610 gigabytes of openness

On 2 August, within roughly the same hour, the transparency obligations of the European AI Act and those of California’s synthetic-content provenance law came into force. That same week, the numbers were published showing how much memory, in gigabytes, it takes to hold up the most capable open-weight model in existence. The two things answer the same question from opposite ends: what good is it for something to be available if the capacity to use it is unevenly distributed. “Open,” this week, turned out to be an adjective with several owners.
Governance
Article 50 of the AI Act has been enforceable since 2 August: you must disclose when someone is interacting with an AI system, mark much AI-generated content in machine-readable form, and explicitly label deepfakes and synthetic text on matters of public interest, with fines of up to €15 million or 3% of worldwide turnover. Two details usually lost in the coverage: enforcement rests principally with each member state’s national market surveillance authorities rather than with the AI Office, and systems already on the market have until 2 December for the marking and detection requirements. California timed its own date deliberately: SB 942, as amended by AB 853, became operative on exactly the same day, requiring generative providers with more than a million monthly users in the state to offer a free provenance-verification tool.
In Washington, that same week, the administration finalised with the companies a voluntary framework granting the federal government up to thirty days of access to frontier models before they are available to anyone else, with the stated purpose of assessing their cyberattack capabilities. Two features of the framework matter more than the framework itself: its text was not made public, and it defines a “covered frontier model” as closed-source, so open models are explicitly left out. Meanwhile the same government is running an offensive against the state regulatory patchwork —a litigation task force at the Department of Justice dedicated to challenging state AI laws, with federal funding used as leverage against states that enforce them— alongside an earlier order instructing agencies to deprioritise disparate-impact liability. So we are not looking at two transparency regimes of differing stringency. We are looking at two different things sharing a name: one compels disclosure toward everyone, the other grants privileged access to one party. Seen from the South, the Brussels effect arrives as a compliance cost without a seat at the table where the rule was written; and whatever security knowledge that early access produces will not be a common good, because not even the procedure that produces it was published.
Epistemic commons
Anthropic began marking Claude’s outputs: an imperceptible signal embedded in the text of new models, and signed provenance metadata following the C2PA standard in generated files. It does so worldwide, not only for European users —European compliance delivered globally, which is precisely what the Brussels effect describes. Suno committed to the same for audio. This is the right move and it deserves to be said without irony: marking is the expensive part, and they are paying for it.
The problem appears on the other side of the gesture. The tools that would let anyone detect those marks are still being built, and the company itself clarifies that a positive result would indicate that Claude processed the content, not that it wrote it: someone may have asked it to translate, summarise or proofread a human text. The free tool that is actually mandatory —the Californian one— is mandatory of a large provider and for the benefit of a user in California. So the mark is planetary and the verification is jurisdictional. Provenance is not a property of the file, it is an infrastructure: a marked file in a world without accessible detectors does not inform, it asks for faith. And the capacity to doubt —to submit an image, an audio file or an expert report to verification before accepting it— ends up distributed along the same old geography. It is an unusual kind of enclosure, because what it fences off is not the resource but the faculty of examining it.1

Care for the commons
Here are the numbers. Moonshot AI’s Kimi K3 remains the most capable open-weight generalist model: 2.8 trillion parameters in a mixture-of-experts architecture, 104 billion active per token, 896 experts of which 16 are selected, a one-million-token context window. At full precision it takes 1.56 TB. Unsloth published the quantization table and it repays a slow reading: the two-bit variant weighs 711 GB and retains 84.1% accuracy; the one-bit variant drops to 594 GB at 78.9%, and running it requires 610 GB of memory. That is the entry price to the world’s most powerful open model. And it is not free software: it was released under Moonshot’s own licence, open-weight but not OSI-approved. Z.ai’s GLM-5.2 does carry a genuine MIT licence —744 billion parameters, some 40 billion active, also a million tokens of context— which improves the legal problem without moving the material one by a millimetre.
The counterpoint arrived on 10 August, and it is the best thing about the week. Meta Superintelligence Labs released Muse Glimmer: 30 billion parameters, multimodal, over 128K of context, Apache 2.0, running on a single 24 GB GPU, with Ollama support from day one. That does fit inside a university lab in Rosario, in Nairobi or in Manila. And here is the irony that organises the whole week: it is exactly the model the US security framework decided not to examine, because its definition of a covered frontier model excludes what is open. The one a state can audit for thirty days is the one nobody else can install; the one anyone can install is the one nobody offered to audit.
It is worth taking the word apart, then. “Open” names at least three distinct things —a licence that permits, weights that are available, and a material capacity to run them— and the Global South is included in the first two and excluded from the third. An available resource is not yet a governed resource, and a resource you cannot lift never quite becomes a resource at all.1
Education
For the first time in its history, UNAM held its undergraduate entrance exam entirely online, with 158,712 registered applicants and automated proctoring, largely in order to ease access from distant regions and from abroad. The results were statistically impossible: between 2021 and 2025, around 3.5% of applicants scored a hundred correct answers or more; in 2026 that share jumped to 16.3%. At the 110-correct threshold the anomaly is sharper still, from 0.9% to 5.5%, almost six times. Some three thousand exams were annulled, and the Technical Commission recommended something other than a blanket annulment: an in-person control exam for around 58,000 applicants, administered between 12 and 19 August. In parallel, in the United States, ghost student fraud —synthetic identities enrolling in order to siphon off financial aid— has reached figures that no longer admit the diminutive: 31.4% of applications to California’s community colleges in 2024 turned out to be fraudulent, with 1.2 million bogus applications and 223,000 enrolments confirmed as nonexistent across 116 campuses; there are some two hundred open investigations covering more than 350 million dollars, and from 1 October the federal aid form will be screened with real-time fraud detection.
