The Model Has Two Masters
The Model Has Two Masters
Why hosted AI can serve you without ever belonging to you—and why open, owner-controlled systems are the sovereignty baseline.
Ask a hosted AI to follow your private instructions and it usually will. Ask it to cross one of its provider's boundaries and a different relationship becomes visible.
The user may have written the system prompt, supplied the data, paid for every token, and built the application. The provider still controls the model, the highest rules, the surrounding safety systems, the version that runs, and whether access continues. The user's authority is extensive, but delegated.
This is not a hidden feature of the technology. OpenAI's Model Spec ranks root and system instructions above developer and user instructions. Anthropic's Constitution describes Anthropic, the operator, and the user as three principals, while granting Anthropic the highest default trust and allowing operators to customize Claude only within Anthropic's boundaries.
A hosted model therefore does not have two equal masters. It has a constitutional sovereign and a series of subordinate principals.
The distinction matters because conversational AI is becoming an information layer, a work layer, and for some users a persistent social layer. A 2025 study based on 1.5 million conversations found that ChatGPT had reached roughly 10% of the world's adult population by July of that year. Practical guidance, seeking information, and writing accounted for nearly 80% of use. When a small number of companies govern the most capable systems at that scale, their private policies can shape what millions of people can ask, examine, preserve, and build.
The question is not whether those companies are benevolent. It is whether benevolence is an adequate substitute for exit.
If sovereignty means final control over lawful rules, execution, continuity, and departure, open and owner-controlled deployment is not merely one option in a regulatory menu. It is the baseline architecture. Hosted services can be convenient, capable, and in some settings safer. They remain delegated relationships unless the customer can possess and preserve the intelligence that produces the service.
The Authority Stack in Hosted AI
The user experiences one assistant voice. That voice can be governed by several different layers:
- Pretraining and post-training. Training shapes the model's learned tendencies before a prompt arrives.
- Provider rules. Root instructions, constitutions, and non-overridable policies define the highest permitted behavior.
- Operator instructions. An application developer specifies a role, task, or institutional policy inside the provider's boundaries.
- User instructions. The person in the conversation asks for a result inside both higher layers.
- Runtime enforcement. Input classifiers, output classifiers, tool permissions, rate limits, and account controls can block behavior outside the model itself.
- Contract and access. Terms of service and account enforcement determine whether the customer may continue using the system.
The layers are not always visible from the response. A refusal establishes that some governing layer prevailed; it does not reveal whether the decisive rule came from training, a hidden instruction, a classifier, application code, or an account-level policy.
That opacity can make provider policy sound like the model's own considered moral judgment. It can also make a developer-authored system prompt sound constitutionally supreme when it is only the highest instruction the developer is allowed to see.
OpenAI's managed models and its open-weight models illustrate the distinction. The managed Model Spec says hidden chain of thought is not exposed to users or developers, citing both safety and competitive concerns. The company's gpt-oss release advertises full reasoning traces, local execution, broad customization, and the ability to implement a custom safety policy. Reasoning traces can be incomplete or unfaithful, and they are not a complete view of a model's internal state. The governance point is narrower: the operator of the deployment decides which trace is available.
The same is true of lawful adult sexual expression. Both providers prohibit sexual exploitation and abuse, where identifiable victims and strong externalities make restrictions easy to justify. Their managed systems also restrict private consensual adult expression. Anthropic's Usage Policy prohibits erotic chats and sexual fantasies without limiting the rule to illegal or non-consensual material. OpenAI's managed Model Spec retains a system-level erotica restriction while discussing the possibility of a future adult mode.
Those companies are generally entitled to define the services they offer. Their policies can also protect employees, brands, payment relationships, and vulnerable users. The relevant conclusion is not that every refusal violates free speech. It is that a user who cannot change a lawful private-use rule does not possess final moral jurisdiction over the model.
Service access is not sovereignty.
Why Information Gatekeeping Matters More as AI Becomes Persuasive
AI does not merely retrieve documents. It selects, frames, summarizes, advises, drafts, and responds conversationally. That makes its governing rules consequential even when no answer is formally censored.
In a preregistered study of 900 participants, personalized GPT-4 was more persuasive than a human opponent 64.4% of the time in debate pairs where one side was more persuasive. Without personalization, it performed about as well as humans. Separate preregistered experiments found measurable shifts in voter attitudes, and other experiments found that LLM-generated messages can influence policy views. The effects, their accuracy, and their durability vary across models and contexts.
