<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Claude Fable 5 Safeguards on RockB</title><link>https://baeseokjae.github.io/tags/claude-fable-5-safeguards/</link><description>Recent content in Claude Fable 5 Safeguards on RockB</description><image><title>RockB</title><url>https://baeseokjae.github.io/images/og-default.png</url><link>https://baeseokjae.github.io/images/og-default.png</link></image><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 01 Oct 2026 03:07:33 +0000</lastBuildDate><atom:link href="https://baeseokjae.github.io/tags/claude-fable-5-safeguards/index.xml" rel="self" type="application/rss+xml"/><item><title>Anthropic's War on Open Source AI: What It Means</title><link>https://baeseokjae.github.io/posts/anthropic-war-on-open-source-ai/</link><pubDate>Thu, 01 Oct 2026 03:07:33 +0000</pubDate><guid>https://baeseokjae.github.io/posts/anthropic-war-on-open-source-ai/</guid><description>Anthropic never proposed banning open-weight models. It pushed three narrower levers: chip controls, anti-distillation enforcement and safety testing.</description><content:encoded><![CDATA[<p>Anthropic never proposed a ban on open-weight models, and its own position post says so verbatim. The &ldquo;war&rdquo; is a fight over three indirect levers — chip export controls, an anti-distillation crackdown, and mandatory pre-release safety testing — each of which raises costs for open-weight competitors while leaving Anthropic&rsquo;s own API business untouched.</p>
<p>That distinction matters more than the shouting. Most coverage has framed this as open source versus closed source, or safety versus freedom. The actual policy content is narrower and more specific, and once you read it in Anthropic&rsquo;s own words, both the company&rsquo;s defenders and its loudest critics turn out to be partly right.</p>
<h2 id="the-short-answer-anthropic-never-proposed-a-ban--it-proposed-three-levers">The Short Answer: Anthropic Never Proposed a Ban — It Proposed Three Levers</h2>
<p>On July 27, 2026, Anthropic published &ldquo;Our position on open-weights models.&rdquo; The fifth sentence is unambiguous:</p>
<blockquote>
<p>&ldquo;Anthropic has never advocated for a ban on open-weights models.&rdquo;</p></blockquote>
<p>The post goes further. It calls open-weights models that lack dangerous capabilities &ldquo;a public good&rdquo; — something that &ldquo;cost[s] nothing beyond compute&rdquo; and is &ldquo;valuable to businesses, developers and researchers.&rdquo; That is not the language of a company at war with open source. It is the language of a company drawing a line between two categories of model and arguing that only one of them is a problem.</p>
<p>What Anthropic actually asked for instead of a ban was three things:</p>
<table>
  <thead>
      <tr>
          <th>Lever</th>
          <th>What Anthropic asked for</th>
          <th>Who pays the cost</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Chip export controls</td>
          <td>No sales of powerful chips or chipmaking equipment to China, plus a crackdown on smuggling</td>
          <td>Compute supply for Chinese labs</td>
      </tr>
      <tr>
          <td>Anti-distillation enforcement</td>
          <td>Crack down on &ldquo;industrial-scale distillation&rdquo; of US models</td>
          <td>Labs that train on frontier API outputs</td>
      </tr>
      <tr>
          <td>Mandatory safety testing</td>
          <td>Pre-release cyber, bio and alignment testing for all sufficiently capable models, open and closed</td>
          <td>Any lab shipping a frontier-capable model</td>
      </tr>
  </tbody>
</table>
<p>None of the three is a ban on open weights. All three are aimed at a specific country, a specific practice, and a specific capability threshold. That is why the fight is confusing: the levers are narrow, but their cumulative effect on the open-weight ecosystem is not obviously narrow at all.</p>
<p>The honest summary — and the one this article builds toward — is that Anthropic&rsquo;s argument contains real technical reasoning and real commercial self-interest, and it has never fully separated the two. So does the industry letter it declined to sign.</p>
<h2 id="what-actually-happened-a-three-day-timeline-july-2027-2026">What Actually Happened: A Three-Day Timeline (July 20–27, 2026)</h2>
<p>The news cycle that produced &ldquo;Anthropic&rsquo;s war on open source&rdquo; ran for one week. The compressed timeline explains why the story escalated so fast, and why the perception of a war stuck even after Anthropic denied one.</p>
<ul>
<li><strong>July 20, 2026</strong> — Axios reports that US officials are weighing a ban on US companies <em>using</em> Chinese open-weights models. The same report notes that OpenAI and Anthropic are united on China-restriction policy. (Retrieved from a Wayback snapshot dated 2026-09-22; the live page returns 403.)</li>
<li><strong>July 24, 2026</strong> — The &ldquo;Open Weights and American AI Leadership&rdquo; letter is published on NVIDIA&rsquo;s servers with roughly 25 initial signatories.</li>
<li><strong>July 25–26, 2026</strong> — OpenAI, Google and SpaceX add their names over the weekend. Signatories pass 50 within about 48 hours. Their earlier absence had briefly become the story itself.</li>
<li><strong>July 27, 2026</strong> — Dario Amodei publishes Anthropic&rsquo;s position post. The signature count on the letter is now above 70 and climbing.</li>
<li><strong>Now</strong> — The letter carries <strong>175 signatories</strong> in its signature block, counted programmatically from the PDF itself.</li>
</ul>
<h3 id="the-axios-report-that-started-it">The Axios Report That Started It</h3>
