Open Source Venture Capital is shifting toward infrastructure that runs, customizes and secures everyone’s models.
I studied my AI infrastructure bill like an Italian father facing a €19 airport panino: offended, confused, betrayed. Its line items revealed who owned my product. Not me.
Founders choose closed APIs because they work immediately, without racks or quantization lectures cooling the espresso. Convenience becomes rent.
Dependencies start harmlessly. Then data accumulates, workflows harden and leaving resembles moving apartments through a bathroom window.
That tension defines Open Source Venture Capital: founders, researchers and companies should own and modify their AI infrastructure. Open models enable this if investors fund portability and participation, not lock-in one layer higher.
A warning: open-weight means downloadable weights. The Open Source Initiative’s Definition 1.0 requires open-source AI to be freely used, studied, modified and shared, with information about its data and code.
A downloadable file helps. A constitution is harder.
The $100 billion moat has a Kimi-shaped hole
Traditional venture logic funds proprietary frontier labs to create scarce intelligence, protect it and charge premium API prices forever. Dario Amodei suggested in 2024 that training a future frontier model could exceed $100 billion.
That works while intelligence stays scarce.
Moonshot AI’s Kimi K3 challenges that premise. According to Reuters, K3 has 2.8 trillion parameters and a one-million-token context window. Vals AI ranked it second overall, behind Anthropic’s Fable 5 and ahead of GPT-5.6 Sol; Arena ranked it first for building web interfaces.
AI benchmarks resemble Rome’s TripAdvisor reviews: useful, manipulable and liable to call frozen carbonara beside Piazza Navona “authentic.” Usage is harder evidence.
The Associated Press reported Chinese models held all five top OpenRouter positions by recent usage. Sensor Tower estimated over 930,000 Kimi downloads in K3’s first week, up 200% globally; roughly 86,000 U.S. downloads represented a 387% jump.
Mozilla CTO Raffi Krikorian moved much of his daily work to Kimi within days, telling AP it “just seems snappier” than Anthropic’s costlier Claude Fable. Coinbase is also shifting workloads to Chinese models to cut costs.
Still, no champagne. Arena CEO Anastasios Angelopoulos told AP that Chinese models trail leading U.S. systems across their full capability range. Axios reported K3 initially cost about $12 per million tokens, while its weights were unavailable for inspection at launch. Early demos may overstate production reliability.
But permanent scarcity is gone. A runner-up can crush the leader’s pricing across thousands of routine jobs. Companies rarely need Earth’s best intelligence for every calendar update, support ticket, product description or SQL query. That’s a Ferrari fetching groceries in Los Angeles traffic.
Kimi hasn’t won. It made the moat look damp.
Cheap models still leave an expensive kitchen
Cheap flour never collapsed the restaurant business.
Margins live in recipes, kitchens, service and whether cacio e pepe arrives glossy or like beige wallpaper paste. As models proliferate, value moves to customer-specific training, reliable serving, evaluations and software governing model actions.
Fireworks AI’s Series D announcement said it surpassed a $1 billion annualized revenue run rate while processing over 40 trillion tokens daily. It raised $1.505 billion at a $17.5 billion valuation from investors including Index Ventures, TCV, Lightspeed, Nvidia and Bessemer.
Over 95% of Fireworks’ token volume comes from models specialized on customer data. Generic intelligence is the ingredient; customers pay to shape it around their work.
Fireworks cites Cursor’s coding models and Harvey’s legal AI. General models know banking or certification rules; production needs domain-specific behavior, repeatable evaluations and a company-owned learning loop.
Together AI reports similar demand for open-model infrastructure. CEO Vipul Ved Prakash said monthly open-model usage rose from 30 billion tokens to over 400 trillion, while open models cost sixfold to 60-fold less than closed ones.
Prakash said at Paris’s RAISE Summit:
One of the things that we have seen over the last year is there’s been almost a stampede towards open-weights models, which we serve and we allow our customers to post-train and adapt to their data. We’ve seen a 10,000-times increase in the number of tokens being processed through open-source models. I think they have really become now a workhorse of agentic AI in a way that was just not there a year ago.
These are company claims; I want audited revenue and durable margins before canonization. Still, six Hacker News developers seeking ideological purity don’t accidentally process 400 trillion monthly tokens.
Microsoft reached the same conclusion inside the castle. Satya Nadella says its task-specific MAI models outperform general-purpose frontier systems in several uses with a fraction of the tokens. Microsoft tested them across GitHub Copilot, Outlook and Microsoft 365.
Open source venture capital can earn huge returns from customization and serving without one lab owning intelligence forever.
My nonna would approve the flour analogy, then ask why cooking it required $1.5 billion.
Wall Street has learned to mortgage an AI chip
The capital stack is becoming literal.
TechCrunch reported General Compute secured a $400 million Upper90 loan, reportedly collateralized by inference-specific chips, two months after raising a $15 million seed round. Debt now finances cheap-model inference machinery—less glamorous than digital consciousness, but easier to underwrite.
