SAN FRANCISCO — Anthropic CEO Dario Amodei drew a clear line between two positions critics have conflated: opposing a blanket ban on open-weight AI models and opposing any regulation of them. In a policy essay titled "Policy on the AI Exponential," Amodei wrote that open-weight models are not a "sufficient" answer to AI safety and that mandatory safety testing should apply to every capable AI system, whether its weights are publicly released or not.

Amodei's position came in direct response to an open letter—signed in part by Palantir CEO Alex Karp—that criticized Anthropic for allegedly supporting restrictions on open-weight AI. Amodei pushed back on that characterization. "To summarize my and Anthropic's position, we have not and are not advocating for a ban on open-weights models as a category," he wrote. He said he agreed with the open letter's core argument that open-weight models expand access to the AI economy, strengthen competition and give customers more control.

Where Amodei parted ways with open-source advocates is on what he calls the attacker-defender asymmetry. His argument is that releasing model weights publicly makes offensive uses of AI easier to scale while providing no equivalent defensive benefit. He said whether that is actually true should be determined by empirical safety testing—not assumed in either direction before the fact.

On the regulatory architecture he supports, Amodei pointed to the Federal Aviation Administration as the model. Frontier AI systems, he argued, should face mandatory technical testing and auditing before release, the same way commercial aircraft require certification before they carry passengers. Under his proposal, a model's release would be blocked or reversed if it failed to meet safety standards—a harder requirement than the voluntary commitments most frontier labs have made to date.

The three specific policies Amodei said he supports are: keeping advanced AI chips out of authoritarian governments' hands, stopping industrial-scale distillation—where a company trains a cheaper model by copying the outputs of a more expensive frontier system—and requiring safety testing for all sufficiently capable models, open and closed. The distillation point carries direct competitive implications for Anthropic. Cheaper models trained by distilling Claude's outputs would undercut Anthropic's pricing without bearing any of the frontier training cost.

Amodei's policy essay addresses the broader problem of who the public should believe when AI companies make safety claims, given that every major frontier lab has an economic interest in the regulation that applies to its competitors. The attacker-defender asymmetry sits at the center of that argument: open-weight release, in his view, shifts the balance toward bad actors, and that question should be settled by testing rather than assumption.

The conflict with Karp and Palantir is worth examining on its own terms. Palantir's commercial model depends on deploying AI inside government and enterprise clients, often with proprietary data. Open-weight models give those clients the option to run inference on their own infrastructure, which removes a dependency on API providers like Anthropic. Karp's defense of open weights is not purely philosophical—it aligns with Palantir's customer base preferring local deployment. Amodei's push for safety testing of open-weight models, if enacted as regulation, would raise the compliance cost of releasing those models and tilt the field toward closed, API-delivered systems like Claude.

Anthropić's own funding position adds context to why Amodei is writing policy essays rather than leaving the regulatory debate to others. The company raised $7.3 billion in total capital through 2024, including a round led by Google. Training a frontier model costs between $100 million and $500 million in compute alone at current scale. That barrier is already high enough to limit serious frontier training to four or five organizations globally. Mandatory pre-release safety testing would add another layer of cost and time that a well-capitalized incumbent absorbs more easily than a challenger.

The FAA analogy Amodei chose is pointed. The FAA's certification process is expensive, slow and requires detailed technical disclosure to regulators—all conditions that favor established players with compliance infrastructure over new entrants. Whether that outcome is an unintended consequence or a feature of the proposal depends on who is making it.

Amodei did not name a specific regulatory agency to run AI safety testing, propose a budget for it, or set a threshold for which model capability levels would trigger mandatory review. Those gaps are where the proposal remains unfinished. The FAA took decades to build the technical staff and institutional knowledge to certify aircraft. No equivalent body for AI currently exists in the U.S. federal government.