Weight access
Can the institution inspect the model it is delegating to? Open weights make inspection possible; they do not make it happen. Governance asks whether anyone has looked.
Ethotechnics does not favor open or closed weights. It classifies a deployment by nine properties and attaches governance to the assembled system, not to the model.
Jump to
Ethotechnics takes no position for or against open weights. It favors architectures in which consequential authority can be inspected, constrained, contested, and reversed, whichever way the weights are distributed.
Open weights move the governance burden from the model provider to the deploying institution. They can improve inspectability, substitutability, version stability, and institutional reversibility while removing central constraint. Closed weights keep central constraint and give up some of the rest.
The method therefore classifies a deployment by nine properties rather than by weight access alone: weight access, runtime control, update authority, version stability, revocation, substitutability, observability, standing, and dependency. Together they form the substrate profile, a forthcoming object in the object model.
Canonical entry: Open weights and the delegation boundary in the glossary.
Two institutions deploy the same open-weight model for benefits triage. The first runs it on its own infrastructure, pins the version, keeps a substitute vendor warm, logs every decision in its own format, and gives applicants a challenge route. The second calls a hosted endpoint for the same model, accepts silent updates, has no substitute, and keeps records only in the vendor's console. The weights are identical. The substrate profiles are not, and the second institution has less governable authority than a well-run closed deployment would give it.
Implementation
Unique operational detail to help this concept stand on its own in policy, procurement, and review workflows.
Can the institution inspect the model it is delegating to? Open weights make inspection possible; they do not make it happen. Governance asks whether anyone has looked.
Who decides where and how the model runs, and can the institution stop it? Runtime control held by a provider is authority the institution has delegated without a grant.
Who can change the model's behavior, and does a change count as a new delegation? An update the institution did not authorize is an expansion it did not decide.
Can the institution keep running the version its evidence was gathered on? Evidence and authority stay coupled only if the thing evaluated is the thing deployed.
Can the provider withdraw the model, and can the institution withdraw from the provider? Both directions are reversibility questions with institutional cost.
How difficult would it be to replace the model with another? Substitutability is the largest single input to dependence, and open weights can raise it or leave it untouched.
Can the institution see what the model did, in a form it controls? Observability that lives in a provider's console is observability the institution can lose.
Who can challenge a decision the assembled system made, and does the challenge reach the system regardless of where the model runs? Standing attaches to the deployment, not to the weights.
How far has the institution come to rely on this substrate, and what would withdrawal cost? Dependency is a state of the deployment that weight access neither creates nor removes.
Doctrine
The twelve laws the nine properties are read against. Law I separates capability from authority; Laws V, VI, and XII govern dependence and reversibility.
Explainer
What a system can do without institutional approval, and why that is the first property to measure.
Research
Where public doctrine has converged on the first-generation laws and left the second-generation laws uncovered.
Neither. The method classifies deployments, not models. A deployment is more governable when consequential authority can be inspected, constrained, contested, and reversed, and either distribution can score well or badly on that.
Because weight access is one property and it does not predict the others. An open-weight model served by a third party with silent updates can have less version stability and less runtime control than a closed model under contract. The nine properties separate what weight access bundles together.
Greater freedom to compose capability requires greater explicitness about delegated authority. When an institution can assemble any model with any tools on any runtime, nothing upstream constrains what the assembled system may do. The constraint has to be stated by the institution, as a grant, or it does not exist.
That it was never a sufficient abstraction. Provider-side policy governs the model. It cannot govern the agent the model is wrapped in, the delegation that authorizes the agent, or the institution that depends on it. Open weights make that visible by removing the provider from the loop, but the gap was there in closed deployments too. Governance attaches to the assembled system.
As a forthcoming schema in the object model, attached to a system record alongside the dependency record and the authority grant. Until it is published, the nine properties can be recorded as a table in the safety case.