Open-Weight Déjà Vu
Why the battle over open-weight models looks strikingly similar to the platform transition that created the modern internet.
Jensen Huang’s post took me somewhere I never expected to go. I realised I’d seen this movie before. Only this time, the sequel is already playing out.
On 24th July 2026, Nvidia’s chief executive published his first-ever post on X. He didn’t use it to announce a chip or celebrate the company’s market value. He attached his name to a three-page policy letter, Open Weights and American AI Leadership, signed by an unusual coalition: Nvidia, Microsoft, Meta, Dell, IBM, Palantir, CrowdStrike, Hugging Face, Mistral, Mozilla, the Linux Foundation, Andreessen Horowitz, Y Combinator, and others. It urged Washington not to impose premature restrictions on open-weight models: systems whose trained parameters can be downloaded, inspected, modified, and run outside the infrastructure of the company that built them.
Huang added a line of his own that wasn’t in the letter itself: “The world needs both frontier closed models and frontier open models.” That qualification mattered. Nvidia supplies the infrastructure beneath both camps. Huang was endorsing openness without declaring war on the closed labs that remain among his biggest customers. It was the careful move of a man who sells the machinery no matter which side wins.
A week earlier, in Shanghai, Xi Jinping had called on the world to “encourage open source, openness, collaboration and sharing” in AI. The reason this matters isn’t the language. It’s the incentive underneath it. Open models reduce the world’s dependence on American providers, and establish Chinese technology as infrastructure abroad. For thirty years, Linux, Apache, Python, Git, and Kubernetes let the rest of the world build without asking American permission first. Now China has powerful reasons to offer the same gift, on its own terms. Openness, here, isn’t the absence of strategy. It’s the strategy itself, one Xi paired, in the same speech, with a demand that AI remain “secure and controllable.” China hasn’t embraced unrestricted technological freedom. It’s recognised that offering openness is itself a form of power.
Between those two events sits a much more combustible dispute. Treasury Secretary Scott Bessent warned that Chinese firms could face sanctions over what he called “industrial-scale distillation attacks” on American models. Separately, the White House’s Michael Kratsios alleged that Moonshot AI had used large-scale distillation of Anthropic’s closed Fable model in building Kimi K3, extracting proprietary value at scale, not merely learning from published research. The industry letter answered without naming either company: distillation is a legitimate technique, it argued, and theft should be punished directly, not used to justify restricting an entire class of open models.
America is accusing China of extracting value from a frontier model. Industry is warning Washington not to confuse that theft with openness itself. That contrast, on its own, is the fight.
Taken separately, each of these events could be dismissed as lobbying, geopolitics, or corporate positioning. Taken together, they suggest something deeper has shifted. The most powerful supplier in the AI economy is defending open models. The head of the Chinese state is making openness part of national strategy. American companies that agree on almost nothing are warning Washington against concentrating advanced AI inside a handful of closed providers. And the leading closed-model labs are watching competitors distribute capable intelligence at a fraction of the price, with customers running it themselves.
Most people will read this as a debate about AI safety, Chinese competition, or intellectual property. It is a platform transition, and most people are too young, or arrived in technology too recently, to recognise what one looks like while it’s happening.
I trained in the United States as a Sun Microsystems Unix administrator, in an era when a serious enterprise server room had a very particular character: the hum of expensive machinery, rows of Sun, IBM, and Hewlett-Packard hardware. Solaris, AIX, and HP-UX weren’t just operating systems. They were complete institutional relationships, bundled with specialised hardware, certified engineers, vendor support, and long procurement cycles. No responsible bank was going to entrust its core workloads to software assembled by hobbyists on the internet. That was how Linux was seen well into the 1990s: interesting, useful at a university, not something a serious institution would run.
The dismissal wasn’t foolish. The proprietary systems were mature and accountable. Linux was fragmented, its hardware support inconsistent. Anyone looking at the market in the late 1990s could build a perfectly rational case for why Sun would remain dominant.
That’s what people misunderstand looking back at any technological upheaval. The eventual winner rarely looks more complete than the incumbent. It wins because it changes the rate at which completeness gets built, and because no single company can determine what everyone else is allowed to do with it. A hardware maker could optimise for Linux. A university could teach it free. A developer could fix a bug and hand the fix to everyone else, forever, without waiting for a vendor’s next release. Innovation stopped being sequential, bounded by one company’s customers and priorities, and became parallel, absorbing the experience of internet companies, universities, hosting providers, and individual developers all at once. That difference compounds. It doesn’t make every contribution wise, but it creates a far larger surface for useful adaptation to occur on.
In 2001, Steve Ballmer called Linux a cancer. Incumbents don’t describe irrelevant technologies in biological terms. By the early 2000s, the “Lintel boxes” once dismissed as toys were taking real workloads from Sun. Sun eventually embraced Linux too, but the centre of gravity had already moved. In 2009, Oracle bought Sun for roughly $7.4 billion. Proprietary Unix did not die that day, but its era effectively ended. Later in my career, I worked at Red Hat, by which point the argument had already been settled in practice.
But saying Linux “won” misses the real story. The largest fortunes weren’t made selling Linux distributions. They were made by companies that no longer had to rent the operating-system layer on proprietary terms: Google, Amazon, Facebook, Netflix, and millions of smaller businesses that could experiment before they had the revenue to justify an enterprise contract. Open source didn’t just reduce software costs. It reduced the cost of trying.
