Open weights are the only model they can't ban
A government can switch off an API in ninety minutes. It cannot recall a weight that has already been downloaded to ten thousand servers. After the Fable shutdown, an open-weight model on hardware you control stopped being an ideological choice and became basic business continuity. Here is how we are actually using it.
The single most important sentence written about AI this month was not in a model card or a policy paper. It was a throwaway observation in the coverage of the Fable shutdown: a government can ban the company that serves a model, but it cannot ban the weights once they have been distributed across thousands of servers globally.
That is the whole argument. Everything else is detail.
On 12 June, the US government took Anthropic's two best models offline worldwide with ninety minutes' notice. It could do that because they were closed: served through an API, controlled from one place, switchable from one desk. No equivalent order could have un-distributed an open-weight model. You cannot issue an export-control directive against a file that is already sitting on ten thousand machines in fifty countries. The off switch does not exist for things you have already given away.
For three years, "open versus closed" has been argued mostly as an ideological or quality question, framed as freedom versus safety, or as how far behind the open models lag the frontier. June reframed it as something far more boring and far more urgent: continuity. An open-weight model running on hardware you control is the only version of this technology that no one can take away from you. After the last fortnight, that is not a hobbyist's preference. It is a line item in a sensible company's risk register.
The argument, stated plainly
A closed model is a service. You rent the capability, and the landlord (and the landlord's government) keeps the keys. When everything is calm, this is wonderful: someone else handles the compute, the updates, the safety, the scaling, and you just call the API. The convenience matters, and we are not going to insult anyone's intelligence by pretending it doesn't.
An open-weight model is a possession. You download the weights, you run them on your own infrastructure, and from that point forward no API deprecation, no pricing change, no export-control letter and no geopolitical falling-out can reach you. The capability is yours, in the only sense that survives a crisis. It is less convenient, frequently less capable than the absolute frontier, and entirely yours.
June made the trade-off legible. Before the 12th, choosing open weights meant accepting a capability gap to hedge against a risk most people considered theoretical. After the 12th, the risk is no longer theoretical (we watched it happen on camera) and the capability gap is closing fast. The most-used models in the world that week were largely open and largely Chinese: DeepSeek, MiniMax, Tencent's and Xiaomi's models near the top of the charts, with something like twenty-one competitive open-weight releases in the previous ninety days, roughly one every four days. That is the densest release cadence the field has ever seen, and every one of those drops is a model that cannot be switched off from abroad.
What the bans cannot reach
Be precise about what kind of protection open weights actually give, because it is narrower than the cheerleaders claim and broader than the sceptics admit.
Open weights protect you against the supply being cut. A ban on a foreign-served model, an export-control order, a trade-war throttle, a sudden "approved organisations only" list like the one the US issued on 26 June for Mythos: none of these can touch a model you already hold. If your product's core loop runs on weights on your own metal, your product keeps working while everyone built on the banned API spends a frantic fortnight migrating. That is bankable resilience, and it is the entire reason to care.
Open weights do not protect you from everything, and we would be selling you something false if we implied otherwise. They do not give you the absolute frontier; the very best closed models are usually still ahead. They do not absolve you of the safety problem; in fact they sharpen it, because an open weight's guardrails can be stripped out in minutes with free, publicly available tools, which is precisely why serious people worry about open release at all. And they shift operating burden onto you: the compute, the serving, the security, the updates that the API was quietly handling.
So the honest framing is not "open good, closed bad." It is: closed for capability when you can afford the dependency, open for continuity so that you always can. The open-weight model is the floor under your business. It does not have to be the best model in the world. It has to be a model that is good enough to keep you alive on a day when the better one gets switched off, and one nobody else gets a vote on.
The geopolitical knot we have to be honest about
There is a catch the UK in particular cannot wave away, and it would be dishonest to write this piece without naming it.
The open-weight models with the most momentum right now are overwhelmingly Chinese. The Fable shutdown handed every Chinese lab a marketing line on a silver platter ("at least our models don't come with a kill switch"), and the adoption numbers show it landing. Meanwhile Meta launched its first Superintelligence Labs release, Muse Spark, as a closed product with no public weights, which tells you which way the most-resourced Western player is leaning.
So "just use open weights" quietly resolves, for a lot of teams, into "depend on Chinese open models instead of American closed ones." That is a different dependency, not the absence of one, and for a British company in a sensitive sector it may be no more comfortable. This is exactly why the open-weight argument and the sovereign argument are two halves of the same point, and why we keep coming back to Cosine and the UK Sovereign AI Fund. The strategically complete position is not "open instead of closed." It is capable models you can actually hold: open weights you run yourself, plus a credible sovereign frontier model trained on home soil, so that neither your supply nor your sovereignty depends on the goodwill of a government in Washington or Beijing.
How we are actually using open weights
Enough principle. Here is what this looks like in the companies we build and the ones we incubate, because resilience that stays on a slide is worthless.
We keep a capable open-weight model deployed on infrastructure we control as a permanent fallback. Not switched on only in a crisis, but live, evaluated, and wired into the same code path as the frontier model so that failover is a config change, not a fire drill. A fallback you have never actually run in production is not a fallback; it is a hope. Ours has to handle real traffic on an ordinary day so it can handle all of it on a bad one.
We run the open and sovereign options through the same evaluation harness as the closed frontier, on our own tasks, continuously, not to win an argument about which is best in the abstract, but to know exactly how much capability we would lose if we had to fail over tomorrow. That number is a board-level metric now. If the gap is small, we lean harder on open by default. If it is large for a particular task, we keep the closed model for that task and accept the dependency knowingly, with a tested exit.
And we treat the durable assets (our data, our domain knowledge, our evaluations, our distribution) as the things to invest in, because they are what make any model, open or closed, valuable in our hands. The model is the most replaceable part of the system. We design so that swapping it is cheap and losing access to any single one of them is survivable.
The line we will not cross back over
We are not romantics about open source. Open weights carry a safety cost, they trail the frontier on the hardest tasks, and "Chinese open model" is its own kind of strategic exposure. None of that is wished away by the events of June.
But the events of June settled one question permanently for us. A capability that your entire product depends on must not be a capability that a government you don't vote for can switch off in ninety minutes. The only version of this technology immune to that is the version you already hold. Open weights are not the whole answer (sovereign models and good architecture are the rest of it) but they are the only part of the answer that no one, anywhere, can ban.
We are building accordingly. We would gently suggest that, after the last fortnight, everyone should be.
Louis O'Connell-Bristow and James Freestone are the co-founders of Moonlabs, the operator-led AI incubator and academy. They build and fund AI-first companies designed to survive contact with the real world, including the parts of it that hold the off switch.
Louis O'Connell-Bristow & James Freestone
Co-founders, Moonlabs. Operator behind home.co.uk, Homemove and homedata.co.uk. AI-native since the week ChatGPT shipped.
Work with usKeep reading
All essaysThe curriculum with no textbook: teaching a field that reinvents itself every quarter
Any fixed syllabus for AI engineering is obsolete before the cohort graduates. The tool we teach in week one is often superseded by week twe...
The candle and the token: what happens when the price of thinking collapses
In 2023 a million tokens from the best model on earth cost thirty dollars. Today a better model costs under fifty cents. The price of machin...
The first week in the Incubator, hour by hour
Most incubators waste their first week on onboarding and vision workshops. We ship something live by Friday. Here is what the opening five d...