Several AI companies, including Hugging Face, Meta, Microsoft, Mistral, and Nvidia, have signed an open letter urging policymakers not to impose broad “premature restrictions” on open weight AI models. The letter comes as the U.S. government debates how the United States should respond to allegations that Chinese AI labs are stealing intellectual property from U.S. AI labs to improve their capabilities.
The letter does not mention China at all, but it comes in the wake of reports that the Trump administration is considering a ban on Chinese indiscriminate models and possible sanctions against the country’s AI companies. The White House even accused Moonshot AI of extracting Anthropic’s Fable model to train the recently released and apparently very impressive Kimi K3 model.
The document appears to be aimed at discouraging outright bans on Chinese models and ensuring that the government’s response to the Chinese distillation scandal does not spill over into broader regulation of common technologies such as promiscuous AI and distillation.
“Policymakers must be careful not to confuse legitimate model development techniques with misappropriation. Distillation, the practice of using the output of one model to help train or improve another, is a widely used technique for improving, evaluating, and validating models. It reflects a long tradition of learning from, building on, and improving existing technology, and has helped drive innovation since the rise of the open source software movement.
In contrast, illegal efforts to extract value from closed models raise legitimate concerns. These concerns should be addressed through targeted legal and commercial frameworks rather than blanket restrictions on technologies that play a key role in AI innovation. ”
Or, as Replit CEO Amjad Massad (who also signed the letter) told TechCrunch, “I think banning China’s open model is just as good as banning open models in general.” He pointed out that Thinking Machine Labs’ new open model, Inkling, was trained with the help of Moonshot’s Kim 2.5. “This is an ecosystem, and the precedent[a ban would set]is bad.”
The letter also pushes back against industry arguments that open weight models are inherently dangerous because they expand access to powerful models that can be used for cyberattacks and other fraudulent activities without any oversight.
“The right response to this risk is not to ban open weights. In a world where cybersecurity attackers use advanced AI, defenders need access to models with comparable capabilities so they can detect, simulate, and respond to emerging threats,” the letter said. “An open model broadens our defense capabilities, increases transparency, and allows us to discover and remediate vulnerabilities across many teams.”
Last week, OpenAI revealed that while testing GPT-5.6 Sol and another unnamed model, one of its systems exploited a weakness in the test environment to access the Hugging Face repository containing solutions for coding benchmarks. Some might argue that the model’s purpose was not malicious and that it was effectively cheating on the test to get the highest score. But the incident has sparked a debate about the risks of concentrating advanced AI technology behind a small number of closed providers.
Hug Face said it was unable to protect itself from the attack because the guardrails in its commercially available Frontier AI model blocked the attack. The closed AI model used could not differentiate between being asked to build an exploit for an attacker or a defender trying to detect it. Instead, the company had to pivot to using GLM 5.2, a powerful promiscuous model from Chinese AI company Z.ai, to protect itself from attacks.
The letter highlights the rifts in the AI industry. Companies like OpenAI and Anthropic are calling on the administration to address allegations of intellectual property theft by Chinese AI companies as the capabilities of the open weight model rapidly grow. The results could have major implications for business models threatened by the proliferation of cheap, powerful, and accessible AI models.
These companies are notable in that they are not listed at the end of this letter, along with other closed-source AI developers such as Google DeepMind and SpaceX.
The signatories of this letter have a clear financial stake in the flourishing of open AI models. Companies like Nvidia, Microsoft Azure, and other infrastructure providers have a vested interest in driving a commoditized model. If the model were interchangeable, people would buy more GPUs, rent more cloud capacity, build more applications, and use more routing layers.
The letter encourages policymakers to expand access to computing for startups and researchers, invest in shared training assets such as datasets, tools, and evaluation frameworks, and “maintain frontier plurality by avoiding premature restrictions on open models that inhibit competition or drive innovation abroad.”
This article has been updated with comments from Replit CEO Amjadmasad.
If you buy through links in our articles, we may earn a small commission. This does not affect editorial independence.
