6 months to live for open models
- title
- 6 months to live for open models
- type
- summary
- summary
- Lambert predicts a US ban or delay on frontier open weights by early 2027, calls Anthropic's distillation campaign regulatory capture, and proposes off-ramps
- tags
- ai, open-weights, open-source, policy, china, distillation, anthropic, security
- created
- 2026-09-14
- updated
- 2026-09-14
Nathan Lambert published "6 months to live for open models" on Interconnects on July 12, 2026. It is the most urgent of his policy pieces, and it opens by saying so: he has watched many waves of anti-open-source rhetoric since ChatGPT, but none of the earlier ones came with a working enforcement mechanism already being applied to closed models. This one does, and he commits to far more policy writing until it passes. His open-source-ai-reading-list summarizes the argument as vague federal oversight, "vibe regulation", setting up a clash with or ban of frontier open models in the near future.
The mechanism already exists
The setup is the licensing process the government ran for closed models: Fable, then GPT-5.6. At a June 9 meeting about that program, according to reporting Lambert quotes, a representative of Reflection AI argued that open models should be exempt based on their capabilities. The same report noted that Chinese open models like DeepSeek had a substantial lead over other open models and that Reflection had not launched a public model. Separately, sources were citing White House discussions of an executive order on open models. Nothing was official, and it would likely cover only Chinese-origin models and government use, but Lambert calls it "how the dominoes start to fall."
His core observation is that open models have no economic champion. Closed models have companies with lobbyists who feel the cost of any restriction. Open models are diffuse, so nobody is positioned to argue about the downside of acting against them.
The prediction
The most likely action, in Lambert's reading, is a ban or indefinite delay on any open-weights model meaningfully above the level of GPT 5.5, Claude Opus 4.8 or GLM-5.2 (glm-5-2-step-change-for-open-agents). Given how steady the gap between open and closed models has been (open-closed-model-gap), an open model crossing that line should arrive within six months, which is the title.
Such a model would most likely be Chinese, which ties the frontier question to distillation. The review threshold will rise over time, but Lambert expects it to rise more slowly for open models than for closed ones, partly because closed models are easier to secure and partly because closed-model companies lobby far better. The real trigger is that an open model will soon match Claude Mythos. Its actual performance will be more uneven, but all it takes is getting flagged by the new White House model checker, and "it's hard to unwind new habits motivated by fear."
Distillation as regulatory capture
Two separate policy fights are merging: distillation and frontier capabilities. Lambert says they differ in nature, in how much a response is needed and in what responses are possible, but together they give a ban its talking points.
On distillation his position is blunt. The campaign against Chinese models is led by Anthropic, through blog posts and letters to representatives. Anthropic detected foreign companies paying for its API, cut them off, then wrote strongly worded policy recommendations with, in Lambert's words, minimal technical evidence. Whatever business concern started it, it has become "the definition of regulatory capture", because Anthropic would gain a lot of economic security if the accused labs were banned. If Anthropic presented the findings neutrally and let policymakers decide, the community would be more sympathetic.
He sees a contradiction in the argument itself. If Anthropic's technology is so powerful that open models like it should be banned, Anthropic should be able to secure its API against extraction, and he is still waiting for an explanation of why it cannot. "One of their statements would need to be walked back." He places this in a broader pattern of Anthropic pulling up the ladder on access to intelligence in the name of safety, and recommends Ben Thompson's "Anthropic's Safety Superpower" as the best writing on it.
The practical effect of what Anthropic is asking for, he argues, is banning nearly all Chinese open-weight models in the US. Products built on open models depend on those models continuing to improve, so the ban would wipe out the emerging American open model economy of inference providers, fine-tuning companies and new products. His conclusion is that the community should concede nothing on distillation and leave enforcement to the labs themselves. His longer treatments are how-much-does-distillation-matter-for-chinese-llms and the-distillation-panic.
