Meta, Microsoft, Nvidia, IBM, and others back open-weight AI

aipulsemedia
5 Min Read

Meta, Microsoft, Nvidia, IBM, and others back open-weight AI

Team all hands in as two dozen companies and organisations signed an open letter urging US policymakers to protect open-weight AI models.

Two dozen companies and organisations signed an open letter urging US policymakers to protect open-weight AI models.

The letter, published today (PDF), carries signatures from a list that spans direct commercial rivals and organisations with little obvious overlap in business model: Meta, Microsoft, Nvidia, IBM, Dell Technologies, CrowdStrike, Palantir, ServiceNow, Hugging Face, Perplexity, Mistral, Andreessen Horowitz, Y Combinator, the Linux Foundation, Mozilla and others.

The letter’s argument centres on a comparison between the open-source software movement of the 1980s and the current fight over whether AI model weights should circulate freely or stay locked behind commercial APIs.

Open-weight models are AI systems where the trained parameters get published for anyone to download, inspect, modify and run on their own hardware. That’s distinct from closed models like the frontier products offered by OpenAI or Anthropic through API access only, where the underlying weights never leave the vendor’s infrastructure.

The signatories frame open weights as the mechanism by which AI capability spreads beyond a handful of well-capitalised labs into what the letter calls the workflows of “factories, hospitals, farms, classrooms, and main street businesses.”

Their argument runs on three tracks:

  1. Open weights lower the cost of entry for startups and public institutions that can’t afford to train frontier models from scratch or pay per-token fees at frontier prices for routine tasks.
  2. They increase competition across the stack, from chips to cloud infrastructure to applications, which the letter says keeps costs down and prevents value capture by a small number of providers.
  3. Open weights also give enterprise customers a way to avoid vendor lock-in, since organisations running open-weight models control their own data and can adapt the model to internal requirements without depending on a single vendor’s roadmap or pricing decisions.

The security argument runs against instinct

The letter’s most pointed section addresses the risk case directly, and it’s worth reading closely because it inverts the usual framing around open models and security.

Once weights are released, the letter concedes, they’re beyond the original developer’s control. Modified versions become difficult to trace or reverse. A fine-tuned or stripped-down version of an open model can circulate with safety guardrails removed, and there’s no recall mechanism.

The signatories argue the answer isn’t prohibition. Their case rests on a comparison to cybersecurity: defenders facing AI-equipped attackers need access to models with comparable capability to detect and simulate threats, which closed, permission-gated systems don’t easily provide.

They extend this into a broader security claim, arguing that closed models aren’t inherently safer because they can be breached, misused, or fail in ways external researchers can’t observe or verify. Concentrating advanced capability behind a small number of closed providers, in this reading, creates single points of failure rather than removing them.

Open models, by contrast, let outside researchers examine behaviour, run red-team exercises, and identify vulnerabilities across many teams rather than relying on one vendor’s internal testing.

The letter draws a direct parallel to the “open-source is more secure than obscurity” argument that shaped decades of software security debate, though it doesn’t cite specific vulnerability-discovery data or incident figures to support the claim as applied to AI systems specifically.

Distillation gets a specific defence

The letter carves out space for one technique that’s become contentious in AI circles: distillation, where one model’s outputs get used to train or improve a second model. This is standard practice in machine learning research and product development, used for evaluation, validation, and capability transfer between models of different sizes.

The signatories draw a line between distillation as a legitimate technique and what they call “unlawful efforts to extract value from closed models,” arguing the former shouldn’t get swept up in restrictions aimed at the latter.

This reads as a direct response to disputes that flared after the rise of Chinese models like DeepSeek and Kimi, when several US labs suggested rival models had been trained by distilling outputs from their own closed systems without authorisation.

The letter’s position: address misappropriation through targeted legal and commercial mechanisms, not blanket restrictions on a technique the entire field depends on.

Share This Article
Leave a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *