6 months to live for open models

Recap
Intro
In the Interconnects article “6 months to live for open models,” Nathan Lambert argues that frontier open-weight AI is approaching a policy trap. He discusses model-review rules, Chinese open models, distillation claims, API security, and the coalition needed to keep frontier models open.
A six-month policy window for open models
Lambert calls this the strongest threat to open-source AI since ChatGPT launched. His concern is policy precedent. The federal government already has a process for testing advanced models, and a Chinese open model could soon trigger demands for review before release or use.
The public mechanism is narrower than that warning. Executive Order 14409 created a classified benchmark for advanced cyber capability and a voluntary channel for developers to provide pre-release access for up to 30 days. It expressly says the order does not authorize mandatory licensing, preclearance, or permitting.
Lambert still expects that threshold to become sticky. Closed-model companies can restrict access and lobby around the review process. Open weights cannot be withdrawn after release, and the strongest new open models are likely to come from China. That joins frontier safety, trade policy, procurement, and distillation in one argument for control.
His six-month deadline is a forecast. Artificial Analysis placed open-weight GLM-5.2 five points behind Claude Opus 4.8 on its composite index on July 20. That shows a gap on one benchmark, not a legal threshold. Axios later reported active discussion of restrictions on Chinese models. No adopted blanket ban was identified.
The distillation debate as regulatory capture
Lambert says Anthropic has turned suspected distillation by Chinese labs into a policy campaign that protects its own market position. His objection is not to securing Claude. It is to asking the government to restrict competitors while offering too little evidence for outsiders to test the allegations.
Anthropic has released more detail than that description allows. In February, it said DeepSeek, Moonshot, and MiniMax generated more than 16 million Claude exchanges through about 24,000 fraudulent accounts. Its technical account names attribution signals and targeted capabilities, but does not release raw logs for independent review.
Its June policy request was also narrower than an explicit ban on every Chinese open model. Anthropic asked for threat sharing, tighter advanced-compute controls, and penalties against labs responsible for evasive access. Those measures could still make Chinese open models harder to build, host, or use in the United States.
Lambert expects that pressure to damage U.S. inference providers, fine-tuning businesses, and products that depend on continued open-model improvement. The FTC has recognized that open models can lower entry barriers and that API terms can protect incumbents. It has not measured the damage from the specific controls under discussion.
Anthropic can have a valid security concern and an economic interest in the outcome. Neither fact settles whether its campaign is regulatory capture.
APIs are not automatically secure
Lambert rejects a simple split between unsafe open weights and safe APIs. Attackers can reach a hosted frontier model through stolen access, weak authorization, proxy accounts, or jailbreaks. If a capability is too dangerous to expose, he argues, the provider should not host it behind an API and then blame open models for the risk.
The examples need tighter labels. WIRED’s Mythos report described unauthorized access caused by location and permission failures, not a prompt jailbreak. The UK AI Security Institute has found that safeguards can be bypassed, while also finding that stronger controls raise attack cost.
APIs retain controls that released weights do not. Providers can monitor traffic, rate-limit accounts, change safeguards, and revoke access. Open weights support independent inspection and local control, but they cannot be recalled.
Lambert also says API access can spread dangerous capability faster than distilling a trillion-parameter model. The cited evidence does not prove that comparison. Published distillation work has transferred useful reasoning into students from 1.5 billion to 70 billion parameters. The relevant risks are different: immediate misuse of a hosted model, repeated extraction through an API, and permanent distribution of learned capability.
Frontier open models require policy and a coalition
A U.S. ban would not remove weights still available abroad. Lambert argues that it would mainly block compliant American researchers and companies while determined users kept access elsewhere. He says governments could impose a durable ceiling only through a global agreement. No such agreement is close.
Current policy cuts both ways. The White House’s June national-security AI memorandum tells agencies to use commercial or open-source AI from diverse suppliers. It also requires testing, assurance, supply-chain security, and partnerships against malicious distillation.
U.S. open-weight models already exist. OpenAI describes them as a tool for research, local control, and American influence. Lambert’s complaint is the capability gap: no U.S. open release yet matches the strongest closed models across the frontier.
He proposes two responses. Lambert wants an American company to release a comparably capable model and the wider open ecosystem to organize around safe deployment and policy. Carnegie Endowment proposed a loose coalition of allies rather than one universal agreement in its June report (source). That approach would not stop all risky releases, but it could set shared rules without waiting for global consensus.
The personal cost of a hotter AI-policy debate
Lambert closes by explaining his position. He says criticism of Anthropic and restrictions on open models has brought more hostility. He also says industry participants privately agree with him or fear speaking publicly.
Those reports cannot be independently verified. Nor can his account of the compensation he gave up to remain independent. Public material does confirm the underlying fight. Anthropic is asking policymakers to act on distillation and frontier risk. Lambert’s ATOM report documents a large open-model ecosystem used by researchers, businesses, and policy advisers.
He does not argue that every model should be open. He also rejects calling Anthropic employees evil. His criticism is aimed at corporate strategy, incentives, and policy. That limit matters because the article depends on a hard claim about institutional power without turning it into a claim of personal malice.