Open weights can't be locked, so ownership is proven by counting surviving fingerprints. Embed thousands of secret key-response pairs; an adversary fine-tunes to scrub them and each audit burns one to leakage. Watch the reserve survive — or not.
You can copy open model weights bit-for-bit, so on-chain ownership can't be cryptographically enforced — only proven. Sentient's answer: fine-tune 24,576 secret key-response fingerprints into the weights and make scale the security parameter.