Who Guards the Model?
Open-Weight Artificial Intelligence and the Problem of an Illiberal America.
Open Models, Closed Republic:
Artificial Intelligence and the Architecture of American Power.
The argument over open-weight artificial intelligence appears, at first glance, to be another technical dispute emerging from Silicon Valley: a quarrel over software architecture, commercial competition, intellectual property, and the proper regulation of a rapidly evolving technology.
But beneath the language of model weights, distillation, chips, safety testing, and frontier capabilities lies a much older political question.
Who should be trusted with power?
In late July, a coalition of major American technology companies—including Nvidia, Microsoft, Meta, IBM, Palantir, Hugging Face, and others—urged the United States government not to impose premature restrictions on open-weight AI models. The coalition argued that models whose trained parameters can be downloaded, modified, and operated independently are essential to American innovation, economic competition, scientific research, and technological leadership. Anthropic, one of the leading developers of closed frontier models, notably declined to sign.
The omission was immediately interpreted as evidence of a commercial divide. Companies invested in open ecosystems defended openness; a company whose most advanced systems remain accessible primarily through controlled corporate interfaces counseled greater restraint.
Anthropic’s chief executive, Dario Amodei, subsequently clarified that the company did not favor a general ban on open-weight models. Models without dangerous capabilities, he wrote, could be a public good. The more serious problem, in Anthropic’s view, was the uncontrolled diffusion of frontier capabilities that could assist hostile governments or malicious actors in cyber operations, biological weapons development, or other forms of catastrophic misuse. Rather than banning open-weight AI categorically, Anthropic advocated controlling strategic chokepoints: advanced computing chips, industrial-scale model distillation, and rigorous capability testing.
The position is more measured than many of Anthropic’s critics have suggested. It also contains a real and difficult truth. Once the weights of a powerful model have been released, they cannot meaningfully be recalled. They can be copied, fine-tuned, stripped of safeguards, hidden on private servers, and operated beyond the reach of the original developer. NIST has summarized the difficulty plainly: open-weight models are harder to monitor and, once distributed, effectively impossible to retract.
But Anthropic’s warning, and the broader policy debate surrounding it, rest upon an assumption that deserves much closer scrutiny. They tend to imagine the primary danger as one in which dangerous AI capabilities escape from responsible American institutions and fall into the hands of irresponsible outsiders: China, Russia, Iran, terrorist organizations, cybercriminals, or rogue proliferators.
That danger is real.
But it is not the only danger.
The more unsettling question is this:
What if the United States itself becomes an illiberal or authoritarian state—or develops a distinctly American hybrid form of authoritarian government?
What if the political authority deciding which models are safe, which actors may possess them, which viewpoints constitute extremism, which organizations are trustworthy, and which uses of artificial intelligence serve “national security” is no longer reliably constrained by constitutional norms, independent courts, congressional oversight, professional civil service, a free press, or meaningful electoral accountability?
At that point, the open-weight debate changes entirely.
The question is no longer merely how a democratic state can prevent dangerous technology from reaching authoritarian adversaries. It becomes how a democratic society can prevent its own technological infrastructure from being monopolized by a state that has ceased to behave democratically.
The Difference Between Open Source and Open Weight
An open-weight model is not necessarily an open-source model.
The distinction matters.
In conventional software, “open source” usually means that the underlying source code is publicly available under a license that allows inspection, modification, and redistribution. Artificial intelligence systems are more complex. They are products not only of software code but also of training data, computational infrastructure, model architecture, optimization methods, post-training procedures, safety interventions, and the resulting numerical parameters known as weights.
The OECD defines an open-weight model as a foundation model whose trained weights are publicly available. Those weights encode the model’s learned internal relationships. Possessing them allows a user to run the model on independent hardware, modify it, fine-tune it for specialized purposes, or integrate it into local systems without continuously relying on the original developer. But the user may still lack the original training data, complete development code, safety documentation, or the means to reproduce the model from the beginning.
