AI Tenders
Should You Mandate Open Weights in a Tender?
· 10 minute read
Mandating open weights is a procurement tool, not a sovereignty certificate. Score licence, load path and phone-home. Leave the slogan out of eligibility unless you can mark it.
A finance committee in a state secretariat last spring wrote three words into the eligibility sheet: open-weight LLM only. The phrase had survived a vendor briefing, a newspaper clipping, and a note that used sovereign and open-source as if they were cousins. Two months later the technically responsive bids included a model whose community licence forbids several government uses, a second model whose weights were open but whose runtime phoned a foreign licence host, and a third whose Apache-licensed weights arrived only through a vendor-controlled CDN. The committee had bought a slogan. It had not bought inspectability.
This article is an opinionated field guide for procurement officers, technical committees and finance concurrence who are being asked to lock open weights into a tender. The opinion is narrow. Open weights can be a good requirement. They are not automatic sovereignty, not automatic DPDP compliance, and not a substitute for an architecture you can isolate. If you mandate them, mandate three testable things: the licence you can actually live with, the load path that does not depend on the vendor's network, and a no-phone-home proof. Anything less is a brand preference dressed as policy.
It is not legal advice. Licence texts change. GFR, GeM category terms and your own financial rules still govern how you write eligibility. Read the current licence file, not a blog that says the model is open.
What open weights are not
They are not open source as a lawyer uses the phrase. A weight file published with a custom community licence, an acceptable-use policy, and a trademark clause is not the Apache License 2.0. SPDX exists so you can name the instrument. If the bid says open source and the artefact is a research-use checkpoint with a use policy that bars law-enforcement or surveillance-adjacent work, you have written an eligibility trap for your own department.
They are not sovereignty. Sovereignty, if you use the word at all, is about who can compel the operator, who holds the keys, and which law reaches the admin plane. A publicly downloadable checkpoint that still needs a vendor tokenizer service, a hosted safety filter, or a licence ping is a public file attached to a private control plane. Geography of the download mirror is not control.
They are not a DPDP answer. The Digital Personal Data Protection Act, 2023 regulates processing of digital personal data. It does not award a gold star because the parameters are published. A local Llama-class model that embeds citizen grievances into a vendor-managed vector host is still processing. Roles, purpose, training bans and erasure still have to be written.
They are not a free lunch on support. Someone has to patch the runtime, pin the tokenizer, and rebuild when a CVE lands. If you forbid a commercial stack and then refuse to staff the rebuild, you have purchased a GitHub link and an incident.
| Claim in the bid | What to ask for | Fail if |
|---|---|---|
| Open weights / open source | SPDX id or attached licence PDF plus acceptable-use file | Licence is 'community' with no text, or use policy bars your purpose |
| Can run offline | Load path: media format, hash, internal registry, no first-boot download | First inference pulls tokenizer, adapters or a safety model from a CDN |
| No telemetry | Staging packet capture on a deny-outbound VLAN | Licence daemon, crash reporter or feature-flag host appears in the pcap |
| Sovereign because open | Who holds keys, who can compel the operator, where logs live | Sovereignty is asserted from the licence recitals alone |
When a mandate is rational — and when it is a PAC in disguise
A mandate is rational when your threat model needs inspectable artefacts: you want to know which checkpoint is on the disk, you want to re-host it, you want to keep running if the vendor disappears, and you want a third party to diff two releases. Those are buyer interests. Write them as artefacts.
A mandate is a PAC in disguise when only one commercially supported stack can meet the sentence you copied from a briefing. If the market of viable, licensable, air-gappable checkpoints for your Indic plus tool-use workload is two vendors and a research lab, say so in the file. Do not hide a limited market inside the word open.
A preference, scored, is usually cleaner than a binary eligibility cut. Score licence permissiveness for your purpose. Score offline load. Score absence of phone-home. Score the vendor's willingness to pin a hash in the contract. A closed-weight on-prem runtime that never leaves the rack can beat an 'open' runtime that phones a safety API. The scorecard should be allowed to say so.
How to write the three tests so an evaluator can fail a bid
Licence. Name the purposes the department will put the model to: drafting file notes, retrieving circulars, classifying grievances, suggesting sanction text. Attach the licence and the acceptable-use policy. Ask counsel whether those purposes are permitted. Ask whether redistribution of fine-tunes, if any, is permitted. Ask whether a later change of licence mid-contract is a termination event. Do not accept 'open' as the answer.
Load path. The checkpoint, tokenizer, chat template and any adapter must arrive on hashed media or through an internal registry the department controls. First boot with the WAN dead must produce the same hash and the same first token. If the vendor's installer reaches huggingface.co, a CDN, or a 'model garden', the load path is a network path. That is not an air-gap design. It is a delayed download.
