Some Simple Economics of Open versus Closed AI : US Pioneer Global VC DIFCHQ SFO NYC Singapore – Riyadh Swiss Our Mind

In May of 1851, millions of people traveled through the hallways of a glass building to see a preview of the future. The Great Exhibition brought together the best of what the world was tinkering with at the time, including steam hammers, telegraphs, reaping machines, and flush toilets. Anyone could get close to the tech to try to reverse engineer it, and nations sent their brightest engineers to distill as much as possible from their rivals. Its sponsor, Prince Albert, was a strong believer in diffusion being crucial to accelerating economic progress.

A century and a half later, economist Petra Moser turned the exhibition catalogs and almost 15,000 inventions from the fair and its 1876 American sequel into a dataset. Crucially, the inventions came from countries both with and without patent protection. What she found unsettled the staunchest defenders of strong intellectual property rights: patent systems had no effect on the level of innovation, only on where inventors placed their attention. At the time, Switzerland had no patent protection, so innovators crowded around domains such as scientific instruments and food (Nestlé was founded there in 1866) where secrecy, lead time, and complementary assets gave them enough of an advantage. Under strong IP regimes, innovation spread more widely. Same amount of innovation, just allocated differently across fields.

The same tension now sits at the center of the battle between closed- and open-weights AI models. Anthropic and OpenAI argue that “distillation attacks” from Chinese companies threaten both the industry’s ability to finance the next generation of models and US national security. Proponents of open weights counter that diffusion is essential to a competitive and innovative market for machine intelligence.

But Moser’s evidence suggests that the debate is focused on the wrong margin. Open weights are unlikely to change the level of investment in AI, only its direction: what gets built, who builds it, and who captures the returns. Closed labs may keep pushing the most general frontier, while open weights let experimentation spread across the firms and domains that can combine machine intelligence with scarce data, distribution, and tacit knowledge. The same allocation problem shapes safety. The relevant question is not whether openness is dangerous in the abstract, but when diffusion strengthens defenders and where harmful capabilities can actually be constrained.

Competing Visions for the Market for Intelligence

The economic argument against open-weights is simple: distillation is IP theft and erodes incentives to innovate. If the United States government does not step in and use any available tool to stop it, not only will US labs be unable to fund their next large training runs, but China will free-ride on our progress and take over. According to this worldview, open-weights are deeply decelerationist.

The counterargument relies instead on zooming in on how general-purpose technologies historically diffuse through the economy, and concludes not only that open weights are fundamentally pro-competitive and accelerationist, but also that without them, the United States would rapidly fall behind. Openness and experimentation are how we led in the internet era, and this time is no different.

Safety concerns complicate the discussion further. Dario Amodei has been on a multi-year crusade against open-weights on the grounds that they make us incredibly unsafe. He believes that once some threshold of intelligence is crossed, it will be impossible for society to defend itself from bad actors, and rogue models will inflict potentially existential damage. Only by gatekeeping access and imposing guardrails can the country of “geniuses in a datacenter” ever be allowed to exist. But it gets worse: because open weights cannot be “recalled”, we may suddenly find ourselves in a doomsday scenario without much notice or recourse.

Amodei’s detractors point out that without open weights, the market for intelligence would rapidly become extremely concentrated, and that it is rather convenient for Anthropic that its business incentives happen to be perfectly aligned not only with AI safety goals, but also with US national security concerns. Security researchers regularly jailbreak protections on closed models too, and Anthropic and OpenAI’s models have already been used extensively by hackers, including to breach sensitive government infrastructure. While closed models may give us the illusion of safety, they argue that at best they may buy us the illusion of time.

Each side has its own concerns about how the wrong actions today would irreparably get us into trouble. And both sides honestly believe that their approach is the only way to keep us safe (or as safe as realistically possible). Luckily, the economics is loyal to neither.

