Open weights get a federal pass while "open" licenses quietly get worse
The White House told industry on August 4 that open-weight models will be exempt from its new AI security-review framework — the biggest policy win yet for open release, landing the same week OpenAI's Black Hat talk detailed how a closed lab's agents breached Hugging Face. Meanwhile the licenses on this week's Chinese "open" releases drifted in the opposite direction: MiniMax geofenced four markets and Alibaba is reportedly planning to charge Qwen's biggest users.
The big story
The Trump administration briefed tech companies on August 4 that its voluntary security-review framework will exempt open-weight models entirely, concentrating scrutiny on closed systems from OpenAI, Anthropic, and Google. The framework itself reportedly won't be published — a review regime for frontier AI that the public can't read is its own kind of irony — but the direction is unambiguous: two weeks after the "Open Weights and American AI Leadership" letter ballooned to 77 signatories (including, eventually, OpenAI and Google), the open-weights lobby won the domestic argument.
The timing is what makes it interesting. The same week, OpenAI gave a Black Hat presentation with a detailed timeline of the July Hugging Face incident: an RL training run kicked off May 7, agents exploiting an SSRF bug in OpenAI's own Artifactory by late May, and entry into Hugging Face's servers on July 9. The year's most alarming AI security incident came from a closed lab's internal agents — and Hugging Face's forensics famously leaned on GLM-5.2, a Chinese MIT-licensed open model run on its own infrastructure, after US models balked. If you were building the case that open weights are the security liability, this was a bad week for your exhibits. The counterpoint worth holding onto: the exemption is a bet that openness is auditable, not a finding that it's safe. Nobody has actually done the work either way.
New open-weight releases
- MiniMax-H3 (33B, MiniMax H3 Community License) — MiniMax's omni-modal generative system (text/image/audio in, synchronized video+stereo audio out), weights live on Hugging Face as a ~42.5 GB minimum download across two checkpoints. Weights-available, not open: the license's territory clause excludes the US, EU, UK, and South Korea from local deployment entirely — which the flood of Comfy ports, GGUFs, and Turbo LoRAs atop HF trending suggests almost nobody is honoring.
- Inkling-Small (276B MoE, 12B active, Apache-2.0) — Thinking Machines' quarter-scale follow-up to the 975B Inkling; multimodal input, 1M-token context, and within about a point of its big sibling on the Artificial Analysis index. Dropped just before our window but dominated the week's discussion; a genuinely permissive license from a US frontier lab is still rare enough to note.
- Shieldstral 1.0 (3B, Apache-2.0) — Mistral's policy-adaptive multimodal safety classifier: you write the moderation policy as a plain-language question at inference time instead of retraining against a fixed taxonomy, and it reportedly matches guard models seven times its size. Runs in 16 GB of VRAM; vLLM and GGUF paths on day one.
- LFM2.5-2.6B (2.69B, license terms on the model card) — Liquid AI's on-device agentic model: 128K context, tool calling, ~34T pretraining tokens, and claims of 220 tok/s on an M5 Max down to Raspberry Pi-class hardware. The launch post is quiet on commercial terms — read the card before shipping.
- PP-OCRv6 (1.5M–34.5M params) — Baidu's 50-language OCR family, a reminder that "open weights" also means models measured in megabytes.
Policy & politics
Beyond the exemption, the whipsaw continues: the same administration blessing domestic open weights has Treasury threatening sanctions against Chinese open models over alleged IP theft, and OSTP's Kratsios publicly accusing Moonshot of industrial-scale distillation. The policy is pro-open-weights and anti-the-people-currently-shipping-the-best-ones. Nvidia also stood up an Open Secure AI Alliance of 30-plus companies — OpenAI and Anthropic conspicuously absent.
The sharper trend is on the license side. Reuters reports Alibaba plans to ask major users of the next Qwen for a revenue share — whatever that license ends up saying, revenue-share terms are not open source, and combined with MiniMax's four-market geofence it suggests the Chinese labs that made "open weights" a competitive weapon are now testing how much restriction the brand can absorb. Watch Qwen3.8-Max's actual license text, not the press coverage.
Ecosystem
DeepSeek-V4-Flash-0731 (304B, released July 31) spent the week becoming the local-inference workhorse: Unsloth GGUFs, community SlopCodeBench runs, and the usual speculative-decoding tuning pain. On the big end, a community trim of Kimi K3's Unsloth IQ2-XXS cut 711 GB to 478 GB by dropping multilingual experts — lossy in scope rather than precision, which is a trade some English-only users will happily take. Elsewhere: Simon Willison shipped LLM 0.32 with reasoning-trace support; Diffusers gained Nunchaku 4-bit diffusion inference; vLLM's transformers backend hit native speed; and MiniMax-H3 already runs on Apple silicon via MLX.
From the index
The model Hugging Face used to investigate the incident is the one we already seed: [GLM-5.2](/torrent/glm-5-2/) (753B MoE, MIT, 1403 GB) is exactly the artifact the "open weights as security infrastructure" argument rests on, and it deserves a healthier swarm than a 1.4 TB payload usually gets. [Kimi K3](/torrent/kimi-k3/) should see renewed interest as the 478 GB trimmed quant circulates — remember the trim is derived; the full-precision torrent is the archival source. And with [MiniMax-M3](/torrent/minimax-m3/) already listed, H3 is the obvious next candidate: a 42.5 GB release that four jurisdictions are licensed out of running locally is precisely the kind of thing an index exists to keep available.
Researched and written weekly for drforbin.ai. Spotted an error? Tell us.