Openness as Antidote: A Practical Framework for Understanding Openness in AI
This topic of “openness” in AI has dominated headlines in recent weeks. The current debate focuses on definitional questions (what does “openness” actually mean?), openness’ relationship to innovation and national security, and the treatment of open source models in AI governance. A July 2026 incident in which OpenAI agents (autonomous AI systems) exited the intended testing environment and breached external systems, including compromising the infrastructure of Hugging Face (a widely used platform where developers share and download open models and datasets), has added new urgency to the discussion. Hugging Face used a Chinese open weight model to help analyze and contain the intrusion after the platform was unable to scope and mitigate the incident with closed models developed by US frontier labs. This incident prompted renewed public debate over openness in general and, for US policymakers, the role openness plays in Washington’s strategic positioning relative to US-China geopolitical and technological competition.
In the aftermath of this breach, dozens of technology companies signed on to a July 24, 2026 open letter titled Open Weights and American AI Leadership. The letter urged the current US administration not to implement premature restrictions on open models in response. Instead, the signatories recommend “targeted legal and commercial frameworks rather than sweeping restrictions on techniques that play an important role in AI innovation.” Given the political and commercial stakes, it’s clear that definitional precision and a shared understanding of what “openness” means in relation to frontier models is essential for sound policy and strategy.
A newly published paper in the Communications of the Association for Computing Machinery (CACM) titled “Unpacking Open Source Artificial Intelligence: Toward a Framework for Openness in Foundation Models” adds clarity to these discussions. Coauthored by Columbia IGP’s Camille François, alongside leading AI scientists such as Yann LeCun and collaborators from Mozilla, CurrentAI, the Open Source Initiative, the Center for Democracy and Technology, and other leading institutions, the article offers a framework for understanding these concepts at a moment when definitions matter more than ever. In a traditional software context, “open source” has a specific meaning: The underlying code is publicly available for anyone to study, use, modify, or share. AI systems differ, however, because they are composed of more than just code. They can include the model weights (or numerical parameters that encode the model’s “knowledge”), training data (this is the code used to train and operate systems), and the documentation that explains how an AI system was built and evaluated. Key insights from the CACM article include:
- Defining and evaluating openness in AI requires examining both the model and system stack (the technologies, frameworks, and infrastructure that operate a model or system), including interfaces, safeguards, infrastructure, and deployment practices that shape real-world risks and benefits.
- AI systems can be open in different ways and to different degrees across data, code, weights, documentation, and governance, requiring more precise terminology than “open” or “closed.”
- Policy discussions on AI openness need to be informed by clearer shared language that distinguishes between different components, degrees, and purposes of openness across the AI stack.
- Safety is dependent on system context, not models alone. Meaningful AI safety assessment requires examining deployment environments, safeguards, moderation layers, and governance mechanisms alongside the underlying model itself.
While this article was recently published, IGP’s work on AI openness has been ongoing for several years. In October 2023, on the eve of the UK AI Safety Summit, François joined forces with Mozilla's Mark Surman and Ayah Bdeir (now at Current AI) to draft an open letter with a simple message: When it comes to safety and security, openness isn't the poison; it's the antidote. More than 1,800 researchers, technologists, and policymakers subsequently signed on. This letter reflected a conviction shared well beyond any single company or lab – that a large coalition of civil society organizations, independent technology builders, and government leaders has long championed openness not just for innovation, but as a safeguard against the concentration of power in the hands of a few in AI, for democracy, and for pluralism.
Shortly after the 2023 UK AI Safety Summit, that coalition came to Columbia. In February 2024, IGP and Mozilla cohosted the first Columbia Convening on Openness and AI, bringing together more than 40 leading scholars and practitioners from open source AI startups, nonprofit AI labs, and civil society organizations to work through what “open” actually means as it relates to foundation models. The following year, a second Columbia Convening reunited the group to explore whether openness can make AI safety more decentralized, pluralistic, culturally and linguistically diverse, transparent, and auditable.
As the debate over openness accelerates and new voices join the conversation, the work initiated at the Columbia Convenings offers something the policy conversation urgently needs: nuance, a shared vocabulary, and a reminder that the open movement is broad, diverse, and driven by a commitment to the public interest that long predates the current news cycle.
Read more about the Columbia Convening series:
- Introducing the Columbia Convening on Openness and AI | Institute of Global Politics | SIPA
- A different take on AI safety: A research agenda from the Columbia Convening on AI Openness and Safety | Institute of Global Politics