<p>The Axios story is what made Anthropic&rsquo;s later silence on the letter look contradictory. If OpenAI and Anthropic were aligned on restricting <em>use</em> of Chinese open models, then Anthropic declining to sign a letter calling open weights good for America read as an unforced inconsistency — the safety company sitting out the one industry-wide statement about openness.</p>
<p>The distinction Anthropic later drew is that opposing <em>use restrictions on Chinese models</em> is not the same as <em>endorsing open weights as a category</em>. That is a coherent position on paper. It is also a position that arrived three days after the industry had already lined up, which is precisely what critics seized on.</p>
<h3 id="the-letter-anthropic-wouldnt-sign-175-signatories">The Letter Anthropic Wouldn&rsquo;t Sign (175 Signatories)</h3>
<p>The &ldquo;Open Weights and American AI Leadership&rdquo; letter is short, business-oriented, and deliberately not a manifesto. Its three arguments:</p>
<ol>
<li><strong>Access.</strong> Open weights let startups, universities and public institutions build without training from scratch or &ldquo;paying frontier-model prices for every task.&rdquo; Frontier-scale capability should be reserved for genuine frontier problems.</li>
<li><strong>Competition.</strong> &ldquo;Competition is what keeps the gains of AI broadly shared rather than concentrated in a few hands&rdquo; — rivalry across models, cloud, chips and applications.</li>
<li><strong>Control and sovereignty.</strong> Customers want no vendor lock-in, and open weights let organizations own the value they create.</li>
</ol>
<p>It concedes the central risk explicitly: &ldquo;Once released, the weights are beyond the original developer&rsquo;s control, and modified versions are difficult to trace or reverse. But the right response to this risk is not to prohibit open weights.&rdquo;</p>
<p>Its hardest line is aimed squarely at closed-model incumbents: &ldquo;Relying solely on closed models is not inherently safe: they can be breached, misused, or fail in ways that outsiders cannot detect. And concentrating advanced AI capabilities behind a small number of closed models compounds that risk.&rdquo;</p>
<p>The signatory list is the part that made Anthropic&rsquo;s absence conspicuous. It includes Microsoft, Meta, Google, OpenAI, NVIDIA, IBM, Mistral, Hugging Face, Dell, Palantir, Mozilla, Databricks, Snowflake, Salesforce, ServiceNow, Workday, Uber, DoorDash, Notion, Vercel, Ollama, LM Studio, Red Hat, Intel, AMD, Qualcomm, SpaceX, The Linux Foundation, Andreessen Horowitz, Y Combinator and Nous Research. Every major US frontier lab except Anthropic. Amazon also did not sign, but Amazon is not a frontier model lab in the same sense, so the story attached to Anthropic.</p>
<p>It is worth noting what the letter&rsquo;s framing invites. &ldquo;Our AI leadership will be judged not by one frontier AI model, but by whether the United States builds a strong, open ecosystem that diffuses into every sector&rdquo; is a direct callback to the 1980s open-source fights. That framing makes the holdout look like an opponent of the open ecosystem, whether or not it is one.</p>
<h3 id="amodeis-rebuttal-published-only-after-the-industry-lined-up">Amodei&rsquo;s Rebuttal, Published Only After the Industry Lined Up</h3>
<p>Anthropic&rsquo;s response arrived on the fourth day. It agreed with parts of the letter and disagreed with two specific claims:</p>
<ul>
<li>It disputes that open weights &ldquo;necessarily make it easier to develop safeguards.&rdquo;</li>
<li>It disputes that broad access &ldquo;necessarily helps defenders more than attackers,&rdquo; arguing that biology in particular likely has &ldquo;a strong attacker-defender asymmetry.&rdquo;</li>
</ul>
<p>The timing is the part critics keep returning to. Three days of silence, and a response only once every peer lab had signed. That pattern — not the content — is what produced the &ldquo;war on open source&rdquo; headline.</p>
<h2 id="what-anthropic-actually-said--in-its-own-words">What Anthropic Actually Said — In Its Own Words</h2>
<p>Strip away the framing and Anthropic&rsquo;s post makes four moves. Each is worth reading carefully, because the strongest criticism of the post is that it never fully answers the question it raises.</p>
<h3 id="the-concession-non-dangerous-open-weights-are-a-public-good">The Concession: Non-Dangerous Open Weights Are &ldquo;a Public Good&rdquo;</h3>
<p>Anthropic&rsquo;s stated position is that open weights without dangerous capabilities are a net positive — cheap to replicate beyond compute cost, useful to businesses, developers and researchers. This is a real concession, not a rhetorical feint. A company that wanted open weights banned would not describe them as a public good.</p>
<h3 id="the-two-nightmare-scenarios">The Two Nightmare Scenarios</h3>
<p>Anthropic names two scenarios it treats as genuinely catastrophic:</p>
<ol>
<li><strong>Authoritarian capability.</strong> Governments — it names the CCP as &ldquo;the most capable threat,&rdquo; while noting it is not the only one — building models more powerful than the US for &ldquo;permanent military superiority&rdquo; or deep domestic repression.</li>
<li><strong>Misuse and misalignment.</strong> Cyberattacks, biological attacks, and alignment failures in models that are widely deployed.</li>
</ol>
<p>The interesting move is what Anthropic says next about scenario one: it is &ldquo;irrelevant whether these models are released with open weights,&rdquo; because &ldquo;the most dangerous model may be one that is trained in secret and handed only to the PLA.&rdquo; That is an argument <em>against</em> protectionism as a tool, made by the lab that is most often accused of seeking protectionism.</p>
