Open Weights Are Not Zero-Sum: America Should Get In the Game and Do Open Source Itself
Treating open weights as a threat to closed labs gets the economics backwards — it only adds AI use cases, and the real money is in inference, not the model itself.
The video won't play here. Listen to the audio instead:
The argument · tap a timestamp to hear it
Open weights are misread as a zero-sum game
Levie signed the open-weights open letter that Jensen Huang kicked off, and his reading has two layers: first, open weights themselves drive AI progress, spawning more innovation and more use cases, and you can train on them and customize them; second, America needs more companies working on open weights. He stresses that open weights get wrongly framed as zero-sum against closed source, when in fact they only increase the number of use cases people have for AI. He also concedes the closed camp has a real argument on safety, but he believes almost unconditionally that more open innovation is good for AI diffusion.
— Aaron LevieThe ethical line on distillation is very hard to draw
Asked when distillation crosses the line, Levie says he doesn't know where that line is. His core argument: it's hard to argue on one hand that an AI model can train on the public internet, and on the other that another AI model can't train on an AI model's outputs. He also points out that most people never chose whether their data gets trained on — it may just be buried in the fine print of the terms of service. If you accept that the world's general knowledge gets trained into models, then whether that knowledge comes from Reddit or from Anthropic, he can't see a meaningful difference. He understands labs wanting to do everything to prevent distillation, but that doesn't mean there's an ethical line that has been crossed.
— Aaron LevieBlocking China only makes American AI more expensive
On the worry that the US ecosystem leans too heavily on Chinese open-weight models, Levie concedes the arguments are decent but asks: so what do you do about it? He offers an analogy: someone says the iPhone should sell for five thousand dollars instead of a thousand, because you shouldn't depend on Chinese manufacturing capacity. If you play out the alternative, the conclusion is America using very expensive AI and the rest of the world using very cheap AI, then seeing how competitiveness looks in five to ten years. He thinks the cat is out of the bag, open-weight models exist, China knows how to produce them, and the dynamic can't be reversed. He sides with Jensen Huang: China won't give up on AI just because it's blocked, and may instead be forced into a separate hardware stack that ends up deployed in sovereign clouds.
— Aaron LevieThe money in AI is in inference, not the model
Levie thinks the money-making link in AI is inference, and the money ultimately flows to the infrastructure stack. If there were only one or two labs in the market and training secrets were fully locked down, maybe you could seal off a few more layers; but America has three to five players who treat leading models as an existential question, and competitive dynamics will push token costs ever closer to infrastructure cost. His range: markup lands at 20%, 30%, 40% of infrastructure cost, not 70%, 80%, 90%. On that premise, if you run the preferred infrastructure for some open model, do its post-training environment, or become the safer brand for enterprises deploying it, you can capture almost as much revenue. He also suggests frontier labs open-source faster followers built on the previous generation of models, which would actually retain more use cases.
— Aaron LevieAnthropic not open-sourcing is a safety faith
Why don't labs open-source? Levie splits them into two groups. The first needs a longer time horizon before believing open weights can be monetized: ship a closed model tomorrow, force all traffic through your own API, and on paper you definitely make more; but stretch the timeline out and the token cost per task gets pushed down no matter what, and after two or three stages of reasoning closed and open are nearly even, because what ultimately matters is inference cost. The second group, specifically Anthropic, he believes treats this as a major safety risk — not an economic argument about market share, but a fundamental belief that one entity needs to control the flow of tokens in order to prevent prompt injection and to route different query types to different models — none of which you can do in an open-weights environment.
— Aaron LevieOpus 5 improves on two axes at once
Box has been running evals on Opus 5 for the past week or two, and Levie says it's a meaningful jump over Opus 4.8, which was already best-in-class at launch. Box handles enterprise data across industries: life sciences, law firms, big banks' documents, contracts, marketing assets, research materials. Enterprises need a model to do two things at once: deep domain understanding (know life sciences, know law) and the horizontal ability to process lots of data, call tools and do analysis. Opus 5 improved on both axes. He also mentions Fable completely crushing 4.8 on certain internal coding tasks, an edge no token-cost difference can make up for, but Fable has a problem: on some capabilities it downgrades you to 4.8, and it's hard to know in advance whether a safety warning was triggered.
