Skip to content

Are open-source and open-weight AI models worth the risk?

July 22, 2026 – Published on IT Brew

For some companies, cheaper might be better when it comes to AI—as long as the right security measures are in place.

Organizations navigating AI implementation are already turning away from tokenmaxxing and trying to restrain their operating costs, especially with cutting-edge “frontier” models produced by Anthropic, OpenAI, and other AI giants. That creates an opening for Chinese tech companies like Moonshot AI and Z.ai, which are offering open-weight and open-source alternatives that organizations can theoretically deploy at cheaper cost than the frontier models.

With open-weight AI models, the “weights” that govern the model’s interpretations of inputted data and how it responds are released to the public for downloading and customization. Open-source AI models, meanwhile, allow users to download and tweak everything, including source code and training data. Provided a company has the infrastructure to run these models, they can prove a less costly alternative to the companies charging per-token for AI usage.

However, Victor Wieczorek, SVP of offensive security at GuidePoint Security, told IT Brew that bad actors can inject malicious code into repositories for open-source and open-weight models, “poisoning” those models into altering their behavior or exposing vulnerabilities. Researchers and IT professionals “feeling the crunch” to implement AI might not do their due diligence of the model’s codebase until it’s too late.

“Because there’s now a desperate effort to either race to get this access to these technologies or to ensure that they are always going to have the influence that they want, it’s generating a lot of bad behavior of people moving too fast, not fully inspecting or thinking about the models or the harnesses, or artifacts they are pulling into their environments,” Wieczorek said.

Read More HERE.