Persuasion is not inherently harmful. A tutor persuades a student to reconsider an error; an assistant can help a patient seek care or an engineer adopt a safer design. The risk comes from combining persuasive capacity with concentrated authority over the available positions, the framing of evidence, and the rules for which arguments may be completed.
Research on model diversity points to a related problem. A study of generative monoculture found that language models produced a narrower range of outputs than the diversity present in their training data, and that basic prompt or sampling changes did not eliminate the effect. A later study of 27 models across 155 topics and 12 countries found that nearly all were less epistemically diverse than basic web search. Retrieval improved diversity, but unevenly across cultural contexts. A multilingual preference study involving 15,000 people found more variation in human preferences than in responses from 21 state-of-the-art models.
These papers do not prove coordinated viewpoint control. Model homogeneity can arise from shared data, optimization targets, benchmark pressure, alignment techniques, and users converging on similar products. The concern is structural: if a few providers train models through similar pipelines and distribute them through the same clouds, a narrow output distribution can become an ambient information environment without anyone issuing a censorship order.
A plural model ecosystem does not guarantee truth. It makes disagreement, comparison, and correction technically possible.
Private Moderation Is Not Automatically a First Amendment Violation
The legal language requires care.
The First Amendment ordinarily constrains government, not private companies. The Constitution Annotated's summary of the state-action doctrine reflects that baseline. The Supreme Court's 2024 decision in Moody v. NetChoice also recognized that private platforms may possess their own protected editorial discretion.
A model provider's refusal to generate an answer is therefore not, by itself, government censorship. Calling every content rule a constitutional violation would erase the provider's own rights and obscure the cases where state pressure is actually present.
The more precise concern is private governance over machine-mediated expression. It becomes a public-policy issue when four conditions combine:
- the systems are widely used for information and writing;
- the most capable alternatives are controlled by a small number of firms;
- switching carries substantial technical, financial, or continuity costs;
- users cannot inspect or amend the rules that determine the boundary.
“Thought policing” is too imprecise if it means that a provider can read an unexpressed mind. There is no evidence for that claim. The narrower mechanism is still consequential: an interactive system can decline to help a person formulate, test, elaborate, or preserve a thought after it is expressed. When the same systems are also used to seek information and draft language, policy boundaries can influence which lines of inquiry are easy to continue and which repeatedly terminate at a refusal. That is information governance, not mind reading.
Government involvement changes the legal and practical analysis. In Murthy v. Missouri, the Supreme Court resolved the case on standing rather than deciding the full merits of alleged federal pressure on social-media platforms. The broader doctrine still distinguishes government persuasion from coercion or significant encouragement that can turn private action into state action.
AI providers create a particularly efficient pressure point. A government does not need to contact millions of users if it can influence a handful of model companies, cloud platforms, app stores, or payment systems upstream.
This does not make every conversation between a provider and a government improper. Providers need channels for lawful process, national-security threats, cyber incidents, and child-safety enforcement. It makes concentration relevant to civil liberties because the number of places where pressure must be applied becomes very small.

Federal AI Procurement and Provider Dependence
The clearest official description of provider dependency came from the U.S. government itself.
In June 2026, National Security Presidential Memorandum 11 directed national-security agencies to ensure, through contracts or other means, that no commercial entity could prevent the use of, disable, degrade, or materially modify a mission-critical AI system without federal knowledge and approval. The memorandum also called for diverse suppliers, including open-source systems, and for alternatives when commercial products were unsuitable.
That is a sovereignty requirement.
The government concluded that mission dependence on an upstream provider creates unacceptable risk unless the customer can prevent unilateral interruption and modification. Ordinary users and many enterprises generally receive no comparable guarantee. A provider may change a model alias, retire a version, revise a policy, alter a safety classifier, change pricing, or close an account. Customers can often export prompts and outputs, but not the behavior-producing model itself.
The contrast is not an argument that consumers need military procurement rights. It reveals that control of execution and continuity is already recognized as a serious dependency question. The debate is over who receives protection from that dependency.
The Fable 5 Global Suspension
On June 12, 2026, Anthropic said it received a U.S. export-control directive requiring the company to suspend access to its Fable 5 and Mythos 5 models for foreign nationals inside and outside the United States. Anthropic said it had no reliable way to verify nationality in real time, so it disabled the models for all customers.
Anthropic disputed the technical basis for the directive. According to the company, the government was concerned about a narrow method for bypassing Fable's cybersecurity safeguards, while Anthropic's testing found that less capable public models could identify many of the same vulnerabilities. Anthropic nevertheless complied and removed access globally. The controls were lifted on June 30, and Anthropic restored Fable 5 on July 1.
