The Arguments Against Open Source AI are Very Bad
- title
- The Arguments Against Open Source AI are Very Bad
- type
- summary
- summary
- Tom Bedor's rebuttal to the frontier-lab case against open weights, using encryption export controls as the precedent
- tags
- ai, open-source, policy, open-weights
- created
- 2026-07-29
- updated
- 2026-09-14
Tom Bedor wrote this in July 2026, days after kimi-k3 shipped and set off another round of argument about whether open-weight models should exist. His target is the position taken by journalists, politicians, and frontier labs that open models are a danger to be contained. The quote he opens with is from OpenAI's Dean Ball:
One probable outcome of an open-weight-model-dominant world is full AI communism... rather than a market product, AI is a "public good"
Bedor's compressed version of the frontier-lab case: open models are dangerous and un-American, the Pandora's box should be opened only by responsible gatekeepers (preferably us), and only trusted users (our most profitable customers) should get access. That is a hostile paraphrase, but it does name the three claims the essay then works through β danger, national interest, and access control.
Throughout, "open source model" means open weights. Bedor flags the imprecision in a footnote rather than defending it.
Two framing corrections
The first is that open source software already sits underneath every proprietary product, including the frontier models themselves. Bedor sketches the usual layered picture: to build Uber you need language runtimes, web servers, data tooling, and hundreds of other components, almost none of which differentiate the business. So commercial actors cooperate on the lower layers and compete above them. His reading of the resistance is straightforward β frontier labs would very much like models not to become the kind of thing so commonplace that competing on it stops making sense.
The second is that suppressing open source software has a track record, and it is bad. He walks through encryption. Phil Zimmermann released PGP in 1991, when the US government classified strong encryption as munitions, and got a criminal investigation for it. Netscape was allowed to ship only a deliberately weakened SSL internationally, and the weakened build was easier to obtain than the domestic one, so many Americans ended up running it. The controls did not keep encryption out of the world; they handicapped the people subject to them. Courts eventually held that publishing encryption source code is protected speech and the export rules were relaxed.
Narrowing the target to "Chinese" models does not make the enforcement problem tractable, in his view, because the category doesn't hold still. Is a model Chinese if it was distilled from an American one, as the frontier labs themselves allege? Is it still Chinese after an American fine-tunes it? qwen-gpt-reasoning-prefills is one small attempt to test such a distillation allegation empirically. llm-distillation covers the allegations and the evidence offered for them. The fine-tuning question is not hypothetical either: us-scrutiny-of-chinese-model-use follows Cursor's Kimi-based Composer 2 and Thomson Reuters' Qwen-based Thomson-1, exactly the models whose nationality Bedor says cannot be pinned down.
Who else wants open weights
The debate assumes open models are something only the Chinese government has reason to fund. Bedor lists four commercial constituencies with their own incentives. Nvidia sells what Jensen Huang calls token factories, and does not care whether the tokens come from a frontier model or a cheap open one, which is why it ships the Nemotron family itself. American startups are betting on commoditization: Thinking Machines Lab released Inkling on the theory that the moat is in the services around a model rather than the model. Enterprise buyers will want cheaper models for low-complexity work and finer control over customer-facing behavior. And Google and Meta are watching OpenAI's new ad product closely enough that commoditizing ad-free open models becomes a cheap way to kill an ad business before it starts.
The vault has several data points on the commoditization thesis. rl-finetune-beats-frontier is the clearest: a $500 GRPO fine-tune of a 9B open model beat every frontier configuration on a catalog-review task at 68Γ lower cost. telnyx is the kind of business that only exists because open weights do. local-ai-is-not-opus is the counterweight, arguing that the "local Qwen is nearly Opus" claim is false while a tuned local model still pays for itself in a small business. deepseek and neutrino-1-8b are the model-side entries.
The race with no finish line
Bedor's shortest section is also his sharpest. Talk of "losing the AI race" never specifies the goal. Best model? Most tokens sold? He compares it to an "Internet Race", a phrase nobody used because it would have been meaningless β the world was reacting to a technology, not sprinting to a moon landing. To whatever extent nations compete here, he says, it is over absorbing the transition and growing economies, and under that description free models are an input rather than a threat.
The three fear arguments
Scott Galloway's is the economic one: China matches Western quality, cuts the price by two thirds, and owns the market, exactly as it did with solar panels, steel, EVs, and batteries. Bedor's objection is that the analogy needs a physical supply chain to work. Solar and steel have links that cannot survive alone β nobody sells solar-grade wafers into a country with no panel manufacturing β and software has no equivalent. A Chinese open model does not foreclose an American fine-tuning business; it supplies one.
The propaganda argument he concedes halfway. It is reasonable to expect Chinese models to ship with a pro-China slant. It is not a reason to suppress them, because the weights are open and anyone bothered by the slant can retune and republish. He doubts a model perceived as pro-China outcompetes a substantially similar one perceived as pro-US inside the US.
The backdoor argument gets the same treatment as the encryption case. Hidden adversarial behavior in weights is possible in principle. But AI does not change the shape of the vulnerability market, where responsible actors patch and attackers exploit, and the fastest way to find planted behavior is to let everyone inspect the artifact. Restricting the tool restricts the defenders.
What the essay does not engage
The rebuttals aim at the political and economic arguments and mostly skip the safety one. "Open source models are dangerous" is treated as an assertion made in bad faith rather than a claim with a specific mechanism behind it β nothing here addresses capability uplift, or the fact that a released set of weights cannot be recalled the way a hosted model can be patched. Bedor's closing position is that the question is moot anyway: open source AI is too powerful and too hard to control, so attempts to squash it amount to noise.
The vault covers the safety side from other sources, most of them collected by open-source-ai-reading-list. a-safe-path-to-open-weights is a lab's own framework for releasing weights after testing them, societal-impact-of-open-foundation-models is the marginal-risk method, and myth-of-unsafe-open-source-ai and nonproliferation-is-the-wrong-approach-to-ai-misuse argue that containment is the wrong tool. banning-open-source-ai-would-be-a-mistake, by Nathan Lambert and Kevin Xu a month earlier, makes a case parallel to Bedor's from market history rather than export controls, and accepts the race framing he rejects.
A footnote does extra work worth extracting. Responding to Derek Thompson's Stratechery piece, Bedor disputes the claim that whoever holds the frontier automatically dominates non-frontier markets, which are "just the frontier minus n-months". open-closed-model-gap collects the measurements of what n is. Access to capital matters less for small-model development, and frontier labs have no incentive to build cheap models when they would rather move users up. He also disputes that claude-code and Codex are sticky in any deep sense, comparing them to Coke and Pepsi: you stop switching because there is no reason to, not because you cannot, and a small price or reliability gap is enough to move people.
- Nathan Lambert on China's AI Ecosystem and the Open Model Gap
- A Safe Path to Open Weights
- Detecting and countering misuse of AI: September 2026
- Banning Open Source AI Would Be A Mistake
- From Open Source Software to Open Source Strategy
- GLM-5.2 is the step change for open agents
- Kimi K3: The open-weights escalation
- Kimi K3
- LLM Distillation
- Nonproliferation is the wrong approach to AI misuse
- Open-closed model gap
- Open-Source AI & Open Models Reading List
- The OpenAI/Huggingface incident; how we should manage the imminent arrival of autonomous hacking too cheap to meter
- Reasoning Prefills on Open Models, v1.1
- 6 months to live for open models
- US Scrutiny of Chinese Model Use
- Why I build open language models