The ban he was assumed to want

On 27 July Anthropic published its position on open-weights models, and the first thing it does is refuse the argument its critics had assigned to it. Dario Amodei writes that Anthropic has never advocated for a ban on open-weights models. Models released without dangerous capabilities, the position holds, are useful to businesses, developers and researchers at little cost beyond the compute to run them. On proposals to bar Chinese open-weight models specifically, he is blunter still: protectionist bans would not address the national-security concern he actually has.

The timing sharpens it. Three days earlier, twenty-five US technology companies had written to Congress asking it to avoid premature restrictions on open weights, a letter on which Anthropic did not appear among the named signatories. The company has now answered the same question in its own document, and the answer is neither the industry's nor the restrictionists'. It is a third position, and the third position is the one with consequences for anyone operating in Europe.

Three asks, and only one is about weights

The position makes three recommendations. Do not sell powerful chips or chipmaking equipment to authoritarian states, and pursue the smuggling routes that move them anyway. Crack down on industrial-scale distillation, the practice of training a cheaper model on a stronger one's outputs, which Amodei argues lets a rival build better models than its chip supply should allow. And subject all sufficiently capable models, open and closed alike, to mandatory safety testing before release, covering cyber, biological and alignment risks.

Notice what the middle ask does to the first one. If distillation can close a capability gap in months, then the download is not the control point and never was. Restricting who may publish weights does little when the capability can be reconstructed from the outputs of a model anyone can call through an interface. That reasoning moves the enforcement surface off the download and onto terms of use, which is a far more mundane place, and a far closer one to where an ordinary company sits.

Europe switches the same idea on in five days

Read the third ask against the European calendar and the argument stops being hypothetical. Obligations on providers of general-purpose AI models have applied under the AI Act since August 2025, but the Commission's powers to supervise and enforce against those providers commence on 2 August 2026. From that date the Commission can request documentation, conduct its own evaluations of a model, demand compliance measures, restrict a model on the market, order recall or withdrawal, and levy fines of up to 15 million euros or 3 percent of worldwide annual turnover. Providers of models designated as carrying systemic risk carry further duties, including model evaluation and reporting of serious incidents.

That is, structurally, the regime Anthropic is asking Washington to build. The difference is that the American version is a proposal in a company blog post and the European version is an enforcement power that switches on next Sunday. For an owner in Frankfurt, Milan or Manchester, the practical reading is not that a testing regime is coming. It is that you are already inside one while the debate about whether to have one continues on the other side of the Atlantic.

Where an owner actually gets caught

The trap is not the fine, which lands on providers rather than on the companies using their models. The trap is the boundary between the two. Under the AI Act the obligations attach to the provider of a general-purpose model, and a company that takes open weights and fine-tunes them substantially can become a provider of that modified model in its own right. The move most owners make for the soundest possible reason, self-hosting an open model to escape a vendor's pricing and lock-in, is precisely the move that can shift them from user to regulated party. Nobody sends a letter when this happens.

So do two things before the date passes. Put a written question to every vendor supplying you a general-purpose model, asking whether it treats itself as a provider under the Act and whether its model is designated as carrying systemic risk, since that answer determines what documentation you can demand and what happens to your service if the Commission restricts the model. Then look at your own fine-tuning. If your team has adapted downloaded weights and put the result into production, establish now whether you have crossed into provider territory, because the honest answer is easier to act on in July than to explain later.