The chart lies. The crowd feels.
But when the crowd inside Anthropic splits, the chart of AI safety fractures into two warring narratives. One side says lock the weights. The other says free them. And in the middle, a 39-year-old post-training researcher named Shaun is drafting an open letter — not to the company, but to the world.
Shaun wants Claude’s model weights open. CEO Dario Amodei says no. And that “no” is now the most dangerous signal in AI.
Hook (Breaking)
Over the past 72 hours, sources inside Anthropic confirm that a coordinated group of employees has been quietly circulating a petition demanding the release of at least one major Claude model as open source. The petition has gathered signatures from more than a dozen staff across research, engineering, and safety teams. The company’s leadership has not responded publicly, but the tension is palpable.

“We believe transparency is the only path to genuine security,” one signatory told me under condition of anonymity. “The current closed-door approach creates a false sense of control.”
Smile while the liquidity drains. In crypto, we saw this pattern before: when a centralized entity claims to protect users by hoarding the keys, the ecosystem eventually revolts.
Context (Why Now)
Anthropic was born from a rebellion. Its founders left OpenAI in 2020 because they believed the company was moving too fast, prioritizing commercial deployment over safety. They built Constitutional AI, a framework to align models with human values without excessive reinforcement learning. Their pitch to investors was simple: we are the safe AI company.
Today, that pitch is cracking.
The company’s valuation sits around $60 billion, backed by Menlo Ventures, Google, and others. Its flagship model, Claude 3.5 Sonnet, is considered a top-tier competitor to GPT-4o. But unlike Meta’s Llama 3.1 or Mistral’s open-weight models, Anthropic has never released downloadable weights. Its entire business model relies on API subscriptions and a premium narrative: you pay extra because we keep the model safe.
Internally, that narrative is being challenged by the very people who built the safety features.
Core (Key Facts + Immediate Impact)
Let’s strip away the PR. The core technical debate is this: Can a model’s safety be guaranteed if its weights are public?
Amodei’s position — stated in multiple private meetings and leaked to this outlet — is clear: “Model weights cannot be recalled. Any security restriction we add through fine-tuning can be removed by anyone with enough compute. Opening the weights is equivalent to giving away the keys to the castle.”
He’s not wrong. In my years auditing crypto protocols, I’ve seen “secure” smart contracts get forked and stripped of their guards within hours. The same applies to AI: a jailbroken model can spread faster than any patch.
But the opposing camp, led by researchers like Shaun, argues that closed-source creates a different kind of danger: a single point of failure. “If only Anthropic can audit the model, then only Anthropic can fix its bugs. That’s not safety; it’s centralization,” one engineer told me.
Data supports both sides. A 2024 study by the Center for AI Safety found that open-weight models like Llama 3.1 have been used in at least 14 documented harm incidents, ranging from disinformation to deepfake scams. But the same study noted that closed-source models have also caused harm — including algorithmic bias and privacy leaks — that went undetected because external researchers couldn’t inspect the weights.
The Hidden Information
Based on my experience as a market surveillance analyst, the real story isn’t about safety. It’s about control.
Anthropic’s safety infrastructure relies on secret data: proprietary adversarial training sets, unreleased reward models, and internal red-teaming methodologies. Once the weights go public, these trade secrets become useless. The competitive moat evaporates.
But there’s another layer: Amodei has publicly endorsed restricting advanced chip exports to China and mandatory safety testing. That’s a political position. If Anthropic opens its models, it cannot enforce those restrictions. The company becomes a vector for global proliferation.
Yet the employees pushing for open-source are not naive. They know the risks. Their counter-argument is that collective defense — a global community of auditors — is superior to a single corporate firewall. Think of it like Ethereum’s open-source security model: vulnerabilities are found and fixed faster because anyone can view the code.
The chart lies. The crowd feels. And right now, the crowd inside Anthropic is feeling a deep distrust of their own leadership.
Contrarian (Unreported Angle)
The mainstream media is framing this as a simple “safety vs. freedom” debate. It’s not. The contrarian angle is that closed-source is actually the riskier bet for long-term AI security.
Here’s why: When a single company controls the weights, they become a honeypot. Hackers, state actors, and rogue employees all have a single target. If a backdoor exists in the weights, only Anthropic knows. If a backdoor exists in an open-source model, the entire world is looking for it.
Moreover, the closed-source strategy creates an intellectual monoculture. Every AI safety researcher wants to study cutting-edge models, but only Anthropic’s employees can access Claude’s internals. This restricts the talent pool and slows innovation. Meanwhile, open-source models like Llama have spawned an entire industry of third-party safety tools.
Consider this: in 2022, when OpenAI’s GPT-3 weights were still proprietary, a group of independent researchers discovered a major bias flaw by probing the API. OpenAI fixed it quietly. The public never saw what was changed. With open-source, the fix would be transparent and auditable.

From my years covering DeFi summer and the NFT art heist, I learned one thing: trust is a function of transparency. When protocols go closed-source, they almost always face a rebellion. The same is happening at Anthropic.
Takeaway (What to Watch Next)
Don’t watch the model. Watch the people.
Over the next six months, track three signals. First, employee departures — especially from Shaun’s team. If they leave en masse, they will likely start a competing “open safety” AI company. That company will have Anthropic’s DNA but none of its baggage. Second, watch Anthropic’s API pricing. If they slash prices or introduce a free tier, it’s a defensive move to retain developers. Third, monitor Hugging Face for any sudden release of old Claude checkpoints. That would be a hostage negotiation.
The real question is not whether Anthropic will open-source. It’s whether the talent exodus will force them to.
Smile while the liquidity drains. But remember: in a bear market for trust, the only safe harbor is transparency.
Wake up. The 24/7 clock never blinks.