ZEROCK

Before You Hand a Drawing to an AI: Why a "We Won't Train On It" Clause Is Not Enough

Published2026-07-28Ryuta Hamamoto

Manufacturers who say "we can't put drawings into an AI" are right. But if you cannot express the reason in the language of the rules, the response stops at wait and see. In its March 2025 revision of the trade secret management guidelines, Japan's Ministry of Economy, Trade and Industry named generative AI providers specifically and wrote that secrecy management may be denied. I check the line the state has drawn, then work through drawings received from customers, four stages for where processing happens, and the real constraints of running a model yourself.

Before You Hand a Drawing to an AI: Why a "We Won't Train On It" Clause Is Not Enough
Share

Hello, this is Ryuta Hamamoto from TIMEWELL.

"We can't put drawings into an AI." Talk to manufacturers and this is the first thing you hear. I think the instinct is right. But ask why not, in the language of the rules, and it gets hazy. When the reason has not been put into words, the response stalls at wait and see.

The state has in fact drawn a line, in March 2025. In its revision of the trade secret management guidelines, METI added this footnote.

Provided, however, that where the information α is provided not only within the company but to a third party other than the company (for example, a generative AI provider or similar), there may be cases in which secrecy management is denied.1

A sentence that names generative AI providers specifically. In this piece I check, from primary sources, where that line actually falls: drawings you received from customers, the stages of where processing happens, and the real constraints if you run a model yourself. The technology of digitising drawings is in what does digitising paper drawings and PDFs mean and the overall picture of AI in manufacturing is in the complete guide to AI and DX in manufacturing, so here I narrow to a single question: may you hand it over at all.

Japan's anxiety is concentrated on "it leaves the building"

Start with the numbers. The FY2026 Information and Communications White Paper from Japan's Ministry of Internal Affairs and Communications (published 24 July 2026) includes an international comparison of the risks companies are concerned about in using generative AI. Fieldwork ran from January to February 2026, with 515 valid Japanese responses (353 large companies, 162 small and medium)2.

Japan's top answer is "there is a security risk such as leakage of internal information", at 46.4 per cent. That is above the United States at 36.9, Germany at 31.7 and China at 42.7, the highest of the four3.

The interesting part is the other side of the same chart. "Output may contain ethically inappropriate content or bias" is 24.7 per cent in Japan against 38.5 in the United States, 35.9 in Germany and 45.0 in China. "There may be an invasion of privacy in the handling of personal information" is 24.5 per cent in Japan against 38.2, 44.0 and 43.43. On both ethics and privacy, Japan is the lowest of the four.

So Japanese corporate anxiety is heavily concentrated on one thing: our information getting out. For manufacturers I think that concentration is rational. A drawing is the technical information itself. Whether it leaves the building comes before whether the output is ethically sound. Of course it does.

The trouble starts after that. The worry is there; the thing that would stop it is not. On risk measures, Japan's most common answer is "we have company-wide policies or guidelines in place" at 41.1 per cent. But the most direct measure of all, "we have a mechanism in place that prevents input to generative AI from being used as training data", sits at 19.9 per cent. The United States is at 32.2, Germany 34.1, China 47.83. And 27.0 per cent say there is no organisational effort at all around transforming work with generative AI, rising to 45.6 per cent among small and medium-sized companies3.

One more. The share of Japanese companies using generative AI in some part of their work has reached 86.4 per cent, up sharply from 55.2 in the previous year's survey. Yet only 24.5 per cent have "had generative AI learn from internal data or built a database the AI can reference", and the white paper notes this is markedly lower than in the other three countries4. They are using it, but not connecting it to the material that matters. The fear has been converted into postponement rather than into controls. If you would like to see where your own company stands, our AI readiness check is a quick place to start.

The state is not saying "no AI". It is drawing a line

So what do the rules actually say? This is where I see the most misreading, so let me go carefully.

For background, a trade secret is defined in Article 2(6) of the Unfair Competition Prevention Act as "technical or business information useful for business activities, such as manufacturing methods or sales methods, which is kept secret and not publicly known"5. From that come the three requirements of secrecy management, usefulness and non-public knowledge. Incidentally, the phrase "secrecy management" does not appear in the statute itself; that terminology sits on the side of METI's trade secret management guidelines5.

Those guidelines (issued 30 January 2003, last revised 31 March 2025) say this about external services.

