Leadership1 publisher3 min readPublished
Anthropic's open-weights holdout turns a safety argument into a supply question
More than 270 companies signed the Open Weights and American AI Leadership letter. Anthropic stayed out, and both sides of the case rest on the same property of published weights: once released, they are permanent.
The Board Room · Leadership desk

What happened
- More than 270 companies and organizations signed the Open Weights and American AI Leadership letter, among them major model developers, technology companies and infrastructure providers.
- Anthropic's position is that safety testing should be mandatory for sufficiently capable models whether they are open or closed.
- A Forbes Tech Council column proposes what its author calls regulated diffusion, in which older model generations get a route to open release instead of staying closed indefinitely.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- decision The choice in front of a buyer this quarter is which permanence to own: weights that cannot be recalled once downloaded, or an endpoint whose availability sits with the seller.
- constraint Until a capability threshold is written down by someone outside the labs, the release call belongs to firms that can profit either from selling a model or from declaring it too risky to open.
- contradiction The column endorses mandatory testing and doubts the motive of the company proposing it, so the word mandatory carries little weight for a buyer while the tester is also the vendor.
- precedent If pharmaceutical exclusivity is the template being argued for, the norm on offer is timed release of superseded models, and whoever sets that clock sets how long accumulated capability stays private.
A buyer weighing an API against a weight file is choosing which permanence to live with. Anthropic's case against opening sufficiently capable models is that safeguards can be removed once weights are out and access cannot simply be withdrawn [3]. The letter's case for opening them is wider access, better competition and control over how and where an organisation deploys AI [2].
Who applies the test is where the Forbes Tech Council column parts company with Anthropic. Harini Gopalakrishnan, listed as founder of theHaze.ai and Industry GTM at Vespa.ai, accepts the need for safety testing and questions the motive behind the proposal, asking how a model leader decides whether a model is safe to release as open weights [15][5]. Her objection is about incentives. A company has reason to show its model is safe enough to commercialise, and it can also have an economic reason to argue that a highly capable model is too risky to open, and the column says both can sit alongside genuine safety concerns [7]. "A closed model is not automatically safe. An open model is not automatically dangerous," she wrote [9].
Her remedy is common benchmarks plus independent assessment involving model developers, researchers, standards bodies, regulators and domain experts, applied to open and closed models with the same rigour [8]. Counting those categories, the developer is one participant in five [18]. The column does not name an existing body that could run such an assessment.
The analogy she draws is pharmaceutical. Drug discovery carries substantial investment, long development cycles and real risk, so companies get a period of commercial exclusivity, and then patents expire and generic competition spreads the benefit [10]. Applied to models, that would let labs monetise the current generation while previous generations get a pathway to broader availability, including open-weight release where appropriate, once they clear an independent safety assessment [11]. She calls this "regulated diffusion", and warns against letting temporary safety controls become permanent control over accumulated intelligence [12].
There is no purchase order attached to any of this: most enterprises buy an endpoint and a service agreement, and never handle a weight file. Their stake sits in the older generations. If capable superseded models never diffuse, the fallback a buyer assumes, that last year's frontier eventually becomes something you can host yourself, does not arrive. The column also holds the safety line in that direction: "A model with dangerous capabilities does not suddenly become safe simply because a newer generation has been developed," Gopalakrishnan wrote [13].
The enterprise half of the argument leans on Microsoft. Satya Nadella has talked about organisations compounding human capital with what he calls "token capital", and Microsoft's version of that future has companies turning their knowledge, workflows and judgment into AI systems that keep improving [14]. The column's closing question, whether enterprises are accumulating AI capability or accumulating dependency, breaks off mid-sentence in the published text [16].
None of this moves a price list next month, though over several years it bears on where a workload runs, and on whether the option to move that workload in-house is written into a contract or only assumed [2].
What to watch
- Whether any letter signatory or standards body funds and stands up an assessor that is not also a seller of the models it tests.
- Whether Anthropic's mandatory-testing position turns into a written capability threshold a buyer can read.
- Whether any lab publishes a superseded frontier model's weights after an outside assessment.