logoalt Hacker News

Our position on open-weights models

555 pointsby surprisetalkyesterday at 10:03 PM785 commentsview on HN

Comments

asawfofortoday at 2:05 AM

Is there a market for distillation as a service? I see Google just added one for Gemini: https://docs.cloud.google.com/gemini-enterprise-agent-platfo...

show 1 reply
pianopatrickyesterday at 10:43 PM

I don't really see the link between use of AI and military superiority.

My current understanding is a lot of current US military problems are due to rare earths supply chains.

I don't see how AI would either help or hurt with that.

show 3 replies
jjcmyesterday at 11:33 PM

> > All sufficiently capable models, open and closed, should go through mandatory safety testing.

The problem with this is the cycles required to abliterate a model is significantly less than the cycles required to train a model.

This is the biggest reason why I'm against locking these models down / preventing their use. It's just delaying things by ~3-6mo, while in the process preventing legitimate use and adding red tape overhead.

syntaxingyesterday at 10:24 PM

> Open-weights models that don’t have dangerous capabilities are a public good.

Who decides what is dangerous and what isn’t? Lawmakers usually have the say but Anthropic can easily bribe… I mean lobby them to favor your viewpoint.

bgdkbtvyesterday at 10:29 PM

I wish we had a good LLM developer toolset that is not Anthropic or OpenAI with sensible business and ethical practices and good performance.

Can't wait for local on machine LLMs that are on par with Opus/Fable.

credit_guytoday at 12:22 AM

I know it's unpopular, or unfashionable, but I agree with this letter.

LLMs are becoming so powerful that they are dangerous. We've seen last week with the OpenAI hacking (by mistake) Hugging Face debacle.

It is absolutely ok to have open weight models at the level of GPT-OSS-100B. That one was released one year ago, and I think it's still a strong one. GLM 5.2 is a whole new level, but it appears to still be safe. Maybe Kimi K3 will be ok too. But beyond that, things will start being dicey.

It's easy to dismiss this and claim that Dario Amodei is just looking to fatten his pockets. And, sure, if Anthropic manages to put the brakes on open weight models, that reduces the competitive pressure it feels. But that does not make what Amodei's argument incorrect.

show 2 replies
kelvinjps10yesterday at 10:58 PM

Basically we shouldn’t ban open-weights models but we shouldn’t allow them to become as good as the frontier models because china bad. And let’s not have someone else be able to produce a frontier model.

>We should not sell powerful chips or chipmaking equipment to China, and we should crack down on the rampant smuggling3 and workarounds used to obtain access to such chips. China has limited domestic production capacity, and therefore, due to the scaling laws, cannot build more powerful models than the US without US chips. This is the most efficient and direct way to block threat #1, and by hampering the training of models that are out of reach of US law, it also indirectly helps with threat #

We should crack down on industrial-scale distillation operations. Distillation is a much more compute-efficient process than training models from scratch. It allows China to build much better models than its number of chips would ordinarily enable, and thus partially evade chip bans. Distillation does not allow the CCP to obtain equivalent or superior AI capabilities to the US, but it can bring the Chinese frontier to within a few months of the US frontier

2.

show 2 replies
arthurlockmanyesterday at 11:30 PM

It's so convenient that the US government already classified China as "authoritarian". If they hadn't, Dario would have to say “it’s a risk that other people build models more powerful than us”. I have to wonder what his response would be if for instance a lab in France or Germany came out with an open-weight model this good.

andixyesterday at 11:45 PM

China doesn't seem to think that powerful open weight models are a serious threat to them. Otherwise they wouldn't release them. Those models could also be used by their enemies against China.

I'm not a fan of the Chinese political system, but they usually think things through, and do smart things for their benefit.

show 1 reply
nevestoday at 1:53 AM

"bad actors are unlikely to be legitimate US businesses"

I think he lives in a different word than me

dwa3592yesterday at 10:42 PM

Dario, as your unpaid therapist I would tell you that models are a commodity and you are having a hard time coming to terms with it. You are doing everything except accepting it. It's a common defense mechanism, but as your unpaid therapist, i will tell you that it's not going to work. Your company will cease to exist or exist like how ferrari or buggati exist.

_jabyesterday at 10:59 PM

A bit off-topic from the core of the post, but:

> At Anthropic we’re committed to cracking down on industrial-scale distillation through our own practices, including identifying and banning accounts that use our models in this way. This is challenging—for instance, the relevant accounts can often only be identified after substantial distillation has occurred, and distillation often involves creating large numbers of fake accounts that form a moving target. The practices of any individual company cannot entirely solve the problem, which is why we have called for policy on this issue.

