Open Weights Are Not Open Source
And This Isn’t Just a USA-China Debate
This article is originally published in LinkedIn on July 31, 2026. View the LinkedIn Article Here.
Preamble:
I’m Bhavesh Senedhun, and I’m writing this article at the request of LinkedIn Senior Editor Tanya Dua, who emailed me today to ask whether Anthropic’s position is backfiring. My view is that the real issue goes beyond open weights and export controls. Open source offers a way forward. By levelling the playing field, it may give humanity its best chance of collectively identifying the bad actors.
Open-weight models have attracted plenty of enthusiasm at least since July 27, when Moonshot AI’s Kimi K3 weights were made public. Conversations do not have to pass through an American cloud provider, so sensitive information can remain within the organisation’s own environment. The model can also be fine-tuned or benchmarked without relying on the developer’s servers.
Open-weight releases benefit from associations established by open-source software. The term recalls Linux and collaborative research. It also suggests freedom from corporate control. Yet a model can provide broad access to its final parameters without disclosing enough information for outsiders to reconstruct or fully audit it.
That gives users a meaningful degree of technological independence. The word “open,” however, can obscure how limited this independence is. A downloadable model arrives as a finished machine. Its engineering history may remain inaccessible, along with the records needed to reproduce its construction or investigate the decisions behind it.
Debates about open AI often compress several questions into one. Open weights address the most immediate question by giving users access to the finished model. They reveal much less about how it was produced. Whether researchers elsewhere can build a comparably capable system is a separate issue.
The Open Source Initiative has spent decades defining openness in software. Its AI definition requires meaningful freedom to use and study a system, with permission to modify and share it. Those freedoms depend on access to the preferred form for making changes. This includes the relevant code, as well as sufficiently detailed information about the training data and development process.
The original training corpus may remain unavailable, including the material deliberately excluded from it. Developers do not necessarily disclose their filtering rules or deduplication methods. Synthetic-data sources may stay private. The same is true of reward models. Annotator instructions, reinforcement-learning datasets and intermediate checkpoints are often withheld. Parts of the training pipeline may be unavailable as well.
Even with these omissions, open weights permit local deployment and independent benchmarking. Researchers can conduct mechanistic studies or security testing without being confined to an API. They can also adapt the system for their own work. Possession of a verified checkpoint protects users against silent replacement or a later withdrawal of access.
LLM weights are matrices of numbers learned during training. They matter enormously, but they are the result of that process rather than a record of how it was carried out. A typical release may include the model’s architecture and final parameters, along with the inference code and a licence. This alone may be enough to run the model locally or adapt it to a specialised task.
The original training corpus may remain unavailable, including the material deliberately excluded from it. Developers do not necessarily disclose their filtering rules or deduplication methods. Synthetic-data sources may stay private. The same is true of reward models. Annotator instructions, reinforcement-learning datasets and intermediate checkpoints are often withheld. Parts of the training pipeline may be unavailable as well.
Even with these omissions, open weights permit local deployment and independent benchmarking. Researchers can conduct mechanistic studies or security testing without being confined to an API. They can also adapt the system for their own work. Possession of a verified checkpoint protects users against silent replacement or a later withdrawal of access.
Calling this arrangement open source borrows a reputation earned by projects whose construction is open to inspection. “Open weight” already describes the narrower bargain. Even OpenAI uses the term for downloadable models that can be run or customised locally.
Moonshot AI describes Kimi K3 as a 2.8-trillion-parameter mixture-of-experts model in which only part of the parameter count is activated for each token. The downloadable weights and accompanying technical information amount to a substantial engineering release.
Running the weights locally gives an organisation direct control over how the model is deployed. Prompts stay on its own infrastructure, where it can set the rules for network access and logging. Checkpoint hashes let administrators verify that the model in use is the same one they originally evaluated. Researchers can also study its behaviour without relying on Moonshot's servers.
Much of the uncertainty concerns what happened before the release. Copyrighted or private material could have entered training without being identifiable from the checkpoint. Manipulated examples and poisoned data present the same problem. Published documentation may not reveal which synthetic outputs were used during training. Nor will it necessarily disclose behaviours found during post-training. Suppressed failures and unpublished evaluations are also difficult to recover from weights alone.
Sleeper-agent experiments have shown a limit of ordinary model testing. A system can behave normally until a trigger causes deliberately unsafe conduct. Some backdoors survived supervised fine-tuning and reinforcement learning. Adversarial safety training did not always remove them either.
This research does not implicate Kimi K3. It shows why possession of a checkpoint cannot settle every safety question.
