Two years ago, publishing a model's weights was an activist gesture. Today, Chinese labs have turned it into an industrial strategy, a US state has published an open scientific model, and Anthropic has deemed it necessary to publicly formalise its position on the matter. The debate no longer pits idealists against merchants: it pits three coherent logics against one another.
This year we covered the publication of weights for several major models. It is time to lay out the debate properly, because it structures much of what is currently being decided.
Position 1: publishing accelerates and protects
The main argument is that openness produces safety rather than removing it.
Available weights can be inspected by independent researchers, which is irreplaceable for work on interpretability. You cannot study what you cannot access.
Openness also avoids concentration. This year we saw that a model can be cut off worldwide on a government's decision. A downloaded file cannot be cut off. That is the sovereignty argument we developed in our reference article.
Finally, openness drives prices down. A good part of this year's price cuts is explained by pressure from freely available models.
Position 2: publishing is irreversible
The opposing argument rests on a simple asymmetry. A model accessible via API can be corrected, restricted, monitored, withdrawn. A published model can no longer be any of those things.
If a model is later found to possess a dangerous capability, the closed version gets updated and the open version keeps circulating indefinitely, including stripped of its guardrails. We documented a concrete case with an open model integrated into an attack tool targeting hundreds of systems.
This position does not oppose openness in general: it argues that openness depends on the level of capability, and that beyond a certain threshold, particularly in offensive cybersecurity and biology, publication creates a risk that no subsequent fix can catch up with.
The third logic, the most recent, considers that the question goes beyond companies. When the US Department of Energy publishes an open scientific model, it is not taking a stance in a technical debate: it is making openness an instrument of public power. China follows the same logic through its labs. In this reading, a country that has no open model it controls is structurally dependent on others, and that is a sovereignty problem before it is a security problem.
What changed this year
Three developments have shifted the debate.
The gap has narrowed. When open models were clearly behind, the question was theoretical. They now closely trail the best closed models on several benchmarks, which makes the trade-off real.
Segmentation by size. The debate has become more refined between giant models, reserved for institutions, and mid-sized models like Qwen 3.8 at 27 billion, which deliver real democratisation. These two categories do not raise the same risk questions.
Documented incidents. Both camps now have concrete cases to cite, which makes the discussion less speculative and more tense.
What to take away
There is no obvious answer, and being wary of anyone who offers one with confidence is probably the best reflex.
What does seem solid, however, is that the question does not arise the same way depending on a model's capability. Publishing a 27-billion-parameter model capable of helping with document processing, and publishing a system that autonomously discovers novel vulnerabilities, are not the same decision. Treating both with the same argument, in either direction, amounts to not addressing the subject.
The real task would be to publicly define where that threshold lies, and by what criteria. That is precisely what the evaluation framework kept confidential could have brought to the debate, had it been published.