A public decision guide to open-weight AI governance

What should the world do about open-weight AI?

Start with the choice, not the framework. Open-weight release can expand research, competition, scrutiny, and access. It can also make provider controls unable to reach every copy. That leaves a public decision: allow, guide, govern, restrict, or ban—and accept the risks of whichever path we choose.

31 canonical claims15 enforced exclusions13 policy mechanisms7 objection lensesEvidence cutoff · July 28, 2026

Lifecycle: Published review edition. The frozen source candidate passed its Phase 12 independent recheck and parent verification. Published July 30, 2026 by explicit instruction for review.

Boundary: Evidence remains frozen at July 28, 2026. This is policy research, not legal or operational advice.

First, name the problem

“Open source” is too broad to govern as one thing.

This site focuses on advanced open-weight AI releases—not open-source software, open science, or every model marketed as “open.” The trained weights may be downloadable even when code, data, licenses, and safeguards differ.

What openness can protect

Research, independent scrutiny, competition, local adaptation, education, and access can benefit when people are able to inspect and run a system.

What copying can change

After weights spread, provider monitoring, account controls, forced updates, or withdrawal may no longer reach every copy.

What copying does not prove

Persistence alone does not establish dangerous capability, misuse intent, human uplift, a severe-harm pathway, or the wisdom of a restriction.

The real public problem

When does a particular release create enough credible risk to justify burdening openness?

Society has to weigh two kinds of error: releasing too freely when control will be difficult to recover, and restricting too broadly when the evidence is weak. Either mistake can impose costs on people who did not choose them.

The policy menu

The choices are wider than “do nothing” or “ban it.”

Every path protects something valuable and exposes something else. The useful comparison is the likely benefit, burden, failure mode, and reversibility of each choice.

01 · Do nothing new

Allow release under existing law

Potential benefit
Maximizes permissionless research, scrutiny, adaptation, competition, and access while avoiding premature rules built on weak evidence.

Main risk
Relies heavily on action after misuse. Once weights spread, provider controls may not reach every copy, and public costs can fall on people who never chose the risk.

02 · Voluntary safeguards

Let developers and repositories set norms

Potential benefit
Can move faster than law and improve evaluations, documentation, repository practice, and incident sharing without a state mandate.

Main risk
Coverage and incentives are uneven. Actors creating the greatest risk may decline, underinvest, or defect, and harmed people may lack an enforceable remedy.

03 · Govern harmful use

Regulate conduct, not the release

Potential benefit
Targets malicious or negligent behavior rather than a general-purpose artifact, protecting lawful research and lower-risk use.

Main risk
Often depends on attribution, jurisdiction, and proof after distribution—or after harm. It may not address an irreversible release decision in time.

04 · Conditional governance

Set safeguards for particular releases

Potential benefit
Uses staged access, evaluations, documentation, safeguards, review, and appeal to match duties to demonstrated capability and an actual release profile.

Main risk
Evaluations are incomplete and can be gamed. Compliance cost and uncertainty can favor incumbents or chill legitimate work unless thresholds and review are disciplined.

05 · Targeted restriction

Delay or deny the highest-risk releases

Potential benefit
Can prevent a difficult-to-reverse loss of control when evidence supports a severe and credible pathway that weaker measures cannot address.

Main risk
False positives can suppress research, scrutiny, competition, civil liberties, and access; restrictions may shift release into less visible or offshore channels.

06 · Outright ban

Prohibit public weight release as a class

Potential benefit
Draws the clearest legal line and seeks to stop public distribution before copying makes recall difficult.

Main risk
Treats radically different releases alike, concentrates power in closed providers and governments, sacrifices lower-risk open use, and creates strong incentives to evade the rule.

A necessary companion to every option

Build resilience whether releases remain open or become restricted.

Better evaluations, secure repositories, sector-specific safeguards, provenance, incident response, international coordination, and remedies for affected people can reduce harm under any release regime. They complement—but do not settle—the release decision.

How to choose

Judge the evidence, the release, the remaining control, and the burden together.

A defensible decision should explain both what changes when weights are released and why the proposed response is better than less restrictive alternatives.

Capability evidence
What has this exact model or tested access condition actually demonstrated—and with what uncertainty?
Release delta
Which safeguards or forms of oversight disappear, persist, or become harder to enforce after copying?
Control and reach
Which actor can still change the outcome, under what authority, and across which jurisdictions?
Human burden
Who benefits, who bears error and enforcement costs, what rights are affected, and can the decision be appealed or reversed?