No phone-home. Isolation drill, packet capture, empty-or-named egress schedule. Feature flags, licence heartbeats, crash dumps and tokenizer updates are in scope. A checkbox titled telemetry disabled is not evidence.
- Attach the licence PDF and the use-policy PDF as bid annexures, not as URLs that can move.
- Name the hash algorithm and the pin in the contract schedule.
- Require a 14-day isolated soak before technical scoring is final.
- State that a later licence change that narrows permitted government use is a material breach.
DPIIT and Make in India are other tests
DPIIT recognition is an eligibility and relaxation fact in many public tenders. It is not a licence opinion and not a sovereignty opinion. A DPIIT-recognised firm can still ship a checkpoint you are not allowed to use for your purpose, or a runtime that phones home.
Public Procurement (Preference to Make in India) speaks to local content. Local content in a wrapper around a foreign checkpoint is a calculation, not a vibe. Do not let the open-weights sentence do the work of the local-content certificate, and do not let the certificate do the work of the isolation drill.
Objections you will hear — and what to do with them
These are the lines that stall the file. Answer them in the room, then put the answer in the note. A spoken answer without paper will be forgotten by the next officer.
If we do not mandate open weights, vendors will lock us in.
Lock-in is real. Kill it with exit artefacts: hashed checkpoint or export of prompts, traces and evaluations; a documented load path; a 90-day run without the vendor; source or escrow for the orchestration if you truly need it. Those clauses work on closed and open stacks. A slogan does not.
Open weights are how we get Indic quality without paying rent.
Sometimes. Indic quality is an evaluation set, not a licence. A closed model that you can isolate and score on your Odia–English code-mix set may outperform an open checkpoint that was never tested on your files. Score the eval. Pay for the better evidence.
Our political note already promised an open-source stack.
Then write what you can defend: published weights where the licence permits the purpose, local load, no phone-home. Brief the political office that open-source in a newspaper and SPDX in a contract are different sentences. Do not make the newspaper the eligibility sheet.
We will decide the model after award.
Then do not put a model family in eligibility. Put the three tests in the contract as conditions subsequent, with a walk-away if the chosen checkpoint fails isolation or licence review. Deciding after award without those conditions is how you inherit a garden.
A four-week open-weights decision you can file
Run this before the eligibility sheet is frozen. Changing eligibility after a pre-bid is a corrigendum problem. Changing it after award is a vigilance problem.
- Week 1: name the workflows and the data classes. Give counsel the licence texts of the two or three families you are tempted to mandate. Get a written yes/no on purpose fit, not a verbal 'should be fine'.
- Week 2: decide preference versus mandate. If the market of licensable, isolatable stacks is thin, score the three tests. Do not cut the field to one logo.
- Week 3: write the load-path and isolation rows into the annexure. Borrow the air-gap rows if you claim air-gap. Require hashes and a pcap.
- Week 4: table a one-page note to the competent authority: what you are mandating, why, what you are scoring instead, and which political sentence you are not putting in eligibility.
How this shows up in the file
The file note can be four sentences. One: open weights are a preference / a mandate because we need inspectable artefacts for these named workflows. Two: eligibility (if any) is licence-permitted use plus offline load plus no phone-home, not the adjective open. Three: SPDX or attached licence text is part of the bid. Four: a later licence narrowing is a breach.
If those sentences cannot be written, delete open weights from eligibility. Put them in the technical score, or drop the phrase.
This article is informational field guidance for Indian public institutions, not legal, procurement, security-accreditation or engineering advice. Confirm against the current Gazette, GFR, GeM term, CVC instruction, CERT-In direction, DPDP text, departmental manual and your counsel before you file it.
Questions this usually raises
- Does mandating open weights make the system sovereign?
- No. Open weights are a distribution and licence fact. Sovereignty is about control, compulsion and architecture. Demand licence fit, an offline load path and a no-phone-home proof. Do not treat a published checkpoint as a sovereignty certificate.
- Is an open-weight model automatically safer under DPDP?
- No. DPDP cares about roles, purpose, security, processors and transfers. A local open model that trains on your traces or ships embeddings to a vendor host can be worse than a closed on-prem model with a training ban.
- Can we accept a custom community licence if the weights are downloadable?
- Only after counsel reads the licence and the acceptable-use file against your named workflows. Downloadability is not permission. Attach the text. Do not rely on a vendor paraphrase.
- Should open weights be eligibility or a scored preference?
- Default to a scored preference unless you can show that only inspectable published weights meet a written threat model. A binary cut is how you accidentally write a single-source spec.