Enterprise Strategy

Jensen Huang Is Arguing Against Every Locked Door in AI, Including Anthropic's

July 27, 2026

Jensen Huang wants Chinese models used and Anthropic's Mythos unleashed. Every gate he opposes, we've already watched close. The fight may be happening at the wrong layer anyway.

Jensen Huang Is Arguing Against Every Locked Door in AI, Including Anthropic's
Credit:
powered by

Make State of AI one of your go-to sources on Google

Google Icon
Add thestateofai.com on Google
Quote Icon

The industry keeps arguing about which model to trust. That question matters less than people think, because the control point an enterprise actually owns is the data layer. If your data lives in a governed environment you control, the model becomes a component you can inspect, swap, or sandbox. If it doesn't, no amount of model provenance will save you

Max Romanenko

Chief Technology Officer
EDB

On Monday, Treasury Secretary Scott Bessent told Fox Business that the administration is examining Chinese AI models for stolen U.S. intellectual property and weighing sanctions. Less than a day later, the most important hardware executive in AI sat down with Axios and told American companies to go ahead and use those models anyway.

Jensen Huang knew what he was walking into. Speaking to Axios' Mike Allen in Fort Worth, where Nvidia partner Wistron had just opened a new phase of an AI infrastructure plant, the Nvidia CEO worked through the case for restricting Chinese open-weight models and rejected nearly all of it. Should the government ban or restrict Kimi and its peers? "I hope not, and I really don't think so." Should U.S. companies be allowed to use Chinese models? "Absolutely, absolutely." The backdoor fear, in his telling, is "a misconception," since a downloaded model can be fine-tuned and guardrailed however its new owner wants.

He also went on offense. The market, Huang argued, has now misread Chinese open models twice, first with DeepSeek in January 2025 and again with Kimi this month, and the panic gets the economics backward. Great open models drive adoption, adoption drives data center demand, and data center demand means, in his words, selling "a lot more Nvidia computers."

The incentive buried in that last quote deserves its own scrutiny, and it will get some further down. The more interesting thing is that the structural argument underneath his China position is one this publication has been circling since June, without a CEO of his weight anywhere near it.

Three gates

Set the geopolitics aside for a moment and Huang is really making one claim: putting powerful AI behind a locked door doesn't reduce risk, it concentrates it. "If everything just becomes one single model, one single point of attack, one single source of failure," he told Axios, "the world is much, much more vulnerable."

Readers here have watched that claim tested against three different doors in six weeks.

Anthropic built the first one. When Fable 5 launched in June, we reported that it shares its underlying model with Mythos, the unrestricted version reserved for approved organizations, and that asking the consumer product about cybersecurity routes you to a weaker model. The guardrail, as we put it at the time, is a capability you are paying to lose. Huang named that gate on camera and told Anthropic to open it, arguing that powerful models get hardened through testing and rapid fixes rather than access restrictions. "Holding Anthropic back," he said, "is not in the benefit of the United States."

The government built the second. In the export-control shutdown that switched off Fable 5 for enterprise customers overnight, no contract bought anyone a way around it, and our conclusion then was that the most capable model on the market had turned out to be the one most easily switched off. That was an argument about continuity. Huang has now made the security version of it, and the two point at the same underlying design problem.

Washington is drawing the third gate now, in the form of Bessent's sanctions talk, watermark hunts for distilled U.S. models, and a reported push toward an outright ban, with OpenAI and Anthropic lobbying in that direction. Huang's answer is characteristically blunt: if a company steals IP or breaks contracts, punish the misconduct, not the model class. "Distillation, learning from AI, learning from other sources of knowledge," he told Axios, "is fundamental to intelligence." Whether Washington sees it that way is a question for the sanctions lawyers, and we'll leave it with them.

Nobody else with real industry standing has drawn a line through all three of those doors. Huang just did.

Where the argument thins out

His case has two soft spots, and our own reporting happens to supply both.

Start with "just download it," which is carrying more weight than it can hold. When Kimi K3 landed, we pointed out that its openness is largely theoretical: at 2.8 trillion parameters almost no enterprise can self-host it, and the weights weren't even shipping at announcement. Openness used to mean access. At this scale it mostly means influence, and most companies "using" Kimi will actually be consuming it as a paid API from a Chinese vendor, a very different security posture from the fine-tune-it-in-your-own-sandbox picture Huang painted. That same reporting did concede his strongest point, though. A frontier-class model that outside red teams can genuinely dissect is something the closed labs have never offered, and on scrutiny he's simply right.

