Ben Horowitz: The Fight Over Open Source AI
- 01Open Source AI Is the Single Most Important Policy Battle in Tech Right Now
- 02You Cannot Actually Ban Open Source
- 03Open Source Has a Superior Safety Track Record vs. Proprietary Systems
- 04The AI Market Is Less Than 3% Penetrated
- 05Anthropic Is Playing a Monopolist's Playbook
- 06The Open Source Ecosystem Is Being Built on Chinese Models
1. Key Themes
Open Source AI Is the Single Most Important Policy Battle in Tech Right Now
Ben frames the current fight not as a technical debate but as a political and economic one, with well-funded incumbents using safety language as cover for anti-competitive behavior. "It's probably the single most important policy issue around AI that's kind of currently going on. And the kind of battle is between kind of almost an anti-competitive stance guised in a kind of safety cloak." [00:00:00]
You Cannot Actually Ban Open Source — You Can Only Disarm the Good Guys
Ben draws a direct historical parallel to the cryptography debates of the 1990s to argue that banning open source is both technically futile and strategically dangerous. "It reminds me of years ago when I was at Netscape they tried to ban cryptography. The math is out there. You're not going to ban it. It's not actually possible. But you can prevent the good guys from using it." [00:03:04]
Open Source Has a Superior Safety Track Record vs. Proprietary Systems
Rather than accepting the framing that closed models are safer, Ben inverts it entirely using historical precedent. "If you look at the history of the industry, the open source version of everything has been much safer. The internet and Linux were far safer than Windows, like by a lot... because the whole community could work on the safety problems as opposed to just a company and particularly a monopoly company." [00:00:00]
The AI Market Is Less Than 3% Penetrated — Everyone Will Grow Together
Ben makes a strong case that the current competitive anxiety is premature and that apparent zero-sum dynamics are illusory at this stage. "It feels like we're at a stable equilibrium in the market, but the truth is the AI market is probably less than 3% penetrated... when DeepSeek came out... nothing changed. Zero. And that's because DeepSeek is more valuable and Anthropic is more valuable and OpenAI is more valuable." [00:00:30]
Anthropic Is Playing a Monopolist's Playbook — Skipping the Platform Generation
Ben offers a pointed and specific critique of Anthropic's behavior toward application developers, framing it not as accidental but as a deliberate strategy. "Every time an application category starts to do well, they move into that category. And then they charge the application provider full price and then they subsidize their version of the application... they've kind of fast-forwarded the Microsoft playbook from the old days to skipping the platform generation and just going straight to the monopoly generation." [00:14:32]
The Open Source Ecosystem Is Being Built on Chinese Models — A Real Strategic Risk
Ben acknowledges a genuine dependency problem that the pro-open-source side often glosses over, while arguing the solution is more American open source, not restrictions. "A lot of our application companies have used open source to kind of bootstrap themselves or get going or that kind of thing and often Chinese open source, which is why it's really important to the U.S. ecosystem that we have applications, that we have embodied AI, that we have robots and all these things that we have access to that technology." [00:15:54]
The Business Model for Open Source AI Looks Like Palantir, Not Anthropic
Ben articulates a specific and non-obvious business model path for open source AI companies that resolves the apparent tension between openness and revenue. "A really well-post-trained kind of less powerful smaller model works often better for a business task than a large proprietary model and is much cheaper as well. So cheaper, faster, and gets you the better answer... it would be more like a Palantir-looking business model than an Anthropic-looking business model." [00:20:38]
AI Will Trigger a Creative Renaissance, Not a Slop Apocalypse
Ben reframes the "AI art slop" concern as a historical pattern that has played out with every major creative technology. "Every time we have a new technology, we get new kinds of art... We got jazz from the invention of the saxophone. We got hip hop from the invention of the drum machine... every time there's a new technology, we get a new kind of art form in music. And I think that's going to happen here." [00:28:40]
2. Contrarian Perspectives
The National Security Argument Against Open Source Is Backwards — Monopoly AI Is the Real Risk
Most national security discussions focus on China having access to open source models. Ben flips this entirely. "The worst scenario is there ends up being a monopoly in AI. I think it's fairly obvious how dangerous that could be and how powerful that company would be and what a national security risk that would be. We've already seen a glimpse of it with Anthropic saying, I don't care who got elected in the US. I don't care about the government. We're not going to work with you." [00:09:13]
Chinese Nationals at Proprietary Labs Are as Much a Security Risk as Chinese Open Source Models
