Anthropic、オープンウェイトモデルに関する立場を表明
AnthropicのCEOであるダリオ・アモダイ氏は、中国製オープンウェイトモデルを巡る規制議論に対し、同社が禁止を主張したことはなく、むしろセキュリティ上の懸念はモデルの公開有無に関わらず存在すると明言した。
AI深層分析を開く2026年7月28日 10:05
AI深層分析
キーポイント
オープンウェイト禁止への否定
Anthropicはビジネス保護のためにオープンウェイトモデルの禁止を主張したことはなく、そのような見解を持たないことを明確にしている。
セキュリティリスクの本質
同社の懸念はモデルが公開されているか否かにあるのではなく、権威主義政府による軍事優位性の確立や国民への抑圧というシナリオにある。
米国の安全保障状況
米国副大統領や情報コミュニティの報告書は、他国によるAI技術の進歩が米国の経済競争力と国家安全保障に挑戦しているとの見解を示している。
重要な引用
Anthropic has never advocated for a ban on open-weights models.
Open-weights models that don't have dangerous capabilities are a public good
authoritarian regimes have stolen and used AI to strengthen their military, intelligence, and surveillance capabilities
編集コメントを表示
編集コメント
この声明は、中国製AIモデルをめぐる国際的な議論において、米国企業の立場を明確にする重要な役割を果たす。特にセキュリティ懸念が技術の公開性そのものではなく、利用主体や目的に起因する点を強調しており、今後の規制議論の方向性を示唆している。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
「オープンウェイトモデルに関する当社の立場」
Anthropic のCEO、ダリオ・アモダイによる投稿です。
ここ数日、特に中国製のオープンウェイトモデルを中心に議論が活発化しています。一部では、米国の高官らが米国内企業による中国製オープンウェイトモデルの使用禁止を検討しているとの報道もあります。これに対し、多くのテック企業がオープンウェイトモデルを支持する書簡に署名し、中には「Anthropic が自社の事業を守るためにオープンウェイトモデルの禁止を望んでいる」とまで非難する声さえあります。
私の過去の著作を読んだ方ならご存知の通り、私はこうした禁止措置が有効な手段だとは考えていません。しかし念のため、明確に述べておきます。Anthropic はこれまで一度も、オープンウェイトモデルの禁止を主張したことはありません。
危険な能力を持たないオープンウェイトモデルは公共財です。実行に必要な計算リソース以外にコストがかからず、企業や開発者、研究者にとって大きな価値をもたらします。
保護主義的な禁止措置が、私が最も懸念する国家安全保障上の課題を解決することにはなりません。具体的には、2 つの悪夢のようなシナリオを心配しています。これらは 6 ヶ月前に執筆した論文『技術の思春期』で初めて述べたものであり、長年にわたり一貫して同じ立場をとっています。
私の最大の懸念は、独裁政権(中国共産党が最も能力に優れていることは明らかですが、それだけに限らず)が米国よりも強力な AI モデルを構築し、それを永続的な軍事優位性の獲得や自国民に対する極めて深刻な抑圧の手段として利用するリスクです。この懸念は米国政府内でも広く共有されています。昨年のパリでペンス副大統領は「独裁政権は AI を窃取・利用して軍事・情報・監視能力を強化している」と警告しました。また、情報コミュニティが発表した 2026 年版年次脅威評価では、「他の主要国における AI の堅実な進展が、米国の経済競争力と国家安全保障上の優位性を脅かしている」と指摘されています。
これらのモデルがオープンウェイトで公開されているかどうか、あるいは米国企業がそれを利用するかどうかは問題ではありません。むしろ最も危険なのは、秘密裏に訓練され、ドローン運用のために中国人民解放軍へ、監視や抑圧のために国家安全保障省へとのみ引き渡されるようなモデルかもしれません。
二つ目の懸念は、強力な AI モデルがサイバー攻撃や生物兵器攻撃の遂行に悪用されるリスク、およびアライメント(目標整合性)に関する深刻な問題です。オープンウェイトモデルは、中国発のものに限らず他国のものでも同様ですが、クローズドモデルと比較してより高いリスクを伴う可能性があります。その理由は、ガードレールを適用したり利用状況を監視したりすることが極めて困難であり、一度重み(weights)が公開されてしまうと撤回できないからです。
しかし、米国企業がこれらのモデルの利用を禁止しても、このリスクに対処することはできません。なぜなら、悪意のある行為者は正規の米国企業である可能性は低いからです。これは米国の AI 企業の競争から守る措置にはなりますが、それが私の目指すところではありません。
これらの懸念に対応するため、私は以下の三つの措置を支持します。これらは私と Anthropic が一貫して提唱してきたものです:
強力な半導体や製造装置を中国に販売すべきではありません。また、これらのチップへのアクセスを得るための横行する密輸や迂回手段にも厳しく対処する必要があります。中国には国内の生産能力に限界があり、スケーリング則(scaling laws)の観点から、米国のチップなしでは米国より強力なモデルを構築することはできません。これが脅威 #1 を阻止するための最も効率的で直接的な方法であり、米国の法律が及ばない範囲でのモデル訓練を阻害することで、間接的に脅威 #2 への対応にも貢献します。
