Te reo Māori has no commercial market to speak of. A broadcaster in the far north of New Zealand has been building speech models for it anyway, under a licence written so the recordings stay with the communities that gave them. Farmers in East Africa point a phone at a cassava leaf and get a diagnosis back with no signal at all, from a model small enough to sit on the handset. In Switzerland, a public consortium trained a national model on public supercomputers and released all of it: weights, data, training code. None of them asked permission, and none of them could have rented this. They own it, and that is the whole idea.
Read what follows as a map: where open AI is winning, where some numbers surprised even us, and where it is exposed. A case that hides its weak points is an advertisement. In the six weeks since our first draft, a major US lab returned to open weights and Washington debated a ban and declined it. The map moved while we drew it. We have been here before. Mozilla exists because one company tried to own the front door to the web, and an open community made sure it never could. The same play is running again, one layer up. Tell us where you agree or, more importantly, where you think we're wrong.
The best open model trails the closed leader by three points at 60% of the price, and the gap resets every release cycle.
K3 debuted first on LMArena's Frontend Code Arena at 1679 Elo, leading in six of seven frontend domains, plus coding, instruction-following and general knowledge.
Frontend Code Arena measures building website and UI code, scored by blind developer votes.
K3 scores 88.3 against Sol's 88.8 on Terminal-Bench 2.1. It wins Program Bench, SpreadsheetBench 2 and BrowseComp, and loses FrontierSWE at 81.2 against Fable 5's 86.6.
Terminal-Bench, Program Bench and BrowseComp measure agent work, running terminal tasks, writing programs and researching the web. FrontierSWE measures resolving real software-engineering tickets.
Fable 5 leads K3 by 92 Elo on GDPval-AA v2, the largest Elo separation among the shared benchmarks, alongside long-context fidelity and conversational polish, which Moonshot concedes still trails.
GDPval-AA v2 measures expert-graded professional knowledge work, where long-context reliability and polish appear.
Open reaches production 12 points less often than closed, and the gap is tooling, not capability. Mozilla / SlashData 2026 developer survey.
| Challenge | W. Europe & Israel | N. America | Greater China | South Asia | East Asia ex GC | S. America | E. Europe & CIS | Oceania | All |
|---|---|---|---|---|---|---|---|---|---|
| High infrastructure or compute costs | 25% | 26% | 29% | 28% | 28% | 28% | 29% | 18% | 27% |
| Security, privacy, or compliance concerns | 20% | 27% | 18% | 39% | 29% | 28% | 25% | 22% | 26% |
| Ongoing maintenance and updates | 27% | 26% | 18% | 26% | 20% | 31% | 21% | 25% | 24% |
| Complexity of deployment, hosting, or scaling | 27% | 24% | 19% | 24% | 11% | 30% | 26% | 25% | 23% |
| Lack of specialised support | 17% | 16% | 21% | 31% | 24% | 23% | 23% | 32% | 22% |
| Difficulty evaluating or comparing models | 14% | 17% | 14% | 23% | 16% | 26% | 25% | 18% | 18% |
| Difficulty fine-tuning or customising | 22% | 18% | 18% | 20% | 11% | 22% | 18% | 12% | 18% |
| Difficulty integrating into existing systems | 19% | 21% | 14% | 20% | 7% | 26% | 19% | 20% | 18% |
| Insufficient documentation or learning resources | 18% | 15% | 15% | 17% | 15% | 20% | 24% | 15% | 17% |
| Model performance is not good enough | 18% | 15% | 13% | 22% | 16% | 17% | 19% | 8% | 17% |
| No major challenges | 9% | 21% | 16% | 5% | 14% | 4% | 8% | 12% | 12% |
| Weighted sample size | 286 | 277 | 206 | 192 | 164 | 147 | 98 | 39 | 1411 |
Twitter acquired Smyte and shut off its API within the hour. Customers on multi-year contracts got about 30 minutes' notice. Discord rebuilt its safety stack from scratch; that rebuild became Osprey.
Nine layers, 48 components, nine criteria. Click a layer to open it.
A frontier model went dark for nineteen days. Metered pricing broke budgets. Washington debated a ban and declined it.
You can switch off a model. You cannot switch off a copy already running on a machine you hold.
