Banning Open Weight Models | Episode 66
In this episode of BHIS Presents: AI Security Ops, the team tackles a deceptively simple question with some very complicated answers:
Can you actually ban an AI model?
Not access to an API. Not the chips used to train it. The model weights themselves — files that can be downloaded, copied, modified, quantized, fine-tuned, and redistributed around the world.
As governments consider restrictions on Chinese open-weight models, the security argument cuts in both directions. There are legitimate concerns around national security, guardrails, model capabilities, and foreign technology dependence. But those same open models are inexpensive, locally deployable, and can give defenders capabilities that commercial frontier models sometimes restrict.
So what would a ban actually accomplish — and could it even be enforced?
We dig into:
- Where U.S. restrictions on open-weight models currently stand
- Why banning downloadable model weights is fundamentally different from restricting an API
- How procurement rules and hosting restrictions could create a “soft ban”
- Why the economics of open-weight models are driving adoption
- How restrictions could disproportionately impact startups and smaller organizations
- Whether modifying, quantizing, or fine-tuning weights makes model-specific bans impractical
- The national-security argument for restricting Chinese models
- Why guardrails on hosted frontier models matter to the security debate
- How Hugging Face turned to a locally hosted open-weight model during incident response
- Whether banning open weights could put defenders at a disadvantage
- How existing government actions can indirectly limit access without banning a model outright
- The hardware and operational costs of self-hosting large models
- China, AI infrastructure, market competition, and industrial-scale distillation
- Anthropic’s argument for mandatory safety testing of sufficiently capable models
- Why safety testing gets complicated when open-weight guardrails can simply be removed
- What realistic AI policy might look like when the technology cannot easily be recalled
This episode explores a central tension in AI security: the properties that make open-weight models difficult to control are also the properties that make them useful.
You can run them locally. You control the data. A provider cannot revoke your access. You can modify the model for your own use case.
But once the weights are released, those capabilities are also difficult to take back.
For defenders, the bigger question may not be whether open-weight models should exist. It may be whether restricting access leaves security teams with fewer tools while attackers and foreign competitors continue developing the same capabilities elsewhere.
https://www.anthropic.com/news/position-open-weights-models
—
Learn more about Black Hills Information Security:
https://www.blackhillsinfosec.com/
Check out Antisyphon Training:
https://www.antisyphontraining.com/
#AISecurity #CyberSecurity #OpenWeightAI #ArtificialIntelligence #LLMSecurity #AIRegulation #DeepSeek #InfoSec #BHIS #Antisyphon
----------------------------------------------------------------------------------------------
🎧 Subscribe to the Podcast:
https://aisecurityops.transistor.fm
About Brian Fehrman - https://www.blackhillsinfosec.com/team/brian-fehrman/
About Bronwen Aker - https://www.blackhillsinfosec.com/team/bronwen-aker/
About Derek Banks - https://www.blackhillsinfosec.com/team/derek-banks/
About Ethan Robish - https://www.blackhillsinfosec.com/team/ethan-robish/
About Ben Bowman - https://www.blackhillsinfosec.com/team/ben-bowman/
Click here to watch this episode on YouTube.
Brought to you by:
Can you actually ban an AI model?
Not access to an API. Not the chips used to train it. The model weights themselves — files that can be downloaded, copied, modified, quantized, fine-tuned, and redistributed around the world.
As governments consider restrictions on Chinese open-weight models, the security argument cuts in both directions. There are legitimate concerns around national security, guardrails, model capabilities, and foreign technology dependence. But those same open models are inexpensive, locally deployable, and can give defenders capabilities that commercial frontier models sometimes restrict.
So what would a ban actually accomplish — and could it even be enforced?
