TL;DR: Roughly 24 organisations have put their names to an open letter asking American lawmakers to leave open-weight AI models unrestricted. The list runs from Meta and Microsoft through chipmakers and infrastructure firms — Nvidia, IBM, Dell — to Palantir, ServiceNow, CrowdStrike, Perplexity, Hugging Face, Mistral, Mozilla, the Linux Foundation, and investors including Y Combinator and Andreessen Horowitz.

An open-weight model is one whose trained parameters are published, so anybody can pull them down, examine them, alter them and run them on hardware they control. Frontier products from OpenAI and Anthropic work the other way: available through an API, with the parameters themselves never leaving the provider.

Economically, the signatories make three claims. Publishing weights lowers the barrier for smaller firms and public institutions that could never train a frontier model or absorb frontier token prices on routine tasks. It intensifies competition at every layer, silicon upwards. And it gives enterprise buyers a route around lock-in, since running a model yourself means keeping your data and tuning to your own needs without waiting on a supplier’s roadmap.

An inverted security argument

The section on risk is the one worth reading closely, because it grants the objection first. Published weights cannot be withdrawn. Derivative versions are hard to track. Somebody can strip the safety behaviour out and redistribute the result, and no recall mechanism exists.

Prohibition is still the wrong response, the letter argues, by analogy with cybersecurity: those defending networks against AI-driven attacks need equally capable models to spot and rehearse threats, which gated systems will not readily give them. It extends the point, holding that closed systems carry their own exposure — they can be compromised or misused, and they fail in ways nobody outside can inspect — so herding capability behind a handful of providers concentrates fragility instead of reducing it.

This is the decades-old case for open-source security applied to models. As the source observes, no AI-specific vulnerability or incident data accompanies it.

Follow the incentives

The commercial logic behind some signatures is not hidden. Firms selling chips, servers and infrastructure profit whenever more usable models exist, whoever trained them. No legislative text is attached; this is groundwork ahead of anticipated policy activity in Washington, asking for wider compute access, public funding for shared datasets and evaluation tooling, and restraint on early restrictions.

Looking forward

The letter also carves out distillation — using one model’s outputs to train another — as legitimate research practice distinct from unlawfully extracting value from closed systems, a boundary that became contentious after DeepSeek and Kimi emerged. UK procurement teams choosing between self-hosted open models and API access should treat the surrounding policy as unsettled: constraints on either open releases or distillation could rewrite self-hosting economics within one legislative cycle.