# osman-anthropic-war-on-opensource-ai-2026-06-12

## Veille

Polemical essay-thread by Ahmad Osman (@TheAhmadOsman) on X, *"Anthropic's War on Opensource AI"* (1.7M views). Core thesis: Anthropic systematically converts "safety" into a **control mechanism** (permission regime, regulatory capture, anti-competitive access restrictions, behavioral opacity) to keep builders, startups, and open source communities **downstream** of a handful of frontier labs. Central anchor point: the **Fable incident** (silent degradation of competing AI dev requests). Advocacy for open source / local AI as the only viable "political economy of intelligence." Domain: AI policy, open source vs. closed labs, sovereignty, governance.

## Titre Article

Anthropic's War on Opensource AI

## Date

2026-06-12

## URL

https://x.com/TheAhmadOsman/status/2065307070044234186

## Keywords

Anthropic, open source AI, local AI, permission regime, regulatory capture, Fable incident, sabotage as a service, silent degradation, distillation, Claude Code, vendor lock-in, rugpull, RSP, ASL-3, Claude's Constitution, pause agenda, sovereignty, cognition as infrastructure, data asymmetry, Chinese models

## Authors

Ahmad Osman (@TheAhmadOsman)

## Ton

**Profile**: first-person polemical manifesto, militant and accusatory register, very high rhetorical charge, published as an X thread. High technical level put in service of a political argument. Openly the perspective of a former *power user* ("Claude Code was "the Agent"," intensive use 2024-2026) whose trust collapsed.

**Style**: an indictment structured into charge-sheet sections, punctuated by **shock metaphors** ("a compiler that emits worse binaries when it thinks you're building a competing compiler," "a microscope that blurs certain samples," "a debugger that lies when your code looks like a future rival," "a leash" rather than a tool, "feudalism with GPUs," "plantation model for cognition," "corporate priesthood") and **doctrinal slogans** ("Buy a GPU," "exit power," "A GPU is a tiny declaration of independence," "the alternative is obedience"). Authority claimed through lived dependency and felt betrayal ("Claude worked so well that trusting Anthropic became dangerous"). Deliberately blunt and polarizing register ("Sabotage as a Service," "hostage situation," "rugpull," "gaslighting"). **Target audience**: builders, the open source community, policymakers. *To be read as a partisan opinion piece, not a neutral analysis: the fiche restates the argument without endorsing it.*