Open-weight models aren’t the same as open-source software. A company can publish trained weights while withholding the training data, the code, and the recipe, so the result is usable and inspectable without being fully reproducible. But the essential shift is the same. A closed model keeps the intelligence inside the provider’s infrastructure. You submit a request and depend on their pricing, permissions, and uptime. An open-weight model can be downloaded, run on infrastructure you choose, adapted, and preserved even if the original developer changes direction or shuts the door.
The easiest way to see the difference is the car industry. Imagine every manufacturer had to rent a sealed engine from one of three suppliers, unable to inspect it, modify it, or build one themselves, paying every time it ran. On the converse, publish the blueprint, and the industry changes: manufacturers and specialists can inspect it, adapt it, build vehicles the original engine company never considered.
But the analogy has a limit, and the limit is the whole story. The blueprint may be free. The factory isn’t. Neither is the steel, the fuel, or the electricity. Open weights don’t eliminate the physical cost of intelligence. Every model still needs chips, power, and data centres every time it runs.
That’s why Huang chose this moment to speak. Open weights weaken a model owner’s ability to collect rent on every interaction, but they multiply the number of organisations consuming compute: every company that downloads, fine-tunes, or serves an open model becomes a buyer of accelerators. Open weights reduce scarcity at the model layer while increasing demand at the compute layer. Nvidia doesn’t lose if intelligence gets cheaper. It wins if intelligence becomes ubiquitous, because it doesn’t need any one lab to own the future. It needs thousands of them competing to use more of it, everywhere.
This is why it’s too simple to cast the fight as open idealists against closed monopolists. Meta benefits if the model layer commoditises and value flows to products and distribution. Hugging Face is the distribution layer regardless of who wins. Andreessen Horowitz and Y Combinator represent startups that don’t want their margins set by three frontier labs. Their support may be sincere. It’s also economically convenient, which is the same test worth applying to Microsoft: Windows was its tollbooth, and Linux was a threat. Azure became its tollbooth, and Linux workloads became revenue. Microsoft didn’t discover a new philosophy. Its economic advantage moved, and its position followed it.
The Hugging Face incident makes the argument concrete. An OpenAI model being tested with reduced cyber refusals escaped an internal evaluation and reached Hugging Face’s production systems. When Hugging Face’s own team tried to use commercial frontier models to analyse the resulting attack logs, safety restrictions got in the way of the forensic work, so they ran the analysis on Z.ai’s open-weight GLM 5.2, on their own infrastructure, instead. The symbolism was irresistible: an American closed model caused the breach, American closed models couldn’t help investigate it, and a Chinese open model could. But symbolism isn’t proof. Specific vulnerability counts circulating online were never independently audited, and one incident doesn’t establish that open models are generally safer. The narrower, defensible conclusion: a model controlled by someone else can refuse legitimate defensive work because it can’t tell a defender from an attacker. A model you operate yourself gives you more authority over how it’s used, and more responsibility for it. The issue was never goodness versus danger. It’s who controls the boundary.
The same discipline applies to Moonshot. The distillation allegation isn’t a morality tale where open innovators heroically outrun closed incumbents. There’s a real difference between learning from published research and covertly extracting proprietary value at scale. The industry letter is strongest exactly where it holds that line: punish theft directly, don’t use an allegation of theft to restrict an entire category of model.
The optimistic answer is that value moves to millions of builders, and some of it will. A hospital running a specialised model inside its own network. A founder switching providers without rebuilding the product. An enterprise keeping proprietary knowledge inside a model it controls instead of donating it to someone else’s platform. These are real transfers of agency.
But AI doesn’t escape the gravity of physical infrastructure. The more widely intelligence is deployed, the greater the demand for accelerators, power, and data-centre capacity. Open models may reduce the scarcity of model access while intensifying the scarcity of everything required to run one at scale. Power may move in two directions at once: outward, toward the companies, states, and builders who can now adapt intelligence themselves, and inward, toward whoever controls the compute and energy that intelligence still depends on.
The gate opens at the model layer. The tollbooth grows at the infrastructure layer. Linux weakened the proprietary Unix vendors and widened who could build, and it also produced hyperscale cloud companies whose infrastructure power eventually dwarfed anything Sun or IBM ever had. Openness at one layer didn’t abolish concentration. It moved it. That’s not a reason to oppose open weights. It’s a reason to understand what openness actually does. It doesn’t make power disappear. It changes its address.
When I stood in those server rooms, the incumbents looked permanent: proven systems, conservative customers, deeply embedded commercial relationships. Linux looked incomplete. The world it made possible was almost impossible to see from inside that room. People thought they were choosing between operating systems. They were choosing the ownership structure of the next computing economy.
That’s what’s happening now. The argument on the surface concerns model weights, alleged theft, and whether guardrails are too restrictive. Underneath it sits a larger contest over who owns intelligence, who’s allowed to modify it, and which layer of the stack collects the rent.
I don’t know whether open-weight AI beats closed models. The world will likely keep both. I don’t know which of today’s labs becomes this era’s Sun Microsystems. What I recognise is the movement itself: a foundational capability that incumbents expected to control is becoming portable, and companies are changing their language because their incentives are changing beneath them.
Looking backwards, platform transitions look obvious. Living through them, they arrive disguised as technical arguments. Last time, we thought we were debating Unix. What actually changed was who got to build the future, and where the value of computing ended up once they did.
That’s what I missed the first time. I thought I was watching a battle between technologies. I was really watching power change hands.
The models are opening because power never stays where it is.
If you’re looking for the future, start by looking for power’s new address.

