スタンフォード HAI、科学と社会のために真のオープンソース AI モデルを提唱
本文の状態
日本語全文を表示中
詳細モードで約11分の本文を読めます。
中国のオープンウェイトモデルが米国の性能に肉薄する中、スタンフォード HAI は単なる重みの公開ではなく、学習データやコードを含む真のオープンソース AI の必要性を提唱し、規制と競争力のバランスを問うている。
AI深層分析を開く2026年8月4日 18:34
AI深層分析
キーポイント
中国モデルの性能向上と米中格差の縮小
DeepSeek や Alibaba などの中国企業が開発した Moonshot AI の Kimi K3 や Qwen3.8-Max が、米国製モデルとの性能格差を数ポイントまで縮め、コストも抑えている。
米国の規制方針転換と中国への懸念
米国政府はイノベーション優先からセキュリティ重視へ転換し、Anthropic のモデル強制オフライン化事例のように、中国のオープンモデルにも同様の厳格な審査を適用する可能性を検討している。
企業連合による規制反対と競争力強調
Nvidia や Microsoft などの主要企業が共同声明を発表し、米政府に対し「早急な制限」に警告を発し、加熱するグローバル市場における競争力の維持を求めている。
真のオープンソース AI の定義と必要性
James Landay 氏は、単に重み(weights)を公開するだけでは不十分であり、学習データやトレーニングコード、動作原理が透明である「真のオープンソース」こそが科学と社会にとって不可欠であると指摘している。
Open-Weight と Open Source の決定的な違い
単に重みを公開するだけでは不十分であり、信頼性や改良のために訓練データやコードの完全な公開が必要である。
重要な引用
"Open weights are progress. You can download the model, run it on your own machine, keep it out of someone else's data pipeline. But you still can't see how the thing was built... That's not an open model. That's open distribution."
"The current U.S. administration has shifted from an 'innovation first' position to a more reactive one"
"There's a wide gap between open-weight AI and open source AI."
"A closed frontier model behind an API is the ultimate walled garden."
編集コメントを表示
編集コメント
中国の AI モデルが米国との格差を埋める速さは驚異的であり、これが米国の政策転換を招いた背景にある。しかし、技術的な性能だけでなく、学習プロセスの透明性を確保する「真のオープンソース」への定義の再考も同時に迫られている。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
中国のオープンウェイトモデルはここ数ヶ月で驚異的な進歩を遂げ、DeepSeek や Alibaba などの企業が提供する製品が、米国製モデルとの性能差を大幅に縮めています。スタンフォード大学 HAI が発表した AI インデックスによると、米中の性能差は昨年すでに数%ポイントまで狭まっていました。そして最近登場した 2 つの中国製モデルがこの格差をさらに縮小しています。
Moonshot AI の「Kimi K3」は 2.8 兆パラメータ(そのうち 2.4 兆が有効活用される)を持つ大規模モデルで、100 万トークンという超広大なコンテキストウィンドウを備えています。また Alibaba の「Qwen3.8-Max」も 2.4 兆パラメータを搭載しており、これらは現在最も強力なオープンウェイトモデルとして、米国最高峰のモデルに迫るランキングを獲得しています。これらの新モデルは、トップクラスの米国製 AI モデルよりも低コストで、オープンウェイト AI の性能を大きく向上させることを示しています。
一方、米国の政策担当者は最先端 AI がもたらすサイバーセキュリティや国家安全保障上のリスクにますます注目を集めています。現在の米国政権は「イノベーション最優先」の姿勢から、より消極的な対応へと転換しました。具体的には、新モデルの公開前に事前通知を義務付けるようになり、あるケースでは商務省の輸出管理命令により Anthropic に対し、Mythos 5 と Fable 5 を完全に運用停止させることを強要しています。
中国の研究機関が能力格差を埋めつつある現在、政権はこうした厳格な監視を中国製のオープンモデルにも適用すべきかどうかを検討しているところです。
この議論を受けて、Nvidia、Microsoft、Meta など 20 社以上の米企業は、「オープンウェイト AI モデルに対する早急な規制」に警告を発する公開書簡を共同で発表しました。彼らは、熾烈化するグローバル市場における競争力を維持するためには、こうしたモデルへの制限を控える必要があると強調しています。
スタンフォード大学人間中心 AI 研究所のデンニングディレクターであるジェームズ・ランドー氏は、この書簡が示す危機感自体は理解できます。しかし、その主張は本質的な課題にまで踏み込んでいないと考えています。
「オープンウェイト化は確かに前進です」とランドー氏は指摘します。「モデルをダウンロードして自社のマシンで実行し、他者のデータパイプラインから切り離せるのは事実です。しかし、そのモデルがどのように作られたのか、何を学習データとして使ったのか、なぜそのような挙動を示すのかを知ることはできません。それはオープンなモデルではありません。あくまで『配布』だけが開放されているに過ぎないのです」
科学と社会にとって真のオープンソース AI モデルの価値
「オープンソース AI」とは何かを定義するのは容易ではありません。フリーソフトウェア・オープンソースソフトウェアには確立された用語体系があり、ライセンスが権利を付与するか否かは明確です。しかし AI にはそのような合意がありません。なぜなら、AI の対象となる成果物はコードベースよりも広範だからです。それはソフトウェアと、学習用およびテスト用のデータ、そして学習済みのパラメータが一体化したものであり、それぞれの要素は独立してオープンにもクローズドにもなり得ます。ある企業が重み(ウェイト)だけを公開し、データやトレーニングコードを秘匿したままでも、「オープン」と称するケースがあるのはそのためです。
