Several AI companies, including Hugging Face, Meta, Microsoft, Mistral and Nvidia, have signed an open letter urging policymakers not to impose broad “premature restrictions” on open-weight AI models. The letter comes as Washington debates how the United States should respond to accusations that Chinese AI labs are stealing intellectual property from their American counterparts and
Several AI companies, including Hugging Face, Meta, Microsoft, Mistral and Nvidia, have signed an open letter urging policymakers not to impose broad “premature restrictions” on open-weight AI models. The letter comes as Washington debates how the United States should respond to accusations that Chinese AI labs are stealing intellectual property from their American counterparts and boosting their capabilities.
The letter does not mention China at all, but comes in the wake of reports that the Trump administration has been considering banning Chinese open-weight models and potentially issuing sanctions against the country’s artificial intelligence companies. The White House has even accused Moonshot AI of distilling Anthropic’s Fable model to train its recently released and, by all accounts, very impressive Kimi K3 model.
The letter appears to be aimed at discouraging an outright ban on Chinese models, as well as ensuring that the administration’s response to alleged Chinese distillation does not extend to broader restrictions on open-weight AI or common techniques like distillation:
Policymakers should be careful not to confuse legitimate model development techniques with misappropriation. Distillation, or the practice of using the results of one model to help train or improve another, is a widely used technique for model improvement, evaluation, and validation. It reflects a long tradition of learning, leveraging and improving existing technologies, a tradition that has helped drive innovation since the rise of the open source software movement.
In contrast, illegal efforts to extract value from closed models raise legitimate concerns. Those concerns should be addressed through specific legal and commercial frameworks rather than sweeping restrictions on techniques that play an important role in AI innovation.
Or as Amjad Masad, CEO of Replit (who also signed the letter), told TechCrunch: “I think banning Chinese open models is as good as banning open models in general.” He noted that Thinking Machines Lab’s new open model, Inkling, was trained with the help of Moonshot’s Kimi 2.5. “It is an ecosystem and the precedent [a ban would] The whole thing is bad.”
The letter also rejects industry arguments that open models are inherently dangerous because they expand access to powerful models, which can be used in cyberattacks or other nefarious activities, without any oversight.
“The correct response to this risk is not to ban open weights. In a world where cybersecurity attackers use advanced AI, defenders need access to models with comparable capabilities to be able to detect, simulate and respond to emerging threats,” the letter reads. “Open models expand defensive capabilities, increase transparency, and enable the discovery and remediation of vulnerabilities across many computers.”
Last week, OpenAI revealed that while testing GPT-5.6 Sol and another unnamed model, one of the systems exploited a weakness in its test environment to access a Hugging Face repository containing a fix for an encoding benchmark. One could argue that the model’s goal was not malicious and was effectively cheating on a test to get the highest score. But the incident sparked debate about the risks of concentrating advanced AI technology behind a handful of closed vendors.
Hugging Face said it was unable to defend against the attack with frontier AI business models because its security barriers blocked its efforts. The closed AI models it used couldn’t distinguish between being asked to create exploits for an attacker and a defender trying to detect them. Instead, the company had to resort to using Chinese artificial intelligence company Z.ai’s GLM 5.2, a powerful open weight model, to defend against the attack.
The letter highlights a divide in the AI industry. Companies like OpenAI and Anthropic have urged the administration to respond to alleged theft of intellectual property by Chinese AI companies as open models rapidly grow in capacity. The result could have important implications for their business models, which are threatened by the spread of cheap, highly capable and accessible AI models.
These companies, along with other closed-source AI developers like Google DeepMind and SpaceX, are notable by their absence at the end of this letter.
Those who signed the letter have an obvious economic interest in seeing open AI models flourish. Companies like Nvidia, Microsoft Azure, and other infrastructure providers have a vested interest in driving commoditized models: If the models are interchangeable, people will buy more GPUs, rent more cloud capacity, and build more applications.
The letter encourages policymakers to expand access to computing for startups and researchers; invest in shared training assets such as datasets, tools and evaluation frameworks; and “[keep] the plural frontier by avoiding premature restrictions on open models that stifle competition or drive innovation abroad.”
This article has been updated with comments from Amjad Masad, CEO of Replit.
When you buy through links in our articles, we may earn a small commission. This does not affect our editorial independence.
Keep following us for the latest insights.
















