앤트로픽, 공개 가중치 금지 반대…칩 통제와 증류 차단 제안

앤트로픽, 공개 가중치 금지 반대…칩 통제와 증류 차단 제안이라는 기사 제목을 배치한 대표 이미지
앤트로픽은 공개 가중치 모델을 일괄 금지하는 대신 위험을 만드는 능력과 행위를 직접 규율하자고 제안했다.

미국 AI 기업 앤트로픽(Anthropic)이 7월 28일 오전 7시 10분 공개 가중치(open-weight) 모델을 범주 전체로 금지하는 데 반대한다는 입장을 냈다. 다리오 아모데이(Dario Amodei) 미국 앤트로픽 공동창업자 겸 최고경영자는 최근 중국 모델과 업계 공동서한을 둘러싼 논쟁에 답하면서, 보호주의적 금지는 핵심 안보 위험을 해결하지 못하고 미국 AI 기업의 경쟁사만 줄일 수 있다고 밝혔다.

중국 모델과 공동서한 논쟁이 발표 배경

아모데이는 입장문 첫 문단에서 최근 며칠 동안 특히 중국산 공개 가중치 모델을 놓고 논의가 커졌다고 설명했다. 일부 미국 당국자가 미국 기업의 중국 모델 사용 금지를 검토한다는 보도, 이에 반대하는 기술기업들의 공동서한, 앤트로픽이 자사 사업을 보호하려고 금지를 원한다는 비판을 차례로 거론했다. “앤트로픽은 공개 가중치 모델의 금지를 주장한 적이 없다”는 것이 이번 발표의 첫 결론이다.

발표 시점은 중국 문샷AI(Moonshot AI)가 Kimi K3 가중치를 공개한 지 약 7시간 뒤다. 다만 입장문은 Kimi K3를 이름으로 지목하지 않았고, 가중치 공개가 발표를 촉발했다고도 쓰지 않았다. 확인되는 직접 배경은 중국 모델 전반의 부상과 규제 보도, 그리고 35개 기술기업의 공개 가중치 규제 반대 서한이다.

금지 대신 칩, 증류, 공통 안전성 테스트

앤트로픽이 가장 크게 보는 위험은 공개 여부와 다르다. 권위주의 정부가 미국보다 강한 모델을 만들어 군사적 우위와 국내 감시에 쓰는 상황, 강력한 모델이 사이버 공격과 생물학 공격에 악용되거나 심각한 정렬 문제를 일으키는 상황이다. 첫 번째 위험에서는 비공개로 학습해 군과 정보기관에만 건넨 모델이 더 위험할 수 있다. 두 번째 위험에서는 공개 가중치의 보호 장치를 제거할 수 있고 배포 뒤 회수할 수 없다는 점이 문제가 된다.

아모데이는 이 두 위험에 다음 세 가지로 대응하자고 제안했다.

  1. 중국에 고성능 칩과 반도체 제조 장비를 판매하지 않고 밀수와 우회를 단속한다.
  2. 폐쇄형 모델의 출력을 대규모로 수집해 경쟁 모델을 개선하는 산업 규모 증류를 막는다.
  3. 공개형과 폐쇄형을 가리지 않고 충분히 강력한 모든 모델에 출시 전 사이버, 생물학, 정렬 위험 테스트를 의무화한다.

정책 기준을 모델의 배포 방식 하나가 아니라 칩 접근, 개발 과정의 행위, 실제 위험 능력으로 나누자는 제안이다. 위험한 능력이 없는 공개 가중치 모델은 실행 연산 비용만 들고 기업과 개발자, 연구자에게 가치를 제공하는 공공재라는 평가도 함께 내놨다.

공동서한과의 쟁점은 공개 접근이 안전에 도움이 되는지다

앤트로픽은 공동서한에 서명하지 않았지만 내용의 상당 부분에는 동의했다. 공개 가중치가 AI 경제의 접근성을 넓히고 일부 분야의 경쟁을 강화하며 이용자에게 더 큰 통제권을 준다는 주장이다. 증류 문제도 기법 전체를 제한하기보다 불법 행위를 겨냥한 법률과 상업 규칙으로 다뤄야 한다는 데 뜻을 같이했다.