Furthermore, where an external cloud is used to store and manage a trade secret, secrecy management is not lost provided it is managed as a secret.1

Not lost. That is the starting point. And then the footnote quoted at the top attaches: where the information is provided beyond the company to a third party, such as a generative AI provider, secrecy management may in some cases be denied1.

Put the two side by side and the line becomes clear. It is not "use AI or don't". It is whether the use keeps the information under your own management or hands it to a third party. Read that way, the direction of a fix changes too. Not "stop using it", but "design where the processing happens".

There is also a reassuring point worth writing down: the secrecy measures do not have to be elaborate. The guidelines say that for the requirement to be met, the holder's intention to keep information secret must be clearly shown to employees through management measures and their ability to recognise it must be secured, and then continue: where, given the content and nature of the information, it is obvious that it is important to the holder, technical measures at the level of an ID and password being set for access to the external cloud, or normative measures such as work rules or a written pledge prohibiting leakage, may in some cases suffice1.

You do not have to wait until a perfect system exists. Note too that the guidelines describe themselves as presenting "one way of thinking, without legal binding force", with individual cases ultimately judged in the round by the courts1. On the export control side of drawings, see export control for drawings and design data.

Struggling with AI adoption?

We have prepared materials covering ZEROCK case studies and implementation methods.

A drawing you received is held to a stricter line than your own

This is where the practical danger sits. A drawing you produced and a drawing you received from a customer are not the same thing.

The guidelines published on 24 June 2026 by the Japan Fair Trade Commission, the Small and Medium Enterprise Agency and the Japan Patent Office, on abuse of a superior bargaining position in transactions involving intellectual property, know-how and data, set out what ought to happen:

Where a party learns the other side's confidential information, it shall keep that information strictly confidential and shall not use it, or disclose it to a third party, without obtaining the other side's express prior consent.6

Without express prior consent, no disclosure to a third party. Feeding a drawing you received into a third party's AI service maps onto that structure directly. The dividing line is whether express prior consent exists. When an NDA says "no disclosure to third parties", can you state with confidence that an AI service is not one of those third parties? I do not think I could.

The same guidelines address the pressure running the other way. Parties should not request the other side's know-how beyond what is reasonably necessary in light of the true purpose of the transaction, and should not force the provision of mould design drawings, design and machining data or other technical data that are not the object of the transaction against the other party's wishes6. For anyone being told to hand over drawings, that is the shield.

The guidelines for the casting, forging and related industries (issued June 2007, last revised November 2025) go further on what a mould drawing is: "it has been designed and produced by the mould manufacturer using its own know-how and is intellectual property necessary for mould manufacture. This is not something the commissioning business is inherently entitled to acquire and is, naturally, not an object of sale"7. The legal basis cited is Article 5(2)(ii) of the Act on Appropriate Subcontract Transactions, the prohibition on demanding unjust economic benefits7. Handing over your own drawings is not a given.

The same guidelines set homework for the supplier side too: technical information such as know-how should be managed appropriately in accordance with the trade secret management guidelines, and a structure should be built that satisfies the requirements of secrecy management, usefulness and non-public knowledge so that protection under the Unfair Competition Prevention Act is available7. In other words, earn the standing to be protected.

The real-world numbers are worth a look as well. Japan's National Police Agency recorded 38 cases of trade secret infringement cleared in 2025, up 16 cases or 72.7 per cent on the previous year, the highest in ten years8. The agency's analysis notes that cases where trade secret information is taken out on changing jobs or going independent are frequent8. Drawings do not only leak through external services. They leak when people move.

A "we won't train on it" clause is not enough

With that in place, let me set out where the common measure runs out.

"Check that the contract says uploaded drawings will not be used to retrain the AI." That is a correct measure. Japan's Personal Information Protection Commission asked for exactly this kind of confirmation in its notice of 2 June 2023, that businesses adequately confirm the personal data will not be used for machine learning9. And yet, as the previous section showed, only 19.9 per cent of Japanese companies have made it a mechanism3. Confirmation is asked for, and eight in ten have not built it.

There is a second gap that a contract cannot close: what happens outside the service the company signed for.

METI's handbook on protecting confidential information (issued February 2016, last revised February 2024 as the sixth edition) carries a reference column on AI use. The first leakage scenario it gives is this: a member of staff privately uses a generative AI whose confidentiality terms are inadequate and ends up having information amounting to a trade secret learned by it10. However good the contract the company signed, it is irrelevant if an employee uses a personal account.

