Standard
Ethics is capability with duties.
Open-source AI ethics is not “be nice,” and it is not “release everything.” It is a fight over who may possess a general-purpose tool of thought, and what obligations attach once that tool can be copied.
Both sides describe real goods and real harms. The argument is which risk you refuse to socialize.
Definitions
Three things called open
Calling an API open is a category error. Calling a weights dump ethical because the license is permissive is also a category error. Ethics lives in capability, irreversibility, and who can refuse the tool.
Open weights
Anyone can download the parameters and run or fine-tune locally. Inspectable. Unrecallable.
Open source
Weights plus code, data recipes, logs, and evals — checkable, not sloganeering. Most labs fail this test.
Open access
You may use the model through someone else’s interface. Convenience with a permission slip. Not ownership.
Rights
What we defend
Concentration is itself an ethical risk. If a handful of labs and states mediate every capable model, speech, research, and work run through their policies. A right that exists only inside someone else\u2019s terms of service is a tenancy.
- Run open models on machines you control.
- Study, fine-tune, and publish methods.
- Teach those skills without a corporate or state chaperone.
- Fork a model that censors, spies, or lies — including one released by a friendly lab.
Duties
What makes the right adult
Release is a one-way door. You can patch an API. You cannot recall weights. Alignment layers are cheap to strip. License text does not travel down a fork. Present-tense harms — fraud, non-consensual imagery, abuse material — are not hypothetical.
- Do not release or amplify weights you have not tested for the harms you claim to care about.
- Prefer refusing the worst knowledge in training data over a chat filter you know will be stripped.
- Publish evals, recipes, and known failure modes. If you cannot show the work, you are not open.
- Say what you will not help with, in public, without pretending a license file stops a fork.
Limits
What we will not claim
- That closed models are safe. They are governable after the fact. Different property.
- That open models are safe. They are inspectable and unrecallable. Different property.
- That “the people” are a single moral patient. Teachers, dissidents, firms, and attackers are not the same user.
- That ethics means maximal release on a timetable set by stars on a repository.
Position
The line Heiwig holds
Open-source AI is a civil liberty because general-purpose models are becoming tools of speech, learning, and work. A free people should be able to run and study them. Liberty here is not the absence of judgment. It is the refusal to let safety become a monopoly on capability. We test what we release, we teach people to operate rather than rent, and we will not dress criminal misuse up as freedom.
Law is already drawing incomplete lines — including partial open-source exemptions under the EU AI Act that disappear for high-risk uses and systemic-risk models. A 2022 U.S. “AI Bill of Rights” blueprint was about protecting people from automated systems, not a right to possess weights. Heiwig answers a different question: who may own the tool. How operators turn duty into evidence is on Compliance.