産業規模の蒸留(distillation)オペレーションに対する取り締まりが必要です。蒸留はゼロからモデルを訓練するよりも計算リソース効率が格段に高く、これにより中国は通常では不可能なレベルでより優れたモデルを構築し、半導体輸出規制の一部を回避することが可能になります。蒸留によって中国共産党(CCP)が米国と同等かそれ以上の AI 能力を獲得できるわけではありませんが、中国の最先端技術を米国の水準に数ヶ月以内に近づけることは十分可能です。確かに、これらのオペレーションを行う企業の多くはオープンウェイトモデルを公開していますが、重要なのはオープンウェイトであることそのものではなく、それを背後で支えるのが米国を凌駕しようとする権威主義国家であるという事実です。こうした行動を抑止するための政策介入が必要です。オープンウェイトモデルに対する包括的な禁止令は適切な解決策ではなく、私たちが主張していることでもありません。
十分な能力を持つすべてのモデル(オープン・クローズドを問わず)は、必須の安全性テストを受けるべきです。脅威 #2 に対処する最善の方法は、リリース前にサイバーリスク、生物学的リスク、アライメントリスクについてモデルを直接テストすることです。このアイデアはすでにコンセンサスに近いものだと考えています。トランプ政権がここ数ヶ月で同様の方向へ動き出したこと、そして業界からの提案(最も能力の高いモデルを対象に、その起源国やオープン・クローズドの別に関わらず安全性テストを適用し、スタートアップや学術機関などから生まれた比較的低能力なモデルは完全に免除する)が相次いで出されたことに心強く感じています。オープンモデルが実際にリスクを増大させるかどうか、またそのリスクを軽減できるかどうかは、事前に決定されるべきではなく、テストを通じて明らかになるべきです。アンソロピック(Anthropic)のモジュラー学習戦略に関する最近の研究など、オープンウェイトモデルの安全性を高める有望な手法が存在するかもしれません。ただし、効果的なものとするためには、このテストはグローバルなものでなければならず、中国共産党もその枠組みに参加する必要があります。これは実は可能だと考えています。『テクノロジーの思春期』で記したように、AI 生物兵器の防止に関する限定的な協力であれば、それが中国自身の利益にもかなうため、実現できる可能性があります。
ここから、オープンレター について述べます。私はこの手紙の多くに同意します。オープンウェイトは AI エコノミーへのアクセスを拡大し、少なくとも一部のユースケースでは競争を強化し、顧客により大きなコントロール権を与えます。蒸留に関する懸念については、上記で述べたような、ターゲットを絞った法的・商業的枠組みを通じて対処すべきです。しかし、私は手紙が主張する「オープンウェイトモデルは必ずセーフガードの開発を容易にする」「能力への広範なアクセスは攻撃者よりも防衛者に有利に働く」という点には同意できません。むしろ逆になる可能性の方が十分にあると考えます。例えば、生物学の分野では攻撃者と防衛者の間に強い非対称性が生じることを懸念しています。十分な能力を持つモデルが、広く入手可能な材料を用いてパンデミックレベルのウイルスを短期間で兵器化できる一方で、それらの病原体に対する防御は最良の場合でも数年単位の運用課題となる可能性があります(これは「ワープスピード作戦」で示された通りです)。こうした疑問については、事前に仮定するのではなく、厳格なリリース前のテストによって実証的に回答されるべきです。
要約すると、私自身とAnthropicの立場は、「オープンウェイトモデル」というカテゴリ全体に対する禁止を主張しているわけではありません。むしろ、強力なチップが権威主義的な手に渡るのを防ぐこと、産業規模での知識蒸留(distillation)を停止すること、そして十分に能力のあるすべてのモデル(オープンかクローズドかを問わず)に対して安全性テストを義務付けることに注力すべきです。
関連記事
CognizantとAnthropicがパートナーシップを拡大し、Claudeを企業顧客に提供
Claude Opus 5の紹介
Opus 5は、長時間稼働するエージェントを支えるOpusティアにおける飛躍的な改善であり、コーディングや専門業務においても向上をもたらします。
経済未来研究基金のための研究アジェンダ
Anthropic Economic Futures Research Fundの研究アジェンダを公開しました。
原文を表示
*A post by Dario Amodei, Anthropic CEO*
Over the last few days there has been a lot of discussion about open-weights models, especially those from China. Reports suggest that some US officials are considering banning the use of Chinese open-weights models by US companies. In response, many tech companies have signed a letter supporting open-weights models, and some people have even accused Anthropic of wanting to ban open-weights models as a means of protecting our business. Anyone who has read my past writing should know that I don’t regard such bans as a useful measure, but let me state it clearly so that there is no doubt: Anthropic has never advocated for a ban on open-weights models.
