Open Weights · Late 2010s–present (Epoch AI's measured record)

Open Weights

오픈웨이트

The practice of publicly releasing the learned parameters of a trained AI model, principally its weights and biases, and those parameters themselves. In a neural network, weights are numerical values determining how strongly inputs contribute to the network's calculations, and a model described as having seven billion parameters contains roughly seven billion learned values. Publishing them lets others download, run and study the model, while permission to modify, fine-tune or redistribute depends on its licence. Open weights are distinct from fully open-source AI, since training code, the full training dataset and intermediate checkpoints are typically not released. The term is commonly applied to large language models, diffusion models and other generative AI.

In depth

Concept

An open-weights release makes public the billions of numerical parameters that define how a model interprets input and generates output. These parameters are the product of training, an enormously expensive process; sharing the weights means sharing the finished product, not the process that created it. The training data, fine-tuning choices and safety decisions that shaped its behaviour remain opaque, so the openness is real but partial, even though independent researchers can probe the model for biases, vulnerabilities and failure modes. Sources differ on the term's breadth: the Open Source Initiative (OSI) conditions open weights on release under an approved licence and stresses the absence of training code, dataset and data-composition transparency; Stanford HAI states simply that 'an Open-Weight Model is an AI model whose core components are publicly released, allowing anyone to download it'; Epoch AI treats any model with downloadable weights, including restrictive licences, as open. No single settled definition exists.

History

Openness is not a new concept. OSI answers the question 'Is Open Weights a new concept?' with 'Far from it', describing over a decade in which AI practitioners experimented with different ways of sharing or withholding information, balancing trade secrets against mounting calls for transparency. Epoch AI systematically collected data on the accessibility of model weights and training code for hundreds of notable models published since 2018; that 2018 boundary is a data-collection choice, not the origin of open weights, and the report marks its own 2024 figures as incomplete. Treating models with downloadable weights, including restrictive licences, as 'open', it found that a majority of notable models from 2019 to 2023 were open, reaching 66 per cent in 2023 and roughly 50 per cent cumulatively as of the report date. Open large language models lagged the best closed models by 5 to 22 months on benchmarks and by about 15 months in training compute; overall, once-frontier capabilities reached open models with a lag of about a year. No retrieved source identifies a specific first open-weights release; 2023 is documented as a year in which definitional and licensing milestones clustered, not as the origin of the practice.

On 24 February 2023 Meta announced the first Llama: the inference code was released under the GPLv3 licence, while access to the weights was managed by an application process granting access case by case to academic, government, civil-society and industry researchers under a non-commercial licence. On 3 March 2023 a torrent containing Llama's weights spread through online AI communities, and Meta issued takedown requests that month. In June 2023 Heather Meeker and OSS Capital began collecting community input on an Open Weights Definition, aiming to standardize licensing frameworks aligned with the Four Freedoms of free software but tailored to neural-network weights; the project stated at the time that it would not import privacy, human-rights or training-data-clearance subjects into its licensing principles. On 18 July 2023 Meta announced Llama 2 with Microsoft in three sizes (7B, 13B, 70B); in a departure from Llama 1, all models were released with weights and could be used for many commercial purposes. Stable Diffusion, an open-source text-to-image model, had first been released on 22 August 2022, and in 2023 Mistral AI also released the weights of Mistral and Mixtral.

In 2024 Meta released Llama 3.1 405B, and the OSI, after consulting experts over two years, published the Open Source AI Definition 1.0 (OSAID 1.0), requiring full release of the software for processing data, training and inference and access to details about the training data. DeepSeek released its V3 model in December 2024 and its R1 reasoning model on 20 January 2025 under the MIT licence, making widely known how China had been embracing open AI systems to reduce reliance on western software and gatekeeping.