— Aaron LevieIt's far too early to lock down models now
Levie says what Fable currently downgrades and blocks you from doing, if it became the long-term environment, would be unsustainable for AI's future — people would simply stop using AI. He appreciates the multi-tier framework Anthropic has put forward: agreeing on capabilities at different risk levels and testing models. But he presses: who sets that risk framework? How do you confirm these risks are real risks we actually perceive? His conclusion is that given how early it still is, locking these models down is premature.
— Aaron LevieAI lets Box take on multi-year projects
Levie remains very bullish on software engineering, and Box uses these models to do far more than before. He describes a mechanism: in the past you either turned down something small because it wasn't worth it, or turned down something big because it was too hard, so most software projects sat in the middle band of "doable in one to six months." Now multi-year projects are no longer multi-year, a week's work becomes two hours, and so you can solve more of the problems customers have always had, which in turn raises ambition. He says Box now has dozens of projects that would never have started if AI didn't exist. His judgment: if you think you no longer need software engineers, your product roadmap definitely isn't ambitious enough.
— Aaron LevieModel routing will become the enterprise default
Levie admits he's biased toward this conclusion: the more you need multiple models to complete a task or a set of tasks, the more value accrues to the layer that understands the task, gets the data and handles the workflow — the application AI layer where he sits. He names Cognition, Factory, Cursor and Replit as companies that all want a world where "multiple models each have their strengths" — a cost-optimized workhorse model and a super-frontier orchestration model. He counts five credible model developers in America: SpaceX, Google, Anthropic, OpenAI, Meta, all simultaneously pushing intelligence costs down and the frontier up. Model routing also eases enterprise analysis paralysis: models keep leapfrogging each other, so enterprises don't want to lock into one model family, and the routing layer amounts to saying you don't have to make that choice.
— Aaron LevieIn their own words · checked verbatim
So much so that I think it's actually kind of mis-framed as zero-sum with closed weights. It actually just adds to the number of use cases that people then do with AI.
Aaron Levie2:01
I think it's very hard to make the argument that AI models should be trained on broadly the public internet, but another AI model can't be trained on the outputs of an AI model.
Aaron Levie3:03
then all you would basically be arguing is America should have really expensive AI and the rest of the world should have very cheap AI.
Aaron Levie7:04
I generally think that the moneymaker in A.I. is inference. And so ultimately, the dollars are going to flow to the infrastructure stack one way or another.
Aaron Levie12:07
Now what happens is you can tackle the multi-year projects because they're not multi-year anymore.
Aaron Levie23:36
But I generally think if you think that you've kind of eliminated the need for software engineers, there's just no chance you're being ambitious enough with your product roadmap.
Aaron Levie24:36
the more that you need multiple models to do a task or a set of tasks, the more value accrues to the layer that can understand the task and get access to the data and handle the workflow
Aaron Levie26:42
Figures
| Token markup range (relative to infrastructure cost) | 20%, 30%, 40%, not 70%, 80%, 90% | 13:09 |
| Number of credible US model developers | 5 (SpaceX, Google, Anthropic, OpenAI, Meta) | 26:42 |
| Number of Box projects that only started because of AI | Dozens | 22:36 |
| Typical length of software projects in the past | One to six months | 23:36 |
Glossary
- open weights
- Model parameters that are publicly downloadable, self-deployable and fine-tunable, as opposed to closed models offered only via API.
- distillation
- Using one large model's outputs to train another model, transferring capability into a smaller model.
- model routing
- A middle layer that automatically dispatches requests across multiple models by task, cost or capability.
- prompt injection
- An attack that hijacks a model's behavior through input content, making it follow unintended instructions.
- sovereign cloud
- Cloud infrastructure run by a national or local entity that meets data-sovereignty and compliance requirements.
How to listen
Founders, investors and enterprise AI leads watching the open-versus-closed fight, especially teams doing model selection or building application-layer products.
The astrology joke in the first minute or so and the small talk at the end can be skipped.