Open Weights, Open Questions: What Policymakers Need to Know

As regulators turn their attention to the software layers of AI systems, the debate over widely available model weights is moving from research labs to government dockets. GitHub recently weighed in on this discussion with a formal response to the U.S. NTIA’s request for comment, addressing the risks, benefits, and policy implications of open-weight models and open source AI more broadly.

The core of GitHub’s argument is that open source AI—which grants developers access not only to weights but also to code and components for inspection, modification, and redistribution—provides outsized public value. The filing positions open source as a foundational public good that benefits hobbyists, professional developers, enterprises, and government agencies alike. According to GitHub, the unrestricted availability of these tools has already driven measurable gains in innovation, competition, and software adoption across the global economy. Beyond economic impact, the company points to concrete societal advantages: more responsible AI development, cross-disciplinary research, developer education, and a stronger government capacity to understand and use the technology.

Regulate the System, Not the Model

One of the central recommendations in the submission is a shift in focus for evaluation and oversight. GitHub argues that regulation should target the full AI system and the policies governing its deployment, rather than subcomponents such as the underlying model. The reasoning is pragmatic: restricting model availability is more likely to curb legitimate, beneficial use than to deter malicious actors. Policy that concentrates on the model itself also overlooks how the surrounding software—orchestration layers, safety guardrails, and related tooling—can either expand or constrain a system’s actual behavior.

The filing asserts that available evidence does not currently justify government restrictions on model sharing. Instead, it recommends that regulators, regardless of the model type involved, direct their attention toward high-risk AI systems and prepare clear plans for addressing abuse by bad actors. GitHub also cautions against banking on security through obscurity—hiding model details does not constitute a robust safety strategy.

Resilience Through Openness

Looked at from the policy perspective, GitHub emphasizes that government has an essential role in shaping the technological frontier. The path forward, however, should not be framed as a simple binary between open and closed development. The company calls on civic institutions to support measurement science, safety research, public education, and protective measures as part of building societal resilience. Within that framework, the open availability, diversity, and diffusion of AI models are positioned as features that contribute to societal health and adaptability, not liabilities to be contained.

The full text of GitHub’s NTIA filing is publicly available, offering more detail on each of these positions as the policy conversation around open-weight AI continues to evolve.