By Robert Brennan, Former Google Engineer and CEO of OpenHands
The argument over open-weight AI is back. This time, it is not being driven by a hypothetical future model. It is being driven by increasingly capable Chinese models, renewed concerns about intellectual-property theft, and growing anxiety in Washington that the United States could lose control of the technology it created.
Those are legitimate concerns. But restricting open-weight AI would still be a terrible solution.
If a foreign company steals protected technology, sanction the company. If it violates intellectual-property law, prosecute the violation. If a model contains backdoors or presents a specific national-security threat, restrict that model.
But do not confuse the conduct or nationality of one developer with the broader question of whether people should be allowed to download, inspect, modify, and run AI models themselves.
Banning or heavily restricting open weights would not stop governments, intelligence agencies, large corporations, or well-funded criminal organizations from acquiring advanced AI.
It would stop researchers, startups, independent developers, nonprofits, and smaller institutions from accessing the same technology.
It would not eliminate the threat. It would eliminate much of our ability to respond to it.
The Debate Has Changed
In July, Nvidia, Microsoft, Meta, IBM, Palantir, CrowdStrike, Hugging Face, Mozilla, the Linux Foundation, and other organizations signed a joint letter urging U.S. policymakers not to impose premature restrictions on open-weight models.
That is an unusually broad coalition. It includes chipmakers, cloud and infrastructure providers, cybersecurity companies, enterprise software vendors, model developers, investors, and open-source institutions.
Open weights are no longer a niche concern for academics and hobbyists. They have become part of mainstream enterprise strategy and a central question in the global competition over AI.
The immediate backdrop is the rise of capable models from Chinese labs, including Moonshot AI’s Kimi K3. Its release prompted concerns that Chinese companies were catching up to leading American labs despite export restrictions on advanced chips. Policymakers have also raised questions about whether some foreign models were developed through unlawful extraction or distillation from American systems.
But several different issues are now being collapsed into one debate:
Should advance model weights be publicly available?
Should American companies use models developed by Chinese companies?
When does model distillation violate intellectual-property or contractual rights?
Does a specific model pose a national-security threat?
These questions require different answers.
If distillation involves theft, fraud, unauthorized access, or a breach of contract, address it through targeted legal and commercial remedies. Distillation itself is also a widely used technical process for making models smaller, cheaper, and more efficient. Prohibiting it broadly would harm legitimate research and American model development along with any intended target.
Regulate the misconduct, not the entire architecture.
Closed Models Are Not Inherently Safe
The strongest argument for closed models is centralized control.
When a model is available only through an API, its creator can monitor activity, block requests, revoke accounts, and update safeguards. When weights are downloadable, users can remove those safeguards and operate outside the provider’s oversight.
That distinction is real.
Open models can be used to create malicious software, disinformation, harassment, non-consensual imagery, and other harmful material. Once weights are released, they generally cannot be recalled.
But keeping models closed does not remove advanced AI from the actors most capable of causing widespread harm.
Governments can fund their own models. Large corporations can train or acquire them. Intelligence agencies can steal them. Sophisticated criminal groups can use models developed abroad, exploit commercial systems, or assemble capabilities from smaller components.
The actors capable of launching state-scale cyberattacks, industrial disinformation campaigns, or AI-enhanced military operations will not be meaningfully stopped by preventing a university researcher or startup from downloading model weights.
Closed systems also introduce risks of their own.
A small number of companies decide who gets access, which uses are permitted, what activity is monitored, how information is retained, and when access can be revoked. Outside researchers can test the interface, but they cannot fully examine the underlying system. Customers must trust the provider’s security, policies, finances, political neutrality, and continued willingness to serve them.
Closed models can still be breached, manipulated, or misused. Their failures may simply be harder for outsiders to detect. Concentrating advanced AI behind a handful of companies creates a single point of technical, economic, and political dependency. That concern was central to the industry’s July letter.
That is not safety. It is centralization.
Open Models Give Defenders a Chance to Fight Back
AI security will not be achieved by ensuring that only the largest companies possess advanced models.