Then there's the incentive, which Huang volunteered himself. Every branch of his argument ends at Nvidia's order book, whether the models in question are open, closed, Chinese, or American. Nor is this his first turn as market therapist; at Computex he talked down an AI fear that had been dragging on software stocks, an intervention we described at the time as a mood swing that might not last. Nvidia holds roughly 86% of the AI chip market. Huang may be the only prominent voice in this debate with no losing outcome.

We've been here with him before, and the conclusion still applies: the man sells shovels and can still be right about the mine. Self-interest doesn't falsify an argument, it just tells you to check the work. Checked against three gates' worth of our own coverage, most of this one survives.

The layer nobody's fighting over

Listen closely to Huang's actual reassurance, though, and it isn't a model argument at all. His answer to the backdoor fear is that enterprises can customize downloaded models and control access inside secure sandboxes. That is a claim about the environment, not the weights. The safety, in his own framing, comes from where the model runs and what it is allowed to touch, which quietly concedes that the question consuming Washington and Wall Street, namely which model, may be the less important one.

The data infrastructure world has been making this point for a while, and EDB has been making it most explicitly. The Postgres company's sovereign-AI thesis runs roughly as follows: intelligence has to move to the data, not the other way around, because the hard problems in enterprise AI are governance, residency, and control at the data layer, and those problems don't change based on whose model you picked this quarter. It's a position with an obvious pedigree. EDB's business is built on an open, inspectable Postgres core, and its standing critique of proprietary data platforms is a database-world cousin of Huang's single-point-of-failure argument: closed, centralized systems concentrate risk and take your leverage with them.

"The industry keeps arguing about which model to trust. That question matters less than people think, because the control point an enterprise actually owns is the data layer. If your data lives in a governed environment you control, the model becomes a component you can inspect, swap, or sandbox. If it doesn't, no amount of model provenance will save you," said Max Romanenko, Chief Technology Officer, EDB

Run the current panic through that lens and it mostly dissolves. If your data never leaves a governed perimeter you control, the model becomes a swappable component inside it. Whether that component is Kimi K3, a Claude variant, or an open Llama derivative, the provenance question doesn't disappear, but it stops being existential, because nothing about your crown jewels depends on the answer. The enterprises sweating the Kimi decision hardest right now are, almost by definition, the ones whose data would have to travel to wherever the model lives. Huang's sandbox is only a reassurance if you actually have one.

That reframe also happens to answer both of Huang's soft spots. Can't self-host a 2.8-trillion-parameter model? Then your controllable surface was never the weights anyway; it's the data plane those weights are permitted to reach. Worried the messenger sells shovels? The data-layer conclusion doesn't depend on his incentives, because it holds whichever way the chip market moves.

What enterprises should take from it

The remark from the interview most likely to outlast the news cycle wasn't about China at all. Huang rejected the whole framing of AI as a race with an endpoint: "The United States is going to be here for a long time. China's going to be here for a long time." That matters because the race framing is what makes every one of these gates feel justified, and it is exactly the framing his interview undercuts.

The practical lesson is the one our coverage has been converging on since the Fable shutdown, now with a sharper address. Concentration is the risk, whoever happens to control the gate, and the durable defense isn't picking the right model but owning the layer underneath all of them. A vendor can be switched off by a phone call from a regulator, as Fable customers learned in June. A sanctioned model class can vanish from your stack inside a news cycle, as Kimi's American users may be about to learn. The enterprises that come through the next panic intact won't be the ones that guessed right on open versus closed. They'll be the ones whose data never left their own governed ground, so that no door, and no ban, stands between them and their own capability.

Huang got to that conclusion because openness sells chips. Our route ran through covering the doors as they closed. The sovereignty debate is real; it's just being fought one layer too high.

Outlever Logo

If this caught your attention, that’s not accidental.


Text Decoration Line

The best editorial systems don’t happen by accident. Outlever builds them.

Decorative Circular LinesDecorative Circular LinesDecorative Circular Lines Mobile

Get the latest AI insights first.

Sign up for updates, interviews, and fresh analysis on how AI is reshaping business, brands, and technology.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.