Nvidia bought Hugging Face for $12.93B. Stripe bought OpenRouter for ~$7.5B.
| Company | HQ | Layer | Disclosed funding | Valuation | Revenue signal | Leading investors | Stage |
|---|---|---|---|---|---|---|---|
| Databricks | USA | Enterprise platform | $5B round, 13 Aug | $190B (from $134B six months earlier) | $7B run-rate, >80% YoY in Q2 | Coatue (lead) · Blackstone · MGX · T. Rowe · Sixth Street Growth | Private |
| DeepSeek | China | Frontier open weights | $7.4B (~$2.8B founder's own) | $50B+ | ~$220M ARR (mid-2025, last disclosed) | Liang Wenfeng · Tencent ($1.4B) · CATL ($700M) · China National AI Fund | Private |
| Moonshot AI | China | Open weights (Kimi) | $7.3B | Pre-IPO track to $50B | — | Meituan/Long-Z · Alibaba · Tencent · HongShan | Private |
| Zhipu / Z.ai | China | Open weights (GLM) | $6.4B (~$1.5B private + $640M IPO + $4.3B placement) | Public | — | Public on 2513.HK since January; prior Alibaba and Tencent | Public |
| Mistral AI | France | Open weights + platform | $3.9B; ~€3B in talks | ~€20B in talks (€11.7B, Sep 2025) | ~$400M ARR (V1 figure) | ASML ($1.4B) · a16z · Lightspeed · Nvidia; Samsung in advanced talks for up to €1B | Private |
| MiniMax | China | Open weights | $3.7B (~$1.15B private + ~$590M IPO + $2B placement) | Public | — | Public on HKEX | Public |
| Reflection AI | USA | Open weights | $4.6B | — | — | Nvidia · Disruptive · Sequoia · Lightspeed · DST Global | Private |
| Cerebras | USA | Compute | $3.7B private | Public | — | Fidelity · Atreides · G42 · Tiger Global; $5.55B IPO in May | IPO May 2026 |
| StepFun | China | Open weights | $3.2B | — | — | HK listing planned late 2026 | Private |
| Baseten | USA | Inference | $2.1B | — | — | IVP · CapitalG · Nvidia | Private |
| Thinking Machines | USA | Open weights + training loop (Tinker) | $2.0B | ~$12B | Inkling (Apache 2.0) Jul 15; Inkling-Small Jul 30 | a16z · Nvidia · AMD · Cisco | Private |
| Fireworks AI | USA | Inference | $1.8B | — | — | Sequoia · Nvidia · AMD · Index | Private |
| Cohere | Canada | Enterprise / on-prem | $1.6B closed (~$600M Series E not confirmed) | ~$20B EV combined with Aleph Alpha | Command A+ under Apache 2.0, May 2026 | Radical Ventures · Nvidia · AMD · Schwarz Group ($600M lead, not yet closed) | Private |
| Together AI | USA | Inference cloud | $1.3B; $800M in July | $8.3B | — | Aramco Ventures (lead) · General Catalyst · Prosperity7 · Nvidia | Private |
| Hugging Face | USA / France | Hub | $400M | $12.93B (acquisition) | — | Salesforce · Google · Nvidia · IBM · AMD · Intel · Qualcomm | Acquired by Nvidia, 3 Sept 2026 |
| LangChain | USA | Harness tooling | $260M | — | 126k+ stars, ~60% dev share | IVP · Sequoia · Benchmark · CapitalG | Private |
| Prime Intellect | USA | Post-training platform (ADAPT layer) | $130M Series A, July | — | — | Radical Ventures; Aaron Levie · Aravind Srinivas · John Schulman · Matthew Prince | Private |
| Acquirer | Target | What it does | Value | Date |
|---|---|---|---|---|
| Nvidia | Hugging Face | The open-model hub and its toolchain | $12.93B | 3 Sept 2026 · signed |
| Stripe | OpenRouter | AI model gateway and routing platform | ~$7.5B per NYT | 19 Aug 2026 · announced |
| Cohere | Aleph Alpha | Sovereign / enterprise open-weight LLMs | ~$20B EV | Apr 2026 · pending close |
| CoreWeave | Weights & Biases | MLOps serving open-model builders | $1.7B | May 2025 |
| Databricks | MosaicML | Open MPT LLMs + training platform | $1.3B | Jul 2023 |
| Nvidia | Run:ai | GPU orchestration, to be open sourced | $700M | Late 2024 |
| AMD | Silo AI | Open-model lab, OpenEuroLLM co-lead | $665M | 2024 |
| Nvidia | Gretel | Synthetic data | $320M | 2025 |
| Nvidia | OctoAI | Inference optimization for open models | $165M (reported) | Sep 2024 |
| Rubrik | Predibase | Open LoRAX fine-tuning | $100–500M | Jun 2025 |
| OpenAI | Astral (uv, ruff) · Promptfoo | Developer-tooling tuck-ins | Undisclosed | 2026 |
| Company | Invested in an open lab | Ships its own open-weight model |
|---|---|---|
| Microsoft | Mistral AI | Phi · MIT |
| Amazon | Hugging Face | — |
| NVIDIA | Hugging Face (acquired), Mistral, Together, Cohere, Fireworks, Baseten, Replicate | Nemotron |
| Hugging Face | Gemma | |
| IBM | Hugging Face | Granite |
| Meta | — | Muse Glimmer · Apache 2.0 · 10 Aug |
Like the browser, the harness is code on the user's side. It is where the owner-vs-renter contest restarts.
