Position: Current Model Cards Are Insufficient for Downstream Governance of Open-Weight Foundation Models
06:00 · August 20, 2026 · arXiv cs.AI RSS

The growth of open-weight foundation models (OWFMs) has prompted the AI community to re-evaluate strategies for effective downstream governance. Although model cards have been widely adopted as transparency artifacts in model repositories, existing frameworks often fail to adequately inform downstream developers and users about the distinct safety challenges posed by OWFMs. This position paper analyzes 500 model cards hosted on Hugging Face and argues that effective governance of OWFMs requires a multi-layered approach integrating three complementary components: (i) model cards, (ii) acceptable use policies (AUPs), and (iii) licenses. To motivate this claim, we identify a safety gap left by existing regulatory approaches, including model heritage, alignment provenance, and empirically observed behaviors, through an analysis of model cards with safety-critical information. We further argue that standard open-source licenses (OSLs) are not well suited for OWFMs and may weaken the enforceability of AUPs. Building on these observations, we outline directions for evolving model cards, AUPs, and licenses into integrated safety artifacts to enable a more comprehensive governance framework that coherently integrates informational, normative, and legal dimensions.
Summary
A position paper from researchers at Seoul National University examines documentation practices for open-weight foundation models by reviewing the 500 most-downloaded models on Hugging Face. Although model cards appear in nearly all cases, the study finds that safety-related content remains inconsistent: only three-quarters include dedicated safety fields, and much of the relevant information appears in unstructured README sections rather than standardized disclosures. Acceptable-use policies surface in just over one-fifth of the cards, while explicit licenses are listed for 85 percent of models, most of them permissive open-source licenses that grant broad rights to modification and redistribution.
The authors identify three recurring gaps. Model cards rarely document model heritage, the provenance of alignment procedures, or observed safety-relevant behaviors in sufficient detail. Acceptable-use policies, when present, lack standardized language and legal force unless they are incorporated into binding license terms. Standard open-source licenses, however, are structurally incompatible with use-based restrictions, leaving downstream developers without enforceable constraints on high-risk applications.
To address these shortcomings, the paper advocates a three-layer governance structure. Safety cards would extend current model cards with explicit sections on heritage, alignment history, and operational evaluations. Standardized acceptable-use policies would supply consistent normative boundaries across developers. OWFM-specific licenses would replace or supplement permissive open-source terms to make those policies legally binding. The authors argue that this integrated approach supplies the informational, normative, and legal mechanisms needed for downstream control, particularly in light of emerging obligations under the EU AI Act.
Why it matters
Directly addresses EU AI Act compliance and downstream governance for open models, actionable for Dutch researchers and advanced practitioners developing or deploying OWFMs. High technical depth with reproducible analysis and templates.