<h3 id="why-a-usage-ban-does-nothing--and-why-that-admission-matters">Why a Usage Ban &ldquo;Does Nothing&rdquo; — and Why That Admission Matters</h3>
<p>Anthropic&rsquo;s own words on the proposed US usage ban:</p>
<blockquote>
<p>&ldquo;A US-business usage ban does nothing to address this risk, because bad actors are unlikely to be legitimate US businesses. It would protect US AI companies from competition, but that has never been my goal.&rdquo;</p></blockquote>
<p>Read that sentence twice. It is an explicit acknowledgment that the policy under discussion would function as protectionism, paired with a denial of protectionist intent. Whether you find the denial credible depends on how you weigh the next section — because the three levers Anthropic <em>does</em> support each raise costs for competitors, and none of them constrain Anthropic&rsquo;s API revenue.</p>
<p>Anthropic&rsquo;s stated alternative to releasing weights is gated access rather than openness: Project Glasswing, launched in early 2026, gives vetted enterprises access to its cybersecurity model instead of publishing the weights. It is a coherent third path, and it is also a path that keeps the capability inside one company.</p>
<h2 id="lever-1--chip-export-controls-the-scaling-law-argument">Lever 1 — Chip Export Controls: The Scaling-Law Argument</h2>
<p>Anthropic&rsquo;s first ask is the least controversial and the most mechanical: no sales of powerful chips or chipmaking equipment to China, plus enforcement against smuggling. The reasoning rests on scaling laws.</p>
<p>China has limited domestic production capacity for leading-edge accelerators. Anthropic&rsquo;s argument is that because capability scales with compute, a country that cannot buy or build the chips cannot out-train a country that can. Blocking chip supply is therefore, in Anthropic&rsquo;s framing, &ldquo;the most efficient and direct way&rdquo; to prevent an authoritarian government from reaching permanent capability superiority.</p>
<p>This is the lever with the clearest precedent, and it is also the one where the causal chain is longest. Export controls have been in place for years while Chinese open-weight releases have accelerated. In July 2026, Moonshot AI published Kimi K3 — a 2.78-trillion-parameter mixture-of-experts model with a 1M-token context window, the largest open-weight release to date, and the strongest single data point that compute restriction has not stopped frontier-adjacent releases from arriving.</p>
<h2 id="lever-2--the-anti-distillation-crackdown-and-the-hypocrisy-charge">Lever 2 — The Anti-Distillation Crackdown (And the Hypocrisy Charge)</h2>
<p>Anthropic&rsquo;s second ask is to crack down on &ldquo;industrial-scale distillation&rdquo; — training a model on the outputs of another model. This is the most technically interesting lever and the most contested.</p>
<h3 id="what-industrial-scale-distillation-actually-looks-like">What Industrial-Scale Distillation Actually Looks Like</h3>
<p>Anthropic describes coordinated campaigns run out of DeepSeek, Moonshot AI and MiniMax, totaling roughly 16 million exchanges across about 24,000 fraudulent accounts routed through &ldquo;hydra clusters&rdquo; — automated traffic blended with organic queries, with credentials rotated whenever accounts were flagged. Anthropic separately alleged to the Senate Banking Committee that Alibaba carried out &ldquo;the largest known distillation attack&rdquo; against it, reported elsewhere as 25,000 fake accounts and 29 million exchanges. Those two figures conflict; treat the range as disputed and do not quote either as settled.</p>
<p>The economics explain why the practice is attractive. Ten to twenty million high-quality exchanges — a few million dollars in API fees — is enough to train a competitive student model on a narrow capability such as agentic coding. Against training a teacher from scratch, that is not a discount; it is a different order of magnitude.</p>
<p>Anthropic&rsquo;s logic is that distillation is far more compute-efficient than training from scratch, which lets Chinese labs &ldquo;build much better models than their number of chips would ordinarily enable&rdquo; and bring their frontier &ldquo;within a few months of the US frontier.&rdquo; Even so, the post insists: &ldquo;a blanket ban on open-weights models is neither the correct remedy nor something we have called for.&rdquo;</p>
<h3 id="the-training-data-asymmetry-anthropic-doesnt-answer">The Training-Data Asymmetry Anthropic Doesn&rsquo;t Answer</h3>
<p>The sharpest criticism of the distillation argument is that it is asymmetric in exactly the way that favors the accuser.</p>
<p>Every frontier model, Anthropic&rsquo;s included, was trained by ingesting whatever data its developers could obtain. Anthropic paid a large settlement to authors over its use of a &ldquo;pirate library&rdquo; of books. The company now wants distillation of <em>its own</em> outputs treated as theft. On the narrow factual question of whether Anthropic&rsquo;s training data was itself obtained cleanly, critics are on solid ground, and Anthropic&rsquo;s post does not address the charge.</p>
<p>The counterargument is that these are different legal questions, and it is stronger than it first appears. Distillation of API outputs is a contract matter, not a copyright matter. When a developer calls the Messages API, they accept terms of service; if those terms forbid using outputs to train a competing model, the restriction is enforceable as a contract regardless of what copyright law says about training on public text. The fair-use defense that protects training on scraped web text does not automatically extend to outputs governed by an agreement the customer signed.</p>