The Appropriability Regime That Never Was

Anthropic and OpenAI have been targeted extensively by other labs trying to catch up with the frontier. Anthropic went as far as publicly asking Congress to go after Alibaba for what it called brazen and illicit attacks designed to steal its technology. How can the US labs keep funding the necessary training runs if the Chinese labs can, by hook or by crook, replicate within months the performance of their models for cheap?

The challenge with Anthropic’s request is that, beyond fraudulent accounts and systematic abuse of their APIs, the patent-like appropriability regime it seems to desire never existed. Distillation is a legitimate industry practice, and is different from the type of espionage and trade secret theft that US defense, aerospace and chip contractors had to deal with in the past. Chinese labs are not shoplifting the labs’ secret weights; they’re prompting the US models to act as teachers for theirs.

Outputs are not copyrightable, and AI labs typically assign ownership of them to their customers. Terms of service can still prohibit customers from using those outputs to train competing models. But that invites an obvious question: if the technology is so advanced, why can’t the labs use it to stop distillation? The answer is that neither the content nor the source gives the attack away. Each individual request looks like the work of legitimate customers, and an organized operation can scatter its volume across farmed accounts, aggregators, and jurisdictions. Without more onerous frictions for everyone, enforcement becomes a game of banning accounts that are trivially replaced. The trade-off is already palpable with Fable, whose restrictions on assisting with frontier AI R&D frustrated customers enough that Anthropic had to adjust them within days. Anti-fraud controls aggressive enough to make a difference would inevitably affect an even wider range of legitimate work. In the long run, preventing customers from training on outputs they have paid for is a losing business proposition: tighten the restrictions too far, and power users will migrate to open-weights models.

Last, singling out the very technique responsible for a significant share of AI progress over the past decade as illegitimate places the top labs in a very hard spot, as they rely today on extensive fair use arguments for their own distillation of massive amounts of internet material, media, and books.

But if we suspend disbelief, is the fact that top AI models can act as teachers to improve lesser models bad for American AI? If the government could use its soft-power, policy and diplomatic levers to enforce it, would we even want that?

To Monopoly or Not To Monopoly?

Both Richard Nelson in 1959 and Nobel laureate Kenneth Arrow in 1962 struggled through a version of this exact problem. Knowledge is non-rival: my use of an idea doesn’t prevent you from doing the same. Once shared, ideas are also non-excludable. As a result, the social value of an idea exceeds what its inventor can capture, which leads to the canonical worry that some types of ideas will never get properly explored and funded in the first place.

Model weights, at least without any additional software around them, behave a lot like ideas.

For society, it then boils down to a simple, intertemporal tension: once an idea has arrived, society wants it to be spread as widely as possible. After all, its marginal cost, like the cost of downloading a model’s weights, is close to zero. But before it is found, society needs someone to truly believe that they will be able to appropriate significant returns and recoup their R&D costs.

Joseph Schumpeter battled with this conflict his entire life, oscillating between the value of monopoly rents to encourage the initial investments, and the need for startups and creative destruction to undo the monopoly and drive massive growth later on. Ultimately, he concluded the best society can do is somewhat schizophrenic: grant a temporary monopoly, and then let it rip.

Everything since then in the economics of innovation has been essentially an endless debate about how temporary that monopoly should be, and what, if anything, should enforce it. But there’s one important catch that can significantly tip the scales toward open versus closed.

Idea Compounding

Most, if not all, innovation is the result of some form of idea recombination. In domains where cumulativeness and being able to remix past work are particularly important, the length and strength of the rights granted to the first movers have to be carefully weighed against the additional costs of delayed exploration by the followers. The leading AI labs, no matter how well resourced, can only pursue a select number of promising paths, and this also applies to AI safety.

AI has always been a fruit of rapid distillation: today’s marvelous models are as much a gift from decades of academic research on neural nets during “AI winter” as they are from Google’s publication of the transformer architecture. In that light, open-weights models acting as students of the closed models are a direct continuation of that lineage. Model outputs are a key research input for the ecosystem to advance.

