Argues that Apertus is the first major release to ship data filtering recipes and provenance for all 15 trillion training tokens — the part 'nobody else ships.' This is framed as what 'open' was supposed to mean before Meta redefined it with restrictive community licenses and opaque training data.
By submitting Apertus to HN with the framing 'Open Foundation Model for Sovereign AI,' the submitter highlights the model's full-stack openness — weights, code, checkpoints, and data provenance — as the differentiating feature worth community attention.
Contends that 'sovereign AI' has mostly been a Jensen Huang sales pitch for GH200s, but Apertus makes the term operational: a model engineers can audit, retrain, and deploy without any US or Chinese provider dependency and without a license that revokes itself at scale thresholds like Meta's 700M MAU clause.
Highlights that Apertus was designed against EU AI Act transparency obligations from day one, with a complete data card and opt-out signal honoring. The inclusion of Romansh — a language with only 60,000 speakers — proves a public research consortium will prioritize linguistic and regulatory goals that no commercial frontier lab would ever pursue.
Acknowledges Apertus sits 'roughly in the Llama 3.1 70B neighborhood on MMLU and HellaSwag — not frontier, not embarrassing.' The implicit argument is that for a publicly-funded sovereign model, matching a year-old open-weights baseline is sufficient because the value proposition is auditability and independence, not benchmark leadership.
Apertus, a 70B-parameter (and 8B sibling) foundation model from EPFL, ETH Zurich, and the Swiss National Supercomputing Centre (CSCS), landed on Hacker News this week at 281 points. The model ships under Apache 2.0 with weights, training code, intermediate checkpoints, and — the part nobody else ships — the data filtering recipes and provenance for all 15 trillion training tokens.
Training ran on Alps, the CSCS supercomputer built around NVIDIA's GH200 Grace Hopper superchips — roughly 10,000 of them. The 70B variant was trained from scratch (no Llama base, no Mistral weights underneath), with multilingual coverage that includes the four Swiss national languages plus Romansh, a language with about 60,000 speakers that no commercial frontier lab will ever prioritize. Benchmarks put it roughly in the Llama 3.1 70B neighborhood on MMLU and HellaSwag — not frontier, not embarrassing.
The more interesting line in the technical report is the compliance posture: Apertus was designed against the EU AI Act's transparency obligations from day one, with a data card that lists every CommonCrawl snapshot, every code repository, every book dataset, and the opt-out signals honored during scraping. This is what 'open' was supposed to mean before Meta redefined it.
The term 'sovereign AI' has been doing a lot of work lately, mostly as a slide in Jensen Huang keynotes selling GH200s to national governments. Apertus is the first release where the term means something concrete to a working engineer: a model you can audit, retrain, fine-tune, and deploy without a single dependency on a US or Chinese provider, and without a 'community license' that revokes itself if you cross 700M MAU.
Compare the lineage. Llama 3 is open weights but ships under a license that prohibits use by Meta's competitors above scale, with a separate acceptable-use policy that Meta can revise. Mistral's 'open' tier is now a strip-mined version of what they ship to enterprise. Gemma forbids derivative model training for commercial use in several geographies. Qwen and DeepSeek are technically more open, but operate under PRC jurisdiction — a non-starter for European public-sector procurement and increasingly for US enterprise compliance teams reading the latest CFIUS guidance.
Apertus collapses that hedge. Apache 2.0 means you can fork it, sell derivatives, ship it inside a closed-source product, and never speak to the authors. The training data recipe means you can re-derive your own checkpoint if you suspect contamination or want a different cutoff. The intermediate checkpoints mean you can do mechanistic interpretability work that's been impossible on Llama because Meta only releases the final weights. For an interpretability researcher, this is the first 70B-class model where you can watch features emerge across training instead of inferring them from a single endpoint.
The HN comments split predictably. The bull case: 'Finally, a model where the data card isn't a marketing document.' The bear case: 'Benchmarks lag Llama 3.3 by 4-7 points across the board, and nobody outside Switzerland will care.' Both are right. Apertus isn't going to win on the Chatbot Arena leaderboard. It's going to win when a French ministry, a German hospital network, or a Swiss bank needs to deploy an LLM and the compliance team asks 'show us the training data' and the answer can't be 'NDA.'
There's also a quietly important second-order effect: Apertus is the first proof point that a publicly funded research consortium can ship a 70B model end-to-end without industry capture. EPFL didn't take Meta money. ETH didn't license a Mistral base. CSCS used a public supercomputer paid for by Swiss taxpayers. If this becomes a template — and the EU's AI Factories initiative is explicitly designed around exactly this pattern — the assumption that frontier models require a $100M private fundraise starts to weaken.
If you're shipping LLM features into the EU, Apertus is now the default 'we need a model we can actually point regulators at' option. The compliance burden of demonstrating training data provenance under Article 53 of the AI Act is real, and no closed model will help you with it. The 8B variant fits on a single H100, the 70B runs on 2x H100 with INT8 quantization or 4x with FP16 — standard self-hosted footprint.
For fine-tuning workflows, the practical win is the intermediate checkpoints. If you're doing LoRA work and hitting the usual problem where your domain adaptation undoes safety training, you can now start from a checkpoint before the SFT phase and rebuild the alignment stack against your own preference data. This was theoretically possible with OLMo but at 7B; Apertus brings it to a size class where the base capability is actually useful in production.
For anyone building agents, the licensing terms matter more than the benchmarks. Agentic systems make many LLM calls per task, often with structured output and tool use that exposes the model's idiosyncrasies to your users. An Apache 2.0 base means you can ship the model inside an air-gapped enterprise deployment, run it on-prem at a regulated customer, and modify it without lawyering every change.
What Apertus doesn't fix: it won't beat GPT-5 or Claude on hard reasoning, it has no vision modality yet, and the multilingual coverage skews European in ways that matter if your product ships in Bahasa or Swahili. Treat it as a serious option for European deployments, regulated industries, and research, not as a replacement for the frontier.
The next twelve months will test whether 'fully open' as a category has a viable economic model outside of national pride projects. CSCS estimates Apertus consumed roughly 2.5M GPU-hours on Alps — call it $5-8M of compute if you priced it on AWS. That's well within reach of a mid-sized national research budget but not of a typical open-source community. If Apertus stays a one-off, it's a curiosity; if it becomes the first of a quarterly cadence from European public infrastructure, the closed-model moat narrows considerably. Watch for the next release from BSC's MareNostrum in Barcelona, which is rumored to be following the same playbook.
I like the idea, and it has become more pressing that everyone outside the US think about tech sovereignty because the US has become an unsafe place to keep your data, but the impression I get from Apertus is that it moves at the speed of a committee. I have no expectation they'll deliver a com
By far the most impactful product of the Apretus project are the people. To quote a memorable line from Dominique Paul (https://www.thisiscrispin.com/):> What most people miss IMO is that this is not a team who is doing this for the fourth time like virtually any other LLM provider
For a model that claims to focus on many languages, it's quite unreliable when it comes to simple questions like "how to say X in language Y" or "how to conjugate verb X in language Y". It keeps hallucinating words that do not exist, and when corrected, it only hallucinates
Looks like their instruct models are Llama3.1 fine tune from last year. Is there any progress on new models?My last hope for soverign AI is from Chinese open models
Top 10 dev stories every morning at 8am UTC. AI-curated. Retro terminal HTML email.
Other fully open LLMs include Allen AI's OLMo 3.1 and MBZUAI's K2 Think V2, both of which have released their full training pipelines and datasets.Nvidia Nemotron is also an open training source model, though a portion of its dataset remains proprietary.Quoting lambda's comment:> N