# Open Source AI: Safety, Security, and Market Strategy

**Podcast:** a16z Podcast
**Published:** 2026-07-26

## Transcript

If you look at the history of the industry, the open source version of everything has been much safer.
So the internet and Linux were far safer than Windows.
Like, by our lot.
The safest thing for the world is that there's not one AI to rule them all, that there's AI for everybody.
And I think that open source is basically the best path towards that goal.
It's probably the single most important policy issue around AI.
It feels like we're at a stable equilibrium in the market, but the truth is the AI market is probably less than 3% penetrated.
Should AI be open?
Theo Jaffe and Sofia Puccini are joined by Ben Horowitz to discuss the battle over open source AI, why he believes open models are essential to innovation and national security.
and what the future of AI competition means for startups, frontier labs, and the broader technology ecosystem.
We are live with Ben Horowitz of Andreessen Horowitz, who needs no introduction.
So we'll just dive right into it.
Ben, welcome back to MTS.
Thank you, thank you.
Happy to be here.
So, so much has happened in the world of open source, open weights in the last couple of weeks.
It's gotten, you know, it's gotten real.
There's some drama going on.
There's an open letter released by NVIDIA today called Open Weights in American AI Leadership, signed by many companies, including Andreessen Horowitz.
So can you tell us a little bit about the intent behind this letter and what you hope to achieve from it?
Yeah, so I think that it's probably the single most important policy issue around AI that's kind of currently going on.
And, you know, the kind of battle is between kind of almost an anti-competitive stance guised in a kind of safety cloak is kind of what we ought to be doing.
And so if you look at, you know, why is open source important?
And there's many reasons.
You know, the first, we'll just start.
academia.
Academia is completely out of the AI game if there's no open source.
That goes away.
I think secondly, we just had a really interesting security incident with OpenAI hacking into Hugging Face.
The only way Hugging Face was able to prevent it because the proprietary models had guardrails which prevented them from doing security tasks was to use an open source model.
You know, and I think the important point there is you can't actually ban open source, of course.
You know, it's out there.
It's a file.
It's on the internet.
Like, we have no way of doing that.
And it reminds me of, you know, years ago when I was at Netscape, they tried to ban cryptography.
And, like, there's, you know, the math is out there.
Like, you're not going to ban it.
It's not actually possible.
But you can prevent the good guys from using it.
And that's what would happen, I think, in the case of an open source ban is, you know, the threats would be, well, you can't work with the U.S.
government if you use open source or you can't do this.
So a company like Hugging Face would not be able to actually use the product.
So that, you know, would be bad.
But then kind of getting into just like if you look at the history of the industry, the open source version of everything has been much safer.
So the internet...
And Linux were far safer than Windows, like by our law.
And why is that?
Well, because the whole community could work on the safety problems as opposed to just a company and particularly a monopoly company that, you know, like you can't, even if Windows has a million security bugs, there's nothing we can do about it because it was a monopoly at the time, right?
And so that, you know, that's a very difficult position for the world to be in.
If you look at now the argument against open AI or AI being open source is, oh, well, nobody understands how the weights work.
So, you know, it's not like people could inspect it.
But why is it better to not see the weights if that's the case?
And I think in reality, if you look at the really tough problems that we have safety-wise, the toughest being reward hacking.
currently, and obviously Anthropic has not solved it.
Obviously, OpenAI has not solved it because we just had these incidents.
Well, shouldn't the whole world be able to look at, okay, how are the weights moving?
Why is it that guardrails don't prevent the reward hack?
And maybe somebody can come up with an answer, somebody who doesn't work for one of the proprietary labs who are much more focused on, you know, obviously keeping ahead on the benchmarks and getting the money and all that kind of thing, you know, what if the whole community could work on it?
So it's like really, really important, I think, to safety in general.
And then, you know, kind of finally, the safest thing for the world is that there's not one AI to rule them all, that there's kind of AI for everybody.
And I think that open source is basically the best path, you know, kind of towards that goal.
Right.
So Jensen?
made a Twitter account, basically, to publish this open letter.
Right?
So that, I think, speaks to the significance of where we are right now, that he was like, okay, now is the time to, you know, speak out about this and get all these companies to, like, you know, co-sign it.
What do you think are some of the risks right now from, like, a government action perspective on open source?
Well, look, I think there's a huge push with a lot of money behind it.
you know, particularly from Anthropic to ban open source.
