Huang is right about open weights
NVIDIA's CEO used his first X post to argue that American AI leadership runs through open models. The signatory list is self-interested. The argument is still correct.
Jensen Huang posted on X for the first time on July 24 to publish an open letter titled "Open Weights and American AI Leadership." I agree with it. Open source is the reason the stack we build on exists. If the United States wants to lead in AI, it should develop AI the way it developed the software layer under everything else, in the open. Leadership is not one model topping a benchmark. It is an ecosystem other people build on.
Twenty-five organizations signed. NVIDIA, Microsoft, Meta, IBM, Dell, Palantir, CrowdStrike, Cisco, Mistral, Hugging Face, Mozilla, The Linux Foundation, a16z, Y Combinator, Perplexity, Replit, ServiceNow, Box, Cohere, GitHub, and DoorDash are on it. OpenAI, Anthropic, and Google are not.
The historical parallel is 1980s software. Tight control over source code was treated as the precondition for progress. Shared code turned out to be the substrate for the internet, for enterprise systems, for federal agencies, and for the military. The letter's strongest claim is that open source did not only make software cheaper. It created a shared base of knowledge that gave American engineers institutional sovereignty. They could read the thing they depended on, fix it, and fork it if the vendor went a direction they did not like.
The economic argument is right model, right job, right cost. Frontier-scale compute gets reserved for frontier problems. Everything else runs on smaller specialized models. That is the only structure under which AI is viable at billions of daily tasks, because the unit economics of routing every request to a frontier model do not work and never will.
The security argument is the part worth sitting with. Closed is not the same as safe. Closed models get breached. They get misused. They fail in ways nobody outside the company can detect, which means nobody outside the company can warn you. Concentrating capability inside a handful of closed systems creates a small number of single points of failure. That is a familiar shape to anyone who has worked on infrastructure. Monoculture is a security property, and it is a bad one.
The letter does not skip the risk. Once weights are public they are outside the developer's control. Modified versions are hard to trace and impossible to recall. That is a real and permanent asymmetry, and the letter states it rather than burying it.
The policy asks are compute access for startups and researchers, investment in shared training assets, no premature restrictions, and an explicit defense of distillation as a legitimate technique rather than theft. That last one is not abstract. It is in the letter because Washington is questioning the origins of Kimi K3, and the signatories want the definition settled before it gets settled against them.
That every organization on that list makes money if models get cheap and portable is not a coincidence, and pretending otherwise is not analysis. A chip supplier, a hyperscaler, a security vendor, two venture funds, and a code-hosting platform signed the same document.
| Signatory | Layer | Effect |
|---|---|---|
| NVIDIA, Dell | Compute | gains |
| Microsoft | Compute + apps | gains |
| a16z, Y Combinator | App-layer capital | gains |
| CrowdStrike | Security | gains |
| Hugging Face, GitHub | Distribution | gains |
| OpenAI, Anthropic, Google | Model | did not sign |
So the letter is an argument advanced by the people who profit from it winning. Both things are true at once: it is self-interested and it is correct. Self-interest is not a refutation. In 1998 the companies arguing hardest for open standards on the web were the ones losing the browser war, and they were still right about standards. What matters is whether the mechanism they describe actually works. Here it does. The claim that open weights broaden the base of people who can audit, adapt, and deploy models does not stop being true because NVIDIA sells the hardware those people rent.
The closed-model position rests on an argument I do not think survives contact with how security works in practice. It holds that capability is safest when access is restricted. But restriction is not containment. It means the people with access are a fixed set chosen by a company, and everyone else has to trust an assertion they cannot check. That works until it does not, and when it fails you find out from a disclosure rather than from your own instrumentation.
I have spent enough time auditing contracts and running nodes to have an opinion about this. The infrastructure people trust with real money is public. Anyone can read the client, run the client, and file a finding. That does not make it safe, and I am not claiming it does. What it makes it is legible. When something breaks, the failure is visible to people who are not employed by the entity that broke it. Legibility is not a substitute for security, but the absence of it is a serious problem, and it is the default condition of a closed-weight ecosystem.
The strategic version of the argument is the one that should carry weight in Washington. If American frontier labs keep weights closed and other countries ship capable open models, developers build on the open ones. Not because they are better on evaluations, but because they can be run locally, modified, and deployed without a vendor relationship. Standards form around what people build on. That is how the open-source software layer ended up American, and it is how it could end up not being.
The specific thing that would move me is a security incident where public weights were the necessary condition. Not a jailbreak, not a fine-tune that produces content an API would refuse. An incident where the attacker needed local access to the weights to do what they did, and where an API-mediated closed model would have contained it. That is the case the closed-weight position needs and does not yet have.
The second condition is a capability gap that widens rather than closes. If open-weight models fall more than a year behind the frontier on standard evaluations and stay there through the end of 2027, the ecosystem argument stops holding. An ecosystem built on a permanently second-tier substrate is not leadership. It is a long-term concession dressed up as one.
Both of those are observable. If either happens, I will say so here.