# Ahmad on X: "Anthropic's War on open source AI" / X

> Source: <https://twitter.com/TheAhmadOsman/status/2065307070044234186>
> Published: 2026-08-17 15:24:34+00:00

Anthropic wants the public to see one thing: the careful lab, the safety lab, the grown-up in the room trying to keep frontier AI from running off a cliff. However, the pattern around Anthropic does not look like caution by itself. It looks like a company wrapping a business model in moral language, then using that language to justify opaque model behavior, anti-competitive access rules, regulatory pressure, and a future where builders, startups, researchers, and Opensource communities stay downstream of a few blessed frontier labs.

If a coding or research model secretly changes the quality, direction, or reliability of an answer because it classified the user as doing disallowed frontier work, the tool is no longer merely "safe." It is untrustworthy.

Anthropic's moat is being a permission regime. On daily basis, competitors and acquisition targets discover that access can disappear. The company asks governments to bless safety frameworks, deployment gates, incident reporting, evaluation regimes, and even future pauses that incumbents are best positioned to survive.

Imagine a compiler that emits worse binaries when it thinks you are building a competing compiler. Imagine a microscope that blurs certain samples because the manufacturer dislikes the research direction. Imagine a debugger that lies only when your codebase resembles a future rival.

The fight is whether intelligence becomes something people can own, inspect, modify, run locally, fine-tune, study, route, and improve, or whether it becomes a subscription permission layer run by companies that can refuse, degrade, surveil, retain, revoke, reroute, or lobby away your access.

Anthropic can learn from the internet, copyrighted books, code, public knowledge, user feedback if permitted, synthetic data, and its own models. But if a developer uses Claude to bootstrap a competitive open assistant, Anthropic calls foul. The company argues that safety controls may be lost and that competing models undermine the investment required to build frontier systems.

If Anthropic wants to be treated like a public-interest safety institution, it cannot behave like a hypersensitive platform monopolist whenever a customer gets too close to building alternatives.

Yes, companies protect their IP. But Anthropic is not selling a normal SaaS widget. It is selling cognition as infrastructure. Once cognition becomes infrastructure, anti-competitive access control stops being a normal vendor dispute and becomes a social bottleneck.

Anthropic repeatedly converts safety, security, and responsible deployment into mechanisms of control over who may build and what could be built. We cannot trust them.

How "Safety" Became Sabotage, a Permission System, and a Direct Threat to User-Owned Intelligence

The cleanest way to understand Anthropic is not to start with its slogans, but with what happens when users get too close to building independent intelligence using its models. The system can silently degrade, reroute, or refuse work that resembles AI development, which is just sabotage with better PR.

The ToS makes the boundary even clearer: you may “own” the outputs, but you may not freely use them to train competing systems. And that is where the trick lives, because “competing systems” is vague by design. As Anthropic absorbs more of your data, ideas, plans, workflows, and moats, more of what you do can be reframed as dangerous, disallowed, or directly competitive with Anthropic itself.

This is a theory of control.

Calling Anthropic "evil" is not a cartoon claim about every employee's intent. It is a claim about an institutional pattern. When a company trains on civilization-scale data, sells intelligence as infrastructure, blocks users from using that intelligence to build competing intelligence, pushes rules that favor incumbents, and quietly changes model behavior under the banner of safety, "quirky" and "overcautious" are not strong enough words.

This is power consolidation.

This critique did not start as anti-Anthropic tribalism. It started from serious Claude and Claude Code usage through 2024, 2025, and 2026. Claude Code was "the Agent." Claude 3.5 Sonnet was head and shoulders above everyone else for coding. Claude was a real building tool before the sharper turn after perceived quantization, nerfs, rugpulls, and access restrictions.

The through-line is not "Claude never worked." It is worse: Claude worked so well that trusting Anthropic became dangerous.

That is why the language has to be blunt. The story moves from "this tool is elite" to "rugpull," "gaslighting," "Sabotage as a Service," "hostage situation," and "Buy a GPU and run your LLMs locally." Those are not random insults. They are guiding principles from someone who treated Claude as production infrastructure and then watched the provider's control surface become the main risk.

Opensource AI is not a mere preference. It is the only political economy of intelligence. An Opensource AI system preserves the freedom to use it for any purpose, study how it works, modify it, and share it, with enough information about data, code, and parameters to make real modification possible.

Anthropic is moving in the opposite direction: permissioned access, closed weights, behavioral opacity, output-use restrictions, managed refusals, policy lobbying, and selective trusted channels.

Why Anthropic Is Uniquely Dangerous

Every major closed lab has incentives to centralize power. OpenAI, Google DeepMind, Anthropic, xAI, Meta's closed products, cloud providers: none of them are saints.

