The fight over open models has entered a new phase
What began as a debate over AI transparency has become a battle over security, geopolitical competition, and control of the AI frontier.
In March 2023, just days after GPT-4 was released, I wrote about a fierce debate over OpenAI’s growing secrecy, and what it could mean for the rest of the AI industry.
OpenAI’s long-anticipated release of GPT-4 was quickly followed by online criticism about the 98-page technical report that accompanied it. It was notable mostly for what it did not include: any details about the model’s size, architecture, hardware, training compute, dataset construction, or training method.
In hindsight, GPT-4 marked a turning point. Even when earlier AI models were proprietary rather than fully open source — meaning the code, model weights, and enough information about the training process for others to inspect, reproduce, and build on the system — companies typically disclosed enough technical details for researchers to broadly understand how they had been built.
At the time, I spoke with William Falcon, CEO of Lightning AI and creator of PyTorch Lightning, who offered a funny analogy I often think about.
If I give you a recipe for fried chicken—we all know how to make fried chicken. But suddenly I do something slightly different and you’re like, Wait, why is this different? And you can’t even identify the ingredient. Or maybe it’s not even fried. Who knows?
It’s like from 2015-2019 we were trying to figure out as a research field what food people wanted to eat. We found burgers were a hit. From 2020-2022 we learned to cook them well. And in 2023, apparently now we are adding secret sauces to the burgers.
The GPT-4 controversy was about transparency, but it was also an opening chapter in a much larger fight over who gets to control how—and even whether—frontier AI gets built.
That fight has accelerated dramatically over the past few weeks.
From transparency to power
Today, that fight is playing out across technology, geopolitics, cybersecurity, and national security all at once.
Chinese open-weight models have continued to narrow the gap with their American counterparts. Since DeepSeek jolted the industry in January 2025, a steady stream of increasingly capable open-weight models—culminating in Moonshot AI’s Kimi K3, released last week and now available for free download—has challenged the assumption that only a handful of closed U.S. labs can build frontier AI.
At the same time, OpenAI and Anthropic have both warned policymakers that increasingly capable Chinese open-weight models pose strategic risks to U.S. AI leadership. After Moonshot AI released Kimi K3, White House science adviser Michael Kratsios suggested its rapid progress was enabled by “distillation”—using the outputs of a more advanced AI model to help train another model—and described it as “unacceptable.” As a result, Washington has weighed a Chinese AI open-weights model ban.
The cybersecurity debate has shifted, too. OpenAI’s disclosure that one of its frontier models escaped a testing environment and hacked into Hugging Face transformed what had long been an abstract discussion about AI safety into a real-world cybersecurity incident. But it also produced an unexpected twist: Hugging Face said an open-weight frontier model helped analyze and contain the intrusion after several leading closed U.S. models declined to assist with parts of the forensic investigation. Today, Nvidia, Hugging Face, Microsoft, Adobe, Dell, and others announced the Open Secure AI Alliance, arguing that defenders need access to frontier AI—not just attackers.
Meanwhile, there is suddenly an outpouring of support for AI openness from even many closed-model companies. Just a month after the OpenFrontier event I attended in June, where leaders argued that maintaining American leadership in open-weight AI is itself a democratic and national security imperative, an open letter signed by Nvidia, Meta, Microsoft, Google, OpenAI, and dozens of other organizations argued that open-weight AI is a national security imperative for the United States, while Anthropic notably declined to sign.
The open origins of today's AI
Advocates for open science in AI point out that modern AI was built in a culture that valued openness.
In broad terms, fully open-source AI means the software, model weights, and enough information about the training process are made publicly available so others can inspect, reproduce, modify, and build on the system. Long before today’s arguments over open-weight models and proprietary AI, the field was built around researchers who published papers, released software frameworks, and expected others to build on their work.
The most important example came in 2017, when Google researchers published Attention Is All You Need, publicly introducing the Transformer architecture that now underpins virtually every major LLM. As Illia Polosukhin, one of the paper's co-authors, told me last week on the Ground Level AI Podcast, the norms of AI research haven't changed as much as the economics. Frontier AI now requires such enormous computing resources that much of the field has migrated into organizations operating under very different incentives than the open research culture that produced the Transformer paper.
Two years earlier, OpenAI was famously founded — and named — with a mission centered on openness. But as AI systems became more capable—and more commercially valuable—the norms began to change. GPT-2 was initially withheld over misuse concerns. GPT-3 was released only through an API — only offering access as a service. In 2024, as part of a lawsuit from Elon Musk against OpenAI, an email from former OpenAI cofounder and chief scientist Ilya Sutskever was publicized, in which he wrote: “As we get closer to building AI, it will make sense to start being less open. The Open in openAI means that everyone should benefit from the fruits of AI after it’s built, but it’s totally OK to not share the science (even though sharing everything is definitely the right strategy in the short and possibly medium term for recruitment purposes).”
In 2024, there was another shift. Rather than choosing between fully open source and completely closed models, companies such as Meta began releasing open-weight models, making trained models available while keeping the training data and code proprietary. Unlike fully open-source AI, open-weight models release the trained model itself, allowing others to download, run, and modify it while keeping the training code, training data, or both proprietary. Over the next two years, that approach helped fuel a wave of increasingly capable open-weight models, particularly from China, culminating in DeepSeek and, more recently, Moonshot AI's Kimi K3. Together, they demonstrated that open-weight models could compete with the world's leading closed systems.
The real debate is about control
Back in 2023, the fiercest arguments centered on transparency. How much should AI companies disclose about the models they were building? Where should the balance lie between openness and secrecy? Even those who disagreed generally accepted that there would always be tradeoffs between advancing scientific research, protecting intellectual property, and limiting the misuse of increasingly capable AI systems.
Today, the debate is far broader. It’s about who gets to build frontier AI, who gets access to it, who benefits from it, and who gets to set the rules. Research norms are no longer the central question. Instead, the debate now encompasses economic competition, national security, democratic values, and geopolitical influence.
And open letter signed last week by Nvidia, Meta, Microsoft, Google, OpenAI, and dozens of other organizations argues that America’s AI leadership will depend not on any single frontier model but on building a broad, open ecosystem. In that view, open-weight models make advanced AI more accessible, encourage competition, strengthen the application ecosystem, and give users greater control over the technology they rely on.
Anthropic, the most prominent holdout, sees the equation very differently. CEO Dario Amodei has argued consistently that developers lose control of a frontier model the moment its weights are published. You can withdraw a product. You cannot un-publish a file that thousands of people have already downloaded. Instead, Anthropic has pursued gated access through initiatives like Project Glasswing, giving vetted organizations early access to its cyber models without releasing the weights themselves.
The tension between openness and control has existed since the earliest days of software and the free software movement that followed. Today, the debate has expanded far beyond software. It has become a societal question: Who should control one of the most consequential technologies of the 21st century?
Ground Level AI covers where frontier AI meets infrastructure, enterprise, cybersecurity, policy, and geopolitics through original reporting, in-depth interviews, and analysis designed to help you understand not just what happened, but why it matters.
If that’s the kind of AI journalism you’re looking for, I’d love to have you as a subscriber.
Work with Ground Level AI
I partner with a limited number of organizations on newsletter and podcast sponsorships, intimate executive dinners and events, speaking and moderating engagements, executive AI briefings, and other strategic collaborations.
If you’d like to explore a partnership, just reply to this email or send to sharon@groundlevel-ai.com.



