Powerful AI models that companies can download, run and adapt are becoming a serious competitive force against the closed systems offered by OpenAI and Anthropic. A new wave of open-weight models from China, including Moonshot AI’s Kimi K3 and Alibaba’s Qwen 3.8, has sharpened a debate in Washington and Silicon Valley over whether open models represent a security risk, an economic opportunity, or both.
The immediate concern for US frontier labs is not simply that these models are available without a subscription. It is that they are becoming capable enough for a growing number of business tasks while offering users more control over data, deployment and costs. That could weaken the pricing power of companies whose business models rely on selling access to proprietary models through cloud services and APIs.
Open-weight models make their trained parameters available for download. They are not always fully open source, since training data and all development methods may remain private. Still, they can be run on a company’s own systems, customized for specific tasks and used without sending every prompt to a model provider’s servers.
A challenge to high-margin AI services
Venture capitalist Bill Gurley argues in an opinion piece for The Washington Post that open models are a familiar form of price competition, rather than an exceptional threat that demands government intervention. He compares the dynamic to earlier industries in which lower-cost challengers forced established companies to improve or lose market share.
His central argument is that software can be reproduced at almost no cost once it has been created. In that setting, freely available software can reduce artificial scarcity and shift revenue to related services, such as support, hosting, hardware, integration and enterprise tools. The commercial history of companies including Red Hat, MongoDB and Databricks shows that free or widely available code can still support substantial businesses.
For AI, however, the economics are more complicated than for conventional software. Ben Thompson writes in Stratechery that downloading model weights removes research and development costs for users, but does not make AI use cost-free. Running a model requires expensive computing capacity, electricity and memory. Those inference costs rise as usage rises.
The relevant comparison is therefore not simply the price per token, Thompson argues. Different models may require very different numbers of tokens to reach the same result, particularly on reasoning tasks and AI agent workflows. A model with a lower published token price may be less economical if it uses substantially more processing to complete a task.
Even so, businesses may choose open models for reasons beyond price. They can retain sensitive information within their own infrastructure, avoid dependence on a single supplier, fine-tune a model for internal terminology and maintain access even if a vendor changes its prices, policies or product roadmap.
Ollama, a platform for running open models locally and in the cloud, says in a company blog post that it serves 8.9 million developers and is used by 85 percent of Fortune 500 companies. Those figures underline the growing demand for tools that make local and self-hosted AI easier to use, though they do not indicate how extensively each company uses the platform.
China’s distribution strategy
Chinese companies have strong incentives to release models openly. US export controls can limit their access to advanced chips and make it harder for them to build global, centralized AI services on the same scale as US providers. Open releases offer another route: distribute the model itself and allow developers, cloud providers and businesses around the world to run it where they choose.
Ben Werdmuller writes on werd.io that this approach can turn a constraint in computing infrastructure into a distribution advantage. Open models can spread through an ecosystem of hosting companies, developer tools, enterprise software and local installations. That ecosystem can make the model layer less valuable on its own while expanding demand for complementary products, including chips and cloud capacity.
China’s government also appears to support that approach. Xi Jinping has called for open source, openness and collaboration in AI. Thompson interprets this as a strategy to make AI broadly available for sectors where China has industrial strength, including manufacturing and robotics.
The latest releases suggest that openness is no longer limited to smaller or less capable models. Wojciech Gryc writes in Emerging Trajectories that Kimi K3, Qwen 3.8 and other recent Chinese systems are challenging the assumption that only heavily funded closed labs can operate near the frontier of model capability. The claims of performance parity still need to be tested across independent benchmarks and real-world workloads.
Washington faces a policy choice
At the same time, US officials are considering measures that could discourage or restrict the use of Chinese open models. Maria Curi reports for Axios that options discussed within the Trump administration have included Entity List designations, procurement restrictions, cybersecurity advisories and rules that would impose security obligations on companies hosting Chinese models.
Supporters of such measures point to possible backdoors, data security concerns and the risk that models could reflect the interests of the Chinese state. Those concerns are particularly important when a model handles confidential company information, government data or security-sensitive work.
Critics warn that broad restrictions could produce the opposite of their intended effect. Gurley argues that suppressing open alternatives would protect the market position of a small number of large US labs. Axios reports that David Sacks, a White House AI adviser, has similarly warned against policies that could eliminate open-source competition for dominant closed-model providers.
There is also a practical cybersecurity issue. Thompson notes that security teams need capable models they can run in their own environments when investigating attacks. He argues that restrictions on advanced US models for cyber work could leave defenders reliant on foreign alternatives.
The debate is unlikely to be resolved by choosing between unrestricted openness and blanket bans. Companies evaluating open models need to assess model quality, total operating cost, licensing terms, data handling, supply-chain security and the ability to audit or host the system themselves. Policymakers face a related challenge: address genuine security risks without turning those safeguards into a barrier that freezes competition in one of the technology industry’s most important markets.
Sources
- Open models for AI were inevitable – The Washington Post
- The secret Trump administration battle to fight Chinese AI – Axios
- Who’s Afraid of Chinese Models? – Stratechery
- Kimi K3, Qwen 3.8, and Anthropic’s (potential) Unravelling – Emerging Trajectories
- American AI is locked down and proprietary. It’s losing. – werd.io
- Ollama: all aboard open models – Ollama Blog
Stay up to date
AI for content creation: the latest tools, tips and trends. Every two weeks in your inbox: