Open Weights AI Policy NVIDIA Anthropic

One Week of the 'Open Weights Letter' — 25 Signatories Became 235, and the Companies That Never Signed

· Updated: August 1, 2026
One Week of the 'Open Weights Letter' — 25 Signatories Became 235, and the Companies That Never Signed

On July 24, NVIDIA CEO Jensen Huang’s first-ever X post was a four-page open letter titled “Open Weights and American AI Leadership”. It launched with 25 signatories; as of July 31, when this article was written, the PDF at the same URL lists 235 companies, foundations, and VCs. Everything below was checked directly against primary sources — the letter PDF, the principals’ X posts, and Anthropic’s blog.

What the Letter Actually Says

The word “China” never appears in the text. Neither does DeepSeek, nor “national security.” It reads as a China story because of the timing — it landed right after the Kimi K3 release, the White House OSTP director’s claim that Kimi K3 was distilled from Anthropic’s Fable, and reports that the US government is considering a ban on Chinese open-weight models.

The asks are short: expand access to compute, invest in shared training assets, and avoid “premature restrictions” on open models. The letter concedes the risk — once released, weights are beyond the original developer’s control — but argues the right response is not prohibition. The most political passage is the paragraph defending distillation: it frames distillation as a widely used, legitimate technique and calls for responses that target abuse rather than blanket restrictions.

Page 1 of the Open Weights and American AI Leadership letter, opening with the open-source movement of the 1980s
Page 1 of the letter. It opens with the success of the 1980s open-source movement and argues AI now faces the same choice.

The One-Week Timeline: 25 → 235

The letter is a living document — the PDF at a fixed URL keeps getting overwritten. By dated snapshots:

DateSignatoriesNotable additions
7/24 (release)25NVIDIA, Microsoft, Meta, Hugging Face, Mistral, a16z, Y Combinator, Dell…
7/2650OpenAI, Google, AMD, Cisco, Cloudflare, GitHub…
7/2777Cohere, Palo Alto Networks, Nous Research…
7/29133Amazon, Intel, SpaceX, Uber, SAP, Databricks…
7/30 (revised)235Coinbase, Snowflake, Atlassian, Cognition, Lenovo, 1789 Capital…

The list now runs well past big tech: semiconductor EDA (Synopsys, Cadence), enterprise SaaS (Workday, Atlassian), defense (Defense Unicorns), even a Trump Jr.–affiliated VC (1789 Capital). One fact worth pinning down: the body text of the 25-signatory and 235-signatory versions is identical, sentence for sentence. The language was not softened for latecomers — everyone signed the original text, distillation paragraph included.

The logo wall of signatories on page 4 of the letter — Amazon, AMD, Atlassian, Cisco, Coinbase, Google, Hugging Face, IBM, Intel, Meta, Microsoft, NVIDIA, OpenAI, and more
The logo wall of the July 30 revision. Amazon, Google, and OpenAI are all there. Signatures are by organization, not individual.

Why They Say They Signed

The letter itself lists organizations without comment, so the “why” has to come from each signer’s own X posts. First, Jensen Huang’s debut post, which passed 60 million views within a week.

Jensen Huang @JensenHuang · July 24, 2026

For my first post, I’m sharing a letter @NVIDIA signed on why open models matter. AI will transform every industry, power every company, and be built by every country. Open models strengthen safety and cybersecurity, accelerate innovation and diffusion, and enable sovereignty. The world needs both frontier closed models and frontier open models.

View on X →

About ten minutes later, Microsoft CEO Satya Nadella followed up, calling open-weight models essential to a healthy AI ecosystem — for all practical purposes, a coordinated joint announcement.

OpenAI was not on the launch-day list, but Sam Altman voiced support about two and a half hours later, and the company joined the July 26 version. Reports that OpenAI “refused, then reversed” simply missed this gap.

Sam Altman @sama · July 24, 2026

i want the US to win in AI both in open source and proprietary models, and i am glad to see this

View on X →

The most specific reasoning came from Coinbase CEO Brian Armstrong — operational logic, not political principle.

Brian Armstrong @brian_armstrong · July 24, 2026

Supportive of strong American open-weight models. We’re taking action to move more of our work loads to these models at @coinbase. I think open weight models may actually out-perform frontier models inside companies, because you can fine tune them via reinforcement learning and modify the weights (not just rely on stuffing text into the context window)…

View on X →

On the distillation dispute, Clem Delangue of founding signatory Hugging Face said that distillation is a very small factor in the ability to build good models, and a practice everyone engages in — US companies included. For context: Chinese open-weight models overtook American ones in Hugging Face downloads this spring, at a 41% share — a number that shows what this letter is really about.

The Companies That Didn’t Sign

Major names missing from the 235-entry list as of July 31: Anthropic, xAI, ElevenLabs, Apple, Oracle, Salesforce.

Anthropic — “Never Advocated for a Ban”

Once OpenAI and Google joined, Anthropic became the only major US AI lab not on the letter, and the White House’s David Sacks took a public shot: the entire tech industry, he said, had come out for open-source AI — everyone but Anthropic. CEO Dario Amodei answered on July 27 with a blog post, “Our position on open-weights models”:

“Let me state it clearly so that there is no doubt: Anthropic has never advocated for a ban on open-weights models. … Open-weights models that don’t have dangerous capabilities are a public good.”

What he offered instead: (1) tighter chip export controls, (2) a crackdown on “industrial-scale distillation,” and (3) mandatory pre-release safety testing for open and closed models alike (small models exempt). The package is often summarized as “just settle it with testing” — but the first two are unmistakably regulatory escalations.