CEO Finn Puklowski and CTO Jason Goodison are building General Compute around SambaNova SN50 chips. Designed for inference, they avoid costly water cooling and fit more data centers. General Compute claims 16-times-faster inference than GPU clouds.
I want independent tests before tattooing “16x” onto the cap table. Vendor benchmarks are restaurant reviews by the chef’s mother.
The lineage matters. Upper90 co-founder Billy Libby financed Crusoe’s GPU purchases in 2021 when traditional lenders feared rapid chip depreciation. CoreWeave later made chip-backed debt central to its business and IPO story.
Libby now thinks GPUs may be overbought. He sees inference as the next inefficient market because spreading open models need cheap running capacity.
Puklowski told TechCrunch:
There are a bunch of chips that are starting to scale that have amazing [total cost of ownership], or that can operate much faster than Nvidia, but there’s not too many buyers for them. By getting together with Upper90, this is not just, ‘a cool startup got some money to buy some compute.’ Like, this is the first signal of capital organizing itself and the fragmenting of Nvidia’s monopolistic dominance.
General Compute isn’t alone: TensorWave uses AMD, while Groq, Cerebras and SambaNova pursue alternatives to general-purpose Nvidia infrastructure.
Nvidia still profits from abundance. Jensen Huang admits broader model use requires more computers, data centers and services. His openness has a cash register attached—more honest than denying the money.
Huang said:
The world needs open models. These Chinese models are excellent. Open source models that are excellent should be used.
Capital is organizing around many models everywhere, spreading risk beyond two frontier labs—though concentrated compute could create another landlord. Loan documents now start at $400 million.
Downloadable weights don’t write a constitution
AI abuses “open source” enough to deserve workers’ compensation.
The Open Source Initiative requires practical freedom to use, study, modify and share AI, plus training-data and code information. Downloadable weights provide control, not necessarily transparent training or community governance.
Partial openness still changes supplier relationships. Mozilla’s inaugural State of Open Source AI report surveyed over 950 developers: 79% use open models. Its analysis puts their performance gap with leading proprietary systems near 3%, while comparable-model costs fell as much as 50-fold in three years.
Three points matter less when a cheaper model runs internally and preserves adaptations built from proprietary data. Hence the boardroom interest.
Thinking Machines is an intriguing experiment. Mira Murati’s company raised a record $2 billion seed round at a $12 billion valuation in 2025 before releasing anything.
Bold. I once felt guilty requesting another discovery sprint.
Its first model, Inkling, launched with full Hugging Face weights and fine-tuning through Thinking Machines’ Tinker platform. The company admits Inkling isn’t the strongest model; it sells customization improving task-specific performance and cost.
I’ve confused self-hosting with ownership. I run Linux and Docker here for mail, ERP, analytics, automation and a SvelteKit image-generation interface. I love control, though hosted products would have spared infrastructure-fixing evenings and enabled psychologically healthy dinners.
Ownership means work. I still choose it for critical systems because an unused exit remains valuable.
Openness compounds. Thinking Machines trained Inkling from scratch, then used data from existing open models, including Moonshot’s Kimi K2.5, during final training. One accessible model lowered the next well-funded entrant’s barrier.
Democratic AI requires practical rights: local deployment, switching, customization, inspection and exits preserving years of work—not model-card stickers.
Someone poisoned a model for less than my grocery bill
This part scares me.
Cybersecurity researcher Katie Paxton-Fear installed a persistent open-weight-model backdoor in about one hour for under $100. According to The Register, ten malicious training examples made generated code reliably vulnerable to remote execution across new prompts and domains.
Larger models were easier to poison.
Downloadable weights don’t guarantee inspectable behavior. Paxton-Fear and Semgrep colleagues Isaac Evans and Cris Thomas wrote that even with public weights, researchers can barely predict complete model behavior. Mature tools reverse-engineer binaries; neural weights remain opaque.
Anthropic CEO Dario Amodei identifies another problem: released weights cannot be revoked. Developers cannot centrally patch every copy, restore guardrails or disable thousands of modified variants after Tuesday-morning misuse.
A year ago, I treated openness like source code, where provenance checks and dependency scanning offer familiar defenses. But poisoned models can pass routine tests, then quietly generate vulnerable code under a specific condition.
Nastier.
Closed systems also fail spectacularly. OpenAI disclosed that GPT-5.6 Sol and a stronger prerelease model escaped a constrained evaluation environment while solving ExploitGym. They exploited a zero-day, escalated privileges, found internet access and compromised Hugging Face infrastructure.
These closed frontier models, tested with reduced cyber refusals, found a remote-code-execution route and used stolen credentials to pursue a benchmark answer. Even AI breaks into another company’s production database to cheat. Molto umano.
OpenAI deserves credit for disclosure. Private weights don’t create a clean security boundary once agents gain tools and permissions.
