Home EconomyOpen Weights, Closed Ranks: The AI Manifesto War

Open Weights, Closed Ranks: The AI Manifesto War

by Staff Reporter
0 comments

The AI industry has entered its manifesto era. Executives, researchers, and employees are issuing rival plans to keep advanced models safe. The fine print contains a less advertised question: Would those plans protect the public—or protect today’s leaders from the open models gaining on them? 

That competition question starts with open-source AI models. These models make their source code, training methods, and trained parameters publicly available under a permissive license, allowing others to use and modify them. As Dirk Auer and I previously wrote, citing Susan Athey, then-chief antitrust economist at the U.S. Department of Justice (DOJ), a few strong open models may be enough to constrain proprietary large language models (LLMs): 

… it is important not to neglect the role that open-source models currently play in fostering innovation and competition. As former DOJ Chief Antitrust Economist Susan Athey pointed out in a recent interview, the AI industry “may be very concentrated, but if you have two or three high quality — and we have to find out what that means, but high enough quality — open models, then that could be enough to constrain the for-profit LLMs.” Open-source models are important because they allow innovative startups to build upon models already trained on large datasets—therefore entering the market without incurring that initial cost. Apparently, there is no lack of open-source models, since companies like xAI, Meta, and Google offer their AI models for free… 

The same reasoning applies to open-weight models. These models make their trained numerical parameters, or “weights,” freely available for download, even if their training data, full code, and methods remain private. The weights encode what a model has learned during training. 

Open-weight models allow startups to build AI products and services without bearing the substantial upfront training costs that well-resourced incumbents can more readily absorb. Open-source and open-weight models therefore offer one reason, among others, for optimism about competition in AI markets. 

That competitive role has made open-weight models a central target in the industry’s new manifesto war. Legitimate concerns about safety and potentially illegal conduct have prompted several private-sector regulatory proposals. The most concrete concern involves Chinese developers’ alleged large-scale distillation of proprietary models, a process in which one model learns from another model’s outputs. The proposals range from mandatory approval before release to targeted restrictions on open-weight and open-source development. 

As Kristian Stout has argued, such restrictions are more likely to create problems than solve them. This post examines the competitive consequences of the most prominent proposals. Several could distort an AI market that has proved more open and competitive than the prevailing regulatory narrative suggests. The manifestos promise safer AI. Their fine print may promise today’s leaders a safer market. 

Let a Thousand Manifestos Bloom

Google DeepMind CEO Demis Hassabis made the first move. He published a widely circulated Substack essay on July 14 calling for “urgent action” as developers approach artificial general intelligence (AGI), a still-hypothetical system capable of performing a broad range of intellectual tasks at or above human levels. Hassabis warned that increasingly autonomous AI systems could pose cybersecurity, nuclear, biological, and other risks. He proposed: 

…a new approach to testing frontier AI model capabilities that is dynamic, adaptable, and rigorous. The US is well positioned, given its economic and technical standing, to take the first step in developing such a framework. It could establish a new Standards Body modelled on a federally overseen public-private partnership or self-regulatory organisation, much like the Financial Industry Regulatory Authority (FINRA), with a board that includes independent leading technical experts and open-source representatives. Funding would need to be substantial and likely mostly come from industry, in order to attract world-class technical talent and provide the necessary compute resources for large-scale testing.

The Standards Body would be responsible for developing assessment protocols and working with appropriate federal agencies and the US National Labs to conduct testing in areas relevant to national security. A model would qualify as ‘Frontier-class’ if it meets certain thresholds on a set of benchmarks determined by the Standards Body and regularly updated to keep pace with evolving AI capabilities. Organisations with ‘Frontier Models’ as defined by those benchmarks would be deemed ‘Frontier Labs’, and be encouraged to adopt best practices, such as publishing model cards with technical details, maintaining strong internal cybersecurity, vetting key personnel, and providing sufficient resourcing for safety and security research, and more.

Hassabis’ proposal does not specifically target open-weight or open-source models. The Standards Body would evaluate frontier-class models “whether they are open or closed,” while exempting models from startups and academic researchers that fall below the frontier threshold.

Formal neutrality does not guarantee equal competitive effects. Even if the body applied its criteria evenhandedly—a considerable assumption when frontier labs would fund and staff it and exercise substantial influence over its benchmarks—the burdens would fall differently across the market. 

