Open-weight AI rules should preserve access for smaller organizations

Washington should measure dangerous AI capabilities without making local model access a privilege reserved for the largest companies.

On July 24, an unusually broad group of technology companies published a letter defending open-weight AI. NVIDIA, Microsoft, Google, OpenAI, Meta, IBM, Amazon, Mozilla, Hugging Face, the Linux Foundation and more than a hundred other companies and organizations signed it. They argued that downloadable models give businesses more control, create competition and allow useful AI to reach people who cannot train a model from the beginning.1

Anthropic's name was missing. Three days later, CEO Dario Amodei published the company's position. He said Anthropic had never advocated a general ban and called open-weight models without dangerous capabilities a public good. He also argued that powerful downloadable models can create a lasting cyber or biological risk because their safeguards can be removed and the weights cannot be recalled after release.2

This debate followed reporting that the administration was considering restrictions on Chinese open-weight models. No federal ban has been enacted. A June executive order created classified cyber-capability benchmarks and a voluntary process for developers to give the government early access to certain frontier models. The order explicitly says it does not authorize mandatory licensing or preclearance for releasing a model.3

The policy question is whether Washington can test genuinely dangerous models without taking a local option away from people who cannot afford to train a frontier model or accept a single provider's terms.

What local access changes for a small organization

Open-weight means that the learned parameters of a model can be downloaded. Open weights are a narrower release than open source. The training data, training code and complete recipe may still be withheld, which limits reproduction and some forms of independent inspection.4

At McQueen Analytics, the choice changes with the work. We pay for access to frontier models, and we keep open-weight models running on our own hardware.

We use local models for work where the material should stay on our machine. Keeping an exact model version also lets us repeat a process without discovering that a provider changed the system between two runs. We can test a second opinion without sending the work through another company, and a product decision made somewhere else does not automatically end our ability to run that part of the process.

Owning the weights does not make a small company independent of everything else. The hardware is expensive. Electricity, storage and cooling are real costs. Good implementation still requires people who know what they are doing. Models arrive through software, model hubs and data pipelines that create their own supply-chain risk. For many jobs, a hosted frontier model remains the stronger and easier choice.

The White House's own 2025 AI Action Plan made a similar practical case. It said open-weight models can help startups avoid dependence on one closed provider, allow businesses and governments to keep sensitive data away from outside vendors and support academic research. The plan also recognized that access to compute remains beyond the budget of many startups and researchers.5

The strongest safety argument deserves a serious answer

Once capable model weights have been released, the developer cannot call every copy back. A person can remove refusal behavior, modify the model and use it privately. The monitoring, rate limits and patches available to a hosted provider may no longer reach that copy. Researchers at the United Kingdom's AI Security Institute describe open-weight systems as useful for research and competition while also being harder to supervise and able to spread irreversibly.6

That concern becomes much more serious when a model can carry out difficult cyber work or help someone move through the technical barriers to a biological attack. A policy that waits until after a dangerous model has been copied around the world has missed its useful window.

The recent joint U.K.-U.S. evaluation of Kimi K3 reports a concrete result. On July 23, the U.K. AI Security Institute and the U.S. Center for AI Standards and Innovation said the model's safeguards did not stop it from attempting offensive cyber work. In a simulated 32-step attack on a corporate network, Kimi K3 reached step 17 on average and completed the full attack in one of ten attempts. The most capable U.S. closed models reached an average of 28.5 steps and completed the exercise much more often.7

Kimi K3 remained behind the closed frontier on these tests and completed the simulated attack once. The work was preliminary, used a limited set of benchmarks and compared systems under different hosting constraints, so those caveats belong beside the result.

I would begin with the capability itself. Washington should name the cyber or biological task that justifies intervention, test for it and use the same threshold for a downloadable model and a hosted one.

More Americans are using AI while concerns remain high

Pew Research Center asked Americans about both chatbot use and their concerns about AI. Forty-nine percent of United States adults said they had used an AI chatbot, up from 33 percent in 2024, and 24 percent said they used one daily. At the same time, 63 percent said AI was advancing too quickly, 40 percent expected a negative effect on society and 71 percent believed wider AI use would make their personal information less secure.8

Our current AI Trust work at McQueen Analytics helps me interpret that combination. The program draws on four United States adult online-panel studies fielded from late May through June 12. We are still finishing claim review and population weighting, so I am not going to publish an early percentage or describe these results as national estimates.

My current read is that people can see useful AI and still expect choice, a responsible person, verification, disclosure, privacy, human review and a way to appeal. In the analysis we have completed, greater familiarity traveled with more specific expectations around those conditions.

Our survey never asked respondents to choose between open and closed model weights, so the bridge to model policy here is mine. My policy conclusion is narrower: a rule that leaves people with fewer choices, less ability to inspect a system and no practical alternative to several large providers needs evidence strong enough to justify that result.

Large businesses are already ahead in AI adoption

The United States Census Bureau reported in May that overall business use of AI was between 17 and 20 percent during the prior six months. Use reached 37 percent among firms with at least 250 employees and remained below 20 percent among businesses with four or fewer employees.9

Open weights will not close that gap by themselves. Small firms also need straightforward tools, people with the right skills, affordable compute and a reason to change a working process. Liability and integration can create a larger barrier than model price. The adoption gap still shows the starting position from which any new compliance burden will land.