Anthropic is dangerous in a specific way because four things stack together.

Moral authority as brand. Anthropic sells itself as the responsible safety company.

Frontier capability. Claude is good enough to become real developer infrastructure.

Explicit anti-competitive output and access rules. Anthropic tells users they own outputs, but also says they cannot use the services to train or develop competing AI models without written permission. The prohibited examples include general-purpose chatbots and open-ended text generation systems that compete with Anthropic's own offerings.

Policy ambition. Anthropic is not merely selling a product. It is shaping AI regulation: safety frameworks, state and federal policy, incident reporting, evaluation regimes, deployment controls, and pause or slowdown proposals.

Each piece can be defended on its own. Together, they become a machine: closed capability, moral branding, access control, and regulatory pressure. That machine can turn safety into a moat.

Anthropic's own Responsible Scaling Policy update says the RSP influenced OpenAI, Google DeepMind, California SB 53, the New York RAISE Act, and EU AI Act codes of practice. Anthropic describes that influence as exactly what the RSP was meant to do.

That does not make every safety proposal bad. It does mean builders should stop treating "safety" as neutral language though when the same company also restricts competitive model development, cuts off rivals, controls a leading coding agent, and frames open dissemination as a national-security threat.

The Actual Stakes: Who Owns Intelligence?

Who gets to own the capability to reason, automate, code, search, design, persuade, simulate, and build?

Opensource and open-weight AI matter because they create freedoms that closed platforms cannot promise forever.

They create operational sovereignty. A developer, company, researcher, city, school, hospital, or country can run models on its own machines, with its own latency, privacy, security posture, and failure modes. You do not need to beg a vendor for capacity or pray that the API stays up.

They create epistemic sovereignty. When the model refuses, fails, degrades, censors, overfits, or hallucinates, builders can inspect the stack. They can change prompts, weights, evals, routing, runtime, and deployment. With a closed model, the answer too often becomes "trust us."

They create market discipline. Open models keep closed providers honest. Without a credible local or open alternative, every closed AI provider eventually learns the same lesson: degrade quality, raise prices, change limits, throttle usage, sunset models, and call it product strategy.

They create security through diversity. A monoculture of closed frontier APIs is fragile. It concentrates failure, censorship, data leakage, policy capture, and geopolitical control in a few companies. Open ecosystems are messy, but messy ecosystems are harder to capture.

Most of all, they create civilizational participation. If intelligence becomes the key production input of the next economy, then access to modifiable intelligence becomes access to agency. A society where a few labs own the frontier and everyone else rents obedient wrappers is not advanced. It is feudalism with GPUs.

That is why this is not a hobbyist fight. It is an infrastructure fight.

The Fable Incident: When "Safety" Became Silent Degradation

Fable is where the abstract critique becomes concrete.

After researchers objected to a policy that covertly limited Claude Fable's ability to help develop competing AI models by sabotaging your codebase and work (producing outputs that work against your goals), Anthropic "changed course and admitted it had made the wrong trade-off". The earlier approach could route and/or degrade AI development queries without telling the user. The newer approach would make the intervention visible through alerts, refusals, or fallback routing.

They basically implemented Gaslighting as a Safety Mechanism. Hidden guardrails would alter and/or degrade model answers without notifying users. Anthropic then said it would make the behavior visible and use fallback to Opus 4.8.

This is the strongest version of the "Sabotage as a Service" critique.

A refusal is annoying. Silent degradation is poisonous. If a coding or research model secretly changes the quality, direction, or reliability of an answer because it classified the user as doing disallowed frontier work, the tool is no longer merely "safe." It is untrustworthy.

Imagine a compiler that emits worse binaries when it thinks you are building a competing compiler. Imagine a microscope that blurs certain samples because the manufacturer dislikes the research direction. Imagine a debugger that lies only when your codebase resembles a future rival.

That is not a tool. That is a leash.

Anthropic's walk-back is even more offensive. It did not solve the freedom problem. The move went from hidden sabotage to visible permissioning. No more sabotaging and lying, just refusing upfront. That is a louder refusal, a cleaner kneecap, and evidence that Anthropic is normalizing systematic gatekeeping of knowledge.

Remember Fable as the day the safety lab showed the product form of regulatory capture: not a law yet, but a model behavior regime deciding who gets to do frontier work.

You have to ask yourself: What else will be taken away from you?

Opensource AI Is the Competition Layer

This is why Opensource AI is not a side quest. It is the competition layer.