A “closed model” operates differently. Users submit requests through an application or programming interface controlled by the developer. The company retains custody of the weights, determines who receives access, monitors usage, adjusts safeguards, changes prices, modifies model behavior, and can withdraw the service altogether.
This difference is not simply technical. It is constitutional in the broadest meaning of the word. It determines where power resides.
A closed model centralizes authority in the institution that owns and operates it. An open-weight model distributes capability among those who possess the hardware and expertise to use it.
Closed systems offer control, consistency, oversight, and the possibility of recall.
Open-weight systems offer autonomy, adaptability, inspectability, local ownership, and resistance to centralized interruption.
Neither architecture is inherently democratic. Neither is inherently authoritarian. But each creates a different political structure of dependency.
The Case for Caution
Anthropic is right to insist that openness is not an unqualified good.
A sufficiently capable model could be adapted to search for software vulnerabilities, automate cyber operations, generate persuasive disinformation, assist in the design of dangerous biological agents, or support sophisticated surveillance. Although current open-weight systems generally trail the most capable closed American models, the gap has narrowed. Recent U.S. government evaluations have found rapid improvement among Chinese open-weight systems, including Kimi K3 and GLM-5.2, even while those models remain below leading American systems on advanced cyber tasks.
Openness creates irreversibility. A company operating a closed model can suspend an account, patch a vulnerability, alter its safeguards, or shut down a service. The developer of an open-weight system cannot reliably impose such changes after release. A model copied onto thousands of machines becomes a durable feature of the technological environment.
Anthropic’s argument therefore resembles traditional nonproliferation logic. Certain capabilities may be so consequential that society should control not merely their use but their distribution. Nuclear weapon designs, advanced missile technology, pathogens, cryptographic systems, and semiconductor manufacturing equipment have all, in different ways, been subject to such thinking.
Yet artificial intelligence differs from most traditional strategic technologies. It is not merely a weapon or an industrial machine. It is becoming a general-purpose layer of social organization: a medium through which institutions process information, allocate resources, interpret law, educate citizens, conduct research, manage infrastructure, produce knowledge, and increasingly make decisions.
To centralize control over such a technology is therefore to centralize something approaching cognitive infrastructure.
And cognitive infrastructure is political power.
The Case for Openness
Open-weight models reduce dependence on a small number of corporations. They allow universities, local governments, hospitals, small businesses, nonprofit institutions, military units, researchers, and private citizens to operate AI systems on their own infrastructure. They can preserve sensitive data locally, develop specialized tools, test model behavior, conduct independent safety research, and continue operating even when a vendor changes its prices, policies, terms of service, corporate ownership, or political alignment.
The OECD has found that greater AI openness can lower barriers to experimentation, diffuse technical knowledge, expand participation, and improve opportunities for innovation.
Open-weight systems can also function as a form of strategic redundancy. A society dependent on three or four corporate models has created a small number of critical nodes. If those companies fail, merge, become politically captured, withdraw services, or align themselves with coercive government demands, much of the society’s AI capacity can be altered from the center.
A more distributed ecosystem is messier. It is also harder to command.
This is the paradox at the heart of the debate. The very quality that makes open-weight AI difficult to regulate—its decentralization—is also what can make it resilient against monopolization and political capture.
From the perspective of compound security, this is not a minor advantage. Resilient systems possess redundancy, diversity, substitutability, and multiple centers of adaptation. Fragile systems concentrate capacity in a small number of nodes and then assume those nodes will remain reliable.
America has made that assumption before.
The country entrusted essential public communication to privately governed social-media platforms. It consolidated cloud computing among a few firms. It allowed data brokerage, digital advertising, telecommunications, finance, and algorithmic information distribution to become concentrated in institutions that were powerful enough to shape public life but insufficiently accountable to democratic authority.
Artificial intelligence threatens to intensify this pattern.