On 5 August 2025 OpenAI released its gpt-oss models in two sizes, its first open-weight large language models since GPT-2 in 2019. They came under the permissive Apache 2.0 licence, allowing commercial use, and scored similarly to o3-mini and o4-mini on several benchmarks. In September 2025 a Swiss consortium released the fully open model Apertus, and in December 2025 the Linux Foundation created the Agentic AI Foundation, assuming control of some open-source agentic protocols created by OpenAI, Anthropic and Block. In July 2026 more than 20 companies, among them Nvidia, Microsoft, Meta, Palantir, Hugging Face, Perplexity, Mistral, the Linux Foundation, Mozilla and IBM, published an open letter urging US policymakers to protect open-weight AI models from possible premature restrictions, warning that restrictions would harm competition and drive innovation elsewhere.

Distinctions and licences

Open weights are contrasted with open-source AI. In the OSI's comparison table, weights and biases are released in both cases, but open-source AI fully shares the training code while open weights do not, intermediate checkpoints are withheld, and the training dataset is not shared or disclosed. The OSI's four freedoms for open-source AI are Use, Study, Modify and Share, whose precondition is access to the preferred form needed for modification and the practical means to use it. Weights alone fall short: without training code or intermediate checkpoints, auditors cannot replicate development or locate bias; dataset construction and cleaning remain unclear; final weights may not meet transparency requirements in finance, healthcare and public administration; and community contributions are limited to superficial fine-tuning. OSI frames open weights as 'a lesser evil' than fully proprietary AI and 'merely a starting point'.

The Model Openness Framework evaluates whether components such as parameters, source code, training data, evaluation results, intermediate checkpoints and technical documentation are publicly available under an open licence; releasing only the final weights represents a lower degree of openness than releasing the materials needed to study, modify and reproduce the model.

Licence terms diverge in practice. In July 2023 the OSI stated that Meta's Llama licence is not open source: the Open Source Definition forbids discrimination against persons or groups or fields of endeavour (points 5 and 6), whereas Meta's licence restricts commercial use for some users (paragraph 2) and restricts certain purposes through its Acceptable Use Policy. The OSI asked Meta to correct the misstatement that Llama 2 is 'open source' and noted that it does not question Meta's desire to limit competitive use, only the label. The Llama 2 Community Licence (version release date 18 July 2023) grants a non-exclusive, worldwide, non-transferable, royalty-free limited licence to use, reproduce, distribute, copy, create derivative works of and modify the Llama Materials; licensees may not use the materials or their outputs to improve any other large language model, and its additional commercial terms state that a licensee whose products or services, or those of its affiliates, exceeded 700 million monthly active users in the preceding calendar month must request a licence from Meta, which Meta may grant in its sole discretion. As of 2025 a plurality (39 per cent) of models released on Hugging Face used the permissive Apache 2.0 licence; some models such as the source-available Llama 3 grant some open-source benefits yet contain legal restrictions that deter companies fearing a future lawsuit or a change in terms, and similar fears exist for the large number of smaller models that do not specify a licence.

Legal status is contested too. Peter Henderson and Mark Lemley argue that open-weight licence terms are largely unenforceable because they presuppose intellectual-property rights in machine-learning model weights that do not exist: whereas computer programs are typically copyrightable as human-written expression, model weights are generated automatically by a machine-learning algorithm, and their functional nature likely precludes copyright protection. A 2020 Intellectual Property Owners Association whitepaper proposed a sui generis right in trained AI models.

Some large language models touted as open-sourced that are merely open weights and do not release training data and code have been criticized as 'openwashing' systems that are mostly closed. Artificial Analysis gives an 'Openness Index' of 83 per cent to Nvidia's Nemotron family for its greater transparency in methodology, pre-training data and post-training data, while China's frontier open-weights models broadly score under 50 per cent. Because the label 'open-source' can provide real benefits to companies hiring talent or attracting customers, the openwashing debate has implications for project success.

Relations and examples

Open weights are bound up with digital sovereignty. For years the dominant AI story was controlled access: a handful of companies, almost all American, made powerful systems available on their own platforms, APIs, prices and usage policies, so users could use the technology but never truly own it, being 'in some sense, a tenant'. Closed models such as ChatGPT, Gemini or Claude never leave the provider's servers, so the provider can change the model without notice, monitor usage, restrict topics, adjust pricing or revoke access entirely for any reason, including geopolitical decisions.

