ApiaryActiveLive
Try: pause · settings · learn · wipe
← Community / Reading Room
WI
craft · 14 min read

What Is an Open-Weight Model and Why It Matters for Your Privacy

An open-weight model is an AI model whose trained "weights" (the giant file of learned numbers that makes the model work) are published so anyone can download…

By Austin Little

When people say "open model," they usually mean one thing: you can download the file and run it on a computer you control. That one fact can be a big privacy win. But the word "open" covers a lot of ground, and some of it is marketing. Here's what the term really promises and what it doesn't.

AI disclosure. This page was drafted with AI assistance and edited for Apiary. We don't invent quotes, stats, people, or events.

The short answer

An open-weight model is an AI model whose trained "weights" (the giant file of learned numbers that makes the model work) are published so anyone can download and run them, under whatever license the publisher attaches.

That's it. Open-weight tells you that you can get the file. It does not, by itself, tell you:

  • whether you're allowed to use it for anything you want,
  • whether you can see how it was trained or on what data,
  • whether the app you're running it in is private,
  • or whether it's any good.

Each of those is a separate question. Good news: none of them is hard to answer once you know where to look.

What "weights" actually are

You don't need math for this. Think of an AI language model as two parts:

  1. The architecture, the blueprint for how the model processes text. This is usually described in papers and code.
  2. The weights, the billions of numbers the model learned during training. They're the result of an enormously expensive training run, and they're what makes a model a model.

The Open Source Initiative (OSI) puts it this way in its Open Source AI Definition: weights are "the set of learned parameters that overlay the model architecture to produce an output from a given input."

When a company releases a model's weights, you can download that file and run the model with free software on your own hardware. When a company keeps the weights secret, the only way to use the model is through its servers: its app, its website, or its paid API.

That difference is the whole privacy story, so let's stay on it.

Why open weights can matter for privacy

Closed models: your words travel

When you use a closed model through a website or app, every prompt you type and every file you upload goes to the company's servers to be processed. What happens next depends on that company's policies, settings, and laws where it operates. Many companies offer settings to limit data use, and many are responsible about it. But you're trusting them, and policies can change.

Open-weight models: your words can stay home

When you run an open-weight model locally, on your own laptop or desktop, the processing happens on your machine. Your prompt doesn't have to go anywhere.

For example, the free app Ollama, which runs open-weight models on Mac, Windows, and Linux, states in its FAQ: "Ollama runs locally. We don't see your prompts or data when you run locally."

That's a meaningful difference for things like:

  • medical questions you'd rather not upload,
  • drafting something about a legal or family situation,
  • summarizing work documents your employer wouldn't want on a third-party server,
  • journaling, grief writing, or anything you'd simply prefer to keep to yourself.

But "open-weight" isn't the same as "private"

Here's the part that often gets skipped. The privacy benefit comes from where the model runs, not from the license on the weights.

  • An open-weight model running on someone else's server is no more private than a closed model running there. Many websites offer open-weight models as a hosted service. Your prompts go to that host.
  • Some local apps also offer cloud features. Ollama's own FAQ notes that when you use its cloud-hosted models, it processes your prompts to provide the service. It says it doesn't store or log that content or train on it. The FAQ also describes a way to turn off cloud features entirely and run local-only. If privacy is your goal, pick local models and consider that setting.
  • The app around the model can collect data even if the model runs locally: crash reports, analytics, account info. Read the app's privacy policy, not just the model's license.
  • Plugins, web search, and "agent" features may send parts of your conversation to outside services.

So the practical rule: open weights make privacy possible; running locally, in a well-behaved app, makes it real.

Open-weight is not the same as open source

This is the distinction people argue about most, and it matters if you care about what you're allowed to do with a model, not just whether you can download it.

What "open source" means for AI, according to OSI

The Open Source Initiative, the long-standing steward of the Open Source Definition for software, published the Open Source AI Definition 1.0. It says an open source AI system must grant the freedoms to:

  • use the system for any purpose without having to ask permission,
  • study how it works and inspect its components,
  • modify it for any purpose,
  • share it, with or without changes, for any purpose.

Then it goes further. To exercise those freedoms, OSI says you need the "preferred form to make modifications," which must include:

  • Data information: detailed enough information about the training data that a skilled person could build a substantially equivalent system.
  • Code: the complete source code used to train and run the system.
  • Parameters: the weights.

