Meta's policy on securing model weights is embarrassingly weak.
They say they will take steps to secure the weights of models that could have “large-scale, devastating, and potentially irreversible harmful impacts on humanity” ... but only when doing so is “commercially practicable.”

Analysis originally shared on Twitter/X
Meta’s policy on securing frontier model weights, in addition to being potentially out of compliance with state laws, has a pretty wild disclaimer:
They say they will take steps to secure the weights of models that could have “large-scale, devastating, and potentially irreversible harmful impacts on humanity” ... but only when doing so is “commercially practicable.”
What?

California’s SB 53 requires that Meta’s safety framework describe its “cybersecurity practices to secure unreleased model weights from unauthorized modification or transfer by internal or external parties.” Most other safety mechanisms rely on this one; you can't ensure effective safeguards if a model's weights have been stolen.

Meta’s policy does not include any specific security practices. It commits to unspecified “processes” to meet a “baseline of controls” for its models in general.
Your guess of what that entails is as good as ours.

What about for critical-risk models, which Meta defines as those that could have “large-scale, devastating, and potentially irreversible harmful impacts on humanity”? Surely more detail is justified here?
For these models, Meta promises “heightened access controls” but only “insofar as is technically feasible and commercially practicable.”
You don’t normally hear tech companies admitting that they will only avert “irreversible harm” if it doesn’t impact their bottom line.

To their credit, Meta does say a bit more about model weight security in their Muse Spark Safety & Preparedness report. Why not add these commitments to their safety framework? Insofar as this only exists in accessory documents, they are under no obligation to notify California if and when they decide to abandon these (and even under the current wording, maybe they wouldn’t need to notify insofar as they deem these to not be “commercially practicable”)

Research, updates, and insights from the frontlines of AI accountability.
We lead strategic initiatives to monitor tech companies, counter corporate propaganda.
OpenAI wrote a safety framework for California. Its system cards are ignoring it.
OpenAI’s research is too important to be turned into propaganda
Anthropic's Long Term Benefit Trust has a revolving door problem

The Midas Project Joins Coalition Warning about xAI’s Track Record in light of SpaceX’s IPO
The Midas Project, alongside a coalition including Encode, Legal Advocates for Safe Science and Technology, and Guidelight AI Standards, released "xAI: The Unpriced Risk in SpaceX's IPO."
Frequently asked questions
Have more questions? Our team is happy to help, contact us.
We engage in a combination of research, outreach, and public advocacy to ensure that AI companies are meeting public expectations, and living up to their past promises, when it comes to ensuring responsible AI development and deployment.
The most important component of our work is helping to identify and disseminate industry best practices for AI development. We review technical literature, regulatory guidance, and case studies to distill concrete measures—such as frontier-model risk assessments, red-teaming requirements, audit regimes, and whistle-blower protections—and advocate for the most important voluntary steps that companies can take today to ensure they are acting responsible.
We also monitor whether companies follow their stated policies and industry norms. When evidence shows back-tracking or inadequate controls, we document these gaps and publicly press for corrective action—mobilizing employees, customers, and civil-society allies until the company adopts the necessary safeguards.
Finally, we publicize our research to help ensure the public is aware of how AI developers stack up on safety and responsibility. We release concise scorecards, incident analyses, and memos so that regulators, investors, and the wider public can see how individual developers perform on safety and responsibility.
Various AI experts including Nick Bostrom and Stuart Russell have compared the development of advanced AI to the myth of King Midas.
According to the legend, King Midas once asked a powerful satyr to make it so that whatever he touched instantly turned into gold. At first, he was thrilled with his new powers. But the King soon discovered that he couldn’t touch food, water, or even his family without instantly turning them to metal. In other words, the sudden attainment of an incredible power with insufficiently well-specified goals and safeguards led to a terrible tragedy.
Much like King Midas, tech companies are now eagerly pursuing incredible wealth and power by developing artificial intelligence, a technology that will change our world forever. But how will we know that it is designed in alignment with our collective human values? If we misspecify even a single goal or safeguard for these systems, how will we prevent them from causing an incredible catastrophe?
In the words of Stuart Russell, “If you continue on the current path, the better AI gets, the worse things get for us. For any given incorrectly stated objective, the better a system achieves that objective, the worse it is.”
The Midas Project is a nonprofit organization founded in early 2024 by Tyler Johnston. Our work is supported by a small core team and a wider base of volunteers and supporters. We are a nonprofit, tax-exempt, 501(c)(3) organization that relies on donations from the public.
No. One of our central values is a pro-technology attitude.
Progress in technology has improved lives for millions of people around the globe (after all, without it, we wouldn’t have penicillin, air conditioning, or the internet). Artificial intelligence is already being used by millions to help improve medicine, education, and overall living standards. We believe this progress should continue, and we hope AI will be a positive force in the world.
However, we are also realists — and skeptical realists at that. We believe advanced AI systems may be a “dual-use” technology that can be used for harm as well. In order to avert social inequality, concentration of power, or AI-driven catastrophes, everybody needs to have a voice at the table when decisions about development and deployment are being made.
Currently, the vast majority of these decisions about the future of AI are being made in shadowy corporate boardrooms with little oversight and accountability. That’s why The Midas Project is committed to raising awareness about the risks of AI, and ensuring that global citizens are given a chance to make their voice heard.
If you’d like to get involved, consider signing up for our newsletter, joining as an official volunteer, or making a charitable donation today.
You can email us at info@themidasproject.com, or reach out via the form on our contact page.