The Paramount Importance of Open Models for American AI

Visiting Fellow Michael Frank argues that open AI models are vital infrastructure for innovation in the United States, but a dominant, risk-focused view threatens to spark restrictive regulations.

Photo of abstract highway cutting through digital buildings

Recently, policy and technology debates have focused on the relative merits and risks of open AI models as opposed to their closed counterparts. Open AI models are not a niche technical preference. As infrastructure for startups, enterprise adoption, security research, competition, and broad AI diffusion, open models are of paramount importance for the future of AI in the United States.

What are Open Models?

Definitions of what constitutes “open source AI” cover a wide spectrum. At one end, the Open Source Initiative presents one the strictest definitions, with many requirements about freely and fully enabled use, study, modification, and distribution. For Large Language Models (LLMs) to meet this definition of open source, a model cannot merely be freely downloadable. The underlying data and training methodology must also be public. It must be free to modify and distribute. Engineers often favor this strict definition of open source AI. 

At the other end of the spectrum, a broader open source definition considers an AI model or system to be open if a user can download model weights and run it locally on their own hardware for free.

Some engineers argue it is heresy to refer to open weight models as “open source” if the training data and methodology are not freely downloadable, or if these models do not have liberal terms of use that allow for modification and distribution. Critics argue that price is just one element of defining something as open source, and insist that the model must also be wholly reproducible independent of the original developer. 

There are two counterarguments to this position. First, the training dataset is the entire scrapable internet, plus distillation from other AI models. Most users do not need full reproducibility to get the deployment, cost, auditability, and customization benefits of open weights.

Second, the vast majority of AI consumers think about open weights and open source as functionally the same, particularly when contrasted with closed weight models that must be called via an Application Programming Interface, or API. For agentic AI systems, the practical definition works well, since open weight models constitute a free input and the configuration of open weight models for agentic systems is not limited by a lack of access to training data or methodology. “Open models” catches both the strict and the narrow definition of open source, as opposed to closed source, pay-for “closed models.” 

Prominent examples of closed models are the families of LLMs made by OpenAI (gpt family of models) and Anthropic (Claude family). Open models include Nvidia’s Nemotron family, Google’s Gemma family, and a variety of Chinese-developed models from developers like Zhipu, DeepSeek, and Kimi.

Why Open Source AI is a Strategic Imperative for the United States

The vast majority of future consumer welfare and economic growth will derive from AI-powered applications. Models are just one sliver of the AI stack. Most AI-powered applications will use open models.

There are five layers of the AI stack: energy, chips, cloud infrastructure, models, and applications. In the internet era, applications created nearly all of the economic value and benefit to consumers, a widely accepted thesis among tech historians and venture capitalists. Most applied AI startups are optimizing for open models to build specialized systems that vastly outperform generalist tools like ChatGPT and Claude Code.

There is a disconnect between Washington’s general fear of and hostility towards Chinese-developed open models and the American AI startup community’s enthusiasm for them. One American founder of an AI infrastructure startup recently told me that he was able to get his personal monthly AI bill from $800 down to zero thanks to open source models. More revealing, Lindy, a generalist AI assistant, recently announced that they were abandoning Anthropic’s Claude Sonnet (a closed model) in favor of DeepSeek V4 Flash (an open one). In the announcement, Lindy laid out the decision that applied AI startups face: “Keep the product reliable. Move work to cheaper intelligence when the evidence says you can. Use the savings to make the business work.” 

Few people would dispute that American AI leadership depends on a vibrant startup ecosystem. Open models can be an enormous tailwind to American AI startups. The money applied startups save on open models instead can go towards cloud infrastructure, non-AI development, better data, and offering better prices to customers.

Open models will also play a major role in maximizing the return on corporate AI deployments, which are often many orders of magnitude larger. Companies seeing massive bills from closed models are already starting to ration their usage. Some companies have reportedly racked up bills on closed models in excess of hundreds of millions of dollars, draining annual R&D budgets in the first few months of the year. At a time of rapid experimentation and innovation, zero-ing out that line item will be the difference between narrow or broad AI diffusion throughout the entire American economy.

Who Supports Open Source, and Who Opposes It?

Among the American AI landscape, the primary opponents of open source AI are Anthropic, an AI company, and think tank analysts focused on cyber and Chemical, Biological, Radiological, and Nuclear (CBRN) security. 

Anthropic itself has categorized LLMs as possessing inherently dangerous capabilities. The company has staked out many public positions either overtly or implicitly hostile to open models, framing them and their training methods variously as CBRN proliferation risks, cybersecurity crises, and intellectual property theft. Anthropic CEO Dario Amodei likened their models to a nuclear bomb.

On the other hand, virtually the entire rest of the AI ecosystem, from big companies like Microsoft, Google and Nvidia to nearly every applied AI startup, strongly support open source and do not believe in the risks purportedly associated with LLMs. The vast majority of the AI ecosystem supports open models for the benefits outlined above, plus their implicit securitysafety, and value creation advantages—so much that few have felt the need to articulate what they believe is self-evident. An ecosystem that facilitates development and availability of open models will diffuse AI capabilities throughout the economy, identify and patch security vulnerabilities, and flag safety risks faster than one in which open models are treated as threats to be mitigated.

Think tank analysts focused on CBRN risks also have a misunderstanding of the risks. Biosecurity-focused researchers worry that AI could lower informational barriers to biological misuse, including by helping a malicious actor retrieve, combine, and operationalize technical information. Some also argue that open-weight models present distinct evaluation challenges because system-level safeguards can be removed, model-level safeguards can be modified, and released weights can spread irreversibly. 

But those concerns are not the same as a case for treating open models as a CBRN threat. The hard constraints on CBRN misuse are not merely text generation. They include tacit expertise, lab access, materials, equipment, procurement controls, synthesis screening, and detection. State actors are further constrained by the intersection of self-interest with international law and norms. Closed models can provide much of the same textual assistance through APIs, while foreign open models will remain available regardless of whether US policy restricts American developers.  For example, if the problem is biosecurity, Congress should strengthen biosecurity controls directly rather than suppressing the open model ecosystem that supports American startups, security research, transparency, and diffusion.

Conclusion

The principal threat to open models derives from perception, not reality. The view that LLMs are capable of vast terrors and catastrophes is a niche view within Silicon Valley. Recently, that niche view has dominated the political discourse as if it is a widely shared opinion among experts. It is not.

Unfortunately, the perception gap between closed and open models may incite regulatory action that locks in that gap, such as through a licensing regime (effectively closing all models) or outright bans on open model training or deployment above a certain capability.

The views expressed are the author's alone, and do not represent the views of the Wilson Center.

Author