Research Notes

Open Models and Safe AI Are Not Opposing Positions

Research Finder

Find by Keyword

Open Models and Safe AI Are Not Opposing Positions

Why the AI Industry Needs Both Openness and Capability-Based Safeguards

7/27/2026

Key Highlights

  • The debate over open-weight AI increasingly presents openness and safety as competing priorities, even though enterprises and policymakers need both.
  • As of July 26, 2026, neither Anthropic nor Amazon has signed the industry letter opposing broad restrictions on open-weight models. Amazon's absence complicates efforts to characterize the disagreement as an Anthropic-only campaign against open AI.
  • Open models expand model choice, enable private deployment, support independent research, and reduce dependence on a small number of proprietary providers.
  • Open-weight release also creates distinct risks because access cannot be revoked and built-in safeguards can be modified or removed.
  • Closed models are not inherently safe, just as open models are not inherently dangerous. Risk depends on model capabilities, deployment context, system access, and the controls surrounding the model.
  • AI policy should govern demonstrable capabilities and potential harm rather than treating a model's distribution approach as a proxy for risk.

The News

A group of technology companies and open-source organizations, including NVIDIA, Microsoft, Meta, IBM, Mistral, Hugging Face, Mozilla, and the Linux Foundation, has called on U.S. policymakers to avoid broad or premature restrictions on open-weight AI models. OpenAI and Google, which were not included among the original signatories, subsequently added their support.

The signatories argue that open models strengthen competition, accelerate innovation, enable independent security research, and give enterprises and governments greater control over how AI is deployed. They acknowledge concerns about intellectual property theft and unauthorized model distillation but contend that those issues should be addressed through targeted legal and commercial measures rather than sweeping restrictions on open models.

As of July 26, Anthropic and Amazon have not signed the letter. Anthropic has attracted more attention because it has publicly warned about the safety implications of releasing powerful models as open weight and has alleged that Chinese AI laboratories used thousands of fraudulent accounts and millions of Claude interactions to extract its capabilities. Anthropic argues that the danger increases when a distilled model is released openly because safeguards can be removed and access cannot be revoked.

Amazon's absence is more difficult to interpret. The company operates across both sides of the model market. AWS benefits from providing customers with access to proprietary and openly available models, while Amazon is also developing its own Nova model portfolio and has a deep commercial relationship with Anthropic. Its decision not to sign could signal caution about the letter's treatment of distillation, Chinese open-weight models, safety, or intellectual property. It could also reflect internal positioning that has not yet been made public.

What it does not support is a simple conclusion that every nonsignatory opposes open models. A company's absence from a coalition letter reveals that it has not endorsed that specific statement; it does not, on its own, establish the company's broader policy position or motivation.

Anthropic has not publicly called for a blanket U.S. ban on open-source AI. Its stated position focuses on export controls, independent evaluation, security requirements, and government authority to block the deployment of models presenting credible catastrophic risks. Critics worry that these policies could nevertheless produce de facto restrictions on open models or strengthen the position of proprietary frontier-model providers.

The disagreement is therefore more nuanced than a contest between companies that support open AI and those that oppose it. The real policy question is whether safety requirements will target specific capabilities and risks or use open-weight distribution itself as a substitute for evidence of danger.

Analyst Take

The AI industry is creating a false choice between openness and safety. Open models are important to the future of the enterprise AI stack, but that does not mean every model should be released without regard for its capabilities. Similarly, supporting stronger testing and safety requirements does not require treating proprietary control as the only responsible model for AI development.

The focus on Anthropic as the lone opponent of open AI oversimplifies both the signatory list and the underlying market dynamics. Amazon's absence is significant precisely because AWS has a clear commercial interest in model choice. Its cloud platform benefits when customers can select among proprietary, open-weight, and third-party models rather than standardizing on one provider.

Amazon also has competing considerations. It develops its own models, provides infrastructure to other model developers, maintains a major relationship with Anthropic, and must manage enterprise, intellectual property, national security, and regulatory concerns. Its absence may indicate that large AI and cloud providers have not reached a common position on where legitimate protection against model extraction ends and overly broad restriction of open models begins.

That uncertainty should make analysts cautious about assigning motives based solely on who signed. Anthropic's public statements provide a basis for examining its safety position. Amazon's absence provides much less evidence about its reasoning. Neither supports presenting regulatory capture as an established fact.

The concern about regulatory capture is still worth examining. Proprietary model providers could benefit if compliance requirements make it more difficult or expensive to release competing open models. Safety rules can create barriers to entry even when they are proposed in good faith. The appropriate analytical question is therefore not whether Anthropic secretly wants to eliminate open competition, but whether the policies it supports would disproportionately constrain open-model developers without producing a corresponding safety benefit.

For enterprises, open models are not primarily an ideological preference. They provide an architectural alternative to consuming AI entirely through a small number of managed APIs. Organizations can deploy them in private environments, bring models closer to sensitive data, customize them for specialized workloads, and exercise greater control over inference infrastructure and costs. Open models can also reduce the operational and commercial risk associated with depending on one provider's pricing, policies, availability, or roadmap.

