他提出三项实际措施:对华芯片出口管制、打击工业级知识蒸馏、对所有足够强大的模型进行强制性安全测试。 Amodei 指出,保护主义禁令无法解决其最担忧的国家安全威胁,包括威权政府利用更强大 AI 实现军事优势或深度监控。
丹尼奥·阿莫迪 (Dario Amodei),Anthropic 首席执行官发布的帖子
在过去几天里,关于开源权重模型(尤其是中国的模型)有很多讨论。有报道称,一些美国官员正在考虑禁止:https://www.axios.com/2026/07/20/ai-us-china-open-source-kimi 美国公司使用中国的开源权重模型。作为回应,许多科技公司签署了一封支持开源权重模型的信:https://x.com/JensenHuang/status/2080643682408321103,有些人甚至指责 Anthropic 想通过禁止开源权重模型来保护我们的业务。任何读过我过往文章的人都应该知道,我并不认为这种禁令是有效的措施,但让我明确表述,以消除任何疑问:Anthropic 从未倡导禁止开源权重模型。
没有危险能力的开源权重模型是一种公共资源:除了运行它们所需的计算资源外,它们不花费其他费用,并且为企业、开发者和研究人员提供价值。
保护主义禁令无法解决我最严重的国家安全担忧。具体来说,我担心两种噩梦般的情景。我在六个月前的文章《技术的青春期》:https://darioamodei.com/essay/the-adolescence-of-technology 中阐述了这些情景,并且多年来一直持有这些观点:
为了解决这些担忧,我确实支持以下三项措施,我和 Anthropic 一直在倡导这些措施:
这让我想到了公开信:https://images.nvidia.com/pdf/Open-Weights-and-American-AI-Leadership.pdf。我同意信中的许多观点:开放权重扩大了AI经济的可及性,它们在某些用例中至少能增强竞争力,并且给予客户更大的控制权。关于蒸馏的担忧应通过有针对性的法律和商业框架来解决——这与我上面描述的措施相同。但我不同意信中关于开放权重模型必然能更容易开发安全措施,或者广泛获取能力必然对防御者有利而非攻击者的说法。在我看来,情况至少同样可能相反。例如,我担心生物学领域会存在明显的攻防不对称性,足够强大的模型可能能够利用广泛可得的材料快速武器化大流行级病毒,而对这些病原体的防御即便在最佳情况下也需要多年的操作(正如我们在“疾速行动”中看到的)5。像这样的问题应该通过严格的发布前测试来实证回答,而不是事先假设。
总结一下我和Anthropic的立场,我们既没有也不支持对开放权重模型作为一类进行禁令。我们应该关注的是防止强大芯片落入极权国家之手,阻止工业规模的蒸馏,并要求对所有足够强大的模型(无论开放还是封闭)进行安全测试。
Opus 5是Opus系列的一次飞跃式改进,为运行长时间任务的代理提供动力,同时在编码和专业工作上带来提升。
我们正在分享Anthropic经济未来研究基金的研究议程。
A post by Dario Amodei, Anthropic CEO
Over the last few days there has been a lot of discussion about open-weights models, especially those from China. Reports suggest that some US officials are considering banning:https://www.axios.com/2026/07/20/ai-us-china-open-source-kimi the use of Chinese open-weights models by US companies. In response, many tech companies have signed a letter:https://x.com/JensenHuang/status/2080643682408321103 supporting open-weights models, and some people have even accused Anthropic of wanting to ban open-weights models as a means of protecting our business. Anyone who has read my past writing should know that I don’t regard such bans as a useful measure, but let me state it clearly so that there is no doubt: Anthropic has never advocated for a ban on open-weights models.
Open-weights models that don’t have dangerous capabilities are a public good: they don’t cost anything besides the compute needed to run them, and they provide value to businesses, developers, and researchers.
Protectionist bans would not address my most serious national security concerns. Specifically, I am worried about two nightmare scenarios. I laid these out in my essay The Adolescence of Technology :https://darioamodei.com/essay/the-adolescence-of-technology six months ago 1 , and have held these positions consistently for many years:
To address these concerns, I do support the following three measures, which I and Anthropic have consistently advocated for:
This brings me to the open letter:https://images.nvidia.com/pdf/Open-Weights-and-American-AI-Leadership.pdf. I agree with much of it: open weights expand access to the AI economy, they strengthen competition at least for some use cases, and they give customers greater control. Concerns about distillation should be addressed through targeted legal and commercial frameworks—the same measure I described above. But I don’t agree with the letter’s assertions that open-weights models necessarily make it easier to develop safeguards or that broad access to capabilities necessarily helps defenders more than attackers. It seems at least as likely to me that the opposite will be true. For example, I worry that biology will have a strong attacker-defender asymmetry, where sufficiently capable models may be able to quickly weaponize pandemic-level viruses with widely available materials, whereas defense against these agents is a multi-year operational task in the best case (as we saw with Operation Warp Speed) 5 . Questions like this should be empirically answered by rigorous pre-release testing, not assumed in advance.
To summarize my and Anthropic’s position, we have not and are not advocating for a ban on open-weights models as a category. We should instead focus on keeping powerful chips out of authoritarian hands, stopping industrial-scale distillation, and requiring safety testing of all sufficiently capable models, open and closed.
Opus 5 is a step change improvement for the Opus tier powering long-running agents while delivering improvements in coding and professional work.
We’re sharing the research agenda for the Anthropic Economic Futures Research Fund.