IPA points at the same structure. In "10 Major Security Threats 2026", cyber risks around the use of AI entered the organisational ranking at number three, on its first appearance. The first risk item in the commentary is shadow AI: using AI for work without the workplace's permission, with the possibility of information leakage11. What I want to highlight is IPA's account of the cause: where, for instance, there is no AI service available in the workplace, employees use an AI service they use personally for work11.

In other words, not providing one is the trigger. Prohibition is not a solution. Prohibit without providing an alternative and the work moves to personal accounts. A domestic survey found that roughly one in five users of generative AI tools falls into shadow AI, with 45 per cent saying there are no internal rules and 26.7 per cent that they do not know (Eltes, published 13 January 2026, n=300)12.

Scale matters here too. IPA's DX Trends 2026 found that close to 80 per cent of companies with more than 1,001 employees have adopted AI, against 16.6 per cent of those with 101 or fewer13. The smaller the organisation that has not managed to provide something, the more room there is to fall back on personal accounts. On how to face shadow AI, see the reality of shadow AI at 71 per cent; on the general risk of handing data straight to an LLM vendor, are you handing your company's assets to AI unprotected.

Think about where processing happens, in four stages

So what is there to design? My answer is to hold the question of where a drawing gets processed as a set of stages. Not everything has to sit at the strictest one. You separate the stages by what is in the drawing.

Stage one is throwing it straight at a shared external API. Doing nothing is this stage. It sits closest to the "provided to a third party" case in the guidelines' footnote. Sensitive drawings do not belong here.

Stage two is stopping training use through the contract and an opt-out. This is where you turn the Personal Information Protection Commission's "adequately confirm" into a mechanism, and only 19.9 per cent of Japanese companies have got there3. As a floor, this is the one to clear.

Stage three is running it inside your own cloud account. In Microsoft Foundry, for example, open-weight models can be deployed as managed compute onto dedicated VMs within your own subscription. Billing is by VM core hour, and the documentation states that deployment requires quota for that VM product in your own Azure subscription14. The location of the data and the account that owns it move to your side.

Stage four is closing it entirely inside your own infrastructure, including environments cut off from the network. NVIDIA NIM lets you fetch model profiles into a cache on a machine with internet access, transfer that cache into an air-gapped environment, and serve inference without any connection to the registry. The official documentation instructs you not to pass an API key when running air-gapped15. vLLM likewise provides official Docker images for CUDA, ROCm and Intel XPU, and runs as an OpenAI-compatible server on your own infrastructure16.

There is public material to help decide which stage applies, too. The handbook on protecting confidential information lists only two points to consider before sharing confidential information with a trading partner: do not carelessly outsource work that involves confidential information, and check the partner's management capability in advance, the latter with reference to certifications such as ISMS or the Privacy Mark10. Build your AI vendor checklist from those two and it rests on public grounds.

If you run it yourself, look at the constraints first

Here is the reality of stage four. Be optimistic about it and the deployment stops on day one.

Starting with the part that disappoints. The open-weight models OpenAI has released are gpt-oss-120b and gpt-oss-20b, licensed Apache 2.0 and published on Hugging Face on 4 August 2025. Parameters are 117B total with 5.1B active for the 120b, and 21B total with 3.6B active for the 20b17. But these do not take images. As of 28 July 2026, all 39 models on OpenAI's official Hugging Face account are for text generation, and none accepts an image as input to produce text18. If you want drawings read, you are choosing from a different line.

Open-weight models that do accept image input have multiplied through 2026.

Model Licence Size Context Published
Qwen3.5-122B-A10B Apache 2.0 122B total, 10B active 262,144 2026-02-24
Qwen3.6-27B Apache 2.0 27B 262,144 2026-04-21
Gemma 4 31B Apache 2.0 30.7B 256K 2026-03-11
Mistral Small 4 119B A6B Apache 2.0 119B total, 6.5B active 256k 2026-01-23

Licence and specification for each can be checked on the model card19. If you narrow the job to reading document images such as drawings, there are lighter OCR-specialised options: GLM-OCR (MIT, 0.9B, published 30 January 2026), DeepSeek-OCR-2 (Apache 2.0, roughly 3.4B, 27 January 2026) and Unlimited-OCR (MIT, roughly 3.3B, 19 June 2026)20.