I would ask a university lab or ten-person company what a proposed rule would cost before Washington adopts it. If meeting the rule requires the lawyers, safety staff and reporting operation of a frontier laboratory, it has excluded smaller developers before their models are tested.

Those developers still need to show what their models can do. Give them access to credible public tests, protected testing environments and independent evaluators. Set the threshold at a demonstrated dangerous capability, let a developer challenge a designation with technical evidence, and put a review date on it so a preliminary judgment does not become a permanent barrier.

The companies asking Washington to act have their own business interests

The coalition letter is advocacy by companies that sell chips, cloud capacity, models, software and services into a larger open-weight market. Anthropic's business is access to closed models.

Anthropic's federal filing reports $1.97 million in lobbying expense for the second quarter of 2026. It lists AI regulation and standards, export controls, distillation, national security, procurement and oversight among the issues discussed with Congress, the White House and federal departments. The filing does not disclose what position Anthropic urged on every issue, so it cannot prove that the company lobbied for an open-weight ban.10

Knowing those interests makes me look harder at the evidence. The Kimi evaluation is what I would use here because it measures capability directly. Claims about competition, safety and irreversible risk should face the same demand for evidence.

What I would ask Washington to prove

A restriction should arrive with evidence a developer can challenge. Washington should show the capability it found, explain enough of the test for outside technical reviewers to examine it and identify when the designation will be reviewed. A small organization that stays below that demonstrated threshold should not have to build the compliance operation of a frontier lab.

Accountability belongs to the action as well as the model. A developer owns the decision to release a model with a known dangerous capability, and someone who later modifies a general-purpose model to commit a crime owns that act. The line between those cases will sometimes be difficult, so Washington will need evidence instead of a rule that treats the size of the provider as proof.

AI is already inside people's work and daily lives. The research keeps bringing me back to responsibility, privacy, verification and recourse. For a company our size, keeping a useful model on hardware we control is part of that choice. We should be able to make it, and we should remain accountable for what we do with it.

Other reads on open-weight AI, safety and access

Source notes

  1. Open Weights and American AI Leadership, July 24, 2026, for the coalition's arguments and signatory list. The letter is an advocacy document by organizations with commercial and institutional interests in the outcome.
  2. Dario Amodei, Anthropic, July 27, 2026, for Anthropic's statement that it has not advocated a category ban, its description of non-dangerous open-weight models as a public good and its case for safety testing based on capability.
  3. Executive Order 14409, June 2, 2026, sections 3(a)-3(c), for the classified benchmarking process, voluntary early-access framework and explicit limitation on mandatory licensing, preclearance or permitting. Axios, July 20, 2026, reported the internal debate over possible restrictions on Chinese models. This article distinguishes that reporting from enacted policy.
  4. Open Source Initiative, Open Weights: not quite what you've been told, checked July 29, 2026, for the distinction between released weights and the broader code, data and freedoms required by the Open Source AI Definition.
  5. The White House, America's AI Action Plan, July 2025, pages 4-5, for the administration's stated benefits of open-source and open-weight AI for startups, sensitive data and academic research, and its recognition of compute-access limits.
  6. U.K. AI Security Institute, Open technical problems in open-weight AI model risk management, checked July 29, 2026, for the research summary on open testing, arbitrary modification, limited oversight and irreversible distribution. The page describes open technical questions rather than a settled regulatory answer.
  7. U.K. AI Security Institute and U.S. Center for AI Standards and Innovation, preliminary Kimi K3 cyber assessment, July 23, 2026, for the 32-step cyber range, comparative results, safeguard behavior and stated methodological limits. The assessment is preliminary and does not measure every form of model risk.
  8. Pew Research Center, Americans and AI 2026, June 17, 2026, based on a nationally representative survey of 5,119 U.S. adults conducted February 17-23, 2026. The article uses Pew for national estimates and keeps the McQueen Analytics directional work separate.
  9. U.S. Census Bureau, May 26, 2026, using Business Trends and Outlook Survey data collected from December 14, 2025 through May 3, 2026. The survey wording covers AI used in any business function and the estimates describe adoption, not trust or causal effects of open-weight access.
  10. Anthropic Q2 2026 Lobbying Disclosure Act filing, filed July 20, 2026, for the reported $1.97 million expense, issue areas and federal bodies contacted. The disclosure identifies broad subjects and does not establish the position Anthropic took on each one.

McQueen Analytics research note

McQueen Analytics' 2026 AI Trust work draws on four U.S. adult online-panel surveys fielded from late May through June 12. Claim review remains underway and final population weighting is incomplete. This article therefore uses only qualitative, directional findings and does not present the work as a nationally representative estimate. The surveys did not ask respondents about open-weight or closed-weight models; the connection to model-access policy is Carl McQueen's evidence-informed interpretation.

Previous post: Cash App's response to fraud should work when a customer needs it

Earlier AI trust read: the AI disclosure gap