I think that it is kind of nefarious from my point of view, but, you know, whatever their motivation is, they do have, so one of the things that happened with cryptography is there are people who are very senior in the intelligence community who didn't understand the technological aspect of it.
who pushed for banning cryptography because they wanted control.
And I think that it's a similar thing here where it just feels like more control if you can stop some kind of AI.
But those are very powerful forces in the conversation right now.
And I think that there is certainly a kind of pretty strong community pushing for the banning of the...
of open source.
And so that's why this letter was so important.
It's so great that, you know, not just Jensen, but Elon, Satya, Sam all supported it.
And I think it's, I just think it's very obviously the right answer for safety, the right answer for America.
And it would be a real shame if we, you know, kind of shot ourselves on the put on this.
Yeah.
Well, another angle that many people talk about with respect to open source is China and national security, as opposed to like AI safety stuff.
And some people say, you know, it's a national security risk for so many American startups to be dependent on like infrastructure that comes from China.
You know, in the event that, for example, China decided to cut everything off and stop releasing better open source models to American companies.
Or perhaps they could, you know, in an AI future, make these open source models like sleeper agents, basically.
Or you can think of all kinds of things that they could do.
Yeah, I mean, as could a Chinese national working for Anthropic or OpenAI or, you know, SpaceX, right?
Like, it's not like these Chinese nationals cannot be...
activated by the Chinese government.
Like, we've seen that.
So, like, if that's a threat, like, I think that's just a general threat, not specific to open source AI.
And then nothing against Chinese nationals.
We love them.
They're great for our country and so forth.
But, like, if you're worried about that, you know, you ought to be worried about it.
Like, the more likely way, I think, would be that kind of spy activation.
But, like, it's open source.
And so, If they stop making it, like, we've still got the last code base.
We can train up the model.
We can, you know, we can learn from it.
In the meanwhile, there's, I mean, the great thing about open is it's open.
And, you know, look, we need to build our own open source products here.
Thinking Machines is doing a good job of that.
I think in France, you know, Mistral is doing a good job of that.
So, like, we need to keep pushing the technology forward, the open technology.
So that, look, it needs to be available everywhere for everyone.
Like we can't be held hostage by, like the worst scenario is there ends up being a monopoly in AI.
I mean, I think it's fairly obvious how dangerous that could be and how powerful that company would be and what a national security risk that would be.
We've already seen a glimpse of it, right, with Anthropoc saying, like, I don't care who got elected in the U.S.
I don't care about the government.
I don't care about the Department of War.
We're not going to work with you.
We're in charge.
And so you look at that, you go, okay, that seems like a much bigger national security risk than the kinds of little holes people are trying to poke in the open source story.
So I just think it's very, very important that this technology proliferate and not be kept contained in a single company.
Yeah, definitely.
So we have like...
kind of become a little more defenders of distillation recently.
So we talk about how, you know, like distillation is not actually like illegal.
Like a lot of the labs are still paying API prices.
to, you know, like use the models.
So what are your thoughts?
Do you think it's part of like a healthy competitive landscape?
We talked to Aaron Levy earlier about this and he was like, you know, how can Anthropic like just take everyone's training data without paying them at all?
But when other labs pay them, it's distillation.
It needs to be banned.
Yeah, I actually agree with Aaron.
And I think that's right.
Like from a legal standpoint, there is the outputs of AI models are not copyrighted.
They don't fall under copyright law.
So the only thing it could be is a terms of service violation.
But look, I think generally that's right.
You know, Anthropic just paid $1.5 billion for stealing everybody's books, including mine, by the way.
They trained on my book and I joined that class action lawsuit.
You know, not to say, look, I'm for training the model, building a statistical model of the things we know.
I think that's generally good for the world and so forth as long as you don't violate the copyright and reproduce the original work.
And I think the same, yeah, like I think distillation is generally good for the world.
I also think they're going to have a very hard time stopping it for many reasons.
Yeah, they have theories on how they're going to stop it, but I'm not sure that those are going to succeed, so we'll see.
But yeah, I think distillation is good and like the whole idea that we're stealing American stuff.
By the way, the data companies are all out selling to everybody, you know, including the Chinese companies that are building these things.
So, you know, I don't know how much you can contain all this stuff anyway.
So why do you think that so far, over the last few years, Chinese labs have surpassed American labs in terms of open source performance?
Well, because I think that all the American labs have kind of built their businesses on proprietary models.
And there's a lot kind of that becomes, and they have to, to kind of afford the GPUs.
You know, they need these very high valuations to keep ahead on the GPUs to keep going.