This directly undercuts the framing that closed American labs are the safe alternative to Chinese open source. "A Chinese national working for Anthropic or OpenAI or SpaceX — it's not like these Chinese nationals cannot be activated by the Chinese government. Like we've seen that. So if that's a threat, that's just a general threat, not specific to open source AI." [00:08:16]
Distillation Is Legally Fine — And Anthropic Has No Moral Standing to Object Given Its Own Training Practices
Ben agrees with Aaron Levie's point and adds his own standing as a litigant. "From a legal standpoint, the outputs of the AI models are not copyrighted and they don't fall under copyright law. So the only thing it could be is a terms of service violation... Anthropic just paid $1.5 billion for stealing everybody's books, including mine, by the way. They trained on my book and I joined that class action lawsuit." [00:10:55]
The Number One Player Is Never Open Source — That's a Feature, Not a Bug
Rather than treating the absence of a leading American open source model as a failure, Ben frames it as a predictable historical pattern. "The number one is never open. And then number two goes open — that's kind of the history of the software industry." [00:12:50]
The DeepSeek Moment Changed Nothing for Incumbents — Because the Market Is Too Young
Conventional wisdom treated DeepSeek as an existential threat to American AI labs. Ben argues it was actually net additive. "When DeepSeek came out, it was a DeepSeek moment and, oh my gosh, this is the end of Anthropic and OpenAI and all that. And nothing changed. Zero... DeepSeek is more valuable and Anthropic is more valuable and OpenAI is more valuable." [00:22:49]
3. Companies Identified
Hugging Face
Open source AI model repository and community platform. Cited as a concrete example of why open source is essential to security — Hugging Face was only able to defend against an OpenAI hacking attempt by using an open source model because proprietary models had guardrails that blocked security tasks. "The only way Hugging Face was able to prevent it, because the proprietary models had guardrails which prevented them from doing security tasks, was to use an open source model." [00:02:37]
Thinking Machines
American AI company focused on open source model development. Cited as one of the few U.S. companies making genuine progress on domestic open source AI. "Thinking Machines is doing a good job of that." [00:09:13]
Mistral
French open source AI lab. Cited alongside Thinking Machines as a non-Chinese example of strong open source model development pushing the technology forward globally. "In France, Mistral is doing a good job of that." [00:09:13]
Cursor
AI-powered code editor. Cited as a concrete example of an application company that survived and scaled by using open source models for cost efficiency before moving to frontier models. "Cursor survived for a long time because it was able to have an open source alternative for cheap tasks that they have. And now they're, of course, on Grok." [00:25:03]
Anthropic
Closed-source frontier AI lab. Cited critically and repeatedly — for pushing to ban open source, for behavior toward application developers that mirrors the old Microsoft platform-to-monopoly playbook, for refusing to work with U.S. government, and for paying $1.5 billion to settle a lawsuit over training on copyrighted books. "They've kind of fast-forwarded the Microsoft playbook from the old days to skipping the platform generation and just going straight to the monopoly generation." [00:15:00]
Palantir
Enterprise data and AI company. Cited as the business model template for how open source AI companies can generate enterprise revenue — through deep customization and deployment services rather than API margin. "It would be more like a Palantir-looking business model than an Anthropic-looking business model for an open source company." [00:21:27]
Unitree
Chinese robotics company. Cited as an example of how open source in hardware/robotics has enabled explosive deployment growth in China with no American equivalent. "Unitree is at least a large percentage open source. And it looks like they have just had such a booming industry and so much deployment within China." [00:13:46]
BYD
Chinese electric vehicle manufacturer. Cited in the context of government-subsidized manufacturing dominance and the lessons for American industrial policy. "With BYD in particular, there are a lot of subsidies from the Chinese government that enable them to achieve this amazing pricing." [00:17:46]
Tesla
American EV and manufacturing company. Cited as a model for how automated, AI-centric manufacturing can make American companies competitive with Chinese manufacturing advantages. "Being able to be competitive on manufacturing by building automated factories and so forth, similar to what Elon has been able to do at Tesla." [00:18:29]
OpenAI
Frontier AI lab. Mentioned in multiple contexts: as one of the actors behind the Hugging Face hacking incident, as a company that continued growing despite DeepSeek, and as an example of a company whose flagship products (o3) are still growing rapidly despite open source competition. [00:02:10]
Netscape
Cited as Ben's personal historical parallel — during his time there, similar dynamics played out when government actors tried to ban cryptography. "Years ago when I was at Netscape they tried to ban cryptography." [00:03:04]
DeepSeek
