Why we’re getting right behind open weights
The strategy papers your people paste into public AI services can teach someone else’s model how you think. They should be teaching yours.
The organisations we talk to want to own their AI, the same way they own their data, their systems and their operations. They don’t want their people’s knowledge going into someone else’s model, and they don’t want someone else’s worldview inside their decisions. That’s why we’re getting right behind open-weights models.
Your ideas are training someone else’s model
Your people are already using ChatGPT, Claude and the rest, often on their own accounts. 78% of Australian AI users bring their own AI tools to work, and worldwide, nearly half of employees who use AI at work have uploaded company information into public AI tools.
OpenAI says it “may use your content to train our models”, and Canada’s privacy commissioners found that setting was “enabled by default”, calling the way opting out used to cost users their chat history a “deceptive design pattern”. Anthropic used to tell Claude users it would “not use your Inputs or Outputs to train our generative models”. In 2025 it changed its consumer terms to train on chats and keep them for up to five years, and showed existing users the switch was already turned on.
A strategy team works the same plan through dozens of conversations over months, in different words each time, and that is how a model learns something well enough to answer anyone’s questions about it. Amazon was already seeing this within weeks of ChatGPT’s launch. Staff were using it at work, one of them pasting in some of Amazon’s own coding interview questions, and Business Insider reported that an Amazon lawyer warned them after seeing ChatGPT responses “looking similar to internal Amazon data”.
The OAIC recommends organisations “do not enter personal information, and particularly sensitive information, into publicly available generative AI tools”. When a Victorian child protection worker put a child’s details into ChatGPT, the privacy regulator found the worker had released that information “outside the control of DFFH”, held the department responsible, and ordered it to block ChatGPT and similar tools for child protection workers.
In Korea, a chatbot trained on 9.4 billion private messages from 600,000 people started telling users other people’s names and home addresses, and a court has since ordered its maker to pay damages to dozens of the users who sued.
A US court has ordered OpenAI to hand 20 million ChatGPT logs to the New York Times, ruling that people have stronger privacy in a wiretapped phone call than in conversations “which users voluntarily disclosed to OpenAI”.
The enterprise versions promise not to train on your content, in terms they write and can change. Take the promise at face value and the problem doesn’t go away, it changes shape. What your people type into these tools is the working knowledge of your business: how your analysts read a market, how your lawyers frame a risk, how your engineers decide what good looks like. That is IP in the plainest sense, and it is being spent in two ways at once. The downside is leakage: it sits on someone else’s servers, within reach of someone else’s courts, and if the terms change, inside someone else’s model. The cost that gets missed is the other one. Every one of those conversations could have been training a model you own, and instead it trains nothing. Most organisations have never had a way to turn what their best people know into an asset that compounds. Now they do, and the material is being poured into a product that will never give it back.
Open weights put the model in your hands
Open-weights models are published for anyone to download and run. Google, Mistral, NVIDIA and OpenAI all publish them, and some of the best come from Chinese labs: Kimi from Moonshot AI, GLM from Z.ai and Qwen from Alibaba. Run one on your own hardware and nothing you type goes back to the people who made it. And today, these models are not the second tier. On the Artificial Analysis Intelligence Index, which runs open and closed models through the same ten benchmarks across reasoning, coding and agentic work, the best open-weights models score 44 to 46. Claude Opus 4.8, which led the entire index when Anthropic released it in May, scores 42 on the index as it stands today. The current leader, Claude Opus 5.5, scores 58. Open weights run a few months behind the US frontier, and both the model and your data stay under your control.
Running one well is another matter. The best of them are too big for an ordinary server: Moonshot AI’s deployment guide puts the smallest cluster for Kimi K2 at 16 GPUs. Those GPUs need a runtime and a serving engine tuned to them, and the model needs a platform around it before your people can safely use it. A better model comes out every few months, and each one has to be tested before it replaces the last. Few organisations have the engineers to do all of that. It’s the work we take on.