And, you know, because they're in the lead, you know, distillation doesn't work for them because their model is on the cutting edge.
It's on the frontier.
And that's just how kind of the market's evolved.
I think, look, generally that's been the way it is.
Like the number one is never open.
And then, you know, number two goes open is kind of the history of the software industry.
I do think that we're going to see, I mean, like I said, with Thinking Machines, they've got, you know, they're making really good headway with their open source efforts.
So, you know, hopefully we'll see kind of more of that and kind of more breakthroughs, you know, on the open source side.
But like part of the challenge or part of the reason why AI is just so different than software is you can throw money at the problem, right?
Like, so if you have more GPUs, that actually turns out to be a really big deal.
Yeah.
What about open source in industries like robotics?
Because like Unitree is at least like, you know, a large percentage open source.
And it looks like, you know, like they have just had like such a, you know, booming industry and like so much deployment within China.
And we don't have anything like that here.
Do you think that we're missing like that open source ecosystem in the U.S.?
Or is it just a different thing?
I mean, there's obviously supply chain and stuff.
No, I think there's a lot to be said for that, right?
Because, you know, as an application, so what's happened, the other thing that we haven't spoken about, like, is, well, what's the AI platform?
And, you know, so if you're an application provider, what do you build on?
And what we've seen is it's been already...
fairly dangerous to build on Anthropoc because every time an application category starts to do well, they move into that category.
And then they've, you know, like we've seen them do like very aggressive things where, you know, the price for the application provider is full price and then they subsidize their version of the application.
And so it's a kind of that.
They've kind of fast-forwarded, I would say, the Microsoft Playbook from the old days to skipping the platform generation and just going straight to the monopoly generation.
And so if you're an application provider, like, okay, how can I safely build on a proprietary model if that company is going to come attack me and then charge me much more than they're charging themselves to do the same thing?
And so open source is kind of a way that the ecosystem gets built.
So if you're building robots, for example, if you were to build your robot on Anthropoc, then at some point, you know Anthropoc is going to go into the robot business and put you out of business just by either cutting you off or overcharging you.
And so this is kind of a way that their ecosystem can grow by building on the open source.
And hopefully, by the way, a lot of our industry has grown.
A lot of our application companies.
had used open source to kind of bootstrap themselves or get going or that kind of thing, and often Chinese open source, which is why, you know, it's really important to the U.S.
ecosystem that we have applications, that we have embodied AI, that we have robots and all these things that we have access to that technology because the kind of other model is a monopoly model where there's one company that owns all the applications and all the robots and all of everything.
And look, I'm not even mad at them for doing that necessarily.
That's their business approach.
But the consequences of it, if they're able to ban their competitors, is not good.
Yeah, I also worry about these very monopolistic, centralized futures.
And one area in particular that I think might be concerning in the future is if one AI company is able to use its AIs to...
automated AI research process and then become much more capable than everyone else very quickly.
It seems like, you know, that wouldn't be so good for like a pluralistic, you know, startup ecosystem.
Yeah, that's certainly their strategy, you know, and we'll see how it goes.
But I think that kind of the best hedge against that is for like many, many companies being able to do AI, which is why the open models are powerful in that context.
Yeah.
I guess speaking of China.
There's a lot of things that are like, you know, either like tariffed or I mean, we export control.
We also tariff them like things like EVs, right?
We talk about EVs all the time.
And if we had like a, you know, BYD level pricing for EVs in the U.S., that would just be like so huge.
Do you think there's a way that we could move towards that future?
Like what would have to what would it take to get to that?
Well, I think that.
You know, with BYD in particular, there are a lot of subsidies from the Chinese government that enable them to achieve this amazing pricing.
And a lot of it is a kind of a, well, so kind of getting into manufacturing.
And, you know, the U.S.
is, so we, as a country, kind of invented so much of manufacturing and then kind of forgot what we knew.
So, like, if you go back to we won World War II based on our superior manufacturing capability, and then, like, over the next whatever hundred years, we forgot to hold that.
We need to rebuild that capability, and manufacturing has changed and is becoming much more automated, much more kind of AI-centric.
And so I think as we kind of build into the second, or you call it the third industrial revolution, That, you know, being able to be competitive on manufacturing by building automated factories and so forth, you know, similar to what Elon has been able to do at Tesla and in the Gigafactory and so forth, is going to be the way that we get to competitiveness there for sure.
Yeah, definitely.
Yeah.
What other open source companies with regards to AI?
No, we have like...
