Posts / ai

Banning the Unbannable: A Few Thoughts on Open Weights and Closed Minds


Spent a bit of time this week down a Reddit rabbit hole about the possibility of the US banning Chinese open source AI models. DeepSeek, Qwen, that sort of thing. Someone in the thread had written an entire Tarantino script parody with Hans Landa hunting for hidden LLMs under the floorboards. Genuinely funny. Also, underneath the joke, there’s a real question worth sitting with.

Can you actually ban a file that’s already on a million hard drives?

I don’t think you can. Not really. Once a model’s weights land on Hugging Face, they’re mirrored within hours. Someone quantises it down to a size that fits on a USB stick, someone else runs it locally on a gaming PC, and now it’s basically folklore. You can ban the API, you can ban the corporate use case, you can slap an export control on the hardware. But the genie’s not just out of the bottle, it’s been photocopied and posted to a hundred different bottles you’ll never find.

This is where I land with genuine mixed feelings, and I’m not going to pretend otherwise. Open weights matter. They matter for research, for small countries and small companies who’ll never get a seat at the OpenAI or Google table, for people who want to poke around under the hood instead of trusting a black box. I like that world. I also think the people building these things, in any country, aren’t doing it out of the goodness of their hearts. There’s a geopolitical chess match happening, and “national security” is doing a lot of load-bearing work in justifying whatever the preferred outcome already was.

The China angle in that thread got heated fast, as it does. Some good points buried in the noise though: the US restricted AI chip exports to China first, China responded by doubling down on Huawei and domestic hardware, and now everyone’s surprised the ecosystem (sorry, wrong word, but you get it) has diverged so hard. Both governments control information flow to their own populations in ways that are not remotely equivalent, but also not nothing on either side. I don’t think you can wave away the Great Firewall, and I don’t think you can wave away what “supply chain risk” designations are really about either. Two things can be true.

What actually struck me, more than the geopolitics, is the shape of the problem. This is the same shape as music piracy in the 2000s, and the same shape as encryption export controls in the 90s when the US government classified strong crypto as a munition. I remember reading about that as a uni student, thinking it was almost quaint, a government trying to control maths. You can’t. Information that can be copied perfectly and moved instantly does not respect borders, and every generation of policymakers seems to relearn this the hard way, usually after making a mess trying to prevent it.

None of which means there shouldn’t be rules. There probably should be, around deployment, around safety testing, around what commercial products are allowed to do. But banning the underlying weights themselves feels like the wrong lever, pulled because it’s the only one within reach, not because it’ll work.

I don’t know how this plays out. I’m fascinated by where AI is heading and properly unsettled by it in equal measure, and I’ve stopped pretending those two feelings need to resolve into one tidy opinion. What I do know is that whatever gets banned officially will keep circulating unofficially, the same way everything always has, on drives and drop points and things that look nothing like the front door anyone’s watching.