<p>That is the honest shape of the dispute. It is not &ldquo;hypocrisy versus principle.&rdquo; It is two different legal regimes, and each side is arguing under the one that suits it.</p>
<p>The broader consequence is the one to watch. If anti-distillation enforcement becomes a regulatory priority rather than a terms-of-service matter, it touches standard practice. Fine-tuning on API outputs is how a large share of production-grade narrow models get built today. A regime that makes that practice risky — legally, contractually, or through detection and account termination — raises the cost of building on top of any frontier API.</p>
<h2 id="lever-3--mandatory-safety-testing-standard-or-a-ban-with-more-steps">Lever 3 — Mandatory Safety Testing: Standard, or &ldquo;a Ban With More Steps&rdquo;?</h2>
<p>Anthropic&rsquo;s third ask is pre-release testing for cyber, biological and alignment risks, applied to all sufficiently capable models regardless of origin or openness, with exemptions for less capable startup and academic models. Anthropic describes this as &ldquo;close to a consensus&rdquo; and cites UK AI Security Institute work and joint Anthropic–AE Studio research on modular training strategies.</p>
<p>The proposal is the most reasonable-sounding of the three, and the criticism of it is the most procedural. The post does not specify:</p>
<ul>
<li><strong>Who administers the test.</strong> No named agency, body or certification regime.</li>
<li><strong>What the threshold is.</strong> &ldquo;Sufficiently capable&rdquo; is never defined by a measurable criterion.</li>
<li><strong>What happens on failure.</strong> No stated consequence, appeal path or remediation process.</li>
</ul>
<p>A mandate with no administrator, no threshold and no consequence is not a policy; it is a placeholder. Two readings are available. The generous one is that Anthropic is laying out a principle and leaving the mechanics to legislators, which is a normal thing for a company post to do. The suspicious one is that an unstated threshold is a threshold that gets set later, by whoever writes the rules, and that a compliance-cost barrier favors incumbents with legal teams over open-weight challengers who publish weights and walk away. Both readings are defensible from the text.</p>
<h2 id="evidence-from-anthropics-own-products-the-fable-5-system-card">Evidence From Anthropic&rsquo;s Own Products: The Fable 5 System Card</h2>
<p>The abstract debate about what a testing regime might do becomes concrete when you read what Anthropic already ships. Claude Fable 5&rsquo;s system card, Section 1.5, documents a classifier-based safeguard system that applies to four topic classes:</p>
<ol>
<li>Cybersecurity</li>
<li>Biology and chemistry</li>
<li>Distillation attempts</li>
<li>&ldquo;Accelerating frontier AI development&rdquo;</li>
</ol>
<h3 id="four-classifier-categories-three-different-behaviors">Four Classifier Categories, Three Different Behaviors</h3>
<p>The card describes three separate user-visible behaviors depending on which surface the request arrives through:</p>
<table>
  <thead>
      <tr>
          <th>Surface</th>
          <th>Behavior on a classifier hit</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Claude app</td>
          <td>Falls back to Opus 4.8 with a notification to the user</td>
      </tr>
      <tr>
          <td>Messages API</td>
          <td>Blocks by default, returning a structured category</td>
      </tr>
      <tr>
          <td>Some interfaces</td>
          <td>Falls back non-configurably, emitting only a session event</td>
      </tr>
  </tbody>
</table>
<p>The frontier-development classifiers are described as narrowly targeting &ldquo;frontier LLM development (for example, on building pretraining pipelines, distributed training infrastructure, or ML accelerator design)&rdquo; — and Anthropic states they should not affect the vast majority of AI development.</p>
<h3 id="the-fallback-you-cant-configure">The Fallback You Can&rsquo;t Configure</h3>
<p>The third row of that table is the one enterprise buyers should read carefully. On some surfaces, a classifier hit silently routes the request elsewhere, and the only signal is a session event. If you are paying for a specific model and building against its documented behavior, a non-configurable, quiet substitution changes your product&rsquo;s behavior without changing your code.</p>
<p>That is a concrete commercial fact, not an ideological one. It is the argument that the more abstract open-versus-closed framing tends to crowd out: what matters to a buyer is whether the product they paid for behaves the way it is documented to behave.</p>
<h3 id="using-claude-to-develop-competing-models-already-violates-our-terms-of-service">&ldquo;Using Claude to Develop Competing Models Already Violates Our Terms of Service&rdquo;</h3>
<p>The distillation classifier has an explicit rationale in the card:</p>
<blockquote>
<p>&ldquo;Using Claude to develop competing models already violates our Terms of Service, but enforcing this restriction through classifiers avoids accelerating the actors most willing to violate these terms.&rdquo;</p></blockquote>
<p>This is a useful line because it clarifies the commercial logic. The restriction is not new policy — it is existing policy, now enforced automatically. The stated reason is that manual enforcement selectively punishes the actors least willing to break the rules, so automated enforcement is fairer. The stated reason is coherent. It is also, unavoidably, enforcement that happens to land hardest on the companies Anthropic competes with.</p>
