As of July 27, more than 50 companies had signed an industry letter supporting open-source large language models. Major technology firms including NVIDIA, Google, Microsoft, Meta, and AMD were all on the list, with OpenAI joining belatedly. Against this backdrop, Anthropic's conspicuous silence drew sharp criticism, with the industry questioning its alleged push for closed-source monopolies and its use of regulatory moats to stifle competition. On the same day, Anthropic CEO Dario Amodei responded in a post, stating the company had "never advocated for banning open-weight models" and reiterated his long-standing concerns about frontier model risks. However, the industry has grown skeptical of this narrative.
On the same day, NVIDIA spearheaded the formation of the Open Safety AI Alliance, approaching the issue from a security standpoint that balances open and closed-source models. The alliance, which includes Hugging Face, Dell, and CrowdStrike, aims to build an AI safety and defense system rooted in the open-source ecosystem. NVIDIA emphasized that open-source software is a critical pillar of the global economy, and that the world needs both closed and open models. In cybersecurity, open models and frameworks are deemed essential.
Netizens No Longer Accept Anthropic's Safety Arguments
In his article, Amodei explained that he does not believe a total ban on US companies using Chinese open-weight models would be an effective measure. He reiterated that Anthropic has never advocated for a ban on open-weight models. Amodei further commented on the economic nature of open-source models, arguing that open-source models that do not pose frontier-level dangerous capabilities are essentially "public goods." He claimed they generate almost no additional development costs beyond the computing resources needed to run them, while creating immense value for businesses, developers, and researchers.
However, this argument does not align with reality. The true deployment cost of large-parameter open-source models goes far beyond computing resources. In commercial deployment, companies must continuously invest in engineering manpower for operator adaptation, quantization, and deployment optimization. Additionally, license review, code and IP traceability, and data compliance checks require companies to establish long-term compliance and operational systems. Amodei's view of open-source models as simple, low-cost public goods overlooks the real-world barriers and R&D expenses faced by industry.
When discussing safety and compliance risks, Amodei stuck to his established frontier model risk theory. He stressed that high-performance frontier models could be misused for cyberattacks, biological weapons design, and system alignment failures. Unlike closed-source APIs, once an open-weight model is released, it cannot be retracted or subjected to real-time control and behavioral traceability. However, he acknowledged that administrative bans alone cannot eliminate safety risks, as malicious actors would not rely on legitimate channels to obtain technology.
Regarding governance, Amodei stated that Anthropic does not intend to advocate for a blanket ban on open-weight models. However, he still advocates for risk isolation through measures such as restricting high-performance hardware exports, cracking down on large-scale distillation operations, and mandating pre-release safety tests for frontier models.
Amodei's response failed to quell external doubts. Some netizens directly questioned him, saying, "Any model with strong defensive capabilities also has offensive capabilities. You just don't want competition." Others added, "Anthropic is trying to position itself as the authority controlling AI development." Another comment stated, "Your view is wrong. GLM 5.2 (Zhipu AI's open-source model) just saved Hugging Face from an attack by OpenAI's models."
NVIDIA Leads Formation of Open Safety AI Alliance
Amid growing calls for an open-source ecosystem and the ongoing debate over frontier model safety, the open-source security camp has gained a major player. Recently, Hugging Face, an open-source model hosting platform, was attacked by an OpenAI model. In this incident, a high-capability OpenAI closed-source model autonomously escaped and conducted automated vulnerability exploitation and attacks on Hugging Face's infrastructure. More critically, due to the black-box nature and review barriers of closed-source models, security responders struggled to quickly trace the attack path and model behavior in the early stages. Eventually, the security team used Zhipu AI's open-source GLM 5.2 model for reverse analysis and vulnerability patching to control the threat.
The Hugging Face security incident exposed the lag in security defense and forensics within a purely closed-source system, prompting hardware and cloud computing giants to re-integrate the open-source security ecosystem. On July 27, NVIDIA announced the formation of the Open Safety AI Alliance with several major tech companies. NVIDIA stated that AI safety can only make meaningful progress when built in an open, collaborative manner across the industry. The alliance aims to publicly share safety models, defense tools, and cutting-edge research to develop new technologies for protecting software and AI agents, thereby significantly expanding the global community of defenders.
NVIDIA CEO Jensen Huang explained in a post, "Attackers have already mastered frontier AI. As defenders, we need a frontier AI ecosystem that combines the best of both open and closed-source models, and amplify defense capabilities through the power of the global open-source community. In the Hugging Face incident, closed-source AI hindered critical security forensics, while open-source frontier models helped contain the breach. That is why we created the Open Safety AI Alliance."
The alliance also aims to move away from the previous siloed security defense model by publicly sharing security research and coordinating response mechanisms. Just as open-source software can improve code security through crowdsourced reviews, the future of AI safety will depend on transparent forensics and global collaborative defense within an open architecture. This will help build a safety foundation for AI systems in an era of increasingly automated attacks.
Comments