The Case Against Open AI Weights Already Lost Once — It Was Called Open Source
July 24, 2026 · 8 min read
In 2001, the CEO of Microsoft described Linux as something like a disease — a licensing model that infected everything it touched and destroyed the intellectual property around it. He wasn't a fringe voice. He was running the most powerful software company on earth, and he was saying out loud what most of the industry's executives, lawyers, and lobbyists believed: freely available, modifiable code was a threat to innovation, a threat to security, and a threat to American software leadership.
Twenty-five years later, Microsoft ships its own Linux distribution. It owns GitHub, the largest repository of open code in existence. Its cloud business — the thing that actually carries the company now — runs a staggering share of its workloads on the operating system its CEO once compared to a pathogen. And on July 24, 2026, Microsoft's name appeared alongside NVIDIA, Meta, IBM, Palantir, Mozilla, Hugging Face, and a couple dozen other companies on a joint statement arguing that freely available AI model weights are essential to American innovation, competition, security, and leadership.
I want to dwell on that arc, because we are currently having the exact same fight about AI models that we had about software, and almost nobody arguing about it seems to remember how the last one ended.
Every Argument Against Open Weights Is a Rerun
Spend a week reading the case against open-weight models — the op-eds, the think-tank papers, the more excitable Congressional testimony — and then go read what was written about open-source software between roughly 1999 and 2005. The overlap is not thematic. It is nearly clause-for-clause.
"It hands our technology to adversaries." This was the argument for treating encryption software as a munition in the 1990s, and it was the argument against open code generally: if anyone can download it, so can China, so can criminals. Today it's the lead argument against releasing model weights. The structure is identical — take a general-purpose technology, note that bad actors are a subset of "everyone," and conclude that "everyone" should be cut off.
"You can't secure what anyone can inspect." Security through obscurity was respectable doctrine once. Proprietary vendors argued, with straight faces, that publishing source code was like publishing the blueprints to your locks. Open-weight skeptics say the same thing about models: if attackers can probe the weights, they can find the jailbreaks, strip the safety training, extract the capabilities.
"It destroys the incentive to invest." Why would anyone spend billions building software — or training frontier models — if the results get given away? This one was supposed to kill open source commercially. Instead, open source became the foundation on which the most profitable technology companies in history were built.
"It's fine for toys, but serious institutions need a vendor." Nobody ever got fired for buying the proprietary option. Linux was for hobbyists; real enterprises ran certified, supported, closed systems. Swap the nouns and you have today's conventional wisdom that open models are for tinkerers while real work happens behind commercial APIs.
I'm not claiming the AI versions of these arguments are made in bad faith. Some of them, in narrow forms, identify real tradeoffs — the book I've just written spends whole chapters taking the strongest versions seriously, particularly around the extreme frontier. But the pattern should give everyone pause. When an argument has been deployed before, against a structurally similar technology, by people with structurally similar incentives, and it turned out to be not just wrong but backwards — the burden of proof shifts. It is no longer enough to assert the risk. You have to explain why this time is different.
How the Last Fight Actually Ended
It's worth being precise about the verdict, because "open source won" undersells it.
Open source didn't merely survive the assault. It became the invisible substrate of everything. The internet runs on it — Linux, nginx, Apache, OpenSSL, the DNS infrastructure. Every smartphone runs a kernel descended from it. Every cloud provider's data centers are built on it. The machine learning revolution itself happened inside open source: PyTorch, TensorFlow, Kubernetes, the entire Python scientific stack. The frontier AI labs whose closed models are held up as the alternative to openness train those models on open-source infrastructure, orchestrate them with open-source schedulers, and serve them behind open-source web servers. There is no closed-model empire that is not standing on an open foundation.
The security argument didn't just lose — it inverted. The consensus among practitioners flipped so completely that "security through obscurity" became a term of derision. Heavily inspected open code, with thousands of independent eyes and adversarial researchers probing it, proved more durable than closed code audited only by its vendor. Vulnerabilities in open systems get found, disclosed, and patched in public; vulnerabilities in closed systems get found by whoever has the strongest incentive to look, which is frequently not the vendor. Anyone who has worked incident response knows which world they'd rather defend.