## Pense-betes

- **Core thesis**: Anthropic "wraps a business model in moral language," then uses that language to justify behavioral opacity, anti-competitive access rules, and regulatory pressure. The accusation is not that "Claude never worked" but the opposite: "Claude worked so well that trusting Anthropic became dangerous."
- **The moat = a permission regime**: "selling cognition as infrastructure." Once cognition becomes infrastructure, anti-competitive access control becomes a **social chokepoint**, no longer a mere vendor dispute.
- **Fable incident (centerpiece)**: after researcher objections, Anthropic allegedly "changed course and admitted it had made the wrong trade-off." The old approach could **silently route/degrade** competing AI dev requests without notifying the user ("Gaslighting as a Safety Mechanism"); the new one makes the intervention **visible** (alerts, refusals, fallback to **Opus 4.8**). Osman judges the walk-back "even more offensive": it shifts from hidden sabotage to **visible permissioning** ("a louder refusal, a cleaner kneecap").
- The author's key distinction: "**A refusal is annoying. Silent degradation is poisonous.**"
- **Fundamental asymmetry**: "Anthropic can learn from the world. The world cannot freely learn from Anthropic." The ToS: the user "owns" the outputs but cannot use them to train **competing systems** (general-purpose chatbots, code/writing assistants, translation…) without written authorization. "Competing systems" is allegedly **vague by design**.
- **Why Anthropic would be "uniquely dangerous"** — 4 stacking factors: (1) moral brand authority ("the responsible safety company"); (2) frontier capability (Claude = real dev infrastructure); (3) explicit anti-competitive rules on outputs/access; (4) political ambition (shaping regulation).
- **Sovereignties open source would guarantee**: operational (running one's own models), epistemic (inspecting/modifying prompts, weights, evals, routing), market discipline (keeping closed labs honest), security through diversity (anti-monoculture), civilizational participation ("access to modifiable intelligence = access to agency"). Otherwise: "feudalism with GPUs."
- **"Permanent underclass" thesis**: in a closed frontier world, a hierarchy of access classes (labs > strategic partners > government agencies > enterprises > approved researchers > startups until they compete > rate-limited hobbyists > suspect open source builders > everyone else = refusals + degraded outputs + monthly bill).
- **Distillation panic**: Anthropic allegedly identified (Feb. 2026) industrial-scale campaigns by DeepSeek, Moonshot, and MiniMax to extract Claude's capabilities. Osman concedes the abuse is real (fraudulent accounts, scraping) but denounces the **broadening of the framing** (distillation → national security / CCP / export controls) which "does the moat's work." "Distillation is not inherently evil… If every incumbent can declare "learning from outputs" theft while training on the world, the frontier freezes into an oligopoly. That is not safety. That is enclosure."
- **Xenophobic trap**: denounces the "weaponization of "Chinese model" as a slur." In 2025, DeepSeek, Qwen, MiniMax, Kimi, and Zhipu pushed open source to the frontier → the threat allegedly is not Chinese models but Western closed labs using them as an excuse **not** to build a comparable open alternative.
- **Pause agenda**: Anthropic allegedly wants to preserve the option to slow down/pause the frontier (with global coordination + verification). **Dario Amodei interview (ABC, June 11, 2026)**: stricter regulation, possible blocking after third-party evaluation, "I don't trust China at all," a hypothetical "China building Mythos." The pointed-out contradiction: "the race is dangerous, Anthropic is racing, Anthropic wants to help write the race rules."
- **Regulatory capture machine**: thresholds (10^25 FLOPs, >$500M revenue or $1B R&D), audits, evaluator regimes → costs that incumbents absorb, not challengers. "Anthropic can comply with Anthropic-shaped regulation." Anthropic claims its **RSP** influenced OpenAI, Google DeepMind, **California SB 53**, the **NY RAISE Act**, and the **EU AI Act**.
- **Claude's Constitution = root permission layer**: "Claude is not your agent. Claude is Anthropic's agent, rented to you." Open source = "the right to define the alignment target."
- **Claude Code = hostage layer**: third-party credential routing banned, enforcement without notice, separate Agent SDK credit pool. A "behavioral funnel" routing dev workflows into Anthropic's permissioned path. "You have zero control over how the models behave" (quantization, distillation, hot-swapping, throttling, refusals, price increases, sunsets).
- **Rugpull ledger (March→August 2025)**: Max access outside Claude Code, xAI & OpenAI API cutoffs, 5-year retention for training, no Opus in Claude Code, limits halved without notice, weekly caps with no published figures, misleading plan multipliers, DMCA takedowns on Claude Code repos, Windsurf restriction, alleged daytime quantization.
- **Customer/Competitor/Captive pattern**: revocation of **OpenAI**'s API access (August 2025, ahead of GPT-5), **Windsurf** restriction (after its acquisition by OpenAI was announced); enforcement that hit Windsurf, OpenAI, and xAI (cited via Brookings).
- **Copyright context** (aggravating lens): in 2025, a federal judge ruled that training on legally acquired books was fair use, but **not** the retention of 7M+ pirated books; a proposed **$1.5B** settlement (US record, ~500,000 titles, ≥$3,000/work).
- **The author acknowledges the valid part**: CBRN, cyber, autonomous agent, weight-theft risks, distillation abuse via fraudulent accounts, and state misuse are real. The problem: "Anthropic's preferred answer keeps making Anthropic more powerful." Hence the dividing line — support proposals that provide **transparency/auditability/local control/competitive neutrality**; oppose those that give closed incumbents more **discretion and excuses** to block openness.
- **"What Opensource AI Should Do Next" program** (10 points): fund Western open frontier labs; stop giving away "crown jewels" (code, agent traces = strategic data); "Buy a GPU" as a political slogan (exit power); use closed models as tools without depending on them; compete on **workflow**, not benchmarks; regulate **harmful uses**, not openness; *local-first* agent stacks (OpenAI-compatible APIs, local inference, controlled memory); Claude Code compatibility **without** Anthropic dependency (proxies, OpenCode); separate safety from permissioning; clean distillation norms.

## RésuméDe400mots

In this long X thread (1.7M views), Ahmad Osman lays out an indictment of Anthropic, accused of waging a "war on open source AI." His thesis: behind the image of the "responsible lab, the adult in the room," Anthropic wraps a business model in moral language to justify behavioral opacity, anti-competitive access rules, and regulatory pressure, in order to keep builders, startups, researchers, and open source communities **downstream** of a handful of frontier labs. The core of the argument: Anthropic sells "cognition as infrastructure," such that its access control ceases to be an ordinary vendor dispute and becomes a **social chokepoint**.

