All insights

Sovereignty & Data Residency

Does Open Weights Solve Sovereignty? Partly

· 9 minute read

A downloadable checkpoint is a continuity hedge. It is not a sovereignty strategy. Hosting, telemetry, licences and the work you do on top still decide the file.

The technical committee had two piles of paper. One pile was a closed, hosted model with a polished safety deck. The other was a USB that held an open checkpoint and a printed licence. A member said the USB was sovereignty. Another said it was a hobbyist toy. Both were wrong in the same meeting.

The USB was a continuity hedge. If the hosted vendor vanished, the committee still had weights they could load. The USB was not a strategy. The serving stack that would load those weights had not been chosen. The licence had a use restriction nobody had read. The integrator’s wrapper wanted to phone home for a tokenizer update.

Open weights solve part of the problem and then sit down. This opinion is the part they solve, the part they do not, and the way to write that split so a committee can score it.

What open actually gives you

Inspection. You can hash the file. You can, if you have the skill, look at how it is served. You cannot fully explain why a 70B model said a particular sentence, but you are no longer dependent on a vendor’s refusal to discuss the artefact.

Portability. A second integrator can, in principle, load the same checkpoint. That is the cut-off test this series keeps returning to. Closed hosted models fail it by design.

Local serving. You can put the file on a card in an SDC and turn the network off. A hosted API cannot follow you into that room.

Those three are real. They are why public institutions should prefer an openable artefact for any workflow they expect to still run in five years.

What open does not give you

Open is an artefact property. Sovereignty is an operating property.
ProblemDoes an open checkpoint fix it?What still must be true
Telemetry from the serving productNoFail closed; no vendor collector
Licence that forbids your useNoCounsel reads the text; file the opinion
Hosted wrapper around open weightsNoIf inference leaves, you bought a hosted model with extra steps
Training on your ticketsNoContract ban; your registry holds adapters
Quality and safety on your tasksNoYour eval set; your refusal to ship on vibes
Personal data in the retrieval storeNoDPDP map; erasure; residency

The hosted wrapper is the fraud to watch. A vendor takes a public checkpoint, adds a thin API, a hosted guardrail and a usage dashboard, then sells it as open-source AI. You have the worst of both: a licence you must still honour and a collector you cannot see.

Distillation and the second model you did not mean to buy

Some teams download an open checkpoint, then send every production answer to a hosted large model to score or rewrite it. They still tell the committee they run open weights. They run a student that is chained to a teacher they do not control. The teacher sees the prompt. The openness of the student is decoration.

Distillation can be honest if the teacher never sees live personal data and the student is later served alone. That means a synthetic or scrubbed distill set, a recorded run, and a cut-over after which the hosted teacher is turned off. If the teacher remains in the graph for safety, you have a hosted safety model, not an open-weight deployment.

The same honesty applies to hosted embeddings used to feed a local generator. The chunks still left. Open weights on the generator do not wash that transfer. Score the whole graph.

Licences are not vibes

Open weights is a community phrase. The legal text may be a custom licence with acceptable-use rules, attribution duties, or triggers at a user count. A government deployment can trip those triggers without anyone meaning to. Put the licence and a two-paragraph counsel note in the file before the first serve.

Some licences also say you must not use the model for certain activities. If your workflow is adjacent to those activities, do not hope. Ask.

Objections

Closed models are safer because the lab tests them. Labs test them on lab distributions. You need your eval set either way. A closed model can still leak your prompt to a reviewer.

Open models are illegal because they were trained on copyrighted data. That is a live dispute in several jurisdictions. It is not currently a reason for an Indian department to prefer a hosted model that was trained the same way and then hides the artefact. Track the dispute; do not use it as a one-line veto unless counsel says so.

If it is open, anyone can steal our fine-tune. Anyone can steal a file you failed to custody. That is an access-control problem, which you already have for PDFs.

Eval is the missing fifth mark

Openness, serving, telemetry and licence are four marks. The fifth is whether the artefact is good enough on your tasks. Committees skip this because it is work. They then blame openness when a 7B model fails a drafting job that needed a better retrieval corpus, or they flee to a hosted model that was never measured on the same questions.

Build fifty questions from real, scrubbed files. Score the open artefact and, if you must, score the hosted alternative on the same sheet. If the hosted model wins by a little and costs you a transfer, write that residual risk. If it wins by a lot, you have a reason to change class or to rent a larger local card — not a reason to skip the other four marks.

Safety eval is part of the same sheet. An open model that invents a subsidy it cannot cite is not sovereign. It is a liability. Your refusal rules and your human-approval step are part of the serving mark, not a separate religion.

A 90-day path that uses open weights honestly

  1. Days 1–15: pick a candidate checkpoint. Hash it. File the licence.
  2. Days 16–40: serve it on a box you admin, with egress denied. Build a fifty-item eval set from your real tasks.
  3. Days 41–70: decide whether quality is enough. If not, try a different open artefact or a larger local model before you run back to a hosted API.
  4. Days 71–90: write the four marks into the next RFP: artefact, serving, telemetry, licence.

What goes in the file

The hash, the licence, the counsel note, the serving diagram that shows no hosted wrapper, the eval scores, and a sentence that openness was scored as four marks, not one. That sentence is the entire opinion in operational form.

Prcept AI will use openable artefacts when they fit the job. We will not call a hosted wrapper sovereign because the underlying papers were public.

How to defend this in the file

A P1 CIO/CTO will be asked to explain “Does Open Weights Solve Sovereignty? Partly” to a secretary who has ten minutes. Do not start with the model. Start with the store, the hop, the clause, or the residual risk. “open weights sovereignty” is a search phrase. The file needs a decision.

A downloadable checkpoint is a continuity hedge. It is not a sovereignty strategy. Hosting, telemetry, licences and the work you do on top still decide the file. DPDP does not define sovereign AI. Transfers can be lawful and still be a bad idea. Sector circulars can be stricter than DPDP. Write which instrument you are using.

If you cannot name the Data Fiduciary, the processor, the location of traces, and the erasure method, you are not ready for production personal data — whatever the architecture PDF says.

  • One sentence on lawful basis or the procurement rule you are invoking.
  • One sentence on where prompts, embeddings and logs live.
  • One sentence on who can compel the operator.
  • One artefact: packet capture, DPA schedule, or deletion certificate template.

Close this loop before the next CAB

Put “Does Open Weights Solve Sovereignty? Partly” on the next change-advisory or bid-opening agenda as a single line item with an owner. If it cannot earn a line item, it will not earn a control. The owner should be a P1 CIO/CTO, not “the vendor.”

Revisit the item when the model, the GeM term, the region, or the SI changes. “open weights sovereignty” is not a one-time workshop. It is a watch item. Date the last check. Unsigned watch items are souvenirs.

Questions this usually raises

If we download Llama or a similar model, are we sovereign?
You are more portable. You are sovereign only if you serve it under your admin plane, close egress, honour the licence, and custody the work you add. The download is step one of six.
Are open weights trained on our citizens?
Public models are trained on broad internet-scale corpora. That is a separate provenance debate. It is not the same as a vendor training on your production tickets. Do not mix the two in the file.
Do open licences allow government use?
Some do, some restrict acceptable use, some have user-count or commercial triggers. Read the licence. A ministry is not a hobbyist.
Is an open model safer to air-gap?
It is easier to carry across a media guard because you can hold the files. Safety of the model’s outputs is a different question and needs your eval set.
Should we reject hosted closed models entirely?
For citizen case files, hosted closed models are usually the wrong default. For a public brochure bot with no personal data, they can be a documented residual risk. Honesty beats a religion.

Sources