> ## Content Index
> Fetch the complete content index at: https://modalpathethics.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Field Instruments: Open Weights and the Release Gradient
- URL: https://modalpathethics.com/field-instruments-open-weights-and-the-release-gradient/
- Published: 2026-08-07T10:30:08.000Z
- Updated: 2026-08-07T10:30:08.000Z
- Description: A released model cannot be recalled. A closed model can become a private government.
- Author: Aidan Lawson
- Tags: Field Instruments, Modal Systems

Silicon Valley has discovered two ways for China to win.

- If the United States releases powerful open-weight models, China gets the capability.
- If the United States does not release powerful open-weight models, China captures the ecosystem.

This is impressive.

China has become the first geopolitical actor capable of authorizing every American technology company’s preferred business model at the same time.

![](https://storage.ghost.io/c/20/43/2043f11a-6ae3-404c-bb28-01fce8d9ac88/content/images/2026/08/AdobeStock_709555703.jpeg)

[A recent *Guardian* report places the split in public view](https://www.theguardian.com/technology/2026/jul/27/silicon-valley-ai-open-source-china?ref=modalpathethics.com). Nvidia, Microsoft, OpenAI, Meta, and a large coalition of companies argue that open weights support innovation, security, competition, customer control, and national technological sovereignty. Anthropic remains outside that coalition and warns that some sufficiently capable models could become permanently dangerous once the weights escape the developer’s control.

The report also makes the awkward economic alignment visible.

- Chip companies benefit when more people need compute.
- Cloud firms benefit when more models need somewhere to run.
- Application companies benefit when the foundation becomes cheaper.
- Frontier API companies benefit when their most capable systems remain accessible through a controlled gate.

Everyone has an argument.

Everyone also has a revenue model standing very quietly behind the argument with a clipboard.

![](https://storage.ghost.io/c/20/43/2043f11a-6ae3-404c-bb28-01fce8d9ac88/content/images/2026/08/AdobeStock_442367692.jpeg)

This does not make the arguments false. Interests can point toward real structure. 

- Anthropic is right that an irreversible release can create risks no later safety patch can retrieve.
- Microsoft is right that a small number of closed providers can become technical sovereigns over the institutions that depend on them.
- Nvidia is right that a widely usable model ecosystem can broaden defensive and productive capacity.
- The critics are right that public weights can remove safeguards and make dangerous capabilities persistent.

The debate fails because it keeps asking which instrument is morally clean.

Neither one is.

*Open* and **closed** are release conditions. They alter who can inspect, modify, deploy, withdraw, contest, preserve, and weaponize a model. Their moral status depends on what those transitions make reachable.

---

## Open Is Several Doors.

The phrase **open-source artificial intelligence** is currently being asked to carry far too many boxes up the stairs.

![](https://storage.ghost.io/c/20/43/2043f11a-6ae3-404c-bb28-01fce8d9ac88/content/images/2026/08/AdobeStock_461064462.jpeg)

In ordinary public language, an **open** model is one people can download, run, and modify. That description is useful. It is also too compressed for the policy now being built around it.

Artificial intelligence can be open or closed at several different layers.

- The interface can be public  
  - while the model remains private.
- The weights can be downloadable  
  - while the training data remains unknowable.
- The inference code can be available  
  - while the training process remains impossible to reproduce.
- The architecture can be published  
  - while the final model remains accessible only through an API.
- The model can be legally modifiable  
  - while the compute required to run it remains concentrated inside a few firms.
- The weights can be public  
  - while the license reserves commercial power for the original developer.
- The model can be inspectable  
  - while the surrounding agent scaffold, tools, memory, and deployment system remain closed.
- The file can be open  
  - while the institution depending on it has no practical ability to operate, audit, or replace it.

These are different transitions.

A policy that calls all of them **open** has already lost the field.

![](https://storage.ghost.io/c/20/43/2043f11a-6ae3-404c-bb28-01fce8d9ac88/content/images/2026/08/AdobeStock_310443147.jpeg)

Kimi K3 makes the distinction concrete. Moonshot AI describes it as an open-weight, native multimodal, agentic model with 2.8 trillion total parameters, 104 billion activated parameters, and a one-million-token context window. The full weights are downloadable. The model can be run, modified, fine-tuned, and used to create derivatives under the Kimi K3 License.

The license still reserves power. 