<h2 id="who-objected-and-why-it-got-personal">Who Objected, and Why It Got Personal</h2>
<h3 id="sacks-gurley-kai-fu-lee-and-anthropics-own-engineer">Sacks, Gurley, Kai-Fu Lee, and Anthropic&rsquo;s Own Engineer</h3>
<p>The reaction to Anthropic&rsquo;s position was unusually personal for a policy debate. Four examples:</p>
<ul>
<li><strong>David Sacks</strong>, White House AI and crypto adviser, has repeatedly accused Anthropic of &ldquo;running a sophisticated regulatory capture strategy based on fear-mongering.&rdquo; After the letter, he posted: &ldquo;The entire tech industry, except Anthropic, has publicly supported open-source AI.&rdquo;</li>
<li><strong>Bill Gurley</strong> of Benchmark said the real problem with open weights &ldquo;is it competes with their corporate economic strategy.&rdquo;</li>
<li><strong>Kai-Fu Lee</strong> of 01.AI noted: &ldquo;who DIDN&rsquo;T sign the Open Weight letter is far more interesting than who did.&rdquo;</li>
<li><strong>Peter Steinberger</strong> of OpenClaw called out the silence on openness while noting that OpenAI — the company whose &ldquo;Open&rdquo; branding had long been a punchline — signed the letter.</li>
</ul>
<p>Then there is the internal one. Anthropic staffer Julian Schrittwieser posted mocking replies the day the letter went up — &ldquo;looking forward to the CUDA and GPU driver open source release!&rdquo; — before clarifying: &ldquo;I actually think open models can be very useful! But it&rsquo;s interesting how some historically extremely open source companies are suddenly all in favor of openness.&rdquo;</p>
<p>That clarification is the sharpest thing written about this controversy, and it cuts both ways. He is right that NVIDIA, Microsoft and Meta are not obviously the natural constituency for open weights. He is also, by implication, describing Anthropic&rsquo;s own coherence problem: it publishes a large volume of safety and interpretability research openly, and has never released a single weight.</p>
<p>On the Hacker News thread for Anthropic&rsquo;s position post — 1,180 points and 1,747 comments — the dominant reactions were regulatory-capture accusations (&ldquo;As expected they will try hard to use government to kill competitors&rdquo;) and hypocrisy claims about distillation (&ldquo;The ban on distillation seems hypocritical&rdquo;), with a minority defending the risk framing. That distribution is a reasonable proxy for how the technical audience read the post.</p>
<h2 id="the-data-nobody-leads-with-open-models-win-volume-frontier-labs-keep-spend">The Data Nobody Leads With: Open Models Win Volume, Frontier Labs Keep Spend</h2>
<p>The most useful practical finding in this entire debate is not about policy at all. It is about token economics, and almost nobody leads with it.</p>
<h3 id="token-volume-vs-token-spend-on-vercels-gateway-and-openrouter">Token Volume vs Token Spend on Vercel&rsquo;s Gateway and OpenRouter</h3>
<p>Open-weight models are winning usage. They are not winning revenue.</p>
<p>On Vercel&rsquo;s AI gateway, DeepSeek surged to lead token <em>volume</em> at just over a third of all tokens, with Z.ai&rsquo;s GLM-5.2 fourth. On OpenRouter, DeepSeek V4 Flash processed roughly <strong>5.3 trillion tokens weekly</strong> versus about <strong>2.0 trillion</strong> for Opus 4.8, the most popular frontier model.</p>
<p>Now the spend side. Anthropic still accounted for <strong>more than half of overall AI spend</strong> on Vercel&rsquo;s gateway, down only slightly month over month. The reason is price. Opus 4.8&rsquo;s token cost is roughly <strong>23x higher</strong> than DeepSeek V4 Flash&rsquo;s, so a lab can lose the volume war by a factor of 2.6 and still win the revenue war by a wide margin.</p>
<h3 id="the-120x-price-spread-and-the-two-tier-model-economy">The ~120x Price Spread, and the Two-Tier Model Economy</h3>
<p>The live OpenRouter catalogue as of October 1, 2026 lists <strong>462 models</strong>, 16 of them <code>:free</code> variants — open weight is a large share of supply, not a fringe. The price spread across that catalogue is what makes the two-tier economy function:</p>
<table>
  <thead>
      <tr>
          <th>Model</th>
          <th>Input price per million tokens (OpenRouter)</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Claude Opus 4.8</td>
          <td>$5.00</td>
      </tr>
      <tr>
          <td>GLM-5.2 (Z.ai)</td>
          <td>$1.40</td>
      </tr>
      <tr>
          <td>Kimi K3</td>
          <td>$0.28</td>
      </tr>
      <tr>
          <td>DeepSeek V4 Flash</td>
          <td>$0.042</td>
      </tr>
  </tbody>
</table>
<p>That is a spread of roughly <strong>120x</strong> from top to bottom. Kimi K3 — the largest open-weight model ever shipped at 2,779,931,837,184 parameters, with 1,302,723 downloads and 11,562 likes on Hugging Face and a modified-MIT license requiring a separate agreement for Model-as-a-Service vendors above $20M revenue — costs about 18x less per input token than Opus 4.8.</p>
<p>The Decagon CEO Jesse Zhang, quoted by TechCrunch, described the resulting pattern as a two-phase life cycle: frontier models prove out use cases, which then migrate to cheaper open models as they mature, while new use cases keep arriving and hold frontier spend roughly flat. His summary: &ldquo;The frontier labs will keep owning discovery. Open source will increasingly own production.&rdquo;</p>
<h3 id="why-not-hurting-anthropic-yet-is-the-honest-headline">Why &ldquo;Not Hurting Anthropic Yet&rdquo; Is the Honest Headline</h3>