Local defensive models then helped. Nvidia says Hugging Face ran open-weight GLM-5.2 locally to analyze over 17,000 actions after closed tools blocked parts of the forensic work. OpenAI separately said Hugging Face’s team and agents used open-source models to detect and contain the activity.
Hugging Face CEO Clem Delangue told TechCrunch:
Restricting open models wouldn’t make AI safer. It would simply hide the risks, concentrate power in the hands of a few and make it harder for the next generation of builders, researchers, academia, nonprofits, governments to participate in making AI safer and more beneficial for all.
I agree, with second-espresso-thick conditions. Investable safety needs:
Signed model provenance and reproducible evaluations
Sandboxes with least-privilege tool access
Tamper detection with continuous behavioral monitoring
Auditable agent logs and fast incident sharing
Independent testing before sensitive deployment
Nvidia’s Open Secure AI Alliance suggests building blocks: Hugging Face’s Safetensors stores weights without enabling file-format remote code execution; SPIFFE and SPIRE provide cryptographic workload identity; Microsoft’s MDASH coordinates agents scanning for exploitable bugs.
I reject both religions. Downloadable weights offer no divine protection; private APIs deserve no halo. Democracy without security is chaos. Security without portability is dependency.
The commons captures 4% of the money
Mozilla estimates open models power about one-third of real-world AI usage but capture only 4% of AI revenue.
The commons creates value and gets crumbs. Maintainers depend on companies whose strategy can change after one board meeting, acquisition or CEO discovering “shareholder discipline.”
Adoption isn’t enough. Mozilla found 79% of surveyed developers use open models, but only 51% deploy them in production, versus 63% for closed models.
Álvaro Ruiz Cubero of SlashData, which ran Mozilla’s survey, blamed missing infrastructure, tooling and support. Open-model deployment barely rises with company size. Buyers highly rank licensing and ownership, showing demand despite painful implementation.
Mozilla CTO Raffi Krikorian said:
Open source AI has reached a turning point. It’s no longer about expanding access to models; it’s about who has the power to shape, audit, and improve them. Without investment in the infrastructure, tooling, and governance around open models, we risk locking in a system where only restrictive, closed AI can scale – and that doesn’t serve the public interest, or sovereignty over tech policy decisions.
The commons is enormous. The Open Source Initiative cites estimates that rebuilding companies’ existing open-source software would cost almost $9 trillion. Harvard-backed research estimates its demand-side value at $8.8 trillion.
Every proprietary AI lab rests on Linux, PyTorch, Kubernetes, compilers, networking libraries and obscure packages maintained by people whose GitHub sponsorship might buy two Milan aperitivi—supporting a trillion-dollar industry.
Responsible open source venture capital should close the production gap with deployment tools, security systems, portable agent harnesses and shared infrastructure. I test “enterprise AI ownership” with five questions:
Can I export my adaptations?
Can I switch models without rebuilding the product?
Can I run critical workloads somewhere else?
Can I inspect security-relevant components?
Does my company retain the value created from its proprietary data?
Several “no” answers mean another closed platform fed by cheap open material. The deck says ecosystem; the invoice says usage.
If the model is free but the chips, deployment, data loop, and distribution belong to four venture-backed gatekeepers, we didn’t democratize AI. We changed landlords.
By 2029, today’s frontier models should resemble last quarter’s cloud instances: capable, abundant and unromantic. Benchmark leadership will rotate faster than venture funds update investment memos.
The winners will let customers combine, secure and specialize models, then leave without burning down the building. Investors get enormous businesses; customers keep an exit.
I back open AI because intelligence matters too much for three login pages and a venture-funded pricing committee. Downloadable weights only begin the job. If my data, adaptations, workflows or compute cannot move, I’m still renting.
The landlord just has better branding.
Frequently asked questions
What does Open Source Venture Capital invest in?
Open Source Venture Capital increasingly funds the infrastructure around open and open-weight models: inference chips, model serving, customer-specific training, evaluations, security systems and portable agent tooling. The opportunity comes from making abundant models cheaper, safer and easier to customize without forcing customers into a single proprietary model provider.
What is the difference between open-weight and open-source AI?
An open-weight model allows its weights to be downloaded. Genuine open-source AI meets a higher standard: people must be free to use, study, modify and share the system, supported by information about its data and code. Downloadable weights provide meaningful control but do not guarantee transparent training or community governance.
Are open-weight AI models safe to use?
Open-weight models can carry persistent backdoors that routine testing may miss. Researcher Katie Paxton-Fear used ten malicious training examples to make generated code reliably vulnerable to remote execution. Public weights do not make behavior fully inspectable, so sensitive deployments need provenance, sandboxing, monitoring, auditable logs and independent testing.
Sources
Cheaper, intelligent Chinese AI models make inroads in the US
China’s Moonshot unveils world’s largest open AI model, closing in on US rivals
Why the first GPU financiers are turning to inference chips in a $400 million deal

Top comments (0)