Model weights, called AI weights in the Open Source AI Definition, are the set of learned parameters that overlay the model architecture to produce an output from a given input. An AI model consists of the model architecture, model parameters including weights, and inference code for running the model.
The term covers the learned parameters of a trained machine learning model. That is a different sense from the sample weighting used in survey statistics, and from the loss weighting applied inside a training run. Most readers arrive with a further question sitting underneath the definition, which is what they actually receive, and what they are permitted to do with it, when a lab describes a model as open.
Key Takeaways
- Weights are learned parameters that overlay the model architecture to produce an output, and they sit alongside the architecture itself and the inference code as the parts of an AI model.
- Open Weights are the final weights and biases of a trained neural network, values that once locked in determine how the model interprets input data and generates outputs.
- The Open Source label sets a higher bar, because Open Source models and Open Source weights must include the data information and code used to derive those parameters.
- According to Article 53(2) of the EU AI Act, two of the obligations in Article 53(1) do not apply to providers of models released under a qualifying free and open-source license whose parameters, including the weights, are made publicly available, and that exception does not apply to general-purpose AI models with systemic risks.
- On July 30, 2024, the National Telecommunications and Information Administration concluded that, at the time of its report, current evidence was not sufficient to definitively determine that restrictions on open weight models are warranted, and suggested the government actively monitor a portfolio of risks instead.
How Do Model Weights Work?
Three stages sit behind any answer a model produces, and the weights carry information across all of them.
- Training sets the values.
- The values are locked in and saved to a file.
- Inference runs a new input through them.
Large language models follow the same sequence as a small image classifier.
1. Training Produces the Values
The Open Source AI Definition describes AI weights as the set of learned parameters that overlay the model architecture. It lists model parameters, such as weights or other configuration settings, among the components of the preferred form to make modifications to a machine-learning system.
Picture a mixing desk. The desk is the architecture, wired the same way for every session, and the weights are the positions of the faders and dials. Move the positions and the same desk produces a completely different sound.
2. The Values Are Locked In and Saved
Open Weights are the final weights and biases of a trained neural network, and those values, once locked in, determine how the model interprets input data and generates outputs.
A compiled binary is the closer industry parallel. You can run it, measure it, and patch it in places, but without the source and the build scripts you cannot rebuild it or audit how it was made.
3. Inference Runs an Input Through Them
At runtime, the weights overlay the model architecture to produce an output from a given input, with the inference code for running the model counted as a separate component.
Hardware sizing is the practical constraint that arrives with a weights download. OpenAI post-trained its gpt-oss models with MXFP4 quantization of the MoE weights, which lets the larger model run on a single 80-gigabyte GPU and the smaller model run within 16 gigabytes of memory.
The mechanism is settled, and the disagreement sits one layer up. The license attached to a weights release decides what openness means in practice, and the same parameters reach the public under four materially different arrangements, each documented in a primary artifact rather than in vendor marketing.
Can You Change a Model’s Weights?
Yes. When AI developers share these parameters under an OSI-approved license, they empower others to fine-tune, adapt, or deploy the model for their own projects, according to Open Source Initiative documentation.
OpenAI describes its gpt-oss models as fully customizable to a specific use case through parameter fine-tuning. Changing the values is the easy half, and whether you may distribute what you changed is a license question, answered further down.
What Is Inside a Model Weights File?
Safetensors is a simple format for storing tensors safely, as opposed to pickle, and it is zero-copy, per Hugging Face documentation. A file named model.safetensors is opened with safe_open and read tensor by tensor with get_tensor. Loading only part of the tensors uses get_slice, which the documentation flags as interesting when running on multiple GPUs, and save_file writes tensors back out.
Hugging Face, EleutherAI, and StabilityAI are named as users of the format, in a list the documentation itself calls non-exhaustive.
What the container leaves out carries more weight than what it holds. Open Weights differ significantly from Open Source AI because they do not include the training code, the full training dataset, or comprehensive data transparency about dataset composition. By withholding those elements, developers only provide a glimpse into the final state of the model.
The comparison below is the Open Source Initiative’s own, transcribed row by row.
| Feature | Open Weights | Open Source AI |
|---|---|---|
| Weights and biases | Released | Released |
| Training code | Not shared | Fully shared |
| Intermediate checkpoints | Withheld | Nice to have |
| Training dataset | Not shared or not disclosed | Released, when legally allowed |
| Training data composition | Partially or not disclosed | Fully disclosed |
Source: Open Source Initiative
Why Do Model Weights Matter?
