← 返回研报
热点解读 · 原文翻译

Anthropic 的开放权重模型立场Dario Amodei《Our position on open-weights models》全文翻译与解读

Dario Amodei(Anthropic 联合创始人兼 CEO)· 原文 2026 年 7 月 27 日 · 编译 AI Insight
阅读英文原文 ↗
背景

2026 年 7 月下旬,围绕开放权重(open-weights)模型的争论骤然升温:有报道称部分美国官员正考虑禁止美国企业使用中国的开放权重模型[2]。作为回应,英伟达、微软、Meta、IBM、Mistral、Mozilla、Linux 基金会、Hugging Face、a16z、YC 等公司联署了题为《Open Weights and American AI Leadership》的公开信,反对"过早限制"——签署方一度从 25 家扩大到约 50 家,而 OpenAI 与 Anthropic 均未在最初名单中[3][4]。此背景下,有人指责 Anthropic 想借"禁开源"保护自身生意。

本文即 Anthropic CEO Dario Amodei 于 7 月 27 日发表的正式立场回应[1]。下文先给出编者总结,随后逐段中英文对照呈现全文。翻译力求忠实、未作增删;灰色小字为英文原文。


一句话总结

Amodei 明确否认 Anthropic 主张"禁止开放权重模型",称不具危险能力的开源模型是"公共产品";但他认为保护主义式禁令解决不了真正的国安担忧——威权政府造出更强模型、强模型被用于网络或生物攻击——并给出三项他一贯支持的替代措施:

他同时"部分认同"那封公开信(开源扩大准入、强化竞争、赋予客户掌控),但不认同"开源必然更利于防御方"的论断,主张这类问题应由发布前的实证测试来回答,而非事先假定。


全文 · 中英文对照

过去几天,围绕开放权重(open-weights)模型——尤其是来自中国的模型——出现了大量讨论。有报道称,一些美国官员正在考虑禁止美国企业使用中国的开放权重模型。作为回应,许多科技公司联署了一封支持开放权重模型的公开信;甚至有人指责 Anthropic 想要禁止开放权重模型,以此保护自身生意。读过我过往文章的人应该都清楚,我并不认为这类禁令是有用的举措;但请允许我把话说明白,以免有任何疑问:Anthropic 从未主张禁止开放权重模型。

Over the last few days there has been a lot of discussion about open-weights models, especially those from China. Reports suggest that some US officials are considering banning the use of Chinese open-weights models by US companies. In response, many tech companies have signed a letter supporting open-weights models, and some people have even accused Anthropic of wanting to ban open-weights models as a means of protecting our business. Anyone who has read my past writing should know that I don't regard such bans as a useful measure, but let me state it clearly so that there is no doubt: Anthropic has never advocated for a ban on open-weights models.

不具备危险能力的开放权重模型是一种公共产品:除了运行所需的算力之外,它们几乎没有其他成本,并为企业、开发者和研究者带来价值。

Open-weights models that don't have dangerous capabilities are a public good: they don't cost anything besides the compute needed to run them, and they provide value to businesses, developers, and researchers.

保护主义式的禁令并不能解决我最严重的国家安全担忧。具体而言,我担心两种"噩梦情景"。我在六个月前的文章《技术的青春期》(The Adolescence of Technology[5]中阐述过它们,多年来一直持有这些立场:

Protectionist bans would not address my most serious national security concerns. Specifically, I am worried about two nightmare scenarios. I laid these out in my essay The Adolescence of Technology six months ago, and have held these positions consistently for many years:

1.我的首要担忧,是威权政府——不仅仅是中国共产党(CCP),尽管 CCP 显然是最有能力的威胁——构建出比美国更强大的 AI 模型,并用它们实现永久性的军事优势,或对本国人民实施极其深重的压制。这一担忧在美国政府内部被广泛认同:副总统万斯(Vance)去年在巴黎警告称"威权政权已经窃取并利用 AI 来强化……";情报界的《2026 年度威胁评估》也发现,其他全球大国在 AI 上的进展正挑战美国的优势。这些模型是否以开放权重发布无关紧要,是否被美国企业使用更是无关紧要。事实上,最危险的模型,可能是那种被秘密训练、只交给中国人民解放军用于无人机、交给国家安全部用于监控与压制的模型。

1.My primary concern is the risk that authoritarian governments—not solely the Chinese Communist Party (CCP), although the CCP is clearly the most capable threat—build AI models that are more powerful than those built by the US, and use them to achieve permanent military superiority or perpetrate incredibly deep repression of their own people. This concern is widely shared within the US government: Vice President Vance warned in Paris last year that "authoritarian regimes have stolen and used AI to strengthen…" and the Intelligence Community's 2026 Annual Threat Assessment found that other global powers' AI progress challenges US advantages. It is irrelevant whether these models are released with open weights, and certainly irrelevant whether they are used by US businesses. In fact, the most dangerous model may be one that is trained in secret and handed only to the People's Liberation Army for use in drones and the Ministry of State Security for surveillance and repression.