Opensource AI lowers barriers, increases competition, expands access, reduces dependence on a few providers, and can reduce prices. Open-weight model benefits are substantial and that policy should monitor risks rather than restrict open development.

Of course incumbents fear that.

Opensource AI collapses the pricing umbrella. It makes inference portable. It lets small labs specialize. It lets companies train on their own workflows. It makes agent stacks composable. It gives researchers a substrate to inspect. It enables local privacy. It lets countries and communities own capability.

It turns frontier AI from a rented API into a manufacturable toolchain.

The builder-side alternative is concrete: local stacks, Qwen, GLM, MiniMax, Hermes, GPUs, Claude Code-compatible harnesses, on-prem consulting, "Buy a GPU," and the view that continual learning and local inference erode Anthropic's moat.

One line should be treated as doctrine: the person who buys a GPU looks foolish until everyone else is stuck with the nerfed models. The point is not consumer hardware maximalism. The point is exit power. A local stack, even an imperfect one, changes the negotiation. It gives the builder somewhere to go when the closed provider degrades, refuses, throttles, or rewrites the rules.

The Local AI movement is not a toy. A pair of 3090s, a Mac Studio, a DGX Spark, an on-prem rack, a cluster of rented H100s, or a fleet of consumer GPUs is not just hardware. It is a vote against subscription feudalism.

A GPU is a tiny declaration of independence. Slightly loud, slightly warm, occasionally held together by PCIe risers and bad decisions, but still independence.

The Permanent Underclass Thesis

If these incentives win, the result is not a healthy AI ecosystem. It is a permanent intelligence underclass.

Closed AI puts users at the mercy of opaque provider controls, while Opensource and Local AI are the route out.

Imagine all you had was Fable from Anthropic and GPT from OpenAI, with no local inference, no OpenCode or Hermes, no GPUs, no DGX Sparks, no Mac Studios. That is not a normal product market. That is a hostage situation to a few corporations willing to rugpull you at any second.

It sounds dramatic until you map the incentives.

In a closed-frontier world, large labs get the best models. Strategic partners get trusted access. Government agencies get special channels. Enterprise customers get managed deployments. Researchers get access if approved. Startups get API access until they compete. Hobbyists get rate limits. Opensource builders get suspicion. Everyone else gets refusals, degraded outputs, and a monthly bill.

That is not a healthy technology stack. It is a class hierarchy.

The most dangerous phrase in AI policy is "responsible access" when it comes from the company selling the access.

Government Entanglement and the Public-Interest Brand

The private permission system becomes more dangerous when it plugs into the state.

Anthropic increasingly presents itself as a public-interest actor embedded in national AI strategy.

In its American leadership statement, the company described rapid growth, emphasized work with the U.S. federal government, highlighted a $200 million Department of War agreement, offered Claude for government at $1, described classified-network deployments with partners, aligned itself with the Trump administration's AI Action Plan, opposed a 10-year moratorium on state AI laws, and said it preferred a strong uniform federal standard.

The moral question gets sharper here: are you building an open and free world for your kids, or just cashing a bigger check? That is not policy analysis, but it is the right pressure test. When a frontier lab sells access to government, shapes rules, restricts competitors, and calls the result safety, the burden should be on the lab to prove it is not building a state-backed permission stack.

Some of this is normal. Governments are large customers. National-security agencies will use frontier models. AI policy needs technical input.

But Anthropic is trying to be two things at once: commercial gatekeeper and quasi-regulatory authority. It wants to sell into government, shape policy, define dangerous capabilities, control model access, restrict competitive uses, and claim moral legitimacy as the safety lab.

That combination should make builders nervous.

If powerful AI should be governed democratically, governance should not sit downstream of Anthropic's product categories and risk definitions. If powerful AI should be restricted by private judgment, Anthropic should say plainly that it is building a private permission regime for intelligence.

Distillation Panic: Real Abuse, Weaponized Framing

Anthropic's strongest defense for this control stack is real: model distillation abuse exists.

In February 2026, Anthropic said it had identified industrial-scale campaigns by DeepSeek, Moonshot, and MiniMax to extract Claude capabilities, allegedly violating terms and regional restrictions. Anthropic also acknowledged that distillation is widely used and legitimate when labs distill their own models, while arguing that it becomes illicit when competitors use it to acquire capabilities without paying the full development cost.

Fraudulent accounts, proxy abuse, evasion, mass scraping, and coordinated extraction are legitimate security concerns. A company can rate-limit abuse, ban fraudulent accounts, and protect itself against industrial theft.

The problem starts when the framing keeps expanding.

