My understanding is that ML model weights cannot be copyrighted as an original creative work. They are trade-secrets and protected through contracts but once leaked to third parties it’s not a copyright violation to use/distribute.
Whether the model is actually a derivative work of the training data is another interesting question.
Or is my theory off here?