Nvidia’s Open-Weights Letter Exposes the Anthropic Google Divide as OpenAI Joins
Nvidia recruited 24 other organizations to defend open-weight AI, while Anthropic and Google stayed outside the original coalition. The split arrived as Washington considered restrictions on downloadable Chinese models. It places the Anthropic Google position opposite an infrastructure industry that benefits when customers can run models wherever they choose.
Nvidia published the three-page letter on July 24, 2026. Microsoft, Meta, IBM, Dell Technologies, Palantir, Hugging Face, and venture firms joined the initial group. The coalition asked policymakers to avoid premature restrictions that could suppress competition or move development overseas.
There is already an important update. OpenAI was absent when the initial 25-company list was reported, but its name now appears in Nvidia’s hosted document. The file also contains additional signatories, although it provides no visible revision history explaining when each organization joined.
That change makes the remaining absences more revealing. Anthropic and Google have not joined the current list, while OpenAI now backs language favoring downloadable models. The policy contest is no longer a simple fight between open-model suppliers and every major closed-model laboratory.
The central divide concerns control. Open-weight developers let customers download trained parameters and operate models on private infrastructure. Closed-model providers generally retain those parameters and deliver intelligence through managed services or programming interfaces.
Washington must decide whether access to weights strengthens American competition or creates security risks that cannot be reversed. Nvidia’s coalition argues that restricting the technology would concentrate influence among a few providers. Critics counter that downloaded models can lose safeguards and become difficult to monitor.
The Coalition Grew After Its First Public Appearance
The original 25-company announcement became a moving document within hours, weakening claims based only on its first signatory list.
Nvidia CEO Jensen Huang promoted the letter through his first post on X. The initial open-weights report identified 25 organizations and highlighted three missing companies: OpenAI, Anthropic, and Google.
The initial signers represented nearly every layer below the leading closed-model laboratories. Nvidia supplies AI processors and software. Dell sells servers, while Microsoft operates cloud infrastructure and distributes models through several products.
IBM, ServiceNow, Box, Palantir, and Replit build enterprise applications or development tools. CrowdStrike and other security firms work on defensive systems. Andreessen Horowitz, Y Combinator, and Emergence Capital finance companies that need affordable access to models.
Meta, Mistral, Black Forest Labs, Arcee AI, and Reflection brought the model-developer perspective. These companies already distribute model weights, so the letter supports their established release strategy. Hugging Face and the Linux Foundation provide infrastructure and governance around downloadable software and models.
The coalition’s composition is commercially coherent. Chipmakers benefit when more organizations operate their own models. Server vendors benefit when inference moves into private data centers, regional clouds, and on-premises systems.
Cloud providers can support both approaches. They can sell managed access to closed models while renting computing capacity for open-weight deployments. Microsoft’s participation reflects that flexible position more than an exclusive commitment to one model philosophy.
The current coalition letter contains more names than the original report. OpenAI now appears alongside Cisco, Cohere, DoorDash, GitHub, Mozilla, Palo Alto Networks, and other additions.
However, Nvidia’s PDF does not display a change log. It does not identify when OpenAI signed, whether every addition endorsed identical language, or whether the original 25-company version remains archived. Readers should therefore treat OpenAI’s absence as an accurate launch detail, not its current position.
Anthropic and Google remain absent from the updated document. Amazon is also missing, despite its large cloud business and investments in model development. Those absences matter, but they do not automatically prove opposition to every claim in the letter.
A company can support access to open models without endorsing a specific policy document. It can also distribute selected open-weight models while keeping its most capable systems closed. Release strategies often vary by model capability, customer, and identified risk.
OpenAI illustrates that complexity. It primarily built its business around hosted models, yet it also released open-weight systems and conducted safety research around their distribution. Its late appearance turns the signatory list into evidence of shifting alignment rather than a permanent industry map.
The firmest conclusion is narrower. Nvidia assembled a broad commercial coalition around open-weight access, and that coalition expanded after publication. Anthropic and Google had not joined by July 25, leaving them outside a statement that now includes OpenAI.
Why Washington Is Reconsidering Chinese AI Models
The letter is aimed at a domestic policy debate, but Chinese model performance supplied the immediate pressure.
The Trump administration was reportedly examining restrictions on advanced Chinese AI models after Moonshot AI introduced Kimi K3. An Axios investigation said officials were revisiting earlier efforts involving DeepSeek and other Chinese developers.
The concern combines cybersecurity, intellectual property, and industrial policy. Downloadable models can be copied across systems after release. That makes a conventional service ban harder to enforce than restrictions on a website or hosted programming interface.