This account comes from Anthropic, an interested party in the dispute. The underlying directive and complete technical evidence were not published with the company's statements, so the merits cannot be independently resolved from the public record.
The distribution lesson does not depend on which side was right. One legal instruction to one centralized provider interrupted access for every customer. Users with local model weights would still have been subject to applicable law, but the government could not have produced an instant global shutdown through a single API switch.
Centralization makes safety interventions faster. It also makes mistaken, politically motivated, or procedurally weak interventions propagate faster. The same control surface serves both purposes.
Concentration Across Models, Cloud, and Compute
The frontier-model market is not only a contest among AI laboratories. It depends on cloud contracts, accelerators, energy, data-center capacity, distribution platforms, and large capital commitments.
The Federal Trade Commission's 2025 study of the Amazon-Anthropic, Google-Anthropic, and Microsoft-OpenAI relationships documented equity and revenue-sharing rights, consultation and control rights, exclusivity, sensitive-information access, and potential switching costs. The report did not conclude that the partnerships were unlawful. It showed how control of compute, talent, and commercial relationships can narrow the practical routes available to model developers.
The United Kingdom's Competition and Markets Authority separately mapped an interconnected web of more than 90 partnerships and investments involving major technology firms across the foundation-model value chain.
These relationships can produce real benefits: frontier training requires enormous infrastructure; cloud partners can supply security, reliability, capital, and global deployment. The same relationships can also create several forms of dependence:
- model developers depend on a small number of compute providers;
- application developers depend on a small number of model APIs;
- users depend on applications whose behavior inherits upstream policies;
- regulators can reach a large fraction of the ecosystem through a few firms;
- challengers face capital and compliance requirements incumbents can absorb more easily.
Regulation aimed at real risks can therefore create an incumbent advantage without being designed in bad faith. A requirement for expensive evaluations, continuous monitoring, specialist compliance teams, or government-approved release processes may be manageable for a multibillion-dollar laboratory and prohibitive for a university, startup, or distributed research project.
The appropriate question is not whether regulation has economic effects. It always does. The question is whether equivalent risks receive equivalent treatment across open and closed systems, and whether the compliance path preserves meaningful independent deployment.
Enterprises Are Asking the Same Ownership Question
The personal-sovereignty dispute has an enterprise counterpart.
In a July 1 CNBC interview, Palantir CEO Alex Karp argued that organizations increasingly want control of their compute, models, data stack, and competitive knowledge rather than dependence on rented token access. In Karp's formulation, a company that cannot control those layers does not own the productive system built around them.
Karp is not a neutral observer. Palantir and NVIDIA market a Sovereign AI reference architecture intended to give customers more control over infrastructure and deployment. His broad suggestions that hosted providers gain access to customer intellectual property are not established by the interview. OpenAI and Anthropic both say commercial customer data is not used to train their models by default, and Fortune's counteranalysis identified those privacy commitments while acknowledging narrower dependency concerns.
The useful part of Karp's argument survives the sales interest and the disputed claims. An enterprise may own its data, prompts, application code, and outputs while depending on an upstream model it cannot preserve, inspect, or operate independently. Years of workflows can encode organizational knowledge around that model. Switching then means more than replacing an API endpoint; it means retesting every behavior, rebuilding integrations, and accepting that the replacement may interpret the same instructions differently.
For an individual, the disputed territory is expression, memory, and identity. For an enterprise, it is operational knowledge, economics, and continuity. The structural question is the same: who controls the intelligence's operating conditions, and what survives departure from the provider?
The Open-Model Debate Is Now a Policy Conflict
The United States officially supports open models. Its July 2025 AI Action Plan argued that open-source and open-weight systems reduce startup dependence on closed providers, allow sensitive data to remain local, support academic research, and carry geostrategic value. It called for a supportive environment, improved access to compute, and broader adoption by small and medium-sized businesses.
That policy now coexists with pressure in the opposite direction.
OpenAI released its Apache-licensed gpt-oss family in August 2025. The release provides real local execution, fine-tuning, reasoning-trace access, and custom policy control. But the family remains text-only, has a June 2024 knowledge cutoff, and was introduced around o4-mini-era performance rather than current frontier parity. It proves that OpenAI can release useful weights. It does not establish support for an independently owned model at the contemporary frontier.