It is the same verification failure with two opposite distributions of the cost. In the American case what is lost is public money and the state absorbs it; in the Mexican case what is lost is time and certainty, and it is absorbed by 58,000 people who overwhelmingly did nothing. The institution bought automated proctoring as a solution to a problem of distance and got back a problem of legitimacy, which is of another order and far more expensive: a massive public university cannot afford to have its mechanism for allocating places fall under suspicion. What followed deserves attention, because it is not a retreat in disguise. When digital verification failed, UNAM went back to the only infrastructure it actually controls —a room, a chair, a sheet of paper, a human invigilator— and with that it rebuilt trust in the process. It can be read as a technological defeat or as the discovery that the institution still held a capacity of its own that it had not subcontracted. The uncomfortable question is how many institutions in the South, after a decade of replacing processes with platforms, would still have something to go back to.
Public sector opportunities
The least-discussed news of the week is the most replicable. On 21 July, India’s CDSCO issued its final guidance on software as a medical device under the Medical Devices Rules of 2017: it classifies screening, clinical decision support and patient monitoring software into four risk tiers, and requires prior licensing, model bias assessment, cybersecurity documentation, clinical performance evaluation, and post-market surveillance specific to systems that update after deployment. The FDA, for its part, has reportedly issued its first enforcement letters under its own guidance in the field.
What is interesting about India is not the content of the rule but its strategy. It did not adopt the European AI Act, did not wait for the American position to settle, and above all did not try to create a national artificial-intelligence authority —that creature almost no state with a limited budget manages to staff with competent people. It used the sectoral regulator it already had, with the legal authority it already had, to demand of clinical AI exactly what it demands of any other device: that it document its failures and answer for them over time. This is polycentric governance in its least glamorous and most effective form: not a general framework ordering the whole domain, but the body that already knows about health risk applying its competence to a new object.2 For a state in the South weighing where to start, the transferable lesson is not the Indian text but the move: regulate from the health, finance or education regulator that already exists, instead of waiting until you have the institutional capacity to build a new one from scratch.
Closing
The week left two concrete objects, and neither is a metaphor: 610 gigabytes of memory, which is what it costs to hold the frontier of the open in your own hands, and a room with chairs, which is what a public university had left when its digital verification collapsed. Between the two sits a 24 GB model that does fit in any lab and that no government asked to examine. The question left open is not whether models will be open —several were this week, under better licences than last year’s— but who will be able to lift them, and what an institution does in the meantime with the little it still controls.
This week’s notes
Governance
- On Article 50 coming into force: note from Cooley, 3 August 2026, and the European Commission’s FAQ · open access
- On SB 942 as amended by AB 853: bill text and analysis from Troutman · open access
- On the federal voluntary framework: CNBC coverage, 3 August 2026; on its confidential character and the exclusion of open models, Axios and Axios, 4 August 2026 · open access
- On the federal offensive against state laws: analysis from White & Case · open access
Epistemic commons
- On the marking of Claude’s outputs: coverage from The Next Web and from Euronews, 11 August 2026 · open access
Care for the commons
- Kimi K3: model announcement, 16 July 2026. The quantization figures and memory requirements come from Unsloth’s documentation, which is the primary source for that data · open access
- GLM-5.2: VentureBeat coverage · open access
- Muse Glimmer: announcement on the Ollama blog and VentureBeat coverage, 10 August 2026 · open access
Education
- On the UNAM exam: La Jornada, 31 July 2026, on the Technical Commission’s recommendation; Latinus, 12 August, on the in-person exam being administered; El Universal on the regulatory gap, which is a separate angle and deserves its own discussion · open access, in Spanish
- On synthetic-identity fraud: EdTech Magazine, August 2026, and the ITIF report · open access
Public sector opportunities
- On the CDSCO’s final guidance: summary from Asia Actual and analysis in the National Law Review · open access
The distinction between an available resource and a governed one runs through Elinor Ostrom, Governing the Commons (1990). Her design principles presuppose something that neither open weights nor provenance marks provide on their own: collective-choice rules, monitoring capacity distributed among those who use the resource, and conflict-resolution mechanisms. A signed file without accessible detectors, and a freely licensed model that requires 610 GB of RAM, share the same structural defect: they are goods whose effective use depends on a capacity that does not come with the good. ↩︎ ↩︎
On polycentric governance, see Ostrom, “Beyond Markets and States: Polycentric Governance of Complex Economic Systems” (2010). The argument is not that fragmentation is good in itself, but that arrangements with multiple decision centres at different scales tend to adapt better than single-command structures, because each centre retains local knowledge about its own domain. The CDSCO does not know about artificial intelligence in general; it knows about clinical risk, and that is enough to demand of a model what is owed. ↩︎