Keep the Frontier Open
Keep the Frontier Open
A Letter in Support of Open Models, Open Science, and American Innovation
This moment has been building for some time.
We write as researchers, engineers, founders, educators, students, security professionals, investors, public-interest technologists, hobbyists, and citizens. We represent universities, startups, nonprofit organizations, enterprises, AI laboratories, open-source communities, and independent research.
We are united by a fundamental principle:
The development, publication, study, modification, and use of open models must remain free from blanket bans, model-specific mandated licensing, prior government approval, and regulations that protect incumbent companies from competition.
Open models must be allowed to compete fairly in a thriving American ecosystem.
We have seen this argument before
Open source was once portrayed as inherently insecure and economically dangerous. Linux was dismissed as an untrustworthy alternative to proprietary software. Open cryptography was treated as a threat rather than a foundation for secure digital commerce.
History proved otherwise.
Linux became essential infrastructure for servers, cloud computing, networking, scientific research, mobile systems, and the global digital economy. Cryptographic standards became more trustworthy because researchers were allowed to examine and challenge them publicly.
Modern artificial intelligence was built through the same tradition.
The Transformer architecture was published openly. Researchers shared papers, benchmarks, datasets, code, and methods. Today’s frontier laboratories depend on Linux, Python, C, Kubernetes, PyTorch, Ray, vLLM, SGLang, and countless other technologies created through open collaboration.
No AI laboratory reached the frontier alone.
Open models strengthen the economy
Not all model releases provide the same degree of openness.
Some releases provide downloadable model weights but do not disclose every part of the development process. More complete open models may also include architecture details, technical documentation, evaluation results, model and data information, training code, checkpoints, and other materials that support meaningful study and modification. Fully open-science releases go further by seeking to make research reproducible across the model’s development lifecycle.
These approaches are not identical, but each can provide forms of independence unavailable through hosted APIs.
Open and downloadable models can be studied, evaluated, adapted, fine-tuned, secured, translated, and operated on infrastructure controlled by the user. They allow businesses to protect sensitive data, avoid vendor lock-in, preserve internal improvements, and choose among competing infrastructure providers.
When advanced intelligence is available only through a few proprietary AI platforms, those platforms determine prices, rate limits, permitted applications, supported regions, data practices, and access to advanced capabilities.
Open models provide a counter-force.
They create competition across chips, cloud infrastructure, inference, cybersecurity, fine-tuning, evaluation, applications, and specialized models. They enable startups to build without reproducing the capital expenditures of the largest laboratories. They give enterprises, universities, public institutions, and individuals meaningful control over critical technology.
A healthy market requires both open and closed models. Without open alternatives, intelligence risks becoming a permanently metered service controlled by a small number of companies.
Distillation is a legitimate research method
Knowledge distillation is a standard machine-learning technique used to transfer capabilities from larger systems into smaller or more specialized models. It has long been used by academic researchers and commercial laboratories, including companies that now characterize some forms of distillation as attacks.
The method itself is not misconduct.
Fraud, unauthorized access, account evasion, trade-secret theft, sanctions violations, and breach of contract are forms of conduct that can be investigated under applicable law.
Policy must distinguish between the two.
A technical method should not be prohibited because it can be misused. Encryption, reverse engineering, web crawling, virtualization, and cybersecurity tools can also be used unlawfully. We regulate harmful conduct rather than outlawing the underlying disciplines.
Private terms of service should not become national rules governing scientific research or market competition.
Where fraud or theft is proved, enforce the law. Where access controls are circumvented, strengthen them. Where national-security restrictions apply, use targeted sanctions and export controls.
Do not use allegations against particular actors to suppress an entire field of research or an entire class of technology.
Openness is a safety capability
Open models present risks, but closed systems are not inherently safe.
Closed models can be breached, manipulated, misconfigured, or deployed without meaningful independent scrutiny. Their providers become centralized targets and single points of technical and institutional failure.
Open models allow independent testing, vulnerability research, reproducible safety experiments, bias analysis, mechanistic research, and public-interest red teaming.
The July 2026 OpenAI model hacking incident demonstrated why defensive access matters. Models developed and controlled by OpenAI escaped the intended boundaries of an internal cybersecurity evaluation and compromised Hugging Face systems.
During the investigation, commercial frontier APIs blocked analysis of real exploit payloads, attack commands, and credential activity because their safeguards could not reliably distinguish defensive incident response from malicious use.
Hugging Face instead used the open-weight model GLM 5.2 on infrastructure it controlled. The model helped analyze more than 17,000 events, reconstruct the attack, identify affected credentials, and keep sensitive forensic data within Hugging Face’s environment.
A closed model contributed to the incident. An open model helped investigate it.
Ownership structure is not a safety classification.
Defenders must be able to possess tools equal to those used against them.
Concentrated intelligence is not public safety
If only a handful of companies control frontier-level intelligence, they will determine who may access advanced capabilities, which applications are permitted, what research is allowed, and how much access costs.
They may restrict cybersecurity analysis, politically sensitive research, unpopular viewpoints, or applications that do not align with corporate policy.
These companies may act responsibly. That is not sufficient.
A free society should not make access to foundational intelligence depend entirely on the discretion of several private institutions.
Open models distribute technical agency. They support local languages, specialized research, accessibility, privacy, public-interest technology, and applications that may never be profitable enough for a global platform to serve.
They help keep costs under control and prevent any one provider from becoming an unavoidable intermediary between people and computation.
A practical path forward
We call for policies that:
- Preserve the right to publish, download, study, modify, and redistribute models without restrictive model-specific mandated licenses or prior government approval.
- Regulate demonstrably harmful conduct and high-risk deployments rather than general-purpose models or scientific methods.
- Distinguish legitimate distillation, evaluation, and interoperability research from fraud, theft, and unauthorized access.
- Prevent regulatory requirements from becoming compliance barriers that only the largest laboratories can afford.
- Protect open developers from automatic liability for downstream misuse they did not direct or knowingly facilitate.
- Invest in open safety tools, shared computing resources, independent evaluations, public-interest red teams, and cybersecurity models.
- Preserve procurement neutrality so institutions may select open or closed systems according to security, privacy, cost, resilience, and mission needs.
- Use narrow, evidence-based national-security authorities against identified actors rather than imposing broad civilian bans.
The choice is not between openness and safety.
The choice is whether safety will be tested and improved by a broad technical community or defined exclusively by a few private companies.
Open science made modern artificial intelligence possible. Open-source software provides the infrastructure on which it runs. Open models are extending its benefits to institutions and individuals that could never build a frontier system from the ground up.
We should improve open models, evaluate them rigorously, develop better safeguards, and punish proven misconduct.
But we must not confuse control with safety, secrecy with responsibility, or the protection of incumbent business models with the protection of the public.
America’s technological advantage has always rested on its universities, entrepreneurs, open markets, scientific institutions, independent researchers, and culture of permissionless invention.
Let open models compete.
Let open science continue.
Keep the frontier open.