These considerations will become increasingly important as enterprises adopt multiple models for different workloads. HyperFRAME Research Lens data shows that 79% of organizations anticipate using multiple foundation models concurrently. In that environment, access to open models expands the range of performance, cost, privacy, and deployment choices available to enterprise architects.

However, open-weight release transfers responsibility along with control. The model provider can no longer centrally update safeguards, disable a compromised system, or revoke access from a malicious user. The organization deploying the model becomes responsible for evaluation, infrastructure security, access controls, monitoring, patching, and governance. Many enterprises are interested in the flexibility of open models without yet having the operational maturity required to manage them safely at scale.

That does not make closed models inherently safer. A proprietary model connected to sensitive data, production systems, broad credentials, and external tools can create a greater operational risk than an open model running within a tightly constrained environment. Closed providers can impose usage policies and monitor activity, but those controls do not eliminate prompt injection, excessive permissions, unexpected agent behavior, data exposure, or failures in the surrounding application stack.

The model's license and distribution method are therefore incomplete indicators of risk. What matters is what the model can do, what systems it can reach, what authority it has, and how quickly harmful activity could scale.

This distinction becomes especially important as models move from generating content to operating as agents. An agent's potential impact is determined not only by the intelligence of the underlying model but also by its identity, credentials, tools, data access, network boundaries, approval requirements, and containment mechanisms. Model governance cannot be separated from runtime governance.

Anthropic is right that irreversible release deserves additional scrutiny when a model demonstrates advanced cyber, biological, autonomous-action, or AI-development capabilities. Open-model advocates are also right that closed providers should not be permitted to define openness itself as a safety failure. Doing so could protect incumbents without addressing the broader risks created by powerful models deployed through proprietary services.

The more defensible approach is capability-based governance applied consistently across open and closed systems. Models presenting credible high-consequence risks should face appropriate evaluation, disclosure, security, and deployment requirements regardless of who developed them or how customers access them. Open-weight status should inform the assessment because it changes the available mitigation options, but it should not predetermine the outcome.

Governing Risk Without Closing the Ecosystem

A workable framework should evaluate several dimensions of model risk:

  • Capability: Can the model materially enable sophisticated cyberattacks, biological threats, autonomous replication, or other high-consequence activity?
  • Accessibility: Can the developer monitor use, restrict access, update protections, or revoke compromised deployments?
  • Modifiability: Can users remove safeguards or substantially expand the model's capabilities?
  • Deployment context: Is the model isolated, or is it connected to tools, infrastructure, sensitive data, and production workflows?
  • Scale: How rapidly could harmful activity be repeated or distributed?
  • Mitigation: Have independent evaluations demonstrated that the relevant controls work under realistic conditions?

This approach recognizes that open-weight models have characteristics that change the risk equation without defining them as categorically unsafe. It also prevents closed-model providers from receiving an automatic presumption of safety simply because they retain control over the weights.

Policy must be equally careful about conflating unauthorized distillation with open-model development. Distillation is a widely used training technique, and the alleged extraction of Claude occurred through Anthropic's controlled service using fraudulent accounts. If those allegations are substantiated, they raise serious questions about intellectual property, identity verification, export controls, and coordinated API abuse. The fact that a resulting model may later be released openly can increase its reach, but openness is not what enabled the original extraction.

The response should target the misconduct directly through stronger identity and account controls, behavioral detection, technical evidence, contractual enforcement, and narrowly tailored legal remedies. Treating all open models as suspect would do little to solve the immediate control failure while potentially weakening the broader ecosystem of researchers, infrastructure providers, startups, and enterprises that depend on model access and choice.

Looking Ahead

The open-model debate will become more consequential as frontier capabilities improve and enterprises place models deeper inside operational workflows. Neither unrestricted openness nor exclusive reliance on proprietary control provides a sufficient governance strategy.

The industry letter demonstrates broad support for preserving open models, but its signatories do not represent a complete consensus. The absence of both Anthropic and Amazon shows that significant questions remain about model extraction, safety, intellectual property, geopolitical competition, and the responsibilities attached to releasing powerful capabilities.

Those disagreements should be examined directly rather than reduced to assumptions about corporate intent. Open models will remain important to competition, research, enterprise control, and technological sovereignty. At the same time, the industry needs credible mechanisms for evaluating whether particular capabilities can be released responsibly and for governing how models interact with data, tools, and critical systems.

The objective should not be to choose between open AI and safe AI. It should be to preserve the benefits of openness while applying proportionate controls to the capabilities and deployment conditions that create measurable risk. That requires a more precise debate than the industry is having today, and a governance model that looks beyond both the license and the signatory list to the complete AI stack.

Author Information

Stephanie Walter | Practice Leader - AI Stack

Stephanie Walter is a results-driven technology executive and analyst in residence with over 20 years leading innovation in Cloud, SaaS, Middleware, Data, and AI. She has guided product life cycles from concept to go-to-market in both senior roles at IBM and fractional executive capacities, blending engineering expertise with business strategy and market insights. From software engineering and architecture to executive product management, Stephanie has driven large-scale transformations, developed technical talent, and solved complex challenges across startup, growth-stage, and enterprise environments.