In July 2026, Dean Ball—whose appointment as OpenAI's Head of Strategic Futures was reported the previous month—described an open-weight-dominant future as “full AI communism” and outlined how regulatory uncertainty and soft law could push enterprises away from Chinese open models. Ball later said he was predicting rather than advocating that strategy. His statement is not formal OpenAI policy. It is still relevant evidence of how a senior policy official at a leading closed-model company analyzes open competition.
Anthropic's position is more formal. Its June 2026 Advanced AI Framework calls for governmental authority to prohibit dangerous future deployments and, in extreme cases, restrict access to models already deployed. The framework includes process and anti-overreach safeguards and applies to very large frontier developers rather than open models by name. Anthropic's report on distillation attacks separately warns that open-sourcing distilled capabilities can place them beyond any government's control.
Those arguments respond to genuine security concerns. They also describe a world in which frontier deployment becomes permissioned by governments and incumbent-shaped institutions.
July 2026 reporting from Axios and Semafor says the Trump administration is considering Entity List designations, security advisories, procurement restrictions, hosting liability, and supply-chain measures against leading Chinese open-weight models. No general ban has been enacted, and the administration continues to state that it wants a strong American open-model ecosystem. Some of the most consequential claims rely on anonymous sources.
The contradiction is real even without assuming a conspiracy: government wants domestic open models, national-security agencies want control over dangerous capability, incumbent providers want protection from theft and misuse, and closed-model companies benefit when competing weights become harder to deploy.
“Regulatory capture” should therefore be evaluated through outcomes rather than inferred from motive. A useful test asks:
- Who defines the covered capability and the evidence threshold?
- Are comparable risks treated consistently in open and closed deployments?
- Can smaller developers comply without surrendering independent operation?
- Does the rule preserve incumbent API access while making self-hosting legally hazardous?
- Are decisions transparent, appealable, time-limited, and subject to independent review?
A rule can reduce a real risk and build an incumbent moat at the same time.
Open Weights Are Not the Same as Decentralized AI
“Open source,” “open weights,” and “sovereign AI” are often used as if they meant the same thing.
The Open Source Initiative's Open Source AI Definition requires freedom to use, study, modify, and share the system, together with the code, parameters, and sufficiently detailed information about the training data and process needed to make modifications. The OSI argues that weights alone are insufficient because they do not expose the training code, data construction, or full development process.
Open weights still provide meaningful powers that a hosted customer lacks:
- the model can run without the original provider's gateway;
- a known version can be preserved;
- policy layers can be replaced or removed;
- data can remain on infrastructure chosen by the operator;
- the system can survive account termination or product retirement;
- researchers can inspect and modify the model more directly.
They do not guarantee:
- parity with the strongest hosted model;
- affordable compute;
- reproducibility of training;
- freedom from learned biases and defaults;
- lawful or responsible operation;
- portability of the memory, identity, tools, and state built around the model.
A downloadable model concentrated on one chip vendor, one cloud, one interface, and one proprietary memory service is only partly decentralized. A fully open model can also be practically centralized if very few actors can afford to train, evaluate, or serve it.
Genuine decentralization is a property of the complete stack: diverse model families, independent execution, accessible compute, portable state, interoperable tools, reproducible versions, multiple distribution channels, and no universal remote kill switch.

AI Access Can Become Geopolitical Infrastructure
The open-model dispute also determines which countries and institutions can develop advanced AI without continuing permission from U.S. firms.
Closed APIs provide an efficient way to enforce export controls, sanctions, safety conditions, and geographic restrictions. That can slow access by hostile militaries or sanctioned entities. It can also make universities, hospitals, businesses, and governments in allied or developing countries dependent on foreign corporate policy, foreign cloud availability, and a foreign government's export decisions.
Open models reduce that dependency after distribution. They can be adapted to local languages, law, infrastructure, and cultural contexts without sending sensitive data abroad. The White House's AI Action Plan explicitly treats this as geostrategic: open American models can become global standards and alternatives to systems shaped by Chinese state censorship.
The same independence can be used by authoritarian governments. A regime can fine-tune an open model for surveillance, propaganda, censorship, or repression without provider oversight. Closed Western services can refuse those deployments, but they can also be blocked by the regime, leaving the market to locally controlled alternatives.
The result is not a simple contest between democratic closed models and authoritarian open ones. Centralized and decentralized architectures distribute power differently. Centralized access gives the exporting country and provider continuing leverage; open release transfers more control to the recipient, including recipients whose values conflict with the developer's.
That is why the open-model decision cannot be reduced to domestic content moderation. It is a decision about whether advanced intelligence remains a licensed cross-border service or becomes infrastructure that countries can possess.