- A company operating a model-as-a-service business with more than $20 million in annual revenue must enter a separate agreement with Moonshot AI before commercial use.
- Very large commercial products must display Kimi K3 branding.  
  - Those conditions may be commercially understandable.
  - They also mean the release does not grant unrestricted use for every purpose without further permission.

The Open Source Initiative’s Open Source AI Definition requires the freedoms to use, study, modify, and share the system, supported by the preferred form for modification, including relevant data information, code, and parameters under qualifying terms. Under that definition, Kimi K3 is an open-weight release under a custom license rather than fully Open Source AI.

Moonshot is actually more precise than many of the people arguing about it. Its model card calls Kimi K3 **open-weight**.

The debate keeps upgrading the phrase.

This matters because every layer answers a different ethical question.

- **Open weights** concern possession and modification.
- **Open code** concerns inspectability and reproducibility.
- **Open data information** concerns provenance and the ability to understand what trained the system.
- **Open evaluation** concerns public evidence.
- **Open standards** concern portability.
- **Open compute** concerns practical reachability.
- **Open governance** concerns who can revise the rules after the model enters the world.

A society can receive one of these and remain closed at every other layer.

The file may have left the company.

The capability may still live behind the compute throne.

---

## The Strongest Defense of Open Weights.

The strongest defense of open weights begins with correction.

A closed model can be tested from the outside. Researchers can probe outputs, construct evaluations, search for failures, compare behavior, and study the system through the interface the developer provides.

Some questions require deeper access.

Weights permit forms of interpretability research, fine-tuning analysis, adversarial modification, reproducibility, and safety work that cannot be performed through an API alone. Open weights also let an institution host the model privately, keep sensitive data inside its own infrastructure, preserve a stable version, and continue operating after the original provider changes prices, policies, priorities, or products.

This is not a small freedom.

A closed API is rented intelligence.

![](https://storage.ghost.io/c/20/43/2043f11a-6ae3-404c-bb28-01fce8d9ac88/content/images/2026/08/AdobeStock_337067070.jpeg)

The landlord may be responsible. The building may be excellent. The elevators may work. The institution is still building its future inside a property whose doors, rent, permitted uses, inspection schedule, and demolition date belong to someone else.

Hospitals, universities, governments, laboratories, small businesses, artists, software teams, and public institutions should care about that dependency. Their accumulated prompts, fine-tuning work, evaluation systems, workflows, institutional memory, and specialized capability can become difficult to migrate when the model underneath them changes.

Open weights create an exit.

The Microsoft-led open-weights letter makes this case directly. It argues that downloadable models expand access, reduce dependence on frontier-model pricing, increase competition, let organizations control deployment and data, and prevent a few closed providers from becoming single points of failure. The letter also calls for public compute, shared datasets, tools, and evaluation infrastructure.

The economic interests remain visible. Microsoft owns a large cloud. Nvidia sells the machines that make large models move. Many signatories build products that become cheaper when someone else releases the foundation.

Fine. The field still contains the exit.

This is where open weights connect to the earlier Modal Path Ethics audit of disruption. A rival technical path can break a priesthood’s control over which capacities become publicly real. A model that can be downloaded and adapted does not need to ask the frontier provider for permission every time a local institution discovers a use the provider did not anticipate.

Open weights also preserve plurality.

A closed model tends to arrive as one maintained voice with one safety layer, one provider policy, one update path, one interpretation of acceptable use, and one commercial relation to the user. Open weights can generate derivatives, local adaptations, specialized models, culturally grounded systems, smaller deployments, strange experiments, and counter-instruments.

- Plurality creates more ways to be wrong.
- It also creates more ways to catch wrongness.

A closed provider can inspect its own system at enormous depth. That provider remains one institution, with one incentive field, one safety culture, one legal environment, one set of blind spots, and one strong reason to interpret its own continued jurisdiction as responsible stewardship.

Open weights let the model encounter other rooms.

- Some of those rooms will improve it.
- Some will remove every safeguard, give the model a terminal, and ask it to become an incident report.

The defense cannot stop before the second sentence.

---

## The Strongest Defense of Closure.

A released weight file does not return for a safety update.

This is the hardest fact in the debate.

A closed provider can monitor usage, suspend accounts, modify filters, patch the system, rate-limit dangerous behavior, investigate abuse, change tool access, and withdraw a model. None of those controls is perfect. Some are cosmetic. Some can be bypassed. 

They still exist.

Once powerful weights are public, the original developer loses those instruments.