Administration officials also focused on distillation. This training technique uses outputs from one model to improve another model, often transferring behaviors without copying the original weights. Closed-model developers have alleged that some foreign competitors extracted capabilities through large volumes of generated responses.
Nvidia’s letter avoids naming China, DeepSeek, Moonshot, Anthropic, or Google. Still, its timing places it directly inside that dispute. It appeared four days after reporting about a renewed Chinese model ban and two days after Huang publicly defended access.
Huang argued that American companies should remain free to use Chinese models. In his China model defense, he rejected broad claims that Chinese systems inherently contain government backdoors. He also warned that relying on one model creates a concentrated point of failure.
That position serves Nvidia’s policy philosophy and commercial interests. Downloadable models usually require third-party processors, servers, networking, deployment software, and support. A diverse model market keeps demand spread across the computing layer where Nvidia holds influence.
Anthropic has a different exposure. Its most capable systems are delivered as managed products, and the company emphasizes controlled deployment and safety evaluations. Chinese open-weight systems can pressure that model by offering customers greater control and easier customization.
Google occupies both sides. It operates Gemini as a managed model family, provides cloud infrastructure, and has released smaller downloadable systems. Its absence from Nvidia’s letter cannot be reduced to opposition against open weights.
The administration also faces an enforcement problem. A restriction can prevent federal agencies or regulated companies from adopting specified models. It cannot reliably retrieve weights already downloaded and redistributed across private systems.
Broad restrictions could therefore change legitimate corporate behavior more than determined adversarial behavior. American enterprises might lose access to efficient models, while overseas users continue modifying them. That imbalance underpins the coalition’s competitiveness argument.
Yet unrestricted availability carries its own costs. Once capable weights are released, the original developer cannot reliably withdraw every copy. Operators can remove safety controls, conceal modifications, or deploy vulnerable versions without central updates.
Washington is consequently choosing among imperfect controls. It can regulate companies, computing infrastructure, government procurement, distribution platforms, or model capabilities. A blanket category such as “Chinese open-weight model” does not resolve which risk each control addresses.
The letter pushes policymakers toward targeted enforcement. It says unlawful extraction from closed systems should be handled through legal and commercial mechanisms. It rejects treating the entire distillation technique as misappropriation.
That distinction matters for American developers too. Model distillation is widely used for evaluation, specialization, and efficiency. A broad prohibition could restrict domestic research while failing to stop actors operating outside American jurisdiction.
The immediate fight concerns Chinese models, but the policy precedent would reach further. Rules written around Kimi or DeepSeek could later apply to Meta, Mistral, OpenAI, or smaller American laboratories. That possibility explains why infrastructure companies entered the debate before Washington published a final restriction.
The Anthropic Google Absence Reveals a Fight Over Control
The primary conflict is between provider-controlled intelligence and customer-controlled deployment, not between companies that simply favor safety or openness.
Open weights are trained model parameters available for download. They let an organization inspect, modify, fine-tune, and run a model without sending every request to its original developer. They do not necessarily include training data or complete source code.
That definition matters because “open source AI” can imply broader transparency. A model might provide weights under a permissive license while withholding its training dataset. Another model might limit certain commercial or downstream uses.
Nvidia’s coalition focuses on operational control. Its letter says organizations should choose where models run, protect their data, and retain specialized knowledge. It frames portability as a defense against dependence on a single provider.
For enterprise buyers, this difference becomes concrete during deployment. A hospital might want sensitive workloads contained within approved infrastructure. A manufacturer might need inference near equipment where connectivity is inconsistent.
A software company may also want to tune a smaller model around internal documentation. Keeping that system local can simplify some data-control requirements. It does not automatically resolve accuracy, security, or governance problems.
Closed services offer a different bargain. Their providers operate the infrastructure, update models, monitor abuse, and maintain centralized safeguards. Customers sacrifice some control in exchange for managed performance and reduced operational work.
Anthropic’s absence fits its established emphasis on controlled access to advanced systems. The company can monitor usage patterns and change safeguards when models remain on its servers. Those options largely disappear after weights circulate.
Google’s position is more mixed. Its hosted models support a managed platform strategy, but its downloadable releases support local and customized use. Remaining outside the letter may reflect policy caution, internal complexity, or disagreement with specific language.
No public statement cited by the coalition establishes Google’s reason. The same applies to Anthropic. Their nonparticipation is a meaningful signal, but attributing a precise motive would exceed the available evidence.
OpenAI’s addition complicates claims of a unified closed-lab bloc. The company’s name now appears beside firms whose businesses depend heavily on downloadable models. It has therefore accepted the letter’s broad argument even while operating major closed services.
The economic incentives remain visible. Nvidia sells computing capacity across model brands. Meta benefits when open models weaken rivals’ ability to charge for scarce access. Hugging Face benefits when developers can distribute, adapt, and host model artifacts.
