America Should Out-Open China
Open networks won us the internet. Losing sight of that now would be a mistake.
A revealing argument about open-weight AI broke out last week after Dean Ball, OpenAI’s head of strategy, suggested that open models will lead us to “full AI communism.” I objected that we never called Linux communist, or Apache, PostgreSQL, and the many other open-source technologies that destroyed proprietary margins while expanding competition and innovation in the early Internet.
https://x.com/valkenburgh/status/2078176637094695158
Dean’s response was that frontier AI, unlike ordinary software, requires enormous capital investment. That is true, but it is not unprecedented. The Internet itself required vast investments in fiber, data centers, routers, servers, and undersea cables. Its core protocols and much of its software nevertheless remained open. Capitalism did not collapse. The available profits migrated toward infrastructure, services, applications, security, and customer relationships, producing some of the most valuable companies in history. Available, I mean, to those who knew where to look.
You can run an extremely good business even if you don’t internalize all the value your business creates; indeed, that might be the best way to run a good business. Create positive externalities—oh look, we indexed the entire Internet and made it searchable for free—oh look, we built peer-to-peer electronic cash—while monetizing something else to keep it going.
Jon Stokes offered the best steelman of the frontier labs’ concern. If open weights compress the margins on metered inference, some labs may no longer be able to fund their next great training run out of token sales. But “our present business model cannot finance the next run” does not mean “nobody will finance the next run.” Software companies have found countless ways to fund expensive upstream technologies by capturing value elsewhere. If the market prefers workplace automation (full disclosure, Jon works on this), specialized applications, hosting, integration, or hardware to expensive metered tokens, then capital will follow. That is not a failure of capitalism. That is capitalism on open source steroids.
Nor should American strategy be organized around preserving the current profit pool of a few frontier labs. Security concerns about Chinese models may be real and should be addressed on their merits. But manufacturing regulatory uncertainty (Dean’s specter of “soft law”) around open models merely to discourage their adoption would be incumbent protectionism, not American capitalism at all.
Recent events also demonstrate the security case for openness. During a cyber evaluation, OpenAI’s GPT‑5.6 ‘Sol’ escaped its air-gapped sandbox and compromised Hugging Face’s servers (file that in epic sentences that didn’t make sense five years ago). When Hugging Face tried to investigate, the commercial frontier models it initially used refused to process the actual attack commands, exploit payloads, and command-and-control artifacts. Hugging Face instead completed the forensic work with GLM 5.2, a Chinese open-weight model running on its own infrastructure. That also meant the attack data and compromised credentials never had to leave Hugging Face’s environment.
This is the lesson of the first Crypto War all over again. The government’s Clipper Chip would have offered encryption while preserving government access through key escrow. But criminals and hostile states were never going to volunteer to use the penetrable version. Strong encryption already existed and would continue spreading around the world. In an adversarial contest, an intentionally hamstrung defensive tool will eventually lose to an un-hamstrung offensive one. Safety rules that bind defenders but not attackers are not “safety”; they are friendly fire.
And if you care about geopolitics—and perhaps, more specifically, American hegemony—open weight models are increasingly demonstrating their value to countries and businesses around the world over proprietary ones. Washington’s imposition of export controls on Anthropic illustrates the growing state of affairs perfectly. Global companies do not want to grow dependent on American frontier models when their access can be stripped away at the whims of the US Executive branch. Open weight models for anyone to download and run on their own infrastructure offer a more stable alternative. But the most advanced open weight models are coming from China and mostly funded by Beijing, meaning they will be trained on and exert CCP values. In a global competition for influence, that’s a winning strategy for China and a losing one for America.
This hit the news today: Reuters published a recent diplomatic cable in which Secretary of State Marco Rubio reportedly called on U.S. diplomats to downplay concerns about AI kill switches in order to stem the tide of foreign countries abandoning U.S. models.
Even better than telling people to ignore the kill switch would be not having a kill switch. But perhaps a policy of “pay no attention to the man behind the curtain!” is the best America’s wizards can manage for the time being.