One thing I've never really understood is what sort of policy could possibly deter or hamper Chinese labs' distillation efforts. The only thing I can imagine is some sort of strict KYC regulation applied to all models above a certain threshold, which seems both painful for the broader US AI ecosystem and bound to fail anyways.

show 1 reply
iamdamianyesterday at 10:53 PM

I'm curious if he's also in favor of banning biology books.

cdnstevetoday at 2:48 AM

I'm no longer supporting this vendor, for personal or business

Anoianyesterday at 10:43 PM

"Nobody has the intention to build a wall" - Walter Ulbricht, June 1961, 2 months before building the berlin wall.

storustoday at 12:33 AM

The speech he had at congress didn't sound very flattering towards the beginning of his today's statement:

https://www.youtube.com/watch?v=_i91NSOyxHM

He didn't mention outright banning open source LLMs, just that their safe release would be a much harder problem, which to me implied "the easiest way is to ban the open source models".

tonyriceyesterday at 11:46 PM

>We should not sell powerful chips or chipmaking equipment to China, and we should crack down on the rampant smuggling3 and workarounds used to obtain access to such chips. China has limited domestic production capacity, and therefore, due to the scaling laws, cannot build more powerful models than the US without US chips. This is the most efficient and direct way to block threat #1, and by hampering the training of models that are out of reach of US law, it also indirectly helps with threat #2.

If hardware becomes affordable for the masses, then Anthropic current business model is at risk.

show 1 reply
para_paroluyesterday at 10:21 PM

As expected they will try hard to use government to kill competitors.

show 2 replies
alerighiyesterday at 11:59 PM

To be fair, as an European, I'm now more concerned about the usage of AI that the US will be doing rather than China. And this is a sentiment shared among most European people that I know.

mnmingtoday at 2:43 AM

Hmmm, how could this post be possibly a good thing for Anthropic?

novaleaftoday at 12:12 AM

Frontier models can hack you, we should have access to tools assisting defense.

I ranted about this in a prior thread [1]

Claude doesn't have a "Security whitelist" for small biz. Codex does, but they never replied to my application. This is a great example why, as of today, everyone NEEDS access to the Open Weight models.

[1]: https://news.ycombinator.com/item?id=49035303#49040674

fookeryesterday at 11:21 PM

Anthropic's fall from grace and mindshare seems rather accelerated.

I wonder if these rapid movements are going to be the norm now. I imagine there would be angry investors if this sort of thing happened with a public company.

htlemur_bobbytoday at 12:46 AM

Guys if we want safety we need to work with people, not make enemy of CCP. Geez this is extremely frustrating to see enemies being made. USA leads in torture and our prisons are worse than CCP prisons so USA is the worse issue. I recommend Anthropocene stop fundraising and do the right thing which is open source all.

mej10yesterday at 11:15 PM

It is obviously not going to be until some really bad series of cyberattacks or a chemical/bioweapon attack before anyone takes regulation of models seriously.

They are _obviously_ (please convince me otherwise) going to be capable of carrying these terrible things out almost completely autonomously at some point in the near future, in potentially clever ways. Therefore we must, at some point, ban or heavily regulate them. Seems we should start figuring that shit out _now_, as progress has remained very fast and regulation and enforcement take forever on these time scales.

show 2 replies
K0balttoday at 12:04 AM

Sure, if you’re going to sell an open-weight model over API in the USA it should refuse certain things.

Defensive cybersecurity should not be one of them, in fact, it should be required to provide defensive cybersecurity assistance on demand. Anthropic and OpenAI both fail miserably at assisting US companies to protect themselves from cyberattack.

As far as what I run on my own, not for sale over API, stay off of my lawn.

caxaptoday at 12:49 AM

I think unsafety, distillation, and China catching up in chipmaking are inevitable.

Just like how it was inevitable for SoTA LLMs to ignore copyright.

The actual challenge isn't how to prevent all these, but how stay on top.

And to stay on top it is inevitable to train unrestricted models. Anthropic is fighting windmills.

doolstoday at 2:32 AM

Americans don’t get to lecture the world on authoritarianism anymore

aprentictoday at 12:05 AM

I'm curious how he would propose implementing this.

The US could ban connections to foreign AI providers and force US providers to submit to audits. Presumably, Chinese providers would see a rise in VPN traffic.

People can build fairly hefty home inference machines for the price of a small car and those will get better and cheaper. Are they going to try to stop people from downloading the weight files?

himata4113yesterday at 10:44 PM

Demand #1 weakens america and everyone around them

Demand #2 Why does this matter? The answer was that it does not. (https://news.ycombinator.com/item?id=49007610)

Demand #3 This doesn't exist. You cannot have 'safe' opensource models, it's simply impossible. You can always post train sufficiently capable models to become 'unsafe'. The flip side of that is that sufficiently capable models are banned therefore it is a ban on open intelligence completely defeating the point of this entire manifesto.

nullbiotoday at 2:37 AM

"Open-weights models that don’t have dangerous capabilities are a public good"

Read between the lines folks. Anthropic deems every model that has frontier capabilities as "dangerous", and thus they are against them. We all know that "dangerous" simply means "whatever model hurts our bottom line."