2.我的次要担忧,是强大的 AI 模型可能被滥用于发动网络攻击或生物攻击,并且可能存在严重的对齐(alignment)问题。开放权重模型——无论来自中国还是其他任何地方——确实可能比闭源模型带来更高风险,因为很难为它们施加护栏或监控其使用,而且权重一旦发布便无法收回。但禁止美国企业使用这些模型,对化解这一风险毫无作用,因为恶意行为者不太可能是合法的美国企业。这样做确实能让美国 AI 公司免于竞争,但那从来不是我的目标。

2.My secondary concern is the risk that powerful AI models may be misused to carry out cyberattacks or biological attacks, and may have serious alignment problems. Open-weights models—it does not matter whether they come from China or anywhere else—do potentially present a higher risk than closed models, because it is very difficult to apply guardrails to them or monitor their usage, and once weights are released they cannot be withdrawn. But banning the use of these models by US businesses does nothing to address this risk, because bad actors are unlikely to be legitimate US businesses. It would protect US AI companies from competition, but that has never been my goal.

为了应对这些担忧,我确实支持以下三项措施,这也是我和 Anthropic 一贯主张的:

To address these concerns, I do support the following three measures, which I and Anthropic have consistently advocated for:

我们不应向中国出售强大的芯片或芯片制造设备,并且应当打击为获取此类芯片而进行的猖獗走私与各种变通手段。中国的本土产能有限,因此,根据规模定律(scaling laws),在没有美国芯片的情况下无法造出比美国更强大的模型。这是阻断"威胁 #1"最高效、最直接的方式;同时,通过阻碍那些不受美国法律约束的模型的训练,它也间接有助于应对"威胁 #2"。

We should not sell powerful chips or chipmaking equipment to China, and we should crack down on the rampant smuggling and workarounds used to obtain access to such chips. China has limited domestic production capacity, and therefore, due to scaling laws, cannot build more powerful models than the US without US chips. This is the most efficient and direct way to block threat #1, and by hampering the training of models that are out of reach of US law, it also indirectly helps with threat #2.

我们应当打击工业规模的蒸馏(distillation)行为。相比从零开始训练,蒸馏是一种算力效率高得多的方法。它让中国能够造出远超其芯片数量本应支撑的更好模型,从而部分绕开芯片禁令。蒸馏并不能让 CCP 获得与美国相当或更强的 AI 能力,但它能把中国的前沿水平拉近到距美国仅数月之遥。诚然,许多从事此类行为的公司都发布开放权重模型——但相比"这些行动背后是一个试图在前沿超越美国的威权国家"这一事实,权重是否开放要次要得多。我们应当采取政策干预来遏制这种行为。对开放权重模型的一刀切禁令,既不是正确的补救措施,也不是我们所呼吁的。

We should crack down on industrial-scale distillation operations. Distillation is a much more compute-efficient process than training models from scratch. It allows China to build much better models than its number of chips would ordinarily enable, and thus partially evade chip bans. Distillation does not allow the CCP to obtain equivalent or superior AI capabilities to the US, but it can bring the Chinese frontier to within a few months of the US frontier. It is true that many of the companies carrying out these operations release open-weights models—but the open weights are far less relevant than the fact that the operations are backed by an authoritarian state seeking to overtake the US at the frontier. We should have policy interventions to deter this behavior. A blanket ban on open-weights models is neither the correct remedy nor something we have called for.

所有足够强大的模型,无论开源还是闭源,都应经过强制性的安全测试。应对"威胁 #2"最好的方式,就是在发布前直接对模型进行网络、生物和对齐风险的测试。我认为这一想法其实已接近共识:令我感到鼓舞的是,特朗普政府近几个月已朝这个方向推进;业界近期的一些提案也主张,无论模型来自哪个国家、是开源还是闭源,都应对最强的模型施加此类测试(而对能力较弱的模型,如初创公司和学术界的模型,则完全豁免)。开源模型究竟是否带来更高风险、这种风险能否被缓解,应当由测试来得出结论,而不是事先就下定论——而且,可能存在提升开放权重模型安全性的有前景的方法,包括 Anthropic 近期关于模块化训练(modular training)策略的研究。需要注意的是,要真正有效,测试必须是全球性的,这意味着连 CCP 也需要参与其中。我认为这或许确实可行:正如我在《技术的青春期》中所写,围绕防止 AI 生物武器的有限合作是可能的,因为这也符合中国的利益。

All sufficiently capable models, open and closed, should go through mandatory safety testing. The best way to address threat #2 is to just directly test models for cyber, biological, and alignment risks before release. I think this idea is actually close to a consensus: I have been heartened both that the Trump administration has moved in this direction in recent months, and by recent industry proposals that would apply such testing to the most capable models regardless of their country of origin or whether they are open or closed (while exempting less capable models, such as those from startups and academia, entirely). Whether open models do or don't pose an increased risk, and whether that risk can be mitigated, is something that should emerge from testing, rather than be decided in advance—and there may be promising methods for improving the safety of open-weights models, including recent research from Anthropic on modular training strategies. Note that to be effective, testing would need to be global, which means even the CCP would need to be on board. I think this may actually be possible: as I wrote in The Adolescence of Technology, limited cooperation around preventing AI biological weapons may be possible because it is in China's interest too.