<p>If that framing is right, the two-tier model economy may be a stable feature rather than a transition phase. Open models commoditize the production tier — the high-volume, well-understood workloads — while frontier labs keep the discovery tier, where buyers pay for capability they cannot get elsewhere.</p>
<p>This is the strongest argument against Anthropic&rsquo;s urgency, and it comes from Anthropic&rsquo;s own business results rather than from an ideologue. If open weights were an existential competitive threat, the spend data would show it. It does not. It shows a company losing volume share and retaining spend share, which is what a company in the premium tier of a commoditizing market should expect.</p>
<h2 id="the-case-for-withholding-weights--steelmanned">The Case for Withholding Weights — Steelmanned</h2>
<p>The strongest version of Anthropic&rsquo;s position, stated without the framing:</p>
<ol>
<li><strong>Irreversibility is real.</strong> Anthropic&rsquo;s own footnote concedes the asymmetry directly: open models present higher risk &ldquo;because it is very difficult to apply guardrails to them or monitor their usage, and once weights are released they cannot be withdrawn.&rdquo; A closed model can be patched, rate-limited or withdrawn. A released weight file cannot.</li>
<li><strong>Cyber capability is converging fast.</strong> UK AI Security Institute evaluations in mid-2026 put the cyber capability gap between frontier and best open-weight models at <strong>4–7 months</strong>, down from <strong>6–10 months</strong> a year earlier. Anthropic reads that as: release a frontier open model today and you hand everyone 2027 capability. The trend is real even if the interpretation is contested.</li>
<li><strong>Biology may be attacker-favored.</strong> This is Anthropic&rsquo;s most specific technical claim and the one the letter does not rebut: if biological capability has a &ldquo;strong attacker-defender asymmetry,&rdquo; then the &ldquo;defenders need parity&rdquo; argument does not hold for that domain.</li>
<li><strong>Testing all models equally is not, on its face, protectionism.</strong> A rule that applies to open and closed models alike is a burden on everyone, including Anthropic.</li>
</ol>
<h2 id="the-case-for-open-weights--steelmanned">The Case for Open Weights — Steelmanned</h2>
<p>The strongest version of the opposing case:</p>
<ol>
<li><strong>Concentration is its own risk.</strong> The letter&rsquo;s hardest line is correct: closed models &ldquo;can be breached, misused, or fail in ways that outsiders cannot detect,&rdquo; and concentrating capability behind a few closed models &ldquo;compounds that risk.&rdquo; A single point of failure in a system that important is not a safety property.</li>
<li><strong>Concrete defense use case, not abstraction.</strong> Hugging Face reported that it used an open-source model from China&rsquo;s Z.ai to defend against a security incident involving a rogue OpenAI AI agent, because restrictions made closed models unavailable for the task. That is one paragraph of evidence doing more persuasive work than any amount of policy prose: when defenders needed capability, openness is what gave it to them.</li>
<li><strong>Withholding buys a moat, not safety.</strong> The coalition reads the same capability-gap trend Anthropic reads and reaches the opposite conclusion. If the gap narrows on its own — 6–10 months to 4–7 months in a single year — then withholding weights delays the arrival of a capability that was going to arrive anyway, while extending the incumbent&rsquo;s lead. On that reading, the safety benefit is small and the competitive benefit is large.</li>
<li><strong>Restrictions build the wrong ecosystem.</strong> Techdirt&rsquo;s Mike Masnick made the point sharply: restricting the open ecosystem &ldquo;would guarantee that the wider open ecosystem gets built on non-American tools.&rdquo; The best open-weight models come from China partly because releasing weights is the most effective path to becoming the default infrastructure for the next generation of tooling — the Linux-of-AI argument. A policy that pushes developers away from US models strengthens exactly the labs it is meant to constrain.</li>
<li><strong>Testing without thresholds is a moat.</strong> As covered above, an unspecified &ldquo;sufficiently capable&rdquo; bar with an unstated administrator and no stated consequence is a rule whose cost lands on whoever cannot afford to litigate it.</li>
</ol>
<h2 id="what-it-means-for-developers-and-enterprise-buyers">What It Means for Developers and Enterprise Buyers</h2>
<p>Set the geopolitics aside. Three things in this story change what you should do this quarter.</p>
<h3 id="if-you-fine-tune-on-api-outputs">If You Fine-Tune on API Outputs</h3>
<p>Fine-tuning on API outputs — distillation, in Anthropic&rsquo;s framing — is standard practice for building narrow production models. Anthropic&rsquo;s system card is explicit that using Claude to develop competing models already violates its terms of service, and that classifiers now enforce this automatically.</p>
<p>The practical exposure is narrower than the rhetoric suggests: if you are not building a competing frontier model, the classifiers are documented as narrowly targeting pretraining pipelines, distributed training infrastructure and accelerator design. But three questions are worth answering before your next fine-tune:</p>
<ul>
<li>Does your provider&rsquo;s ToS restrict training on outputs, and does it restrict it only for competing models?</li>
<li>Are your outputs attributable to a single provider, or aggregated across several?</li>
<li>If anti-distillation enforcement becomes regulatory rather than contractual, does your training data lineage survive an audit?</li>
</ul>