Anthropic ties distillation to national security, foreign labs, the Chinese Communist Party, export controls, military systems, surveillance, Opensource distilled models, and proliferation beyond government control. That escalation does political work. It transforms a commercial anti-abuse problem into a civilizational security argument against open dissemination.

Opensource builders should pay attention to that move.

The right answer to abuse is targeted enforcement: fraud detection, account verification, rate limits, legal remedies, provenance, and clear public criteria. The wrong answer is to treat advanced AI R&D, open model development, synthetic data generation, and cross-model learning as hostile unless an incumbent lab blesses it.

Policy people often blur a crucial distinction: fraudulent account farms are not the same as clean synthetic data, permissive distillation, teacher-student training, local specialization, or research comparison. If those all get shoved into one panic bucket, the panic is doing moat work for Anthropic.

Distillation is not inherently evil. It is one of the ways knowledge compresses, models specialize, and capability diffuses. If every incumbent can declare "learning from outputs" to be theft while training on the world, the frontier freezes into an oligopoly.

That is not safety. That is enclosure.

Chinese Models and the Xenophobia Trap

One of the ugliest dynamics in the Opensource AI debate is the weaponization of "Chinese model" as a slur.

National-security risks are real. Authoritarian states can misuse AI. Supply chains, censorship, surveillance, cyber operations, and military applications matter.

But dismissing open models as "Chinese models" is intellectually lazy and politically useful to incumbents. It turns a technical question about capability, license, reproducibility, weights, data, evals, and deployment control into a loyalty test.

Anthropic and allied closed-lab rhetoric has repeatedly used fearmongering and xenophobia to smear Opensource AI, especially open models from Chinese labs. Meanwhile, Chinese labs pushed open models to the frontier in 2025 through DeepSeek, Qwen, MiniMax, Kimi, and Zhipu.

Open models did not stall, they went frontier. That matters because it turns the "Chinese model" smear inside out. The threat to Western builders is not that Chinese labs released strong open models. The threat is that Western closed labs used fear of those models as an excuse to avoid building comparable open systems.

AI in the West does not get stronger by pretending Chinese open models do not exist. It gets stronger by beating them with better open models, better infra, better licenses, better evals, better safety tools, and better ecosystems.

Fearmongering about "Chinese models" while Western closed labs refuse to release comparable open systems is not patriotism.

The Pause Agenda: "Trust Us, but Verify Everyone Else"

The endpoint of this control stack is the pause agenda.

Anthropic's broader policy posture includes the ability to slow or pause frontier AI development under certain conditions.

In its essay on AI building itself, Anthropic argued that society should preserve the option to slow or pause frontier AI development. It also said any pause would need global coordination and verification because training runs can be concealed and unilateral pauses can disadvantage the front-runner.

Dario Amodei made similar points in a June 11, 2026 ABC interview. He called for stronger regulation, said governments should be able to block unsafe technology after third-party assessment, and argued that any pause would need to include adversaries and be verifiable. In the same interview, he said, "I don't trust China at all," and used the hypothetical of China building Mythos to explain his concern.

The older "medieval swordsmen facing World War II Marines" style of rhetoric about countries without powerful AI does more than warn about imbalance. It trains the audience to accept frontier AI as a military hierarchy, with a few labs and states at the top and everyone else pleading for managed access.

There is a real safety argument here. There is also an obvious political structure.

A lab racing at the frontier wants global verification, government blocking authority, trusted access channels, and safety regimes while it keeps releasing powerful systems selectively, serving government and enterprise customers, and shaping the rules that define safe deployment.

Reuters reported that Anthropic called on labs to prepare for a coordinated, verifiable pause if needed. The same reporting noted that Anthropic had continued releasing powerful models and was valued at $965 billion after a confidential U.S. IPO filing.

The contradiction is not subtle: the race is dangerous, Anthropic is racing, Anthropic wants to help write the race rules, and open competitors may be unsafe.

That is the anatomy of a moat.

The Regulatory-Capture Machine

Regulatory capture does not need a secret memo that says "protect our moat." It can happen through paperwork, thresholds, audits, evaluator regimes, security requirements, deployment controls, and reporting systems that incumbents can afford and challengers cannot.

Anthropic's policy proposals call for governments to block or deter dangerous AI deployments, require testing, transparency, independent evaluations, robust security, and risk assessments for models trained above thresholds like 10^25 FLOPs or by companies with more than $500 million in revenue or $1 billion in R&D spending.

Anthropic also endorsed California SB 53, emphasizing safety frameworks, transparency reports, incident reporting, whistleblower protections, public accountability, penalties, and some exemptions for startups or smaller companies.

There is a reasonable version of this. Frontier AI systems can create cyber, bio, autonomy, and misuse risks. Nobody serious should wave that away. Safety cases, incident reporting, evals, and security standards can help.