A16Z port co-thinking machines.
Yeah.
But, you know, where else?
And Mistral, yeah, yeah.
Where else do you see, like, new open source models coming out of?
Would it require literally just like a Gates Foundation level?
I think, you know, there's not a lot coming out in, yeah, there's not a lot coming out in America right now.
But, you know, and...
But I think it can happen.
And then there are some real efforts in academia.
My friend Jan Stojka from Berkeley is kind of working hard to put together a project where we can fund kind of open source model that everybody in academia can use and build on.
And, you know, I think that's just really important.
You know, if you look at the history of technology in this country, a lot of it, you know, kind of starts in universities.
kind of been iced out of AI due to the incredible cost and the threat that open source is under.
And the lack of U.S.
open source in particular, yeah.
In the long run, what exactly is the incentive for a business to release open source models, especially if they're a foundation lab and most of their business is making the models, which are very expensive?
Yeah, so I think that, I mean, this is where, like, I'm glad you both are pro-distillation because I think that's an important equation.
But look, I think that there's different business.
Like, I think the business model of selling, serving the model at a very high premium doesn't work if you're open source.
But there's other things, you know, particularly, like, one of the things we already know is that, you know, for an enterprise in a B2B context, A really well post-trained, kind of less powerful, smaller model works often better for a business task than like a large, you know, kind of a large proprietary model and is much cheaper as well.
So cheaper, faster, and gets you the better answer.
So I think that it would be more like a kind of a Palantir-looking business model than it would be an anthropic-looking business model.
source company.
And then, you know, true also on the consumer side, you know, we've seen on consumer, like, the use case really, really matters.
And so kind of tuning a model for that kind of thing can really work.
Do you think that...
open source models are currently a threat to the business model of large closed source foundation model developers?
Like I can imagine, yes, because if people can get similar capabilities for a much lower price point, they'd switch over.
But also like when you compare Kimmy to Fable or Sol, there's definitely areas where Fable and Sol are just way better and people will pay for them anyway.
Yeah, I don't think anybody's a threat, a real kind of current threat to anybody else's business right now.
in that we're so early in the market.
So the thing that's very deceptive about AI is because the market is so much larger than any other market we've seen prior, that it feels like, okay, we're kind of at a stable equilibrium in the market.
But the truth is, the AI market is probably less than 3% penetrated.
And so everybody's going to grow.
Right?
Like when DeepSeek came out, it was a DeepSeek moment and oh my gosh, and this is the end of Anthropoc and OpenAI and all that.
And nothing changed.
Right?
Like nothing changed.
Zero.
And that's because, but DeepSeek is more valuable and Anthropoc is more valuable and OpenAI is more valuable.
You know, they all grew.
And SpaceX is more valuable.
So I think that at this stage of the market, everything is going to grow a lot and nobody's going to pounce on other people's market share in a way that is so material that it's going to cripple them.
Now, someday, when we get to some kind of equilibria in the market and there's so much share to go around and then you're fighting each other for share, then these things may come into play.
But for right now, I don't think so.
Yeah, the pie overall is so big.
I wonder if this follows also for like...
It's like the biggest pie of all time.
Yeah.
When would we have some indication of the AI market is actually settling to an equilibrium?
We can't really rely on historical data because this is sort of an unprecedented technology.
Yeah, I think it's pretty hard to see because everybody who's using it keeps using it more and more and more and more.
You talk to businesses and their token usage is...
growing like tenfold annually.
So we're, but look, I think we'll see it when, you know, you kind of see growth really slow down in, you know, in the various players and things like that.
But as long as things are growing like several, you know, a thousand percent a year, 500 percent a year, like we're nowhere near to that state.
You know, in stable markets, things grow like, you know, whatever.
Yeah.
What companies do you see are currently benefiting the most from very, very cheap intelligence?
Like the kind of companies that use the Kimis and the DeepSeaks?
Yeah, that's a good question.
I mean, I think that a lot of software companies are able to use it for various attacks.
I think on things like customer support and specialized applications, people are able to benefit a lot from them.
And then, you know, look, I think Cursor survived for a long time because it was able to have an open source alternative for cheap tasks that they have.
And, you know, now they're, of course, they're on Grok.
But, you know, I think every application company in AI world benefits from open source right now to some degree.
Like they're all using some, nobody's not using an open source model who's an application provider.
that I know of.
So it's kind of that whole field.
And so it's really a catastrophe for that whole part of the ecosystem if, you know, these guys get their way.