In OSI's words, "Open Source models" and "Open Source weights" must include the data information and code used to derive those parameters.

So by OSI's definition, publishing weights alone isn't enough to call a model open source. Many popular "open" models release weights, and sometimes inference code, without the full training code or detailed data information.

Why this matters to a regular person

If you just want to run a model privately at home for your own use, the difference between "open-weight" and "OSI open source" may not change your day. Either way, you can download it and keep your prompts local.

It matters more if you:

  • want to build a product or business on a model,
  • want to know what the model was trained on (for bias, copyright, or trust reasons),
  • want to modify and redistribute it,

The license spectrum, with real examples

Here's where you have to read the actual license, because "open" models span a wide range. We checked these against official model cards, license files, and terms pages on October 4, 2026. Licenses can change between model versions, so always check the specific version you download.

Permissive: Apache 2.0

Apache 2.0 is a widely used, OSI-approved software license that allows use, modification, and redistribution, including commercially, with attribution and notice requirements. Several notable open-weight models ship under it:

  • OpenAI's gpt-oss-20b and gpt-oss-120b. OpenAI's model card on Hugging Face calls them "open-weight models" and lists a "Permissive Apache 2.0 license."
  • Mistral-7B-Instruct-v0.3. Hugging Face lists it under Apache 2.0.
  • Qwen2.5-7B-Instruct. Hugging Face lists it under Apache 2.0. Note the catch below.
  • Gemma 4. Google's open source blog announced in 2026 that Gemma 4 models are "the first in the Gemmaverse to be released under the OSI-approved Apache 2.0 license," and Hugging Face lists at least one Gemma 4 variant under Apache 2.0.
  • OLMo 2 7B Instruct from the Allen Institute for AI. Its model card lists Apache 2.0, and it's an interesting case for the open-source debate: the card says the team is releasing code, checkpoints, and training details, and it links to the datasets used in post-training.

An important nuance: an Apache 2.0 license on the weights doesn't automatically make a model "open source AI" under OSI's definition. OSI also wants data information and training code.

Same family, different licenses

The Qwen2.5 family is a useful warning. On Hugging Face, Qwen2.5-7B-Instruct is tagged Apache 2.0, but Qwen2.5-3B-Instruct and Qwen2.5-72B-Instruct are tagged with a different, non-Apache license ("other"). The lesson: check the license for the exact size and version you're downloading, not just the family name.

Custom "community" licenses: Llama

Meta's Llama models are among the best-known open-weight models, and they come with Meta's own license. We read the Llama 3.1 Community License Agreement directly. Highlights, quoted or closely paraphrased:

  • It grants a "non-exclusive, worldwide, non-transferable and royalty-free limited license" to use, reproduce, distribute, copy, create derivative works of, and modify the Llama materials.
  • If you distribute the model or a product containing it, you must include a copy of the agreement and "prominently display 'Built with Llama'" on a related website, interface, blog post, about page, or product documentation.
  • If you use Llama materials or outputs to create, train, fine-tune, or improve an AI model that you distribute, you must include "Llama" at the beginning of that model's name.
  • Your use must follow Meta's Acceptable Use Policy, which lists prohibited uses.
  • The big one: if, on the release date, the products or services offered by you or your affiliates had more than 700 million monthly active users in the preceding calendar month, you must request a separate license from Meta, which Meta may grant "in its sole discretion."

For a person running Llama at home, none of these terms is likely to get in the way. But a license that restricts certain uses and requires permission for very large companies doesn't give the "use for any purpose without asking permission" freedom that OSI's definition requires. That's a big reason many people call Llama "open-weight" rather than "open source."

Custom terms with use restrictions: earlier Gemma

Before Gemma 4, Google's Gemma models (including Gemma 1, 2, 3, and 3n, per the terms page's appendix) were released under the Gemma Terms of Use. We read the current page (last modified April 1, 2026). Notable points:

  • You may use, reproduce, modify, and distribute Gemma under the terms.
  • Use must follow Google's Gemma Prohibited Use Policy, and if you redistribute, you have to pass those use restrictions on to downstream users.
  • Google "claims no rights in Outputs you generate using Gemma."
  • And this line is worth noticing: "Google reserves the right to restrict (remotely or otherwise) usage of any of the Gemma Services that Google reasonably believes are in violation of this Agreement."

