US Leadership on Open-Weight Models is Key to Global AI Safety
Simon Hedlin / Sep 24, 2026
President Donald Trump and China's President Xi Jinping watch a flyover during a military review in the Rose Garden of the White House, Thursday, Sept. 24, 2026, in Washington. (AP Photo/Jacquelyn Martin)
As President Trump opens the White House doors to Chinese President Xi for a high-level bilateral summit beginning today, AI safety is top of mind for many policymakers, industry professionals, and experts—as we’ve heard all month. But there is a critical question that has received surprisingly little attention: what should the US government do about ever-advancing open-weight models?
Open-weight models are models whose weights, or numerical parameters, are released publicly. That means anyone can download and modify the models. Some open-weight models require specialized hardware to host, while others are small enough to run on a personal device. Currently, most of the capable open-weight models—including GLM 5.3, Kimi K3, DeepSeek V4.1-Flash, and Qwen3.8—are Chinese. Open-weight models generally lag the best American closed-weight models, but the gap is narrowing. The UK government’s AI Security Institute estimated in July that leading open-weight models’ cyber capabilities are only four to seven months behind those of the best closed models.
From an AI safety perspective, open-weight models present unique challenges. Because anyone can download open-weight models, users can often easily remove the guardrails that are meant to prevent people from using AI to hack others or build a bioweapon. And once a model has been downloaded, the developer cannot recall it, meaning that there is no “kill switch.” Some argue that these features make open-weight models riskier. It might therefore be tempting for the US to prohibit open-weight models and cede the global open-weight market to China. Indeed, some AI safety experts predict that open-weight models will be banned “before too long.” But that would be a big mistake. Instead, the US should make it a national priority to develop safer open-weight models.
The US is uniquely positioned to improve the safety of the global open-weight ecosystem. America is already a leader in AI safety research; it has an enormous talent pool and hosts an estimated 75% of the world's computing capacity (safety research can require significant computational resources). America is better able to develop advanced methods for open-weight models for removing dangerous capabilities (like cyber and bio capabilities) and imposing guardrails that cannot easily be stripped out. The United States sharing new methods for safer open-weight AI with China would be akin to how it shared nuclear safety technology with the Soviet Union and later Russia. The US would also have the capacity to quickly disseminate novel safeguards to the rest of the world through new model releases. By one count, last year, the US developed 59 significant AI models compared with 35 models for China and only one each for France and the UK.
If the US were to abandon the global open-weight ecosystem, it would only worsen the safety risks, as Chinese open-weight models proliferate in other countries. And it cannot outcompete the Chinese models solely with closed-weight models, because open-weight models are often cheaper, and the ability to modify and self-host models appeals to enterprises and researchers who want to train AI in specific tasks and keep proprietary data on systems that they control. If the US does not lead on the safe development of open-weight models, there is a risk that China will distribute more dangerous models to every corner of the world, where they can be downloaded freely by malicious actors.
American open-weight leadership would also improve the prospects for the US and China to eventually cooperate on safeguarding and pacing new models. Open-weight models will likely require a different safety regulatory regime that accounts for the fact that users can modify the weights and developers cannot recall downloaded models. If both countries are developing frontier open-weight models, there is a symmetry that makes it easier to agree to mutual safety standards because the two governments’ commitments will be comparable. Having frontier open-weight models would also add to America’s credibility. If the US proposes a bilateral safety framework for open-weight models without having any models capable enough to be subject to the framework, the proposal risks being perceived as a pretext for kneecapping China’s AI industry.
So, what should America do to quickly build out its open-weight ecosystem?
Here are three ideas:
First, the federal government should make an advance market commitment for frontier open-weight models by American developers. The government would set objective criteria, including for performance and safety, and commit to paying a certain sum to labs that develop models that meet the criteria. The government only pays on delivery and does not take equity in the labs to preserve competition and limit conflicts of interest.
Some open-weight labs report having struggles to raise capital because the economics are viewed less favorably when the model weights are free. An advance market commitment could increase both private funding today and revenue in the future. But the federal investment needs to be large enough—to the tune of tens of billions of dollars.
Second, the government should build on its Genesis Open Models Initiative, which promotes open-weight models, and use procurement to give preference to secure and high-performing American open-weight models over closed models within agencies that benefit most from customized and self-hosted models.
Third, the leading closed-weight labs should consider selling distillation rights to American open-weight labs so the latter could pay to legally and directly train their models on the outputs of the best closed-weight models.
Skeptics may argue that the US should stay away from open-weight models for safety reasons. But ceding the global open-weight ecosystem to China would be far more dangerous.
Authors