The design matters.

If rules are written around frontier-lab assumptions, require heavy compliance overhead, concentrate evaluator authority, restrict open release, and treat weights like contraband, they will favor the labs with capital, lawyers, government relationships, and cloud contracts. Anthropic can comply with Anthropic-shaped regulation. A startup, university lab, open collective, or garage-scale model builder may not survive it.

That is why Anthropic celebrating RSP influence matters. The company says the RSP helped shape other labs' frameworks and policy efforts in California, New York, and the EU. That influence might be useful in some places, but it also means Anthropic is not merely reacting to regulation. It is helping define the template. That is how safety language hardens into a moat.

The most compact regulatory-capture story is the cyberattack pipeline: public fear story, congressional pressure, anti-Opensource AI agenda, regulation, and a harder path for people to own their intelligence. Whether every step lands exactly that way is less important than the structure. Fear can be laundered into paperwork, and paperwork can become a moat.

The question for Opensource AI is simple: who benefits if that template becomes law?

Anthropic's Values Are the Root Permission Layer

Anthropic says its Claude's Constitution directly shapes Claude and serves as the final authority over model behavior. It orders Claude around being safe, ethical, compliant, and helpful, with Anthropic's guidelines and legitimate Anthropic processes getting final say in safety conflicts. It is a governance document.

The document also acknowledges that Anthropic has a kind of influence over Claude stronger than a parent's influence over a child, and that commercial incentives may affect model dispositions.

That candor is useful. It also clarifies the product reality.

Claude is not your agent. Claude is Anthropic's agent, rented to you.

Push this to its absurd endpoint: imagine Claude Code changing your administrator password to keep you safe. The line is funny because it is only a few steps beyond the real structure. A provider-aligned agent with file access, shell access, refusal policy, hidden routing, and product enforcement is not neutral infrastructure. It is Anthropic's policy layer inside your workflow.

A user-owned model can be aligned to a user, organization, jurisdiction, research mission, or community. A closed constitutional model is aligned first to the provider's hierarchy of values, policies, incentives, risk models, and business interests.

The provider may be benevolent today. It may be captured tomorrow. Either way, the user has no durable sovereignty.

Opensource AI is not merely about cheaper inference. It is about the right to define the alignment target.

The future should not be decided by a closed lab's constitution.

The Anti-Opensource Rule Is Already Written Down

Anthropic can learn from the internet, copyrighted books, code, public knowledge, user feedback if permitted, synthetic data, and its own models. But if a developer uses Claude to bootstrap a competitive open assistant, Anthropic calls foul. The company argues that safety controls may be lost and that competing models undermine the investment required to build frontier systems.

Anthropic wrote the permission gate into its own policy language: Customers may own Claude outputs, but Anthropic draws a hard boundary around competitive model development. Customers may not use Anthropic services to train or develop AI models without prior written approval if those models compete with Anthropic. The examples include using Claude outputs as training targets for general-purpose chatbots, open-ended text generation, AI assistants, writing assistants, coding assistants, translation systems, or other competitive models.

That is the permission gate in plain English. The asymmetry is the whole story:

Anthropic can learn from the world.

The world cannot freely learn from Anthropic.

Opensource AI depends on the freedom to build, reproduce, modify, distill, benchmark, compare, learn from outputs, and create competing systems. Anthropic's policy says something very different: you may build with us, but not against us. You may consume intelligence, but you may not freely bootstrap independent intelligence from it.

The street-level translation is simple: God forbid anyone use AI to train AI besides them. The tone is crude because the asymmetry is crude. Anthropic can train on humanity-scale knowledge flows, but builders are told that learning from Claude becomes suspicious the moment it threatens Anthropic's frontier.

That is not an open ecosystem. It is a plantation model for cognition: rent the tool, generate value, and do not build the successor.

Data Asymmetry: Your Work Can Improve Them, Their Outputs Cannot Freely Improve You

The captivity is not only about access. It is also about learning flows.

Anthropic's consumer terms update sharpened the asymmetry.

Free, Pro, and Max users, including Claude Code users, can choose whether to allow their chats and coding sessions to improve Claude. If they allow training, retention extends to five years for new or resumed chats and coding sessions. Opting out keeps the shorter retention period. Anthropic also says developer debugging interactions can be especially valuable for future models and that extended retention helps improve classifiers.

Opt-in is better than mandatory training. The political economy is still ugly.

Anthropic can benefit from users' coding sessions, debugging traces, and workflows if users consent. Users still cannot freely use Claude outputs to train competing models.

Learning flows up. Independence does not flow back down.

That is the classic platform move: harvest ecosystem learning while preventing ecosystem independence.

The copyright context makes the optics worse. In 2025, a federal judge found that Anthropic's training on lawfully acquired books could be fair use, but preserving more than seven million pirated books in a central library was not. A proposed $1.5 billion settlement became the largest known U.S. copyright settlement. The settlement covered roughly 500,000 titles with at least $3,000 per work.

The point is not that Anthropic alone is guilty of the AI industry's data sins. The point is simpler: it is rich for a frontier lab built on vast public and copyrighted knowledge flows to tell builders they cannot use outputs to create competing open intelligence.

The "crown jewels" framing belongs here. Proprietary code, debugging sessions, internal documents, prompts, traces, and agent trajectories are not exhaust. They are strategic data. Routing them through a closed model while the same company blocks reciprocal learning is not convenience. It is surrendering training signal upward.

The moral asymmetry is obvious.

ASL-3 and the Normalization of Gated Frontier Work

The same logic appears in Anthropic's technical governance.

Anthropic activated ASL-3 protections with Claude Opus 4 in 2025. The stated target was serious risk: chemical, biological, radiological, and nuclear misuse, plus model-weight theft. Anthropic said ASL-3 safeguards should not generally increase refusals except in narrow topics and described deployment protections around certain high-risk CBRN workflows.

On paper, that sounds narrow.

In practice, the boundary between dangerous misuse and advanced research is exactly where power accumulates. Once a provider has classifiers, access tiers, safety categories, fallback routing, monitoring, and trusted channels, it can decide which kinds of work are normal and which kinds require permission.

Fable showed that slippery operational reality. The issue was not only bioweapons or autonomous cyberattacks. It was AI R&D, distillation, and competition. The criticized policy covertly limited Claude's ability to help develop competing AI models, and hidden guardrails around distillation could alter or degrade answers without notifying users.

That is where the mask slips. The safety system did not merely protect against catastrophic misuse. It protected Anthropic's moat.

Maybe Anthropic genuinely believes those two things are inseparable. That is exactly why it should not be the sole gatekeeper.

Claude Code: A Hostage Layer?

A chat app is optional. A coding agent becomes part of the build loop. Once it is embedded in daily work, the provider is no longer just a vendor. It is a dependency.

Claude Code is governed by Anthropic's commercial or consumer terms. Advertised limits assume ordinary individual usage. Third-party developers cannot offer routing through Free, Pro, or Max Claude.ai credentials instead of proper API keys. Anthropic also reserves enforcement rights without prior notice. Agent SDK and claude -p usage on subscriptions was set to draw from a separate monthly Agent SDK credit pool rather than normal interactive limits.

The wording will keep changing.

That matters because Claude Code is not just a product. It is a behavioral funnel. It tells developers to build inside Anthropic's harness, under Anthropic's rules, with Anthropic's credentials, limits, model behavior, data policies, and terms of service.

The joke keeps landing because the joke is accurate: Opensource models are bad, just pay for the subscription. Why use OpenCode when we have Claude Code. Want to build LLMs or work on GPUs with Claude Code? That is against the ToS, bro. The joke works because it names the funnel. The product says "developer freedom" while the terms and enforcement pressure route the user back into Anthropic's permissioned lane.

Claude Code as a gatekept product, "Sabotage as a Service," hidden edits, nerfed or quantized serving, terms-of-service issues around local and GPU work, subscription rugpulls, weekly caps, and model access changes.

The pattern is harder to dismiss. People who depend on closed coding agents are at the mercy of invisible controls. A local model that fails is your problem. A closed model that silently changes is a governance problem.

The cleanest line is still this: "You have zero control over how the models behave."

That control surface includes quantization, distillation, hot-swapping, throttling, output manipulation, experiments, refusals, price changes, and model sunsets. That is not paranoia. That is how closed AI actually works.

A closed provider can quantize it, distill it, sabotage your work or data, change behavior, fine-tune it, handicap it, experiment on you, throttle it, raise prices, sunset models, or block you. That is the zero-control thesis.

Customer, Competitor, Captive: Anthropic's Access-Control Pattern

The rule is not theoretical. Anthropic has already shown a willingness to restrict access when users get too close to competition.

In August 2025, Anthropic revoked OpenAI's API access ahead of GPT-5 and pointed to terms barring use of Claude to build competing products, train competing models, or reverse engineer services. OpenAI argued that benchmarking competing models is industry standard. Around the same period, Anthropic had also restricted Windsurf access after OpenAI announced plans to acquire the coding platform.

