities, develop safeguards and improve them over time. The letter defended distillation as a legitimate development practice in the tradition of open source software, which is the point most directly aimed at the policy Lambert had predicted.

Reading the signatory list, the notable thing is who is on it rather than what it says. Microsoft has no frontier open model of its own. NVIDIA sells to everyone. The letter is a coalition of companies whose business depends on there being many models rather than three, and its argument about scrutiny is one that this foundation has made for years and that we still think is right for models below the frontier.

July 27: Anthropic answers

Three days later Dario Amodei published Anthropic's position. Its opening line is that Anthropic has never advocated for a ban on open-weights models, and it describes open models without dangerous capabilities as beneficial public goods. Then it ranks two threats. The primary one is an authoritarian government, and the post names the Chinese Communist Party, building models more capable than American ones. The secondary one is models enabling cyberattacks and biological attacks or suffering serious alignment failures, where open weights are riskier because guardrails are hard to apply and weights cannot be recalled.

The three proposals follow from the ranking. Tighten chip export controls, since the post argues China has limited domestic production capacity. Crack down on industrial-scale distillation, which the post concedes can bring the Chinese frontier to within a few months of the American one. And require safety testing for cyber, biological and alignment risk on every sufficiently capable model before release, open or closed, from any country. On the Microsoft letter specifically, Amodei agrees that open weights expand access and competition, and disputes that they strengthen defence, pointing to asymmetries between biological attack and defence.

Set the two documents side by side and the disagreement is narrower than the coverage suggested. Both say open models below some capability line are good. Both accept some form of testing. The dispute is about distillation and about where the line sits, and that is exactly the compromise Lambert described. A distillation crackdown plus a testing gate is a rule that closed labs can meet and open releases mostly cannot, whatever the intent.

July 28: pacing the frontier

The third letter is different in kind. Signed by 1,324 employees of frontier companies, including Jakub Pachocki at OpenAI, Ilya Sutskever, and Amodei and Jack Clark from Anthropic, it asks governments to support an international effort to develop technical and governance tools for deliberately pacing automated AI development. The concern is competitive pressure accelerating progress through automated research, and the request is for tools, not a pause.

We read it as the honest version of the first two. The Microsoft letter and the Anthropic post are each arguing for a regime that suits the signatory's position. The employee letter says that the people doing the work would like someone to build a brake, and does not say who should hold it. That is a smaller claim and, for us, a more credible one. It also does not mention open weights at all, which matters, because pacing automated research is a question about the top three labs and not about whether a 30 billion parameter model ships with a license.

Where this leaves open research

For a foundation that publishes replications, the open question is which of the proposals would change what we can study. Chip controls do not. A pacing agreement does not. A pre-release testing requirement would, if it applies to any model above a threshold regardless of who releases it, because a university group cannot run a cyber and bio evaluation suite before posting weights, and the requirement would push open releases below the line. A distillation rule would, because most academic fine-tuning is distillation by any workable definition.

Lambert's six months run out in January. Our expectation is that neither letter gets enacted as written and that the testing requirement is the piece that survives, since it is the one both sides said yes to. The thing we would want written into it is a carve-out for non-commercial release below a stated capability level, with the level published and updated on a schedule. Without that, the paper trail from this week will read as the moment open research agreed to its own ceiling.

Sources

  1. Simon Willison, notes on the three open letters (August 2, 2026)
  2. Anthropic, Our position on open-weights models (July 27, 2026)
  3. Nathan Lambert, 6 months to live for open models (Interconnects, July 12, 2026)