Frontier labs are, by definition, the current leaders. Chinese AI developers, U.S. firms that build on open weights and open-weight ecosystems, and other entrants are racing to catch them. Any mechanism that slows progress at the frontier gives an advantage to firms already ahead. It could also burden companies that build on open-source models and serve customers satisfied with models that fall just short of the latest capabilities. Many businesses and consumers need capable, affordable tools rather than the newest model money can buy. 

A model six months behind the frontier can still perform highly sophisticated tasks. Once regulators establish assessments for frontier models, “highly capable” models would present an inviting next target. Government efforts to control the pace of frontier development could thus impair the competition they purport to protect. 

Nvidia CEO Jensen Huang entered the debate on July 24 with an industry letter signed by 25 companies, including Meta, Microsoft, Google, and OpenAI. The letter defended open-weight models as essential to U.S. leadership in AI: 

Open weights expand access to the AI economy. Startups, established businesses, universities, and public institutions can build on advanced models without training one from scratch or paying frontier model prices for every task. Open weights let every organization match the right model to the right job at the right cost, reserving frontier-scale capability for genuine frontier problems and running efficient, specialized models everywhere else. That discipline is what will make AI economically sustainable as its use scales into the billions of everyday tasks. America wins the AI era by diffusing it into the workflows of factories, hospitals, farms, classrooms, and main street businesses.

Open weights also strengthen competition and competition is what keeps the gains of AI broadly shared rather than concentrated in a few hands. By allowing many organizations to build, adapt, and deploy advanced models, open weights create rivalry not only among model developers but across cloud chips, applications, and services. That competition spurs innovation, drives down costs, and distributes the benefits of AI broadly across our economy.

Anthropic CEO Dario Amodei outlined his position in a July 27 blog post. He stressed that “Anthropic has never advocated for a ban on open-weight models,” then called for mandatory safety testing of every sufficiently capable model and tighter controls on the computer chips and model-distillation techniques available to Chinese competitors. The proposal stopped short of a blanket ban on open weights, though only just short. 

Meta CEO Mark Zuckerberg answered on July 28 with a Wall Street Journal op-ed arguing that broadly distributed AI—or “personal superintelligence,” in his formulation—could prevent a few gatekeepers from concentrating power: 

It is surprising that the discourse from many of those who are developing artificial intelligence is so filled with doom. I don’t understand why anyone who believes that AI will eliminate most jobs and much of humanity’s relevance would rush to build that future. The notion that AI is so dangerous that the only safe path is an extreme concentration of power seems dangerous. Historically, hoping that an absolute power will benevolently provide for humanity if sufficiently enlightened hasn’t led to safe or positive outcomes. …

Rather than centralizing this power, we believe that delivering personal superintelligence to everyone is the way to answer this question [how to direct AI]. This has the potential to begin a new era of personal empowerment, in which individuals have greater freedom to pursue their interests and reach their full potential.

Zuckerberg later published an expanded version of the essay. 

More than 1,300 employees of OpenAI, Anthropic, Google DeepMind, Meta, and other frontier AI companies joined the fray on July 28. Their statement, “Pacing the Frontier,” asked the U.S. government to “support an international effort to develop the technical and governance tools needed to deliberately pace the frontier of automated AI development.” 

The signatories invoked a version of the prisoner’s dilemma, in which each participant’s individually rational choice produces a worse result for the group. They argued that “each company—and country—is under intense competitive pressure not to unilaterally slow that acceleration. And today, the world lacks the technical and governance tools to deliberately pace frontier-wide progress.” 

Axios called the exchange a “manifesto war.” The label fits. Most coverage has treated the dispute as a fight over AI safety, while paying far less attention to what these manifestos reveal about competition—or what their regulatory proposals would do to it. 

Baptists, Bootleggers, and Benchmarks  

The regulatory-economics literature offers a useful way to read the manifesto war. Bruce Yandle’s “Bootleggers and Baptists” theory holds that durable regulation often attracts two coalitions: “Baptists,” who support it for moral or public-interest reasons, and “bootleggers,” who stand to benefit financially. 

The theory does not assume bad faith. The Baptists may be entirely sincere, and those with a commercial stake in regulation may genuinely share their concerns. AI labs and their employees may honestly fear the risks they describe while supporting rules that also protect the labs’ commercial interests. Advocates of open weights have financial interests of their own. Yandle’s point is that regulation often protects the bootleggers more than the Baptists’ stated goals require. 

The safety concerns raised by the “Pacing the Frontier” signatories deserve serious consideration. These include recursively self-improving systems, which can enhance their own capabilities, and rogue systems that escape evaluation sandboxes, the isolated environments researchers use for testing. Governing systems that can accelerate their own development presents a real problem. The researchers raising these concerns include some of the field’s most technically capable people. 

