Who set
the lock?
What open weight models undo is not the supplier's monopoly. It is the law's capacity to locate dependence.
An enclosure with no one
For fifty years, technological dependence had an address. It was called a publisher, a manufacturer, a service provider. It was constituted by a licence agreement, an exclusivity clause, a patent, a proprietary architecture. When an organisation wanted to measure what held it, it re-read its contracts. When the law wanted to grasp it, it had a point of purchase: the supplier.
The artificial intelligence models known as open weight undo this geography. The European regulation does not know the word; it designates the same reality as models whose parameters, including weights, are made publicly available. Such a model can be downloaded freely, modified freely, hosted in-house, sometimes without a contract, often without a price. Open weight is not open source in the strict sense: the weights are public, but the training data, the complete code and the development process most often remain undisclosed. No proprietary licence retains the organisation that adopts it. No provider conditions its use. At every moment, it remains legally free to leave.
And yet, three years later, it can no longer leave.
In the meantime, it has composed. Hundreds of agents, thousands of prompts, processing chains, evaluation sets, connectors, compliance procedures, working habits: an entire patrimony has aggregated around a family of models. Replacing the model is no longer swapping a component. It is retesting, requalifying and refounding a substantial part of what the organisation knows how to do. The cost of exit is written in no contract. It is written in the organisation itself.
Dependence no longer passes through the contract. It passes through composition.
The phenomenon is no longer a hypothesis. In February 2026, open Chinese models overtook American models in weekly token volume consumed on the OpenRouter platform. At the end of 2025, seven of the ten most downloaded models on Hugging Face were Chinese, and the ecosystem of derivatives of Qwen alone exceeded one hundred thousand. In March 2026, a report by the United States China review commission of the American Congress described this diffusion as a loop of industrial reinforcement. In July 2026, at the world AI summit in Shanghai, official Chinese discourse erected open source as a path of development; the models actually released belong, for their part, to open weight.
This displacement has no nationality. That Chinese laboratories have made of it, since 2025, an industrial policy of global scale is only its first revealer. The phenomenon will hold for any open model, wherever it comes from, and for any organisation that composes.
What the law sees: openness as mitigation
Positive law looks at this phenomenon. It sees in it a guarantee.
Regulation (EU) 2024/1689 organises for open artificial intelligence a double regime of favour. Article 2(12) excludes from the regulation's scope AI systems released under a free and open-source licence, outside high risk and prohibited practices. Article 53(2) exempts providers of general-purpose models made available under a free and open-source licence, whose parameters, weights and architecture information are made publicly available, from two of the four documentation obligations: the technical documentation intended for the authorities and the information for downstream providers. Only the copyright compliance policy and the training-data summary remain, and the exemption falls away entirely beyond the systemic-risk threshold of Article 51.
The motivation of this regime is more instructive than its mechanism. Recital 102 salutes the contribution of open models to research, innovation and the growth of the Union's economy. Recital 104 grounds the alleviation on the high levels of transparency and openness ensured by the publication of the parameters. The legislator's reasoning holds in one equation: what is open is inspectable, what is inspectable is masterable, what is masterable is less risky. Amending Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July 2026, postponed the calendar for high-risk systems without modifying this regime.
The equation is not false. It is incomplete. It measures the risk of the model: its biases, its failures, its uses. It does not measure the risk of what is built around the model. Yet it is there, precisely, that dependence is constituted. The legislator treated openness as a property of the product. Composition makes of it a trajectory of the organisation.
What the law presupposes: an identifiable supplier
One will object that other bodies of rules exist to grasp technological dependence. That is correct. All rest on the same presupposition.
Regulation (EU) 2022/2554, known as DORA, is the most accomplished mechanism for mastering third-party technological risk. Its Article 3 defines the third-party ICT service provider; its Articles 28 to 44 organise the oversight of critical providers; its Article 28(8) requires financial entities to have exit strategies for services supporting critical or important functions; its Article 30 enumerates the clauses contracts must contain. Every mesh of this net presupposes a contractual relation with an identifiable provider. An open weight model, downloaded then self-hosted by the entity itself, meets none of these meshes: there is no provider, no contract, no service supplied. The exit strategy loses its object when there is no one to exit from. The mandatory clauses have no counterparty on whom to impose themselves.
