Closed and open-weights AI each come with a failure you have to accept: control by a few providers, or capability that cannot be taken back once released.
- Closed means you only get access. The weights stay with the provider, who can reprice, restrict, change or withdraw the model.
- Open weights are not open source. You can download, run and modify the model, but the training data and pipeline are usually not released, so it cannot be rebuilt.
- The open layer trails the frontier by months, not years. What the leading closed models can do soon becomes something anyone can download.
- Open gives independence and costs control. Downloaded weights cannot be recalled, monitored or labelled, and guardrails applied on a provider's servers do not travel with the file.
- Watch the gap. If it keeps closing, oversight at the frontier protects less; if it widens, concentration becomes the bigger risk.
What the words actually mean
Closed means the weights stay on the provider's servers. You send text in and get text back; the model itself is never in your possession. It can be priced, rate-limited, restricted, updated or discontinued, and its behaviour can be changed underneath you between one Tuesday and the next.
Open-weights means the trained numbers are published. Download the file, run it on your own hardware, modify it, keep it. It is not "open source" — the training data and the pipeline that produced the model are usually not released, so it can be run and adapted but not independently reproduced. The distinction gets blurred constantly, often by people with an interest in blurring it.
The file is yours; the rights come from the licence. Some open-weights licences allow any use. Others bar commercial use by default, exclude some countries, or withdraw every right from companies above a revenue line. Read the licence next to the weights before building on them; the main ones are compared on AI labs outside the US.Mistral AI, Mistral Medium 3.5 licence, read at source 18 Sep 2026: “You are not authorized to exercise any rights under this license if the global consolidated monthly revenue of your company (or that of your employer) exceeds $20 million (or its equivalent in another currency) for the preceding month.”
The open layer trails the frontier by months, not years. Capability that costs hundreds of millions to reach becomes downloadable within roughly a year. Everything else on this page follows from that single measurement — and it is simultaneously the strongest argument against permanent concentration of power and the strongest argument that frontier safety measures cannot hold, because the capability does not stay at the frontier.Checked at source 11 Sep 2026 and confirmed. Epoch AI, Open models lag state-of-the-art closed models by 4 months: “Since January 2026, the most capable open-weight models have lagged frontier closed models by an average of four months in the Epoch Capabilities Index (ECI)… The average ECI gap was 8 points” epoch.ai. On the “within roughly a year” half, Epoch AI, Frontier AI capabilities can be run at home within a year or less: “Using a single top-of-the-line gaming GPU like NVIDIA’s RTX 5090 (under $2500), anyone can locally run models matching the absolute frontier of LLM performance from just 6 to 12 months ago” epoch.ai. See who builds AI for the labs on each side, recorded July 2026.
Ask what you actually hold. A model you can only query can be changed or withdrawn; open weights you can run and keep, but not rebuild.
The honest trade
No provider can tell you no
- Independent scrutiny. Researchers can examine a model they possess. They cannot examine one they can only query.
- No permanent dependence. A file that works today works in five years. A service does not owe you that.
- Privacy by construction. A model running on your own hardware sends nothing anywhere — the entire question of what a provider retains simply disappears. More in local or cloud.
- It breaks the five-company story. Without the open layer, this technology would belong to a handful of organisations outright.
Nothing can be withdrawn
- No recall. Weights that have been downloaded cannot be updated, restricted or taken back. Whatever a model can do at release, it can do permanently.
- Safety measures do not travel. Guardrails applied at a provider's servers are absent from a copied file, and the behavioural training on top can be stripped by anyone with modest resources.
- No provider is monitoring it. Post-release monitoring — one of the four layers of AI testing — simply does not exist for a model running on private hardware.
- No labelling either. Provenance schemes and transparency laws reach providers, not downloaded files. See how AI content gets labelled.
Weigh the trade, not the label. Open brings scrutiny, privacy and independence; it also means no recall, no monitoring and no provider guardrails once the file is copied.
Why "which is better" is the wrong question
Both positions are usually argued as though the other side is being reckless or naive. Neither is. They are choosing which failure to live with.
Choose closed, and you accept that a small number of organisations decide who may use the most capable systems, at what price, under what conditions, with the ability to revoke. Choose open, and you accept that capability, once released, is permanent and unmonitored.
There is no third option where the technology is both fully controllable and fully available. Anyone selling you that is selling something.
The direction of travel matters more than today's snapshot. If the gap keeps closing, safety strategies built entirely on frontier oversight become decorative — the capability arrives on consumer hardware regardless. If the gap widens, the open layer stops being a meaningful check and the concentration argument becomes correct after all. That gap is the single number worth watching in this field. Epoch AI, cited above, measures it; check its latest figure rather than trusting this page's snapshot.
The open layer is under-defended by people who benefit from it and over-blamed for risks that exist on both sides. It is the reason this technology is not simply owned. But the recall problem is real and not answerable by good intentions: a released capability is released forever. The defensible position is to support the open layer and stop pretending frontier safety measures protect anyone once weights are public — because they demonstrably do not, and building policy on the assumption that they do is how you end up with rules that bind only the people already following them.
Choose the failure you can live with, and name it. Closed leaves a few organisations in control; open makes released capability permanent. Neither choice removes the risk.