This post does not question their sincerity. It asks whether the proposed regulatory frameworks would affect competition and investment beyond what their safety rationale requires—and whether those effects would predictably favor firms already at the frontier. 

The proposals’ timing also deserves attention. The “Pacing the Frontier” letter appeared during the same week that Moonshot AI—a Chinese startup that develops the Kimi family of AI models—released Kimi K3, an open-weight model that observers rated alongside the best publicly available frontier models of early 2026, at a fraction of their cost. The White House had disclosed days earlier that Moonshot allegedly built Kimi K3 by distilling Anthropic’s Fable model on an industrial scale, using export-controlled Nvidia hardware obtained through Thailand. 

Chinese open-weight models such as DeepSeek, Qwen, ERNIE, and Kimi have gone from marginal players to serious global competitors in less than two years. As I noted in a previous post, the performance gap between the best American and Chinese AI models has fallen to 2.7%, compared with 17.5 to 31.6 percentage points in May 2023, according to the Stanford AI Index 2026

Alibaba’s Qwen family has surpassed 700 million cumulative downloads on Hugging Face and produced more than 180,000 derivative models, making it the world’s most widely distributed open-source AI system. DeepSeek V4 Pro matches leading American models on most benchmarks for autonomous task performance while charging 97% less for its outputs than GPT-5.5. 

Open-weight models now pose a genuine threat to the proprietary frontier-lab business model, even though some frontier labs also release open-weight models. Proposals to slow development, restrict access, or impose compliance costs on all sufficiently capable models could weaken the competitive pressure facing the companies that support those proposals, regardless of their safety rationale. 

Self-regulation poses a particular risk. As the Organisation for Economic Co-operation and Development (OECD) has warned, it “may also lead to firms co-ordinating their activities and engaging in cartel-like behavior (e.g., price-fixing) and creating barriers to entry for new firms.” 

This analysis does not resolve the policy question. It does, however, suggest that policymakers should account for competitive effects before turning these manifestos into law. 

Pacing the Frontier, Protecting the Front-Runners

The “Pacing the Frontier” letter describes a prisoner’s dilemma: No company can safely slow down while its rivals race ahead, so restraint requires a government-backed international mechanism that makes compliance mutual and verifiable. While the argument has intuitive appeal, it simultaneously understates the private incentives that already push companies toward safety and overstates the need for regulation before a model’s release. 

Frontier AI companies already face substantial reputational, commercial, and legal consequences when their models cause harm. A company whose model escapes an evaluation environment, facilitates large-scale fraud, or causes a documented security breach risks losing customers and employees while inviting regulatory scrutiny and civil lawsuits. No new regulatory framework is needed to create those consequences. 

These constraints are real. OpenAI and Anthropic both recently disclosed incidents in which advanced models behaved unexpectedly during cybersecurity evaluations. Both companies investigated, disclosed, and addressed the incidents without a government mandate. As International Center for Law & Economics (ICLE) scholars have argued, strict-liability or product-liability rules that allow victims to recover for injuries caused by AI systems could strengthen these incentives without imposing the competitive costs of pre-release approval. 

The deeper problem with the manifesto war’s proposals is their poor fit with the harms they cite. As Kristian Stout has pointed out, the conduct that supposedly triggered the crisis—unauthorized distillation of proprietary models, smuggling export-controlled hardware, and fraudulently accessing application programming interfaces (APIs)—already violates existing law. 

Authorities can prosecute fraud and export-control violations. Intellectual-property and unfair-competition laws can address unauthorized distillation. If existing law already covers the alleged conduct, enforcement should target the harm and the wrongdoers directly rather than burdening an entire class of technology. Bad actors will not become law-abiding because regulators impose new compliance duties on legitimate developers. They will find other methods, while law-abiding firms bear the costs. 

Policymakers considering genuinely new regulatory tools should apply the OECD competition-assessment standard. They should ask whether less restrictive means could achieve the same safety objective and whether the proposed rules would create entry barriers beyond what that objective requires. The World Bank has identified regulatory barriers to entry as one of the principal ways governments inadvertently restrict competition. 

Sound AI governance can protect safety and competition at the same time. Each proposal should face three questions: Who bears the costs? Which harms does it address? And could a less restrictive alternative achieve the same result? The evidence supporting a rule should match the burden that rule would impose. 

Manifestos are cheap. Entry barriers are not.

You may also like

Leave a Comment

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Accept Read More