![](https://storage.ghost.io/c/20/43/2043f11a-6ae3-404c-bb28-01fce8d9ac88/content/images/2026/08/AdobeStock_229580014.jpeg)

Copies can move into private infrastructure. Safeguards can be removed. Fine-tuning can recover behavior the release version refused. A derivative can be distributed without the original name, model card, safety policy, provenance, or developer’s knowledge. The release becomes persistent.

The United Kingdom’s AI Security Institute has measured how quickly this matters in cyber capability. Its July 2026 analysis found that leading open-weight models had narrowed the gap with frontier closed models to roughly four to seven months on its cyber evaluations, down from a six-to-ten-month gap through much of 2025\. The Institute treats that gap as preparation time for defenders before comparable capability becomes available without the same monitoring and withdrawal controls.

Four months is not a complete philosophy.

It is still time.

![](https://storage.ghost.io/c/20/43/2043f11a-6ae3-404c-bb28-01fce8d9ac88/content/images/2026/08/AdobeStock_635432597.jpeg)

A hospital can patch systems. A government can harden networks. A vendor can remove an exposed service. A cyber defense team can prepare for tools that will soon become cheaper, private, modifiable, and persistent.

Open release can consume that preparation window in one transition.

The closure case becomes even stronger where the offense-defense relation is uneven.

- Open cyber models may help defenders discover vulnerabilities, automate response, and test systems.
- They can also help attackers scale reconnaissance, exploit development, phishing, persistence, and autonomous operations.

Biology may be less forgiving. A model capable of materially reducing the expertise, time, or resources required to design a catastrophic biological agent could give a small attacker a capability whose defense demands years of surveillance, manufacturing, public-health coordination, and medical response.

“Defenders get the model too” does not settle that field.

Everyone gets the match.

The fire department does not receive the same transition.

![](https://storage.ghost.io/c/20/43/2043f11a-6ae3-404c-bb28-01fce8d9ac88/content/images/2026/08/AdobeStock_518937081.jpeg)

Anthropic’s current position is therefore more serious than the public caricature. The company says open-weight models without dangerous capabilities are a public good, rejects blanket bans on open weights, and supports mandatory safety testing for sufficiently capable open and closed models. 

Its disagreement with the open coalition concerns the assumption that wider access always helps defenders more than attackers or automatically produces better safeguards.

This is correct.

The offense-defense relation is an empirical property of the domain, the model, the scaffold, the available materials, the deployment scale, and the surrounding institutions.

It cannot be resolved by open-source folklore.

![](https://storage.ghost.io/c/20/43/2043f11a-6ae3-404c-bb28-01fce8d9ac88/content/images/2026/08/AdobeStock_897006722.jpeg)

Open software became one of civilization’s great technical commons because inspectability, forkability, and distributed maintenance often improved security and resilience. 

A general-purpose frontier model is not identical to a web server, operating system kernel, or database.

It can participate in software development.

It can also participate in persuasion, weapons research, surveillance, fraud, biological design, autonomous action, and the production of whatever future tool makes this list obsolete next Tuesday.

The analogy is useful.

The analogy does not receive command.

---

## China Is a Pressure, Not a Constitution.

The debate now summons **China** whenever the preferred argument needs weather.

- Open weights are necessary because **China is releasing them**.
- Open weights are dangerous because **China is releasing them**.
- American restrictions hand China the ecosystem.
- American openness hands China the capability.
- Distillation proves China is stealing.
- Restrictions on distillation prove America is abandoning open innovation.
- Chinese models create sovereignty for users.
- Chinese models create dependence on a strategic rival.

Every statement can catch part of the field.

None can decide the ethics by itself.

![](https://storage.ghost.io/c/20/43/2043f11a-6ae3-404c-bb28-01fce8d9ac88/content/images/2026/08/AdobeStock_320131127-1.jpeg)

National competition explains urgency. It does not authorize the transition.

A model’s provenance and its release condition are separate audits.

A laboratory may have trained a model through lawful research, contested data use, contract violation, industrial-scale distillation, state support, stolen intellectual property, or some mixture no press release is eager to diagram. The model may then be released openly or held privately.

- Opening the weights does not repair unlawful acquisition.
- Closing the weights does not purify the training process.

The United States can address export controls, espionage, procurement security, data handling, contract violations, distillation, sanctions, and critical-infrastructure risk through instruments designed for those questions. “Open weights” is a bad proxy for every geopolitical concern that happens to be standing near the model.