| Harness | Openness | Harness | Openness |
|---|---|---|---|
| Claude Code | Closed / proprietary | Vibe CLI | Open (hosted surfaces closed) |
| Codex | Open · Apache 2.0 | Grok Build | Open · Apache 2.0 |
| Gemini CLI → Antigravity CLI | Open → closed (Qwen Code is the living fork) | OpenCode | Open · MIT · 75+ providers |
| Kimi Code CLI | Open · MIT | DeepSeek Harness | Open · MIT · new |
| Incident | Date | Retrieval checked | Output not checked | Result |
|---|---|---|---|---|
| Microsoft 365 Copilot "EchoLeak" | Jun 2025 · CVSS 9.3 | victim's M365 permissions | attacker's URL | Zero-click exfiltration via hidden email instructions, never opened |
| Anthropic Slack MCP | Jul 2025 · CVE-2025-34072 | employee's permissions | attacker's domain | Zero-click exfiltration via link unfurling |
| Salesforce Agentforce "ForcedLeak" | Sep 2025 · CVSS 9.4 | admin OAuth, employee's CRM permissions | attacker's server | A $5 expired domain became a trusted exfil channel |
| ServiceNow "BodySnatcher" | Oct 2025 | impersonated user's permissions | attacker identity | Email + hardcoded secret = full impersonation, MFA bypassed |
Hugging Face rerouted its whole analysis pipeline to GLM-5.2 (Z.ai, MIT license), self-hosted. The model recovered the agents' chunk+XOR+compress encoding and the per-campaign key they had leaked in their own logs, surfacing about four times the credentials a plain text scan had found. No attacker data or live credentials left the building.
OpenAI confirms Hugging Face had begun forensic reconstruction on its own open models before the two teams connected.
Hugging Face's published lesson: have a capable model you can run on your own hardware, vetted, before the incident.
Reversible and low-consequence. Fetching a document, querying a database, listing a calendar. These can largely be permitted by default. A bad read costs little and can be repeated safely.
Side effects that are costly or irreversible. Sending a message, spending against a budget, modifying a record, executing a transaction. This is where confirmation, approval thresholds, cost caps and revocation must concentrate.
Thinking got cheap and memory got expensive. Lock-in now runs through state that accumulates on the provider's side.
K3 disproportionately identifies itself as Claude, a statistically significant distribution that researchers describe as difficult to explain as random noise. Asked what it is, it answers "Claude 4.5", never Fable, never Mythos.
Limit: it names a model that predates the case, and self-identification is a known artifact of training on text containing Claude outputs. Anthropic's September report supplies a direct mechanism for that artifact, reasoning transcripts harvested from Claude Opus, and the model K3 names fits it: a system post-trained on Opus traces has no reason to call itself Fable.
The highest cross-vendor similarity in the benchmark. The top four cross-vendor pairs are all K3 against Anthropic models.
Limit: Together AI frames this as capability convergence and a cost comparison, and makes no distillation claim.
The highest among all non-Anthropic models, exceeding the similarity between some pairs of Anthropic's own models.
Limit: measured on Kimi-K2 and Sonnet 4.5. It predates the K3 and Fable case and stands as prior-pattern context only.
