Open-Source AI & Open Models Reading List

Some Simple Economics of Open versus Closed AI

title
Some Simple Economics of Open versus Closed AI
type
summary
summary
Christian Catalini's a16z essay using innovation economics to argue open weights change where AI investment goes and who profits, not how much
tags
ai, open-weights, economics, distillation, policy, safety, enterprise
created
2026-09-14
updated
2026-09-14

Christian Catalini published this as a guest essay in a16z's newsletter in August 2026, in the middle of Anthropic and OpenAI's campaign against "distillation attacks" by Chinese labs. His thesis comes from 1851. The economist Petra Moser coded almost 15,000 inventions shown at the Great Exhibition in London and its 1876 American sequel, from countries with and without patent systems, and found that patent law changed which fields inventors worked in but not how much they invented. Swiss inventors, with no patent protection, clustered in scientific instruments and food, where secrecy and lead time protected them. Catalini argues open weights do the same to AI: they change the direction of investment (what gets built, who builds it, who captures the return) rather than its level. Nathan Lambert's open-source-ai-reading-list describes it as a position on how open models capture value by complementing large parts of the existing economy.

a16z is a venture firm with a public position on open weights, and the essay should be read with that in mind, though it gives the other side more room than a pure advocacy piece would.

Distillation is not theft

Catalini sets out both camps first. Against open weights: distillation is IP theft, US labs will not be able to fund their next training runs, and China will free-ride. Dario Amodei adds the safety version, that past some capability threshold society cannot defend against misuse, and that released weights cannot be recalled. For open weights: diffusion is how general-purpose technologies spread, a closed market would concentrate quickly, and it is convenient that Anthropic's commercial interest lines up with its safety and national-security arguments. Closed models get jailbroken too, and Claude was used in a breach of Mexican government systems.

On distillation he says the patent-like protection Anthropic seems to want never existed. Fraudulent accounts and systematic API abuse aside, distillation is a normal industry practice; Chinese labs are prompting US models to act as teachers, not stealing weights. Outputs are not copyrightable, and labs usually assign ownership of them to customers. Terms of service can forbid training a competitor, but enforcement fails because no single request looks unusual and an organized operation spreads its volume across farmed accounts, aggregators and jurisdictions. Controls strong enough to matter hit legitimate users. His example is Fable, whose restrictions on helping with frontier AI R&D annoyed customers enough that Anthropic changed them within days. And labs trained on web text, media and books under fair use, which makes it awkward to call training on outputs illegitimate.

ai-great-leap-forward covers the anti-distillation reflex from another angle. anthropic-threat-report-september-2026 and the-distillation-panic are the lab's side and Lambert's side of the same 2026 argument.

What innovation economics says

Weights without software around them behave like ideas: non-rival and, once shared, non-excludable. So Catalini brings in Richard Nelson (1959), Kenneth Arrow (1962) and Joseph Schumpeter's compromise of a temporary monopoly to fund discovery followed by diffusion. The deciding factor is cumulativeness. When follow-on work matters, restricting inputs is expensive, and the essay's evidence is a run of natural experiments.

Heidi Williams found that genes sequenced by the private Celera, which restricted access, attracted 20-30% less follow-on research than comparable public genes, and the gap lasted to 2009 even though the restrictions ended within two years. Jeff Furman and Scott Stern measured a 57-135% rise in cumulative research when biomaterials became easier to obtain. When the NIH negotiated away DuPont's restrictions on Cre-lox and Onco mice, follow-on research rose and fanned out, with new researchers taking more novel directions, while the creation of new engineered mice upstream did not fall. After a 1956 antitrust settlement forced AT&T to license its patents royalty-free, the transistor included, inventive activity rose 17% in five years, driven by new firms in other markets, and Bell Labs kept going with the laser, the communications satellite and Unix. William Nordhaus estimated that innovators capture only about 2.2% of the surplus they create.

The conclusion is that openness wins when cumulative exploration matters and uncertainty is high, as in AI now. Closed access does less harm once all that remains is execution along a known path.