One more option is worth knowing about. On 17 April 2026 OpenAI released an open-weight model for PII masking, OpenAI Privacy Filter, under Apache 2.0. It has 1.5B total parameters with 50M active and a 128,000-token context, and the model card states plainly that it is for teams that need a model they can run on premises21. Strip before you send, implemented with a small model. Where not every part of a drawing needs protecting, deciding what to remove before handing it over is a realistic middle path.

Get the GPU estimate wrong and nothing runs. Google's official documentation puts Gemma 4's memory requirement at 69.9GB for 31B in BF16, 57.7GB for 26B A4B, 26.7GB for 12B, 17.9GB for E4B and 11.4GB for E2B; at four-bit quantisation, 17.5GB, 14.4GB, 6.7GB, 4.5GB and 2.9GB22. But as the source states, these estimate only the memory needed to load the static weights and exclude the additional VRAM required for the context window22.

The mixture-of-experts trap is worth holding onto as well. Gemma 4's 26B A4B activates only 4B parameters per token, yet the documentation states that all 26 billion must be held in memory to preserve routing and inference speed22. Size the GPU off the active parameter count and it will not start.

The idea of bringing your own weights into a managed service can also stop on specification. Amazon Bedrock Custom Model Import supports four regions, eu-central-1, us-east-1, us-east-2 and us-west-2, with Tokyo not listed. Imported weights must be under 100GB for a multimodal model, and the maximum context length the model supports must be under 128K23. Look at the table above and 256K is the standard for current image-capable models. Combine that with a domestic-region requirement and some combinations simply do not go through.

And the operational responsibility lands on you. Microsoft's documentation states that models from partners and the community are typically validated by the providers themselves, with support and maintenance managed by each provider. On managed compute deployments, the safety filter is not integrated into the inference API the way it is for serverless deployments; you call the content safety API yourself14. Gemma 4's model card likewise recommends that developers implement content safety measures appropriate to their own product policy and use case, and records a pre-training data cutoff of January 202519. The structure is the same one I wrote about the other day in open-weight AI and cyber defence. Choosing to hold it yourself comes bundled with a decision to take on the operational load. For a comparison of existing tools that run on domestic servers, see comparing high-security AI agents.

ZEROCK, the service we offer, is built around stages three and four for manufacturers. Drawings are stored encrypted on domestic AWS servers, and customer drawings are never used to retrain the AI. When no longer needed they are completely deleted within seven days and a deletion certificate is issued (ISMS-compliant). Past drawings and cost records connect through a knowledge graph, all inside the company. Let me be honest about the order, though: first decide which stage each of your drawings belongs to. Tooling comes after that decision.

To sum up

The points, gathered up.

  • In the FY2026 Information and Communications White Paper, the top concern of Japanese companies about generative AI is security risk such as leakage of internal information, at 46.4 per cent, the highest of the four countries, while ethics at 24.7 and privacy at 24.5 are the lowest. The anxiety is concentrated on the information leaving the building
  • The worry has not turned into controls. Only 19.9 per cent have a mechanism preventing input from being used as training data (32.2 in the United States, 34.1 in Germany, 47.8 in China). Use has reached 86.4 per cent while only 24.5 per cent have made internal data referenceable
  • The state is not saying "no AI". The trade secret management guidelines say secrecy management is not lost on an external cloud provided it is managed as a secret, and add in a footnote that where the information is provided to a third party, giving generative AI providers as an example, it may in some cases be denied. The line is your own management versus provision to a third party
  • The guidelines also say the measures need not be elaborate. Where the importance of the information is obvious, technical measures at the level of an ID and password plus normative measures such as work rules or a written pledge may suffice
  • Treat a drawing received from a customer more strictly. The guidelines of 24 June 2026 set out, as what ought to happen, no disclosure of the other side's confidential information to a third party without express prior consent
  • A "no retraining" clause is necessary but shadow AI happens outside the company's contract. IPA attributes the cause to there being no AI service available in the workplace: not providing one is the trigger
  • Hold four stages for where processing happens (a shared external API, contract plus opt-out, your own cloud account, and your own infrastructure or air-gapped), and use them according to what is in the drawing
  • If you run one yourself, look first at the fact that OpenAI's gpt-oss does not take images, that GPU memory estimates exclude the context window, that a mixture-of-experts model still needs all parameters in memory, and that bringing weights into a managed service comes with region and context-length constraints

One last thought. I expect the gap to widen between companies stuck at "we can't put drawings into an AI" and companies that have set the stages and started with a subset. The first group ends up losing to employees' personal accounts. The second has decided for itself how far things may travel.

