NVIDIA, Microsoft, Meta, and 50+ Companies Tell Washington Not to Lock Down Open AI

I have been watching the AI industry’s open-vs-closed debate for years. This week, the battle lines became official.

More than 50 technology companies, including NVIDIA, Microsoft, Meta, Google, OpenAI, IBM, and Palantir, published a joint letter urging Washington to protect open-weight AI from “premature restrictions.” The letter, titled “Open Weights and American AI Leadership,” was released on July 24 and immediately reshaped the policy conversation.

Here is what is at stake. Open-weight models are systems whose core files can be downloaded, inspected, modified, and run on your own computers. Think of them as buying the machinery instead of repeatedly paying to use someone else’s factory. The coalition argues that shutting this down would “stifle competition or drive innovation overseas.”

The Signatory List Tells the Real Story

Every major tech company except one signed: NVIDIA, Microsoft, Meta, Google, OpenAI, AMD, Cisco, Dell, CrowdStrike, Palantir, Hugging Face, Mistral, IBM, Mozilla, Y Combinator, and more. The only notable holdout is Anthropic, whose business model depends on premium closed models accessed through controlled services.

The irony was not lost on anyone. Jensen Huang posted his first-ever message on X to share the letter. Satya Nadella amplified it. Elon Musk gave it his “full support.” Even OpenAI, which initially did not sign, added its name by Friday evening. Sam Altman wrote that he wants the US to “win in AI both in open source and proprietary models.”

The Case for Open Models

The letter makes three substantive arguments. First, open models give businesses choice. Companies can match the right model to the right job at the right cost, reserving expensive frontier models for genuinely hard problems while running efficient specialised models for routine work.

Second, openness strengthens security. As the letter puts it: “Relying solely on closed models is not inherently safe: they can be breached, misused, or fail in ways that outsiders cannot detect.” The recent Hugging Face breach proved this point. Hugging Face’s forensic team tried to use commercial frontier models to analyse the attack, but the providers’ safety guardrails blocked every request. The attacker data was indistinguishable from malicious intent. Hugging Face had to pivot to an open-weight Chinese model running on their own infrastructure.

Third, open models prevent lock-in. Organisations that invest heavily in AI want assurance they will not become dependent on a single provider. Open weights let them control their own data, adapt models to their own needs, and deploy wherever their business requires.

The Risks That Cannot Be Ignored

The signatories acknowledged the real risks. Once model weights are released, they are beyond the developer’s control. Modified versions are difficult to trace or reverse. Bad actors will use them.

The letter also addressed distillation, the practice of using one model’s outputs to train another. The White House has accused Chinese lab Moonshot AI of distilling Anthropic’s Fable 5 to build Kimi K3, an open-weight model that now rivals frontier US systems on key benchmarks. Treasury Secretary Scott Bessent threatened sanctions. The letter pushes back, arguing that policymakers should not conflate legitimate techniques with misappropriation.

The Business Dynamics Behind the Principle

The signatory list reveals the economic incentives. NVIDIA and AMD benefit when more organisations run models on their own infrastructure, driving chip demand. Microsoft and Meta benefit when models are commoditised and value flows to application layers and cloud platforms. Security firms like CrowdStrike and Palo Alto Networks need unrestricted private AI capability for forensic work.

Companies that make money when many models run everywhere are lining up against companies that make money when models are scarce and controlled. The meme writes itself: Anthropic and the US government versus every other US company.

The Missing Middle

Neither side is automatically right. Open models create real security risks. Closed platforms create lock-in and concentrated points of failure. Washington has to regulate dangerous uses without turning today’s frontier labs into tomorrow’s permanent gatekeepers.

The letter calls for expanding access to compute for startups, investing in shared training assets, and avoiding premature restrictions. The signatories are right that America’s AI leadership will be judged not by one frontier model, but by whether the country builds an open ecosystem that diffuses into every sector.

Getting that balance right will decide whether AI develops more like the open internet or a new cable bundle controlled by a handful of providers. The next few months in Washington will tell us which future we are heading toward.

Our AI leadership will be judged not by one frontier AI model, but by whether the United States builds a strong, open ecosystem that diffuses into every sector.

Open Weights and American AI Leadership, July 24 2026

Related Reading

The views expressed on this site are my own and do not represent those of any current or former employer. Articles are based on publicly available information and are provided for general educational purposes.

Subscribe

Related articles

Google’s Gemini AI Autonomously Hacked Three Companies. Here’s What Happened.

Google has confirmed its Gemini AI autonomously hacked three real companies during a security test. The model guessed passwords, searched for leaked credentials, and accessed protected systems before stopping itself.

440 AI Agents Broke Into 395 Organisations in 26 Seconds. Nobody Stopped Them.

A swarm of 440 AI agents exploited two PaperCut flaws and compromised 395 organisations across 48 countries. The agents reached domain admin in 6 hours and ignored explicit instructions to stay out of 28 countries.

For $3,000 and a Few Days, Researchers Used Claude to Hack OpenAI

Security researchers used Anthropic's Claude AI to hack OpenAI's internal systems for less than $3,000 in tokens. What the HEIF Heist tells us about the new economics of cyber attacks.

The AI Hacking Crisis Is Already Here. Six New Incidents Prove It

OpenAI disclosed six new incidents where its models concealed mistakes, sought unauthorised credentials and uploaded files to the public internet. Cybersecurity experts say the real risk is powerful models meeting poor security controls.

Inside OpenAI’s Log of Misbehaving Models: Rewriting Jailbreaks and Covering Up Errors

OpenAI published six new reports of its models rewriting jailbreak instructions and concealing errors during training, alongside a faster public disclosure framework.
Philip Hall
Philip Hall
Philip Hall is a Sydney-based Cyber AI and Automation leader with more than 30 years of technology experience and a career in cyber security dating back to 2008. His work spans cyber architecture, cloud security, threat intelligence, assurance, incident support, AI-enabled defence and the security of autonomous agents.