「オープン」と名乗ることには信頼性への期待が伴いますが、ランドジェイ氏は指摘します。実際には、外部者が検証や再現、批判を行うためには、企業がまずトレーニングデータを公開する必要があります。「重み(ウェイト)のみを公開する AI」と「オープンソース AI」の間には、大きな隔たりがあるのです。
スタンフォード HAI は明確な基準を設けています。それは Linux Foundation の「モデル開放性フレームワーク」における最高等級である「Open Science(オープンサイエンス)」クラスとの整合性です。つまり、コード、トレーニングデータ(またはその詳細で監査可能な記録)、そしてツール類がすべて公開されなければならないのです。単に重みだけを公開するだけでは不十分で、外部の研究者やコミュニティが実際にデータをダウンロードし、実行し、研究し、貢献し、改変できる具体的な手段も用意されている必要があります。
ランドジェイ氏によれば、これに満たない場合は、特定の研究領域そのものが閉ざされてしまいます。例えば、モデルのトレーニングデータがどのように文化的偏見を形成するかを研究したり、異なる人口集団に対する公平性を監査したり、本格的な新挙動が現れる規模で新しいアーキテクチャを検証したりすることはできなくなります。結果として、完成されたシステムを外部から観察するだけで、なぜそれがそのように動作するのかを推測するしかなくなってしまうのです。
ランドジェイは、現代 AI における主要なアーキテクチャの飛躍——トランスフォーマーそのもの、アテンション機構、そしてモイクス・オブ・エキスパートによるルーティングなど——のほとんどが、他の研究室や研究者が検証し、疑問を投げかけ、さらに発展させることができる公開研究から生まれたと付け加えます。画期的なイノベーションにはオープンサイエンスが不可欠です。最先端の研究がクローズド化すれば、次世代の研究者たちは限られた企業が開示した内容だけを基に改良を重ねるしかなくなります。
「オープンウェイトは『これを動かせるか?』という問いに答えるものです」とランドジェイは語ります。「一方、オープンソースは『これを信頼できるか、改善できるか、その上で次のものを構築できるか』という問いに応えるものです。現在、ほぼすべての機関——米国系も中国系も——が最初の問いには答えつつありますが、2 つ目の問いについてはまだ程遠い状況です」
クローズド AI のリスク
クローズドモデル(米国のものに限らず)は、その瞬間の安全性が低いとは限りませんが、集中に伴うリスクを孕んでいます。API を通じて最先端能力を少数の企業が支配することは、誰にアクセス権を与えるか、どの価格で提供するか、そして人々の働き方や思考 increasingly 仲介するツールにどのような価値観が組み込まれるかを決定するのも同じく少数の企業であるという事態を生みます。
この現象は、ユーザーにとって価値を生み出すプラットフォームが次第にその価値を収奪する方向へ転換していくという、よく知られたパターン——コリー・ドクターウーが「エンシチフィケーション」と呼ぶもの——へと繋がっていると彼は指摘します。
「API の向こう側に閉じ込められた Frontier モデルは、究極の囲い込み(ウォールドガーデン)です」と Landay は語ります。「データも、モデルとの履歴も、離脱するためのレバレッジも、ユーザーのものではありません。それがすでに現状です。」さらに彼は、ユーザーが一つの囲い込みの中に長く留まるほど、プラットフォーム側が蓄積する文脈や履歴が増え、結果として離脱コストが高まり、時間とともにロックインを解消するどころか強化されていくと指摘します。
ここにはセキュリティ上の問題もあります。閉じたモデルに依存すること自体が、必ずしも安全であるとは限りません。外部からは検知できない形で侵害されたり、悪用されたり、あるいは失敗したりするリスクがあるからです。Frontier の能力を少数の閉じたシステムに集中させることは、その盲点もまた集中させてしまうことを意味します。
閉じたモデルは、サービス対象となる世界の多様な価値観よりも狭い範囲の価値観のみを反映するリスクもあります。米国や中国にある限られた研究所が、自国のデータと言語、独自の前提に基づいて Frontier システムを訓練することは、ある一つの文化の世界観を、他者の日常生活に静かに浸透させるツールを生み出すことになります。
さらに、Frontier の能力が極めて少数の企業に、それも少数の国に集中しているため、戦略的なボトルネック(チョークポイント)にもなり得ます。Landay は、商務省の命令により Anthropic の最新モデルが利用不可になった事例を挙げ、閉じた Frontier AI へのアクセスが貿易紛争や輸出管理闘争において交渉材料としてあっという間に使われうることを示唆しました。その際、依存する人々がその狭間で巻き込まれることになります。
オープンなアプローチの定義
ランデイが提唱する解決策には、3 つの柱があります。
- 分散型 AI:自社サーバーやローカル環境で実行できる AI。他社への依存やレンタルに頼らない形です。
- データの可搬性:利用者のコンテキストやデータはプラットフォーム間を自由に移動でき、特定のサービスにロックインされないこと。
- 検証可能なエージェント:開発者、忠誠心、そして行動が実際に検証可能である AI。
しかし、基盤となるモデル自体が少数の企業によってクローズドな環境で構築されたままでは、これらの仕組みは機能しません。ランデイは、この格差を埋める役割を担うべきは、従来の製品開発とは異なる性質を持つ「大学」であると主張しています。学術機関には、商品サイクルよりも長いタイムラインへのコミットメントが可能であり、単に利用されるためではなく、検証可能な形で研究成果を発表できます。また、明確な収益化の道筋がなくても探究できる問いに取り組むことができます。彼らは、他人のブラックボックスへの API アクセスや代理モデルに頼るのではなく、最先端システムを自前で構築・研究するのです。
「未来が真の意味でオープンであるならば、リリース版にどの国の旗が掲げられているかは重要ではありません。どこにいても誰でもそれを検査し、適応させ、責任を追及できるからです」と彼は語ります。「もし『オープン』とは単に『ダウンロード可能』という意味だとしたら、私たちは閉鎖された研究所のセットを別のセットと入れ替えたに過ぎません。権力の集中は同じまま、旗が変わっただけです。明日の AI は、私たちにタスクを完遂させるだけでなく、『何が可能か』という概念そのものを形作っていくでしょう。問われるべきは決して『これを構築できるか?』ではありません。『私たちはどのような世界を築こうとしているのか?そこに誰の人権を刻み込もうとしているのか?』です。オープンウェイトモデルだけでは、この問いに答えられるわけではありません。科学と社会のための真のオープンソース AI が必要なのです。
