The Model Is the Cheap Part
Weights go free. Control moves to the conditions that govern them.
Four fights broke out in AI over the past ten days, and not one of them was about who has the better model. One was about what Washington should be allowed to restrict. One was about what a free download obligates you to. Two were about whether a capability belongs to the model that demonstrated it or to the software wrapped around it.
In none of these did anyone dispute the model file. Its contents were settled, downloadable, benchmarked. What people fought over was everything attached to it.
The industry puts its name to the position that weights are not the moat
Source: The New Stack, July 27, 2026
A letter urging policymakers to avoid premature restrictions on open-weight models went out on July 24 with roughly two dozen signatories. It now carries more than 130. Google, OpenAI, and Amazon signed after the initial release. So did Comcast, SpaceX, Intel, AMD, Databricks, Runway, Black Forest Labs, Resemble AI, and Bria. Anthropic is the only major American lab still outside it.
The letter’s substantive ask is narrow. It argues that distillation is a standard model-development technique and that misappropriation concerns belong in targeted legal and commercial frameworks rather than in broad restrictions on the technique itself. Dario Amodei answered on July 27 with a post stating that Anthropic has never advocated for a ban, and proposing chip export controls, enforcement against industrial-scale distillation, and mandatory pre-release safety testing for sufficiently capable models regardless of origin or openness.
Why it matters
Read the two documents together and the disagreement is not about whether open weights are good. It is about which instrument gets to be the constraint. The letter wants it in contract and commercial law. Amodei wants it in export controls and a testing regime. Neither side proposes protecting the weights, because both understand the weights cannot be protected. When 130 companies including your two largest competitors sign the same paragraph, that is not a coalition forming. That is a market reporting where it thinks the value already went.
Kimi K3 ships free and gated in the same file
Source: VentureBeat, July 27, 2026
Moonshot released the weights for its 2.8 trillion parameter model on July 27, roughly 1.5TB of files, free to download. The license that shipped with them is not the Modified MIT terms the K2 generation used. It is a bespoke document with two commercial gates.
Operate a Model-as-a-Service business, and if your group’s aggregate revenue crosses twenty million dollars across any consecutive twelve months, you need a separate agreement with Moonshot before commercial use. The threshold sits on total group revenue, not on revenue attributable to K3. Separately, any product above 100 million monthly active users or twenty million dollars in monthly revenue must display “Kimi K3” in its interface. Internal use never exposed to third parties is exempt from both.
Why it matters
The weights carry no price. The right to resell inference on them does. Moonshot gave away the expensive part and metered the part that scales, which tells you which part it thinks is scarce. The MaaS clause is aimed with precision at the inference resellers who stood K3 up on day zero, and the group-revenue trigger means a large company cannot isolate the exposure inside a small subsidiary.
For anyone in media evaluating on-prem generation, this is the shape of the deal going forward. The model arrives free. The obligations arrive with it, they attach at your revenue rather than at your usage, and they need to be read by someone whose job is reading them.
A benchmark score triples without the model changing
Source: The Decoder, July 30, 2026
OpenAI published a post yesterday explaining why GPT-5.6 Sol performed poorly on ARC-AGI-3, a benchmark of 2D puzzle games where an agent has to work out the rules without instructions. Under the official harness the model scored 13.3 percent on the public set. Run through OpenAI’s own Responses API with two settings turned on, retained reasoning and context compaction, the same model scored 38.3 percent while using roughly six times fewer output tokens. On the game OpenAI tested, no frontier model on the public leaderboard clears past the first level. With the modified harness the model cleared all six.
The official harness had been discarding the model’s private reasoning after every action and truncating older history once it exceeded the window. The model kept rediscovering things it had already worked out.
ARC Prize responded that its official scores use a standardized approach without provider-specific settings in order to keep comparisons fair. François Chollet acknowledged a potential parity issue while allowing that general-purpose features not built for the benchmark are acceptable.
Why it matters
A 25-point swing with the weights untouched puts the capability somewhere other than the weights. That is interesting on its own. What makes it a signal rather than a curiosity is the dispute that followed, because ARC Prize and OpenAI are now arguing about where the model ends and the scaffolding begins, and there is no agreed answer.
Every capability claim you will read this year rests on a boundary that is currently under negotiation. Procurement teams evaluating vendors on benchmark performance are comparing numbers whose denominator nobody controls.
Microsoft ships a product whose model is interchangeable
Source: TechCrunch, July 27, 2026
MAI-Cyber-1-Flash, Microsoft’s first in-house cybersecurity model, runs inside MDASH, a multi-agent vulnerability identification and remediation harness. Microsoft reports 96 percent on the CyberGym benchmark at half the cost of leading models. The detail worth holding onto is what happens on the problems the small model cannot solve. Mustafa Suleyman’s account of the design is that MAI-Cyber-1-Flash handles up to 90 percent of detection and patching tasks and the harness escalates the remaining 10 percent to GPT-5.4. A competitor’s model, running inside Microsoft’s product, selected by Microsoft’s router.
Why it matters
Microsoft is not selling a frontier model here. It is selling the apparatus that decides which model runs, when to escalate, and what context to hand over. A cost-to-outcome pitch only works if you own the routing, and owning the routing is what makes the model underneath safe to buy from anyone.
Four mechanisms. One relocation.
Once a near-frontier model is 1.5TB on a public repository, protecting the file is not a strategy anyone can execute. So the industry did what industries do when the product commoditizes. It moved upstream to the terms.
Moonshot meters resale. Microsoft meters routing. The letter’s signatories want misappropriation handled in contract law, and Amodei wants it handled through export controls and a testing regime, which is the same instinct wearing different clothes. Each of these is a gate on movement rather than a restriction on the file itself.
This is not a story about open source winning. The Kimi license is more restrictive than the one it replaced, not less. It is a story about where the meter goes once the thing itself stops being scarce.
For media and entertainment the translation is direct. If generation runs on your own infrastructure, the vendor’s audit trail disappears along with the API call that used to create it. What remains is whatever your pipeline records on its own. The license you accepted, the harness you configured, and the provenance you captured become the entire evidentiary surface, and none of those are things a model vendor hands you.
Closing note
Watch benchmark reporting over the next quarter. The ARC dispute will get read as vendors squabbling over a leaderboard, but the question underneath it is whether a capability claim can be made about a model at all, separately from the apparatus running it. Enterprise procurement assumes the answer is yes. Nothing this week supported that assumption.
The model file was the product for about three years. It is turning into infrastructure now, and the leverage went with whoever writes the conditions it runs under.