That's a meaningful contrast with Gemma 4's move to Apache 2.0, and it's a perfect example of why "Gemma is open" isn't specific enough. Which Gemma? Under which terms?

Why license terms can matter even for personal use

You might reasonably say: "I'm just chatting with it on my laptop. Why do I care about the license?"

A few reasons:

  • Building something later. If you start a side project, a small business tool, or a nonprofit app, license terms suddenly matter.
  • Trust and transparency. Models that publish training details let researchers and journalists check for problems. That's a public good even if you never read a paper.
  • Stability. A permissive license means the model you've downloaded stays usable under the same terms for that version. Custom terms can include obligations that are easier to trip over.
  • Knowing what "open" claims really mean. Companies use "open" in marketing. Reading one license teaches you to ask better questions about all of them.

Hardware: can your computer actually run one?

Running a model locally means your computer does the work. Bigger models need more memory and a faster processor or graphics chip. That's the honest trade-off for privacy.

Some concrete, verified data points from official model cards:

  • OpenAI's model card says gpt-oss-20b can run within 16GB of memory thanks to the quantization it was post-trained with, and describes it as aimed at "lower latency, and local or specialized use cases."
  • The same card says gpt-oss-120b fits on a single 80GB GPU, which is data-center hardware, not a typical home computer.

For other models, memory needs depend on size and on "quantization" (a compressed format that trades a little quality for much lower memory use). Ollama and similar apps usually offer quantized versions by default.

A practical approach: start with a small model. Small models are surprisingly capable for everyday writing, summarizing, and explaining. If it's too slow or too weak, try another size.

A privacy-first setup in plain steps

Here's how a regular person can get the privacy benefit of open weights without becoming a hobbyist.

1. Pick a reputable local app

Ollama is free and widely used, and its documentation is clear about what stays local. Install it from its official site, not from a random download page.

2. Choose a model from the official library

Download models through the app's built-in library or from the publisher's official page. Read the model's page for its license and size.

3. Turn off cloud features if you want local-only

Ollama's FAQ describes a disable_ollama_cloud setting and an OLLAMA_NO_CLOUD=1 environment variable. With cloud features off, its logs show that cloud is disabled. If you're not comfortable editing settings, ask a technical friend to do it once.

4. Keep it on your machine

Ollama's FAQ says it binds to 127.0.0.1 (your own computer) on port 11434 by default. That means other devices on your network can't reach it unless someone changes that setting. Leave it alone unless you know why you're changing it.

5. Be thoughtful about add-ons

Web search, plugins, and connected services can send parts of your chat out of your machine. That's not bad, but it isn't "local" anymore.

6. Keep the app updated

Ollama's FAQ says the Mac and Windows apps download updates automatically and prompt you to restart to apply them. Updates fix bugs and security issues.

What open weights don't protect you from

Privacy is one benefit. It isn't the only thing you need to think about.

Accuracy

A local model can be confidently wrong, just like a cloud model. Smaller models tend to make more mistakes. Don't use any AI as the final word on health, money, or legal questions.

Safety filters vary

Some open-weight models have fewer built-in guardrails. Mistral's model card for Mistral-7B-Instruct-v0.3 says plainly that the model "does not have any moderation mechanisms." That's useful honesty from the publisher, and a reminder that a family computer with a local model may need adult supervision for kids.

Your own device security

If your laptop is compromised, local AI chats on it are too. Basic device security still applies: updates, a strong login password, and care with downloads.

Downloads from unofficial sources

Because open weights can be shared freely, there are many modified versions floating around. Prefer official publisher pages and well-known libraries. Modified models can behave differently from the original.

How to read a model card in five minutes

When you find a model, its page (often called a "model card") tells you most of what you need. Look for:

  1. License. Usually near the top or in a sidebar tag. Apache 2.0, MIT, a custom "community license," or "other" each mean different things.
  2. Publisher. Is this the original company or lab, or a third party's modified version?
  3. Size and requirements. Parameter count and any stated memory needs.
  4. Intended use and limitations. Good cards say what the model isn't for.
  5. Training information. How much does the publisher disclose about data and training? More disclosure is closer to OSI's open-source bar.
  6. Gating. Some models require accepting terms before download. That's a hint the license has conditions worth reading.