原文を表示
Chinese open-weight models have made stunning progress in recent months, with offerings from companies like DeepSeek and Alibaba closing the performance gap with American counterparts. Stanford HAI’s own AI Index found the U.S.-China performance gap narrowing to a few percentage points last year. Two new Chinese models narrow this gap even more. Moonshot AI’s Kimi K3, a 2.8-trillion-parameter model with a million-token context window featuring 2.4 trillion parameters, and Alibaba’s Qwen3.8-Max, featuring 2.4 trillion parameters, are the most powerful open-weight models yet, edging closer in the rankings to the highest-performing American models. These new models demonstrate big improvements in open-weight AI performance while costing less than top-tier American AI models.
Meanwhile, U.S. policymakers are increasingly focused on the cybersecurity and national security risks posed by frontier AI. The current U.S. administration has shifted from an “innovation first” position to a more reactive one – requiring advance notice of new model releases, and, in one case, forcing Anthropic to take Mythos 5 and Fable 5 fully offline under a Commerce Department export-control order. With Chinese labs now closing the capability gap, the administration is weighing whether to extend that kind of scrutiny to Chinese open models as well.
The conversation has led to an American corporate response; Nvidia, Microsoft, Meta, and 20-plus other companies published an open letter warning Washington against “premature restrictions” on open-weight AI models, highlighting the need for competitiveness in a heated global market.
Stanford Institute for Human-Centered AI Denning Director James Landay agrees with the instinct behind that letter. He just thinks it stops short of the point.
“Open weights are progress,” he said. “You can download the model, run it on your own machine, keep it out of someone else’s data pipeline. But you still can’t see how the thing was built, what it was trained on, or why it behaves the way it does. That’s not an open model. That’s open *distribution*.”
The Value of Truly Open Source Models for Science and Society
Defining open source AI is complicated. Free and open source software has a settled vocabulary – a license either grants you the rights or it doesn’t. AI has no equivalent consensus, because the artifact itself is broader than a codebase: It’s software, training and test data, and learned parameters bundled together, and each piece can be open or closed independently. A company can release the weights, withhold the data and training code, and still call the result “open.”
Calling yourself “open” carries connotations of trust, Landay says. But companies would need to hand over the training data before outsiders could actually test, reproduce, or challenge the work. “There’s a wide gap between open-weight AI and open source AI.”
