How AI works

What is the difference between open weights and open source?

Short answerOpen weights means a model's trained numbers are published, so anyone can download, run, and adapt it. Open source, in the traditional sense, also publishes the code and often the training data. Nearly every model marketed as open is open weights only.

Open weightsOpen source
What is publishedThe trained weightsThe code, and often the data and license
What you can doDownload, run, fine-tune, and host it yourselfAll of that, and see how it was built
What stays hiddenThe training data and the processLittle, by design
How common in AINearly every model marketed as openRare

Models marketed as "open," Chinese and Western alike, are almost all open weights only. The training data and process stay closed.

What can be audited when the weights are public

The weights themselves can be examined and the model tested. What went into them cannot. Publishing weights publishes the result of training and keeps the training private: the data, the filtering, and the process. So what a model absorbed cannot be audited from outside, however open the weights are. Inspectable and auditable are different properties.

The benefits are real. There is no dependency on a single vendor, the model can be hosted on hardware you control, and building on it costs less.

Why this runs backwards from open-source software

In conventional software, publishing the code is what makes review possible: more people read it, and more flaws get found and fixed. Weights invert that. Publishing them exposes the artifact and leaves the process hidden, which gives a reviewer little to act on, while handing anyone the means to strip out safety behavior that was trained in. The instinct that open means safer is a good instinct aimed at the wrong object.

What cannot be walked back

A model served through an interface can be withdrawn, rate-limited, or changed after release. Downloaded weights sit on machines nobody controls, permanently, in the state they were released. A restriction imposed afterwards does nothing about copies already out, and a capability judged acceptable at release cannot be judged again later. Every other AI control assumes you can change your mind. Published weights are the one decision with no reverse gear.

Where the US federal position stands

The National Telecommunications and Information Administration (NTIA) examined the question in 2024 and recommended against restricting open weights at this time, favoring monitoring and the capacity to respond as evidence develops. The 2025 AI Action Plan went further: it endorsed open models and tasked NTIA with identifying barriers to their adoption by smaller firms.

The government also measures them. The Center for AI Standards and Innovation, inside NIST, publishes evaluations of individual open-weight models, including DeepSeek V4 Pro in May 2026 and Z.ai's GLM-5.2 in July 2026. It put the strongest open-weight model from China roughly eight months behind the American frontier on its own benchmarks.

One caution. Trade press in early August 2026 reported that open-weight models had been exempted from a new federal security review framework. We could not confirm that against any primary source. Treat it as unverified until the framework itself is published.

What this means for an organization

  • Ask which "open" a vendor means. Open weights tells you who can run the model. It tells you nothing about the training data. See Who built this model, and on what?
  • Treat self-hosting as a data decision. An open-weight model on your own hardware keeps prompts inside the organization. The training data question stays open either way.
  • Put your guardrails outside the model. Anyone holding the weights can remove the safety behavior trained into them, so test the copy you run and enforce your own rules around it.

Sources

  1. National Telecommunications and Information Administration, Dual-Use Foundation Models with Widely Available Model Weights, July 2024. The federal position on restriction, and the finding that open-sourcing makes built-in safeguards easier to remove or weaken.
  2. NTIA, Risks and Benefits of Dual-Use Foundation Models with Widely Available Model Weights. The open-source and open-weights risk asymmetry.
  3. NIST Center for AI Standards and Innovation, evaluations of open-weight models, published individually and dated at nist.gov/caisi.
  4. The White House, AI Action Plan, 2025. Endorses open models and tasks NTIA with identifying barriers to adoption by smaller firms.

Reviewed