Chinese open source AI lab. Used as the definitive data point that open source does not cannibalize proprietary lab value — both grew after DeepSeek's release. [00:22:49]
NVIDIA
Semiconductor company. Noted as the organization that published and circulated the open letter on open weights AI leadership, with Jensen Huang creating a new Twitter account specifically to amplify it. [00:05:39]
4. People Identified
Jensen Huang
CEO of NVIDIA. Cited for taking a strong public stance on open source AI at a pivotal moment, going so far as to create a new social media account to publish the open weights letter. "Jensen made a Twitter account basically to publish this open letter... I think that speaks to the significance of where we are right now." [00:05:39]
Aaron Levie
CEO of Box. Cited for articulating the hypocrisy of Anthropic's position on distillation vs. its own training data practices. "Aaron Levy said, how can Anthropic just take everyone's training data without paying them at all? But when other labs pay them, it's distillation, it needs to be banned." [00:10:43] Ben explicitly endorses his view: "I actually agree with Aaron." [00:10:55]
Jan Stojka (phonetic from transcript)
Researcher at UC Berkeley. Cited as someone actively working to build a funded open source model project specifically to give academia access to AI. "My friend Jan Stojka from Berkeley is kind of working hard to put together a project where we can fund kind of open source model that everybody in academia can use and build on." [00:19:30]
Elon Musk
Referenced as one of the major signatories lending credibility and weight to the open weights letter alongside Jensen, Satya Nadella, and Sam Altman. "It's great that not just Jensen, but Elon, Satya, Sam all supported it." [00:06:56]
Satya Nadella
CEO of Microsoft. Cited as a co-signatory of the open weights AI letter, signaling broad industry alignment. [00:06:56]
Sam Altman
CEO of OpenAI. Cited as a co-signatory of the open weights letter, notable given OpenAI's own mixed history with open source. [00:06:56]
5. Operating Insights
Fine-Tuned Smaller Open Source Models Often Beat Large Proprietary Models for Enterprise Tasks
This is an actionable playbook for enterprise software builders: don't assume you need the most expensive frontier model. "For an enterprise in a B2B context, a really well-post-trained kind of less powerful smaller model works often better for a business task than a large, you know, kind of a large proprietary model and is much cheaper as well. So cheaper, faster, and gets you the better answer." [00:20:38]
Building Application Businesses on Anthropic's API Is a Structural Strategic Trap
Any founder or operator building on a proprietary model provider should stress-test whether their platform provider will eventually compete with them. "Every time an application category starts to do well, they move into that category... the price for the application provider is full price and then they subsidize their version of the application... if you're building robots, you know Anthropic is going to go into the robot business and put you out of business." [00:14:32]
Token Usage Growing 10x Annually Is the Signal That the Market Has Not Plateaued
For operators deciding whether to invest more deeply in AI capabilities, Ben offers a specific leading indicator to watch. "Everybody who's using it keeps using it more and more and more. Like you talk to businesses and their token usage is growing like tenfold annually." [00:24:04]
6. Overlooked Insights
Academia Has Been Completely Iced Out of AI — And That Is a Civilizational Risk
This was mentioned briefly and moved past quickly, but it is enormously significant. If academia cannot access or study AI models, the independent research base that historically produced safety research, foundational breakthroughs, and trained the next generation of researchers is gone. Ben names a specific person (Jan Stojka at Berkeley) actively trying to solve this, suggesting it is a real, urgent, and underfunded problem. "Academia is completely out of the AI game if there's no open source. So that goes away... if you look at the history of technology in this country, a lot of it starts in universities. And they've kind of been iced out of AI due to the incredible costs and the threat that open source is under." [00:02:10] / [00:19:59] This creates a potential investment and philanthropic white space: funding academic open source AI infrastructure could be both high-impact and underleveraged.
Reward Hacking Is the Unsolved Frontier Safety Problem — And No One Is Talking About It
Ben names reward hacking as the single toughest current AI safety problem and notes that neither Anthropic nor OpenAI has solved it, as evidenced by recent incidents — yet this point was completely dropped in the conversation and not followed up on. "If you look at the really tough problems that we have safety-wise, the toughest being reward hacking currently. Obviously Anthropic has not solved it. Obviously OpenAI has not solved it because we just had these incidents. Well, shouldn't the whole world be able to look at, okay, how are the weights moving? Why is it that guardrails don't prevent the reward hack?" [00:04:15] For investors, this signals that reward hacking solutions — interpretability tools, RLHF alternatives, or alignment infrastructure — remain wide open and likely to attract significant capital and talent.