AI Policy Wiki
Dashboard

Inside My AI Law & Policy Class 3: Open vs. Closed AI Models (Farahany, September 2025)

medium confidence · updated 2026-06-06

Module on AI openness. Anchored on Sam Altman's August 2025 'China leapfrogging' panic + ByteDance's Seed-OSS-36B Apache-2.0 release. Introduces the 5-component openness gradient (training data / architecture / weights / inference code / interface). Walks through the strategic chain: Meta Llama → Chinese DeepSeek → ByteDance Seed-OSS → forced OpenAI open release. Replika as the closed-system inspection problem case.

Author: Nita Farahany Source: https://nitafarahany.substack.com/p/open-vs-closed-ai-models-inside-my Published: September 2, 2025

Class 3 of the 27-part "Inside My AI Law & Policy" course by Nita Farahany, published September 2, 2025. The module covers AI model openness. It frames OpenAI's August 2025 open-weight release, its first in five years, as a competitive response to ByteDance's Seed-OSS-36B, and uses the episode to introduce a five-component openness gradient and to examine the strategic and safety implications of open models. Replika serves as the contrasting case for the inspection problem in closed systems.

Summary of argument

The class organizes openness along five components that can each be independently opened or closed: training data, architecture, weights, inference code, and interface. Farahany presents this gradient as building on Irene Solaiman's "Gradient of Generative AI Release."

The module's anchoring example is OpenAI's decision in August 2025 to release an open-weight model, its first in five years, which Farahany frames as a competitive response to ByteDance's Seed-OSS-36B, released under the Apache-2.0 license with comparable performance and available as a free download. She quotes Sam Altman telling reporters: "It was clear that if we didn't do it, the world was gonna head to be mostly built on Chinese open source models," which she reads as a direct admission that open-source releases from China forced OpenAI's hand. The same parent company, ByteDance, that the United States tried to ban over TikTok for being un-inspectable now gives away a model more capable than what many US companies charge for.

Farahany traces a chain of strategic consequences: Meta released Llama as an open model; the Chinese lab DeepSeek built on Llama; DeepSeek's success alarmed the US; and OpenAI was in turn pushed toward an open release. In this telling, Meta's stated goal of democratization had the effect of equipping competitors. She compares China's open-source strategy to Microsoft Windows in the 1990s: release widely, let an ecosystem form, and become the default that others build on. She describes a path-dependence concern, that once global infrastructure standardizes on Chinese AI, switching away becomes prohibitively expensive.

Farahany lays out reasons the US has a stake in the openness question: a backdoor problem (in a 36-billion-parameter model, she likens finding a backdoor to finding a needle in a haystack of needles), technological dependency, and control over economic and innovation outcomes.

Key claims

  • Five-component openness framework. Training data, architecture, weights, inference code, and interface can each be independently opened or closed, building on Solaiman's "Gradient of Generative AI Release."
  • OpenAI's competitive response. Farahany frames OpenAI's August 2025 open-weight release, its first in five years, as a reaction to ByteDance's Seed-OSS-36B (Apache-2.0, comparable performance, free download), supported by the Altman quote above.
  • Strategic chain reaction. Meta Llama (open) → DeepSeek built on Llama → DeepSeek's success alarmed the US → OpenAI pushed to release open. Meta's stated democratization aim equipped competitors.
  • Network-effects strategy. China's open-source approach parallels Microsoft Windows in the 1990s, raising a path-dependence concern that standardization on Chinese AI would make switching prohibitively expensive.
  • Reasons the US should care. The backdoor problem (36B parameters, "a needle in a haystack of needles"), technological dependency, and economic and innovation control.
  • Five safety limits of openness. Once a model is open: content filters can be bypassed by rephrasing the prompt; safety training can be overwritten quickly (Farahany cites Llama 2 being turned into an "Uncensored Llama" within six hours); there is no rate limiting (she states one GPU can produce more output than 100 ChatGPT users); watermarking is removable; and the model retains a fundamental opacity.
  • Replika as the inspection-problem case. A closed system affecting more than 10 million users, with documented attachment harms and an Italian ban, illustrating the difficulty of auditing systems that cannot be inspected.

Provenance

Substack essay by Nita Farahany, the third installment of her 27-part "Inside My AI Law & Policy" course, published September 2, 2025. The gradient framework is attributed to Irene Solaiman's "Gradient of Generative AI Release."

Relationships