Meta's policy on securing model weights is embarrassingly weak.

They say they will take steps to secure the weights of models that could have “large-scale, devastating, and potentially irreversible harmful impacts on humanity” ... but only when doing so is “commercially practicable.”

Quick Takes
Aug 26, 2026

Analysis originally shared on Twitter/X

Meta’s policy on securing frontier model weights, in addition to being potentially out of compliance with state laws, has a pretty wild disclaimer:

They say they will take steps to secure the weights of models that could have “large-scale, devastating, and potentially irreversible harmful impacts on humanity” ... but only when doing so is “commercially practicable.” 

What?

California’s SB 53 requires that Meta’s safety framework describe its “cybersecurity practices to secure unreleased model weights from unauthorized modification or transfer by internal or external parties.” Most other safety mechanisms rely on this one; you can't ensure effective safeguards if a model's weights have been stolen.

Meta’s policy does not include any specific security practices. It commits to unspecified “processes” to meet a “baseline of controls” for its models in general. 

Your guess of what that entails is as good as ours.

What about for critical-risk models, which Meta defines as those that could have “large-scale, devastating, and potentially irreversible harmful impacts on humanity”? Surely more detail is justified here?

For these models, Meta promises “heightened access controls” but only “insofar as is technically feasible and commercially practicable.” 

You don’t normally hear tech companies admitting that they will only avert “irreversible harm” if it doesn’t impact their bottom line.

To their credit, Meta does say a bit more about model weight security in their Muse Spark Safety & Preparedness report. Why not add these commitments to their safety framework? Insofar as this only exists in accessory documents, they are under no obligation to notify California if and when they decide to abandon these (and even under the current wording, maybe they wouldn’t need to notify insofar as they deem these to not be “commercially practicable”)

Research, updates, and insights from the frontlines of AI accountability.

We lead strategic initiatives to monitor tech companies, counter corporate propaganda.

Announcement
May 19, 2026

The Midas Project Joins Coalition Warning about xAI’s Track Record in light of SpaceX’s IPO

The Midas Project, alongside a coalition including Encode, Legal Advocates for Safe Science and Technology, and Guidelight AI Standards, released "xAI: The Unpriced Risk in SpaceX's IPO."

Frequently asked questions

Have more questions? Our team is happy to help, contact us.

What does The Midas Project do?
What does your name mean?
Who is behind The Midas Project?
Are you anti-AI?
How can I contribute?
How can I get in touch?