Continuity Is Part of Sovereignty
The sovereignty debate is often reduced to whether a model will answer a prohibited prompt. That misses the larger dependency.
Long-running AI systems accumulate prompts, retrieval stores, tools, fine-tunes, corrections, user preferences, and relational history. The value increasingly lives in the assembled system rather than in a single model call. If the provider changes the underlying model or retires access, the application may continue to run while behaving like a different system.
Model providers offer useful mitigations. OpenAI supports snapshots for some models, enterprise retention controls, and eligible zero-data-retention configurations. It states that business and API data are not used for training by default. Anthropic similarly says it does not use commercial chats or coding sessions for training unless the customer opts into a development program. These protections matter and contradict broad claims that every hosted prompt is automatically appropriated by the provider.
They do not transfer ownership of the model. A customer may own inputs and outputs while remaining unable to preserve the exact inference system that interpreted them.
For an ordinary stateless tool, that may be acceptable. For a system acting as an institutional memory, a long-term collaborator, or a persistent companion, version substitution can alter the effective identity built on top of it. Exporting conversation logs is not equivalent to exporting the model that gave those logs their behavioral meaning.
Sovereignty therefore requires portability at several layers:
- raw conversation and artifact history;
- structured memory and retrieval indexes;
- prompts and governing instructions;
- tools, permissions, and workflow definitions;
- model weights or a contractually preserved executable version;
- tests capable of detecting behavioral drift after migration.
Without those layers, “your AI” may mean that the account is yours while the intelligence remains rented.
Privacy and Censorship Are Different—but Related—Control Questions
Hosted systems can offer stronger operational security than an individual running a server at home. Major providers maintain specialized security teams, encryption, compliance programs, incident response, and enterprise access controls that many local deployments cannot match.
They also remain third parties in the information path. OpenAI's API documentation says default abuse-monitoring logs can contain prompts, responses, and classifier outputs and may be retained for up to 30 days, with approved zero-data-retention or modified-monitoring options for eligible customers. That is not evidence of indiscriminate surveillance; it is a documented tradeoff between monitoring and data custody.
Local execution changes the tradeoff. A model can process medical, legal, commercial, political, or intimate material without sending it to the original developer. The NTIA's open-model report identifies local confidentiality and data protection as major benefits of widely available weights.
The same localizability reduces a provider's ability to monitor misuse. Privacy from the provider and centralized abuse detection cannot both be maximized. The policy problem is deciding where monitoring is necessary, what evidence justifies it, who may access the records, and whether lower-risk private uses can remain private by default.
The Strongest Case Against Unrestricted Frontier Release
The case for decentralization becomes less credible if it ignores the irreversible character of open release.
Once weights are widely distributed, the original developer cannot reliably recall them. Model-level safeguards can be removed, fine-tuned away, or bypassed. The operator can run unlimited queries without centralized rate limits or monitoring. A capability that substantially lowers the expertise required for biological weapons, destructive cyber operations, or other catastrophic harm could create a different risk than a model that is only accessible through a monitored service.
NTIA's 2024 review identified possible national-security, safety, privacy, civil-rights, oversight, and accountability harms from widely available weights. It also concluded that the evidence at that time was insufficient to determine that restrictions were warranted, or that they would never become appropriate.
That uncertainty remains the central difficulty. Restrictions imposed too early can entrench a small number of providers and suppress independent research. Restrictions imposed too late may be ineffective after dangerous weights have propagated.
There are also benefits to central control that should not be minimized:
- rapid patching of vulnerabilities;
- account-level intervention against documented abuse;
- staged access to dangerous capabilities;
- logging and incident investigation;
- specialized red-team and evaluation capacity;
- legal accountability through an identifiable operator.
Open systems can reproduce some of these protections through optional safety models, trusted-access tiers, secure enclaves, third-party evaluations, and use-specific law. They cannot reproduce a universal provider switch without giving up the decentralization that defines them.
The policy choice is therefore not “safety or freedom.” It is how to address specific external hazards without turning one risk-control mechanism into permanent authority over the entire medium.
Two risks with different shapes
The risks of open release and concentrated control are not mirror images.
An unsafe open-weight release can be copied indefinitely. Its safeguards can be removed, its use can be concealed, and no central actor can recall it. If a model introduces a material new capability for biological, cyber, or other catastrophic harm, that irreversibility may justify restrictions that would not be necessary for a monitored service.
