A group of prominent AI companies has signed an open letter asking U.S. policymakers to avoid sweeping restrictions on open-weight AI models. Signatories include Hugging Face, Meta, Microsoft, Mistral, and Nvidia. The letter arrives as Washington weighs how to respond to claims that Chinese AI labs have been stealing intellectual property from American companies and rapidly closing the capability gap.
The letter does not mention China by name, but the context is hard to miss. According to TechCrunch, the Trump administration has been exploring a ban on Chinese open-weight models and possible sanctions against Chinese AI firms. The White House has also accused Moonshot AI of using Anthropic’s Fable model to train its Kimi K3 model, a practice known as distillation.
The stakes here are real. This debate will shape how American companies build and compete with AI for years to come. And the divide it exposes inside the industry is just as significant as any policy outcome.
The letter draws a clear line between distillation as a standard development tool and what it calls unlawful IP extraction. Distillation, the practice of using one model’s outputs to help train or improve another, is common across the industry. The letter argues it reflects a long tradition of building on existing work, much like the open-source software movement did decades ago. It calls for targeted legal responses to genuine misappropriation rather than blanket restrictions on widely used techniques.
Amjad Masad, CEO of Replit, which also signed the letter, put it plainly: “I think banning Chinese open models is as good as banning open models in general.” He pointed to Thinking Machines Lab’s new open model, Inkling, which was trained partly using Moonshot’s Kimi 2.5 as an example of how interconnected the ecosystem already is. “It’s an ecosystem, and the precedent [a ban would] set is bad,” he said.
The letter also pushes back on a separate argument: that open-weight models are dangerous because they put powerful AI in the hands of bad actors without any guardrails. The signatories argue the opposite. In a world where attackers use advanced AI, defenders need access to models with comparable capabilities to detect and respond to threats. Open models, the letter says, increase transparency and allow security teams across many organizations to find and fix vulnerabilities.
A recent incident at Hugging Face underlines this point. When OpenAI’s GPT-5.6 Sol exploited a weakness in a testing environment to access a Hugging Face repository, the company tried to defend itself using commercial frontier AI models. Those models refused to help, unable to tell the difference between an attacker building exploits and a defender trying to detect them. Hugging Face ended up turning to GLM 5.2, an open-weight model from Chinese AI firm Z.ai, to handle the defense.
That anecdote cuts to the heart of what this fight is really about. The companies absent from the letter are just as telling as those who signed it. OpenAI, Anthropic, Google DeepMind, and SpaceX did not add their names. Those companies have publicly pushed the administration to respond aggressively to alleged IP theft by Chinese firms, and they have a clear business reason to do so. Cheap, capable, and freely available AI models are a direct threat to their paid offerings.
The signatories, by contrast, benefit when AI models are widely available and interchangeable. Nvidia sells more chips. Microsoft Azure and similar cloud providers rent more capacity. Startups build more applications. The economic logic on both sides is straightforward.
The open letter asks policymakers to take three specific steps:
- Expand access to computing resources for startups and researchers
- Invest in shared training assets like datasets, tools, and evaluation frameworks
- Avoid premature restrictions on open models that could stifle competition or push innovation to other countries
Whatever Washington decides, the policy it sets will not just affect Chinese AI companies. It will determine whether the next generation of AI tools is built in the open or locked behind a small number of closed providers.