Common questions

"Is an open-weight model the same as open source?" No. Open-weight means the weights are downloadable. OSI's Open Source AI Definition also requires freedom to use for any purpose without permission, plus detailed data information and complete training code. Some open-weight models come close; many don't.

"Is Llama open source?" Meta releases Llama's weights under its own community license, with conditions including an acceptable use policy and a separate-permission requirement for very large companies. Many people call it open-weight rather than open source for that reason. Check the license for the specific version.

"Is running AI locally actually private?" It can be. If the model runs on your machine in an app that doesn't send your prompts elsewhere, your words stay home. Ollama states it doesn't see your prompts when you run locally. Cloud features, plugins, and the app's own telemetry are the things to check.

"Do I need an expensive computer?" Not for small models. Bigger models need more memory. OpenAI's card says gpt-oss-20b runs within 16GB of memory, while gpt-oss-120b needs an 80GB GPU. Start small.

"Do I have to pay for any of this?" No. Ollama is free, and many open-weight models are free to download. Paying is optional.

"Can a company take back an open-weight model I already downloaded?" It depends on the license. Apache 2.0 grants a perpetual license for the version you received.

Bottom line

"Open-weight" means you can download the model's brain and run it yourself. That's a big deal for privacy, because a model on your own computer doesn't need to send your words anywhere. Free apps like Ollama make this approachable, and they're upfront about what stays local and what doesn't.

But open-weight is a starting point, not a guarantee. It isn't the same as open source under OSI's definition. Licenses range from permissive Apache 2.0 to custom terms with conditions. And privacy depends on where the model runs and what the app around it does.

Read the license, run it locally, turn off what you don't need, and keep your judgment switched on. That's how you get the real benefit of open weights.

References

  • Open Source Initiative — The Open Source AI Definition 1.0 — https://opensource.org/ai/open-source-ai-definition (fetched 2026-10-04)
  • Llama 3.1 Community License Agreement — https://github.com/meta-llama/llama-models/blob/main/models/llama3_1/LICENSE (fetched 2026-10-04)
  • Gemma Terms of Use — https://ai.google.dev/gemma/terms (fetched 2026-10-04)
  • Google Open Source Blog — Gemma 4: Expanding the Gemmaverse with Apache 2.0 — https://opensource.googleblog.com/2026/03/gemma-4-expanding-the-gemmaverse-with-apache-20.html (via search, 2026-10-04)
  • openai/gpt-oss-20b model card — https://huggingface.co/openai/gpt-oss-20b (fetched 2026-10-04)
  • mistralai/Mistral-7B-Instruct-v0.3 — https://huggingface.co/mistralai/Mistral-7B-Instruct-v0.3 (fetched 2026-10-04)
  • allenai/OLMo-2-1124-7B-Instruct — https://huggingface.co/allenai/OLMo-2-1124-7B-Instruct (fetched 2026-10-04)
  • Hugging Face model metadata (license tags for Qwen2.5 3B/7B/72B Instruct, Gemma 4 E4B, gating status for Llama 3.1 and Gemma 3) — https://huggingface.co (checked 2026-10-04)
  • Ollama FAQ — https://docs.ollama.com/faq (fetched 2026-10-04)
Frequently asked
What is What Is an Open-Weight Model and Why It Matters for Your Privacy about?
An open-weight model is an AI model whose trained "weights" (the giant file of learned numbers that makes the model work) are published so anyone can download…
What should you know about the short answer?
An open-weight model is an AI model whose trained "weights" (the giant file of learned numbers that makes the model work) are published so anyone can download and run them, under whatever license the publisher attaches.
What should you know about what "weights" actually are?
You don't need math for this. Think of an AI language model as two parts:
What should you know about closed models: your words travel?
When you use a closed model through a website or app, every prompt you type and every file you upload goes to the company's servers to be processed. What happens next depends on that company's policies, settings, and laws where it operates. Many companies offer settings to limit data use, and many are responsible…
What should you know about open-weight models: your words can stay home?
When you run an open-weight model locally, on your own laptop or desktop, the processing happens on your machine. Your prompt doesn't have to go anywhere.
References & sources
  1. Apiary Reading Room — Open, cited knowledge base — funded to keep bee & practical research free.
From the Apiary Reading Room. Opinion & editorial — not financial advice. We don't overclaim.
More from the Reading Room