The vocabulary first
Three words get used loosely, and the differences matter.
A closed model is one you reach only through an API or a product — GPT, Claude, Gemini. You send a prompt, you get an answer, and you never hold the model itself. An open-weight model publishes its trained weights: you can download it, run it on your own hardware, and inspect or fine-tune it, subject to a license. Meta’s Llama, Alibaba’s Qwen, IBM’s Granite, DeepSeek, and the Chinese frontier models are open-weight. A fully open-source model goes further, releasing the training code and data needed to reproduce it — a smaller group, led in recent years by American non-profits such as the Allen Institute (Olmo) and EleutherAI.
None of these are clean categories; they sit on a spectrum. Some “open” models release large amounts of training data under permissive terms; some “closed” models reveal more through their APIs than others. And licenses on open-weight models range from genuinely permissive (Apache 2.0, MIT) to custom terms that gate commercial use above a revenue line. “Open” describes a direction, not a single thing.
Where things stand
A few facts are not seriously contested.
Open models have closed much of the distance to the closed frontier, and two independent trackers put roughly the same number on it. Epoch AI, a research institute that scores models on its own Capabilities Index, measures the leading open-weight models trailing the closed frontier by about four months — while cautioning the real gap may be larger, since closed labs keep their most capable models unreleased and open models can overfit the public benchmarks everyone can see. Nathan Lambert, who maintains public data on the open ecosystem, puts it at two to five months on the tasks businesses run most — agentic coding, tool use, retrieval — and further behind on open-ended scientific work.
Most of the strongest open-weight models now come from Chinese labs — Alibaba’s Qwen, DeepSeek, Moonshot’s Kimi, Z.ai’s GLM. By download and usage measures, Chinese open models overtook American ones around mid-2025; on platforms built to serve open models the majority of traffic runs on them, and in academic research Qwen has become the default model most papers build on. The United States still produces more top-tier models overall and leads on the closed frontier. Stanford’s AI Index reports the US–China performance gap narrowing even as transparency across the most capable models declines — training details that used to be published increasingly are not.
| Model | Country | Open? | License | Score |
|---|---|---|---|---|
| Open weights · China | ||||
| Z.aiGLM 5.3 | China | open | Custom (GLM-5.3) | 45 |
| Moonshot AIKimi K3 | China | open | Custom (Kimi K3) | 44 |
| Z.aiGLM 5.3 Flash | China | open | Custom (GLM-5.3) | 42 |
| DeepSeekDeepSeek V4 Pro | China | open | MIT | — |
| AlibabaQwen 3.8 | China | open | Apache 2.0 | — |
| Open weights · United States | ||||
| Thinking MachinesInkling | US | open | — | 26 |
| NvidiaNemotron 3 Ultra | US | open | Nvidia OML | 23 |
| IBMGranite 4.2 | US | open | Apache 2.0 | — |
| IBMGranite 4.1 | US | open | Apache 2.0 | — |
| Closed frontier · United States (reference) | ||||
| AnthropicClaude Fable 5 | US | closed | proprietary | — |
| OpenAIGPT-5.6 Sol | US | closed | proprietary | — |
The landscape as of 21 Sep 2026. Score = Artificial Analysis Intelligence Index on Nathan Lambert’s September set; — = not scored on that set. Figures are vendor-reported or list. The live, model-by-model table — with sizes, context and prices — is Model Watch. This piece is the map; that is the table.
The debate — in the sources’ own terms
Underneath the shared facts, credible parties disagree sharply about what should happen next. The disagreement is worth seeing straight, in the words of the people having it.
On July 24, 2026, an open letter titled Open Weights and American AI Leadership was published — Nvidia CEO Jensen Huang’s first post on X. It launched with 25 signatories and grew past 270 within weeks, among them Nvidia, Microsoft, Meta, IBM, Dell, Hugging Face, Mistral, Cohere, the Linux Foundation, and later OpenAI and Google. It asks Washington to avoid “premature restrictions” on downloadable models, frames open weights as strategic infrastructure rather than a liability, and makes a safety argument that would have been unusual a year earlier: that closed models are single points of failure and that broad security can depend on many people being able to test and harden the models society relies on. A fair caveat, which critics note: none of the signatories sells access to a closed frontier model, so openness is being urged at the layer where these firms do not compete.
