Anthropic CEO warned that open-source AI could become “very dangerous” as Western companies quietly switch to Chinese AI models
Anthropic CEO Dario Amodei cautioned Congress that releasing powerful AI models without centralized oversight could create irreversible risks. Nearly three years later, enterprises are increasingly adopting open-weight Chinese models that are closing the gap with America’s leading AI systems.
For years, the biggest debate in artificial intelligence centered on which company would build the smartest model. That conversation is changing. The new question is who, if anyone, can control it once it is released.
Long before Chinese open-weight models began challenging America’s AI leaders, Anthropic co-founder and CEO Dario Amodei stood before Congress to warn. Releasing increasingly capable AI models into the open, he argued, could create risks that developers could no longer contain.
At the time, frontier AI remained largely concentrated inside a handful of U.S. companies. Today, that assumption is fading. Chinese-developed models, including DeepSeek, Qwen, Kimi, and GLM, are gaining traction across global enterprises, offering lower costs and competitive performance at a time when businesses are struggling with soaring AI infrastructure expenses. The result is an industry moving in the opposite direction of the caution Amodei urged lawmakers to consider.
A video of Amodei’s testimony before the Senate Judiciary Committee on July 25, 2023, resurfaced on X after being shared by Coin Bureau under the headline, “ANTHROPIC CEO: OPEN SOURCE AI IS GETTING DANGEROUS.” His remarks are drawing renewed attention as open-weight AI models continue to improve and spread across the industry.
Speaking before lawmakers, Amodei drew a distinction between smaller open-source models and increasingly capable frontier systems.
“Open source is a good thing. It accelerates progress, and I think even within AI there’s room for models on the smaller and medium side. I don’t think anyone thinks those models are seriously dangerous. They have some risks, but the benefits may outweigh the costs. And to be fair, even up to the level of the open source models that have been released so far, the risks are relatively limited. So, construed very narrowly, I’m not sure I have an objection.”
His concern centered on the direction of open-source AI development, an area currently dominated by Chinese AI companies, rather than on the technology itself.
“But I’m very concerned about where things are going. If we talk about two to three years for the frontier models, for bio risks, and probably less than that for things like misinformation, where we’re already there now, I think the path that things are going in terms of the scaling of open source models is a very dangerous one. And if that path continues, I think we could get to a very dangerous place.”
Amodei explained that companies operating closed AI systems can respond when models are abused. They can revoke access, update safety systems, adjust model behavior, and introduce new safeguards. Openly released models present a different challenge.
“When you control a model and you’re deploying it, you have the ability to moderate usage. It might be misused at one point, but then you can alter the model, revoke a user’s access, or change what the model is willing to do. When a model is released in an uncontrolled manner, there’s no ability to do that. It’s entirely out of your hands.”
He urged lawmakers to recognize the distinction between traditional open-source software and the release of frontier-scale AI systems trained with hundreds of millions of dollars in computing resources.
“Open source normally refers to smaller developers who are iterating quickly, and I think that’s a good thing. But what we’re talking about here is something a little different: the uncontrolled release of much larger models by big entities that pay tens or even hundreds of millions of dollars to train them. I think we should treat those in a somewhat different category, with different obligations.”
The market is moving in the opposite direction
Nearly three years after that testimony, many enterprises are making decisions that would have seemed unlikely at the time.
Large organizations are quietly adding Chinese AI models to production workloads to reduce operating costs. The shift is being driven less by model quality than by economics.
Running autonomous AI agents across software engineering, customer support, research, and internal operations consumes enormous amounts of compute. Per-token prices have declined across the industry, yet total AI spending continues to rise as businesses deploy more agents, process larger datasets, and automate more workflows. Economists describe this pattern as the Jevons Paradox, where lower unit costs lead to much higher overall consumption.
That economic pressure is pushing companies beyond the traditional U.S. AI ecosystem. Instead of relying exclusively on models from OpenAI, Anthropic, and Google, some Western companies are quietly switching to Chinese AI models, including DeepSeek, Alibaba’s Qwen, Moonshot AI’s Kimi, and Z.ai’s GLM family.
The performance gap has narrowed at the same time.
According to reporting by The Information and The Wall Street Journal, Z.ai’s new GLM-5.2 open-weight model has demonstrated cybersecurity capabilities comparable to Anthropic’s Mythos model in vulnerability discovery and bug-finding evaluations. The 744-billion-parameter mixture-of-experts model performs strongly on repository-scale coding tasks and can approach the performance of leading U.S. systems on selected security benchmarks after additional instruction tuning.
Unlike proprietary frontier models, GLM-5.2 is downloadable and modifiable, making advanced capabilities available to researchers, developers, businesses, and anyone else who chooses to run the model.
That is precisely the type of future Amodei described during his Senate testimony.
His warning was never that open source itself is inherently dangerous. His concern was that once frontier AI systems become widely available without centralized oversight, developers will lose the ability to update safeguards, revoke access, trace misuse, or respond after deployment.
The debate has only grown more relevant since those remarks were delivered. AI companies continue to build larger and more capable models. At the same time, open-weight systems are becoming more powerful, less expensive, and easier to deploy worldwide.
Whether that trend leads to broader innovation, greater security risks, or a mix of both remains one of the defining questions facing the AI industry today.
Watch Dario Amodei’s full testimony before the Senate Judiciary Committee on AI oversight and regulation, delivered on July 25, 2023. The hearing provides the full context behind his remarks on open-source AI and the governance challenges posed by increasingly capable frontier models.

