Remember when OpenAI actually called itself “Open”? It was a simpler time, before “open” became a semantic battlefield where companies spend more time arguing about the definition of a word than actually releasing code. Anthropic has now joined the fray with a position paper on open-weights models that reads less like a technical manifesto and more like a legal disclaimer for their business model. It is a calculated attempt to redefine the terminology of the industry to suit their specific brand of closed-door development.

The argument rests on the idea that “open weights” is a misnomer because it doesn’t include the training data or the full training code. This is a pedantic hill to die on. For the developer who just wants to avoid a monthly subscription or the latency of a congested API endpoint, the weights are the only thing that matters. (The semantic gymnastics are truly impressive). If you can load the tensors into VRAM and run an inference loop, the model is effectively open for the purposes of utility. To argue otherwise is to pretend that the “source code” of a neural network is the dataset, which is like saying the source code of a cake is the wheat field it came from. You can’t realistically expect a lab to release a multi-terabyte dataset of proprietary or scraped data, so using that omission to disqualify the “openness” of the weights is a hollow gesture.

Then we get to the safety angle, which is where the prose gets really thick. Anthropic claims that releasing weights allows bad actors to remove safety filters, creating a “dual-use” risk. This is the standard corporate boogeyman. It’s the same logic used by pharmaceutical companies that keep their formulas secret under the guise of preventing “misuse,” while actually just protecting a patent. Does the theoretical risk of a rogue agent outweigh the benefit of a thousand developers optimizing a model for local use or auditing it for bias? Probably not, but it’s a great way to justify a closed ecosystem to a board of directors and a nervous set of investors.

We also have to talk about the hardware friction. Let’s be real: the gap between a “leaked” weight and a usable local model is massive. Most of us are staring at 24GB of VRAM on a 3090 or 4090, while these frontier models require a small data center just to breathe. The “safety” risk is a nice talking point for the press, but the real friction is the cost of compute. Anthropic knows that as long as the hardware floor remains high, their API is the only viable path for 99% of users. They aren’t protecting the world from a super-intelligence; they are protecting their margins from the inevitable day when quantization makes frontier models run efficiently on a MacBook.

Do they really believe that the world is safer when a handful of companies hold all the intelligence in a black box? (I suspect not). By framing the debate around “responsible release,” they are attempting to move the goalposts. They want the prestige of being the “ethical” lab while maintaining a moat that would make a medieval king jealous. It is a strategic pivot disguised as an ethical one, and it smells like a preemptive strike against the rising tide of Llama and Mistral. For a while, the “closed for safety” argument worked because the performance gap between closed and open models was a canyon. Now that open-weights models are nipping at the heels of the frontier, the safety argument is starting to look like a convenient excuse for a lack of a distribution strategy.

They are just stalling for time. By Q4, we will see another “safety” update that conveniently aligns with a new enterprise pricing tier or a restrictive new set of API limits.

A transparent attempt to gatekeep intelligence.