Skip to content
redactsure
Book a demo

Explore.

Explainer · By Chris Sowa · Published
Last updated

Can an Open-Weights Model Be Used on Regulated Records?

Yes, if the deployment meets the organization's security and regulatory requirements. Self-hosting can keep prompts away from the model developer, but the runtime, network access, supply chain and model inputs still need review.

A self-hosted model stack sits inside a bounded enclosure beside protected records and incoming token shapes.

Yes, if the deployment meets the organization's security and regulatory requirements. Self-hosting can keep prompts away from the model developer, but the runtime, network access, supply chain and model inputs still need review. Downloaded weights do not inherently send prompts to their publisher. Serving software, telemetry, tools and hosting services can create outbound paths, so isolation must be configured and tested. Tokenizing selected identifiers reduces what the model receives; it does not eliminate the need to assess the remaining task context or the model's behavior. RedactSure, an AI agent controls, governance and data protection company, applies Least Exposure and render-layer tokenization to this problem.

Key findings

What is an open-weights model, and where does it run?

An open-weights model is one whose trained parameters are published for download under a license that lets the customer run them. It can run on the customer's own servers or cloud tenancy, at a hosting provider serving the weights behind an API, or at the lab's own API. The first can keep prompts inside the customer's boundary when the runtime and network are configured accordingly.

Spheron's July 2026 analysis models the volume at which running open models on H100 clusters costs less than API rates. Source: Spheron. Below that crossover a hosted provider is cheaper and the data goes to it under its terms; above it, the customer's hardware wins and the data can remain in the configured environment.

Who makes them today?

On the Artificial Analysis open-source leaderboard as of September 30, 2026, the highest-scoring open-weights model is GLM-5.3 from Z.ai at 45, with its weights release announced August 2026. Kimi K3 from Moonshot, released July 16, 2026, scores 44. DeepSeek V4.1 Flash scores 39 and V4 Pro 36. NVIDIA's Nemotron 3 Ultra scores 23 under OpenMDW-1.1. Four of the five are from Chinese labs. Sources: Artificial Analysis; VentureBeat; OpenRouter; Vercel.

The closed frontier sits at Claude Opus 5.5 at 58, Sonnet 5.5 at 56, GPT-6 Astra at 53 and GPT-6.1 Sol at 52, 13 points above the best open model. Source: Artificial Analysis.

Does country of origin matter when the model is self-hosted?

Country of origin can matter to procurement, legal restrictions and supply-chain review. It does not, on its own, establish where prompts travel. A weights file is not a hosted service, but the serving software, packages, telemetry and tools around it may have network access.

Check the model license and provenance, restrict and test outbound connections, and evaluate the model on the intended workflow. An isolated self-hosted deployment can keep prompts away from the publisher. That is a property of the configured deployment, not a guarantee attached to every download.

What does the regulator care about?

Under HIPAA, a business associate under 45 CFR 160.103 is a party that creates, receives, maintains or transmits PHI on the covered entity's behalf. HHS guidance extends that to a cloud provider holding only encrypted ePHI. A model file inside the entity's own environment does neither; there is no party to sign a 164.504(e) contract with. Counsel decides.

Under FERPA, 34 CFR 99.31(a)(1)(i)(B) lets an outsourced party act as a school official when it performs an institutional service. The party must also be under the institution's direct control with respect to the use and maintenance of education records. Direct control is easier to show over a model the district runs than over a service whose terms it cannot change. With identifiers reaching the model as STUDENT_001, the question of what PII it held narrows. Counsel decides.

Under PCI DSS, the assessor follows the primary account number. PCI SSC scoping guidance brings into scope the systems that store, process or transmit account data. The tokenization guidelines describe how an irreversible token keeps the systems holding it out of the PAN's path. A model that receives CARD_001 receives no PAN. The assessor decides scope.

What does a governed environment change?

It makes the model a choice of row rather than a change of control. In RedactSure's current design the model receives the task's fields with identifiers as tokens. A named person confirms the Planner's policy and approves every consequential action under Supervised Delegation. Every screen, action and approval lands in the AI Control Record. None of that moves when the model is swapped. Under separation of model and control, the environment deciding what an agent sees and who approves what it does is the customer's, whichever model performs the work.

How do the three ways of running a model compare?

