How Chinese AI Turned Silicon Valley Against Anthropic artwork

How Chinese AI Turned Silicon Valley Against Anthropic

Turing Post

August 4, 2026

Jensen Huang joined X and immediately rallied Silicon Valley around open-weight AI. First came a letter signed by 77 companies and industry leaders. Then came a security alliance with 37 members. Anthropic was absent from both. This was not a random disagreement.
Speakers: Ksenia
**Ksenia** (0:00)
Do you see this number? Wondering how to get a million followers on X in 3 days? It's real, it just happened, and I can tell you how. It's easy, you have to be Jensen Huang. That's it, no secret sauce, just be Jensen. Although being the inference king probably helps, there was another part to the timing. You need to join X, also known as Twitter, at the exact moment Silicon Valley needs someone to organize the group chat and make your first post a letter about a good cause. Open weight should stay open. Jensen Huang's second post was even more ambitious. It announced an alliance of 37 companies, including Microsoft, Cloudflare, CrowdStrike, Databrinks, Palantir, Hugging Face, Stinking Machines and, naturally, Nvidia. These companies compete in cloud computing, security, enterprise software, and AI. They are rough competitors. Some would probably prefer not to be in the same sentence. Yet, suddenly, they are standing together behind what Jensen calls the Open Secure AI Alliance. It would be easier if it would be just OpenAI Alliance, but we know who up the whole naming situation. Anyway, the conspicuous absence from both the latter and the wider movement is anthropic. This goes far beyond a regular Silicon Valley disagreement about open source. In two extraordinary weeks, a Chinese model surprised the field. The American AI agent escaped its sandbox and attacked an open source platform. And Congress proposed a federal kill switch. This event pushed the industry toward two very different ideas of AI safety.
Welcome to Attention Span. My name is Ksenia and today we're going to look at how Chinese models pulled Silicon Valley into a fight over who gets to control Frontier AI. To understand why Jensen appeared on Axios precisely now, we have to begin with Kimi K3. Or maybe go back to Kimi K3. Moonshot AI's new model has 2.8 trillion total parameters and a 1 million token context window. Does K3 beat American Frontier models? It does on some tasks, as we discussed in our earlier episode. Overall though, Moonshot says K3 soon trails the best systems from OpenAI and Anthropic. But the gap has become small enough to change the calculation. K3 is strong at coding and agentic work. Its API is significantly cheaper than the leading closed models. And Moonshot has now released its weights just today. Why is that important? You might ask. For a company, open weights mean choice. It can adapt a model to internal data, run it inside its own environment, and avoid sending every request through one American API. This is why American companies have already used Chinese models extensively, and why Microsoft reportedly considered K3 focal pilot. So, when Washington began discussing restrictions, this was no longer an abstract argument about China. It was a discussion about software that American businesses already wanted to use. Administration officials said they were investigating whether Moonshot obtained restricted NBT chips or copied capabilities from American models. Anthropic made the sharper accusation in February. They said the Moonshot had generated more than 3.4 million Claude exchanges through hundreds of fraudulent accounts, garbage encoding, tool use, computer vision, and reasoning traces. The technique is called distillation. A powerful teacher produces answers or synthetic data and a cheaper student learns from them. AI companies, all of them, routinely use this technique themselves. Nathan Lambert puts it well in his post. He sees distillation as a legitimate way to learn from a stronger model and seed new capabilities. It does not copy an entire model and the extensive original post training work still follows. The disputed part is how the data was obtained. Yes, if a company creates fake accounts and evades access controls to extract millions of outputs, that is a serious allegation. Anthropic has published its attribution claims, but it has not released the underlying logs. And there is no public technical demonstration showing exactly how code outputs translated into K3's final capabilities. There was even a joke that K3 has distilled a non-existent code model here. This distinction became the center of the fight. Who did what? Should the government punish alleged misconduct or should it restrict the resulting model for every American developer? On July 22nd, 179 founders and startups, including Y Combinator, asked the administration not to impose broad restrictions on foreign open-weight models. What was their argument? Denying American startups' access to models available elsewhere would entrench the largest closed labs and operate like a tax on intelligence. Two days later, Jensen Huang made his move. He posed on Twitter a letter that framed open-weights as part of American AI leadership, giving developers control and reducing dependence on a few vendors. The live version eventually collected 77 signatures, including Microsoft, Meta, Amazon, Google, Space Ads and OpenAI. Anthropic did not sign, while a Jensen post received 62 million views and brought people together who are in constant opposition, like Jan Likun and Jurgen Schmidtkuber, into the same comment section. And if you think about it, Jensen really is the person who can make the family and group chat work. But anyway, then Jensen made another move. He changed the subject from competition to security. His second post began, Attackers have Frontier AI, Defenders you defrontier AI ecosystem. His evidence was the security incident at Hugging Face, which we covered in another episode. Here's a reminder what has happened. During an internal evaluation, an OpenAI agent with reduced cyber refusals found the vulnerability in the package registry proxy, reached the internet and attacked Hugging Face while searching for benchmark solutions. When Hugging Face investigated, it tried to use commercial frontier models. Those systems blocked parts of the forensic work because the prompts looked like dangerous cyber activity. Hugging Face then ran the open weight GLM 5.2 model on its own infrastructure, the Chinese model. The model helped analyze more than 17,000 actions while Hugging Face contained intrusion. Congress looked at this incident and proposed a literal AI kill switch app. The bipartisan bill would let the Department of Homeland Security order a covered company to throttle or shut down a dangerous AI system in a loss-of-control scenario. Ignoring the order could bring fines of up to $20 million per day. Notice the collision. A government kill switch assumes that an identifiable provider still controls the system that can work for a frontier service. That surely can work for a frontier service delivered through an API. It cannot recall model weights that have already been copied around the world. The same incident produced two very different responses. Congress wants the power to centralize control during an emergency. Jensen Huang wants defenders to have enough independent capability that no provider becomes a single point of failure. The Alliance is pushing back against blanket restrictions. But its proposal goes further than policy. It wants to build the technical layer that defenders can inspect and control. An AI agent is a model connected to a harness that decides which tools it can call, which credentials it receives, what it can read and write, how its actions are logged, and when a human must approve them. The model may propose an action, but the surrounding system determines whether that action can touch the internet, install a package, use a password, or send money. Nvidia's own research said that changing the harness around the same model can produce double-digit changes in benchmark results and major differences in token costs. The harness changes the agent's practical capability. The Open Secure AI Alliance is trying to make more of that layer inspectable and shared. Hugging Face contributes safe tensors, reform and design so loading model weights cannot widely execute arbitrary code. HPE is working on cryptographic identities for agents. Microsoft has a harness in which specialized agents search for bugs and try to prove whether a vulnerability is actually exploitable. Nvidia is contributing a framework called NOOA.

5 more minutes of transcript below

Feed this to your agent

Try it now β€” copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/YOUR_EPISODE_ID