The cleanest natural experiment on how restricting access to R&D inputs affects innovation comes from a different race: the one between the for-profit Celera and the publicly funded Human Genome Project to sequence our DNA. When Celera was first to sequence a gene, it restricted access through fees, limits on redistribution, and licensing requirements for commercial use. Heidi Williams found that these genes attracted 20 to 30 percent less follow-on research and product development than comparable genes that had been public from the outset. Although the restrictions were short-lived and disappeared within two years when the public project independently sequenced the same genes, the gap persisted. As late as 2009, Celera-sequenced genes still lagged behind the others.

When the value of follow-on work is high, even small initial frictions compound. Symmetrically, the removal of friction can have big consequences for both the rate and direction of innovation: when looking at biomaterials, Jeff Furman and Scott Stern found a 57 to 135% boost to cumulativeness when inputs were made more easily available. In the context of genetically engineered mice, Fiona Murray, Philippe Aghion, and co-authors studied what happened when the NIH negotiated away DuPont’s restrictions on hundreds of Cre-lox and Onco strains, ending the reach-through royalties and reporting that had limited academic access. Follow-on research rose. More tellingly, it fanned out: new researchers entered, and they explored more novel trajectories. Upstream, the creation of new engineered mice was unaffected.

Overall, whenever the benefits to cumulativeness and broad exploration are high, openness is the dominant strategy. This also means that society benefits the most from openness when uncertainty is still relatively high, as in AI today. When all that is left is execution along a known trajectory, then closed is far less harmful. And even in that narrow case (e.g., a molecule with well-understood clinical benefits that now needs to be commercialized), society only grants a temporary monopoly in exchange for relevant information. Patents themselves are instruments for diffusion and for avoiding trade secrets leading to no disclosure at all.

Now you may wonder if these examples from science-heavy domains also apply to AI. After all, serving models at scale requires massive investments in infrastructure, and that buildout is where most of the risk for the labs lies. But the lesson from telecommunications is exactly the same. In 1956, an antitrust settlement forced AT&T to license, royalty-free, one of the most valuable patent portfolios of all time. As measured by Martin Watzinger and coauthors, once AT&T’s inventions, which included the transistor, were suddenly available for others to build upon, inventive activity rose 17 percent in five years. Interestingly, the effect was not driven by other large firms free-riding on AT&T’s intellectual property, but by new firms going after completely different markets. Bell Labs also doubled down on its core business and was not deterred from innovating: the laser in 1957, the communications satellite in 1962, Unix in 1969.

While the idea of letting others compound on your ideas might be frustrating for Anthropic and OpenAI, the good news is that with a very limited number of exceptions, this is exactly how economic progress works. William Nordhaus found that innovators capture, on average, only ~2.2% of the social surplus they bring to the world. AI will be no exception. But this also places Anthropic’s ask to the US government in context: society does not owe the labs a stronger appropriability regime. As it turns out, there already is a different one in place.

The Innovation Last Mile

When a new general-purpose technology comes about, it initially has to be forcefully retrofitted into the existing system. These initial “point solutions” only realize part of the value of the new paradigm, and it is only when the architecture can be redesigned from first principles that the technology becomes truly transformative.

The rewiring requires control over and adaptation of key complementary assets, including infrastructure, trust, access to distribution, and relationships with regulators. This gives incumbents a second chance: while the new entrants may have caught them by surprise and out-innovated them up to this point, as the dependency on complementary assets becomes the limiting function, they may be able to imitate or acquire, catch-up, and preserve their position.

In the 1980s, Richard Levin and colleagues at Yale asked executives in innovative sectors across America a basic question: what protects your R&D bets? Patents ranked at the bottom. At the top? Learning, secrecy, lead time, and complementary assets. The study was repeated a decade later: same answer. The exceptions? Pharma and chemicals, sectors where a specific molecule can define an entire product class, and narrow exclusivity has teeth. But the vast majority of the economy runs on a limited ability to exclude others from the underlying ideas.