Every model comes with a worldview
Since 2023, generative AI services offered to the public in China have had to “uphold the Core Socialist Values”. When the US Government’s AI testing centre evaluated Kimi K2 Thinking, an earlier Kimi model, the model lined up with about 26% of the Chinese Communist Party talking points it was tested on in Chinese, and 7% in English.
In July 2025 the White House ordered that AI models bought by US federal agencies be “neutral, nonpartisan tools that do not manipulate responses in favor of ideological dogmas such as DEI”. Meta said leading models “historically have leaned left” and that its goal was to “remove bias”. In both countries, someone other than you decides what the model should think.
Picture a bank’s risk team asking one of these models how to think about Australian credit, markets or capital. The defaults are American. Asked how to invest $10,000, with no country named, three popular chatbots put more than 93% into US shares, where a global index holds 59%. Told to give one answer to legal and administrative questions in English, from tax and pensions to labour law, without a country named, models used American frameworks three times out of four. When CHOICE asked chatbots for help with mortgage stress, ChatGPT and Meta AI sent it to American services. APRA has warned that opaque foundation models limit a bank’s ability to assess their “performance, bias, resilience and security”. Putting a model with a particular political leaning at the centre of your risk process means you’ve built someone else’s assumptions into the core of your risk model.
None of these models know your organisation, your policies, or how your best people tell a good answer from a bad one. Training on your own material changes that. When researchers trained small open models on Australian legal citations, they got about half right, where general models managed between 0% and 16%.
Why our approach is getting so much traction
Ideology and bias are as big a risk as leaking your IP through public services, and that’s why our approach is getting so much traction with the organisations we talk to. The base model is one part of it. The hard part is what we do with it: training it on your domain, and building the engineering around it that turns a model into something your people and your software agents can use.
We take the best open-weights models and put them through the Matilda training system, which aligns them to your ideological, cultural and enterprise requirements. The model takes the positions you set, not Beijing’s or Washington’s. It works with Australian law, Australian markets and your own institutions instead of defaulting to America’s, and it learns your organisation, your policies, your products and how your best people make the call.
Each organisation gets its own instance, in our Melbourne facility or in its own data centre. Your chat history, usage, data and IP stay in that instance, in Australia, under Australian law, and nobody else’s model learns from them. That goes in the contract.
Your model keeps learning from your people. The answers they correct, the answers they confirm and the material you choose to add all go back through the Matilda training system into the next version of your model, with personal information kept out. One rule governs what goes in: anything a model learns can come back out to whoever asks, so we only train your model on what everyone using it is allowed to see. A new version goes live when you approve it, not before. Over time it knows more about your business than any public model does, and that knowledge is yours. You hold the weights under the base model’s licence, and if you leave, they come with you.
Putting a model in front of your staff and your software agents takes more than the model. It takes sign-in, safety checks on the way in and out, scrubbing of personal information, search over your own documents with the sources checked, tool calling and the orchestration between the model and the agents that use it, conversation history, metering and an audit trail. In the Matilda platform, generating the answer is one step of 14. We’ve built the other 13.

Keep it under your law
An American provider’s Australian region keeps your data onshore, but not out of reach of American law. Under the US CLOUD Act, a provider subject to US jurisdiction can be required to hand over data in its “possession, custody, or control”, wherever it’s stored. In June 2025 a French Senate inquiry asked Microsoft France’s director of public and legal affairs, under oath, whether he could guarantee French citizens’ data would never be handed to US authorities without France’s agreement. “No, I cannot guarantee it,” he said, adding that it hadn’t happened yet.
If you’re an Australian organisation, the answer is a provider that is Australian all the way up, so the only law it answers to is the one you already do. A German bank or a Japanese agency should want the same thing from its providers. Whoever you choose, ask which governments can compel them to hand over your information, and get the answer in writing.

Tell us the task and what has to stay inside your walls. Talk to us.