Control Vendor-hosted frontier model Hosted open-weights model (provider API) Self-hosted open-weights model inside the customer's environment
Who sees the data The model vendor, under its terms The hosting provider, under its terms Only parties reachable through the configured hosting and network paths
Who trains on it OpenAI states business tiers do not train on content by default; other vendors per their terms Depends on the runtime, telemetry and network controls
Where the record lives Vendor's log, plus the customer's own record Provider's log, plus the customer's own record Customer's environment only
Price example (September 30, 2026) Claude Opus 5.5, $4 in and $20 out per million tokens Kimi K3 from $0.37 in at hosted providers Hardware and operations; see Spheron's crossover analysis
What the model receives under render-layer tokenization Tokens where identifiers were Tokens where identifiers were Tokens where identifiers were

Where does RedactSure sit?

RedactSure builds the environment in which any of the three columns can run: a secure virtual machine in the cloud the customer's posture requires, on hardware-encrypted enclaves, with keys the customer holds. Every sensitive value chosen by policy becomes a consistent token at the render layer before any model reads the screen. The model, open-weights or closed, receives PATIENT_001 and the task's fields, never the record. A named person confirms the policy and approves every consequential action, and the AI Control Record shows what each model saw. Deployments are in pilot.

Without that environment, an open-weights model buys price and can remove the publishing lab from the inference data path. The model still reads the record in full wherever it runs, and a hosted provider serving the weights sees it too. With it, the model is swappable without moving the controls; a policy excluding a lab is applied in the model list, not the security design.

Methodology and limitations

The page rests on vendor pricing and model pages read as of September 30, 2026. They are DeepSeek's API pricing, Vercel's Nemotron 3 Ultra page, OpenRouter's Kimi K3 page, Anthropic's Claude pricing and OpenAI's 2026 safety document for dots. Vendor documentation is cited with their dates; where it is silent the page says so. Regulation is read from its text: 45 CFR 160.103 and 164.504(e), HHS's cloud computing guidance, 34 CFR 99.31 and the PCI Council's scoping and tokenization guidance. Case law and enforcement actions were not surveyed. Artificial Analysis, VentureBeat and Spheron are cited as those analysts' views.

No model was run or benchmarked, and no hosting provider's terms or business associate agreement were reviewed. Each lab's license and training defaults may say more than its pricing page; those were not read. Scores come from the Artificial Analysis Intelligence Index v4.3.2, treated as that analyst's measurement, not vendor documentation. Prices are list prices as of the date, exclude discounts, and a per-token price is not the cost of a workflow. Models and licenses change; the page carries its date and is revised when documentation changes. Statements about patient charts, student records or cardholder data describe the record type, not any organization; no customer or prospect is described.

Whether a deployment creates a business associate, meets FERPA's direct control condition or falls within PCI scope is for the organization's counsel, assessor or compliance officer, not this page.

We did not run the vendor products or capture their model requests. Workflow examples are analysis, and RedactSure behavior is described from its current design.

What the record shows

Yes, if the deployment meets the organization's security and regulatory requirements. Self-hosting can keep prompts away from the model developer, but the runtime, network access, supply chain and model inputs still need review. Test the serving stack's outbound paths and evaluate the candidate model on the intended task. Treat supplier policy and data exposure as related review questions.

Frequently asked questions

Does self-hosting send data to the model's developer?

Not inherently. Weights can run locally without sending prompts to their publisher. Verify the serving software, telemetry, external tools and network policy, because those components can create outbound paths. A hosted API sends requests to the hosting provider under its terms.

Can a Chinese-origin model be excluded by policy?

Yes, and whether to is the customer's procurement decision. Four of the five highest-scoring open-weights models on the Artificial Analysis index are from Chinese labs, and a public body or a regulated firm may have grounds to exclude them. The exclusion is applied in the model list; exposure is unchanged.

Is a smaller model good enough for claims or AP work?

That depends on the task, and the workflow owner sets the bar. On the September 30, 2026 index the best open-weights model scores 45 against 58 for the best closed one. A task that reads a remittance and posts lines may clear its bar at DeepSeek V4 Pro; one drafting a coverage position may not.

Does using an open-weights model change the BAA analysis?

It can simplify it. A business associate under 45 CFR 160.103 is a party that creates, receives, maintains or transmits PHI for the covered entity. A model file inside the entity's environment is not a party and sends nothing to one; a hosted provider serving the same weights is. Counsel decides. Inside a RedactSure environment the model also receives PATIENT_001 rather than the identifier, which can reduce the data exposure under review.