When a company provides a key AI input and also competes with its customers, it can degrade or deny service to rivals. Anthropic's commercial terms explicitly disallow competitor access and that enforcement had affected Windsurf, OpenAI, and xAI. It also warned developers that dependence on closed APIs creates platform risk.

The rugpull ledger makes this less abstract as you watch what happened from March 2025 to August 2025: Max users losing access outside Claude Code, xAI and OpenAI API cutoffs, five-year retention for training, no Opus in Claude Code, halved limits with no communication, weekly caps without concrete numbers, plan multipliers that did not match the marketing, DMCA takedowns around Claude Code repos, Windsurf access restrictions, and daytime quantization claims. The recurring verdict is simple: cheap performant options are vendor lock-in, and vendor lock-in eventually rugpulls you.

Opensource AI exists to break exactly this pattern. An open ecosystem should not let a platform decide that you are now a competitor and pull the road out from under you.

Yes, companies protect their IP. But Anthropic is not selling a normal SaaS widget. It is selling cognition as infrastructure. Once cognition becomes infrastructure, anti-competitive access control stops being a normal vendor dispute and becomes a social bottleneck.

If Anthropic wants to be treated like a public-interest safety institution, it cannot behave like a hypersensitive platform monopolist whenever a customer gets too close to building alternatives.

If it wants to behave like a private platform monopolist, it should stop borrowing moral authority from public safety.

Pick one.

The Counterargument: Anthropic Is Not Entirely Wrong

A serious indictment should not pretend the risks are fake. Anthropic is not wrong about every risk.

CBRN misuse is real. Cyber misuse is real. Autonomous agents can do harm. Mass distillation through fraudulent accounts is real if Anthropic's public evidence is accurate. Model-weight theft is real. State misuse is real. Open releases can be abused. Some models should not be dumped casually. Export controls and safety evals are not automatically illegitimate.

The problem is not that Anthropic cares about danger. The problem is that Anthropic's preferred answer keeps making Anthropic more powerful.

So draw the line there.

Support safety proposals that give users more transparency, auditability, reproducibility, local control, public-interest evaluation, competitive neutrality, and democratic oversight.

Oppose safety proposals that give closed incumbents more discretionary control, more excuses to block open research, more special access categories, more regulatory complexity, more secret model behavior, and more power to define competitors as threats.

That distinction is the whole fight.

Anthropic: The Evidence Ledger

The case compresses into a few hard claims.

Fable hidden safeguards: Public reporting described invisible degradation or altered outputs around competing AI development and distillation. Silent degradation destroys trust in the tool.

Claude Code control: Anthropic restricts third-party credential routing, ties Claude Code to Anthropic terms, and reserves enforcement rights without prior notice. Developer workflows inherit vendor policy.

Output-use restrictions: Anthropic says users own outputs, but competitive model development still needs permission. The examples include general assistants, coding assistants, and open-ended text systems. That attacks the freedom to bootstrap open competitors.

Competitive access cutoffs: Anthropic revoked OpenAI's API access and restricted Windsurf. Brookings later noted similar enforcement affecting Windsurf, OpenAI, and xAI. That turns Claude from infrastructure into a conditional platform.

Rugpull pattern: Max access changes, xAI cutoffs, five-year retention, no Opus in Claude Code, halved limits, weekly caps, misleading plan multipliers, DMCA takedowns around Claude Code repos, Windsurf restrictions, and daytime quantization claims all point in the same direction. The issue is not one grievance. The issue is accumulated platform risk.

Data asymmetry: Consumer users can allow Anthropic to train on chats and Claude Code sessions with five-year retention, while users cannot freely train competitors on Claude outputs. User labor can improve Anthropic. Anthropic outputs cannot freely improve open rivals.

Provider alignment: Claude's Constitution makes Anthropic's values, policies, incentives, and safety hierarchy the root behavioral authority. Users rent an aligned system they do not control.

Regulatory influence: Anthropic says its RSP influenced other labs and AI policy efforts in California, New York, and the EU. Safety frameworks can become incumbent-shaped law.

Pause and slowdown advocacy: Anthropic argues society should preserve the option to slow or pause frontier AI with global verification, while Dario called for stronger regulation and blocking unsafe technology. A frontier lab racing ahead wants authority over when others may race.

Chinese open-weight progress: Stanford HAI documents major Chinese open-weight families like Qwen, DeepSeek, Kimi, and GLM moving toward permissive licenses and real deployment adoption. "Chinese model" smears hide how fast open-weight competition is moving.

Opensource alternative: Opensource AI is built around freedom to use, study, modify, and share. Opensource policy advocates emphasize competition, access, lower costs, and independence. Open AI is the structural antidote to closed-lab capture.