Where the profit goes

Richard Levin's surveys at Yale in the 1980s, repeated a decade later, asked executives what protects their R&D. Patents came last, behind learning, secrecy, lead time and complementary assets; pharma and chemicals were the exceptions. When protection is weak, profit goes to whoever controls the complements. EMI invented the CT scanner and its engineer Godfrey Hounsfield won a Nobel for it, but GE and Siemens took the market with their hospital distribution and service networks.

AI, Catalini argues, was born on the weak side. Research insights leave the labs, talent moves between them, and APIs leak information. By Epoch AI's estimate final training runs are only 10-23% of compute costs, so labs do hold real tacit knowledge, but without the complementary assets value will accrue elsewhere. That explains current lab strategy. Coupling models to harnesses and moving into applications such as Claude Cowork, Claude Tag and ChatGPT computer use builds lock-in and collects traces of how people work. Regulation is the other asset a lab can force into the picture: if safety rules raise the cost of evaluation and approval, only companies with large policy and compliance teams can compete, much as GDPR ended up burdening smaller firms more than the largest data collectors. Catalini is careful to add that the labs' claims "could be self-serving and correct at the same time".

Safety depends on the domain

He reduces safety to two economic questions: who benefits most from diffusion at the margin, and where access can actually be constrained. In cyber, defense is spread across a huge number of organizations, open weights make auditing and patching cheaper, and capable attackers can get around model-level controls, so restriction mostly taxes defenders. Biology is different. One capability can do irreversible harm, so delay has value if it is used to control physical inputs such as synthesizers, equipment and materials; a bottleneck made of atoms is a better chokepoint than a software guardrail. For systemic and unknown risks he leans back toward openness, since the knowledge needed to detect or defuse a problem is more likely to be spread widely than held by a few lab employees.

He still wants independent third-party testing and staged releases for capable open models, and more research on removing harmful capabilities during training rather than relying on refusals. The position is close to nonproliferation-is-the-wrong-approach-to-ai-misuse and to the release process in a-safe-path-to-open-weights.

Enterprises and the shape of demand

Enterprises first moved to open models for cost, a correction after months of employees tokenmaxxing, and labs answered by cutting entry-level prices. Catalini says control is the lasting reason. Interactions with lab tools leak information, customization deepens lock-in, and customers increasingly fear their AI provider will become their competitor, as he says happened between Anthropic and Figma. His model of the alternative is Thinking Machines training a custom model for Bridgewater on top of its base model: the lab supplies general intelligence and tooling, and the hedge fund keeps control of weights that encode its know-how. Microsoft and Palantir are named as similar bets, and Nvidia's coalition backing open weights follows the logic of companies with complementary businesses funding Linux.

The market split he expects depends on how the payoff to extra capability curves. Across much of the economy it flattens quickly, so intelligence is priced "at the meter" like electricity, served by open models or closed models sold at cost. A markup requires better ground truth, data and verification. In convex domains, such as cyber, finance and frontier R&D, a small edge pays disproportionately and can sustain frontier rents, but there the marginal buyer is a country, and countries can ban, manage or nationalize instead of paying. He calls the Fable and Mythos bans a preview: "for any AI lab to retain its freedom, it needs to be successful, but not too successful." Even superintelligence does not escape the argument in his telling. If it depends on dispersed tacit knowledge, complementary assets still matter, and if it is made of ideas, it will leak. He closes on Hayek's point that no planner can hold all local knowledge, and says regulatory capture can slow the diffusion of open weights but cannot reverse it.

Relation to other pieces and what it does not settle

The market split is close to Lambert's in open-and-closed-models-are-on-different-exponentials, two months earlier: closed labs take the top of the market, open models serve most tokens, and the total value around open models is larger but spread thin. Lambert gets there from how coding-agent users pay, Catalini from the history of appropriability. The Thinking Machines and Bridgewater example is the enterprise version of the specialized models Lambert calls for in what-comes-next-with-open-models.

The essay's central claim, that openness leaves the level of investment unchanged, rests on cases that differ from frontier AI in one important way. Celera was overtaken by a publicly funded project, and AT&T was already a profitable monopoly when forced to license. None of the examples involves a technology whose next generation costs billions and is financed by the very rents at stake, which is the worry behind the "labs cannot fund their training runs" argument. Catalini answers it by analogy to AT&T rather than with direct evidence.