AI Models & Platforms
Nvidia and Microsoft Back Open-Weight AI in Joint Letter

A coalition of 25 American technology companies published a joint letter on July 24, 2026, arguing that the United States will hold its lead in artificial intelligence only if it builds an open model ecosystem, not by guarding a single best system. The signatories to Open Weights and American AI Leadership, hosted on Microsoft’s (MSFT ) corporate-responsibility site, include Nvidia (NVDA ), Microsoft, Meta, Andreessen Horowitz, IBM, Dell, Palantir, Mistral, Hugging Face and Y Combinator. Nvidia CEO Jensen Huang amplified it in the first post he has ever made on X, writing that “open models strengthen safety and cybersecurity, accelerate innovation and diffusion, and enable sovereignty”.
The letter lands in the middle of an active fight in Washington over whether to restrict open models, especially Chinese ones. It reads as a direct counterargument, framing American AI leadership as something that will be judged not by any single frontier model but by whether the country builds an open ecosystem that spreads into every sector of the economy.
What the letter argues
Open-weight models are systems whose trained parameters are published, so anyone can download, inspect, modify and run them on their own hardware. That distinguishes them from closed models such as Anthropic’s Claude Fable 5 or OpenAI’s GPT-5.6 Sol, which their developers operate and control through an API.
The letter makes three practical claims: that open weights widen access to AI by letting organizations build on existing models instead of training their own or paying top-tier prices for routine tasks; that they sustain competition across chips, clouds and applications; and that they give customers control over their own data and models rather than locking them into one provider.
The argument most relevant to how these systems are actually secured is the safety claim. The signatories contend that relying only on closed models is not inherently safe, because a few closed systems become concentrated single points of failure that outsiders cannot inspect. Open weights, they write, let a broad community examine model behavior, find vulnerabilities and build safeguards, which is why “openness may be one of the most important paths to AI safety and security.” The letter also draws a line on distillation, the practice of training one model on another’s outputs, calling it a legitimate and widely used technique that should not be conflated with unlawful extraction of value from closed models. Genuine theft, it says, should be handled with narrow legal and commercial remedies, not blanket restrictions on the technique itself.
Why the timing matters
The letter follows the July 16, 2026 release of Kimi K3, an open-weight model from Beijing-based Moonshot AI that reset expectations for how capable a downloadable system can be. Independent testing has placed it near the frontier, ranking third on one widely tracked capability index behind Fable 5 and GPT-5.6 Sol, and at the top of a blind coding arena. Those numbers still carry the usual caveat that matters here: the full weights are due to go public within days, and only then can the benchmark claims be replicated outside Moonshot’s own release and early API testing. Kimi K3 is also far cheaper to run than the leading American systems, which is what turned a model launch into a market event and a policy one.
That capability jump is what put open weights on Washington’s agenda. The Trump administration has weighed limits on U.S. access to Chinese open models, alleging that Moonshot distilled an Anthropic model and used export-controlled Nvidia servers to train Kimi K3, claims the U.S. has floated as grounds to blacklist the company. In June 2026, the administration used export controls to block distribution of Anthropic’s most capable models after a jailbreak in their cybersecurity guardrails, and it asked OpenAI to hold back its top model until it could show its own guardrails were robust. The signatories, several of whom compete directly, are pushing back on that instinct before it hardens into rules.
Where the safety claim is contested
The letter’s central security argument is a position, not a settled result, and the labs building the most capable closed models take the opposite view. Anthropic has argued that open weights are harder to keep safe precisely because release is irreversible: once the parameters are public, a developer can no longer revoke access, patch a guardrail or stop misuse. It keeps its most capable cybersecurity model, Claude Mythos, restricted to a vetted set of partners, and OpenAI has warned that distillation lets rivals copy hard-won capability. Security researchers note that closed frontier models still lead on the offensive cyber tasks where an inspectable open model would, in theory, help defenders most.
It is also worth reading the document for what it is: an advocacy letter from companies with direct stakes in the outcome. Nvidia sells the chips that train and run every model, open or closed; Meta and Mistral ship open-weight systems; Hugging Face hosts them. The broader push for American open-weight models has commercial logic behind it as much as a safety thesis, and the same openness that lets defenders inspect a model lets anyone else strip its safeguards.
What the letter cannot do is resolve the empirical question at its core, which is whether broad access makes AI more secure or less. That is the kind of claim independent evaluation settles, not signatures. Kimi K3’s full weights going public is a concrete near-term test of at least the capability half of the argument, and it arrives just as Chinese open models keep closing the gap with the frontier the American labs still hold.