We dig into:
- Where U.S. restrictions on open-weight models currently stand
- Why banning downloadable model weights is fundamentally different from restricting an API
- How procurement rules and hosting restrictions could create a “soft ban”
- Why the economics of open-weight models are driving adoption
- How restrictions could disproportionately impact startups and smaller organizations
- Whether modifying, quantizing, or fine-tuning weights makes model-specific bans impractical
- The national-security argument for restricting Chinese models
- Why guardrails on hosted frontier models matter to the security debate
- How Hugging Face turned to a locally hosted open-weight model during incident response
- Whether banning open weights could put defenders at a disadvantage
- How existing government actions can indirectly limit access without banning a model outright
- The hardware and operational costs of self-hosting large models
- China, AI infrastructure, market competition, and industrial-scale distillation
- Anthropic’s argument for mandatory safety testing of sufficiently capable models
- Why safety testing gets complicated when open-weight guardrails can simply be removed
- What realistic AI policy might look like when the technology cannot easily be recalled
This episode explores a central tension in AI security: the properties that make open-weight models difficult to control are also the properties that make them useful.
You can run them locally. You control the data. A provider cannot revoke your access. You can modify the model for your own use case.
But once the weights are released, those capabilities are also difficult to take back.
For defenders, the bigger question may not be whether open-weight models should exist. It may be whether restricting access leaves security teams with fewer tools while attackers and foreign competitors continue developing the same capabilities elsewhere.
https://www.anthropic.com/news/position-open-weights-models
—
Learn more about Black Hills Information Security:
https://www.blackhillsinfosec.com/
Check out Antisyphon Training:
https://www.antisyphontraining.com/
#AISecurity #CyberSecurity #OpenWeightAI #ArtificialIntelligence #LLMSecurity #AIRegulation #DeepSeek #InfoSec #BHIS #Antisyphon
----------------------------------------------------------------------------------------------
🎧 Subscribe to the Podcast:
https://aisecurityops.transistor.fm
About Brian Fehrman - https://www.blackhillsinfosec.com/team/brian-fehrman/
About Bronwen Aker - https://www.blackhillsinfosec.com/team/bronwen-aker/
About Derek Banks - https://www.blackhillsinfosec.com/team/derek-banks/
About Ethan Robish - https://www.blackhillsinfosec.com/team/ethan-robish/
About Ben Bowman - https://www.blackhillsinfosec.com/team/ben-bowman/
- (00:00) - Intro: Can You Actually Ban an AI Model?
- (01:26) - Where U.S. Open-Weight Restrictions Stand Today
- (05:20) - Why Cost Makes Open-Weight Models Hard to Replace
- (06:32) - What Would an Open-Weight Model Ban Actually Look Like?
- (13:06) - National Security, Guardrails, and the Case for Restrictions
- (15:02) - Hugging Face and Why Defenders Need Open Models
- (20:02) - Soft Bans, Model Access, and the Cost of Self-Hosting
- (23:14) - China, AI Competition, and Model Distillation
- (27:09) - Anthropic’s Proposal for Open-Weight Model Safety
- (31:19) - Final Takeaways: Competing in an Open-Weight World
Click here to watch this episode on YouTube.
Brought to you by:
Black Hills Information Security
☯️ Introducing BHIS Fusion Penetration Testing
https://www.blackhillsinfosec.com/fusion-penetration-testing/
Antisyphon Training
Active Countermeasures
Wild West Hackin Fest
Episode Video
Creators and Guests
Host
Brian Fehrman
Brian Fehrman is a long-time BHIS Security Researcher and Consultant with extensive academic credentials and industry certifications who specializes in AI, hardware hacking, and red teaming, and outside of work is an avid Brazilian Jiu-Jitsu practitioner, big-game hunter, and home-improvement enthusiast.
Host
Bronwen Aker
Bronwen Aker is a BHIS Technical Editor who joined full-time in 2022 after years of contract work, bringing decades of web development and technical training experience to her roles in editing pentest reports, enhancing QA/QC processes, and improving public websites, and who enjoys sci-fi/fantasy, Animal Crossing, and dogs outside of work.
Host
Derek Banks
Derek is a BHIS Security Consultant, Penetration Tester, and Red Teamer with advanced degrees, industry certifications, and broad experience across forensics, incident response, monitoring, and offensive security, who enjoys learning from colleagues, helping clients improve their security, and spending his free time with family, fitness, and playing bass guitar.