Policy
OpenAI And Anthropic Press Washington Over Chinese Open Models
OpenAI and Anthropic are aligned in Washington against what they describe as risks from powerful Chinese open-weight models, intensifying a policy fight over access, competition, and model provenance.
By Michael C ยท

OpenAI and Anthropic are usually described as rivals, but this week they are aligned in Washington around a shared concern: powerful Chinese open-weight models are moving faster than U.S. policy. Axios reported on July 22 that the two companies are pressing officials over the risks posed by China's open model push, a campaign that lands as Moonshot AI's Kimi K3 and other Chinese systems gain attention from developers and enterprise buyers. The immediate fight is about model access. The larger fight is about whether the United States can protect national security without using regulation as a shield for incumbent closed labs.
The timing is not accidental. AP reported earlier this month that Moonshot's Kimi K3 surprised parts of the U.S. technology industry with performance that appeared competitive with leading systems from OpenAI and Anthropic. The appeal of open weights is straightforward. Developers can inspect, adapt, and run models closer to their own data. Companies can reduce dependence on a single API provider. Researchers can reproduce and extend work. Those benefits are real. So are the security concerns when a capable model can be copied and modified after release.

The institutional problem starts with the difference between hosted and distributed systems. Hosted models give providers a control point. They can monitor usage, revoke access, apply rate limits, and enforce terms. Open-weight models distribute responsibility outward. Once weights are available, the original developer has less ability to prevent misuse, but users and defenders also gain more ability to test, adapt, and secure the system. Policymakers who treat one model of access as inherently safe and the other as inherently dangerous will miss the tradeoff.
The U.S. government is also weighing model provenance. Business Insider reported that White House technology official Michael Kratsios accused Moonshot of illicitly distilling Anthropic's Fable model to develop Kimi K3. Distillation itself is a legitimate machine-learning technique, but covert large-scale extraction from another company's model would raise different questions about intellectual property, contract enforcement, and national security. The reported accusation remains contested unless more evidence is made public.
That distinction matters because the policy tools are different. If the concern is misuse after release, the answer might involve capability thresholds, procurement limits, customer due diligence, and export controls. If the concern is model theft, the answer moves toward audits, watermarking, contractual restrictions, sanctions, and civil litigation. If the concern is competition from lower-cost Chinese systems, the honest answer may be industrial policy rather than safety regulation.

Open-model advocates will argue that restrictions could weaken U.S. competitiveness. Nvidia chief executive Jensen Huang has made a version of that case, warning that banning or discouraging open systems could reduce visibility and defensive capacity. The counterargument from frontier labs is that the most capable models can enable cyber, bio, persuasion, and surveillance risks that should not be freely downloadable. Both arguments can be sincere and self-interested at the same time.
The risk of regulatory capture is not theoretical. If the largest closed labs persuade Washington that open weights are uniquely dangerous, they may win a compliance environment that favors companies with large legal teams, government relationships, and hosted infrastructure. If policymakers ignore legitimate risk, they may allow powerful systems to circulate without testing or accountability. The correct standard has to be capability-based, evidence-based, and open enough for smaller developers to understand before enforcement arrives.
The international dimension makes the problem harder. A U.S. restriction may bind U.S. companies while foreign models continue to circulate through repositories, private mirrors, and overseas cloud providers. A complete ban on downloadable weights is difficult to enforce once a model has spread. That does not make policy useless. It means policy has to focus on realistic levers such as government procurement, trusted vendor rules, high-risk deployment controls, and disclosure requirements.
Washington now has to separate three questions that are often collapsed into one. Are Chinese open models capable enough to create material security risks? Were any of them trained through improper extraction from U.S. systems? Would restricting them help the United States, or would it push developers toward less visible channels? Those questions need evidence, not only lobbying.
OpenAI and Anthropic have put their weight behind a stricter view of the risk. Their argument deserves scrutiny because the technology is powerful. It also deserves scrutiny because the companies making the argument stand to benefit if the market moves toward hosted, regulated, U.S.-approved model access. The policy challenge is to govern the capability without letting any one business model write the rules.
Topics: OpenAI, Anthropic, open models, China AI