We need independent researchers to discover vulnerabilities, evaluate dangerous capabilities, reproduce results, challenge vendors’ claims, and build defenses. That work requires meaningful access.
Open weights let researchers test how systems behave under adversarial conditions. They can study model manipulation, develop detection systems, reproduce security findings, test mitigations, and build safer deployment infrastructure.
They also allow companies, hospitals, governments, and other organizations to run AI on infrastructure they control. Sensitive source code, medical records, government information, and intellectual property do not have to be sent to a third-party API.
Openness does not automatically make a model safe. Model weights do not reveal every decision, dataset, or process that produced a system. But open access provides a stronger foundation for scrutiny than a chatbot interface and a corporate assurance that everything has been tested.
The answer is to build a serious safety ecosystem around open models: standardized evaluations, model documentation, provenance records, vulnerability disclosure processes, deployment guidance, independent audits, incident reporting, and enforceable accountability for harmful use.
Make openness safer. Do not pretend that eliminating openness eliminates risk.
AI Sovereignty Matters
There is also a broader question of sovereignty.
An organization that depends entirely on a proprietary API does not fully control its AI capability. The provider can change prices, alter the model, restrict a use case, discontinue a product, retain data, or terminate access.
For a small business, that is vendor lock-in. For a government or an entire country, it is a loss of technological sovereignty.
Open-weight models allow organizations and nations to operate AI on infrastructure they control, govern their own data, customize systems for local needs, and avoid permanent dependence on a small group of foreign or domestic vendors.
This is one reason Nvidia CEO Jensen Huang has framed open models as important not only to innovation, but also to cybersecurity, safety, and sovereignty.
The United States should want American open models to become part of the global technology stack.
If the U.S. discourages open development, other countries will not stop. Developers will build on the models they can access, adapt, and deploy. Standards, ecosystems, technical talent, and commercial relationships will form around those systems.
Trying to preserve American leadership by limiting access to American technology would be self-defeating.
Neither Side Is Economically Neutral
It is also worth acknowledging that this debate is not purely philosophical.
Companies whose value depends on controlling access to scarce frontier models have an incentive to emphasize the dangers of openness.
Companies that sell chips, infrastructure, security products, hosting, and AI applications benefit when models become more widely available and interchangeable.
Neither business model is automatically right or wrong. But policymakers should evaluate the actual risks and benefits rather than treating either group’s commercial interests as a neutral theory of AI safety.
We also do not have to choose between a world in which every model is open and one in which every model is closed.
Closed systems have legitimate advantages. They can support centralized monitoring, managed updates, and controlled access. Some models may present capabilities that justify delayed release or tighter safeguards.
The mistake is not building closed models.
The mistake is designing policy around the assumption that closed models are the only model’s society should be allowed to use.
Punish Abuse, Not Access
Powerful AI will cause real harm. People will use it to deceive, harass, steal, impersonate, manipulate, and attack. Governments should strengthen laws covering fraud, defamation, non-consensual intimate imagery, cybercrime, discrimination, and deceptive political or commercial media.
Organizations deploying AI in high-risk environments should face obligations proportional to the consequences of failure. Hosting platforms should respond to illegal content, compromised models, and credible security reports. Model developers should disclose known limitations and cooperate with independent evaluation.
But there remains a fundamental difference between punishing harmful conduct and preventing the public from possessing a technology because it might be misused.
The former is how free societies generally respond to powerful tools.
The latter requires centralized permission, pervasive oversight, and the assumption that governments and large corporations are more trustworthy than the public.
A ban on open-weight models might stop some individuals from doing harm.
It would also consolidate AI inside the organizations already powerful enough to build it. It would weaken competition, limit independent research, reduce technological sovereignty, and deprive defenders of the tools available to their adversaries.
The United States should investigate theft, espionage, hidden backdoors, and dangerous uses of AI aggressively. But it should not use those threats to justify restricting an entire mode of technological development. Doing so would concentrate power in the hands of the few organizations already capable of building advanced models, while limiting the researchers, companies, and institutions best positioned to make them safer.