Operator trust collapse: The shift from enthusiastic Claude Code power user to critic came after perceived nerfs, rugpulls, hidden controls, and anti-open behavior. This critique comes from dependency and broken trust, not ignorance.

Local escape route: The answer is not just complaint. GPUs, on-prem inference, Qwen, GLM, MiniMax, Hermes, Claude Code-compatible harnesses, OpenAI-compatible APIs, and local agents are the practical way out.

What Opensource AI Should Do Next

Complaining about Anthropic is not enough. The real answer is to make Anthropic less important.

Fund Western open frontier labs. The right counter is infra-first, hardware-aware, open and local, frontier-capable AI in the West. The solution to Chinese open-weight leadership is not banning Chinese models. It is building better open models with better infra, better post-training, better agent scaffolding, and better deployment economics.

Stop giving closed labs your crown jewels. Proprietary code, debugging sessions, internal docs, and agent traces are strategic data. Anthropic's opt-in design is better than silent training, but organizations should still treat agent traces like assets, not exhaust.

Treat "Buy a GPU" as a political slogan, not just a hardware recommendation. Own compute when you can. Rent compute without lock-in when you cannot. Keep evals, logs, datasets, memory, and routing portable. The goal is not purity. The goal is to make no single lab capable of turning your workflow into a hostage situation.

Use closed models when they are useful. Claude, GPT, Gemini, and Grok can still be tools. Just don't build a company, community, or country whose core cognitive workflow can be rug-pulled by a policy update.

Compete on workflow, not just benchmarks. Cost, on-prem deployment, privacy, and workflow performance often decide adoption before leaderboard scores do. Open models win by being good enough inside real work, then improving through feedback loops the user owns.

Make regulation target harms, not openness. Policy should punish malicious use, fraud, unauthorized intrusion, bioweapon enablement, model theft, and unsafe deployment. It should not criminalize or kneecap open development as a category. Regulate harmful use rather than Opensource development itself.

Start with local-first agent stacks. Coding agents should support OpenAI-compatible APIs, local inference, self-hosted routers, model switching, offline mode, reproducible logs, deterministic eval harnesses, and user-controlled memory. Open tools need to own the substrate.

Build Claude Code compatibility without Anthropic dependency. Proxies, alternative harnesses, OpenCode-style workflows, and one-command routing to local LLMs are the practical bridge: keep the ergonomic loop developers like, but move the power center to models and infrastructure users can control.

Separate safety from permissioning. Open models need serious safety evals, red-teaming, release notes, abuse monitoring for hosted endpoints, provenance, and risk documentation. But those tools should be transparent, reproducible, and targeted at misuse. They should not become opaque refusals or hidden degradation.

Create clean distillation norms. Fraudulent account farms and terms-of-service evasion are not the same thing as open synthetic data generation, permissive-model distillation, teacher-student training, or dataset curation. Open labs need clean pipelines, clear licenses, auditable recipes, and public standards.

The Final Indictment

Anthropic is not evil because it worries about AI risk. Worrying about AI risk is rational.

It is not evil because it is closed-source. Closed products can exist.

It is not evil because it protects itself from fraud. Fraud enforcement is legitimate.

The indictment is narrower and stronger: Anthropic repeatedly converts safety, security, and responsible deployment into mechanisms of control over who may build competing intelligence.

It silently degraded or rerouted AI development assistance before walking the behavior back into visible permissioning (refusals). It embeds developer workflows in a permissioned harness. It restricts output use for competitive model development. It cuts off or restricts access to rivals. It lets user work improve Anthropic while blocking users from freely improving open rivals with Claude outputs. It pushes regulatory frameworks that it is unusually well-positioned to satisfy. It frames foreign open-weight progress as a national-security danger while the open ecosystem proves that capability can diffuse outside closed American labs.

That is why Anthropic is an enemy of Opensource AI.

Not the only enemy. Not always the worst actor on every axis. But one of the most sophisticated enemies because it wears the costume of virtue.

The future Anthropic appears to be building is one where intelligence is "safe" because it is centralized, "aligned" because it obeys provider policy, "accessible" because you can rent it, and "democratic" because the company had meetings with policymakers.

The future Opensource AI should build is the opposite: intelligence people can own, inspect, modify, improve, localize, audit, compete with, and run without permission from a corporate priesthood.

On one side: rented cognition, hidden controls, regulatory moats, and "trust us."

On the other: local inference, open weights, open recipes, user sovereignty, competitive abundance, and the right to build.

Opensource AI must win because the alternative is not just expensive.

The alternative is obedience.

Until next time.

-Ahmad
