我们对于开放权重模型的立场
Our position on open-weights models

原始链接: https://www.anthropic.com/news/position-open-weights-models

Anthropic 首席执行官达里奥·阿莫代(Dario Amodei)澄清,他并不支持禁止开源权重 AI 模型,并强调安全、开源的工具具有重要的公共价值。他认为,对中国模型实施保护主义禁令无法解决他所担心的核心国家安全问题,即威权政权开发军事级 AI 以及网络或生物攻击的风险。 阿莫代建议通过以下三项战略性干预措施来取代全面禁令: 1. **硬件限制:** 对先进芯片的销售和走私实施严格管控,以防止外国对手训练出更强大的模型。 2. **打击模型蒸馏:** 实施政策以遏制国家支持的、工业规模的“模型蒸馏”行为,防止对手绕过硬件限制并模仿先进的 AI 能力。 3. **强制性安全测试:** 要求所有高能力模型——无论其来源或架构如何——在发布前必须进行严谨的实证测试,以识别并减轻灾难性风险。 阿莫代坚持认为,虽然开源权重模型带来了独特的安全挑战,但应通过有针对性的监管和基于证据的测试来解决,而不是实行全行业禁令,从而确保 AI 创新在不损害全球安全的前提下继续发展。

Anthropic 近期关于“开放权重”模型的博文在 Hacker News 上引发了强烈反弹。首席执行官 Dario Amodei 认为,虽然他不赞成全面禁止,但美国政府应限制向“威权”政权出售芯片、抑制“工业级蒸馏”技术,并要求对所有具备足够能力的模型进行安全测试。 批评者大多认为这些提议是赤裸裸的“监管俘获”。评论区的主流观点是,Anthropic 正试图借国家安全之名,通过制造竞争壁垒来削弱开放权重竞争对手。许多用户指出,Anthropic 自己在训练模型时使用了海量抓取的知识产权,如今却反过来要求禁止“蒸馏”,这种行为极其虚伪。 此外,参与者还质疑了所谓的“安全”论调,认为安全护栏往往被用作限制强大工具的借口,而这些工具在网络安全防御中实际上是必不可少的。许多人指出,在近期的真实安全事件中,开放权重模型对防御者而言比受限的闭源模型更有用。这种广泛的舆论反映了人们对 Anthropic 动机的深切不信任,许多用户将该公司的立场解读为一种通过政府强制保护主义来捍卫其市场估值的绝望之举。
相关文章

原文

A post by Dario Amodei, Anthropic CEO

Over the last few days there has been a lot of discussion about open-weights models, especially those from China. Reports suggest that some US officials are considering banning the use of Chinese open-weights models by US companies. In response, many tech companies have signed a letter supporting open-weights models, and some people have even accused Anthropic of wanting to ban open-weights models as a means of protecting our business. Anyone who has read my past writing should know that I don’t regard such bans as a useful measure, but let me state it clearly so that there is no doubt: Anthropic has never advocated for a ban on open-weights models.

Open-weights models that don’t have dangerous capabilities are a public good: they don’t cost anything besides the compute needed to run them, and they provide value to businesses, developers, and researchers.

Protectionist bans would not address my most serious national security concerns. Specifically, I am worried about two nightmare scenarios. I laid these out in my essay The Adolescence of Technology six months ago1, and have held these positions consistently for many years:

  1. My primary concern is the risk that authoritarian governments—not solely the Chinese Communist Party (CCP), although the CCP is clearly the most capable threat—build AI models that are more powerful than those built by the US, and use them to achieve permanent military superiority or perpetrate incredibly deep repression of their own people. This concern is widely shared within the US government: Vice President Vance warned in Paris last year that “authoritarian regimes have stolen and used AI to strengthen their military, intelligence, and surveillance capabilities,” and the Intelligence Community’s 2026 Annual Threat Assessment found that “other global powers’ robust progress in AI is challenging US economic competitiveness and national security advantages.” It is irrelevant whether these models are released with open weights, and certainly irrelevant whether they are used by US businesses. In fact, the most dangerous model may be one that is trained in secret and handed only to the People’s Liberation Army for use in drones and the Ministry of State Security for surveillance and repression.
  2. My secondary concern is the risk that powerful AI models may be misused to carry out cyberattacks or biological attacks, and may have serious alignment problems. Open-weights models—it does not matter whether they come from China or anywhere else—do potentially present a higher risk than closed models, because it is very difficult to apply guardrails to them or monitor their usage, and once weights are released they cannot be withdrawn2. But banning the use of these models by US businesses does nothing to address this risk, because bad actors are unlikely to be legitimate US businesses. It would protect US AI companies from competition, but that has never been my goal.

To address these concerns, I do support the following three measures, which I and Anthropic have consistently advocated for:

  • We should not sell powerful chips or chipmaking equipment to China, and we should crack down on the rampant smuggling3 and workarounds used to obtain access to such chips. China has limited domestic production capacity, and therefore, due to the scaling laws, cannot build more powerful models than the US without US chips. This is the most efficient and direct way to block threat #1, and by hampering the training of models that are out of reach of US law, it also indirectly helps with threat #2.
  • We should crack down on industrial-scale distillation operations. Distillation is a much more compute-efficient process than training models from scratch. It allows China to build much better models than its number of chips would ordinarily enable, and thus partially evade chip bans. Distillation does not allow the CCP to obtain equivalent or superior AI capabilities to the US, but it can bring the Chinese frontier to within a few months of the US frontier. It is true that many of the companies carrying out these operations release open-weights models—but the open weights are far less relevant than the fact that the operations are backed by an authoritarian state seeking to overtake the US at the frontier. We should have policy interventions to deter this behavior. A blanket ban on open-weights models is neither the correct remedy nor something we have called for4.
  • All sufficiently capable models, open and closed, should go through mandatory safety testing. The best way to address threat #2 is to just directly test models for cyber, biological, and alignment risks before release. I think this idea is actually close to a consensus: I have been heartened both that the Trump administration has moved in this direction in recent months, and by recent industry proposals that would apply such testing to the most capable models regardless of their country of origin or whether they are open or closed (while exempting less capable models, such as those from startups and academia, entirely). Whether open models do or don’t pose an increased risk, and whether that risk can be mitigated, is something that should emerge from testing, rather than be decided in advance—and there may be promising methods for improving the safety of open-weights models, including recent research from Anthropic on modular training strategies. Note that to be effective, testing would need to be global, which means even the CCP would need to be on board. I think this may actually be possible: as I wrote in The Adolescence of Technology, limited cooperation around preventing AI biological weapons may be possible because it is in China’s interest too.

This brings me to the open letter. I agree with much of it: open weights expand access to the AI economy, they strengthen competition at least for some use cases, and they give customers greater control. Concerns about distillation should be addressed through targeted legal and commercial frameworks—the same measure I described above. But I don’t agree with the letter’s assertions that open-weights models necessarily make it easier to develop safeguards or that broad access to capabilities necessarily helps defenders more than attackers. It seems at least as likely to me that the opposite will be true. For example, I worry that biology will have a strong attacker-defender asymmetry, where sufficiently capable models may be able to quickly weaponize pandemic-level viruses with widely available materials, whereas defense against these agents is a multi-year operational task in the best case (as we saw with Operation Warp Speed)5. Questions like this should be empirically answered by rigorous pre-release testing, not assumed in advance.

To summarize my and Anthropic’s position, we have not and are not advocating for a ban on open-weights models as a category. We should instead focus on keeping powerful chips out of authoritarian hands, stopping industrial-scale distillation, and requiring safety testing of all sufficiently capable models, open and closed.

联系我们 contact @ memedata.com