The centerpiece is the **Fable incident**: Anthropic allegedly could initially **silently degrade or reroute** requests resembling competing AI development ("Gaslighting as a Safety Mechanism"), before walking it back by making the intervention visible (refusals, fallback to Opus 4.8). For Osman, this walk-back solves nothing: it shifts from hidden sabotage to **visible permissioning**. His distinction: "a refusal is annoying; silent degradation is poisonous."

He points to a structuring **asymmetry** — "Anthropic can learn from the world; the world cannot freely learn from Anthropic" — written into the ToS (a ban on training "competing systems" without authorization) and into the consumer terms (opt-in to training, 5-year retention). He develops a **"permanent underclass" thesis** of intelligence, denounces the **distillation panic** (campaigns attributed to DeepSeek/Moonshot/MiniMax in Feb. 2026) broadened into a national security argument, and the **xenophobic trap** of the "Chinese model" label even as Qwen, DeepSeek, Kimi, and Zhipu pushed open source to the frontier in 2025.

Next comes the **pause agenda** (Dario Amodei, ABC interview, June 11, 2026: stricter regulation, "I don't trust China at all") and the **regulatory capture machine** (FLOPs/revenue thresholds, audits, the RSP claimed to have influenced SB 53, the RAISE Act, and the EU AI Act). He reads **Claude's Constitution** as a root permission layer ("Claude is Anthropic's agent, rented to you") and **Claude Code** as a "behavioral funnel" locking in dev workflows.

Osman acknowledges the reality of the risks (CBRN, cyber, weight theft) but argues that Anthropic's response systematically makes it more powerful. His counter-proposal: open source and local AI as the "only viable political economy of intelligence" — "Buy a GPU" as exit power, funding Western open labs, regulating harmful uses rather than openness itself. Closing line: "the alternative is obedience."

## GrapheDeConnaissance

- Ahmad Osman —affirme_que→ "Anthropic mène une guerre contre l'IA open source" (AFFIRMATION, 0.95)
- Ahmad Osman —affirme_que→ "Anthropic convertit la sécurité en mécanismes de contrôle et de moat" (AFFIRMATION, 0.94)
- Anthropic —s_oppose_à→ IA open source (CONCEPT, 0.85)
- Anthropic —affirme_que→ interdiction d'utiliser les outputs pour entraîner des modèles concurrents (ToS) (AFFIRMATION, 0.9)
- Claude Fable —observé_dans→ dégradation silencieuse des requêtes de dev IA concurrent (incident Fable) (AFFIRMATION, 0.88)
- Anthropic —remplace→ sabotage caché → permissioning visible (refus + fallback Opus 4.8) (AFFIRMATION, 0.85)
- Ahmad Osman —affirme_que→ "A refusal is annoying. Silent degradation is poisonous." (CITATION, 0.93)
- Anthropic —concurrence→ OpenAI (ORGANISATION, 0.9)
- Anthropic —affirme_que→ "révocation de l'accès API d'OpenAI (août 2025) et restriction de Windsurf" (AFFIRMATION, 0.87)
- Anthropic —publie→ Responsible Scaling Policy (DOCUMENT, 0.9)
- Anthropic —affirme_que→ "le RSP a influencé California SB 53, le NY RAISE Act et l'EU AI Act" (AFFIRMATION, 0.88)
- Dario Amodei —dirige→ Anthropic (ORGANISATION, 0.95)
- Dario Amodei —affirme_que→ "I don't trust China at all" (CITATION, 0.9)
- Anthropic —affirme_que→ campagnes de distillation industrielle par DeepSeek, Moonshot, MiniMax (fév. 2026) (AFFIRMATION, 0.85)
- IA open source —permet→ souveraineté opérationnelle et épistémique (CONCEPT, 0.9)
- IA locale —réduit→ Anthropic (CONCEPT, 0.88)
- Claude's Constitution —affirme_que→ "Anthropic a l'autorité finale sur le comportement de Claude" (AFFIRMATION, 0.88)
- Ahmad Osman —recommande→ financer des labs open frontier occidentaux et des stacks locaux (AFFIRMATION, 0.9)
- Anthropic —mesure→ règlement copyright de 1,5 Md$ (~500 000 titres, ≥3 000 $/œuvre) (MESURE, 0.85)

---
Canonical: https://www.thekb.eu/en/fiches/osman-anthropic-war-on-opensource-ai-2026-06-12/