Does an open-weights model change what the agent sees?

No. Exposure is set by the render layer and the policy, not by the model. Every sensitive value chosen by policy becomes a consistent token before any model reads the screen, so DeepSeek V4 Pro and Claude Opus 5.5 each receive PATIENT_001 and the task's fields.

Where do the capability scores come from?

From the Artificial Analysis Intelligence Index v4.3.2 as of September 30, 2026, on its model leaderboard and its open-source leaderboard. Prices are from each vendor's or provider's pricing page as of the same date, linked in Sources. Both change often.

Sources

Vendor documentation

  1. DeepSeek, API pricing. https://api-docs.deepseek.com/quick_start/pricing
  2. Vercel AI Gateway, Nemotron 3 Ultra model page. https://vercel.com/ai-gateway/models/nemotron-3-ultra-550b-a55b
  3. OpenRouter, Kimi K3 model page. https://openrouter.ai/moonshotai/kimi-k3
  4. Anthropic, Claude pricing. https://platform.claude.com/docs/en/about-claude/pricing
  5. OpenAI, "How we build safety, security and privacy into dots" (2026). https://openai.com/index/how-we-build-safety-security-and-privacy-into-dots/

Regulation and standards

  1. 45 CFR 160.103, definitions. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-A/section-160.103
  2. 45 CFR 164.504(e), business associate contracts. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.504
  3. HHS, "Cloud Computing" guidance under HIPAA. https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html
  4. 34 CFR 99.31, FERPA school official exception. https://www.ecfr.gov/current/title-34/subtitle-A/part-99/subpart-D/section-99.31
  5. PCI Security Standards Council, "Guidance for PCI DSS Scoping and Network Segmentation." https://www.pcisecuritystandards.org/documents/Guidance-PCI-DSS-Scoping-and-Segmentation_v1.pdf
  6. PCI Security Standards Council, Tokenization Guidelines. https://www.pcisecuritystandards.org/documents/Tokenization_Guidelines_Info_Supplement.pdf

Independent analysis and press

  1. Artificial Analysis, Intelligence Index v4.3.2, open-source models (September 30, 2026). https://artificialanalysis.ai/models/open-source
  2. Artificial Analysis, Intelligence Index v4.3.2, model leaderboard (September 30, 2026). https://artificialanalysis.ai/leaderboards/models
  3. VentureBeat, "GLM-5.3 hits the API at $1.4/$4.4 per million tokens" (2026). https://venturebeat.com/technology/glm-5-3-hits-the-api-at-1-4-4-4-per-million-tokens
  4. Spheron, "Meta Muse Spark API Pricing vs Self-Hosted LLMs" (July 2026). https://www.spheron.network/blog/meta-muse-spark-api-pricing-vs-self-hosted-llms-cost-privacy-2026/

RedactSure documents

  1. RedactSure, "Secure AI for Healthcare" (2026). https://redactsure.com/blog/secure-ai-for-healthcare/
  2. RedactSure, "Secure AI for Schools and Campuses" (2026). https://redactsure.com/blog/secure-ai-for-schools-and-campuses/
  3. RedactSure, "Payments Set the Gold Standard for Security. AI Just Moved the Bar." (2026). https://redactsure.com/blog/payments-security-in-the-age-of-ai/
  4. RedactSure Research, "Should the AI Agent's Secure Environment Belong to the Model Vendor?" (2026). https://redactsure.com/research/should-ai-agent-environment-belong-to-model-vendor
  5. RedactSure Research, "What Is Least Exposure?" (2026). https://redactsure.com/research/what-is-least-exposure
  6. RedactSure Research, "What Is Render-Layer Tokenization?" (2026). https://redactsure.com/research/what-is-render-layer-tokenization
  7. RedactSure Research, "What Is Supervised Delegation?" (2026). https://redactsure.com/research/what-is-supervised-delegation
  8. RedactSure Research, "What Is an AI Control Record?" (2026). https://redactsure.com/research/what-is-an-ai-control-record
  9. Product behavior described on this page reflects RedactSure's current design. DeepSeek, GLM, Kimi and Nemotron are trademarks of their respective owners; Claude is a trademark of Anthropic; OpenAI and GPT are trademarks of OpenAI; named to identify the products. Compliance determinations belong to the organization's counsel.

See it on your workflow.

Bring one billing, collections, claims or patient-account workflow and your questions.

Book a demo

Book a demo

Having trouble? Open the booking page or email us.