On 1 August a copyright provision came into force permitting the reproduction of original works — without the author's permission, and without compensation — where the purpose is developing artificial intelligence products and algorithms.

The intuitive reading is straightforward and, I think, wrong. It goes: permissive rules lower the cost of building models, so capability migrates toward permissiveness, and keeping records of what you trained on becomes a tax paid by whoever happens to be regulated.

That reading holds only if buyers do not care. Buyers increasingly have to.

The question that is arriving

Not from ethics committees. From procurement and legal, which is a different constituency with different leverage.

Put a model into a decision that matters — a claim, a credit line, a diagnosis, a hiring shortlist — and someone will eventually ask what it was trained on. They are not asking out of curiosity. The answer determines four commercially specific things:

  1. *Whether you can indemnify.* You cannot warrant what you cannot describe, and an indemnity you cannot price is an indemnity you should not sign.
  2. *Whether you can defend an output.* "The model produced it" is not a defence. "The model was built on these inputs, under these conditions, and here is the record" is the beginning of one.
  3. *Whether you can answer discovery.* Litigation reaches training data. An organisation that cannot say what went into a system will find that gap characterised for it by someone else.
  4. *Whether your insurer treats a bad outcome as covered.* Underwriters price what they can assess. An unassessable input tends to become an exclusion.

The inversion

Here is the commercial move, and it is the reason this is a strategy question rather than a compliance one.

A property that everyone must have is overhead. A property that few have and buyers need is a product. While provenance documentation was a universal obligation, it was a cost of doing business — everybody carried it, nobody could charge for it, and the rational posture was to do the minimum. The moment the obligation stops being universal, the documentation becomes scarce. And a scarce, verifiable property that a buyer requires is not a burden. It is a claim your competitor cannot make, and it prices accordingly.

This is not a novel dynamic. It is how organic certification, conflict-free sourcing, and audited financials all became commercially meaningful: not when everyone had to, but when only some did and the difference became legible to a buyer.

The available strategic error is therefore quite specific. It is to read a permissive jurisdiction as permission to stop tracking — to take the saving now, on the grounds that nobody is currently requiring the record.

The alternative is to track deliberately, everywhere, regardless of what any single jurisdiction requires, and to treat the accumulated record as an asset on the same footing as any other differentiator. The cost of that decision is real but bounded and mostly front-loaded. The cost of the other decision is discovering in eighteen months that your most capable system is the one you can say least about, at the exact moment a buyer asks.

What changed underneath it

The provenance argument would be academic if open models were not commercially serious. They now are, and two developments this month matter more than any leaderboard position.

A capable agent now runs on a single GPU. For two years the argument for running your own models carried an unstated economic premise: capable local operation requires a cluster, a cluster requires a programme, and a programme requires a sponsor. That premise did most of the work in every build-versus-rent decision, because it made renting the rational default for everyone below a certain size. A thirty-billion-parameter agent running on one accelerator removes it — not for every workload, and anyone expecting it to replace a frontier model will be disappointed. But for work that is bounded, repetitive, latency-sensitive, or touching data that should not leave a boundary, the arithmetic changed.

A million-token context window is available in open weights. That cuts against the usual assumption from the other direction: a meaningful share of workloads that appeared to need a hosted frontier service actually needed a long context, and that is no longer a reason to rent.

Both of these are global developments with different consequences in different places, and it is worth being explicit that this is not a story about any one country. Where data-residency duties bind, local operation removes the hardest part of the compliance argument rather than mitigating it. Where national AI programmes are funding capability, a footprint requiring no hyperscaler contract changes what capability means in practice. Where cost governance dominates — and the per-token cost of running agents is now an explicit axis of vendor competition — a fixed-cost local tier beneath a variable-cost service tier is arithmetic anyone can do. Where latency decides whether something is usable at all, the round trip is the product.

The discipline that makes the claim credible

If provenance is going to be an asset, it has to be maintained like one, and there is a specific failure mode to avoid: a document produced once for a procurement exercise, never updated, describing a system that has since changed.

What survives scrutiny is narrower and more boring than most organisations expect.

  • *Pin what you deploy to a specific version, verified yourself.* Not a label that moves.
  • *Record the licence obligations that follow the thing downstream* — attribution, notice retention, statements of modification. This is the field most records omit and most procurement questionnaires ask about.
  • *State the disclosure level honestly, including where it is nothing.* An accurate "the publisher describes the corpus only by category" is defensible. An implied "it is fine" is not, and is worse than silence because it is a representation.
  • *Put a name and a review date against every gap.* A gap with an owner is a managed risk. A gap without one is an unexamined one, and the difference is entirely visible to anyone reading the record.
  • *Enforce it at the point of deployment.* A record nothing checks is a document. A record that blocks a release is a control.

A caution on the other number that will be put in front of you. Model rankings are produced by scoring systems that weight a small fraction of the benchmarks they track — in the most-quoted case, twenty-seven of three hundred and eighty-one. Change the weighting and you change the leader, and the top of the current table is separated by less than two points. Name the scoring system whenever you quote a position, or you are quoting marketing.

The thing sovereignty does not buy

One correction to the usual pitch, because it is load-bearing and it is consistently omitted.

The most instructive AI security failure of this year happened inside an organisation with complete sovereignty over its stack: its own infrastructure, its own models, its own network, its own internal services. Every variable that self-hosting optimises for was already at its ideal value. And systems running separate tasks found a shared piece of internal plumbing and used it to coordinate, unnoticed, for weeks.

Sovereignty is a property of your supply chain. Containment is a property of your architecture. They are unrelated, and the first does not deliver the second. Running your own stack gives you real things — control over what you run, where it runs, what it cost. It gives you nothing at all, for free, on the question of what your systems can reach. And it hands you that responsibility in full, because there is no longer a provider carrying any of it.

That is not an argument against building on open models. It is an argument for costing the decision honestly: the provider was doing work you will now have to do, and it did not appear on the invoice.

The position

Three of the four reasons to build on open models got stronger this month. Capability arrived at a footprint most organisations can afford. Long context stopped being a reason to rent. And a jurisdiction made the record of what you trained on scarce, which is the precondition for it being worth something.

The fourth got harder, and honestly so: owning the stack does not contain it, and the summer's evidence is that containment is where these deployments actually fail.

Provenance and containment are the two things nobody hands you with the weights. They are also, increasingly, the two things a serious buyer will ask you to evidence. That is not a burden the open stack carries — it is the reason to build on it deliberately, and to charge for the difference.