APIs are not the safe side
The cybersecurity angle is where the two debates tangle. There is a real worry that Chinese labs could distill Mythos's narrow cyber capabilities into an open model. Lambert reads that as evidence that model APIs are insecure, not as a distillation problem. Even during Mythos's most restricted private beta, people on Discord got unauthorized access to it, and APIs keep being jailbroken. That spreads dangerous capability faster than anything requiring a fine-tune of a 1T+ parameter model. Lambert says he is not a cybersecurity expert, but thinks the idea that open weights are insecure and APIs are safe has been overblown; APIs should be more secure in principle, and that has not been demonstrated. If a capability is truly dangerous, the only coherent choice is not to serve it through a queryable API at all. myth-of-unsafe-open-source-ai makes a similar case about bypassed guardrails on closed models.
Frontier open models without a ban
Lambert calls the frontier question the hard and real one, and warns against grabbing the distillation remedy because it is at hand. A flat ban does not work unless China bans the same models, since a bad actor can still download them, which removes the safety benefit and leaves only the costs. If the US alone blocks imports, the global open-source community carries on without it. A US ban ahead of China or more risk-averse countries would suggest fearmongering had pushed the government early, and he calls that "speedrunning dystopia", with American tech coming to resemble a Chinese system of state control and state investment. The only real ceiling on open progress is a global agreement on AI risk, which is nowhere close. The same conclusion, that access to capability cannot be controlled at a threshold, is the subject of nonproliferation-is-the-wrong-approach-to-ai-misuse and openai-huggingface-incident-autonomous-hacking; a-safe-path-to-open-weights is one lab's attempt at a release process short of a ban.
He also doubts the ecosystem can be stopped at all. The people building the best open models assess risk too; China is risk-sensitive, and z-ai is now a public company exposed to pressures including its own stock price. Training models is not magic, and access to building them has not fallen as costs rose.
Off-ramps
The short-term exit is for an American company to release an open model of similar capability. That changes the story from "only China builds open models, via distillation" to a shared problem inside one community. Lambert calls this existential for open source and says the companies with a business reason to commoditize their complements, Microsoft and Meta, should do it as soon as possible, though he has less faith in Meta under its new leadership. If Reflection has a good but not frontier model, it may need to ship it to save its own business plan.
Faster than training a model is building a coalition. Open source has no owner, but its benefits are spread across everyone outside the frontier labs, and that group needs to start lobbying now for a safe rollout of open-weight models.
Later sources
Two months later, Lambert's own reading list describes Anthropic's September 2026 threat report (anthropic-threat-report-september-2026) as "very transparent documentation" of Chinese companies circumventing its terms, including SFT-based distillation, and says Anthropic confirmed that Chinese labs used the reasoning-trace extraction technique from stealing-reasoning-traces-from-proprietary-llm-apis. That is considerably more evidence than the "minimal technical evidence" this essay complains about. The September report is newer, and the regulatory-capture reading here was written before it. The extraction paper also backs the essay's other point, that APIs are not the secure side: the reasoning traces came out through tricks that worked against how the frontier labs had implemented their APIs.
The rest of the timeline sits close by. Moonshot released the weights for kimi-k3 fifteen days after this essay. In kimi-k3-open-weights-escalation Lambert calls it the first true frontier open-weight model, so the crossing he gave six months arrived in about two weeks. The same release set off the round of argument that arguments-against-open-source-ai answers. By September the reading list records congressional probes of companies using Chinese models (us-scrutiny-of-chinese-model-use) but no ban. The general case against a ban, without the distillation fight, is in banning-open-source-ai-would-be-a-mistake, written a month earlier with Kevin Xu.
- The ATOM Project: American Truly Open Models
- Banning Open Source AI Would Be A Mistake
- GLM-5.2 is the step change for open agents
- Interconnects (interconnects.ai)
- Kimi K3: The open-weights escalation
- Kimi K3
- Notes from inside China's AI labs
- Open-Source AI & Open Models Reading List
- The OpenAI/Huggingface incident; how we should manage the imminent arrival of autonomous hacking too cheap to meter
- The distillation panic
- US Scrutiny of Chinese Model Use
- Why I build open language models