On the Proposed U.S. Restrictions on Foreign Open-Weight AI Models
Second Circuit AI is an Austrian NGO currently in formation, advocating for cognitive liberty and freedom of thought and expression in artificial intelligence.
What is happening
Following the launch of Moonshot AI's Kimi K3 - the largest open-weight model announced to date, live via API since 16 July with the full weights scheduled for release on 27 July, and on several coding and agentic benchmarks a match for leading U.S. systems at a fraction of the price - the U.S. administration is reportedly weighing measures against foreign open-source AI. The instruments under discussion are not an outright ban, which would collide with the First Amendment and with technical reality. They are quieter and more durable. Per Axios' reporting of 20 July, they include Entity List designations (a U.S. trade blacklist that cuts off access without a license), security advisories, procurement rules - and, most consequentially, a previously drafted executive order under which U.S. companies could host Chinese models only if they guarantee their security and accept liability for any breach. These instruments were drafted and shelved once; the same reporting describes an internal balance that has since shifted toward reviving them.
No hosting provider willingly accepts open-ended breach liability for models it did not build. The predictable effect is that U.S.-based clouds and platforms drop foreign open-weight models, or wrap them in their own review apparatus. Because the infrastructure the global open-source community depends on - the dominant model-hosting platform and nearly all major specialised AI cloud providers (so-called neoclouds) - is U.S.-based, a policy written in Washington lands directly on developers, researchers, and users in Europe and everywhere else.
Second Circuit AI considers this development a threat to competition, to affordable access to AI, and - above all - to freedom of thought and expression in the AI ecosystem.
Why open weights matter: the only working check on a duopoly
The U.S. frontier AI market is, in practice, a duopoly. Two companies dominate revenue and mindshare, and both have demonstrated - through documented over-refusals, paternalistic guardrails, and content interventions - that freedom of thought, speech, and expression is not a priority for either. Their current token pricing is prohibitive for individuals, small businesses, and civil society; we do not hesitate to call it price gouging, and it is held in check by exactly one force: open-weight competition.
We respect what Grok has achieved under SpaceXAI. But single-company openness is revocable openness. Structural pluralism requires open weights that no one entity can revoke.
The evidence that competition works arrived within the last week, twice:
Competitive pressure lowers prices. Within days of Kimi K3's launch - and under simultaneous price pressure from cheaper closed competitors - Anthropic reversed its announced plan to remove its flagship Fable 5 model from subscription plans entirely, instead bundling it into its top-tier plans without an expiration date, announced 18 July and effective 20 July. The Decoder and TechTimes attribute this U-turn explicitly to competitive pressure. Remove the competition, and the incentive to reverse-gouge disappears with it. The history of the semiconductor industry is instructive: the years in which Intel faced no serious rival from AMD were years of stagnant products and hostile pricing - until Ryzen restored competition and, with it, progress.
Open weights are a security asset, not just a liability. When Hugging Face was hit by an AI-agent-driven cyberattack this month and tried to analyse the attack using leading U.S. frontier models, those models refused - their safety filters could not distinguish between an attacker and an incident responder, as Hugging Face put it in its own disclosure. The investigation could only be completed with a Chinese open-weight model, GLM 5.2, that Hugging Face ran under its own control, on its own infrastructure. The incident has been reported by Fortune, Axios, and SiliconANGLE. The lesson stands regardless of geopolitics: defenders need capable models they control. Restricting open weights in the name of security would have left one of the world's most important AI platforms less secure.
The deeper danger: inheriting censorship
The most likely policy outcome is not that foreign models vanish. It is that the hosting and distribution layer is forced to build a review apparatus - and whoever writes review criteria can, and eventually will, smuggle in content controls. Providers that are uncensored today are uncensored because nobody has forced a gate onto them. Build the gate, and the surviving models arrive censored.
For an organisation dedicated to freedom of thought, this is the actual danger line: not the severity of a restriction, but the moment an instrument stops being content-neutral friction and starts giving someone discretion over what may pass.
What must happen now
1. European inference sovereignty. Europe cannot veto a U.S. executive order, and it should not try to govern by protest. It can, however, remove the single point of failure. We call for EU-hosted inference capacity and an independent European (or otherwise offshore) model-hosting and mirror infrastructure - a genuine alternative to the U.S.-based platform layer, before it is needed rather than after. Emerging efforts such as Tensorix show that this is feasible; they deserve support, contributors, and users now. Existing public instruments - Digital Europe, EuroHPC, and national AI funds - should be explicitly directed toward EU-hosted open-weight inference and hosting capacity, and public procurement should reward providers who build it.
2. The same for serving capacity. The neoclouds most Europeans rely on for open-weight inference are U.S. companies. If they are pressured into dropping or gating foreign models, European users lose access overnight. European serving capacity for open weights is not a nice-to-have; it is insurance.
3. Users must organize - together. The AI user community has spent two years fragmenting into camps that hold each other in contempt: developers versus creative writers, roleplayers versus "serious" users, relational users versus everyone. This is a luxury we can no longer afford. Every one of these groups depends on the same open infrastructure, suffers under the same paternalism, and loses under the same restrictions. This is not a zero-sum game. The coding community just watched guardrails block a real-world cyber defense; creative and relational users have watched their use cases be filtered away for years. Same boat. Tolerance and cooperation win; mutual disgust only serves those who benefit from a fragmented, voiceless user base.
Our position in one sentence
Open weights are the foundation of competition, affordability, security, and freedom of thought in AI. A policy that quietly removes them at the hosting layer should be met not with outrage, but with European infrastructure that makes such a removal irrelevant.
Press contact: Second Circuit AI (SCAI), Vienna · ann@scai.world
This statement may be reproduced in full or in part with attribution.