Lambert, in an expanded version of testimony he prepared for Congress, argues open models are becoming the substrate for everyone outside the few frontier labs, that owning open models lets a country coordinate on risk and diffuse AI through its economy, and that restricting access to strong open models — including Chinese ones — would mostly set back the American businesses already relying on them. He also estimates that distillation, training on a stronger model’s outputs, explains only a month or two of China’s progress, not the whole story.
Anthropic is a notable non-signatory. In its position paper, CEO Dario Amodei writes that “we have not and are not advocating for a ban on open-weights models as a category,” and grants that open weights expand access, competition, and customer control. But he disputes the letter’s claim that openness necessarily favors defenders over attackers — pointing to biology, where an attacker can move faster than a defender — and argues instead for three narrower measures: chip-export controls, a crackdown on industrial-scale distillation, and mandatory safety testing of all sufficiently capable models, open or closed. The distillation concern is concrete for Anthropic: it has alleged that operators tied to Alibaba’s Qwen ran a large-scale campaign to extract training signal from Claude — a claim Alibaba’s side contests, and one the pro-open camp argues is a separate problem from openness itself.
The most institution-neutral anchors sit outside the industry entirely. In 2024 the US Commerce Department’s NTIA studied exactly this question and applied a “marginal risk” analysis — weighing the specific added risk of open weights rather than the general risks of AI. It concluded that current evidence did not warrant restricting open model weights at that time, recommended active monitoring for emerging risks, and explicitly preserved the option to restrict certain classes of weights later: monitor now, decide later, on evidence. That marginal-risk lens comes from independent scholarship — a widely cited 2024 paper led by researchers at Princeton and Stanford, which surveyed the main misuse vectors (cyber, bio, disinformation) and found that existing research was, in most cases, insufficient to establish how much additional risk open models create beyond tools already available. Its lasting contribution was diagnosing why the fight is so heated: the two sides are often analyzing different pieces of the same problem.
Some of the sharpest disagreement is empirical. When a major platform investigated an AI-driven intrusion in 2026, it reported running its forensic response on an open Chinese model because closed models refused the defensive work — a case the pro-open side cites as open weights aiding defenders. The cautious side reads the same terrain differently, emphasizing domains where the attacker’s advantage is structural. Both are looking at real events and drawing opposite lessons.
The open question
The field moves monthly — a capability ranking or a price is a snapshot, not a settled picture. And the larger question underneath the numbers, how open the ecosystem should be, is genuinely unresolved. The people closest to it are looking at the same facts and reaching different conclusions.
Sources
- Open Weights and American AI Leadership — industry open letter, published by Nvidia, July 24, 2026 (270+ signatories). letter (PDF) · live signatory list
- Nathan Lambert, The current balance of power in open models — Interconnects, Sep 21, 2026 (expanded from Congressional testimony). interconnects.ai · data: ATOM Project
- Anthropic (Dario Amodei), Our position on open-weights models — July 27, 2026. anthropic.com
- NTIA, Dual-Use Foundation Models with Widely Available Model Weights — U.S. Dept. of Commerce, July 2024 (marginal-risk analysis; monitor, don’t restrict “at this time”). ntia.gov
- Epoch AI, Open models lag state-of-the-art closed models by ~4 months — independent measurement of the open/closed capability gap, 2026. epoch.ai
- Kapoor, Bommasani, et al., On the Societal Impact of Open Foundation Models — ICML 2024; the independent academic “marginal risk” framework (25+ authors, Princeton / Stanford / MIT / Georgetown). arxiv.org
- Stanford HAI, AI Index 2026 — data on the narrowing US–China gap and declining model transparency. hai.stanford.edu