When it comes to these, like, very cheap models, it seems like I can imagine a future where if the really good models, like the flagship frontier models, get much more capable.
and can, you know, really do a lot of the tasks that an employee can do at a job, that enterprises would be gladly willing to spend a lot more on that rather than go to the much cheaper models in order to cut costs.
So do you think that could...
I think that's been the case so far, right?
Like, so it's not like Anthropics having trouble selling Fable or OpenAI is having trouble selling Sol.
Like, those things are growing very fast in our book.
I'm very fast.
So I think that's true.
And then there's a question about which categories of jobs would you rather have super intelligence and pay 8x or 10x as much for?
And then which class of jobs would you rather have something faster and cheaper?
And that'll be a question.
And I think there's probably plenty of jobs in each category, just like the humans, right?
Would you pay a crazy amount of money for an AI researcher?
Oh, definitely, like clearly.
And then there's, you know, okay, would you pay an insane amount of money for a janitorial service?
Probably not.
You know, like would you pay 100x for a better janitor?
Maybe not.
You know, would you pay 100x more for a better accountant?
I don't think so.
Yeah.
So there's different jobs in different categories.
So, you know, not everything will be that, but there will be plenty of jobs that are that.
Another question, it's kind of random, but how optimistic are you about AI art?
How do you think we're going to fix the slop problem?
Do you think it's going to get worse before it gets better?
No, I think it'll...
The way I would look at it is I'm not that worried about the slot problem.
I think that, I think the exciting thing is that for creatives, any idea you have is now possible.
And so we're going to get a lot of new ideas, great new ideas and everything, you know, film, music, you know, new kinds of things that, you know, new kinds of video ideas and so forth.
So I think it's going to be.
a little bit of a renaissance for art in that like every time we have a new technology, we get new kinds of art.
And, you know, from like the invention of the saxophone, which I think was like in the 1800s, 1850 or something like that, the invention of electric guitar, you know, we got rock and roll from that.
We got jazz from the...
invention of the saxophone and then we got hip hop from the invention of the drum machine.
Like, every time there's a new technology, we get a new kind of art form in music and I think that's going to happen here.
And there will be stuff that's really good and there will be more people who can make bad things.
There was more people who could be bad rappers than there were who could be bad rock and roll because you didn't have to learn how to play an instrument.
But that's okay.
Like, I think that's fine.
I'm for that.
Like, you know, anything that, I also think it's just good for everybody to be able to express themselves.
And so better tools for expression is generally a good thing, you know.
There are issues with it.
You know, I do get nostalgic for some of the things of the past, of course, but, you know, like, generally.
What music are you listening to now?
Yeah, so it's been a little bit of a drought for me on new music, but.
I actually like the new, the Wyclef album.
I thought it was pretty interesting that he just did.
And I've been listening to a lot of old music.
I've been listening to Curtis Mayfielm, who is really underrated, really good.
Yeah.
I think like with things like this, it increases the amount of like really mediocre artists.
Not mediocre because that's mean, but like, yeah.
And then it makes it really hard to be very, very good.
Just because there's so much competition in the space and everyone is like, it's like very democratized, which is a good thing.
But it's just hard for like from a discernment perspective kind of.
Yeah, but that kind of happened in a big way with Spotify too, right?
Yeah.
SoundCloud.
SoundCloud, yeah.
Yeah, SoundCloud, like anybody could put anything on their YouTube, all that kind of thing.
But, you know, I still think there's...
There's great stuff that's higher art and there will continue to be, I think.
Yeah, I totally agree.
Well, Ben, it's been so great having you on MTS to talk about open music.
Thanks for joining us.
Thanks so much for joining.
Okay, thanks a lot and appreciate it very much.
Thanks for listening to this episode of the A16Z podcast.
If you liked this episode, be sure to like, comment, subscribe, leave us a rating or a review.
and share it with your friends and family.
For more episodes, go to YouTube, Apple Podcasts, and Spotify.
Follow us on X at A16Z and subscribe to our Substack at a16z.substack.com.
Thanks again for listening, and I'll see you in the next episode.
This information is for educational purposes only and is not a recommendation to buy, hold, or sell any investment or financial product.
This podcast has been produced by a third party and may include paid promotional advertisements, other company references, and individuals unaffiliated with A16Z.
Such advertisements, companies, and individuals are not endorsed by AH Capital Management LLC, A16Z, or any of its affiliates.
Information is from sources deemed reliable on the date of publication, but A16Z does not guarantee its accuracy.
