Trump Officials Quietly Shift on Open AI Models as Chinese Releases Force a Policy Reckoning

The Trump administration has spent months hammering out rules for the most powerful artificial intelligence systems. What began as a closed-door effort aimed squarely at proprietary models from a handful of U.S. giants now shows signs of widening. Officials plan to bring certain open models under the same secretive pre-release review process. The move reflects fresh anxiety that American leadership could slip if Washington ignores rapidly advancing systems from China.
Earlier this month the framework looked straightforward. It would cover only closed-source models judged to possess state-of-the-art capabilities and national security risks. The entire document would stay hidden from the public, shared only with the companies expected to submit their work. Axios first reported the details. Open models received an explicit exemption. Nothing in the text should be read as restricting them once released, sources told the publication.
That exemption no longer feels permanent. Gizmodo revealed Wednesday that expansion is underway. The administration worries that blessing only closed systems could damage the reputation of open alternatives and discourage U.S. firms from publishing weights. Recent Chinese breakthroughs have sharpened the debate. Moonshot’s Kimi K3, an open model, matched or beat several leading closed offerings from American labs on cost and performance. The episode triggered what some called a freak-out across the industry.
Executives responded with a public letter titled “Open Weights and American AI Leadership.” Signers included Meta, Microsoft, Palantir and, after initial hesitation, OpenAI CEO Sam Altman. They argued that closed models are not inherently safe. Restricting open systems would hand China an advantage in the global race. Nvidia CEO Jensen Huang went further. He posted on X for the first time on the subject. “Open models strengthen safety and cybersecurity, accelerate innovation and diffusion, and enable sovereignty,” Huang wrote. “The world needs both frontier closed models and frontier open models.” The chipmaker also helped form the Open Secure AI Alliance to promote open-weight development.
Anthropic stayed out of the letter. CEO Dario Amodei pushed back against accusations that the company favored tighter rules to protect its closed-model business. The firm had clashed publicly with the administration earlier. Yet its absence fueled suspicion among open-model advocates.
The original framework emerged from a June executive order. It requires companies to submit certain frontier models for up to 30 days of government review before public release. Testing focuses on cybersecurity risks. Models would sit in high-security environments with strict access logs. Multiple agencies, not one office, would participate. Benchmarks used in the process remain classified.
During a Tuesday meeting with staff from OpenAI, Anthropic, Google, Meta, Nvidia and Microsoft, White House officials laid out the initial plan. The New York Times described the session. Only closed models faced scrutiny. Open-source code available for anyone to download and modify would sit outside the process, at least for now. The approach aimed to give the government influence over the most dangerous capabilities without choking off broader progress.
But the ground shifted quickly. The Wall Street Journal noted the exemption for U.S. open-weight models made by domestic companies. Critics immediately warned that the carve-out created blind spots. Chinese open models circulate freely among U.S. startups and enterprises. They receive no independent safety checks under current rules. A piece published hours ago by Tech Policy Press called the exclusion short-sighted. It gives Beijing an incentive to push open systems while the U.S. ties its own hands.
Advocates for open models point to concrete gains. Weights released publicly let researchers, smaller firms and even foreign allies inspect, improve and secure the technology. Proponents say this collective scrutiny beats any single company’s internal safety team. Yet the same openness raises fears. Once a model leaves the lab, no one can yank it back. Malicious actors or rival states can fine-tune it for offensive cyber operations, disinformation or autonomous weapons.
The administration’s hesitation speaks volumes. It wants the benefits of rapid American innovation. At the same time it dreads ceding control over systems that could reshape national power. The framework’s voluntary label masks real pressure. Companies understand that refusal could invite export controls or other penalties. The Center for American Progress described the setup as a de facto licensing regime operating in near-total secrecy. It determines who sees models early, which partners gain privileged access and when releases occur.
Uncertainty surrounds the exact threshold. No public definition exists for “state-of-the-art” or “national security risk.” That vagueness leaves room for case-by-case judgment. It also invites lobbying. Larger labs with resources to navigate the process may gain an edge. Smaller players and open-source communities risk being frozen out or forced to seek trusted-partner status they cannot easily obtain.
Balancing Innovation Against Unseen Dangers
Industry leaders have made their case directly to the White House. They warn that over-regulating open systems would slow diffusion of useful tools across the economy. Defense contractors, universities and startups all benefit from accessible models. Sovereignty arguments carry weight too. Nations that control their own AI infrastructure avoid dependence on a few cloud providers. Huang’s coalition pushes exactly this vision.
Yet safety voices refuse to yield. They note that open weights lower the barrier for bad actors. A sophisticated terrorist group or rogue state needs far less infrastructure to weaponize a downloaded model than to train one from scratch. The framework’s focus on cyber capabilities underscores the point. Advanced systems can already discover novel vulnerabilities, chain exploits and operate autonomously. When those abilities spread without review, the risk profile changes.
The administration appears to be threading the needle. Keep the core framework intact for the biggest closed models. Add open systems only when they demonstrate frontier-level performance. The approach buys time. It signals seriousness to critics while avoiding immediate damage to the open-model movement that many U.S. executives now champion.
But time may be short. Chinese labs show no sign of slowing. Each new competitive release increases pressure on Washington to either tighten controls or accept higher risk. Policymakers must decide where the line sits between abundant intelligence available to anyone with a graphics card and guarded capability reserved for institutions the state can oversee.
That choice will shape more than AI development. It will influence who holds cognitive power in the coming decade. Private actors with local, irrevocable models gain a form of sovereignty historically reserved for governments. The modern regulatory instinct is to push such power back into accountable channels. Whether open models can be reviewed without destroying their advantages tests the limits of that instinct.
So far the Trump team has kept its criteria, test results and exact decision process hidden. The public sees only the contours. Expansion to open models marks a pragmatic adjustment. It acknowledges reality on the ground. Chinese models are here. American ingenuity produced the open-weight idea. Now Washington must figure out how to live with both without losing the race or the peace.