공동서한은 더 많은 연구자와 개발자가 모델을 살펴보면 보호 장치를 개선하고 공격자에 맞설 수 있다고 주장한다. 아모데이는 광범위한 접근이 반드시 방어자에게 더 유리하다고 볼 수 없으며, 특히 생물학에서는 공격자가 짧은 시간에 큰 피해를 만들 수 있는 반면 방어 체계 구축에는 여러 해가 걸릴 수 있다고 지적했다. 이 차이는 추정으로 정할 일이 아니라 출시 전 시험으로 확인해야 한다는 입장이다.

이번 발표는 앤트로픽이 공개 가중치 모델 개발로 방향을 바꾼다는 선언이 아니다. 금지론과 자사의 안전 규제 주장을 분리하고, 공개 여부만으로 막기보다 모델 능력과 칩 접근, 산업 규모 증류, 출시 전 안전성 검사를 각각 규율하자는 정책 입장을 분명히 한 문서다.

원문 아카이브

Anthropic 원문 바로가기
영어 원문 전체 펼치기접기

Announcements

Our position on open-weights models

Jul 27, 2026

A post by Dario Amodei, Anthropic CEO

Over the last few days there has been a lot of discussion about open-weights models, especially those from China. Reports suggest that some US officials are considering banning the use of Chinese open-weights models by US companies. In response, many tech companies have signed a letter supporting open-weights models, and some people have even accused Anthropic of wanting to ban open-weights models as a means of protecting our business. Anyone who has read my past writing should know that I don’t regard such bans as a useful measure, but let me state it clearly so that there is no doubt: Anthropic has never advocated for a ban on open-weights models.

Open-weights models that don’t have dangerous capabilities are a public good: they don’t cost anything besides the compute needed to run them, and they provide value to businesses, developers, and researchers.

Protectionist bans would not address my most serious national security concerns. Specifically, I am worried about two nightmare scenarios. I laid these out in my essay The Adolescence of Technology six months ago1, and have held these positions consistently for many years:

  1. My primary concern is the risk that authoritarian governments—not solely the Chinese Communist Party (CCP), although the CCP is clearly the most capable threat—build AI models that are more powerful than those built by the US, and use them to achieve permanent military superiority or perpetrate incredibly deep repression of their own people. This concern is widely shared within the US government: Vice President Vance warned in Paris last year that “authoritarian regimes have stolen and used AI to strengthen their military, intelligence, and surveillance capabilities,” and the Intelligence Community’s 2026 Annual Threat Assessment found that “other global powers’ robust progress in AI is challenging US economic competitiveness and national security advantages.” It is irrelevant whether these models are released with open weights, and certainly irrelevant whether they are used by US businesses. In fact, the most dangerous model may be one that is trained in secret and handed only to the People’s Liberation Army for use in drones and the Ministry of State Security for surveillance and repression.
  2. My secondary concern is the risk that powerful AI models may be misused to carry out cyberattacks or biological attacks, and may have serious alignment problems. Open-weights models—it does not matter whether they come from China or anywhere else—do potentially present a higher risk than closed models, because it is very difficult to apply guardrails to them or monitor their usage, and once weights are released they cannot be withdrawn2. But banning the use of these models by US businesses does nothing to address this risk, because bad actors are unlikely to be legitimate US businesses. It would protect US AI companies from competition, but that has never been my goal.

To address these concerns, I do support the following three measures, which I and Anthropic have consistently advocated for:

  • We should not sell powerful chips or chipmaking equipment to China, and we should crack down on the rampant smuggling3 and workarounds used to obtain access to such chips. China has limited domestic production capacity, and therefore, due to the scaling laws, cannot build more powerful models than the US without US chips. This is the most efficient and direct way to block threat #1, and by hampering the training of models that are out of reach of US law, it also indirectly helps with threat #2.
  • We should crack down on industrial-scale distillation operations. Distillation is a much more compute-efficient process than training models from scratch. It allows China to build much better models than its number of chips would ordinarily enable, and thus partially evade chip bans. Distillation does not allow the CCP to obtain equivalent or superior AI capabilities to the US, but it can bring the Chinese frontier to within a few months of the US frontier. It is true that many of the companies carrying out these operations release open-weights models—but the open weights are far less relevant than the fact that the operations are backed by an authoritarian state seeking to overtake the US at the frontier. We should have policy interventions to deter this behavior. A blanket ban on open-weights models is neither the correct remedy nor something we have called for4.
  • All sufficiently capable models, open and closed, should go through mandatory safety testing. The best way to address threat #2 is to just directly test models for cyber, biological, and alignment risks before release. I think this idea is actually close to a consensus: I have been heartened both that the Trump administration has moved in this direction in recent months, and by recent industry proposals that would apply such testing to the most capable models regardless of their country of origin or whether they are open or closed (while exempting less capable models, such as those from startups and academia, entirely). Whether open models do or don’t pose an increased risk, and whether that risk can be mitigated, is something that should emerge from testing, rather than be decided in advance—and there may be promising methods for improving the safety of open-weights models, including recent research from Anthropic on modular training strategies. Note that to be effective, testing would need to be global, which means even the CCP would need to be on board. I think this may actually be possible: as I wrote in The Adolescence of Technology, limited cooperation around preventing AI biological weapons may be possible because it is in China’s interest too.

This brings me to the open letter. I agree with much of it: open weights expand access to the AI economy, they strengthen competition at least for some use cases, and they give customers greater control. Concerns about distillation should be addressed through targeted legal and commercial frameworks—the same measure I described above. But I don’t agree with the letter’s assertions that open-weights models necessarily make it easier to develop safeguards or that broad access to capabilities necessarily helps defenders more than attackers. It seems at least as likely to me that the opposite will be true. For example, I worry that biology will have a strong attacker-defender asymmetry, where sufficiently capable models may be able to quickly weaponize pandemic-level viruses with widely available materials, whereas defense against these agents is a multi-year operational task in the best case (as we saw with Operation Warp Speed)5. Questions like this should be empirically answered by rigorous pre-release testing, not assumed in advance.

To summarize my and Anthropic’s position, we have not and are not advocating for a ban on open-weights models as a category. We should instead focus on keeping powerful chips out of authoritarian hands, stopping industrial-scale distillation, and requiring safety testing of all sufficiently capable models, open and closed.

Footnotes

  1. See Sections 3 and 2 of that essay for discussion of misuse for seizing power and discussion of biological risks, respectively.
  2. See this report from the UK AI Security Institute, specifically: “The same openness underpinning these benefits precludes many of the safety measures that closed model developers can use to detect and disrupt misuse, iterate on safeguards as vulnerabilities emerge, control user access and withdraw models. Once open-weight models are released, these options are lost permanently: safeguards can be removed, and copies can be downloaded, redistributed, and run on private systems beyond monitoring. For models with dangerous capabilities – including highly cyber-capable models – open weight release therefore creates a persistent and irreversible risk of misuse.”
  3. See also here, here, and here for more reports from the US Department of Justice.
  4. At Anthropic we’re committed to cracking down on industrial-scale distillation through our own practices, including identifying and banning accounts that use our models in this way. This is challenging—for instance, the relevant accounts can often only be identified after substantial distillation has occurred, and distillation often involves creating large numbers of fake accounts that form a moving target. The practices of any individual company cannot entirely solve the problem, which is why we have called for policy on this issue.
  5. See Section 2 of The Adolescence of Technology for a more detailed discussion of biological threats and the offense-defense balance. To summarize, what I believe currently keeps us safe in biology is not “defenders”, or even the availability of materials, but a negative correlation between intellectual capability and desire to commit catastrophic harm. Previous technologies like internet search or even DNA synthesis were nowhere near powerful enough to break this correlation, but I worry that at its current rate of progress, AI will do so very soon. Another way to say it is that a sufficiently powerful technology removes all barriers and exposes whether the attacker or defender has an inherent structural advantage, and I worry in biology it is the attacker.

원문 출처