September 30, 2026

The Anatomy of Private AI, Part 1: What a Model Actually Is

Before you can judge whether open-weight AI is private, you have to know what a model physically is. This page carries a complete, working language model you can inspect, run, and corrupt. It has 729 weights. The ones you'd deploy have trillions, and work the same way.

Say "open-source AI" to a room of partners or portfolio managers, and someone hears "client data ends up in public." The confusion is understandable: in software, open source means the code anyone can read, and people reasonably assume the openness points at their information too. It points the other way. Open means you can see and hold the model. Your data is exactly as private as wherever you choose to run it.

This is the first of three short explainers making that concrete. Today: what a model physically is, with a real one embedded in this page for you to poke at. Part 2 follows the question that actually matters, who can read what you type. Part 3 walks the security case for owning the whole perimeter.

What's in the box

Every modern AI model is two things. The first is the architecture: code describing how to do the arithmetic, and not much of it; the core of a transformer fits in a few hundred lines. The second is the weights: an enormous list of numbers that the training process tuned, saved to disk as a file. The architecture is the recipe; the weights are the cake.

The file is big but it is just a file. Meta's Muse Glimmer has about 30 billion weights;2 at two bytes per number that's roughly 60 GB, a large download and a small hard drive. Kimi's K3, the strongest open model you can download, has 2.8 trillion;1 the same arithmetic puts it near 5.6 TB. Nothing about either file runs, listens, or transmits. A model at rest is as inert as a spreadsheet.

Claims like that are easy to write and easy to doubt, so instead of asking you to believe it, this page carries a model you can hold in one glance.

A complete language model, on this page

The grid below is not a picture of a model. It is one: a complete, working language model with 729 weights, trained in your browser the moment the page loaded, from thirty sentences embedded in the page itself. Each cell holds one number: how likely one letter is to follow another. That's the entire machine.

Fig. 1
The lab

A language model with 729 weights

Type to light up the weights your words use. Let it write. Then break it.

The entire model · 27×27 = 729 weights
abcdefghijklmnopqrstuvwxyz␣abcdefghijklmnopqrstuvwxyz␣
Click any cell to read one weight.
the model’s guess for the next letter:
n
18.1%
␣
13.5%
t
11.1%
r
8.8%
i
6.4%
Damaged cells turn rust. Generate again and watch the writing fall apart — the behaviour lives entirely in the numbers.
This model: 729 weights, about 2.9 KB as a file. Muse Glimmer: ~30 billion weights, roughly 60 GB. Kimi K3: 2.8 trillion, near 5.6 TB. Same idea, same inertness, more numbers.
Trains and runs entirely in your browser from text embedded in this page; nothing is fetched, stored, or sent.
A live model, not a diagram. The matrix is every weight; the amber trail is the path your typing takes through them; the slider overwrites weights with noise. Reload to restore it.

Three things to try, in order. First, type a few words and watch the amber trail: those are the exact weights your sentence touches, and the bars underneath are the model's live guess at your next letter. Second, press the write button and let the matrix babble; it produces plausible half-English because plausible half-English is what 729 numbers can encode. Third, drag the corruption slider and generate again. The writing decays into static in direct proportion to the damage, because there is nowhere else the behaviour could live. No lookup, no service, no mind. Numbers in, numbers out.

And note what did not happen while you played: nothing left this page. The model answered you because arithmetic ran near the numbers, not because your keystrokes traveled to the numbers' maker.

So what is a weight, then

A weight is one learned number: a tiny statement of preference, like "after the letter t, lean toward h." Training is the process of nudging billions of those preferences until the file, taken together, can continue text usefully. The models you'd actually deploy differ from this toy in scale and sophistication, their weights encode preferences over concepts rather than letter pairs, but not in kind. A model is the frozen result of training: a file of numbers that arithmetic runs through.

Frozen matters. The weights were set during training, before you ever downloaded the file, and answering a question doesn't change them; you watched that here, the matrix sat still no matter what you typed. What a model "knows" about your business after answering a thousand of your questions is precisely what it knew before: nothing. Where your questions travel on their way to the arithmetic is a separate issue, and it's the entire subject of Part 2.

"Open" comes in four strengths

Once you know the model is a file, "open" stops being a vibe and becomes a question with a checkable answer: which artifacts do they hand you, and under what license?

Fig. 2
The spectrum

Four strengths of open

The file is published. You can download, inspect, and self-host it. The license decides what you may build on it, so read it.

You get
· The weights file
· Self-hosting rights per license
You don’t
· Training code or data
· Always-permissive terms
For example
Kimi K3 — bespoke license with revenue and attribution clauses
Muse Glimmer 30B — plain Apache 2.0, no usage caps
Kimi K3 license per Moonshot (Jul 2026); Muse Glimmer per Meta (Aug 2026); Mistral Large 3 per Mistral (Dec 2025); OLMo 3 per Ai2.
The spectrum, with current examples at each stop. Licenses are the fine print of openness: two models can both be 'open-weight' and carry very different terms.

The practical reading for a buyer: anything from "open-weight" rightward can live entirely inside your walls. The license column is where diligence happens, and the spread is real, K3's bespoke terms ask for a negotiation above certain revenue, while Muse and Mistral ship under plain Apache 2.0 with no caps.123 Ai2's OLMo goes furthest and publishes the recipe itself.4

What this buys you

Here's the asymmetry that the rest of this series builds on. An API-only model obliges your data to travel; that's not a criticism, it's geometry, the arithmetic happens where the weights are. An open-weight file inverts the geometry: the arithmetic comes to your data. A file on your server, in your rack or your tenancy, has no channel home; it can't phone anyone because there is no phone in it, as you just verified at small scale.

Honest limits, before the next installment oversells itself: the weights file is the easy part. Running it well takes a serving stack, patches, evaluations, and monitoring, and that operational layer, not the model, is where real security work lives. That's Part 3. And openness of weights isn't openness of recipe; only the far end of the spectrum shows you the training data. What the file guarantees is narrower and, for privacy, decisive: the model is an object you possess, not a counterparty you talk to.

Key takeaways

  • 01A model is architecture plus weights, and the weights are just a file: 60 GB for a 30B model, inert until arithmetic runs through it.
  • 02This page carries a working 729-weight language model; every capability it has, you can see as numbers, and corrupting the numbers destroys the behaviour.
  • 03Weights are frozen at training time. Answering questions does not change them, and it never teaches the file your business.
  • 04From open-weight rightward on the spectrum, the model can live entirely inside your walls; the license, which varies widely, is where diligence belongs.

Sources

  1. Tom's Hardware, "Moonshot AI releases weights for Kimi-K3" (July 2026): https://www.tomshardware.com/tech-industry/artificial-intelligence/moonshot-ai-releases-weights-for-kimi-k3-firing-a-shot-across-the-bow-of-openai-and-anthropic-open-weight-model-performs-almost-as-well-as-frontier-models-while-being-2-3x-easier-to-run
  2. Meta AI Research, "Introducing Muse Glimmer" (August 2026): https://research.meta.ai/blog/introducing-muse-glimmer-open-agentic-model
  3. The Register, "French AI shop Mistral rolls out full suite of Apache-licensed models" (December 2025): https://www.theregister.com/2025/12/02/mistral_3/
  4. Ai2, OLMo 3 release notes: https://allenai.org/blog/olmo3
  5. Interconnects, "Kimi K3: the open-weights escalation" (2026): https://www.interconnects.ai/p/kimi-k3-the-open-weights-escalation