Dario Amodei says he never called for a ban. The memo's structure does the work of one, and tilts the field toward the labs that already run the evaluations.
Last week, Dario Amodei published a position paper insisting he has 'never advocated for a ban on open-weights models' (Anthropic memo). Within the same document he drew a line that does the structural work of one: open-weight models are a 'public good,' he wrote, only when they 'don't have dangerous capabilities.' The asterisks arrive right after the headline. So does the question they raise: who decides which open models cross that line, and which labs already own the infrastructure to prove it?
"Open-weight" describes AI models whose parameters are publicly downloadable, as opposed to accessed only through an API. A US and possibly EU regulatory regime around frontier AI is being shaped right now, and Amodei's memo is part of the conversation. The rules it sets will determine who can train, release, and deploy the next generation of models. The reader should understand that this is not an abstract safety debate.
The strongest substantive critique of the memo is structural rather than personal. The Polish AI blog Janilowski frames it as an evaluation asymmetry (Janilowski): Anthropic controls Claude's safeguards, but open models must be evaluated under their worst plausible modification, because users can strip built-in restrictions. Closed models can be patched in place when a safeguard fails. Open models must be designed to survive stripping. Identical nominal tests are not actually equivalent.
The strongest counterargument, raised on Hacker News, is that Amodei's actual proposals exempt smaller models (HN thread). If the regime's load-bearing tests only apply above a compute or capability threshold, the policy debate shifts from the current memo text to the regulatory direction of travel: where the threshold lands, who sets it, and who audits the auditor. That is the question the memo does not answer, and the one the next round of rulemaking will.
Two recent news events put pressure on the memo's stated neutrality. The New York Times reported, per Implicator's summary, that OpenAI and Anthropic privately lobbied Washington regulators to restrict Chinese open-weight AI models, with US officials more likely to review individual Chinese models as national security cases than impose a blanket ban (Implicator). An industry letter defending open weights drew 32 signatories. OpenAI signed on Friday, and Anthropic is the only major US frontier lab not on the published list.
TechCrunch's July 27 report on Amodei's response captured the public version of the rationale: he does not oppose open-weight models, but fears Chinese AI (TechCrunch). The fear is on the record. The mechanism by which "fear of Chinese AI" produces a US domestic compliance regime that disadvantages university labs, startups, and open-weight communities is the part the memo leaves implicit.
That mechanism is what the critique names a compliance moat. A safety regime built around pre-release evaluation, continuous monitoring, identity verification, and revocable access is structurally cheaper for the company that already runs the largest compliance, legal, and evaluation operation. It is structurally hostile to a university lab, startup, or open-weight community that does not. A community fine-tuning a 7B model on a single rented cluster cannot staff a dedicated red team, file continuous monitoring telemetry, or absorb the legal cost of identity verification at scale. The fixed cost of compliance is roughly the same whether you are a frontier lab or a weekend project. The point is not that any single rule is illegitimate. The point is that a regime whose costs scale with the size of the safety operation is a regime whose winners are predictable.
The next test is whether the rulemaking that emerges from Washington and Brussels writes the threshold as a hard capability cutoff or as a process regime. A hard cutoff can be measured. A process regime hands the keys to whoever runs the largest evaluation shop. Watch for the first draft of the EU AI Act's third-tier obligations, and for the first US frontier-model bill that names an evaluation vendor.