A Shared Framework for Open Model Risk Management

The Partnership on AI (PAI) has released a new report, Risk Mitigation Strategies for the Open Foundation Model Value Chain, offering practical guidance for organizations that build, host, adapt, or serve AI systems based on open source and other weights-available models. The publication is a notable step toward standardizing responsible practices across a distributed development ecosystem.

The report draws on a workshop co-hosted by GitHub, reflecting the company’s ongoing focus on the open source AI landscape. GitHub reports roughly 1.6 million repositories dedicated to AI-related work, spanning foundational frameworks such as PyTorch, agent orchestration tools like LangChain, model projects including Grok, and responsible AI utilities like AI Verify. GitHub’s platform data efforts are intended to make this activity more legible to developers, researchers, and policymakers.

The company also points to its own governance work as context: periodic updates to platform policies to support responsible development, participation in the Munich Tech Accord to address AI risks in elections, and outreach to policymakers—including input on the implementation of the Biden Administration’s Executive Order in the U.S. and advocacy for improvements to the EU’s AI Act.

Why the Value Chain Matters for Policy

One of the report’s central contributions is its delineation of the open value chain, providing a clearer map of the roles and responsibilities involved in creating AI systems. This matters because policymakers tend to be more familiar with vertically integrated stacks and API-based access than with the decentralized collaborations typical of open source development.

By consolidating emerging best practices, the report helps bridge that gap. It gives policymakers a more accurate view of where risks arise and where mitigations can be applied across the full lifecycle of open foundation models—from initial release through hosting and downstream adaptation.

Diagram of the value chain for open foundation model governance. Highlighted actors are open foundation model providers; model hubs & hosting services; model adapters & optimizers; and app developers, services developers, & model integrators. Additional roles portrayed above the highlighted: compute & cloud providers and data providers; and below the highlighted: distribution platforms and users. ML ops & evaluation providers cut across multiple stages of the value chain and associated actors.