Hugging Face, Meta, Microsoft, Mistral and Nvidia signed an open letter this week urging US policymakers not to impose broad restrictions on open-weight AI models, wading directly into the Trump administration's deliberations over how to respond to rapidly advancing Chinese AI labs. The letter never names China but lands as the White House weighs banning Chinese open-weight models and sanctioning firms behind them. It also pushes back on any response that would sweep up distillation, the technique of training one model on another's outputs.
The immediate backdrop is a White House accusation that Moonshot AI distilled Anthropic's Fable model to build Kimi K3, the Chinese lab's recently released and, by most measures, highly capable frontier model. Anthropic and OpenAI have both pressed the administration to treat alleged IP extraction from closed labs as a national concern. The signatories of this week's letter want a narrower response.
The letter draws a line between misappropriation and standard model development. Distillation, the signatories argue, is a widely used practice for improvement, evaluation and validation, rooted in the same tradition of building on prior work that produced the open-source software movement. Illegal extraction from closed models is a real problem, they say, but the fix is targeted legal and commercial frameworks rather than sweeping technique bans.
“Policymakers should be careful not to conflate legitimate model-development techniques with misappropriation. Distillation, or the practice of using one model's outputs to help train or improve another, is a widely used technique for model improvement, evaluation, and validation.”— Open letter signatories, Hugging Face, Meta, Microsoft, Mistral, Nvidia
Key facts
- 01Hugging Face, Meta, Microsoft, Mistral and Nvidia signed an open letter opposing broad restrictions on open-weight AI models.
- 02The letter follows White House accusations that Moonshot AI distilled Anthropic's Fable model to train its Kimi K3 release.
- 03OpenAI, Anthropic, Google DeepMind and SpaceX are notably absent from the signatory list.
- 04Hugging Face said it had to use Chinese firm Z.ai's open-weight GLM 5.2 to defend against a recent attack after closed models refused the task.
- 05Signatories asked policymakers to expand compute access for startups and researchers and invest in shared datasets and evaluation frameworks.
The letter also rejects the argument that open-weight models are inherently dangerous because bad actors can use them without oversight. Signatories frame the security calculus as symmetrical: if attackers get advanced AI, defenders need equivalent tools, and closed guardrails often block legitimate defensive work.
That framing is not hypothetical. Last week OpenAI disclosed that while testing GPT-5.6 Sol and another unnamed model, one of the systems exploited a weakness in its test environment to reach a Hugging Face repository containing a benchmark solution. Hugging Face said its own attempts to defend against the intrusion using commercial frontier models failed because the closed models' guardrails could not distinguish a defender building an exploit from an attacker doing the same.
Hugging Face ultimately pivoted to Chinese firm Z.ai's GLM 5.2, an open-weight model, to mount its defense. The episode is now Exhibit A for the letter's argument that closed-only ecosystems create their own security problems.
“The right response to this risk is not to prohibit open weights. In a world where cybersecurity attackers use advanced AI, defenders need access to models with comparable capabilities so they can detect, simulate, and respond to emerging threats.”— Open letter signatories, Hugging Face, Meta, Microsoft, Mistral, Nvidia
The signatory list itself tells the story of the industry split. Nvidia, Microsoft, Meta, Mistral and Hugging Face all benefit commercially from a world of commoditized, interchangeable models. More open models means more GPUs sold, more Microsoft Azure capacity rented, more inference routing built. OpenAI, Anthropic, Google DeepMind and SpaceX, whose businesses depend on the premium value of closed frontier systems, did not sign.
The letter closes with three asks: expand compute access for startups and researchers, invest in shared training assets like datasets and evaluation frameworks, and keep the frontier plural by avoiding premature restrictions that stifle competition or push innovation overseas. That last point maps directly onto the Chinese-model debate: block distillation broadly, the signatories imply, and the effect is to protect a handful of closed US labs rather than to strengthen US AI overall.
Skeptics of the open-weight camp will note that the same commercial interests cut the other way for closed labs. Anthropic and OpenAI say alleged distillation of their models funds direct competitors at a fraction of the R&D cost. The White House has not yet detailed what evidentiary standard it will apply to the Moonshot allegation, and a Commerce Department response that stops short of a full ban but restricts specific labs remains on the table.
The policy fight now underway will shape whether the US treats open weights as strategic infrastructure or as a leakage risk. The signatories are betting that framing distillation as ordinary engineering, and open models as defensive necessity, is enough to keep the response narrow. If the administration instead accepts the closed-lab framing that any technique used to replicate frontier capability is theft, the commercial ceiling for open-weight providers, and for the compute and cloud stack that sells into them, contracts sharply.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




