Here is the uncomfortable fact at the center of this essay: whatever gets said about safeguards, filters, licenses, and takedown regimes below, none of it can reach the thing that actually determines the outcome. Once a model’s weights are published — once the file exists on Hugging Face, mirrored a thousand times before anyone official notices — there is no version of the future where that file goes back in the box. You can regulate the people who use it. You cannot regulate the file.
That’s the frame I want to hold onto, because the open-source video generation ecosystem has moved fast enough this year that it’s worth taking stock of where it actually stands, not where it stood when this became a talking point a couple of years ago.
The state of the tools, briefly: what used to require a data-center GPU cluster now runs on a well-specced desktop. Alibaba’s Wan line, Tencent’s HunyuanVideo, LTX, CogVideoX, and a handful of newer entrants like NVIDIA’s SANA-WM have all converged on the same basic reality — quantized versions of frontier-adjacent video models now fit on a consumer 16 to 24GB GPU, generate minute-scale clips at 720p, and cost nothing per generation once you’ve done the setup. The gap between “what a closed API can do” and “what you can run in your own bedroom” has nearly closed. That’s the headline, and it’s genuinely remarkable engineering. It’s also the whole problem in one sentence.
Because “open weights” means something specific and underappreciated: it means no centralized filter sits between the model and the output. A closed system like Veo or Sora can refuse a request, watermark an output, log an account, ban a user. An open-weight model, once downloaded, answers to nobody. There’s no terms-of-service violation to enforce, because there’s no service. There’s just a file on a hard drive and whatever restraint the person running it chooses to exercise — which, per the data, is often none. A recent audit found that when researchers set up a monitored space mimicking an open image-editing tool, the overwhelming majority of prompts submitted were sexual in nature, most requested removing a real person’s clothing from an uploaded photo, and nearly all the subjects were women. That’s not a hypothetical misuse case. That’s the modal use case, observed directly, on a mainstream hosting platform, in a single week.
Video makes this categorically worse than the still-image version we’ve been arguing about since 2023 or so. A fabricated photo is disturbing. A fabricated video with synchronized motion, lighting continuity, and now — as of the newest model generations — native audio, closes the gap between “obviously fake” and “I can’t tell” for the average viewer, which is the entire population that matters for reputational and psychological harm. And the target list runs exactly where you’d expect: MIT researchers tracking this over the past couple of years found that the vast majority of circulating deepfake video is nonconsensual pornography, and that celebrities remain the largest and most searched-for category, with the technology’s reach extending disturbingly into ordinary teenagers as fast as it extends into famous women.
The legal system is, to its credit, no longer sitting on its hands the way it was a few years ago. The federal TAKE IT DOWN Act now requires platforms to remove nonconsensual intimate deepfakes on notice, with enforcement teeth arriving this year. The DEFIANCE Act — a federal civil cause of action letting victims sue creators and distributors directly, with statutory damages running into six figures — cleared the Senate unanimously and is sitting in the House. States have gone further and stranger: Minnesota just passed the first law in the country that targets the developers of “nudification” tools rather than only the end users, a liability model serious enough that it’s already drawn a First Amendment lawsuit from one of the major AI labs trying to block it before it takes effect. Forty-plus states now have some version of this on the books.
All of which is real progress, and none of which touches the file on the hard drive. Every one of these laws regulates distribution, hosting, or the act of creation by an identifiable person within reach of a court. Not one of them can un-train a model or un-download a checkpoint that’s already propagated across a dozen mirrors, forks, and quantized community re-releases. The Minnesota approach — go after the developer, not just the user — is the most interesting legal experiment precisely because it’s the first one that seems to grasp this: if you can’t control the weights once they’re out, your last leverage point is upstream, at the organization deciding whether to publish them in the first place. Whether that survives the First Amendment challenge is genuinely an open question, and I don’t think it’s a frivolous one on either side. It’s a real collision between two things worth caring about — open scientific publication and the prevention of a specific, well-documented, gendered harm — and I’m not going to pretend the tension resolves cleanly.
What I keep circling back to is that this is the sharpest possible test case for the “open source is inherently good, closed source is inherently a power grab” reflex that a lot of us, myself included on other days, carry around as a default. Open weights are how you avoid a handful of corporations owning the only cameras. They’re also, provably, how you get a tool whose single most common real-world use, per direct measurement, is stripping the clothing off photos of nonconsenting women. Both of those sentences are true at the same time, about the same technology, and holding them together without flinching toward either “ban everything” or “information wants to be free” is the actual work here — not a rhetorical hedge, an honest description of a problem that doesn’t have a clean exit.
If there’s a policy instinct I’d defend, it’s the Minnesota one, imperfect and legally contested as it is: push responsibility as far upstream as the architecture allows, because downstream enforcement — chasing individual anonymous uploaders across jurisdictions, platform by platform, takedown by takedown — is a game the victims lose by default, every time, no matter how good the statute is on paper. The weights are already out for everything released so far. The only lever left is what gets released next, and under what terms, and whether “open” gets redefined to mean something other than “no one is responsible.”