The AI Industry Is Betting on Open Weights
Security News
/Research
Fake Corepack Site Distributes Infostealer and Proxyware to Developers
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.
An open letter signed by 50 companies, from NVIDIA and Microsoft to Mistral and Hugging Face, urges Washington not to restrict open weight AI.
July 27, 2026
4 min read
NVIDIA CEO Jensen Huang, who had long stayed off social media, posted on X for the first time on July 24. His debut was not a product launch or a GPU teaser. It was a policy letter, with one argument: Washington should not restrict open weight AI.
Microsoft CEO Satya Nadella wrote on LinkedIn that open-weight models are "essential to a healthy AI ecosystem." The letter, Open Weights and American AI Leadership, launched with 25 signatures and now carries 50, a roster that runs from NVIDIA, Microsoft, Meta, and Google to IBM, Dell, Mistral, Hugging Face, Mozilla, and the Linux Foundation. The letter frames this as a national choice: "Our AI leadership will be judged not by one frontier AI model, but by whether the United States builds a strong, open ecosystem that diffuses into every sector."
When that much of the stack signs the same document, support for open weights has become the industry consensus.
Two things happened over the past six weeks that turned an ideological preference into a practical one.
The first: open models got good enough to matter. Moonshot AI's Kimi K3, a 2.8 trillion parameter open-weight model, landed in July and took the #1 spot in the Frontend Code Arena, passing Claude Fable 5.
On a separate long-horizon evaluation from the independent benchmarking firm Artificial Analysis, Kimi 3 lands just behind Fable 5, with the full weights out this week. When a model anyone can download and self-host reaches the frontier, paying frontier API prices on every routine task gets hard to justify. That is the letter's economic argument: open weights, it says, "let every organization match the right model to the right job at the right cost."
The second: closed models showed how fragile leaning on them can be. On June 12, the US government forced Anthropic to pull Claude Fable 5 days after launch, applying export controls that required blocking all foreign nationals. Anthropic had no way to verify nationality in real time, so it shut the model off worldwide within about 90 minutes. A frontier model that teams had wired into production simply went dark by government order. This outage that showed frontier AI is now critical infrastructure, the kind of dependency whose sudden loss is a business continuity event rather than an inconvenience. A model you can download and run yourself does not get switched off by a letter to someone else's CEO.
Open models made giant leaps forward and dependence on closed ones got riskier within the same few weeks. The open model everyone is now benchmarking against is chasing the exact closed model the government pulled offline.
Sovereignty is the letter's recurring theme. The signatories want organizations to "control their own data, evaluate and adapt models to their own needs, and deploy them wherever their business requirements demand." Own what you build instead of renting it from a provider who can raise prices, deprecate a model, or be ordered to shut it off.
That argument resonates most where data is sensitive and regulated. In finance, open-weight models let institutions fine-tune on proprietary data and keep it on their own infrastructure instead of sending sensitive records to a third-party provider. It also explains an otherwise strange coalition: a French model lab in Mistral, a chipmaker in NVIDIA, two of the biggest names in cyber in CrowdStrike and Palo Alto Networks, and Microsoft, the company that once called Linux a cancer, all on the same page. Open source made this argument about source code over thirty years. The letter is making it about model weights, and betting it gets settled faster.
The letter's most consequential claim is not about cost. It argues that openness makes AI more secure, not less. "Relying solely on closed models is not inherently safe: they can be breached, misused, or fail in ways that outsiders cannot detect," the letter argues, and concentrating capability in a few closed models creates "single points of failure." The conclusion the signatories reach is that "openness may be one of the most important paths to AI safety and security." In a world where attackers use advanced AI, defenders need models with comparable capabilities to test, simulate, and respond. It is the security-through-transparency argument the open source community has made for decades, pointed now at weights instead of code.
The security case has real limits, and the letter admits some of them. It concedes that once weights are released they cannot be recalled and modified versions are hard to trace. A high benchmark score is also not the same as reliability on real security work. Open models are gaining ground fast but still trail the best closed ones where it matters most to defenders.
The launch roster skewed toward companies without a closed frontier model of their own: chipmakers, cloud operators, open-weight labs, and application vendors. OpenAI and Google, which both sell closed frontier models, signed on after launch as the list grew to 50.
Anthropic and Amazon are the most notable names not on the list. Anthropic has publicly argued for more government oversight of frontier AI, including export controls aimed at China, while the letter opposes new restrictions. Even with those absences, a roster that spans chipmakers, cloud providers, open-weight labs, and two of the largest closed-model developers marks how far support for open weights has moved toward a mainstream industry position.
Subscribe to our newsletter
Get notified when we publish new security blog posts!
Security News
/Research
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.
Research
/Security News
A large-scale campaign abused GitHub Actions in compromised repositories to exploit CVE-2026-41940 in cPanel and WHM and steal server credentials.
Security News
Five frontier LLMs generated the same nonexistent package names, leaving 53 available for potential slopsquatting across PyPI and npm.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.