Anthropic and Google earn value from managed intelligence, although Google also earns from cloud computing. Their strongest models help differentiate their services. Releasing equivalent weights would weaken control over distribution and safeguards.
That does not make the coalition’s argument insincere. Commercial interest often shapes which risks a company notices first. Nvidia sees concentration and restricted deployment, while a frontier laboratory sees safeguard removal and capability theft.
The policy challenge is to separate those interests from testable claims. Does downloading weights materially improve competition for smaller firms? Does local control reduce privacy exposure in real deployments?
Conversely, how much additional cyber or biological risk comes from releasing a specific model? Can capability evaluations identify that threshold before distribution? These questions require evidence beyond the number of logos on a letter.
The OECD openness analysis treats model openness as a spectrum with both benefits and risks. That framing is more useful than labeling one release approach inherently responsible.
For knowledge workers, the same control question appears in everyday tools. Hosted assistants process information through provider-managed systems, while local systems can keep selected materials closer to the user. A personal knowledge base still needs careful permissions, reliable retrieval, and clear data boundaries.
The Anthropic Google divide therefore reaches beyond Washington. It influences how buyers evaluate vendor dependence, data location, customization, and long-term portability. The winning policy will shape which of those choices remain practical.
Open Weights Trade Lock-In for Irreversible Risk
Open-weight models reduce dependence on central providers, but their most valuable freedom also makes their safeguards difficult to enforce.
The coalition acknowledges this problem directly. Once weights are released, the original developer loses control over copies. Modified versions can become difficult to trace, and a flawed release cannot be fully recalled.
That admission gives the letter more credibility than a simple lobbying statement. It does not claim that openness eliminates danger. Instead, it argues that distributed access helps defenders inspect models, identify weaknesses, and develop protections.
Security teams can use downloadable models to simulate attacks without exposing sensitive data to an external service. Researchers can reproduce evaluations and investigate suspicious behavior. Smaller organizations can adapt models for specialized defensive tasks.
The same access helps attackers. They can remove refusal mechanisms, fine-tune models for harmful objectives, or combine capabilities with private datasets. Centralized usage policies cannot block those modifications after distribution.
Closed models do not eliminate abuse either. Attackers can probe hosted services, steal credentials, exploit applications, or find prompts that bypass protections. Centralized systems can also create attractive targets with widespread downstream effects.
The tradeoff concerns marginal risk, meaning the additional danger created by distributing weights rather than offering equivalent capability through a service. That risk changes with model capability, available alternatives, deployment costs, and existing safeguards.
A highly capable downloadable model creates a different problem from a compact system performing routine classification. Policy based only on release format misses those differences. Capability-based evaluations offer a more precise starting point, although measurements remain incomplete.
OpenAI’s own risk evaluation study demonstrates why its later signature is plausible. The company evaluated whether malicious fine-tuning could push an open-weight release toward dangerous capabilities. It used those findings in its release decision.
That approach supports neither automatic publication nor automatic prohibition. It treats each model as an evidence problem. Developers estimate possible misuse, test safeguards, and compare the release against systems already available.
Nvidia’s letter goes further by arguing that openness can improve safety. Independent researchers can examine behavior that a closed provider might overlook. Multiple defensive teams can also test models without waiting for permission.
However, transparency does not guarantee correction. A vulnerability discovered in an open model can persist in old copies. Downstream operators may skip updates, conceal changes, or lack the expertise to apply mitigations.
The coalition’s security argument is therefore conditional. Open access supports broader inspection only when institutions fund evaluations, publish findings, and maintain deployment practices. Availability alone does not create an effective safety community.
Its policy recommendations recognize part of this requirement. The letter requests shared datasets, evaluation frameworks, and expanded computing access for researchers and startups. Those resources could make independent testing more credible.
The document provides fewer details about liability, incident reporting, or responsibility for modified versions. It does not specify capability thresholds that should delay a release. It also does not explain how regulators should address models originating outside American jurisdiction.
Those omissions matter because the Chinese model debate is not purely domestic. American release standards cannot bind every developer. Restrictive national rules might reduce domestic openness without preventing comparable foreign weights from appearing online.
A useful framework would distinguish model origin, measured capability, intended deployment, and actual access. Government procurement rules may require verified supply chains. Critical infrastructure could face stricter testing than consumer experimentation.
Distribution platforms can also provide model cards, checksums, security notices, and provenance records. These measures would not restore central control, but they could help responsible operators identify approved versions. Hardware providers might support monitoring without inspecting private customer data.
