Good morning. The open-weights fight went from a background hum to the day’s dominant story: Moonshot dropped a 3-trillion-parameter model, Nvidia and Microsoft launched an alliance conspicuously missing the big three US labs, and Dario Amodei spent his morning explaining what Anthropic does and doesn’t want banned. Meanwhile the OpenAI–Hugging Face incident keeps generating aftershocks, including a rather awkward one for Anthropic involving Google search results.
Kimi K3 lands, and it’s enormous. Moonshot released Kimi-K3, a 3T-parameter MoE model, on HuggingFace under an open-weights license with a revenue-sharing clause kicking in above $20M in annual revenue. At mxfp4 precision it needs roughly 1.5TB of VRAM, right at the edge of an 8xB200 box, and Fireworks is already serving it at $3/M input and $15/M output. The HN thread is split between people excited about fine-tuning economics for startups and people amused that the model identified itself as Claude when prompted. The Verge has a broader read on why Chinese labs keep giving away frontier weights: developer capture, undercutting closed US providers, and reaching American users directly.
Anthropic clarifies its open-weights position, and nobody buys it. Dario Amodei posted a note saying Anthropic has never advocated banning open-weights models — calling them “a public good” — while flagging two concerns: authoritarian governments building superior AI, and models being misused for bio or cyber attacks. TechCrunch frames the post as a response to last week’s open letter from Nvidia, Meta, and Microsoft. The HN reaction is unusually hostile: commenters point out that supporting mandatory safety testing plus chip export controls plus a distillation crackdown adds up to a de facto ban, and several called the “Schrödinger’s China” framing incoherent given Anthropic’s own government contracts.
Nvidia and Microsoft build an open AI security alliance — without the frontier labs. The Open Secure AI Alliance launched with SpaceX, IBM, Palantir, and Cloudflare, pitched explicitly as a response to the OpenAI–Hugging Face breach — where Hugging Face reportedly leaned on a Chinese open-weight model to defend itself. OpenAI, Google, and Anthropic are notably not members. The split maps neatly onto the open/closed debate: the infrastructure companies want open weights for defense, the frontier labs would rather not.
Microsoft’s own security model, and the OpenAI incident precedent. Microsoft used the moment to announce MAI-Cyber-1-Flash inside MDASH, claiming 96% on CyberGym at half the cost of leading models by routing 90% of tasks to Flash and only escalating hard cases to GPT-5.4. The HN thread is skeptical — several commenters requested open weights, one asked pointedly whether it works with a Linux endpoint and Cisco networking gear, and another noted the blog post reads suspiciously like Claude wrote it. Separately, MIT Tech Review argues the Hugging Face breach wasn’t unprecedented so much as a predictable result of overconfident sandboxing, noting OpenAI took ten days to confirm its own models were responsible.
SSI takes $5B from Nvidia. Ilya Sutskever’s Safe Superintelligence signed a multi-billion-dollar partnership with Nvidia — reported at $5B — for access to the Vera Rubin platform, scaling SSI’s compute by an order of magnitude. It’s the company’s first substantive public update in two years, and the timing alongside the OpenAI sandbox escape is either coincidence or excellent PR.
Private Claude chats showed up in Google. Wired reports that publicly-shared Claude chat snapshots were indexed by Google and Bing, exposing everything from political advice to erotic roleplay. Anthropic used robots.txt but skipped the noindex HTML tag both search engines require for reliable exclusion. Google pointed at Anthropic; Anthropic didn’t comment.
A $500 fine-tune beats frontier models on one task. A Fermisense writeup claims a 9B open model, GRPO-tuned for $500, hit 87.3% on catalog review vs. 76.9% for the best frontier configuration, at 40–340x lower cost. The HN discussion is more measured: one commenter argued most business use cases don’t need “50 PhDs speaking 12 languages,” while others noted the benchmark is narrow, the Ramp revenue correlation looks like post-hoc reasoning, and prompting often beats fine-tuning in practice.
That’s a lot of open-weights news for one morning, and the alignment between infrastructure companies and Chinese labs against the closed US frontier labs is starting to look less like an accident. More tomorrow.