| Dimension | Thinking Machines · Inkling US · 15 Jul 2026 | Moonshot · Kimi K3 CN · 27 Jul 2026 |
|---|---|---|
| License | Apache 2.0, unambiguous and known at announcement. The Hugging Face repos carry Apache 2.0 while the model card attaches a separate, changeable Acceptable Use Policy. | Kimi K3 License, custom: MaaS above $20M/yr needs a separate agreement; above 100M MAU or $20M/month must display "Kimi K3" in the UI. K2 was modified-MIT, and that did not settle K3. |
| Weights-to-API order | Weights first. Nothing to gate. | API 16 July, weights 27 July. |
| Serving footprint | ≥600 GB VRAM (NVFP4). A small cluster. | ~1.56 TB, 96 shards, native MXFP4, 64+ accelerators. Open, but not runnable by most who hold it. |
| Upstream contribution | Standard architecture. The existing serving stack already runs it. | KDA broke runtime compatibility. Moonshot fixed it by contributing prefix caching to vLLM, and gained influence over the standard. |
| Evidence at launch | Model card with disclosed limitations. "Inkling is not the strongest overall model available today, open or closed" is TML's own sentence. | Self-reported benchmarks on its own harness, with deployed-system comparisons in footnotes. |
| Capacity posture | No hosted dependency to strain. | New subscriptions paused 20 July as demand neared capacity. |
| Smaller sibling · updated | Inkling-Small (276B / 12B), weights shipped 30 July. Apache 2.0, NVFP4 floor 180 GB, single B300. | None announced. |
| Provenance · new | Trained with help from Moonshot's Kimi 2.5, labelled. | Anthropic alleges Claude Opus reasoning traces as a late-stage input; Moonshot has not responded. |
None requires beating the frontier. Each requires owning a boundary around it while the boundary is still being drawn.
There is a test you can run for the rest of this. Look at who is seated in the rooms where AI gets decided, and with what status. The day they seat the people who keep AI open, portable, and widely deployed on equal footing, the shift from renting to owning will have happened. The window is open now. It is closing slowly enough to be easy to ignore, and the lease is shorter than it looks. Build with us.
Right now, in New Zealand's far north, a Māori broadcaster trains speech models for te reo — a language too small for any market — on open tools, under a license that keeps the data with its people. At PwC, one of the world's biggest accounting firms, teams fine-tuned a small open model on the language of finance and run it today for hundreds of clients — on their own hardware, with no per-token meter running. In East Africa, farmers diagnose cassava disease with a free app whose model runs on the phone itself, offline, in fields the cloud has never reached. In Lausanne, researchers built an open medical model with the Red Cross, tuned to its humanitarian guidelines, with clinical trials being prepared at home and in Tanzania. In Switzerland, a public consortium trained a national model on public supercomputers and released all of it — weights, data, training code — free for any country to copy. They built it themselves. They didn't ask permission, they didn't rent it — they own it, theirs to run, change, and keep
They are not outliers. Open-source and open-weight AI have become one of the fastest-growing builder ecosystems in the history of software: on Hugging Face alone, 2.5 million public models, thirteen million users, a third of the Fortune 500 among them. And the market has voted. On OpenRouter, where developers route real production traffic, open-weight models grew from a sliver to roughly a third of usage by late 2025. Six months on, the platform moves 25 trillion tokens a week — five times more — and the single biggest source of that traffic is an open model. Nobody does that out of idealism. The models are good and the economics are better.
Technology's best-kept secret is publicly available for all to use. This spring, the best closed model scored 60 and the best open models 54. A year earlier, the leading open model scored 22. The frontier still leads on the hardest problems — and for the work most builders actually ship, where price, control, and deployability decide, the data does not say “promising.” It says “ready.” If you have been waiting for open AI to grow up, stop waiting.
Governments are moving too: the European Commission has proposed an “open source first” rule for how public institutions buy AI, and Canada has set a national target to take business adoption from 12 percent to 60. When communities, markets, and states reach for the same thing at once, that is not a movement but a direction — and the direction is abundance: more intelligence, in more hands, owned by more people, than any closed system could distribute.
But none of this is inevitable, and the other future on offer is seductive: a handful of validation machines reading the world to you — smooth, confident, sourced to nothing you can check — the bazaar of a billion arguing voices traded for one polished concierge that answers only to its owner. We got the preview this June, on a Friday afternoon, when one of the most advanced AI models in commercial use went dark everywhere because one government sent one letter. Every business renting it learned what renting means: the off switch was never theirs. But the exit showed itself in the same week, as open-weight models became the instant second source — because no order, from any capital, can un-download weights already running on your own hardware.
We have been here before. Mozilla exists because one company once tried to own the web's front door, and an open community made sure it never would. This is not a new fight; it is the sequel. Then the prize was the front door. Now it is the engine. We bet on open the first time. Open won. Together, we can do it again.
Our belief is simple: the path forward is competition and interoperability — many models, standard connections, and the freedom to leave. Open did not make the pie smaller and share it. It made the pie bigger and let more people own a slice.
So read what follows as a map, not a brochure: where open AI is winning — some numbers surprised even us — and where it is exposed. A case that hides its weak points is an advertisement.
The builders are already building. The motors are turning. A rented future has deeper pockets; an owned one has more hands — millions more — and this story ends the same way every time it is told: the many, building in the open, outbuild the few behind walls.
Build with us.