Open-source AI models have come a remarkable way: from experiments in research labs to a serious option for businesses. If you run an open model on your own infrastructure or on infrastructure you have deliberately chosen, you decide for yourself where queries and documents are processed.
But “open” does not always mean the same thing. Some models release only their trained weights, others also their training data and code. And even the most open model is of little use as long as nobody has servers, updates and security under control.
We show how open source, open weights and proprietary models differ, what the Swiss model Apertus can do and what matters when it comes to running them. How language models work in principle is explained in our brief overview of AI.
Key facts at a glance
- Open-source AI models in the strict sense disclose their weights, code and information about the training data; open-weights models disclose only the trained weights.
- With Apertus, EPFL, ETH Zurich and CSCS have released a fully open language model, available as version 1.5 since 24 July 2026.
- Open models can be run on your own infrastructure or on infrastructure you commission, so you choose where processing takes place.
- The price of this freedom is operational effort: hardware, updates, security and quality checks.
- Before deploying a model, scrutinise its licence, its origin and how up to date it is.
Open-source AI models and open weights: the differences
Put simply, a language model consists of architecture, code and weights. The weights are billions of numerical values that emerge during training and determine the model’s answers. What matters is which of these parts you actually get to see.
Proprietary models: access through the provider
With proprietary models, the weights stay with the developer, and the model is used through an application or interface. That is convenient: the provider takes care of operation and further development. With international providers, the place of processing, the applicable law and the use of the content entered depend on the respective contractual terms.
Open weights: the finished model to download
Here the developer makes the trained weights available for download. Depending on the licence, you can run the model on your own servers and fine-tune it. According to the Open Source Initiative, however, the training code, the training dataset and detailed information on the composition of the data are missing. How the model came into being remains largely hidden.
Open source: weights, code and data information disclosed
The Open Source AI Definition, published by the Open Source Initiative in October 2024, raises the bar. An open-source AI model must be free to use, study, modify and share for any purpose. Besides the weights, this requires the complete code and data information detailed enough to build a substantially equivalent system.
In everyday language, models with open weights are often called open source too. Both can be run in-house, but for traceability the difference matters a great deal.
What open-source AI models can do today: Apertus as a Swiss example
The gap between open and closed models is tracked by Stanford University’s AI Index. After briefly narrowing in 2024, it widened again in 2025. In March 2026, the best closed model on the Arena Leaderboard was 3.3 per cent ahead of the best open one.
Apertus: open from the training data to the weights
On 2 September 2025, EPFL, ETH Zurich and the Swiss National Supercomputing Centre (CSCS) released Apertus. The name is Latin for “open” and a statement of intent: architecture, model weights, training data and methods are openly accessible and documented. The first version came in sizes of 8 and 70 billion parameters.
Apertus was trained on 15 trillion tokens from more than 1,000 languages, including Swiss German and Romansh. Forty per cent of the data is not in English. According to the press release, the data comes only from publicly available sources and was filtered to respect machine-readable opt-out requests from websites and to remove personal data.
Apertus 1.5: images, audio and compact variants
On 24 July 2026, Apertus 1.5 followed. Alongside text, it also understands images and audio, reasons better and handles tools better. In addition, there is Apertus Mini, a suite of 16 compact models for deployments with limited computing power.
The first version is already in use, for example in the Canton of Ticino: according to the ETH AI Center, an in-house service there uses Apertus to translate sensitive government documents.
Run open-source AI models yourself or have them run for you?
Downloading an open model is the easy part; running it reliably is an ongoing commitment. The Apertus press release makes the same point: practical use requires additional components such as servers, cloud infrastructure or user interfaces.
The advantage: control over data and versions
If the model runs on infrastructure that you control or have deliberately selected, you know where queries and documents are processed. You test new model versions before they go live. Our introductory article explains why this matters for data sovereignty.
The effort: hardware, operation, maintenance
Large models need powerful graphics processors with plenty of memory. On top of that come monitoring, security updates, access rights and specialists who know how to handle all of this. Compact variants such as Apertus Mini lower the barrier to entry, but they do not take the operation off your hands.
The third way: having open models run for you
Between running models in-house and using a proprietary service, there is a middle ground: a provider runs open models on its own servers in Switzerland. You know where processing takes place and do not have to procure graphics processors. Make sure you clarify who owns the servers and who has access.
Licence, security, updates: what to look out for with open-source AI models
Openness shifts responsibility: what the provider handles in a proprietary service is up to you when you run the model yourself. Four checkpoints help.
1. Read the licence before the model goes live
“Open” is not a licence. Only the terms of use determine whether and how you may use a model commercially. Apertus, for example, is released under the Apache License 2.0: it permits use without licence fees but, on redistribution, requires you to include the licence text and retain copyright notices.
In addition, an acceptable use policy from ETH Zurich and EPFL applies, covering liability and personal data, among other things. Document which terms apply where.
2. Check origin and integrity
Model files often come from public repositories. The OWASP Gen AI Security Project warns that pre-trained models can be tampered with and contain backdoors. It recommends using models from verifiable sources and checking their integrity with signatures and checksums.
3. Plan for updates
According to OWASP, a model that is no longer maintained is a security risk. Plan updates as you would for any software: monitor new versions, test them and roll them out in a controlled way. For Apertus, the development team has announced regular updates.
4. Test quality against your own use case
Leaderboards show averages, not your day-to-day work. Test candidates with your own tasks, documents and languages. Even when you run a model yourself, you are processing personal data as soon as you enter any. What applies then is explained in our article on AI and data protection.
Openness is a start, not an operating concept
Open-source AI models have become a real option for businesses. They create transparency and allow you to run them at a location of your choice. What matters is who runs, maintains and secures the infrastructure.
At BE BRAVE, we bring open models together with our own operations. EagleCHAT combines model variants fine-tuned by BE BRAVE with selected current open-source models. All models run on our own infrastructure in Switzerland. Your content is not used for training, fine-tuning or improving AI models.
If you want to deploy your own models, Swiss AI Hosting gives you Swiss AI computing power without having to build your own operation. We provide GPU capacity, networking and operations, and run them on our own servers in Switzerland.
FAQ
What are open-source AI models?
These are models that can be freely used, studied, modified and shared. In the strict sense, this means that code and information about the training data are open as well as the weights.
What is the difference between open source and open weights?
Open weights make only the trained weights available. Open source also discloses the training code and data information, so that you can trace how the model came into being.
Can businesses use Apertus?
In principle, yes. Apertus is released under the Apache 2.0 licence, which also permits commercial use; an acceptable use policy applies as well. For practical use, you also need servers and a suitable application.
Are open-source AI models more secure than proprietary models?
Not automatically. Openness makes it possible to scrutinise a model and run it under your own control, but security depends on origin, updates and operation.