The duty of vigilance proceeds from the same grammar. The French law of 27 March 2017 and Directive (EU) 2024/1760 reason by supplier chains and commercial relations: links are mapped, partners identified, flows traced upstream. A dependence without a commercial relation appears on no mapping, because there is no relation to map. Regulation (EU) 2024/2847 on cyber-resilience pushes the logic as far as creating a new figure, the open-source software steward, in order to apply to it a lightened regime and exempt it from fines: there again, openness calls for gentler treatment, never more attentive treatment.
As for the supervisory authorities, none, to date, conceives of dependence on a self-hosted open model as an autonomous category of risk. When the European Central Bank worries about a concentration, it targets the large providers of proprietary models; when supervisors list the remedies, they cite contractual clauses and service-level agreements; when the French cybersecurity agency recommends, the self-hosting of an open model figures among the measures of mastery. Everywhere, openness is the solution. Nowhere is it questioned as the new form of the problem.
What litigation reveals
Competition law has, however, already encountered dependences built on gratuity. Each time, it held by a single thread, and that thread was a contract.
In the Android case, the European Commission, followed in essence by the General Court of the Union in 2022, grasped the dependence built on an open and free operating system. But it grasped it only by means of the contractual arrangement imposed on manufacturers, pre-installation agreements, anti-fragmentation obligations, exclusivity payments, and a characterised dominant position. Remove the arrangement and the dominant: the analysis has no more purchase. In the CUDA ecosystem, dependence proceeds from free software backed by proprietary hardware; it is through the hardware and the dominance that the authorities investigate it. In enterprise-software litigation, the SAP v Diageo case decided in London in 2017 priced at more than fifty million pounds the cost of indirect access: the dependence there was lodged entirely in a proprietary licence and its definitions.
A contract, a licence, a dominant: such are the three points of purchase available to the law for qualifying enclosure. The open weight model, composed by the user, offers none. There is no contractual arrangement, since there is no contract. There is no proprietary licence, since the licence is free. There is not necessarily a dominant supplier, since the lock would hold even if the model's publisher disappeared. The categories are not badly applied. They are without object.
The lock built from within
What these categories miss must then be named.
The lock is no longer set by the supplier. It is built, piece by piece, by the user itself. Each agent added, each evaluation validated, each procedure backed onto the behaviour of a model increases two magnitudes at once: the value of the whole and its irreversibility. It is the same gesture that produces the one and the other. Composition does not have dependence as its hidden price; it has it as its reverse face. An organisation that composes becomes more capable and less reversible, in the same movement, and no moment presents itself at which it would have consented to the enclosure, because no separate act ever constituted it.
This is why the notions inherited from the nineteen-nineties, vendor lock-in, switching costs, describe the phenomenon poorly. They presuppose an encloser and an enclosed. Here, the two figures coincide. The organisation is free at every moment and enclosed at the end; free in law, held in fact; and what holds it is its own patrimony, that is, what it would have the least reason to destroy.
The law's blind spot can then be formulated exactly. Positive law knows how to reason about dependence when it has an author: a contract to review, a licence to interpret, a dominant to discipline. It does not know how to reason about reversibility as a capacity proper to the organisation, that of recomposing itself after having accumulated. It presumed that openness guaranteed this capacity, because it guarantees access, modification and redistribution. But reversibility is not a property of the licence. It is a state of the organisation, and that state degrades in the very measure that composition enriches. A perfectly open architecture can become practically irreversible, by the sole fact of what has been built upon it.
The question boards of directors believe they are settling when they choose a family of models is a technical and reversible question. The question they actually settle is that of a trajectory: the way the organisation will produce, evaluate and transmit its work for the years in which composition will have done its work. The law does not warn them, because it looks elsewhere: it inspects the model, and the model is beyond reproach.
Closing
The question is not who owns the models, nor whether the open should be preferred to the closed. It is what becomes of an organisation's mastery when dependence ceases to have an author. As long as the lock had a setter, the law could summon it to account. The lock that is coming has no setter. It has a builder, and that builder is the very one it encloses.
Openness guarantees access. It has never guaranteed return.
Canonical version: www.delex-consortium.org/en/positions/who-set-the-lock