A closed-model economy could leave the United States with a handful of corporations controlling the systems through which much of the nation thinks, writes, plans, teaches, analyzes, and governs.
Supporters of closed frontier models may respond that these corporations are more responsible than an uncontrolled global marketplace.
Perhaps they are.
But a durable constitutional order cannot be designed around the hope that powerful institutions will always be led by responsible people.
The Missing Threat Model
Much of American AI policy is built around an externalized threat model.
The dangerous actor is imagined as foreign: an authoritarian rival, hostile intelligence service, sanctioned corporation, terrorist network, or criminal organization.
The American state, by contrast, is assumed to be the responsible regulator—the institution standing between dangerous technology and dangerous users.
That assumption reflects the traditional logic of national security. The state protects the political community against external threats.
But liberal constitutionalism begins from a different insight: the state is itself a potential threat.
The Constitution does not assume that American officials will always be virtuous. It divides power because they may not be. It protects speech because government may suppress it. It requires due process because authorities may accuse unjustly. It protects against unreasonable searches because officials may convert legitimate investigative powers into instruments of domination.
The American constitutional system was designed not merely to enable government but to mistrust it.
AI policy must incorporate the same wisdom.
An administration moving toward illiberal authoritarianism would not necessarily abolish elections, dissolve Congress, suspend the Constitution, or declare a dictatorship.
An American authoritarianism would more likely emerge through legal forms and administrative mechanisms. It could preserve the outward architecture of democracy while hollowing out its constraining substance.
It might politicize law enforcement.
It might define dissent as extremism.
It might use emergency authorities as routine instruments of governance.
It might pressure private companies to restrict disfavored speakers.
It might replace professional civil servants with ideological loyalists.
It might expand surveillance in the name of border security, public order, counterterrorism, election protection, or national unity.
It might use regulatory power to reward aligned firms and punish resistant ones.
It might preserve elections while manipulating the information environment, the rules of participation, or the institutional machinery through which electoral outcomes are certified and enforced.
Such a system would not necessarily resemble twentieth-century totalitarianism. It would be digital, privatized, legalistic, data-driven, and selectively coercive. It would operate not by controlling every citizen at all times but by possessing the capacity to identify, isolate, intimidate, discredit, economically disable, or administratively burden those who become politically inconvenient.
Artificial intelligence would be ideal for this form of power.
AI can make censorship, surveillance, disinformation, and political profiling easier, faster, cheaper, and more scalable. Freedom House has documented how governments already employ AI to strengthen censorship systems and automate forms of digital repression. Its most recent global assessment warns that authoritarian investment in sovereign AI may accelerate surveillance, censorship, and efforts to isolate populations from the open internet.
There is no reason to believe the United States is metaphysically immune from these temptations.
Indeed, the most dangerous AI system in an illiberal America might not be an open-weight model circulating among private extremists. It might be a closed, highly capable model operated through a public-private partnership between the federal government and a politically compliant technology corporation.
Such a system could integrate immigration records, financial data, social-media activity, geolocation histories, facial recognition, government benefits, tax information, employment records, security-clearance files, political speech, and predictive behavioral analysis.
Its safeguards could be changed centrally.
Its audit logs could be arbitrarily classified.
Its definitions of threat could be modified by executive instruction.
Its services could be denied to disfavored institutions.
Its underlying decisions could remain protected as proprietary corporate information or matters of national security.
And because the system would be closed, citizens, journalists, researchers, defense lawyers, state governments, and civil-society organizations might have no meaningful ability to examine its operation.
In such a world, centralization would not guarantee safety. It would guarantee control.
The only question would be who exercised it, … and against whom?
The Sovereignty Paradox
Open-weight advocates often speak of “AI sovereignty”: the ability of a country, organization, or community to operate artificial intelligence without dependence on foreign or corporate providers.
Governments understandably value this capacity. A state that controls its own model can preserve sensitive information, tailor systems to national priorities, and protect itself from foreign interruption.