None of these options creates perfect enforcement. They instead allocate responsibility across developers, hosts, deployers, and users. That layered approach matches the distributed character of open-weight systems better than a single national ban.
The skeptical reading of Nvidia’s campaign remains valid. Its members profit when open models increase demand for hardware and deployment services. The letter’s claims about safety should therefore be tested, not accepted because respected companies signed them.
The skeptical reading of closed providers is equally necessary. Restrictions on downloadable rivals can protect managed-service revenue and strengthen existing market concentration. Safety arguments should not become an automatic shield against competition.
Washington needs standards that survive both forms of self-interest. That means testing capabilities, documenting incidents, and targeting identifiable harms. It also means preserving legitimate research and enterprise deployment where risks remain manageable.
Three Signals Will Show Which Side Is Winning
The next stage will be decided by regulatory language, signatory changes, and measured enterprise adoption rather than another round of public statements.
The first signal is Washington’s treatment of Chinese models. Officials can pursue a broad ban, targeted procurement limits, sanctions against named developers, or capability-based rules. Each option would create a different precedent for American open-weight releases.
A broad restriction based on national origin would strengthen Nvidia’s warning about fragmented access. It could push multinational enterprises toward separate model stacks for different markets. It would also test whether downloadable weights can be meaningfully contained after publication.
Targeted procurement rules would produce a narrower result. Federal agencies and critical contractors might face supply-chain controls, while researchers and ordinary businesses retain access. That outcome would weaken claims that all open weights face immediate restriction.
Capability-based rules would shift attention toward evaluations. Regulators would need thresholds for cybersecurity, biological assistance, autonomous action, or other identified risks. The credibility of those rules would depend on repeatable tests and transparent enforcement.
The second signal is whether Anthropic or Google changes its public position. Joining the letter would broaden the coalition across release strategies. Publishing a competing proposal would clarify where each company believes Nvidia’s framework fails.
Silence would remain ambiguous. Neither company must sign another firm’s document to support selected open-model policies. A direct policy submission, safety framework, or testimony would offer stronger evidence than an absent logo.
OpenAI’s addition also deserves verification. Nvidia should publish a dated revision record or archived versions of the letter. That would let readers distinguish the original coalition from later endorsements and avoid outdated reporting.
The third signal is enterprise adoption of open-weight models. Downloads alone do not establish sustained use. More useful evidence includes production deployments, infrastructure commitments, security incidents, and organizations switching between hosted and self-managed systems.
If enterprises adopt open models for sensitive or specialized workloads without rising incident rates, the coalition’s control argument grows stronger. If safeguard removal or vulnerable derivatives cause repeated harm, the case for stricter release conditions strengthens.
Model quality will shape that adoption. Buyers rarely choose openness as an abstract principle. They compare accuracy, latency, operational complexity, data requirements, available expertise, and the cost of maintaining infrastructure.
Chinese developers add another variable. A model that performs well and permits local deployment can attract American users despite political concern. A weaker release will not create the same regulatory urgency, regardless of its origin.
Developers should watch model licenses as carefully as benchmarks. Access to weights does not always permit every commercial use or redistribution method. A deployment that ignores license conditions can create legal exposure alongside technical risk.
Enterprise buyers should also avoid treating self-hosting as automatic independence. Running a model requires processors, orchestration software, monitoring, updates, and specialized staff. That stack can replace one form of vendor dependence with several others.
Closed services retain clear advantages for teams that need rapid deployment and managed operations. Open weights become more compelling when customization, data location, latency, or portability outweigh that convenience. Most large organizations will probably use both approaches.
That hybrid outcome would support the letter’s statement that the world needs closed and open frontier models. It would not resolve which models should be downloadable. The difficult policy question begins when capability reaches a level with credible irreversible harm.
The original headline framed OpenAI, Anthropic, and Google as a missing bloc. Within a day, that framing had already changed because OpenAI appeared in the hosted document. The remaining Anthropic Google absence now carries more weight, but less certainty about a unified closed-model position.
Readers should resist turning the signatory list into a morality scorecard. The companies are defending different combinations of revenue, safety, customer control, and strategic influence. Those incentives can produce useful arguments without producing neutral ones.
The better test is practical. Does a proposed rule address a measured risk, or does it mainly limit a competing distribution model? Does an open release provide enough benefit to justify the control its developer permanently surrenders?
Over the next three months, watch the exact regulatory target, any Anthropic or Google counterproposal, and verified production adoption. Those signals will show whether Nvidia built a durable policy coalition or captured only a fast-moving moment.
The debate should remain open to evidence from both sides. Developers and enterprise buyers can help by demanding dated policy documents, reproducible evaluations, and clear deployment terms. The Anthropic Google divide matters, but the rules created around it will matter much longer.