Open-weights models that don’t have dangerous capabilities are a public good: they don’t cost anything besides the compute needed to run them, and they provide value to businesses, developers, and researchers.
Protectionist bans would not address my most serious national security concerns. Specifically, I am worried about two nightmare scenarios. I laid these out in my essay The Adolescence of Technology six months ago1, and have held these positions consistently for many years:
- My primary concern is the risk that authoritarian governments—not solely the Chinese Communist Party (CCP), although the CCP is clearly the most capable threat—build AI models that are more powerful than those built by the US, and use them to achieve permanent military superiority or perpetrate incredibly deep repression of their own people. This concern is widely shared within the US government: Vice President Vance warned in Paris last year that “authoritarian regimes have stolen and used AI to strengthen their military, intelligence, and surveillance capabilities,” and the Intelligence Community’s 2026 Annual Threat Assessment found that “other global powers’ robust progress in AI is challenging US economic competitiveness and national security advantages.” It is irrelevant whether these models are released with open weights, and certainly irrelevant whether they are used by US businesses. In fact, the most dangerous model may be one that is trained in secret and handed only to the People’s Liberation Army for use in drones and the Ministry of State Security for surveillance and repression.
- My secondary concern is the risk that powerful AI models may be misused to carry out cyberattacks or biological attacks, and may have serious alignment problems. Open-weights models—it does not matter whether they come from China or anywhere else—do potentially present a higher risk than closed models, because it is very difficult to apply guardrails to them or monitor their usage, and once weights are released they cannot be withdrawn2. But banning the use of these models by US businesses does nothing to address this risk, because bad actors are unlikely to be legitimate US businesses. It would protect US AI companies from competition, but that has never been my goal.