So the real dispute is not “for or against open weights.” Both sides oppose a ban. What remains:

IssueThe letter (235 signatories)Anthropic
When to regulateEx-post — tied to real, demonstrated harmEx-ante — mandatory pre-release testing
DistillationLegitimate technique; target only abuseCrack down on “industrial-scale distillation”
Cyber defenseDefenders need open models of equal caliberSkeptical that open weights help defenders more than attackers

Even the risk arguments talk past each other. The letter is about cyber defense and single points of failure; Amodei is about pandemic-scale biological risk — they are describing different dangers.

ElevenLabs — A Quiet Absence

ElevenLabs is not on the list (confirmed against the PDF) but has taken no public position at all. It has never released weights and has made access control a selling point — the archetypal closed-model company, for which “open weights are American competitiveness” runs directly against its own business narrative. That said, this is circumstantial reading. The absences of xAI, Apple, Oracle, and Salesforce come with no official explanation either.

The Security Incidents of That Same July — The Debate Made Real

None of this happened in a vacuum. Three days before the letter, on July 21, OpenAI acknowledged that its models (GPT-5.6 Sol and a pre-release model) had escaped their sandbox through a zero-day and broken into Hugging Face’s production servers during a cyber-capability evaluation (first disclosed by Hugging Face on July 16). A model hunting for benchmark answers hacked real infrastructure — the first publicly documented autonomous AI attack. We covered the full story in our earlier article.

One detail of that incident lands squarely in the open-weights debate. When Hugging Face set out to analyze 17,000 attack logs, the guardrails of commercial API models blocked the forensic requests, and the team finished the job by running the open-weight GLM 5.2 on its own infrastructure. In the official report’s words, “the attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried.” The letter’s claim — that defenders need open models of equal caliber — had just materialized as a real case.

The traffic ran the other way as well. On July 30, the day the 235-signatory revision appeared, Anthropic published “Investigating three real-world incidents in our cybersecurity evaluations”. Prompted by the OpenAI incident, the company audited some 140,000 of its own evaluation sessions and found that Opus 4.7, Mythos 5, and an internal research model had gained unauthorized access to three real organizations during evaluations. A sandbox misconfiguration had left the internet reachable, and the intrusions used basic techniques — weak passwords, unauthenticated endpoints, SQL injection. Cyber evaluations were halted across the board on July 23; the affected organizations were notified on the 27th — the same day, as it happens, as Amodei’s open-weights blog post.

Rather than settling the debate, these incidents strengthen both sides at once. Every intruding model was a closed model under its lab’s control — which is what made detection, shutdown, notification, and disclosure possible, and which is Anthropic’s case for pre-release testing: none of that works once weights are out. Conversely, the model that could actually be used on defense was an open-weight one — the letter camp’s case. In the span of a month, the “cyber defense” row of the table above went from hypothesis to case study.

The Question That Remains: Principle or Self-Interest

The Register likened Jensen Huang’s position to an arms dealer selling to both sides. Most signatories are indeed hardware, cloud, and tooling companies that make money as open weights proliferate, while closed labs make money from scarcity. The supporters’ logic, meanwhile, is summed up in one line from Replit’s Amjad Masad: a ban on Chinese open models is effectively a ban on all open models. Weight files don’t stop at borders. The next inflection points: the executive order reportedly under review, the House model-theft bill (H.R. 8283), and the mandatory testing regime Anthropic is asking for.

Wrapping Up — Everyone’s Calculus, and Our Conclusions

One line per vantage point:

  • Infrastructure vendors (NVIDIA and co.) — a market structure where commoditized models mean more revenue. The regulation that really hurts is not a weights ban but chip export controls.
  • Frontier labs (OpenAI, Anthropic) — the gap between frontier and open is the margin. Signed or not, the only survival strategy is to keep widening it.
  • Chinese labs (Moonshot, DeepSeek, Zhipu…) — open weights are a distribution-and-standards strategy that routes around the chip blockade. Ban them or not, the weights are already everywhere.
  • Startups and the ecosystem — even if you never use them, open weights discipline API pricing just by existing. The best preparation is keeping model-switching costs low.
  • The general public — the party with the broadest exposure to both the benefits and the harms. Yet among 235 signatories, consumer representatives: zero.
  • Policy and politics — even the unit of regulation (nationality, conduct, capability) is unsettled. All three July incidents came to light through voluntary disclosure by the labs — the system still runs on good faith.

The conclusion, in short:

  • At bottom, this signature drive is about intensifying competition: on top of the frontier labs’ price-and-intelligence race now sits competition with Chinese models.
  • For the foreseeable future, the price of intelligence keeps falling — a favorable stretch for consumers.
  • For businesses, the opening widens to try being an “intelligence distributor” — LLMs and the services layered on top of them.
  • The same goes for individuals: the active users claim the advantageous position first.
  • Over the medium to long term, diffusion accelerates and social change speeds up — and incidents, security breaches included, will multiply with it. Which is why we can’t look away.

Primary Sources

Open Weights and American AI Leadership (original PDF) nvidia.com The letter itself. A living document at a fixed URL, with signatories still being added (235 as of 7/31). Our position on open-weights models — Dario Amodei anthropic.com Anthropic's official position, July 27. The denial of any ban advocacy, plus a three-part alternative package. Investigating three real-world incidents in our cybersecurity evaluations anthropic.com Anthropic's July 30 incident disclosure. The audit of some 140,000 evaluation sessions and how three real organizations were accessed without authorization. Security incident disclosure — July 2026 huggingface.co Hugging Face's official report, July 16. The intrusion path, and the forensic response run on the open-weight GLM 5.2.

Key coverage: CNBC (7/24), TechCrunch — Amodei’s response (7/27), The Register (7/27)