Microsoft, Nvidia, and Meta say restricting foreign 'open weight' models, whose internal settings are published, would cut US cybersecurity teams off from infrastructure they already rely on, with Chinese AI lab Moonshot's open weight Kimi K3 model
A Trump administration push to restrict foreign-made open-weight AI models on cybersecurity grounds has drawn a rare joint objection from Microsoft, Nvidia, Meta, and a roster of venture firms, who argue the move would undercut the very open ecosystem US developers and security researchers already treat as shared infrastructure. The dispute now has a concrete trigger: Moonshot AI's July release of Kimi K3, a Chinese open-weight model the company says matches or exceeds US frontier systems on its own evaluations.
"Open-weight" means the model's internal parameter settings, the values that shape how the AI behaves, are published for anyone to download, inspect, and modify. That is different from "open-source," a label whose meaning in AI is contested. The practical effect is that a security team, a startup, or a defense contractor can run an open-weight model on their own hardware without sending data to a vendor. Closed models from OpenAI, Anthropic, or Google run on the vendor's terms.
Kimi K3 is a 2.8-trillion-parameter model with a 1-million-token context window and native vision, released under an open-weight license in July 2026, according to Moonshot's launch blog and the model card on Hugging Face. Moonshot's claims of parity with US frontier models rest on its own evaluation suite and have not been independently corroborated. The release landed in the same window as National Security Technology Memorandum 4 (NSTM-4), the April 2026 White House policy document that frames the administration's AI security posture.
On July 24, a coalition of developers and investors including Microsoft, Nvidia, and Meta sent a public letter urging the administration to reconsider. The letter argued, as summarized by CNET, that the United States' AI leadership would be judged not by any single frontier model but by whether the country builds a strong, open ecosystem that spreads across every sector. A Yahoo/Axios report described an internal fight inside the administration over how to handle open-weight models from Chinese labs.
Per a recent Mozilla report cited by CNET, nearly 80% of developers use open models. Linda Griffin, Mozilla's vice president of global policy, put the practical stake in plain terms: "Open-weight models are everywhere in the industry already. So a world without them would hit a lot of people." The argument is that defenders already build detection, triage, and code-review tooling on top of open-weight models. Cutting supply at the import gate would force them onto domestic commercial alternatives that may be more expensive, less customizable, and subject to vendor-side change.
Administration-aligned voices have pushed the other way. Michael Kratsios, the White House's AI and crypto policy lead, posted on X defending the policy direction. David Sacks, the administration's AI czar, and Dean Ball have also weighed in, with Sacks's post and Ball's post signaling skepticism of unfettered open-weight release.
The strongest counterargument is also the simplest: weights can be downloaded, fine-tuned, and re-deployed. A security researcher or a malicious actor with the same file a defender uses can strip the alignment and produce a model tuned for offensive tasks. That is the case for narrower, supply-chain-style controls aimed at state-affiliated Chinese releases, rather than a blanket restriction on foreign open-weight models as a category. NSTM-4's specific restrictions on open-weight models have not been publicly detailed, and the draft rules reportedly under consideration are not finalized.
The rulemaking window is open now. The July 24 letter is the public ask; the question is what NSTM-4's implementing rules actually restrict, and whether the White House treats "foreign open-weight model" as a category to ban or as a supply-chain risk to manage.