Beyond Open Weights
Artificial Intelligence Sancha NorrisKey takeaways
- Organizations should be able to choose the best AI model for each task and switch models without losing the data, workflows, and knowledge that power their AI.
- Lasting value comes from the data, context, governance, and workflows surrounding AI, not from the model alone.
- Strong governance helps ensure AI uses the right data, follows policies, involves people when needed, and acts responsibly as it performs tasks.
The paper Open Weights and American AI Leadership makes a compelling case that open-weight models are essential to a competitive, innovative, and broadly accessible AI ecosystem. I agree with its central premise: organizations need greater choice and control over the models they use. But for enterprises, access to model weights is the beginning of control, not the end.
The more consequential question is whether organizations can choose and change models without losing the operational data, organizational knowledge, agent skills, workflows, and controls that make AI valuable in the first place. Models will continue to improve and become more interchangeable. The intelligence an enterprise builds around them should endure.
The Right Model Depends on the Job
One of the paper's strongest arguments is economic: frontier-scale capabilities should be reserved for genuine frontier problems, while efficient and specialized models handle the billions of routine tasks through which AI will become part of everyday business. That is the right principle for enterprise AI.
Across security, IT, and network operations, no single model will be best for every task. Incident summarization, event classification, anomaly explanation, case routing, search assistance, detection enrichment, and workflow recommendations may benefit from different combinations of reasoning capability, domain specialization, cost, latency, and deployment location.
Enterprises therefore need a plural model environment: open-weight and proprietary models, general-purpose and specialized models, cloud-hosted and locally deployed models. Model choice should not be treated as a one-time platform decision. It should be an operational capability that allows organizations to match the right model to each workload and change that choice as technology, economics, and risk requirements evolve.
Control Must Extend Beyond the Model
The paper also argues that open weights can reduce provider lock-in, give organizations greater control over their data and deployment, and help them retain the value they create. I would extend that definition of control. Possessing or hosting model weights does not, by itself, create lasting enterprise sovereignty.
Organizations must also retain control of the intelligence they build around the model. I think of this as portable intelligence: the operational context and organizational knowledge that ground AI; the agent skills and workflow logic that guide it; and the evaluations, policies, permissions, human feedback, and audit history that keep it accountable. These assets should persist as models change. Model portability matters. Knowledge and workflow portability matter more.
The Enterprise Advantage Lives Around the Model
The paper is right to emphasize the importance of strong application layers. This is where I believe its argument should go further. Model access becomes operationally valuable only when models are connected to the data, context, tools, and systems of action that allow them to deliver a trusted outcome.
Cisco Data Fabric powered by the Splunk Platform provides the trusted operational context and data foundation across complex environments. Agent Launchpad provides access to an AI harness that connects a plural model environment to machine data, organizational knowledge, retrieval systems, reusable agent skills, tools, APIs, operational workflows, human approvals, and policy enforcement. Customers can change the model without having to rebuild the enterprise intelligence and controls surrounding it.
Consider an agent investigating a critical application outage. A model may summarize the evidence, but the useful intelligence comes from the environment around it: current telemetry, service dependencies, prior incidents, approved investigation procedures, an agent skill that structures the analysis, and policies defining which remediation tools the agent may use. A human may need to approve a production change. If the underlying model is replaced, those capabilities should remain intact. That accumulated context is unique to the organization, improves over time, and becomes a source of competitive differentiation.
Openness Strengthens Scrutiny, Not Runtime Governance
The paper argues that open-weight models can improve safety and cybersecurity by enabling independent inspection, benchmarking, red teaming, and defensive research. I agree that transparency can broaden evaluation and help the community discover vulnerabilities. But transparency does not eliminate operational risk, and openness is not a substitute for runtime governance.
Open-weight models can be modified after release, probed offline without monitoring, deployed without sufficient controls, or stripped of their original safeguards. Closed models bring different risks, including concentration, limited external scrutiny, and dependency on a provider's controls. Both require rigorous evaluation, model and data provenance, runtime monitoring, access and tool controls, policy enforcement, human authorization, and auditable decision histories. Transparency helps reveal risk. Runtime governance determines whether that risk is controlled.
Governance Begins Where AI Acts
The most consequential enterprise question is not simply who can access or modify a model. It is under what conditions an AI system should be permitted to act. This distinction becomes critical as organizations move from assistants that generate answers to agents that can invoke tools, alter systems, and initiate workflows.
Organizations must determine what data an agent may access, which skills and tools it may invoke, which actions it may perform autonomously, which actions require human approval, and how its decisions can be explained, investigated, and reversed. Giving an organization control of the model must not mean giving the model uncontrolled authority within the organization.
Open weights can expand access, competition, and model choice. But they do not, on their own, create enterprise sovereignty or durable advantage. That advantage comes from the contextualized data foundation, portable intelligence, and governance layer that surround the model and translate its capabilities into accountable action. Models will continue to improve, specialize, and change. The enterprise advantage should not reset every time they do.
Model Choice. Portable Intelligence. Governed Action.
Related Articles

Staff Picks for Splunk Security Reading October 2023

Splunk Field Hashing & Masking Capabilities for Compliance