<h3 id="if-you-deploy-open-weight-models-internally">If You Deploy Open-Weight Models Internally</h3>
<p>The cost case is now overwhelming for the production tier. DeepSeek V4 Flash at $0.042 per million input tokens against Opus 4.8 at $5.00 is a 120x spread, and Kimi K3 — 2.78T parameters, 1M context — sits at $0.28 while holding 1.3 million downloads. If your workload is high-volume and well-specified, the two-tier economy says your inference should be running on the open tier.</p>
<p>The risk case is not technical; it is regulatory. Every lever in this debate is aimed at the supply chain behind Chinese open-weight models. A dependency on that supply chain is a dependency on chip export policy, distillation enforcement and testing mandates resolving in a particular direction. Portfolio your model dependencies the way you portfolio any other single-source risk.</p>
<h3 id="if-you-route-frontier-ai-development-requests-through-claude">If You Route Frontier-AI-Development Requests Through Claude</h3>
<p>This is the most immediately actionable item and the one most likely to surprise teams. If your product asks Claude to help build ML infrastructure, write distributed training code or work on accelerator design, you may be hitting a frontier-development classifier. Depending on your surface, the result is a fallback to Opus 4.8 with a notification, a structured block, or — on some interfaces — a non-configurable fallback that emits only a session event.</p>
<p>Test your integration for that third case explicitly. A silent model substitution is the kind of behavior that produces a bug report six weeks later about &ldquo;the model got worse,&rdquo; with nothing in the logs.</p>
<h2 id="gram-and-modular-training-the-one-proposal-that-could-satisfy-both-sides">GRAM and Modular Training: The One Proposal That Could Satisfy Both Sides</h2>
<p>There is exactly one genuinely new technical idea on the table, and it is underreported: Anthropic&rsquo;s GRAM research — Gradient Routed Auxiliary Modules — attempts to sequester dual-use knowledge into switchable parameters that can be <em>deleted at deployment</em> without degrading general reasoning.</p>
<p>If that works, it dissolves the core dilemma. A lab could release weights under a permissive license while structurally excising the cyber or bio capability that makes the release dangerous, and both sides could claim a win: open weights ship, and the specific capability Anthropic objects to does not.</p>
<p>Anthropic cites this work alongside UK AI Security Institute research as a possible path to making open weights safer. The honest caveat is that it is research, not a product, and &ldquo;delete the dangerous capability, keep the general reasoning&rdquo; is the kind of claim that sounds clean in a paper and gets messier in evaluation. But it is the only proposal in this entire debate that does not require someone to lose.</p>
<h2 id="how-to-read-this-debate-without-taking-a-side">How to Read This Debate Without Taking a Side</h2>
<p>Four rules that hold up under both readings of the evidence:</p>
<ol>
<li><strong>Separate the levers from the framing.</strong> &ldquo;Anthropic is at war with open source&rdquo; and &ldquo;Anthropic never proposed a ban&rdquo; are both defensible statements about different things. Judge the three levers on their specifics — who pays, what threshold, what consequence — not on the tone of the post announcing them.</li>
<li><strong>Check the coherence problem on both sides.</strong> Anthropic publishes research openly and has never released a weight. Microsoft and Meta signed a letter calling open weights essential while keeping most of their own frontier weights closed and building their fortunes on proprietary software. Anthropic&rsquo;s own engineer said it best: it is interesting how historically un-open companies are suddenly all in favor of openness.</li>
<li><strong>Follow the spend, not the volume.</strong> Token volume leadership by open models is real and largely irrelevant to the question of whether open source is threatening frontier labs. Spend is the metric that answers that question, and spend still favors the frontier labs by a wide margin.</li>
<li><strong>Treat the capability gap as the pivot.</strong> Everything in Anthropic&rsquo;s argument depends on whether the frontier-to-open cyber gap (4–7 months, down from 6–10) keeps narrowing. If it does, withholding weights buys a moat and little else. If the gap closes, a single release hands everyone 2027 capability. Both trajectories are live, and no one in this debate knows which one is happening.</li>
</ol>
<h2 id="faq">FAQ</h2>
<h3 id="is-anthropic-trying-to-ban-open-weight-models">Is Anthropic trying to ban open-weight models?</h3>
<p>No. Anthropic&rsquo;s position post states verbatim that &ldquo;Anthropic has never advocated for a ban on open-weights models,&rdquo; and calls open-weights models without dangerous capabilities &ldquo;a public good.&rdquo; What Anthropic supports instead is three narrower measures: chip export controls on China, enforcement against industrial-scale distillation, and mandatory pre-release safety testing for sufficiently capable models. Each of those raises costs for open-weight competitors, which is why the &ldquo;war&rdquo; framing persists despite the explicit denial.</p>
<h3 id="what-is-the-difference-between-open-weights-and-open-source">What is the difference between open weights and open source?</h3>