Dual-use foundation models with widely available model weights diversify and expand the array of actors, including less resourced actors, that participate in AI research and development. They also decentralize AI market control from a few large AI developers, according to the National Telecommunications and Information Administration. Making the weights of certain foundation models widely available could also engender harms and risks to national security, equity, safety, privacy, or civil rights, the same report states.
Regulation has already attached a consequence to the choice. Article 53(2) of the EU AI Act disapplies two of the obligations in Article 53(1) for providers of AI models released under a free and open-source license that allows for the access, usage, modification, and distribution of the model. The same provision requires that the parameters, including the weights, the information on the model architecture, and the information on model usage, are made publicly available.
The same regulation treats weights as an asset to be defended in Recital 115, which says cybersecurity protection related to systemic risks should duly consider accidental model leakage, unauthorized releases and model theft, and could be facilitated by securing model weights, algorithms, servers, and data sets. Meeting the rest of the regime is a separate calculation, tracked in our EU AI Act compliance cost data.
Weights are the one component of a model that copies perfectly and cannot be recalled. Every access decision a lab makes therefore runs one way only, which is why the license attached to a download does more work than the download itself.
Across our AI coverage, the same pattern keeps surfacing. Capability rankings churn every few months, while the licensing arrangement around a release outlives several model generations.
Pros, Cons, and Risks
Advantages
- Published parameters let others fine-tune, adapt, or deploy the model for their own projects when those parameters are shared under an OSI Approved License.
- Widely available weights decentralize AI market control from a few large AI developers.
- A qualifying open release relieves the provider of two of the obligations in Article 53(1) of the EU AI Act.
- A permissive license can travel with the release, as with the Apache 2.0 license OpenAI lists among the gpt-oss highlights.
Trade-offs and Risks
- Reproducibility breaks down because without training code or intermediate checkpoints, researchers and auditors cannot replicate the model’s development process.
- Data opacity persists, since Open Weights often do not clarify how the dataset was constructed or cleaned.
- Disclosing only the final weights may not meet emerging regulations, and Open Weights limit meaningful contributions to superficial fine-tuning rather than in-depth improvements.
- The EU AI Act exception does not apply to general-purpose AI models with systemic risks.
Neither posture removes risk. Publishing parameter changes changes who carries the risk, and withholding them changes who is able to check the work.
Types of Model Weight Access
At the closed end, the National Telecommunications and Information Administration defines limited access as AI models that do not give access to model weights, source code, or training data. One step out, Meta’s Llama 3.3 Community License Agreement defines Llama 3.3 to include trained model weights among other elements. It grants a non-exclusive, worldwide, non-transferable and royalty-free limited license to use, reproduce, distribute and modify the Llama Materials.
Further out, OpenAI describes the gpt-oss series as open-weight models and lists a permissive Apache 2.0 license among the release highlights. At the far end sits Open Source AI. That label also requires data information detailed enough for a skilled person to build a substantially equivalent system, the complete source code used to train and run the system, and parameters made available under OSI-approved terms.
| Access tier | What you can download | Example | Condition attached |
|---|---|---|---|
| Limited access | Nothing beyond the interface | Models offered through an API only | No access to weights, source code or training data |
| Community license | Trained model weights and documentation | Llama 3.3 | Redistribution conditions plus a commercial threshold |
| Permissive open weights | Trained model weights | gpt-oss-120b and gpt-oss-20b | Apache 2.0 license terms |
| Open Source AI | Parameters, data information and training code | Systems meeting the Open Source AI Definition | Parameters under OSI-approved terms |
Sources: National Telecommunications and Information Administration, Meta, OpenAI, Open Source Initiative
The middle tiers are where the vocabulary breaks down. Both get called open source in ordinary conversation, while the Open Source AI Definition reserves that label for releases that also publish data, information, and training code. Release cadence is easy to watch, and our AI model release tracker does that, though the license name on a download page carries more information than the adjective in the announcement.
Real-World Applications
Meta: Weights You Can Download, With Conditions
The Llama 3.3 version release date is December 6, 2024. Meta’s Community License Agreement defines Llama 3.3 to include the foundational large language models and software and algorithms, including machine-learning model code, trained model weights, inference-enabling code, training-enabling code, and fine-tuning enabling code distributed by Meta.