What decides it is not technology but policy. Start by sorting your drawings into three piles: ones it would not hurt to send out, ones you could send with a contract in place, and ones that never leave the building. Once that sorting exists, all that remains is matching each pile to a stage. If you would like to work through a design that keeps drawings and cost inside your own company, please talk to the ZEROCK team. We can start from the sorting.

References and primary sources

Footnotes

  1. Ministry of Economy, Trade and Industry, "Trade Secret Management Guidelines", issued 30 January 2003, last revised 31 March 2025. Under secrecy management, examples of management measures for electronic media, it states that where an external cloud is used to store and manage a trade secret, secrecy management is not lost provided it is managed as a secret, and that where the importance of the information is obvious, technical measures at the level of an ID and password for cloud access, or normative measures such as work rules or a written pledge prohibiting leakage, may in some cases suffice. Footnote 24 reads that where the information is provided beyond the company to a third party other than the company (for example a generative AI provider or similar), there may be cases in which secrecy management is denied. The introduction states that the guidelines present one way of thinking and have no legal binding force. https://www.meti.go.jp/policy/economy/chizai/chiteki/guideline/r7ts.pdf 2 3 4 5

  2. Ministry of Internal Affairs and Communications, "FY2026 Information and Communications White Paper", appendix. Valid responses to the corporate survey were 515 in Japan (353 large companies, 162 small and medium), 309 each in the United States, Germany and China, 1,442 in total. Fieldwork ran from January to February 2026 as an internet survey. https://www.soumu.go.jp/johotsusintokei/whitepaper/ja/r08/pdf/01fuchuu.pdf

  3. Ministry of Internal Affairs and Communications, "FY2026 Information and Communications White Paper", published 24 July 2026. Exhibit I-2-1-8, risks of concern in using generative AI by country: Japan reports security risk such as leakage of internal information at 46.4 per cent (United States 36.9, Germany 31.7, China 42.7), ethically inappropriate content or bias at 24.7 (38.5, 35.9, 45.0) and invasion of privacy at 24.5 (38.2, 44.0, 43.4). Exhibit I-2-1-9, risk measures: Japan reports company-wide policies or guidelines at 41.1 per cent and a mechanism preventing input from being used as training data at 19.9 per cent (United States 32.2, Germany 34.1, China 47.8). Exhibit I-2-1-3: "no organisational effort" is 27.0 per cent in Japan (18.1 for large companies, 45.6 for small and medium; the base for this exhibit excludes respondents who said generative AI use is prohibited). https://www.soumu.go.jp/johotsusintokei/whitepaper/ja/r08/pdf/n1210000.pdf 2 3 4 5 6

  4. Ministry of Internal Affairs and Communications, "FY2026 Information and Communications White Paper", summary. The share of Japanese companies using generative AI in some part of their own work is 86.4 per cent (55.2 in the FY2024 survey; the base excludes respondents who answered "don't know" on the question about their approach to generative AI). The share that has had generative AI learn from internal data or built a database the AI can reference is 24.5 per cent in Japan, which the white paper notes is markedly lower than in the other three countries. https://www.soumu.go.jp/johotsusintokei/whitepaper/ja/r08/summary/summary01.pdf

  5. Unfair Competition Prevention Act (Act No. 47 of 1993), Article 2(6): a trade secret means technical or business information useful for business activities, such as manufacturing methods or sales methods, which is kept secret and not publicly known. The statute itself does not contain the terms "secrecy management", "usefulness", "non-public knowledge" or "three requirements"; that terminology is used on the side of METI's trade secret management guidelines and similar documents. https://laws.e-gov.go.jp/law/405AC0000000047 2

  6. Japan Fair Trade Commission, Small and Medium Enterprise Agency and Japan Patent Office, "Guidelines on abuse of a superior bargaining position and related conduct for appropriate transactions in intellectual property rights, know-how and data", 24 June 2026. Under information management, on the handling of confidential information and the conclusion of NDAs, the section on what ought to happen states that a party learning the other side's confidential information shall keep it strictly confidential and shall not use it, or disclose it to a third party, without obtaining the other side's express prior consent. On the handling of know-how it states that parties should not request the other side's know-how beyond what is reasonably necessary in light of the true purpose of the transaction, and should not force the provision of mould design drawings, design and machining data or other technical data that are not the object of the transaction against the other party's wishes. https://www.jftc.go.jp/houdou/pressrelease/2026/jun/260624_chizaitorihiki2.pdf 2