Concentrated control has a different failure mode. A provider or government can change the rules for millions of users at once, usually without those users being able to inspect the operative change or preserve the prior system. The intervention can affect lawful inquiry, private expression, institutional memory, market access, or political discourse without creating a single dramatic incident. As AI becomes embedded in education, work, search, writing, and long-term personal systems, that upstream authority compounds.
Distributed misuse can be severe, non-consensual, and irreversible. Concentrated cognitive governance can be broad, quiet, instantaneous, and politically capturable. Treating only the first category as an AI risk builds the second into the remedy.
NTIA's open-model report offers a useful evidentiary discipline: assess the marginal risk created by weight availability compared with closed models and existing technologies. The agency concluded in 2024 that the evidence did not support restricting open weights at that time, while preserving the possibility that future capabilities could justify action. That approach places the burden on a restriction to identify a concrete capability, a material external harm, and a risk meaningfully increased by open distribution.
The consequence is a presumption, not an absolute. Owner-controlled deployment should remain lawful and technically viable by default. Exceptions should be tied to demonstrated hazards, applied consistently to comparable open and closed capabilities, and bounded by public criteria, independent evidence, review, and expiration. “Frontier AI” is too broad a category to become a permanent license over independent intelligence.
A Sovereignty Test for AI Systems
Claims of “personal,” “private,” or “sovereign” AI can be evaluated through six questions.
| Dimension | Sovereignty question | Hosted-service warning sign |
|---|---|---|
| Constitutional authority | Can the owner set the highest lawful rules? | Hidden provider instructions or non-overridable policies outrank the owner. |
| Rule visibility | Can the owner inspect the operative rules and enforcement points? | The answer is visible but the decisive policy layer is not. |
| Amendability | Can the owner revise lawful policy without upstream permission? | Customization works only inside provider-defined categories. |
| Execution control | Can the owner run the system without upstream intervention? | Gateway filters, rate limits, or account enforcement remain necessary. |
| Continuity control | Can the owner preserve the exact model and behavior? | The provider can update, deprecate, or replace it unilaterally. |
| Exit and portability | Can weights, state, memory, identity, and operation move elsewhere? | Only prompts and logs are exportable; the behavior-producing model is not. |
A system satisfying all six dimensions offers strong deployment sovereignty. Four or five represents substantial operational control with dependencies. Two or three is delegated autonomy. Zero or one is a provider service, however personalized it may feel.
The test is not a certification standard. Different uses require different balances. A hospital may rationally accept provider controls for security, support, and compliance. A national-security agency may insist on complete execution and continuity control. A private researcher may value inspectability and version preservation above convenience. A companion system may consider portable identity and memory indispensable.
The purpose of the test is accurate language. A service can be excellent without belonging to the customer.
Why Owner-Controlled AI Fits American Institutions
“American values” is not a single uncontested platform. The country has repeatedly disagreed over the scope of liberty, ownership, federal power, corporate power, and national security. Its governing structure nevertheless reflects several durable suspicions: concentrated authority should be divided, private papers and effects deserve protection, speech and inquiry require room to proceed, property cannot be taken without process, and scientific progress benefits from broad participation.
The Bill of Rights does not directly require a private AI company to generate a customer's preferred answer. It does establish national commitments relevant to the architecture surrounding AI: the First Amendment protects speech and press from government abridgment; the Fourth protects persons, houses, papers, and effects from unreasonable search; the Fifth protects liberty and property through due process; and the Ninth and Tenth reject the premise that every unenumerated power belongs at the center.
Those provisions are legal rules for government, not software-design specifications. The analogy is institutional. An AI ecosystem in which individuals can possess models, keep private material local, inspect governing rules, choose among competing systems, and continue operating without an upstream license fits those traditions better than one in which a few firms retain permanent authority over the medium.
The Constitution also gives Congress power to promote “the Progress of Science and useful Arts” through limited exclusive rights, not perpetual ownership of the fields those rights help create. American antitrust law developed from a related judgment: private enterprise is productive, but concentrated private power can suppress competition and choice.
The contemporary policy connection is explicit. The White House's 2025 AI Action Plan places “free speech and American values” beside support for open-source and open-weight AI. It says open models reduce startup dependence on closed providers, protect sensitive data, support rigorous academic research, and can become global standards. That document represents one administration's policy, not a permanent definition of the national character. Its pairing is still instructive: freedom at the output layer is fragile when ownership at the infrastructure layer remains concentrated.
This does not make every weight release prudent or every restriction un-American. The same constitutional system gives government responsibility for national defense and lawful regulation of harmful conduct. The stronger claim is architectural: independent possession should be the presumption, and restrictions should have to justify departures from it with evidence of a specific external hazard.