NIST treats training data and source code as separate security concerns. It considers model weights separately as well. Its generative AI risk framework calls for documentation of training-data sources and safeguards against tampering throughout development.
Publishing a system as open source does not make it trustworthy by itself. Malicious software can be released openly, and a documented training process may still contain mistakes that reviewers overlook. Disclosure does, however, allow independent groups to inspect the data pipeline and see how material was filtered. They can try to reproduce parts of the process, compare their findings with the developer’s account and question its safety claims.
American institutions and technology companies do not all want the same thing from open AI. The result is a collection of competing positions rather than a single national policy.
Nvidia and Microsoft have backed a letter titled “Open Weights and American AI Leadership.” Meta and IBM support it as well, while Dell signed separately. The broader coalition includes Palantir and Hugging Face among hundreds of organisations. Its members argue that downloadable models encourage competition and give countries more control over their digital infrastructure. They also say wider access helps researchers find weaknesses and devise safeguards. Microsoft reported on July 30, 2026, that the coalition had grown to more than 230 members.
These principles align with commercial interests too. Chipmakers make money when more models are deployed, while cloud providers benefit when organisations use their infrastructure to train or host them. Enterprise-software vendors have another incentive: models are more useful to them as interchangeable components than as proprietary gateways.
Frontier laboratories have made a different calculation. Anthropic supports strict limits on exports of advanced semiconductors and has backed controls on large-scale model distillation. It argues that an advantage in computing power could preserve a democratic lead in frontier AI. The company has also blocked Claude access for certain Chinese-controlled entities, despite saying that the decision cost it substantial revenue.
Anthropic treats lower-capability releases differently from future models that could have serious cyber or biological applications. Greater autonomy would add to those concerns.
OpenAI likewise supports the international distribution of American AI while arguing that export policy should protect the country’s technological advantage. Its submission on the U.S. AI Action Plan advocated exporting what it called democratic AI under controls designed to prevent that advantage from eroding.
Selected model releases can logically coexist with restrictions on the chips and infrastructure needed to train their successors. Specialised knowledge can be controlled for the same reason. In practice, this arrangement encourages worldwide adoption of American technology while reserving the frontier for American developers.
Meta benefits from a different outcome because strong open-weight models weaken businesses that charge for model access. As models become commodities, value can move towards infrastructure and applications. Advertising or distribution may then play a larger role. The philosophical argument about openness is therefore entangled with a contest between revenue models.
Advanced AI could support military operations or cyberattacks. Biological misuse presents another category of danger. These risks form the safety case for export controls. Governments considered especially risky can be denied cutting-edge chips and models, leaving approved actors with a capability lead.
Policy makers rarely separate that safety rationale cleanly from industrial advantage. Anthropic has argued that access to compute may determine whether Chinese developers remain months behind the American frontier. Semiconductor restrictions can preserve that gap. This may be a legitimate national-security objective, but it also maintains an international hierarchy in technical capability.
The United States has changed the design of its controls while keeping the same broad objective. In May 2025, the Commerce Department withdrew the Biden administration’s global AI Diffusion Rule, describing it as burdensome and harmful to relations with partner countries. It said semiconductor controls would instead be tightened through a different approach.
With restrictions already in force, the argument is now about how far they should extend and how long they should remain. Controls make training more expensive and large computing clusters more difficult to build, limiting the number of experiments a laboratory can afford. Older hardware is a poor substitute for advanced chips once electricity use and networking requirements are considered. Reliability makes the trade-off harder still.
Such restrictions are more likely to delay progress than prevent it indefinitely. Algorithms cross borders more readily than fabrication equipment, while older chips can be combined at additional cost as domestic manufacturing develops. Distillation can transfer some model behaviour without reproducing the original training run. Advances in engineering may lower computing requirements, and routing supplies through third countries makes enforcement more difficult.
The pressure also gives the target country an incentive to reduce its dependence on foreign technology. Denying China access to foreign chips or software encourages it to build an independent stack. Limits on cloud access add to that pressure. Recent Chinese model development suggests that controls can affect the cost and pace of progress, but a permanent technological barrier is difficult to envisage given China’s scientific and industrial capacity. Its financial resources make such an outcome less plausible.
China’s long history is sometimes invoked as a response to American technological nationalism. Its institutions can plan beyond Western election cycles and quarterly reporting periods. Industrial programmes may continue across several five-year plans instead of being redesigned whenever political control changes.
Long-term planning matters, but the age of a civilisation says little about whether it will govern AI responsibly. Ancient societies have produced scientific achievement and wisdom, alongside repression and war. Their longevity cannot tell us how a modern laboratory will behave or guarantee the conduct of a government or company.