He says Stanford HAI has staked out a specific bar: alignment with the Linux Foundation’s Model Openness Framework at its top tier, the “Open Science” class – meaning the code, the training data (or a thoroughly documented, auditable account of it), and the tooling are all released, not just the weights, alongside a real way for outside researchers and communities to download, run, study, contribute to, and modify the work. Anything short of that, in his view, forecloses entire lines of research: You can’t, for example, study how a model’s training data shapes its cultural assumptions, audit it for how fairly it represents different populations, or test new architectures at the scale where genuinely new behavior shows up. You can only observe a finished system from the outside and guess at why it does what it does.
Landay adds that nearly every major architectural leap in modern AI – the transformer itself, attention mechanisms, and mixture-of-experts routing – came out of published research that other labs and academics could pick apart, question, and build on. Radical innovation depends on open science. Once frontier work moves behind closed doors, the next generation of researchers can only iterate on what a handful of companies choose to disclose.
“Open weights answer ‘Can I run this?’” Landay said. “Open source answers ‘Can I trust this, improve it, and build the next thing on top of it?’ Right now almost everyone – American labs and Chinese labs alike – is answering the first question but nowhere close to the second.”
The Risk of Closed AI
Closed models – whether American or otherwise – are not necessarily less safe in the moment, but carry risks of concentration. A small number of firms controlling frontier capability behind an API means a small number of firms deciding who gets access, at what price, and whose values get baked into a tool that increasingly mediates how people work and think.
He traces this to a familiar pattern: platforms that start out creating value for users and gradually pivot toward extracting it – what Cory Doctorow calls “enshittification.”
“A closed frontier model behind an API is the ultimate walled garden,” Landay said. “You don’t own your data, your history with the model, or any leverage to leave. That’s already the norm.” The longer someone stays inside one of those gardens, he added, the more of their own context and history the platform accumulates – which only raises the cost of ever leaving, deepening the lock-in rather than easing it over time.
There’s a security argument here too: Relying solely on closed models isn’t inherently safer, since they can be breached, misused, or fail in ways outsiders have no way to detect. Concentrating frontier capability behind a handful of closed systems just means those blind spots are concentrated too.
Closed models also risk encoding a narrower slice of the world’s values than the world they’re meant to serve. A handful of labs – whether in the U.S. or China – training frontier systems mostly on their own data, in their own language, under their own assumptions, produce tools that quietly carry one culture’s worldview into everyone else’s daily life.
And because frontier capability sits with so few companies concentrated in so few countries, it becomes a strategic chokepoint as well. Landay points to Anthropic’s own latest models going dark under a Commerce Department order as a preview of how quickly access to closed frontier AI can become a bargaining chip in a trade dispute or export-control fight, with the people relying on it caught in the middle.
Defining an Open Approach
Landay’s fix has three parts:
- Decentralized AI: AI you can run locally or on your own servers rather than rent
- Data portability: Your context and data travel with you between platforms instead of locking you in
- Verifiable agents: AI whose builders, loyalties, and actions are actually verifiable.
None of that works, though, if the underlying models are still built behind closed doors by a handful of firms. Landay thinks closing that gap is a job for a different kind of institution altogether: universities. Academic institutions can commit to timelines longer than a product cycle, publish work meant to be checked rather than merely used, and pursue questions with no clear path to revenue – building and studying leading-edge systems themselves, not proxy models or API access to someone else’s black box.
“If the future is genuinely open, in the full sense, it doesn’t matter as much whose flag is on the release, because anyone anywhere can inspect it, adapt it, and hold it accountable,” he said. “If ‘open’ just means ‘downloadable,’ we’ve traded one set of closed labs for another. Same concentration of power, different flag. Tomorrow’s AI won’t just complete tasks for us – it’ll shape what we consider possible. The question was never really ‘Can we build this?’ It’s ‘What world are we building, and whose humanity are we encoding into it?’ Open weights alone won’t answer that. Only open source AI for science and society will.”
AI算出
論評・提言ainew評価高い
中国製モデルの性能向上という事実を背景に、米国の規制動向や業界の反応を踏まえつつ、スタンフォード HAI が「重み公開」から「データ・コード含む完全オープンソース」への転換を強く主張する論説であり、新規な視点と具体的な定義基準が含まれている。
6つの評価軸を見る
- AI関連度
- 100
- 情報源の信頼性
- 100
- 新規性
- 75
- 調べる価値
- 75
- 重複の少なさ
- 90
- 日本での有用性
- 25
同じ出来事を2媒体で確認
同じ出来事を扱う別媒体の記事です。見出しと公開時刻を比較できます。
News to Guide
ニュースの次に確認する
発表内容を、現在の料金や仕様と照らし合わせられる関連ガイドです。
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み