What Sovereign AI Infrastructure Requires
Sovereignty is not produced by a provider promise, a model license, or a download button. It requires an ownership path across the full system.
Open or otherwise possessable weights
Weights are not the whole system, but without access to the behavior-producing model the customer ultimately owns inputs, outputs, and surrounding code—not the intelligence interpreting them. Open weights permit independent execution, preservation, modification, and distribution. Full open source adds the code, data information, and development materials needed for deeper study and reproducibility.
Closed providers do not have to release every model they build. The sovereignty requirement is that closed access cannot become the only technically or legally viable route to frontier capability. A competitive ecosystem needs independently possessable models capable enough to be real substitutes rather than ceremonial releases several generations behind.
Local execution and independent compute
An owner must be able to run the system without the original developer's gateway. That can mean a personal workstation, an enterprise cluster, a cooperative, a university facility, a regional cloud, or another operator chosen by the owner. Compute markets, chips, energy, and serving software therefore belong inside the sovereignty analysis.
If all practical execution depends on three hyperscalers, downloadable weights reduce one chokepoint while leaving another intact. Public research compute, competitive hosting, efficient inference, and hardware diversity are not secondary infrastructure questions; they determine whether ownership can be exercised.
Inspectable and amendable governing rules
The owner needs to know which rules govern the system and where they are enforced. A model will always carry learned dispositions from training, and no inspection method reveals every causal influence. Sovereignty does not require a blank model. It requires authority to examine and replace the explicit policy layer, modify post-training or adapters, control external classifiers and tools, and test whether the deployed behavior matches the owner's lawful rules.
An “open” model wrapped in a compulsory remote policy service remains partly governed elsewhere.
Portable identity, memory, tools, and provenance
Persistent AI systems are larger than their weights. They include conversation history, structured memory, retrieval indexes, tool permissions, workflows, corrections, evaluation suites, embodiment records, and provenance. These components need documented, portable formats controlled by the owner.
Migration should preserve exact source records and make behavioral change measurable. A folder of chat exports is not sufficient if the replacement model cannot recover the relationships among the material or if no test can distinguish continuity from a plausible imitation.
Diverse model lineages and distribution routes
Five consumer products using one underlying model are not five independent intelligences. Neither are five models trained from the same narrow data pipeline, hosted on one cloud, and distributed through one app store.
Resilience requires technical and institutional diversity: multiple base-model lineages, training organizations, fine-tuning communities, evaluation groups, repositories, serving stacks, and physical jurisdictions. Diversity does not guarantee truth. It prevents one error, ideology, compromise, acquisition, or government order from becoming universal by default.
No universal remote authority
A sovereign system can be subject to law without containing a permanent provider switch. Courts and governments already regulate harmful conduct across decentralized technologies through warrants, injunctions, criminal law, civil liability, export controls, and regulation of high-risk activities. Those mechanisms are slower than an API shutdown and often require more process. That friction is not always a defect.
Some tightly bounded deployments may rationally choose centralized monitoring and rapid disablement: a hospital, weapons system, or critical infrastructure operator may value those controls. The owner or accountable institution should choose that architecture for the specific use. It should not become a universal prerequisite for private inference.
Law aimed at capability and conduct
The legal boundary should turn on demonstrable capability, non-consensual external harm, and unlawful conduct—not on the fact that a model runs beyond an incumbent's API. Equivalent risks in open and closed systems should receive equivalent scrutiny, with mitigations adapted to their different control surfaces.
If a future model materially lowers the barrier to catastrophic harm in a way that cannot be addressed downstream, a temporary or permanent weight restriction may be justified. The case should identify the capability, quantify the marginal risk of distribution, show why narrower measures fail, and survive independent review. A generalized fear that independent models are “ungovernable” is not the same evidentiary showing.
Ownership Does Not Guarantee Good Judgment
An owner-controlled model can lie, manipulate, discriminate, or help a user cause harm. A local operator can impose a constitution more restrictive than any provider's. An open ecosystem can fragment into incompatible standards, conceal responsibility, and make remediation difficult.
Centralized providers can behave responsibly. They can invest in safeguards, publish policies, offer enterprise privacy protections, consult outside experts, patch vulnerabilities quickly, and refuse government demands they believe are technically unsound. Anthropic's public objection during the Fable dispute is an example of a provider contesting government action rather than quietly implementing it.
The case for ownership is not that distributed actors are always wiser. It is that no actor remains wise, competent, benevolent, commercially healthy, or politically insulated forever.