To address these concerns, I *do* support the following three measures, which I and Anthropic have consistently advocated for:
- We should not sell powerful chips or chipmaking equipment to China, and we should crack down on the rampant smuggling3 and workarounds used to obtain access to such chips. China has limited domestic production capacity, and therefore, due to the scaling laws, cannot build more powerful models than the US without US chips. This is the most efficient and direct way to block threat #1, and by hampering the training of models that are out of reach of US law, it also indirectly helps with threat #2.
- We should crack down on industrial-scale distillation operations. Distillation is a much more compute-efficient process than training models from scratch. It allows China to build much better models than its number of chips would ordinarily enable, and thus partially evade chip bans. Distillation does not allow the CCP to obtain equivalent or superior AI capabilities to the US, but it can bring the Chinese frontier to within a few months of the US frontier. It is true that many of the companies carrying out these operations release open-weights models—but the open weights are far less relevant than the fact that the operations are backed by an authoritarian state seeking to overtake the US at the frontier. We should have policy interventions to deter this behavior. A blanket ban on open-weights models is neither the correct remedy nor something we have called for4.
- All sufficiently capable models, open and closed, should go through mandatory safety testing. The best way to address threat #2 is to just directly test models for cyber, biological, and alignment risks before release. I think this idea is actually close to a consensus: I have been heartened both that the Trump administration has moved in this direction in recent months, and by recent industry proposals that would apply such testing to the most capable models regardless of their country of origin or whether they are open or closed (while exempting less capable models, such as those from startups and academia, entirely). Whether open models do or don’t pose an increased risk, and whether that risk can be mitigated, is something that should emerge from testing, rather than be decided in advance—and there may be promising methods for improving the safety of open-weights models, including recent research from Anthropic on modular training strategies. Note that to be effective, testing would need to be global, which means even the CCP would need to be on board. I think this may actually be possible: as I wrote in The Adolescence of Technology, limited cooperation around preventing AI biological weapons may be possible because it is in China’s interest too.
This brings me to the open letter. I agree with much of it: open weights expand access to the AI economy, they strengthen competition at least for some use cases, and they give customers greater control. Concerns about distillation should be addressed through targeted legal and commercial frameworks—the same measure I described above. But I don’t agree with the letter’s assertions that open-weights models necessarily make it easier to develop safeguards or that broad access to capabilities necessarily helps defenders more than attackers. It seems at least as likely to me that the opposite will be true. For example, I worry that biology will have a strong attacker-defender asymmetry, where sufficiently capable models may be able to quickly weaponize pandemic-level viruses with widely available materials, whereas defense against these agents is a multi-year operational task in the best case (as we saw with Operation Warp Speed)5. Questions like this should be empirically answered by rigorous pre-release testing, not assumed in advance.
To summarize my and Anthropic’s position, we have not and are not advocating for a ban on open-weights models as a category. We should instead focus on keeping powerful chips out of authoritarian hands, stopping industrial-scale distillation, and requiring safety testing of all sufficiently capable models, open and closed.
Related content
Cognizant and Anthropic expand their partnership to bring Claude to enterprise clients
Introducing Claude Opus 5
Opus 5 is a step change improvement for the Opus tier powering long-running agents while delivering improvements in coding and professional work.
A research agenda for the Economic Futures Research Fund
We’re sharing the research agenda for the Anthropic Economic Futures Research Fund.
AI算出
論評・提言ainew評価高い
AI モデルの公開方針とセキュリティリスクに関する明確な立場表明であり、業界への影響を示す重要な一次情報源として novelty が 0.75 に相当します。ただし、日本固有の企業・市場への直接的な言及や適用条件が欠けているため japan_relevance は低く設定されます。
6つの評価軸を見る
- AI関連度
- 100
- 情報源の信頼性
- 100
- 新規性
- 75
- 調べる価値
- 75
- 重複の少なさ
- 100
- 日本での有用性
- 25
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み