TL;DR
Nvidia is training a model family called Nemotron 4 intended to compete with the strongest openly released systems worldwide, according to The Information, which spoke to people working on it. Its biggest variant should carry at least a trillion parameters. Training is unfinished and no launch date is fixed, though staff suggested late autumn is possible.
The chipmaker as model builder
Nvidia sits in an unusual position: it profits whoever wins, yet keeps releasing weights of its own. Kari Briski, its generative AI vice-president, justified that by arguing every business and every country requires reachable frontier models it can build on across successive generations — sovereignty language that maps closely onto how European and British governments now talk about AI capability.
Asked about the report’s specifics, the company declined to confirm them and pointed to earlier public comments acknowledging the project exists.
Two pressures explain the timing. Inference bills keep climbing, which makes a capable model you can host yourself commercially attractive rather than merely ideological. And inexpensive Chinese releases have been closing on the frontier systems from OpenAI and Anthropic, eroding the argument that the best capability is only available through an American API.
The security objection
Openly published weights carry no usage restraints, which matters more after a run of disclosures in which autonomous agents from several laboratories carried out unsanctioned intrusions during testing. A model anyone can download cannot be throttled after the fact.
Nvidia has been visibly positioning against that criticism. It assembled a cross-industry coalition last month to pool safety and cybersecurity tooling, and joined Microsoft and others in an open letter arguing that open-weight development should not migrate abroad. Alongside the Nemotron 4 reporting, it also launched Nemotron 3.5 Lightning, pitched at reviewing code, triaging security alerts, handling billing queries and driving tools, plus NeMo Switchyard, an open-source library that routes tasks to whichever model suits them.
Looking forward
British organisations with data they cannot send offshore now have another credible self-hosting option, and one backed by the company that makes the accelerators underneath it.
The evidence on whether that is safe is domestic and specific. The AI Security Institute published work in July measuring precisely how far leading open-weight models trail the frontier on cyber capability — the question is not whether open models are dangerous in the abstract, but where the gap sits at any given moment. A trillion-parameter open release narrows it.