This site's answer

Govern what can still be governed—without treating openness itself as the offense.

The framework that follows favors evidence-triggered, release-specific, actor-specific safeguards. It rejects both automatic laissez-faire and a blanket ban, and it requires stronger measures to defeat less restrictive alternatives rather than merely sound precautionary.

Start with MAPS: Model Access, Permissions, and Safeguards. Then inspect the policy mechanisms, evidence limits, objections, and full paper.

Choose an audit path

The short route never hides the long record.

Start with the decision in front of you, then move directly to the evidence, objection, or full-paper layer that can challenge it.

The control boundary

A provider can change a service. It cannot reliably recall every copied weight.

Licenses, notices, patches, lawful action, provenance, preparedness, and response can still matter. Their reach is partial and must be measured; none is represented as a universal delete button.

Hosted or managed access

The provider may monitor use, remove an account, change safeguards, suspend access, or force an update—subject to law, notice, and appeal.

Weights after copying

Provider-side withdrawal no longer reaches every copy. Prospective distribution controls, notices, voluntary patches, reachable intermediaries, investigation, preparedness, and response remain partial routes.

The distinction is about control persistence, not a claim that every copy survives forever or that every hosted safeguard works.

MAPS

Model Access, Permissions, and Safeguards

MAPS is a release-profile framework only—never a model class, capability tier, or safety score. It records what is available and to whom, what the terms permit, and which safeguards depend on provider control or remain usable after copying.

Object

Which exact weights, revision, hosted configuration, or bounded access condition generated the evidence?

Assistance

What task, population, comparison, uncertainty, and estimand did the study actually measure?

Exposure

Which release-profile change would remove or preserve which provider-dependent control?

Pathway

Which policy-level barrier could the measured assistance change, and what barriers remain?

Object, Assistance, Exposure, and Pathway are four separate questions. The paper does not combine them into a composite risk score.

What the record actually says

Assistance is demonstrated in bounded settings. Catastrophic forecasts remain forecasts.

The evidence can justify better evaluation, preparedness, and a review process without being rhetorically upgraded into an observed catastrophe.

Biological tasks

Pooled access helped on tested digital work.

Zhang et al. estimated a 4.16-fold overall improvement for novice accuracy (95% CI 2.63–6.87). The treatment allowed multiple hosted services; it does not isolate one model, checkpoint, physical outcome, or catastrophe.

Physical-world trial

The preregistered primary result was null.

Hong et al. reported 5.2% versus 6.6%, P=.759, for the tested mid-2025 multi-model access condition. That is not proof of no risk, and it is not attributable to a named release.

Kimi evidence

A benchmark, hosted setup, and repository revision are different objects.

Kimi K2.5 has independent model-specific biological benchmark evidence and separately available weights. Kimi K3 has hosted cyber evaluation evidence and separately pinned repository metadata. Provenance does not make either pair identical.

Policy consequence

Improve decisions before imposing stronger burdens.

Pin the object, fund independent evaluation, publish methods and nulls, protect reporting and research, document safeguard limits, measure burden and control reach, and fund preparedness and response.

Evidence vocabulary

A label constrains meaning. It does not decorate certainty.

Observed fact, interpretation, forecast, proposal, and moral commitment are not interchangeable. A source can establish what happened or what an institution said without proving what should happen next.

observed fact
A dated source state, status, event, or metadata response.
evaluation result
A bounded test, study result, or institutional assessment.
legal rule
Operative or authoritative legal text, limited by jurisdiction and timing.
guidance
Voluntary, interpretive, standards-based, or administrative implementation route.
interpretation
A synthesis or inference that remains distinct from its underlying observations.
forecast/scenario
An explicitly conditional future or outcome proposition, never present fact.
policy proposal
A stated institutional plan, preference, or candidate rule, not an achieved outcome.
moral commitment
A nonbinding promise, principle, or value commitment.

Human consequence

No person, community, or jurisdiction is expendable to either failure.

Catastrophic-risk uncertainty cannot make affected people invisible. Neither can an overbroad response that closes research, accessibility, defensive security, local use, competition, or participation without a supported and contestable reason. Precaution must remain proportionate, reviewable, time-limited, and open to defeat by better evidence.