The Model War
A fight over the most consequential technology of this century is being settled by licenses, weight files, and export rules — not by anyone you elected.

There is a war underway over the most consequential technology of this century, and most people do not know it is happening. It is not fought with tariffs or aircraft carriers. It is fought with licenses, weight files, and export rules. On one side are companies that keep their artificial intelligence models sealed behind an API, arguing that the technology is too dangerous to hand out. On the other are companies and governments releasing model weights to anyone with a download link, arguing that the technology is too important to lock up. Both sides claim to be protecting you. Neither side is entirely wrong, which is what makes the fight so hard to referee.
The vocabulary has been engineered to flatter
Start with what the words mean. A "closed" model, like the frontier systems from OpenAI and Anthropic, runs on the developer's servers. You send a request, you get an answer, and the company can watch, filter, and revoke your access. An "open" model, like Meta's Llama family or the systems pouring out of Chinese labs such as DeepSeek, ships as a file of numerical weights. Once you have the file, no one can watch what you do with it, no one can filter it, and no one can take it back. The open camp calls this freedom. The closed camp calls it proliferation. Both descriptions are accurate.
Closed
Access can be revoked
The weights never leave the developer's servers. Requests can be watched, filtered, and cut off the day a capability is discovered.
Open
Copies cannot be recalled
Once the file is downloaded, nobody watches what happens next. Safeguards become suggestions, and every copy keeps going.
The case for openness deserves respect
The modern internet runs on open source software because thousands of independent eyes found the flaws that no single vendor would have caught. Linux, encryption libraries, the web itself: all of it improved because outsiders could inspect it. Open weight advocates make the same argument for AI. A model that anyone can probe is a model whose failures get found. Researchers at universities that could never afford to train a frontier system can study open models, red team them, and publish what breaks. When DeepSeek released its R1 reasoning model in January 2025, academic labs around the world could suddenly run experiments on a frontier-class system for the cost of a few GPUs, work that had previously required a corporate partnership and a signed agreement.
There is also a blunter argument, the one made in national security terms. If American companies withhold open models, Chinese companies will not, and the developing world will build its hospitals, courts, and schools on Beijing's software. That argument moved from think tank papers to policy in 2025, when the American debate over open weights shifted from whether to restrict them to how to promote them. Openness, in this telling, is not charity. It is market share, and market share is influence.
Policies versus suggestions
Now hold that argument next to the other one. A closed model's safety measures are policies. An open model's safety measures are suggestions. Every major open model released with safeguards has had those safeguards stripped within days by hobbyists using techniques that cost a few hundred dollars in compute. The fine-tuned versions circulate freely, and they will answer questions the original refused.
For most misuse this matters less than the headlines imply, because the information was already on the internet. But the concern was never really about a chatbot repeating Wikipedia. It is about what the next generation of models can do that the internet cannot: walk a novice through a complex technical process step by step, correcting mistakes, adapting to available materials, functioning less like a document and more like a patient expert who never gets suspicious and never calls the authorities. A closed model that develops this capability can be restricted the day it is discovered. An open model that develops it has been copied ten thousand times before anyone notices.
The honest version of this debate admits that both sides are describing real futures. The dishonest version, the one that dominates the discourse, treats the other side's future as fantasy.
The war is being settled by default, not by decision
Here is what should worry you more than either camp's talking points. No legislature has voted on how much capability should ship in an uncontrollable format. The threshold moves every quarter, set by whichever lab releases next, and each lab's incentive is to release slightly more than its competitor.
Settled by default, not by decision
The threshold only moves one way
Meta releases open weights partly because commoditizing the model layer damages rivals whose business is selling model access. Chinese labs release open weights partly because it neutralizes American export controls on chips: you cannot embargo a file. These are rational corporate and geopolitical strategies. None of them are safety judgments, and yet they are producing the outcome a safety judgment would be supposed to produce, which is a de facto answer to the question of how much intelligence the public gets to hold.
The closed camp's unexamined danger
Concentrating frontier AI in three or four American companies creates a chokepoint that has no precedent in the history of general-purpose technology. Imagine if literacy had been licensed, or if the printing press had shipped with a remote kill switch controlled from Mainz. The companies holding closed models can already decide which countries get access, which research questions get asked, and which uses count as acceptable, and those decisions are made by trust and safety teams accountable to no electorate. The record of concentrated information gatekeepers, from broadcast networks to social platforms, does not suggest that this power stays neutral. It suggests that it gets used, first carefully, then commercially, then politically.
So the society-level danger is not open models or closed models. It is that we have framed a governance question as a product question. Whether a technology this general should diffuse freely is the kind of decision democracies exist to make, the way they made it, imperfectly, for firearms, for pharmaceuticals, for encryption. Instead the decision is being made in release announcements, and the public's role has been reduced to downloading or subscribing.
What a real answer would look like
Probably something neither camp wants to hear. It would treat openness as a dial rather than an identity, with the setting determined by measured capability rather than by business model.
A dial, not an identity
Set by measured capability, not by business model
Below the threshold
Ships open. The research and competition benefits are real and the marginal danger is not.
Above the threshold
Release requirements with teeth. Independent evaluation before the weights move, not a blog post after.
Models below a demonstrated risk threshold ship open, because the research and competition benefits are real and the marginal danger is not. Models above it face release requirements with teeth: independent evaluation before the weights move, not a blog post after. It would require capability testing that is public, adversarial, and standardized, so that the threshold is a fact rather than a negotiation. And it would accept an uncomfortable truth that the current debate is built to avoid: some future model will be too capable to open and too important to leave in private hands, and no institution currently exists that could hold it.
Building that institution is slow, boring, procedural work, the opposite of a model release. Which is why it is not happening, and why the war continues to be won, week by week, by whoever ships next. The question of who should control machine intelligence is being answered right now. It would be a good time to notice that nobody asked you.
Cogensec builds open integrity infrastructure for autonomous agents. Explore Agentegrity on GitHub, or read why we signed the Open Weights and American AI Leadership letter.
Related news
Open weights make AI competitive. Open integrity makes it trustworthy.
Why Cogensec signed the Open Weights and American AI Leadership letter, and why the security argument for openness extends to the agent layer.
Introducing Agentegrity: An Open Framework for the Structural Integrity of Autonomous AI
Agentegrity is now live at agentegrity.cogensec.com — an open, four-dimensional framework (AR, BC, RI, CP) for measuring whether autonomous AI agents can be trusted to act on their own.
Introducing Gideon: Open-Source Autonomous Security Operations
Open-source AI agent for defensive cyber ops—ethical, extensible, and GPU-accelerated. Built by defenders for defenders.