
Follow ZDNET: Add us as a preferred source on Google.
ZDNET's key takeaways
- The conflict between open and closed large language models is on.
- Open weights and open source are not the same, but open weights are the future.
- On the proprietary side are Anthropic and OpenAI; on the other, most everyone else.
The open-weight Moonshot AI's Kimi K3 is faster than Anthropic Fable 5 in some ways, and is nearly as fast as Fable 5 and OpenAI's GPT-5.6 in others. That's fast. And that has some American AI companies and the Trump administration worried.
Michael Kratsios, Trump's director of the Office of Science and Technology Policy, has claimed that "Moonshot AI distilled Anthropic's Fable for the development of its K3." In short, he's suggesting that China's Moonshot stole from Anthropic. That's not how everyone sees it. Many US AI companies see Moonshot's open-weight methods as perfectly legitimate.
Also: AI Model Release Tracker
You might think it would be simple -- good guys versus bad guys -- but it's not. Even Kratsios admitted, "Legitimate AI distillation used to create smaller, more efficient models plays a vital role in this open innovation ecosystem." But, he added, "large-scale, covert industrial distillation aimed at stealing proprietary US technology and undermining American research is unacceptable."
Are they really, though? The difference between illegitimate and legal uses of other models is paper-thin. It largely depends on where you sit. All AI models have been built on top of other models, and their data comes from essentially everything and anything their builders can grab.
Microsoft and a host of tech giants support open weights
So, immediately after the Kimi K3 kerfuffle surfaced, Microsoft released its new "Open Weights and American AI Leadership" policy statement. It defines open-weight models as systems anyone can download, inspect, modify, and run on their own infrastructure. As Microsoft and its allies, which include Amazon, Nvidia, Google, and a host of other tech giants, see it, the use of open weights is a net good for everyone, including US AI giants.
They aren't the only ones. Almost 200 Silicon Valley start-ups, the Little Tech Association, have urged the Trump administration not to limit access to Chinese open-source models.
Also: Why AI tokens will send your enterprise cloud bill sky-high again
Microsoft's statement does a better job than most industry letters of tying open weights to actual economics. It argues that open models let startups, universities, hospitals, factories, and public institutions match the right model to the right job without paying frontier-model prices for every task. This makes AI economically sustainable for everyone. For now, we're still living at a time when frontier AI is comparatively cheap. That won't be the case much longer. AI pricing will explode by year's end. Open weights are the only way forward to affordable AI.
The Redmond giant also makes a security case that's easy to miss if you stop at the headline. Microsoft says open weights can help defenders simulate attacks, find security holes, and improve models through broader testing, rather than relying on proprietary systems. That's always been one of the arguments for open source. Indeed, Linus's law declared "given enough eyeballs, all bugs are shallow." Now, instead of human eyeballs, we have AI models hunting bugs faster than people ever managed.
In a Wall Street Journal editorial, Meta CEO Mark Zuckerberg acknowledged that "In most cases, like cybersecurity, the history of open-source software has shown that giving everyone full access to powerful systems will be the best way to protect safety and security over time."
Also: Is open source the answer to rogue AI agents? Nvidia's new alliance says yes
Backing this up, Nvidia's brand-new Open Secure AI Alliance "will work to remediate and disclose vulnerabilities using open technologies." As Nvidia put it, "Some argue that open models are inherently less safe because they can be misused for cyberattacks or modified to remove guardrails. Those risks are real, but they do not disappear in closed systems, and simply keeping weights closed does not prevent determined attackers from seeking or exploiting powerful AI."
China, of course, is all about open weights. China's leader Xi Jinping recently said, "AI development should not be a solo performance by a single country but a symphony of global collaboration." Open-source is a "rare and historical opportunity" to spread AI's benefits worldwide.
The difference between open weights and open source
However, open weights are not open source. The difference between open-source AI and weights, according to the Open Source Initiative (OSI), is that open weights usually means the trained weights are available, but not necessarily the full training data or source code. The two terms are frequently conflated.
The OSI itself declared, "Every AI system in the headlines today, whether proprietary or open source, exists because researchers shared their work openly." Without open source, there is no AI.
Also: How AI has suddenly become much more useful to open-source developers
That said, as Stefano Maffulli, former head of the OSI and Grist Labs chief revenue officer, pointed out on LinkedIn, "Full open source AI, as in its definition, would be better. I'd settle for open weights at this point and continue pushing for data transparency, protecting those who disclose their ingredients and release the weights freely."
I know this. You should know this. And the companies supporting open weights, whether they're building them in the US, Canada, the EU, or China, know this too. Indeed, Nvidia CEO Jensen Huang's first-ever tweet supported Microsoft's AI position. He was far from alone. Elon Musk, Google CEO Sundar Pichai, and Zuckerberg all have publicly supported the open position.
The strategic conflict
For Washington, the message is clear: Open weights are being recast as part of American industrial policy. The coalition is asking policymakers not to impose premature restrictions on downloadable models or to confuse legitimate techniques like distillation with misappropriation. That is a direct challenge to any move that would use China as the reason to lock down model distribution more broadly.
Also: Canonical's approach to AI is refreshingly thoughtful - Microsoft should take note
The bigger story is that open weights have become the language through which a large slice of the AI industry talks about competition. The open-source movement promised and delivered on shared infrastructure and broader innovation. The Microsoft coalition is arguing that the same logic now applies to AI, even if the result is not "open source" in the strictest sense. That makes the fight less about idealism than about who gets to shape the next layer of the AI stack.
OpenAI and Anthropic: The proprietary opposition
Now, both Anthropic and OpenAI state that they support open source. Their actions say otherwise. For example, Anthropic is the one US AI powerhouse that hasn't signed the open-weight policy statement.
Also: Is your AI model secretly poisoned? 3 warning signs
Anthropic CEO Dario Amodei is trying to thread the open-weight needle by underlining in a blog post, "Anthropic has never advocated for a ban on open-weight models." However, he emphasized, his "primary concern is the risk that authoritarian governments -- not solely the Chinese Communist Party (CCP), although the CCP is clearly the most capable threat -- build AI models that are more powerful than those built by the US, and use them to achieve permanent military superiority or perpetrate incredibly deep repression of their own people."
He also argued that "We should crack down on industrial-scale distillation operations" and demanded that "sufficiently capable models, open and closed, should go through mandatory safety testing."
The problem with these arguments is that there's nothing about the Chinese models that makes them uniquely dangerous. The same could be said of any AI models. Many people are worried sick about all AI models. AI attacks are already common; Anthropic's Claude AI shared chats were shared with anyone who could do a Google search; and recently, OpenAI AI models attacked a Hugging Face model. There's nothing "safe" about anyone's AI.
OpenAI didn't sign the document immediately, but it finally got on board. That said, OpenAI executives have been partnering with the Trump administration to require mandatory security evaluations of new AI programs. It's hard to imagine a Chinese model passing such an inspection.
Also: Claude AI shared chats indexed by Google - see if your conversations were exposed
Ot a higher level, what we have here is a conflict between those who support open models and those who want a more closed approach. This is not a philosophical argument over "open versus closed." No, it's a fight over who benefits from openness, and who gets to define safety.
Anthropic and OpenAI's future relies on their expensive, proprietary models beating open-weight models. If cheaper open-weight models deliver similar performance, then both are in a world of trouble. Microsoft and the rest, however, already have successful cloud-based businesses. For them, open-weight AI means more customers coming to them for the infrastructure to run anyone's models.









English (US) ·