  7. Ministry of Economy, Trade and Industry, guidelines for promoting appropriate contracting transactions in the casting, forging and related materials industries, issued June 2007, last revised November 2025. Chapter 2, section 13 on the outflow of drawings and know-how, states that a mould drawing has been designed and produced by the mould manufacturer using its own know-how and is intellectual property necessary for mould manufacture, that this is not something the commissioning business is inherently entitled to acquire and is naturally not an object of sale, and cites Article 5(2)(ii) of the Act on Appropriate Subcontract Transactions (prohibition on demanding unjust economic benefits). The section on target practices states that supplier firms should manage technical information such as know-how in accordance with the trade secret management guidelines and build a structure satisfying the requirements of secrecy management, usefulness and non-public knowledge so as to receive protection under the Unfair Competition Prevention Act. https://www.meti.go.jp/policy/mono_info_service/mono/sokeizai/pdf/sokeizaiguideline202511.pdf 2 3

  8. National Police Agency, Community Safety Bureau, "On the clearance of economic crimes affecting daily life in 2025", March 2026. On trade secret infringement it states that 38 cases were cleared in 2025, up 16 cases or 72.7 per cent on the previous year, and that cases where trade secret information is taken out on changing jobs or going independent are frequent. The figure of 38 is the highest in the ten-year series. https://www.npa.go.jp/publications/statistics/safetylife/2026_nenpou_teisei.pdf 2

  9. Personal Information Protection Commission, notice on the use of generative AI services, 2 June 2023. Asks that when handling personal data, businesses adequately confirm that the personal data will not be used for machine learning. Reviewing the commission's list of notices, this remains the most recent notice specifically addressing generative AI as of July 2026. https://www.ppc.go.jp/news/careful_information/230602_AI_utilize_alert/

  10. Ministry of Economy, Trade and Industry, "Handbook on the Protection of Confidential Information", issued February 2016, last revised February 2024 (sixth edition, 29 February 2024). A reference column in Chapter 1 on AI use from the standpoint of protecting confidential information gives, as one leakage scenario, a member of staff privately using a generative AI whose confidentiality terms are inadequate and having information amounting to a trade secret learned by it. Chapter 3, on measures directed at trading partners, lists two points to consider before starting a transaction: do not carelessly outsource work involving confidential information, and check the partner's management capability in advance with reference to certifications such as ISMS or the Privacy Mark. https://www.meti.go.jp/policy/economy/chizai/chiteki/pdf/handbook/full.pdf 2

  11. IPA, "10 Major Security Threats 2026", decided 29 January 2026, with the commentary for organisations issued March 2026. Cyber risks around the use of AI entered the organisational ranking at number three on their first appearance. The first risk item in the commentary is using AI for work without the workplace's permission, with the possibility of information leakage (shadow AI), explained as employees using an AI service they use personally for work where, for instance, no AI service is available in the workplace. https://www.ipa.go.jp/security/10threats/10threats2026.html 2

  12. Eltes Co., Ltd., survey on the actual state of generative AI use, published 13 January 2026 (n=300). Roughly one in five users of generative AI tools falls into shadow AI; 6.8 per cent have entered data containing personal information; 45 per cent say there are no internal rules and 26.7 per cent do not know. A private survey with a limited sample. https://eltes.co.jp/

  13. IPA, "DX Trends 2026" (fieldwork 17 April to 12 June 2026, 1,799 companies). Close to 80 per cent of companies with more than 1,001 employees have adopted AI, against 16.6 per cent of those with 101 or fewer. The full report and data set were stated to be scheduled for release in late July 2026, so the breakdown by industry was not available at the time of writing. https://www.ipa.go.jp/digital/chousa/dx-trend/index.html

  14. Microsoft, "Foundry Models overview", updated 20 April 2026. Open-weight models can be deployed as managed compute onto dedicated VMs within your own subscription, billed by VM core hour, with quota for the VM product required in your own Azure subscription. Models from partners and the community are typically validated by the providers themselves, with support and maintenance managed by each provider, and on managed compute deployments the safety filter is a matter of calling the Azure AI Content Safety API yourself rather than being integrated into the inference API. https://learn.microsoft.com/en-us/azure/ai-foundry/concepts/foundry-models-overview 2