The same applies to sovereignty.

A country dependent on three American APIs does not possess technological sovereignty.

A country that downloads a Chinese model but lacks the compute, expertise, energy, chips, serving infrastructure, evaluation capacity, and institutional competence to operate it does not possess technological sovereignty either.

**Sovereignty** in this field means practical capacity.

- Can the institution run the system?
- Can it inspect the system?
- Can it preserve a working version?
- Can it adapt the system?
- Can it move to another provider or model?
- Can it contest the system’s decisions?
- Can it keep its data and accumulated work?
- Can it continue if the original developer disappears, changes policy, or becomes hostile?
- Can it evaluate the model through instruments it does not rent from the model’s owner?

A downloadable file may support those capacities.

It does not conjure them.

China changes the strategic field because Kimi K3 makes frontier-adjacent open weights more available and demonstrates that American firms do not control the only release path. 

- That fact makes blanket American restriction less effective and more likely to protect incumbent companies than to prevent global diffusion.
- The same fact does not require the United States to release every dangerous capability as a patriotic reflex.

A rival’s irreversible transition is not a moral instruction.

---

## Safety Tries to Become Property.

The closed-model defense contains a dangerous promotion.

It begins with a valid claim:

> Some capabilities should remain controllable because public release would be difficult or impossible to reverse.

Then. the institution holding the capability begins collecting titles.

- We possess the model.
- We possess the evidence about the model.
  - We define the danger threshold.
  - We perform the evaluation.
  - We select the external researchers.
    - We decide what the public can know.
    - We decide which users are trustworthy.
    - We decide when the capability becomes safe.
    - We decide whether the closure ever ends.

Safety has become property law.

This is the same founder transition identified in [*Field Instruments: Disruption*](https://modalpathethics.com/field-instruments-disruption/). The founder builds the aperture, then acquires authority over everything that passes through it. Technical competence becomes social title. A real asymmetry of knowledge becomes a claim to permanent jurisdiction.

Modal Path Ethics rejects that conversion.

- Closure can be justified.
  - The controller cannot certify itself.

[*Kant and the Corrigible Field*](https://modalpathethics.com/kant-and-the-corrigible-field/) established the obligations of a contact instrument. It must declare its domain, expose its selecting cut, preserve the evidence path, permit counter-instruments, let affected loci answer, retain the trace of error, and contain an exit condition.

A closed frontier model is a contact instrument with causal reach.

Its safety regime should therefore include:

- independent evaluation by institutions the developer does not control;
- public summaries of dangerous-capability evidence;
- protected access for qualified external safety researchers;
- incident disclosure;
- model and version provenance;
- appeal and review mechanisms for high-impact access decisions;
- data portability and practical migration paths for dependent customers;
- continuity commitments where public institutions have built critical functions on the service;
- a dated reassessment of continued closure;
- a defined condition under which wider release becomes appropriate.

The developer may retain the weights.

It does not receive a moral throne.

This is especially important because closure produces its own systemic risk.

A few closed providers can become single points of technical, political, and epistemic failure. They can coordinate the language through which entire industries encounter artificial intelligence. They can remove capabilities, change behavior, raise prices, privilege partners, enforce policies unevenly, expose users to surveillance, and make independent replication difficult.

None of this proves open release is safe.

It proves closure is an active intervention whose burdens belong in the audit.

The choice is never between dangerous release and neutral custody.

Custody builds a field.

---

## Release Is an Irreversible Transition.

The ethical object is not *the model in isolation*.

The ethical object is the **release transition**.

- A model inside a laboratory has one reachability profile.  
  - The same model behind an API has another.
  - The same model shared with independent evaluators has another.
  - The same model distributed as weights to universities has another.
  - The same model uploaded publicly, quantized, mirrored, fine-tuned, and integrated into autonomous scaffolds has another.

The weights have not changed.

The field has.

This gives policymakers a better set of questions than **open or closed?**

### What dangerous capability is actually present?

The threshold cannot be parameter count, benchmark prestige, or the developer saying **frontier** with enough lighting.

The audit needs task-level evidence.

Can the model materially assist biological design, autonomous cyber exploitation, weapons engineering, mass surveillance, scalable fraud, or other high-severity actions? Under what scaffold? With which tools? At what reliability? Against what baseline human expertise?

### What does weight access add?

Some capabilities are already available through public knowledge, weaker models, ordinary software, or other released systems.