Anyone who distributes the Llama Materials picks up conditions that travel with them:
- Provide a copy of the agreement.
- Prominently display “Built with Llama”.
- Include “Llama” at the beginning of the name of any AI model created, trained, fine-tuned, or otherwise improved using the Llama Materials and then distributed.
- Retain the attribution notice inside a “Notice” text file in all distributed copies, and adhere to the Acceptable Use Policy.
A separate license request to Meta becomes necessary when, on the Llama 3.3 version release date, the monthly active users of the licensee’s products or services are greater than 700 million monthly active users in the preceding calendar month. Those conditions travel with every derivative, which is why the “Built with Llama” string turns up on model cards that have little else in common. Our Meta AI adoption data tracks how far the family has spread.
OpenAI: Open Weights Under a Permissive License
OpenAI released two flavors of the gpt-oss series and describes both as open-weight models. The model card puts gpt-oss-120b on production, general-purpose, and high reasoning use cases, and gpt-oss-20b on lower latency and local or specialized use cases.
The vendor’s own wording is the useful part here. A company that sells API access chose the phrase open-weight for the release it gave away.
The European Union and NTIA: Two Governments, Two Postures
Recital 102 says general-purpose AI models released under free and open-source licenses should be considered to ensure high levels of transparency and openness if their parameters, including the weights, the information on the model architecture, and the information on model usage, are made publicly available.
A license should be considered free and open-source, the same recital adds, when it lets users run, copy, distribute, study, change and improve software and data under the condition that the original provider is credited and comparable terms of distribution are respected.
The NTIA report named Meta, Google, Microsoft, Stability AI, Mistral, the Allen Institute for AI and EleutherAI as developers that have released models with weights that are widely available, though not always their most advanced models. Widely available means open to the public by allowing users to download those weights from the Internet.
Its conclusion carried a time stamp. At the time of the report, published July 30, 2024, current evidence was not sufficient to definitively determine either that restrictions on such open weight models are warranted, or that restrictions will never be appropriate in the future.
One government wrote relief into statute and the other recommended observation. Both positions keep moving, which is what our AI regulation tracker follows.
What Is the Difference Between Open Weights and Open Source?
Open Weights stop at the parameters. Open Weights are the final weights and biases of a trained neural network, published without the training code, the full training dataset, or comprehensive data transparency about dataset composition, according to the Open Source Initiative. The Open Source label reaches further, because Open Source models and Open Source weights must include the data information and code used to derive those parameters.
The Open Source AI Definition anchors that label in the freedoms a release has to grant. Those freedoms are to use the system for any purpose without asking permission, to study how it works and inspect its components, to modify it for any purpose, and to share it with or without modifications. A precondition to exercising those freedoms is access to the preferred form to make modifications to the system.
Can You Use Open Weight Models Commercially?
The license attached to the release answers it, and the two published examples land in different places. Meta’s Llama 3.3 Community License Agreement grants a royalty-free limited license to use, reproduce, distribute, and modify the Llama Materials. It also requires a separate license request from Meta where, on the Llama 3.3 version release date, the licensee’s products or services had greater than 700 million monthly active users in the preceding calendar month.
OpenAI lists a permissive Apache 2.0 license among the gpt-oss release highlights. What Apache 2.0 permits in general sits outside anything the model card states, so the license text is the document to read before shipping work built on the weights.
Conclusion
The definition settles quickly, and the license does not. Open Weights are the final weights and biases of a trained neural network. The comparison the Open Source Initiative publishes puts training code, intermediate checkpoints, the training dataset, and dataset composition outside that release. A community license layers further conditions on top, with Meta requiring a separate license request where, on the Llama 3.3 version release date, a licensee’s monthly active users are greater than 700 million in the preceding calendar month.
The direction of travel runs from open as a marketing word toward open as a license test a regulator can apply. Europe already applies one, and the moment a legal consequence attaches to the wording, the wording stops being free. Anyone evaluating a release currently gets further by opening the license file than by reading the announcement.











































