  15. NVIDIA, "Deploy NIM in an Air-Gapped Environment". Model profiles can be fetched into a cache on a machine with internet access and that cache transferred into an air-gapped environment, serving inference without any connection to the NGC registry; the documentation instructs that NGC_API_KEY not be passed when running air-gapped. https://docs.nvidia.com/nim/large-language-models/1.4.0/deploy-air-gap.html

  16. vLLM, "Using Docker". Official Docker images are provided for NVIDIA CUDA (vllm/vllm-openai), AMD ROCm (vllm/vllm-openai-rocm) and Intel XPU (vllm/vllm-openai-xpu, from 0.26.0), running as an OpenAI-compatible server. https://docs.vllm.ai/en/latest/deployment/docker.html

  17. OpenAI, "gpt-oss-120b" Hugging Face model card. Licensed Apache 2.0, published on Hugging Face 4 August 2025. Parameters are 117B total with 5.1B active for gpt-oss-120b and 21B total with 3.6B active for gpt-oss-20b. https://huggingface.co/openai/gpt-oss-120b

  18. Verified through the Hugging Face API on 28 July 2026. Retrieving the pipeline_tag for all 39 models on the OpenAI account, including gpt-oss-120b, gpt-oss-20b, gpt-oss-safeguard-120b and gpt-oss-safeguard-20b, every one was text-generation, and no image-text-to-text model was present. https://huggingface.co/api/models?author=openai&sort=createdAt&direction=-1&limit=30

  19. Hugging Face model cards for each model. Qwen3.5-122B-A10B (Apache 2.0, 122B total with 10B active, 262,144-token context, published 24 February 2026) https://huggingface.co/Qwen/Qwen3.5-122B-A10B ; Qwen3.6-27B (Apache 2.0, pipeline_tag image-text-to-text, 27B, 262,144 tokens, published 21 April 2026) https://huggingface.co/Qwen/Qwen3.6-27B ; Gemma 4 31B (licence apache-2.0, 30.7B total, 256K context, text and image modalities, published 11 March 2026, with a pre-training data cutoff of January 2025 and a statement that developers are recommended to implement content safety measures appropriate to their own product policy and use case) https://huggingface.co/google/gemma-4-31B-it ; Mistral Small 4 119B A6B (Apache 2.0, 119B total with 6.5B active per token, 256k context, image input supported, published 23 January 2026) https://huggingface.co/mistralai/Mistral-Small-4-119B-2603 2

  20. OCR-specialised open-weight models. GLM-OCR (MIT, 0.9B per the model card, published 30 January 2026) https://huggingface.co/zai-org/GLM-OCR ; DeepSeek-OCR-2 (Apache 2.0, approximately 3.39B measured, published 27 January 2026); Unlimited-OCR (MIT, approximately 3.34B measured, published 19 June 2026)

  21. OpenAI, "Privacy Filter" Hugging Face model card, published 17 April 2026. Licensed Apache 2.0, 1.5B total parameters with 50M active and a 128,000-token context. The model card states that it is for teams that need a model they can run on premises. https://huggingface.co/openai/privacy-filter

  22. Google, "Gemma core models" official documentation. Memory requirements are 69.9GB for 31B, 57.7GB for 26B A4B, 26.7GB for 12B, 17.9GB for E4B and 11.4GB for E2B in BF16, and 17.5GB, 14.4GB, 6.7GB, 4.5GB and 2.9GB respectively at four-bit quantisation (Q4_0). The source states that these estimate only the memory needed to load the static weights and exclude the additional VRAM required for supporting software and the context window. For 26B A4B it states that although only 4B parameters activate per token, all 26 billion must be held in memory to preserve routing and inference speed. https://ai.google.dev/gemma/docs/core 2 3

  23. AWS, "Import a customized model into Amazon Bedrock". Supported regions are eu-central-1, us-east-1, us-east-2 and us-west-2. Imported weights must be under 100GB for a multimodal model and under 200GB for a text model, and the maximum context length the model supports must be under 128K. https://docs.aws.amazon.com/bedrock/latest/userguide/model-customization-import-model.html

Ready to optimize your workflows with AI?

Take our free 3-minute assessment to evaluate your AI readiness across strategy, data, and talent.

Share this article if you found it useful

Share

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

Learn More About ZEROCK

Discover the features and case studies for ZEROCK.

Related Articles