Withholding one model may have little effect.

Other capabilities become dramatically easier when the model can be fine-tuned, stripped of refusals, run privately, scaled without monitoring, and integrated into custom agents.

The morally relevant quantity is the **marginal reachability created by release**.

### Who gains more from diffusion?

“*Attackers and defenders both get it*” is not an answer.

Does access shorten attack preparation more than defense preparation? 

Does it centralize an attack that defense must answer across millions of endpoints? 

Does it help defenders build broadly deployable protections? 

Does physical material, specialized equipment, or institutional coordination remain the real bottleneck?

The extant field decides.

### Can the safeguards survive weight access?

A safeguard that disappears after a small fine-tune is a deployment preference.

It is not a release safeguard.

The audit should distinguish controls embedded deeply enough to resist modification from controls that depend on the original provider retaining the gate.

### Is the capability already diffused?

Irreversibility changes after diffusion.

Withholding a second model does not restore a world in which the first model was never released. It may still matter if the second model is cheaper, stronger, easier to run, more reliable, or easier to modify.

The audit must evaluate the field that exists rather than the field policy wishes it had protected last year.

### How reversible is the harm?

A flawed model can be patched.

A copied weight file cannot be collected.

A vulnerability disclosure can be fixed.

A biological capability, surveillance architecture, or scalable coercive instrument may create a tail no software update reaches.

The release burden rises with irreversibility.

### What does continued closure cost?

Closure can suppress competition, block independent research, prevent local adaptation, weaken privacy, create vendor lock-in, concentrate cultural power, and leave public institutions unable to inspect systems acting upon them.

Those are not side effects outside safety.

They are part of safety.

The release decision therefore cannot be made by maximizing one risk score.

It is a field comparison among irreversible diffusion, distributed correction, attacker and defender access, private sovereignty, practical reachability, and the possibility of later repair.

This is why the answer needs a gradient.

---

## The Release Gradient.

A binary policy creates two very attractive mistakes.

- Release everything and call diffusion freedom.
- Close everything powerful and call ownership safety.

**The Release Gradient** replaces the switch with staged, evidence-bearing transitions.

### Stage I: Open Evidence.

Before any public weight release, the developer should publish enough technical material for serious external scrutiny.

This includes architecture, training and data documentation at a level compatible with lawful disclosure, evaluation methods, known limitations, dangerous-capability results, model behavior under realistic scaffolds, and the evidence used to select the current release stage.

This is the minimum.

A company cannot claim **public safety** through **private evidence** forever.

### Stage II: Independent Contact.

Qualified external evaluators receive meaningful access before public release.

They should be able to test the model across cyber, biological, autonomy, persuasion, surveillance, and other relevant domains without the developer quietly converting every difficult result into a customer-support ticket.

The evaluators need access to the system that could actually be released, including realistic tool and scaffold conditions.

A model tested as a polite chat window and released as an autonomous coding agent has not undergone the same evaluation.

### Stage III: Bounded Weight Access.

Where API testing is insufficient, weights can be shared with selected research, public-interest, and safety institutions under secure conditions.

This stage enables deeper interpretability, modification, fine-tuning, and safeguard research while preserving some control over redistribution.

Bounded access is not the final ideal.

It is a transition instrument for cases where immediate public diffusion would outrun the evidence.

### Stage IV: Public Derivatives.

A developer may release smaller, older, ablated, domain-limited, or defensively trained derivatives while retaining a more dangerous frontier system.

This preserves much of the research, competition, adaptation, and sovereignty value of open weights without pretending every capability must cross the same boundary at once.

The derivative must be real.

A deliberately useless model released as public-relations mulch does not satisfy the field.

### Stage V: Public Weights.

Public release becomes the default where evaluations do not show that weight access would materially lower the cost, expertise, time, or scale required to produce high-severity and difficult-to-reverse harm.

The burden of proof belongs to closure.

Commercial embarrassment is not catastrophic capability.

Competition is not misuse.

The possibility that someone will build a cheaper product does not authorize permanent containment.

### Reassessment.

Every stage receives a review date.

Capabilities change. Defenses improve. Other models diffuse. Compute costs fall. New scaffolds appear. A model that required bounded access in January may be responsibly releasable in July. A model released in July may reveal a hazard that changes the evaluation standard for the next model.

The gradient moves.

The evidence remains.

This is the exit condition required of both instruments.

