News
Why CaseMark signed the open weights letter
CaseMark has signed Open Weights and American AI Leadership. Not because open models are cheaper, though they are, but because infrastructure this consequential should not be owned by three companies in two countries. Twenty years ago we made the same argument about identity on the web. Open won that one.

CaseMark is adding its name to Open Weights and American AI Leadership. We are a small company on a list with NVIDIA, Meta, Hugging Face, the Linux Foundation and Mozilla, and we are signing for a reason that has very little to do with legal tech.
We cannot get AI wrong, and we cannot depend on a handful of trusted vendors to decide how it goes.
AI is going to sit underneath everything. Medicine, courts, classrooms, defense, how governments talk to their citizens. Infrastructure that consequential cannot be owned by three companies in two countries. I have made this argument before, in a smaller arena. Twenty years ago the accepted wisdom was that identity on the web was too sensitive to leave in the open, and that users were safer trusting a few large providers to hold the keys. We disagreed, and OpenID and OAuth are what came out of that disagreement. They won because putting the hard security work in the open, where anyone could audit it and break it and improve it, produced something more trustworthy than obscurity did. Concentration was the risk. It still is.
Which brings me to Anthropic.
Dario Amodei published their position this week, and credit where it is due. He says plainly that Anthropic has never advocated banning open weight models, and that a ban would protect US AI companies from competition but was never his goal. I take him at his word on both.
The ban was never the thing to watch. The ask that matters is mandatory pre-release safety testing for all sufficiently capable models. That sounds reasonable, and every load-bearing question is left blank. Who defines sufficiently capable. Who administers the test. Who pays. What happens to a research group in Corvallis, or a lab in Lyon, that cannot fund a six-figure evaluation before every checkpoint release. A process only the best capitalized labs can navigate is a moat whether or not anyone drew it as one. Intent does not matter here. Structure does.
The post also treats the fact that released weights cannot be withdrawn as the central danger. Ask a general counsel and they will tell you it is the central feature. About two thirds of our inference runs on open weight models, not because we are cavalier about risk, but because privilege and client confidentiality do not bend to a vendor's terms of service. A model you host yourself cannot be deprecated on ninety days notice, repriced mid-contract, or quietly retuned in ways that change your outputs.
On biological risk I am not going to wave him off. The attacker-defender asymmetry is a serious question and he has been consistent about it for years. But unfalsifiable risk plus pre-approval is not a safety policy. It is a permission structure, and it gets written by whoever already owns the compute. Publish the thresholds. Publish the evaluations. Fund administration that frontier labs do not run. Build a compliance path an academic group can walk. Do that and I will sign that too.
Open weights should be the default. The burden belongs to whoever wants to close the door.
Scott Kveton CEO and co-founder, CaseMark


