A Closed Model Is a Foreign Dependency Wearing an API | Saad Ullah Bilal
Back to Blog
AI Governance6 min read

A Closed Model Is a Foreign Dependency Wearing an API

Why the most important question about enterprise AI is not how good the model is, but whose it is, where it runs, and whose law governs it.

Saad Ullah Bilal
Saad Ullah Bilal
AI Strategist & Builder
A Closed Model Is a Foreign Dependency Wearing an API

When an institution adopts AI today, the transaction feels clean. You get an endpoint, a key, and a page of documentation. You send text in, you get intelligence back. It looks like you bought a capability.

You did not. You took on a dependency. And if the model is closed and hosted somewhere else, it is a dependency you cannot see, cannot govern, and cannot guarantee. The API is the part you touch. The dependency is the part you inherited.

For a consumer app, that is a fine trade. For a bank's credit decisions, a tax authority's enforcement, or a ministry's records, it is a structural problem that no amount of model quality fixes.

Three layers of "someone else's"

Strip the interface away and look at what a hosted closed model actually is. The weights run on infrastructure you cannot see. The model is owned by a company that does not answer to you. And that company operates under a jurisdiction that is not yours.

Infrastructure, ownership, jurisdiction. Three layers, and you control none of them. The endpoint on your side is local. Everything behind it is foreign, in the precise sense that it belongs to someone else and obeys rules you did not write.

The API is what makes this easy to miss. A good interface feels like control. You hold a key, you set parameters, you read the docs, and it responds on demand. But an interface is not ownership. You are renting access to a system you are not allowed to inspect, version, or hold. The steering wheel is in your hands. The engine, the fuel, and the road belong to someone else, in another country.

What a dependency you cannot govern actually does

This is not a hypothetical worry. It shows up as four concrete failure modes, and none of them require anyone to act in bad faith.

It can change under you. A closed model can be updated, retrained, or retired with no notice. The system that made a decision six months ago may no longer exist, which means you cannot reproduce that decision, and cannot explain it to a regulator who asks. You are not auditing a system. You are trusting a memory.

It can be withdrawn or repriced. Access is a commercial arrangement, and commercial arrangements change. The core function you built on top of someone else's model is only as stable as their pricing, their roadmap, and their willingness to keep serving you.

It can be compelled. This is the one that matters most and gets discussed least. A model hosted in another jurisdiction answers to that jurisdiction. Export controls, legal orders, and policy shifts made in a capital that is not yours can reach through the API and into your core operations. You did not choose that authority. You inherited it the moment your decisions started depending on their infrastructure.

And your data does not stay yours. Whatever you send crosses into a system you do not control, hosted where your rules do not reach. Whether it becomes training signal, how long it persists, and who can be compelled to hand it over are all answered by someone else's policy, not your architecture.

Why government is where this stops being negotiable

A consumer chatbot can tolerate all of the above. A state cannot.

The decisions a government makes about a citizen carry the force of law. Tax enforcement, benefits, identity, security. When one of those decisions is shaped by a model, the provenance of that model becomes part of the legitimacy of the decision. "An algorithm we rent from a foreign company decided this, and we cannot show you how" is not an answer a public institution can give.

The principle is simple. The state cannot let a core function depend on a system the state cannot govern. Citizen records, tax data, and defense signals cannot route through a model owned elsewhere and bound by another country's law, no matter how capable that model is. Capability was never the question. Provenance is.

The honest part

Here is where most arguments for owned AI go quiet, so let me say it plainly. The alternative is not free.

Running your own open weight model on your own infrastructure means you now carry everything the API provider used to carry for you. The serving, the security, the scaling, the monitoring, the whole operational burden of keeping a model alive and safe. That is real work and real cost, and anyone who tells you otherwise is selling something.

But for a government or a regulated institution, that burden is not a downside. It is the point. Sovereignty means holding responsibility, not offloading it. An institution that wants to own its decisions has to own the machinery that makes them. The cost of control is the whole meaning of control.

Open weights, correctly understood

This is why open weights are not an ideology. They are the mechanism that lets a model run inside your boundary instead of behind someone else's API. Once the model runs on infrastructure you own, the foreign dependency disappears. You can pin a version and reproduce a decision. You can fine tune it on your own data and shrink it to your own hardware. You can run it on premise, air gapped if you need to, answerable only to your own rules.

One honest caveat, because it keeps the argument credible. Open weights do not hand you the training data, so this is not total transparency. It is deployment control. But deployment control is exactly what a regulator asks for. Which model, which version, which inputs, what came out, provable on demand. That is the standard that matters, and a closed API cannot meet it.

The test

Before an institution lets AI into a function that matters, the first questions are not about the benchmark. They are about provenance. Whose model is this. Where does it run. Whose law governs it if someone reaches for it.

A closed model behind an API answers all three the same way. Not yours, not here, not your law. It is a foreign dependency in local clothing, and the API is the clothing.

The institutions that understand this early will own their intelligence. The ones that do not will keep renting it, and keep discovering, one incident at a time, exactly how much of their core they handed to someone they cannot govern.