In July 2025, Mark Zuckerberg published a letter on "personal superintelligence" that also warned about being careful with what Meta chooses to open source. The pairing is the whole policy problem in one page: a race toward general systems, and a release decision that cannot be undone once the weights are public.
What "open" means here
People say "open source AI" when they mean different things: open code, open data, open weights, open paper. The high-stakes fight is mostly about weights: the trained parameters you can download and run. Once those ship at frontier generality, anyone with enough hardware can fine-tune, strip filters, and keep a private fork forever.
Release is a one-way door. You can patch a hosted API. You cannot recall a torrent.
What openness genuinely protects
The strongest case for openness is not naivete. Closed concentration is a power risk. Independent researchers need access to find failures labs will not prioritize. Security through obscurity fails often. Researchers outside rich-country firms should not be permanent API tenants. Open tooling, open evals, and open science on systems we can still contain are goods worth defending.
The risk case without melodrama
At high capability, open general weights are proliferation. They multiply actors who can misuse bio assistance, cyber offense, persuasion, and autonomous agents. They also multiply independent experiments in long-running autonomy. Most will fail. Some will generate new techniques for evasion. Licenses and "responsible use" text do not contain a determined fine-tuner. Red-teaming before release helps and still cannot certify a model against every future scaffold and tool.
The strongest pushback
The fairest objection is that open weights democratize scrutiny and that closed labs are the real concentration hazard. Scrutiny helps on systems we can still patch and recall. Democracy of access is not the same as safety of capability. A world where only three firms host frontier models has governance problems. A world where highly general weights sit on every enthusiast GPU has different, harder ones.
"Bad actors already have it" is usually premature. Capability jumps. That a weaker model leaked last year is not a license to ship the next one. Timing matters.
Middle paths that are real
Graded release: open the small and the narrow; gate the large and the general. Structured access: trusted research environments, logged queries, and credentialed fine-tunes instead of a raw dump. Open tooling: keep compilers, eval harnesses, and safety research stacks open even when frontier weights stay closed. Those are policy choices, not vibes.
A decision tree for labs
Will this download still be useful after the next six capability jumps? If yes, treat it as a proliferation decision. If no, treat it closer to a normal product launch. Can independent security and biosecurity teams get the access they need without a public torrent? If yes, prefer structured access. If the only argument for opening is marketing parity with a rival, that is not a safety case.
What to do
Builders: default closed at the high end; publish evals and interfaces that enable outside scrutiny. Hosts and platforms: log and rate-limit high-risk uses; do not launder proliferation as "community." Policymakers: write triggers on capability and compute, not on the word "open"; require staged review before general weight drops. Individuals: prefer open tools on narrow systems; treat frontier-weight releases as civic events, not free swag.
The Foundation's line is simple. Narrow AI that stays tool-like can stay open and should. Programs aimed at artificial superintelligence should not be open-weighted into the wild while control is unsolved. Open science is not a suicide pact. See our plan.