Institutional capacity offers a stronger basis for judgment. China should not be presumed incapable of responsible governance simply because its political system differs from the American one. Chinese institutions have pursued industrial goals over decades, while American technology policy can shift sharply when a new administration takes office.
Neither country acts with a single purpose. Chinese academics may disagree with technology companies, while regulators may have different priorities from military institutions. American universities do not necessarily share Nvidia’s interests. Anthropic and OpenAI may disagree with the Commerce Department or with each other. Describing either civilisation as a unified actor hides the institutional conflicts that influence policy.
Export controls may buy time for work on governance. Whether that time proves useful depends on governments establishing international arrangements that can survive changes in national policy.
The United States promotes what it calls democratic AI. China stresses sovereignty and development while opposing containment. Each government points to the other’s surveillance or military activity, and both accounts are reinforced by cyber operations and propaganda.
Great powers regularly describe themselves as responsible custodians of dangerous technology. Yet if unilateral control of frontier AI is itself hazardous, a system based on the permanent supremacy of whichever state appears most trustworthy at the time is unlikely to remain stable.
Mutual auditability could provide a starting point for an international arrangement. Researchers outside the laboratory that created a model need enough access to find vulnerabilities. Smaller countries should also be able to examine systems on which they rely rather than accept the supplier’s assurances. Claims about bias or censorship must remain open to testing, as should claims about hidden capabilities. Defenders need the technical access required to build tools for detection and neutralisation.
Broader access carries serious risks. Safeguards can be stripped from downloadable models, which may then be adapted for cyberattacks or other harmful purposes. Once weights have been distributed around the world, recalling them is exceptionally difficult. Immediate publication cannot therefore be assumed harmless. Permanent corporate secrecy and national containment are still far from the only possible responses.
Frontier developers could be required to assemble an auditable package for every significant model. Cryptographic hashes would cover the weights and code, while datasets and checkpoints would have their own records. Reproducible tools would show how the data was curated and filtered. Further documentation would identify where the data came from and whether synthetic-data systems were used. Teacher models would be disclosed separately. The package would also include the methods used during training and post-training, followed by red-team findings and unresolved failures.
This material would not need to be released worldwide at once. Accredited independent auditors could receive intermediate checkpoints first. Institutions from several countries could then run standardised evaluations, rather than leaving the developer to assess its own model. Any poisoning incident or hidden behaviour would have to be reported. The same duty would apply if the weights were compromised.
The right to run a model matters but so does the ability to understand how it was built. We all should strive to question the claims made about it and develop defences independently. Those powers should not belong to one company or country alone in my opinion. National security should not become a standing excuse for preserving one country’s technical dominance either, be it China, the USA, or Mauritius for that matter.
References
Anthropic. “Anthropic’s AI Export Controls Framework Response.” April 30, 2025. Anthropic argues that controls on semiconductors and model weights could preserve the United States’ computing advantage over China.
https://www.anthropic.com/news/securing-america-s-compute-advantage-anthropic-s-position-on-the-diffusion-rule/Bureau of Industry and Security, U.S. Department of Commerce. “Department of Commerce Announces Rescission of Biden-Era Artificial Intelligence Diffusion Rule, Strengthens Chip-Related Export Controls.” May 13, 2025.
https://www.bis.gov/press-release/department-commerce-announces-rescission-biden-era-artificial-intelligence-diffusion-rule-strengthensHubinger, Evan, et al. “Sleeper Agents: Training Deceptive LLMs That Persist Through Safety Training.” arXiv, January 10, 2024. The researchers created proof-of-concept models whose triggered behaviour persisted through supervised fine-tuning and reinforcement learning. The behaviour also survived adversarial training.
https://arxiv.org/abs/2401.05566Kimi Team. “Kimi K3: Open Frontier Intelligence.” arXiv, July 2026. The report describes Kimi K3 as a 2.8-trillion-parameter mixture-of-experts model, with 104 billion parameters activated at a time. It also reports a context window of one million tokens.
https://arxiv.org/abs/2607.24653National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile. NIST AI 600-1. Gaithersburg, MD: U.S. Department of Commerce, July 2024. The framework covers the provenance and integrity of training data. It also addresses documentation and supply-chain risks.
https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdfNVIDIA et al. “Open Weights and American AI Leadership.” July 24, 2026. The industry letter argues that open-weight models encourage competition and innovation. It also presents them as supporting security research and American leadership in AI.
https://images.nvidia.com/pdf/Open-Weights-and-American-AI-Leadership.pdf




You are welcome!
Excellent read! Thank you for explaining the difference, so open source all the way!