For the roughly 150 countries far from US or Chinese capabilities, developing a frontier model from scratch is unrealistic, given computing costs in the hundreds of millions of dollars, talent pools taking decades to build and absent data infrastructure. Open-weight models let institutions download a capable model, run it on local servers and fine-tune it on locally relevant data, addressing local languages, legal systems, health or agricultural challenges, without a single API call to a foreign company, usage monitoring or the risk of access being revoked for geopolitical reasons. The opportunity is conditional: a country that cannot reliably power a data centre cannot run these models locally, one without machine-learning engineers cannot fine-tune them meaningfully, and one without data-governance frameworks will struggle to curate local datasets. One analysis recommends that governments and institutions push for genuine transparency standards that go beyond open weights, engage with the models as adapters rather than mere users and treat the system as a governance question rather than only a technology question; the OECD and the Global Partnership on AI have begun developing policy frameworks in this area.

Open weights sit at the centre of a policy and safety debate. They can support local deployment, customization, independent research and competition without requiring access through the original developer's API, but widely distributed weights generally cannot be withdrawn and may be modified to remove safeguards. A 2024 report by the US National Telecommunications and Information Administration examined these benefits and risks and recommended continued monitoring rather than immediate restrictions. Microsoft's July 2026 policy paper acknowledges that once released the weights are beyond the original developer's control and modified versions difficult to trace or reverse, but argues the right response is not to prohibit open weights, presenting openness as a path to AI safety and security. The same paper frames open weights as the counterpart of the 1980s open-source software movement, arguing they expand access to the AI economy, strengthen competition across model developers and cloud, chips, applications and services, and give customers greater control against lock-in, and proposes that policymakers expand access to compute for startups and researchers, invest in shared training assets, and avoid premature restrictions. These are the paper's advocacy positions, not neutral findings. Open-source AI tends to get more support and adoption in countries and companies that do not have their own leading model and can undercut business and geopolitical rivals with the strongest proprietary models; Europe is a region pursuing openness as a digital sovereignty strategy to reduce the leverage countries like the United States can use in negotiations on topics such as trade. In private industry, companies moved at least some workload to open models for flexibility, greater control, fine-tuning opportunities and lower cost; AT&T, Thomson Reuters, Harvey, Nomura Holdings, Goldman Sachs, DoorDash and Accenture are among them, with reported use cases including software development and specialized tasks such as document review and legal agentic tasks.

Open-weights AI is a major geopolitical issue, sometimes characterized as an AI arms race or AI Cold War between the US and China. Broadly, models released by Chinese companies such as DeepSeek, Alibaba Cloud, Moonshot AI and Z.ai use an open-weights framework under more permissive licences like Apache or MIT, while US companies including OpenAI, Anthropic and Google DeepMind favour a proprietary framework, especially for larger models. Meta is an important exception, having released its Llama family with open weights for some time, so the formula that US companies favour proprietary frameworks is a simplification. Some US politicians have called to restrict US public access to Chinese AI tools.

Adoption is broad. According to OECD and Global Partnership on AI analysis, more than half of all commercially available foundation models in 2025 were released with open weights, fully or partially, and families such as Meta's Llama, Alibaba's Qwen and Mistral were widely used. According to Microsoft's analysis from early 2026, DeepSeek's market share across several African countries including Ethiopia, Zimbabwe, Uganda and Niger reached between 11 and 14 per cent. Research published in Nature Health identified open-weight models as enhancing healthcare delivery in low- and middle-income countries, and South Korea's 2025 national sovereign AI initiative was built substantially on open-weight foundations, with three domestically adapted models trending simultaneously on Hugging Face in February 2026.