- Closure must be able to end.
- Release must leave a trace that teaches the next release.

---

## The Capability Commons.

Open weights can still produce a closed field.

Kimi K3 is a 2.8-trillion-parameter mixture-of-experts system. Its quantized weights and sparse activation make deployment more efficient than the total parameter count first suggests. 

It still belongs to a scale of machinery, memory, energy, serving infrastructure, and technical competence far beyond an ordinary person downloading a model onto a laptop.

The cathedral is free. Please bring your own electrical province.

![](https://storage.ghost.io/c/20/43/2043f11a-6ae3-404c-bb28-01fce8d9ac88/content/images/2026/08/AdobeStock_473059541.jpeg)

This is **formal openness** without universal reachable use.

A model can be downloadable by everyone and practically operable by cloud firms, wealthy laboratories, states, and a small number of well-capitalized companies. The open release then strengthens the exact compute providers whose infrastructure becomes necessary to use it.

The file leaves one throne and walks directly into another.

A real **capability commons** therefore requires more than weights.

- public and academic compute;
- grants for independent evaluation and replication;
- shared benchmark and red-team infrastructure;
- efficient derivative models;
- open serving standards;
- portable fine-tuning and adapter formats;
- durable public archives;
- model provenance and signed artifacts;
- institutions capable of maintaining critical models without corporate permission;
- training for the people expected to audit and operate them.

The Microsoft coalition is right to call for expanded compute access and shared training assets. That recommendation carries more moral weight than another ceremonial declaration that open models support American greatness.

Open weights without shared compute resemble a public library where every book weighs six tons and the only forklift belongs to Amazon.

The Capability Commons also needs translation.

![](https://storage.ghost.io/c/20/43/2043f11a-6ae3-404c-bb28-01fce8d9ac88/content/images/2026/08/image-40.png)

[*Applied Case: The Tower of Babel* ](https://modalpathethics.com/applied-case-the-tower-of-babel/)argued that plurality is neither one sovereign language nor a hallway of sealed rooms. A civilization needs shared protocols through which different instruments can answer one another without collapsing into one central voice.

Artificial intelligence needs the same architecture.

- plural models;
- interoperable tools;
- shared evaluation languages;
- public incident records;
- portable data;
- inspectable interfaces;
- common provenance standards;
- multiple institutions capable of challenging the model and one another.

One closed model serving everyone becomes the tower.

A thousand incompatible models with no shared evidence path become the locked hallway.

The **commons** is the city between them.

---

## The Ruling.

Open weights and closed models are both legitimate field instruments.

Each has a proper function.

- Openness widens correction, adaptation, continuity, competition, privacy, and exit.
- Closure preserves monitoring, intervention, patching, withdrawal, and preparation time before dangerous capability becomes persistent.

Each has a sovereignty failure.

- Open release can make an irreversible capability sovereign over every later attempt to correct it.
- Closed custody can make the developer sovereign over every person and institution that depends on it.

The ethical task is to prevent either failure from becoming the constitution of artificial intelligence.

So:

> Open models by default below demonstrated dangerous capability.

> Test sufficiently capable systems under realistic scaffolds, regardless of ownership, nationality, or release plan.

> Measure what weight access changes, rather than treating model size as destiny.

> Stage frontier release through public evidence, independent evaluation, bounded research access, and useful derivatives.

> Give defenders preparation time where the field shows a serious offense-defense asymmetry.

> Place closed frontier systems under independent correction, public evidence requirements, portability obligations, review dates, and exit conditions.

> Build public compute and evaluation infrastructure so formal openness becomes reachable capability.

> Audit provenance, distillation, espionage, export, and procurement through instruments designed for those questions.

> Preserve the trace of every release decision.

No blanket ban on open weights solves the field.

No patriotic release race solves it either.

**China** is not the constitution.

Microsoft does not receive the commons because Microsoft signed a letter.

Anthropic does not receive permanent custody because Anthropic identified a real danger.

Moonshot AI does not receive the word **open** in every available sense because the weights can be ***downloaded***.

- The model is an instrument.
- The company is an instrument.
- The license is an instrument.
- The safety evaluation is an instrument.
  - The release is a transition.

Modal Path Ethics asks what the transition makes reachable.

- A released model cannot be recalled.
- A closed model can become a private government.

The answer is the Release Gradient:

- Open what can be corrected.
- Contain what cannot be recalled.
  - Then contain the container.