My brokerage account wants Jensen Huang to win this argument. I hold semiconductor exposure, I think the compute buildout has further to run than the bears do, and I’ve spent years defending open source against people who confused “anyone can read this code” with “someone is reading this code.” When Nvidia, Microsoft, Palantir, Dell and twenty-odd others signed a letter on July 24 saying Washington shouldn’t strangle open-weight models, my instinct was to nod along.
Then I read the second clause. The letter makes four arguments: open models expand competition, accelerate diffusion, enable national sovereignty, and strengthen safety and cybersecurity. Three of those are defensible. The fourth is borrowed credibility from a different technology, and it’s the one Huang put in his post.
Open weights do not strengthen cybersecurity. Not on balance. Not with caveats. They don’t.
Ask what actually made open source defensible
The letter’s strongest evidence is its own: open-source software underpins most of the internet, the systems of the largest technology companies, and federal missions including cybersecurity itself. All true. So ask the follow-up question — what made that ecosystem survivable?
It wasn’t the reading. Heartbleed sat in OpenSSL for two years while, in principle, millions of people could have looked at it. Log4Shell lived in a logging library that ships inside half the enterprise Java on earth. Many eyes didn’t catch either one. What saved the open ecosystem in both cases was the thing nobody puts in a manifesto: a version bump, a package manager, a distro maintainer pushing to a mirror, and a fleet of machines that pull updates on a Tuesday. Openness didn’t produce the security. The patch pipeline did.
Now try to build that pipeline for weights. A model is a file. Once it’s on a drive in Shenzhen or a bucket in Frankfurt, there is no maintainer, no CVE, no upgrade path, no revocation. You can publish version 3.1 with the flaw corrected. You cannot unpublish version 3.0. The disclosure norm that governs everything else in this industry — find it, report it, patch it, then talk — has no mechanism here at all. A vulnerability found in an open checkpoint isn’t a bug to be fixed. It’s a permanent property of every copy already distributed.
That’s not a smaller version of the open-source story. It’s the open-source story with the load-bearing part removed.
The asymmetry runs the other way
The letter’s security case leans on a real observation: attackers are already using capable AI, so defenders need models of equal capability to detect and simulate threats. Fine. Now ask which side the download actually helps.
The defender was never the constrained party. A bank’s security operations center can sign a contract, pass a compliance review, buy frontier API access, and get a model with a support number attached. It has budget, procurement and a legal department. The party that can’t do any of that is the one who needs to operate without a payment record, without a corporate identity, and without an inference log sitting on someone else’s server describing exactly what was asked and when.
Open weights are the only frontier capability that arrives with no customer relationship. That is precisely their appeal to sovereignty-minded governments, and precisely their appeal to everyone else who’d rather not be observed. You can’t hand one group the ability to run unlogged and withhold it from the other. It’s the same file.
And the safety training doesn’t survive the trip. Stripped variants of major open releases show up on public hubs within days of launch, advertised as uncensored, produced by fine-tuning that costs less than the laptop I’m writing this on. Whatever guardrails a lab spends months building, someone removes over a weekend for the reputational reward of being first. There is no version of “transparency improves security” that survives contact with that fact.
What I still won’t sign
None of this makes the restriction crowd right, and I want to be clear that I’m not joining it.
Banning Chinese open weights doesn’t unpublish Kimi K3. The weights are out. Every research lab, every hedge fund quant desk and every startup that wants them already has them, and a US import rule reaches exactly the institutions that would have complied anyway — universities, defense contractors, regulated enterprises — while leaving the actual adversary untouched. A distillation ban is worse. Distillation is how a graduate student builds anything at all on a departmental budget, and outlawing it to punish one Chinese lab hands a permanent moat to the four American companies that can afford to train from scratch. The Little Tech signatories are right about that, and they’re right that a rule written by incumbents will be a rule that protects incumbents.
So keep the letter. Keep the competition argument, the diffusion argument, the sovereignty argument. Keep the 1980s parallel, which is a good one, because the people who wanted to lock down source code were wrong and the industry is richer for having ignored them.
Just don’t tell me the man selling the GPUs has settled the security question in a subordinate clause. Openness is a bet worth making. It is not a defense.
Argue for it on the merits it actually has.
Leave a Reply