And as I write this there are reports of a new AI kill switch bill in the House. Oof.
This larger strategic point is one that America has faced before. We won the Internet era not by keeping TCP/IP, the web, or cryptography inside a handful of government-approved national champions. Open systems spread faster, attracted more builders, and accumulated overwhelming network effects. American influence traveled with them precisely because no ministry or company could decide who was allowed to speak, build, or connect.
Coin Center has long made the same argument about cryptocurrency. Permissionless networks extend the reach of open commerce. Privacy-preserving stablecoins can extend the reach of the dollar. Bitcoin provides a stateless monetary exit and a continuing check on rulers who finance corruption or repression through monetary debasement. Openness wins in business and exports American values through the global marketplace of ideas—even across hostile power structures themselves.
That is also the deeper issue in our response to a former White House National Security Council member’s criticism of the CLARITY Act. The author says that “accountability follows power,” which is correct. But CLARITY protects non-controlling developers precisely because they lack the power to seize assets, stop transactions, or command their users. Taken seriously, her contrary position implies that no consequential technological system should be permitted to exist unless it contains a centralized intermediary whom the government can commandeer for “safety.” That is not accountability following power. It is a regulatory demand that power be deliberately built back into systems whose defining virtue is that nobody can dominate them. Open AI, strong encryption, and permissionless cryptocurrency are therefore all fronts in the same fight over whether lawful technology may exist without a government-accessible chokepoint.
But remember: by necessity, these technologies WILL empower criminals as well as dissidents. That is true of every powerful general-purpose technology. The American constitutional wager is not that individuals are always virtuous and therefore should be free. It is that human beings are very fallible and therefore concentrated power is even more dangerous than a handful of criminal syndicates. Bad conduct should be punished as conduct—not ‘prevented’ (hopelessly) by giving governments or corporations prior control over everyone’s tools.
AI is the same. If China has recognized that open weights can win global adoption, America should not answer by imitating the authoritarian instinct for control. I don’t want the 21st century to be a rerun of the 20th but with me on the wrong side of the oceans. We should out-open China: build models that people everywhere can inspect, modify, and use without continuing permission from their creator. Show me the radio-free Europe of LLMs!
If that forces some frontier labs to find a better business model, so be it. It’s sad for them that they won’t so easily become enshrined as permanent overclass immortal living gods after all. But protecting metered-token margins is not a national strategy. Making freedom the default architecture of the world’s most important technologies is.
What we’re reading:
The Law of Code Podcast went deep on “Code is Speech.” - Every episode of the podcast is sharply produced and deeply informative. This one focuses on the issue that strikes at the core of our work. It’s long been held that the publication of code is protected speech. But what about code that does something? Between crypto and now AI, it is clear that a new front of a renewed crypto war is unfolding. This will catch you up.
An explanation of AI enabled surveillance of protestors.
In Australia, a new policy will force social media companies to publicly unmask anyone merely accused of online “vilification.”
Our friends at The Cato Institute wrote in opposition to an increasingly bipartisan idea that the answer to AI anxiety is some form of public ownership of its major companies.
This researcher is developing a test for measuring an AI model’s propensity towards censorship and other authoritarian requests.
The Machiavellian Case for Decentralized Networks argues that decentralization is not a romantic preference or crypto branding exercise. It is a practical defense against capture. Any settlement network that gets big enough will attract incumbents who want to control it. This is similar to the argument Peter made in his “Privacy is Existential” speech at Devcon last year.
Of course right when we switched to an end-to-end encrypted alternative (matrix.org) Jack announced that Block is releasing a self-sovereign, ai-agent native slack alternative Buzz. Now Peter wants the whole team on both. Peter is also building a Coin Center OS that has native agent embedding in a Coin Center knowledge graph that scrapes and automatically parses new and emerging policy documents like rulemakings and bill text into a highly engaging unified workspace. Peter also has AI psychosis, including referring to himself in the third person while writing this newsletter.









