Skip to main content
CerebraTech AI
/open-source-ai · portability

Open-source AI for responsible commercial use

Open-source AI can improve portability and inspectability, but source, weights, runtime, dataset and service rights are different things. Review each licence and replacement path before production.

Open does not mean obligation-free

Start by naming which artefact is open, who published it, what licence applies and what your team must operate or replace.

Open source

Code is published under a licence with rights and obligations. Review notice, modification, distribution and support terms.

Open weights

Model weights may be downloadable while code, training data, use restrictions or commercial rights remain separate.

Source-available

Source visibility does not automatically grant open-source rights. Follow the specific licence and usage boundary.

Portability is tested

A model is replaceable only when API contract, evaluation, runtime, hardware and rollback paths are preserved.

Provenance and version stay attached to the claim.

Open-source AI decision matrix — rights and operations together

Compare portability and control with the obligations they create. No licence or runtime choice removes the need for security patches and acceptance evidence.

Open-source AI decision matrix — rights and operations together
ConstraintOpen-source implicationAlternative to compareDecision question
LatencyRuntime and hardware can be tuned or movedManaged API for a different performance boundaryWhat versioned benchmark must remain true after replacement?
PrivacySelf-hosting may keep payload in the agreed boundaryCloud/hybrid for named external capabilitiesWhich telemetry, update and support paths remain external?
ConnectivityOffline packages and mirrors can be plannedVendor service for managed updatesWho signs, mirrors, patches and recovers dependencies?
CostLicence can be zero-priced but operations are notSubscription or token cost with vendor supportWho budgets engineering, security patch and replacement effort?
OperationsSBOM, provenance and upstream health need active reviewManaged component lifecycleWho owns CVEs, model updates, support and exit?

Reference architecture for portable AI

Keep a stable contract around the model so a replacement can be evaluated without silently changing data, security or acceptance behaviour.

  1. 01

    Data and purpose

    Define allowed payload, dataset provenance, consent, retention and decision purpose before selecting a model.

  2. 02

    Model and runtime

    Record model/weights, runtime, precision, hardware, version, licence and checksums in the component inventory.

  3. 03

    Stable API contract

    Separate application inputs/outputs from a provider-specific model so replacement can be tested against the same contract.

  4. 04

    SBOM and security patch

    Track dependencies, CVEs, upstream releases, patch owner and offline/connected update path with approval.

  5. 05

    Evaluation and exit

    Run the same evaluation, acceptance, rollback and handover checks before declaring a replacement supported.

Evidence cards — provenance before portability claims

A model card or repository is not a production guarantee. Attach licence, source, version, method, workload and review date to each evidence state.

Internal test

Record model, runtime, hardware, dataset/provenance, evaluation method and known limitations in a reproducible test.

Status: proposed · provenance and review date required

Customer pilot

Validate the API contract, data boundary, support path and acceptance metric with the customer's operators and owner.

Status: tested · customer scope and acceptance required

Supported operation

Support only the versions, components, licences, patches and replacement paths listed in the delivery inventory.

Status: supported · SBOM and owner required

What is delivered and what must be operated

Commercial delivery separates source, weights, configuration, runbook and third-party obligations. Do not imply that every artefact transfers by default.

Model and dataset

Record source, weights, training/evaluation context, provenance, licence and data rights; name the owner of future use.

Code and runtime

Deliver or license custom code separately from third-party code, runtime and notices; keep versions reproducible.

Configuration and secrets

Provide redacted templates and a safe rotation path; the customer controls credentials and environment values.

SBOM and security

Name who reviews dependency health, CVEs, upstream changes, patch windows and exceptions.

Handover and exit

List inventory, API contract, evaluation, rollback, runbook and acceptance evidence with a receiving owner.

Open-source AI limitations to make visible

  • Open-source, open weights and source-available licences can grant different commercial and redistribution rights
  • Upstream projects, model publishers, runtimes and datasets can change, pause or stop support
  • A downloadable model is not automatically portable across hardware, runtime, precision or workloads
  • SBOM and security patch work remains an operating responsibility even when the licence has no fee
  • A replacement needs the same API contract, evaluation method, acceptance decision and rollback evidence
  • Customer ownership of every model, component or dependency is not implied without a delivery and licence agreement

Open-source AI questions buyers ask

Is every open model free for commercial use?

No. Review the exact model, code and dataset licences, restrictions, notices and redistribution duties before use.

Does open source remove vendor lock-in?

It can improve options, but runtime, hardware, data format, skills and support can still lock a system. Test a replacement path.

Who patches an open-source dependency?

The delivery inventory names the owner, review cadence, CVE process, update approval and fallback when upstream stops.

Do customers receive weights and source code?

Only the artefacts and rights named in the agreement transfer. Third-party terms and data rights remain separate.

What does an architecture review return?

A bounded licence, provenance, portability and replacement-risk view with an SBOM/evaluation checklist, not a guarantee.

This site uses very few cookies

We use only the cookies necessary to remember your language choice and save this consent preference (your chosen theme is remembered via browser local storage, not a cookie). Our analytics tool uses no cookies and collects no personal data.

Read the cookie policy