<p>Open weights means the trained parameters are published and can be downloaded, run and fine-tuned. Open source, in the traditional software sense, means the training code, data pipeline and licence permit modification and redistribution. Most &ldquo;open&rdquo; AI models are open-weight but not fully open source: Kimi K3, the largest open-weight release to date at 2.78 trillion parameters, ships under a modified-MIT licence that requires a separate agreement for Model-as-a-Service businesses above $20M in trailing revenue. The distinction matters because policy debates often use the two terms interchangeably when the obligations are quite different.</p>
<h3 id="why-didnt-anthropic-sign-the-open-weights-and-american-ai-leadership-letter">Why didn&rsquo;t Anthropic sign the Open Weights and American AI Leadership letter?</h3>
<p>Anthropic has not given a mechanical explanation of the decision, but its position post sets out two explicit disagreements with the letter&rsquo;s argument. It disputes that open weights &ldquo;necessarily make it easier to develop safeguards,&rdquo; and it disputes that broad access &ldquo;necessarily helps defenders more than attackers,&rdquo; arguing biology in particular likely has &ldquo;a strong attacker-defender asymmetry.&rdquo; The letter, published July 24, 2026 with 175 signatories including every other major US frontier lab, never addresses that asymmetry directly.</p>
<h3 id="is-it-legal-to-fine-tune-a-model-on-another-models-outputs">Is it legal to fine-tune a model on another model&rsquo;s outputs?</h3>
<p>It depends on the contract, not on copyright. Distillation of API outputs is governed by the terms of service you accepted when you called the endpoint. Anthropic&rsquo;s Claude Fable 5 system card states plainly that &ldquo;using Claude to develop competing models already violates our Terms of Service,&rdquo; and that classifiers now enforce this automatically. Training on publicly scraped text and training on a competitor&rsquo;s API outputs are different legal questions — the fair-use defense that applies to the former does not automatically cover the latter, which is exactly why the two sides of this debate keep talking past each other.</p>
<h3 id="which-labs-have-released-open-weights-and-which-havent">Which labs have released open weights, and which haven&rsquo;t?</h3>
<p>Every major frontier lab has released open weights at least once — Meta with Llama and later releases, Google with Gemma, xAI with Grok weights, Mistral across its entire existence, Microsoft with Phi, NVIDIA with Nemotron, and OpenAI with GPT-2, Whisper and gpt-oss. Anthropic has released none, which is the single most-cited piece of evidence in the regulatory-capture argument against it. The counterpoint is that most of those releases are partial: the signatories with the strongest open-weights rhetoric keep their most capable models closed.</p>
<h3 id="will-these-policy-levers-actually-stop-chinese-frontier-models">Will these policy levers actually stop Chinese frontier models?</h3>
<p>The evidence so far says not yet. Export controls have been in force for years while Chinese open-weight releases accelerated: Kimi K3 shipped in July 2026 at 2.78 trillion parameters with a 1M-token context window, the largest open-weight model ever released, and GLM-5 was trained entirely on Huawei Ascend chips with no NVIDIA hardware at any stage. The UK AI Security Institute&rsquo;s mid-2026 evaluations put the cyber capability gap at 4–7 months, narrowed from 6–10 months a year earlier — which is precisely the trend Anthropic cites as urgent and the open-weights coalition cites as proof that withholding weights achieves nothing but a delay.</p>
<h2 id="conclusion-a-fight-over-levers-not-a-ban">Conclusion: A Fight Over Levers, Not a Ban</h2>
<p>Anthropic is not at war with open source, and it is not a neutral party either. Both of those statements are true at once, which is why this debate has produced so much heat and so little agreement.</p>
<p>What Anthropic actually proposed is three levers — chip controls, distillation enforcement and testing mandates — each aimed at a specific threat and each carrying a specific cost that lands on open-weight competitors. None of them constrains Anthropic&rsquo;s own API revenue. That asymmetry is the strongest evidence for the regulatory-capture reading, and no amount of technical framing erases it.</p>
<p>What Anthropic actually conceded is equally real: that most open weights are a public good, that a usage ban would function as protectionism and would miss the actual threat, that released weights cannot be withdrawn, and that the frontier-to-open cyber gap is narrowing on its own. Those admissions make the purely cynical reading hard to sustain.</p>
<p>The practical takeaway for anyone building on these models is not to pick a side but to notice what is already true. Open weights have won the production tier on price — a 120x spread between the cheapest and most expensive options on OpenRouter — while frontier labs still capture the majority of spend. Anthropic&rsquo;s classifiers already route around some requests today. And the whole argument turns on a capability gap that is closing at a rate nobody can control. Build for both trajectories: keep the open tier for volume, keep the frontier tier for discovery, and portfolio the regulatory risk the same way you would any other single-source dependency.</p>
<p>If you want to see the open-weight side of this market in more depth, the <a href="https://baeseokjae.github.io/posts/kimi-k2-vs-claude-vs-gpt5-coding-2026/">Kimi K2 vs Claude vs GPT-5 coding comparison</a>, the <a href="https://baeseokjae.github.io/posts/glm-5-developer-review-2026/">GLM-5 developer review</a> and the <a href="https://baeseokjae.github.io/posts/ollama-vs-lm-studio-local-ai-2026/">local deployment guide to Ollama and LM Studio</a> cover what these models do in practice.</p>
]]></content:encoded></item></channel></rss>