# Open source or proprietary LLMs: choosing models for the enterprise

> “Mistral or GPT?” The question is often framed as picking a side, open models against closed ones. In reality it mixes three subjects: the licence, where the model runs, and how well it does your tasks. This guide separates them, then offers a method to choose without relying on a public leaderboard.

Source: https://smartagt.ai/en/ressources/llm-open-source-ou-proprietaire/
Published: 2026-09-22
Publisher: SmartAGT (NERVIAL LABS)

---
## Open source, open weights, proprietary: three realities {#definitions}

The term “open source” is used for models that are not open source in the strict sense. The Open Source Initiative, which maintains the reference definition of open source software, published an [Open Source AI Definition](https://opensource.org/ai/open-source-ai-definition) at the end of October 2024. It requires four freedoms (use, study, modify, share) and, to exercise them, access to the training and inference code, the model parameters, and sufficient information about the training data.

Few models meet all three conditions. Most so-called open models publish their weights, meaning the trained model, without the code or the data used to produce it. These are open-weight models.

- **Open source** Code, weights and data information published, under terms that let you use, study, modify and share.
- **Open weights** The trained model can be downloaded and run on your infrastructure. Its licence may restrict some uses.
- **Proprietary** The model stays with its vendor. You use it through an API, on the terms of the contract.

*Three legal and technical realities, often grouped under the same word.*

For a company, the practical distinction is mostly the second one: an open-weight model can run inside your perimeter, with no outbound traffic at all. That is what makes it eligible for sensitive use cases.

## Read the licence before the leaderboard {#licence}

Two open-weight models can come with very different licences. A few public examples show the gap.

Mistral AI releases some of its models under the Apache 2.0 licence, which allows commercial use, modification and redistribution, and keeps other models for its commercial offering: its [model list](https://docs.mistral.ai/getting-started/models/) shows the licence of each one. Meta's [Llama 3 licence](https://www.llama.com/llama3/license/) imposes an acceptable use policy, and requires the licensee to request a licence from Meta if its products exceeded 700 million monthly active users on the model's release date. OpenAI, known for its GPT models available through its API, also released [open-weight models](https://openai.com/index/introducing-gpt-oss/) in 2025 under the Apache 2.0 licence, together with a usage policy.

The consequence is simple: “Mistral versus GPT” is not “open versus closed”. Each vendor has models of both kinds. For each candidate model, check:

- **Commercial use**: is it allowed without conditions, or subject to a threshold or an approval?
- **Prohibited uses**: does the licence point to a usage policy that excludes certain sectors or processing?
- **Modification**: can you fine-tune the model and use the modified version?
- **Attribution duties**: must you credit the model in your products or documentation?
- **Licence changes**: does the version you download remain under the licence in force when you downloaded it?

This review belongs to the legal team. It is quick, and it avoids building a use case on a model you are not allowed to run.

## Compare what really matters {#compare}

Once the licence is cleared, the comparison is not about the brand but about how the model runs. A model hosted on your infrastructure and a model called through an API do not offer the same guarantees.

| Criterion | Open model hosted in-house | Proprietary model via API |
| --- | --- | --- |
| Data leaving | None, by design | On every call, governed by contract |
| Version control | Full: the version stays frozen | The provider updates and retires versions on its own schedule |
| Performance on complex tasks | Depends on the model and the hardware available | Direct access to the vendor's latest models |
| Cost structure | Capacity-based: GPUs and operations | Variable: price per token |
| Customisation | Fine-tuning possible if the licence allows it | Limited to what the provider offers |
| Operating burden | Yours | The provider's |

The versions row is often underestimated. API providers publish retirement schedules for their older models, such as [OpenAI's deprecations page](https://developers.openai.com/api/docs/deprecations). A use case validated on one version may need to be validated again on the next, on a date you do not choose.

## Evaluate on your cases, not on a leaderboard {#evaluate}

Public leaderboards measure generic tasks, often in English. They do not tell you how a model summarises your meeting notes, extracts clauses from your contracts or answers your customers in their language. Only an evaluation on your own cases does.

- **Build a test set** A few dozen real cases per use case, edge cases included, with the expected answer or the criteria of a good answer.
- **Define the criteria** Accuracy, format compliance, language quality, ability to say “I don't know”, adherence to instructions.
- **Compare blind** Business reviewers score the answers without knowing which model produced them.
- **Measure cost and latency** For each model, on the same test set: what it costs and how long it takes to answer.
- **Replay on every change** New version, new model, new instructions: the same test set serves as a regression check.

*An internal evaluation answers the only useful question: which model, for which use case.*

The result is often surprising: a model that ranks in the middle of leaderboards can be enough for an extraction or classification task, at a much lower cost. How the choice of model affects the bill is covered in the guide on [the cost of generative AI](~/ressources/cout-ia-generative/).

## A portfolio of models, not a single one {#portfolio}

An organisation often ends up with several models, each on the use cases where it fits best: a compact local model to sort and extract, a larger local model for sensitive documents, an API model for complex drafting on non-sensitive data, an embedding model for document search.

This approach requires a platform where the model is an interchangeable resource: use cases are described once, and the model can be swapped without rewriting them. It follows the logic of the [pillar guide on on-premise AI](~/ressources/ia-on-premise/) and the use-case-by-use-case split described in [On-premise, SaaS or hybrid](~/ressources/on-premise-saas-hybride/).

## Frequently asked questions {#faq}

### Is an open-weight model less secure than a proprietary one?

Not in itself. Hosted on your infrastructure, it sends no data out, which removes a major risk. On the other hand, its operational security becomes your responsibility: updates, access control, content filtering. With an API provider, those measures are taken by the provider, under its own rules.

### Should we fine-tune a model on our data?

Rarely as a first step. To make a model aware of your documents, document retrieval (RAG) is simpler, easier to keep up to date and able to cite its sources; the guide [RAG in the enterprise](~/ressources/rag-entreprise/) covers it. Fine-tuning is better suited to enforcing a style, a format or a very specific vocabulary.

### Can we change models along the way?

Yes, if the use cases do not depend on the quirks of one model. Replay the test set on the new model before switching: instructions that worked with one can give different results with another.

### Where SmartAGT fits
SmartAGT is model-agnostic. It connects to OpenAI-compatible servers hosted on your premises (vLLM, Ollama, etc.) and to Mistral AI, OpenAI and Google Gemini, which you contract with directly. Further European providers are listed on the Integrations page, each with its status.
The provider remains your choice, from 100% local with no outbound traffic at all to a cloud provider under direct contract. The full list is on the [Integrations](~/integrations/) page.