这就说到那封公开信了。我认同其中的很多内容:开放权重扩大了进入 AI 经济的通道,至少在某些用例上强化了竞争,也让客户拥有更大的掌控权。对蒸馏的担忧,应通过有针对性的法律与商业框架来解决——也就是我上文所述的措施。但我不认同信中的这些论断:开放权重模型必然让安全防护更易开发,或者说能力的广泛可得必然对防御方比对攻击方更有利。在我看来,相反情形至少同样可能成立。举例来说,我担心生物领域存在强烈的"攻防不对称":足够强大的模型或许能用广泛可得的材料迅速将大流行级别的病毒武器化,而针对这些病原体的防御,即便在最好的情况下也是一项耗时数年的系统工程(正如我们在"曲速行动"(Operation Warp Speed)中所见)。诸如此类的问题,应当由严格的发布前测试来给出实证答案,而不是事先就假定结论。

This brings me to the open letter. I agree with much of it: open weights expand access to the AI economy, they strengthen competition at least for some use cases, and they give customers greater control. Concerns about distillation should be addressed through targeted legal and commercial frameworks—the same measure I described above. But I don't agree with the letter's assertions that open-weights models necessarily make it easier to develop safeguards or that broad access to capabilities necessarily helps defenders more than attackers. It seems at least as likely to me that the opposite will be true. For example, I worry that biology will have a strong attacker-defender asymmetry, where sufficiently capable models may be able to quickly weaponize pandemic-level viruses with widely available materials, whereas defense against these agents is a multi-year operational task in the best case (as we saw with Operation Warp Speed). Questions like this should be empirically answered by rigorous pre-release testing, not assumed in advance.

总结我和 Anthropic 的立场:我们过去没有、现在也没有主张把开放权重模型作为一个类别加以禁止。我们真正应当聚焦的,是把强大的芯片挡在威权者手外、阻止工业规模的蒸馏,以及要求对所有足够强大的模型(无论开源还是闭源)进行安全测试。

To summarize my and Anthropic's position, we have not and are not advocating for a ban on open-weights models as a category. We should instead focus on keeping powerful chips out of authoritarian hands, stopping industrial-scale distillation, and requiring safety testing of all sufficiently capable models, open and closed.


延伸 · 这场争论的当下坐标

Amodei 此文正值开放权重阵营"实货"密集落地之时:月之暗面 7 月中旬发布 Kimi K3——2.8 万亿参数 MoE、原生多模态、百万 token 上下文,被普遍视为迄今参数最大的开源权重模型[6]。与此同时,安全侧也在组织化:NVIDIA 联合 Linux 基金会等 40 余家机构(微软、IBM、红帽、Hugging Face、CrowdStrike 等)成立 Open Secure AI Alliance,共建保护 AI 智能体与软件的开放安全技术[7]。"开放"与"安全"两条线同时加速,正是本文争论的现实注脚。


参考文献

[1]Anthropic / Dario Amodei — "Our position on open-weights models"(2026-07-27)
anthropic.com/news/position-open-weights-models
[2]Morning Brew — "Tech companies want US govt to protect access to open-weight AI"(2026-07)
morningbrew.com/stories/tech-companies-want-us-govt-to-protect-access-to-open-weight-ai
[3]AI News — "Meta, Microsoft, Nvidia, IBM, and others back open-weight AI"(2026-07)
artificialintelligence-news.com/news/meta-microsoft-nvidia-ibm-others-back-open-weight-ai
[4]Forbes / Sandy Carter — "Huang's Open Weights Letter Doubled To 50 Without Amazon And Anthropic"(2026-07-25)
forbes.com/sites/sandycarter/2026/07/25/huangs-open-weights-letter-doubled-to-50
[5]Dario Amodei — "The Adolescence of Technology"(2026-01-26)
darioamodei.com/essay/the-adolescence-of-technology
[6]Moonshot AI / Kimi K3 开源权重发布(2.8T MoE,2026-07);技术综述见 Interconnects(Nathan Lambert)
interconnects.ai/p/kimi-k3-the-open-weights-escalation
[7]NVIDIA Blog — "Industry Leaders Join Open Secure AI Alliance for AI Safety and Security"(2026-07-27)
blogs.nvidia.com/blog/open-secure-ai-alliance

译注:本文为英文原文的忠实编译,中文翻译仅供参考,专有名词(如 CCP、PLA、alignment、distillation 等)保留原意直译;如与原文有出入,请以英文原文为准。"威胁 #1 / #2"沿用作者原文编号,原文强调(黑体 / 斜体)尽量对应保留。背景与延伸信息来自公开报道,已逐条附来源。