“With Apertus, we offer a high-performance alternative to U.S. and Chinese providers”
You made Apertus available to the public in September 2025. What conclusion have you reached since the launch? And how did users and the open-source community react?
We’re pleasantly surprised. The models have already been downloaded more than 2.5 million times. And that is even more impressive given that a single model ranges from several dozen to hundreds of gigabytes in size. International users have responded very positively, too. They really like the idea of having a fully open and transparent model.
You mentioned the download numbers. Do you have any figures on actual usage? For example, any numbers that show how widely companies are using Apertus, or how many productive applications there are?
Since Apertus is open source, we cannot track its use completely. However, we do see specific examples: For example, the administration of the Canton of Ticino is using Apertus productively. The Federal Supreme Court in Lausanne is running a pilot program, and so is the City of Zurich (oss.zuericitygpt.ch). The University of Göttingen in Germany, as well as ETH and EPFL, among others, is using it in applications. In addition, there are already more than 100 scientific publications based on Apertus.
Why did you decide to develop Apertus? What gap in the LLM ecosystem do you want to fill?
Unfortunately, at the moment, commercial AI systems like Claude and ChatGPT are black boxes developed behind closed doors. We see Apertus as an alternative to them: It may not be quite as powerful as the leading commercial models, but it is trained responsibly and fully transparent and traceable. This makes Apertus particularly well suited for sensitive applications, such as those in the public sector. But in fact, it is ideal for any setting where data security and independence are critical and organizations do not want to rely on providers from the United States or China. After all, organizations can host the model themselves and retain full control over the data. But fundamentally, Apertus is a general AI model that organizations can use for many different applications.
You mentioned in an interview that you will update the foundation model regularly. Apertus is currently based on data up to the spring of 2024. How will you keep the model up to date in the future, and what role do computing power and funding play in this?
We plan to release a new version twice a year going forward: Firstly, we will enhance the existing model. This summer’s update, for example, will include options for inputting images and audio. Secondly, we will release a completely new and more robust foundation model toward the end of the year. It will have a mixture-of-experts architecture. Having a completely up-to-date knowledge base during training is less important: Modern AI systems rely on web searches and other tools when they need up-to-date information.
You trained Apertus exclusively on legal data. How do you obtain this training data, and how do you decide which data to include and how to weight it?
We only use publicly available data for training, and we respect websites’ opt-out requests. To do this, we follow the established Robots Exclusion Protocol, which is already used to give instructions to search engines. When we are deciding on the weighting, we make sure that the languages are not competing against each other. Instead, we try to reflect Switzerland’s linguistic diversity as broadly as possible.
“At the moment, commercial AI systems like Claude and ChatGPT are black boxes developed behind closed doors. We see Apertus as an alternative to them: It may not be quite as powerful, but it is trained responsibly and fully transparent and traceable.”– Martin Jaggi
Other LLMs have access to much bigger datasets – some of which are not publicly available. What’s more, these LLMs benefit from years of optimization and fine-tuning. Can fully legal and transparent models like Apertus compete with them in terms of performance?
In the AI field, we make a distinction between openweight models and open-source models. An open-weight models means that the trained parameters are released publicly, but not the training data. Currently, open-weight models such as DeepSeek are only a few months behind the commercial frontier models. For a model to be completely open source – like Apertus – the training data must also be released. These open-source models are a few months behind the open-weight models at the moment. However, I firmly believe that the open-source community can continue to narrow this gap. When you are comparing the performance of different AI models, you’ve got to make sure you are comparing similar criteria. Apertus is the only modern model of this size that is both open source and open weight. Other models are only open weight and do not release their training data. However, in terms of accessibility, adaptability, and practical use, Apertus is the same as open-weight models.
What are the challenges of maintaining and further developing an open-source model? And how can the community help with this?
The main challenge at the moment is keeping up with rapid technological advancements, especially as they continue to accelerate. However, the spirit of collaboration within the global open-source community is really strong. This makes me optimistic that we will continue to keep up. However, there is a clear need for even more international collaboration: for example, when it comes to sharing and using expensive GPU computing power efficiently.
Fairness and transparency are key priorities for Apertus. How do you deal with hallucinations, misinformation, and bias? And what measures do you have in place to prevent abuse, such as users generating harmful content?
Hallucinations have already decreased significantly. More intelligent models and using tools such as web search more widely have both contributed to this. However, the question of how well AI systems align with human values still poses a major problem. Individual commercial providers should not decide this on their own. It’s a question of reflecting the perspectives and values of broader segments of the population. After all, we are all affected by AI. And this question is just as relevant in Switzerland and Europe. To achieve this, we need a public discussion that really analyzes the risks and underlying mechanisms of AI. We hope that Apertus can help make that happen.
Regardless of the language of the data source: How does weighting work with such large amounts of data? Is the quality indexed and then weighted accordingly?
LLMs learn remarkably well directly from raw data, even without special weighting or filtering. However, we use smaller machine learning classifiers to select only approximately the best third of the raw data. An additional classifier is used to remove problematic or toxic content based on transparently defined criteria.
ti&m Special “Digital Sovereignty”