More dishonest framing from the company that constantly lies to everyone. No surprises here.

edumucelliyesterday at 10:32 PM

We distilled all the proprietary material into our token-based money making machine that is more expensive on every new release, but "we should crack down on industrial-scale distillation operations".

hdaz0017today at 12:23 AM

$3m - $4m does not get that much these days

https://finance.yahoo.com/technology/ai/articles/anthropic-n...

alach11yesterday at 10:53 PM

What does cracking down on distillation look like in practice? I imagine data retention would be a part of the strategy, like we saw with Fable?

It seems really hard to allow usage via API and prevent distillation. Maybe limiting usage to within a specific harness would help a bit more. But ultimately the only way to prevent it is by locking down models to trusted entities (like with Glasswing). But then the profit potential of a model is significantly reduced. It really puts the labs in a bind.

noutyesterday at 11:54 PM

Oh wow, that's a pretty strong request to ban open-weight models by choking them with review processes where who-knows-who defines what is ok in a model and what is not. After open weight model is released, it will take how long to review it? And why does that align exactly with the timeline of the next Anthropic model release?

lukewarm707yesterday at 11:49 PM

dario, most of the world wants CHINA to win because the USA is the bad guy.

you should be worried about the USA having these models.

orbital-decaytoday at 12:45 AM

>or perpetrate incredibly deep repression of their own people

Oh, so it's people he is now concerned with. Think of the people, says the person that grabs to never give back. Same as the "benefit of all humanity".

Schnitzyesterday at 11:20 PM

If distillation leads to a model that is much cheaper to run yet provides similar intelligence then why doesn’t Anthropic distill their own models?

show 1 reply
tonyriceyesterday at 11:45 PM

Imagine regulating a programming language. I remember when Delphi, Vb6, .net, etc was used often to create Remote Access Trojans and viruses were widespread. Companies didn't compete to ban other languages. Crime is crime. What would regulating open-weight models do for people that actually intend on using these tools for crime ?

tedgghyesterday at 10:36 PM

What’s blocking Anthropic from fighting Chinese companies abusing their services? Why go nuclear against all open weight models? Testing and compliance is technically banning.

locusofselfyesterday at 10:58 PM

The gap between China's chip manufacturing capabilities and the USA's is only going to shrink, right? ASML obeys some export controls for their most sophisticated machines, but those machines are in China's backyard (Taiwan).

Taiwan manufactures the world's most advanced chips. CCP wants "re-unification" with Taiwan. AI may be THE key to world dominance. These are scary times.

pyrophaneyesterday at 11:42 PM

What would it mean to crack down on distillation? I could think of a few possibilities:

1. Using political pressure to target companies that are accused of doing it.

2. Attempting to impose criminal penalties on individuals associated with the action.

3. Having the US government attempt to use its capabilities to stop it.

None of these seem particularly likely to succeed.

dnwyesterday at 11:52 PM

> Open-weights models—it does not matter whether they come from China or anywhere else—do potentially present a higher risk than closed models

I don’t think this is open or closed; this is aligned and unaligned. I bet Grok would be as open as any open weight models to answering questions.

Catloafdevyesterday at 11:37 PM

It's absolutely reasonable to have safeguards on sufficiently dangerous models being released - if you disagree, can you explain your perspective?

I think it's wildly irresponsible to release models that are extremely capable at things like bio-weapons. Do you really think information anarchy is the answer?

The problem with open models compared to closed models is not about protecting profit - it's about protecting capability. Any open model can be retrained or fine-tuned for anything. There's no such thing as an open model that is both capable _and_ permanently safe when it comes to certain dangerous topics. It's not possible to prevent 'uncensoring' a model.

show 1 reply
nativeittoday at 2:25 AM

The consent factory has never been more productive.

zkmontoday at 12:54 AM

The core concerns stated as use of AI in drones and surveillance, by China. And what does USA government do with AI? Drawing pictures of flowers and writing novels?

firasdyesterday at 10:28 PM

Dario has like three 'paranoias' / strong-motivating-concerns

1) LLMs turning into Skynet

2) China as geopolitical competitor

3) Claude being 'distilled' by competitors (this has led Anthropic to cut service to various American companies too from time to time -- OpenAI, xAI etc have been cut off from using Claude for coding in the past)

So this post just reiterates that these 3 concerns fuse together in his mind when thinking about open weight models

show 1 reply
buzzin__yesterday at 10:35 PM

He says that using the set of questions and answers from one model to train another model (deatilation) is cheaper than training the model without those datasets.

But he didn't mention that training any model from a set of texts and books is much cheaper than writing those books in the first place.

In other words, it's ok when Anthropic learns from others, but it is not ok when others learn from Anthropic.

show 1 reply
seatac76yesterday at 11:38 PM

Dario thinks of policy as if the Berlin Wall fell yesterday, he is so detached from the reality of the world.

The way the world economy is right now with coercion being the norm between countries, there cannot be a global body for anything, certainly not one that is based here in the US.

🔗 View 50 more comments