But sovereignty belongs not only to states.
Institutions need sovereignty.
Universities need intellectual autonomy. News organizations need editorial independence. States and municipalities need protection against coercive federal dependence. Businesses need continuity. Citizens need spaces for inquiry, association, and expression that cannot be switched off by administrative order.
The freedom to run a model independently may therefore become a component of civil society’s autonomy from centralized power.
This does not mean that every frontier model should be released without restriction. It means that the distribution of AI capability must be evaluated not only against the risk of misuse by private actors, but also against the risk of monopolization by governments and dominant firms.
A policy that prevents every possible misuse by citizens by giving the state exclusive control over advanced cognition would solve one danger by institutionalizing another.
A free society cannot define safety solely as the government’s ability to prevent unauthorized action.
It must also define safety as the citizen’s ability to resist unauthorized government.
Anthropic’s Chokepoints—and Their Double Edge
Anthropic recommends focusing regulation on advanced chips, large-scale distillation, and frontier capability evaluations rather than on open-weight models generally. As policy, this has considerable merit. These interventions target the production of highly capable systems without outlawing openness as such.
But chokepoints are never neutral.
Whoever controls a chokepoint gains leverage over the system that depends on it.
Chip controls intended to prevent foreign proliferation can also determine which domestic institutions are permitted to train or operate advanced models.
Licensing regimes can become tools of political favoritism. Safety evaluations can become ideological tests. Definitions of dangerous capability can quietly expand from biological weapons and cyberattacks to disinformation, extremism, civil disorder, threats to public confidence, or speech alleged to undermine national stability.
The problem is not that such abuse is inevitable. The problem is that a serious governance system must assume it is possible.
Every restriction placed upon open AI therefore needs a civil-liberties counterpart.
If the government restricts access to compute, the criteria must be transparent and judicially reviewable.
If frontier models are licensed, licenses cannot be granted or withheld according to political loyalty.
If models are evaluated for dangerous capabilities, the standards must focus on demonstrable operational harm rather than lawful political expression.
If companies cooperate with intelligence or law-enforcement agencies, those relationships require statutory limits, independent oversight, auditability, and meaningful remedies for abuse.
If emergency access is created, it must expire.
If models are used to classify individuals as threats, citizens must possess rights of notice, challenge, and appeal.
If the state deploys AI against the public, the public must not be told that the system is too proprietary, too classified, or too complicated to question.
These are not ancillary concerns. They are the democratic content of AI safety.
Beyond the False Choice
The open-weight debate is often presented as a choice between innovation and security.
That framing is inadequate.
The true problem is one of architectural balance.
A fully closed AI ecosystem would create dangerous concentrations of economic, informational, and governmental power. A completely unrestricted frontier ecosystem could distribute capabilities with catastrophic potential to actors who cannot be monitored or deterred.
The United States therefore needs neither absolute openness nor absolute closure. It needs a layered system that distinguishes among capabilities, uses, actors, and levels of risk.
Models below clearly defined high-risk thresholds should presumptively remain open to research, local deployment, modification, and commercial use.
Frontier models demonstrating specific, reproducible capabilities for catastrophic harm should be subject to stronger controls before release.
Independent researchers should receive protected access for auditing, including secure pathways to examine closed systems.
Public agencies using AI in consequential decisions should face stricter transparency requirements than private citizens experimenting with general-purpose models.
No single corporation should become an indispensable provider of cognitive infrastructure to the federal government.
Government agencies should be required to maintain technological diversity and fallback capacity rather than becoming dependent upon one company or model family.
Open-weight public-interest models should be supported for education, scientific research, local government, health, emergency management, and other civic applications.
Most importantly, AI governance should be designed through a dual-threat framework.
The first threat is misuse from below: criminals, terrorists, hostile states, reckless developers, and private actors employing AI to cause harm.
The second is misuse from above: states and corporations using concentrated AI power to surveil, manipulate, exclude, punish, or dominate.