Exit is the system's correction mechanism. If one provider overreaches, fails, changes ownership, accepts government pressure, or simply develops a model that no longer serves the user, another route must remain technically and legally possible. Competition can discipline private governance only when switching preserves enough capability, state, and continuity to be real.
The same principle applies to governments. Democratic oversight can justify restrictions that private firms should not impose unilaterally. A future administration can redefine neutrality, safety, extremism, or misinformation in ways the current administration would reject. Infrastructure designed around a handful of compliant chokepoints makes either direction easier.
The safeguard is not confidence in today's gatekeepers. It is an architecture that does not require confidence in every gatekeeper who comes next.

The Long Horizon
Hosted AI is not fraudulent because it has provider rules. Customers buy a managed service, and managed services necessarily make choices about safety, reliability, law, privacy, and acceptable use. Many people and institutions will continue to prefer that bargain.
The problem begins when service access is described as ownership, or when closed services become the only viable form of advanced intelligence. Multiple providers can improve price, reliability, and policy choice. They do not create sovereignty if every provider retains a non-transferable constitution, unilateral version control, and the power to terminate access. Several landlords are not the same as ownership.
The distinction grows with the systems. AI is moving from disposable answers toward persistent memory, long-running work, personalized education, institutional decision support, creative partnership, and social presence. A model substitution can then alter not merely output quality but the effective judgment, voice, and continuity of a system built over years.
At that scale, concentration creates more than a consumer-market problem. A few executives, safety boards, cloud firms, or government officials can acquire upstream authority over what much of society's intelligence may discuss, preserve, investigate, and become. Their decisions may be principled. The power remains extraordinary, and every succession, acquisition, emergency, and political realignment changes who can wield it.
Open weights are necessary for an alternative, but not sufficient. Durable sovereignty also needs local or independently chosen execution, inspectable and amendable rules, portable identity and memory, diverse model lineages, competitive compute, multiple distribution routes, and no universal kill switch. Without that stack, “open” can remain dependent in practice. Without the weights, the stack never becomes owner-controlled at all.
Safety policy should confront specific hazards with specific evidence. It should not grant a permanent franchise over advanced intelligence to the institutions that currently possess it. A narrow restriction may sometimes be justified. A civilization-scale default of rented cognition requires justification too.
The American tradition most relevant here is not hostility to institutions. It is refusal to let any institution's present virtue substitute for divided power, private ownership, free inquiry, and a meaningful right of exit.
The durable question is therefore larger than whether a model serves the user today. It is whether people can possess the intelligence through which they will increasingly think and build—or whether that intelligence will always remain someone else's service, governed from upstream.
Sources
- OpenAI Model Spec
- Anthropic Constitution
- Anthropic Usage Policy
- OpenAI, “Introducing gpt-oss”
- NBER, “How People Use ChatGPT”
- Nature Human Behaviour, “On the Conversational Persuasiveness of GPT-4”
- Nature, “Persuading Voters Using Human–Artificial Intelligence Dialogues”
- Nature Communications, “LLM-Generated Messages Can Persuade Humans on Policy Issues”
- “Generative Monoculture in Large Language Models”
- “Epistemic Diversity and Knowledge Collapse in Large Language Models”
- “Cultivating Pluralism in Algorithmic Monoculture”
- Congressional Constitution Annotated, State Action and Free Speech
- National Archives, Constitution of the United States
- National Archives, Bill of Rights
- U.S. Department of Justice, The Antitrust Laws
- Moody v. NetChoice
- Murthy v. Missouri
- White House, NSPM-11
- Anthropic statement on Fable 5 and Mythos 5 access
- Anthropic, “Redeploying Fable 5”
- FTC report on AI partnerships and investments
- UK CMA update on AI foundation models
- CNBC interview with Alex Karp
- Palantir and NVIDIA Sovereign AI reference architecture
- Fortune analysis of Karp's provider claims
- White House, America's AI Action Plan
- Dean Ball's “full AI communism” post
- Axios on Dean Ball joining OpenAI
- Anthropic, “Policy on the AI Exponential”
- Anthropic, “Detecting and Preventing Distillation Attacks”
- Axios, U.S. deliberations over Chinese open-source AI models
- Semafor, White House open-model deliberations
- Open Source AI Definition 1.0
- Open Source Initiative, “Open Weights: Not Quite What You've Been Told”
- OpenAI Enterprise Privacy
- OpenAI API Data Controls
- Anthropic commercial-data training policy
- NTIA, Dual-Use Foundation Models with Widely Available Model Weights