And the incentive argument collapsed into its opposite. Giving away the commodity layer turned out to be how you build markets on top of it. Red Hat sold support for free software and was acquired for thirty-four billion dollars. Android was given away and conquered the planet's pockets. Companies learned that the question was never "how do we stop the open thing" but "where does value accrue once the open thing exists" — and the answer made more money than the proprietary strategy ever had.
Here's the part I find genuinely instructive, though: the losers of that fight didn't just concede. They converted. Microsoft didn't grudgingly tolerate open source; it reorganized its business around it. IBM bet the company on Linux back when that was a radical act. The firms that adapted early captured the platforms; the ones that fought longest — remember SCO's litigation crusade against Linux? — are trivia questions now. That's the piece of history I'd want every AI policymaker to sit with. The July 2026 letter isn't a coalition of idealists. It's a coalition of companies, several of which were on the losing side last time, that have already run this experiment on their own balance sheets.
I lived through this arc from the trenches, not the boardroom. I've spent my career as a solutions architect in banking — the most conservative, compliance-bound corner of enterprise software — and I watched financial institutions go from "open source is a legal risk we can't touch" to running their core integration layers on it. Not because they became ideological. Because it was auditable, it was adaptable, and no vendor could hold their infrastructure hostage. (My day-to-day work on that kind of banking automation lives at grizzlypeaksoftware.com, for the curious.)
The Same Logic Now Applies to Models — With Higher Stakes
So why does this rerun matter more than the original?
Because software was a tool, and models are closer to a workforce. When the open-source fight was settled, the prize was who ran the servers. The prize this time is who gets to apply machine intelligence to their actual problems — and a striking share of the real economy cannot do that through a closed API, no matter how good the model behind it is.
Think about who holds the valuable data. Hospitals, whose patient records legally cannot leave their custody. Banks and credit unions, wrapped in examination regimes that make "we send member data to a third-party endpoint" a very short conversation with a regulator. Manufacturers whose process data is the company. Defense and intelligence networks that are air-gapped by design. Foreign governments with sovereignty requirements. For all of them, "use the best closed model via API" is not the premium option — it's not an option at all. A downloadable model they can run inside their own walls is the only door into the AI economy they're allowed to walk through.
This is where I think the entire framing of the "AI race" goes wrong. The scoreboard everyone watches — which lab has the best model this quarter — measures possession. But general-purpose technologies have never rewarded possession; they reward diffusion. Britain didn't lead the industrial age because it kept the best steam engine in a vault. America didn't win the software era because it had one great program; it won because software soaked into every industry, carried by millions of people who could get their hands on the tools. A country with the single best model and shallow diffusion is a country with a trophy. A country with very good models running in every hospital, factory, bank, and school district has an economy.
And the diffusion layer is, empirically, the open layer. It's also — and this is the uncomfortable part — currently being supplied to much of the world by Chinese labs, which figured out faster than Washington did that the model everyone builds on wins something more durable than a benchmark. When a developer in Jakarta or São Paulo reaches for an open model and the natural choice is a Chinese one, that's a form of standard-setting no export control claws back. The response to that cannot be for the United States to restrict its own openness. You do not counter someone else's diffusion by strangling your own.
None of this means "open everything, always, immediately." There are genuinely hard questions at the extreme frontier, and honest uncertainty about where lines belong. But the lesson of the last twenty-five years is specific: when the arguments for restriction are the same arguments that failed before, restriction should carry the burden of proof. Openness shouldn't have to justify itself against hypotheticals. The hypotheticals should have to justify themselves against the historical record — and the record, so far, is 1-0 against them.
I build AI agents for a living, and every architectural decision I make lands somewhere on this open/closed spectrum — which is exactly why I stopped treating it as an abstract policy debate. (I write about that hands-on agent work at shanelarson.com.) If this argument resonated — or if you think I'm wrong and want the strongest version to argue against — the book goes much deeper: the economics of self-hosting, the concentration risk nobody is pricing, the defender's dilemma, the distillation debate, China's open-weight statecraft, and what a serious pro-diffusion American policy would actually contain.







