Two words decide whether a Fortune 500 legal department will approve an open-weight model: "AS IS." The open-weight argument built around everything else is elegant. The models are free. The benchmarks are closing. The inference costs are 2% to 10% of API pricing. Fine-tuning lets an enterprise build on its own data, and the community moves faster than any single lab. The argument is compelling, well-sourced, and widely endorsed by people who have never had to explain to a board why the company deployed a model that produced a hallucination costing real money, then discovered there was nobody to sue.

Meta's Llama 4 license states: "THE LLAMA MATERIALS AND ANY OUTPUT AND RESULTS THEREFROM ARE PROVIDED ON AN 'AS IS' BASIS, WITHOUT ANY WARRANTY OF ANY KIND." Source Not "limited warranty." Not "best efforts." The words "AS IS" are in all caps because the lawyers who drafted the license wanted to leave zero room for interpretive ambiguity. Meta disclaims all warranties, express and implied, and the license also requires the enterprise to indemnify Meta: if the model does something that gets Meta sued, the enterprise pays Meta's legal bills. The indemnification runs one direction, and it is the opposite of the direction the enterprise wants.

OpenAI's service terms, by contrast, include explicit indemnification obligations to API customers for third-party claims arising from the customer's use of OpenAI's services Source. OpenAI's Copyright Shield, announced in late 2023, provides IP indemnification for ChatGPT Enterprise and API customers: OpenAI will defend and pay settlements for copyright claims against customers using its models Source. Anthropic maintains SOC 2 certification, enterprise DPAs, and a trust center with compliance artifacts Source. The comparison concerns legal architecture rather than model quality. One side has built one, and the other side's maximum legal commitment is good luck.

The DeepSeek situation makes this concrete, and it is the kind of exposure that a risk committee is paid to catch before procurement signs anything. DeepSeek's privacy policy gives the company broad rights to exploit user data collected through prompts Source. The company transfers personal data to "Chinese data processors" and stores it on servers in China, where there is no EU adequacy decision and where Chinese law requires companies to cooperate with state data access requests Source. Multiple European data protection authorities have opened investigations. Privacy assessments describe the service as unsuitable "for processing personal data, protected health information, or confidential business data in 2026" Source. DeepSeek V4-Pro may match Claude on coding benchmarks, and it also exposes any enterprise that deploys it to data export liability that most Western corporate counsel would classify as unacceptable risk.

The Fortune 500 general counsel does not care about MMLU scores. She cares about two questions: if a model produces a hallucination that costs the company money, who gets sued, and does deploying it create regulatory exposure that exceeds the cost savings. The answers for open-weight models run "nobody" and "it depends on which model and which jurisdiction, and the answer might be yes."

AI hallucinations are costing businesses an estimated $67.4 billion per year Source. A small but growing market for generative AI liability insurance has emerged, offering coverage for claims stemming from hallucinated content or errors Source. An insurance market forming around a specific risk is evidence the risk is real and the losses are being tracked. The enterprise that deploys an open-weight model with zero warranty coverage is self-insuring against a risk class that other enterprises are paying real premiums to transfer to someone else.

The closed-weight labs understand this is their real moat. Model capability is converging, and open-weight inference is cheaper at any meaningful scale, so the moat is the piece of paper that says: if the model breaks the customer's business, there is a balance sheet on the other end that can be sued. OpenAI has raised tens of billions of dollars at valuations that imply the company will exist for decades. Anthropic has Amazon and Google as backers. When a model from one of these companies produces a hallucination that costs a Fortune 500 company $10 million, there is a legal entity to pursue, an indemnification clause to invoke, and a settlement process with precedent behind it.

When a self-hosted Llama 4 model produces the same hallucination, the enterprise's remedy amounts to nothing.

No slower response time, no degraded experience, just the license's "AS IS" and a legal team explaining that the company downloaded a free model from the internet and deployed it in production. The board asks who approved that. The answer to that question is a career-ending conversation.

The benchmark gap is closing. The cost gap has already inverted. The liability gap traces back to who bears the risk when a non-deterministic system produces a wrong answer in a high-stakes context, and that allocation is structural rather than incidental. The open-weight community can ship better models every quarter. It cannot ship a legal entity with a treasury department that writes settlement checks, and that gap does not close with more GPUs.

The open-weight argument wins on benchmarks and cost and loses on the variable the Fortune 500 procurement process weights highest: who pays when it breaks. The general counsel reading the Llama license does not see a faster model at lower cost. She sees unlimited downside risk with zero contractual protection. The model could be Claude at half the price and she would still decline, because her job is not to deploy the best model but to make sure her company does not deploy one that becomes a lawsuit with no defendant — two words, all caps, no warranty.