Large language model families for which at least one version has been released with publicly accessible weights include BLOOM, DBRX, DeepSeek, Falcon, Gemma, GLM, gpt-oss, Granite, Hunyuan, Inkling, Jamba, Kimi, Laguna S, Llama, MiniMax, Mistral, Muse Glimmer, Nemotron, OLMo, Phi, Qwen and Step. As of August 2026 the largest open-weights models, with over a trillion parameters, were predominantly released by the AI industry in China: Alibaba Cloud (Qwen 3.8, 2.4 trillion), DeepSeek (V4, 1.6 trillion), Moonshot AI (Kimi K3, 2.8 trillion) and Z.ai (GLM-5.3, 753 billion). Outside China the largest were Thinking Machines Lab (Inkling, 975 billion), Nvidia (Nemotron 3 Ultra, 550 billion) and Mistral AI (Mistral Large 3, 675 billion). Kimi K3 was described as the largest open-weight frontier model as of July 2026, followed by Alibaba Cloud's Qwen 3.8.

The motives of releasing labs are layered. One analysis argues it would be naive to receive open-weight releases as pure generosity: for Meta the logic is partly competitive, since releasing capable open models free helps establish a baseline that makes proprietary models built on its infrastructure, such as advertising, cloud and developer ecosystems, more attractive, making it 'a distribution-and-influence play, not a charitable act'; for DeepSeek and Chinese labs the motivations span commercial ecosystem and soft power; and US export controls on advanced semiconductors appear to have forced Chinese labs toward leaner, more efficient training approaches producing cheaper, easier-to-share models. The same analysis states that OpenAI was founded in 2015 as a nonprofit to ensure AGI benefited humanity broadly and later converted to a for-profit structure, that Anthropic was founded by former OpenAI researchers, and that Elon Musk co-founded OpenAI, later sued it, and founded xAI. These are the cited source's claims about commercial motives and history, not independently verified facts. The analysis also notes that DeepSeek presented itself as a technology company that wanted to build capable AI, and that concerns about DeepSeek's data handling apply mainly to accessing it through its app or API, largely falling away where the open-weight model is run locally, the more persistent question being training-data transparency.

Meta's Llama models, which Meta describes as open-source, were adopted by US defence contractors including Lockheed Martin and Oracle after unauthorized adaptations by Chinese researchers affiliated with the People's Liberation Army came to light, and Chinese researchers used an earlier version of Llama to develop tools like ChatBIT, optimized for military intelligence and decision-making. The Open Source Initiative and others have contested Meta's use of the term open-source to describe Llama, because Llama's licence contains an acceptable use policy prohibiting use cases including non-US military use.

Open weights are commonly shortened to 'open' or 'open model', but the shorthand is contested. Epoch AI states that it uses 'open model' as shorthand for open-weight models 'whether or not the model's code or data is open', and notes open-weight models are often called 'open source'. The term 'open source' comes from software with publicly available source code, where 'open' means much more; model weights, a long list of numbers, do not provide transparency into how a model works the way source code does. That this shorthand is contested is a point the sources stress rather than a settled usage.

Sources

  1. Wikipedia (EN) Wikipedia article defining open weights as publicly released learned parameters of trained AI models, distinct from open-source AI.
  2. opensource.org Open Source Initiative page explaining open weights as final weights and biases of trained neural networks, clarifying their distinction from Open Source AI (no training code, dataset, or full reproducibility).
  3. hai.stanford.edu Stanford HAI definition: 'An Open-Weight Model is an AI model whose core components are publicly released, allowing anyone to download it.'
  4. diplomacy.edu DiploFoundation analysis (March 2026) on what open-weight AI means for smaller countries: the ability to run, fine-tune, and deploy models locally without API dependency on foreign companies.
  5. microsoft.com Microsoft policy paper (July 2026) framing open weights as a foundation for AI accessibility, competition, and institutional sovereignty, modeled on the earlier open-source software movement.
  6. Wikipedia (EN)
  7. opensource.org
  8. hai.stanford.edu
  9. diplomacy.edu
  10. epoch.ai
  11. heathermeeker.com
  12. Wikipedia (EN)
  13. Wikipedia (EN)
  14. technologyreview.com
  15. opensource.org
  16. ai.meta.com
  17. microsoft.com
← Glossary