anthropic

Amodei: open weights don't break the compute chokehold

Promtime

anthropic

Anthropic CEO Dario Amodei said open weights are "nowhere near a sufficient solution" to AI's concentration of power, because they shift that concentration toward whoever holds the most compute and chips. He made the argument during a public exchange on X with investor Gavin Baker, reported by Thenewstack.

At a glance

  • Amodei attributes the concentration to scaling laws rather than government policy, and argues that institutions at their best vest power in ideas rather than people, decentralizing it in the process.
  • Anthropic backed California's SB 53, which sets the frontier threshold at more than 10^26 training FLOPs and adds disclosure duties for developers earning more than $500 million a year.
  • Preliminary cyber testing by the U.S. Center for AI Standards and Innovation found Moonshot AI's Kimi K3 completing a full 32-step attack path against a simulated small corporate network in one of 10 attempts.

The dispute matters to anyone building on open models, because the practical question is not who publishes weights but who can afford to serve them at scale. Amodei's framing appears to move the debate from licensing to infrastructure, where rental costs and chip supply set the real ceiling. His tiered proposals also read as an attempt to keep regulatory pressure on the largest labs while leaving room for challengers.

Baker built his case on Zuckerberg's warning against extreme concentration

Gavin Baker, managing partner at Atreides Management, framed the debate as a choice between concentrating powerful models inside a few regulated companies or distributing them widely without the same guardrails. He quoted Meta CEO Mark Zuckerberg, who called the notion that AI is so dangerous that the only safe path is extreme concentration of power inherently problematic.

Baker argued that more models in circulation would spread power and improve the odds that people could use systems reflecting their values. He also said Amodei's repeated warnings about AI risk could strengthen opposition to new data centers. Amodei rejected the Silicon Valley shorthand equating regulation with regulatory capture.

Open weights let developers adapt a model and keep sensitive data inside their own environment, but that becomes harder as models grow. Smaller teams can rent hardware, yet stay exposed to its cost and availability, as five European companies showed by agreeing to buy AI compute that does not yet exist.

SB 53 draws the frontier line at 10^26 FLOPs and $500 million in revenue

Anthropic supported California's SB 53, which defines a frontier model as one trained using more than 10^26 floating-point operations. Developers earning more than $500 million a year face additional requirements, including publishing a framework that explains how they test for and respond to catastrophic risks.

We try very hard to make proposals that disadvantage (slow down) frontier AI companies while advantaging smaller competitors.

Amodei has called for the same distinction in federal policy, saying the testing process Anthropic has advocated at the Center for AI Standards and Innovation and the White House applies more rigorous tests to frontier models than off-frontier ones. He also supports Google DeepMind CEO Demis Hassabis' proposal for a FINRA-like standards body, which would classify models as frontier after crossing updated benchmark thresholds and apply the same rules to open and closed releases.

Kimi K3 scored zero arbitrary code executions across 41 ExploitBench samples

Anthropic was one of the few major AI labs that did not sign the July 24 letter organized by Nvidia, whose signatories argued that open weights encourage competition by giving customers an alternative to proprietary APIs. Amodei later said Anthropic does not support a blanket ban and called open models without dangerous capabilities a public good, though his position changes once a model can help someone carry out a serious attack.

The U.S. Center for AI Standards and Innovation found that Moonshot AI's Kimi K3 remained behind the strongest closed models in preliminary cyber evaluations. Kimi K3 failed to achieve arbitrary code execution on any of the 41 ExploitBench samples, while the most capable models achieved it on an average of 20 samples. DeepSeek's smaller model outperformed its own flagship, showing that model size alone is not a reliable measure of capability.

When a challenger crosses the threshold

Amodei wants models that reach dangerous capability levels to undergo mandatory safety testing regardless of how they are released, since once weights are public the developer cannot retrieve every copy or stop users from stripping safeguards. Training compute is a threshold developers can anticipate, but it may miss capabilities added through fine-tuning or external tools. Neither the exchange nor Anthropic's published proposals set a date for federal testing rules.

Comments

No comments yet. Be the first.

Join the conversation

Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.

We only use your name and avatar from Google. We never store your email address.