A serious democratic policy must defend against both.
The Regime Question
Technology does not enter politics from outside. It acquires the character of the regime that controls it.
The same database can administer social benefits or identify dissidents.
The same facial-recognition system can locate missing children or track protesters.
The same language model can improve public services or automate ideological censorship.
The same national-security platform can defend a constitutional republic or help dismantle one.
This is why the political character of the United States cannot be treated as a fixed constant in the AI equation.
American policy frequently assumes that technology controlled by the United States is safer than technology controlled by China simply because the United States is democratic and China is authoritarian. As a comparative judgment, that remains meaningful. But as a permanent planning assumption, it is dangerously complacent.
Regimes change.
Institutions decay.
Norms weaken.
Emergency powers migrate into ordinary government.
Public-private partnerships deepen without public scrutiny.
Officials redefine exceptional authorities as inherent executive powers.
Political opposition becomes associated with disloyalty, disorder, subversion, or national decline.
No country receives an eternal democratic exemption from history.
If the United States becomes its own form of illiberal authoritarian state, it will not need to import a foreign model of repression. It will build one from American materials: constitutional ambiguity, executive power, privatized technology, corporate concentration, data brokerage, national-security secrecy, partisan media, administrative discretion, and a public conditioned to exchange liberty for protection against a succession of declared emergencies.
AI could bind those elements together.
That is the scenario missing from much of the present debate.
Anthropic asks, reasonably, what happens when powerful American models reach hostile authoritarian states.
A democratic society must also ask what happens when powerful American models remain at home—and the authoritarian state comes to them.
The Bottom Line
Anthropic’s intervention should not be dismissed as simple corporate self-interest. The company has identified a genuine problem: once highly dangerous AI capabilities are openly distributed, society may lose the ability to contain them.
But the open-weight coalition has identified an equally genuine danger. A nation that concentrates AI capability inside a few firms and federal institutions may gain control at the cost of adaptability, competition, autonomy, and democratic resilience.
The deepest issue is not whether models are open or closed.
It is whether the architecture of artificial intelligence disperses power or concentrates it; whether it creates redundancy or dependence; whether citizens and institutions can inspect and contest the systems governing them; and whether safeguards designed for a liberal democracy would become instruments of control in an illiberal state.
AI policy cannot be founded upon a single faith: that the American government will always be constitutional, that American corporations will always be responsible, or that the alliance between them will always serve the public good.
The framers did not build the republic upon such faith. They built it upon divided power, institutional rivalry, procedural restraint, public accountability, and the presumption that authority must be checked because human beings are fallible and power is corrupting.
The same realism must now be applied to artificial intelligence.
Open-weight models carry risk because they can escape control.
Closed models carry risk because they may never escape it.
The task is not to choose one danger and deny the other. It is to construct an AI order in which no foreign adversary, private corporation, president, political party, intelligence agency, or technological priesthood can acquire uncontestable command over the cognitive infrastructure of the republic.
The question is not merely whether America will lead the age of artificial intelligence.
It is what kind of America will possess that power—and whether the people will retain any meaningful power of their own.
If you value this work, here are three ways you can step into the story with us:
📰 Subscriber (Free)
Stay informed. Receive every new essay, briefing, and analysis straight to your inbox. Join a growing community committed to civic resilience and national security.
🎧 Supporter (Paid Pledge)
Strengthen the signal. Your support sustains both Compound Security, Unlocked and our companion podcast The Civic Brief. Supporters ensure these conversations remain accessible to the wider public while elevating the quality, depth, and reach of the work.
🛡️ Sustainer (Patron Level)
Invest in the mission. Sustainers fuel new research, convenings, and storytelling that enlarge the civic frame of security. This is more than content — it’s a civic project. Your sponsorship helps preserve an independent voice committed to equipping citizens, leaders, and institutions for the compound challenges ahead.



