Open Means You Can Leave
Ownership matters most when the model changes, the contract ends, or the vendor disappears.
A system’s ownership terms become visible when the model is deprecated, a better one appears, or the contract ends.
An export of old conversations leaves most of the intelligence layer behind: the tasks, agent logic, environment, verifier, reviewed data, and model artifacts may still live inside the product that created them.
The useful question is what the organization can keep operating.
The exit test
“Open” is doing too many jobs in AI.
It can describe public source code, downloadable weights, disclosed training data, a permissive license, interoperable interfaces, export rights, or the ability to self-host. These properties can reinforce one another. They are not interchangeable.
The Open Source Initiative defines open-source AI through freedoms to use, study, modify, and share, supported by access to the preferred form for modification. That is a broader standard than customer portability.
Our exit test asks whether an ownership promise has operational substance when the provider is no longer in the picture. It sits alongside the open-source definition rather than replacing it.
The test has to be applied one layer at a time.
| Layer | The exit question |
|---|---|
| Work data | Can the organization retain the source data, transformations, labels, and metadata it has the right to keep and use? |
| Agent | Can it inspect and move the prompts, tools, policies, memory design, and orchestration logic? |
| Environment | Can it run the tasks, state, fixtures, tool interfaces, and sandbox rules outside the original service? |
| Evaluation | Can it retain the rubrics, verifier logic, traces, and raw results needed to reproduce a decision? |
| Training data | Can it keep the reviewed examples, preferences, trajectories, filters, and provenance records it is authorized to use? |
| Model artifact | Can it use the resulting weights or adapters, checkpoints, configuration, and inference recipe under workable terms? |
| Continuation | Can a new operator evaluate and improve the system without rebuilding the layer from screenshots and exports? |
We use this as a draft standard, including for our own systems.
Private work, portable system
Legal work changes the openness boundary. Matter files may include client information, licensed sources, counterparty documents, personal data, and privileged material. Technical custody is not the same as the right to retain, train on, publish, or transfer that material.
Confidential work can stay private while the surrounding system remains inspectable and portable.
A private environment may expose a documented interface, with verifier code and test cases available inside the organization. The organization can keep reviewed training data confidential and state the rights to use it. A managed provider can operate the infrastructure while the organization retains the artifacts it needs to continue.
Customer control and public open source are separate properties. Both can matter. The architecture should say which one applies to each component.
The weights are only one surface
Open model projects show how much sits around a checkpoint.
Ai2’s Olmo releases include data, code, checkpoints, evaluations, and post-training artifacts across the model flow. Hugging Face started Open-R1 to reconstruct training data and code that were absent from an open-weight release. A usable model depends on more than its final weights, even when an organization has no reason to publish an Olmo-scale research package.
An intelligence layer for legal work also includes task definitions, tool interfaces, verifier tests, reviewed examples, and operating knowledge. Those artifacts can remain useful after the base model changes.
Base models are changing quickly, and organizations will want the option to replace them. Replacement will never be free. Tokenizers differ. Tool behavior changes. Adapters depend on particular model families and licenses. A real exit path preserves the option; it does not erase the switching cost.
Open Law Library offers a useful legal analogue. Its model gives government partners control over separate databases and domains, so the ability to publish law does not disappear with a publisher relationship. The technical object and the operating right reinforce one another.
An ownership claim needs both a usable artifact and the right to operate it.
Managed operation with an exit
Managed infrastructure can make sense because training systems are difficult to operate and maintain.
A provider can build and operate the system while the organization retains defined artifacts, access, and continuation rights. That gives the organization an exit without requiring it to run every component in-house.
That leaves a practical question for any AI system sold as open or owned:
If the model changes or the relationship ends, which parts still work, and who has the right to use them?