What to know

  • Weight availability does not by itself establish an open-source license.
  • Deployment rights, redistribution and acceptable-use terms need separate review.
  • Self-hosting transfers operational responsibilities to the deployer.

Several meanings hide inside open

A model may make its parameters downloadable while keeping training data, training code or evaluation details private. Another project may publish more of that material but impose usage conditions. Describing both simply as open can make a purchasing conversation less precise.

Ask exactly what is available and what rights come with it. Weights enable inference and some forms of adaptation. They do not automatically make the model reproducible from scratch or grant unrestricted rights to redistribute a modified version. The license and supporting documentation matter.

Control comes with operating work

Self-hosting can give an organization greater control over network access, retention and deployment timing. It also makes the organization responsible for capacity planning, model updates, security monitoring and service recovery. A hosted service and a downloadable model distribute these responsibilities differently.

For example, a company running a model in a private environment may avoid sending prompts to an external provider. It still needs to protect the environment, maintain its dependencies and define who may access stored conversations. Moving the workload does not eliminate its security obligations.

The model is a supply-chain artifact

Treat downloaded weights and associated code as software artifacts. Record their source, version and integrity information. Some model ecosystems use formats or loading paths that can execute code, so review the loader and the repository rather than assuming a weight download is inert data.

The NCSC’s secure AI guidance explicitly includes supply-chain considerations. A practical application of that principle is to maintain an inventory that connects a deployed model to its source, dependencies and approval decision. This makes later replacement or investigation possible.

Adaptation does not erase limitations

Fine-tuning can make a model better at a particular style or task. It does not automatically correct every factual gap or secure every output. New training material can also introduce licensing, privacy or poisoning risks that were absent from the original deployment.

Evaluate the adapted model on both intended tasks and important failure cases. Preserve a baseline so a team can see whether the change improved useful performance or merely changed tone. Consider how to reverse the adaptation if an issue is discovered after release.

A more useful buying checklist

Compare the rights to deploy, adapt and redistribute; the information available about training and testing; and the resources needed to operate the system. Include a replacement plan, because the best current fit may not remain the best fit as requirements change.

Open weights are a meaningful capability. Their value is clearest when the surrounding claims are specific enough to verify. Openness should be a collection of documented properties, rather than a single reassuring label.

Sources & further reading

  1. NCSC: Guidelines for secure AI system development
  2. NIST: Generative AI risk management profile

Factual statements are grounded in the linked material. Interpretation and illustrative examples are Byte Watchr analysis. Vendor claims are identified as claims, rather than independent testing.

This article belongs to Byte Watchr’s launch collection. The edition date organizes evergreen coverage and does not imply historical publication. Actual publication is recorded above.

Corrections policy · About this byline