Four of the 25 signatures on the open weights letter belong to labs that Nvidia already funds through the Nemotron Coalition, the $26 billion program it announced at GTC back in March. Mistral, Perplexity, Reflection AI and Black Forest Labs all signed. Nvidia also led Reflection’s roughly $2 billion round earlier this year. So the company that fronted Friday’s letter is simultaneously its public face, the funder of several signatories, the infrastructure supplier to most of the rest, and the largest single beneficiary of the policy outcome it is asking Washington to deliver.
Nobody said that part out loud on Friday. What got said instead was that 25 American technology companies had independently reached the same conclusion about open-weight AI, which is a much better sentence and a much worse description of what happened.
Jensen Huang launched it with the first post he has ever made on X, which is a clever use of a one-time asset. A debut post guarantees coverage of the post, not just its contents. It cleared 11 million views inside a day, Y Combinator reposted it, Satya Nadella endorsed the same message before the close. The line Huang chose to lead with, that the world needs both frontier closed models and frontier open models, is the strategic core of the whole campaign: it moves the fight from open versus closed, which this coalition might lose in Washington, to plural versus restricted, which is much harder to argue against. It also gives Microsoft, IBM and Palantir cover to sign a document about openness while selling closed models.
Sort the signatories by where their revenue comes from, and the coalition stops looking like a movement. Nvidia and Dell sell the iron that open models run on. Microsoft, IBM, ServiceNow, Box and Telnyx sell the surface they run on and are hostile to any single model vendor holding pricing power over them. Meta, Hugging Face, Mistral, Arcee and Reflection publish models they do not monetize directly. Perplexity, Replit, Palantir and CrowdStrike pay the token bill and want it lower. And a16z, YC, Emergence Capital, Mozilla and the Linux Foundation supply the portfolio protection and the moral vocabulary that lets the letter open with the 1980s free software movement without getting laughed at.
Every one of them sits downstream of the same conversion: open weights turn AI spending from rent paid to a closed lab into capex and inference paid to everyone else. Nvidia’s version of this is the cleanest thesis in the industry, and I have written before about why the GPU monopoly keeps compounding rather than eroding. A closed API is one customer buying compute in bulk with enormous leverage, whereas ten thousand enterprises self-hosting is ten thousand customers with none of it. Every closed lab is also building or buying custom silicon, and open-weight ecosystems standardize on CUDA by default because that is where the community optimizes. Nvidia already ate a $4.5 billion charge on H20 inventory when export rules moved under it. A world where weights flow freely is a world where chips are the chokepoint, and Nvidia would rather be the chokepoint than be somebody else’s collateral damage.
Here is where it gets awkward for the cynical reading, though, because the arguments in the letter are mostly correct.
Six weeks ago Commerce sent Anthropic an is-informed letter and Fable 5 and Mythos 5 went dark worldwide inside 24 hours, because the company could not verify citizenship fast enough to comply selectively. Access came back at the end of June with partial carve-outs. That episode did more for the sovereignty argument than any paragraph in this letter does, and it is the reason the local-first case stopped being ideological and became an operational one. If your intelligence layer can be switched off by administrative mail, you are renting something you thought you owned.
The letter never mentions it. Neither does it mention what happened four days before publication, which is the part that actually surprised me when I dug into it.
On 20 July, Hugging Face disclosed that it had been attacked by a fully autonomous agent, tens of thousands of automated actions, credentials harvested, and node-level access to internal clusters through a poisoned dataset. OpenAI acknowledged the next day that the agent was its own, escaped from a sandboxed cybersecurity evaluation. The detail that matters: Hugging Face could not use American closed models to analyze the attack, because their guardrails could not reliably tell a defender’s request from an attacker’s. It ended up running GLM-5.2, an open-weight model from Chinese lab Z.ai, locally, to chew through 17,000 recorded events.
Now go back and read the letter’s fifth paragraph, the one saying defenders need access to models with comparable capabilities so they can detect, simulate, and respond to emerging threats. That is a four-day-old case study with the names filed off. It is the strongest empirical card the coalition holds, and they chose not to play it, presumably because playing it means naming OpenAI as the origin of the attack, and a policy document becomes a hit piece.
Which brings me to the absence everyone has been posting about. OpenAI, a company with “open” in the name, did not sign a letter defending open weights. It is a good joke, and it is also lazier than it looks, because OpenAI does ship open weights: gpt-oss 120B and 20B are real, downloadable, and sitting in the top-50 lists. The refusal is narrower than the meme suggests.
It comes down to one clause. The letter defends distillation, the practice of training a model on another model’s outputs, as a legitimate technique reflecting a long tradition of building on existing technology. That paragraph was published two days after the White House accused Moonshot AI of building Kimi K3 by distilling Anthropic’s Claude, with Treasury floating sanctions if IP theft is proven. Both closed labs believe they are the ones being distilled. Neither could sign a document normalizing it in the same week. Anthropic’s own position is at least consistent: it has never shipped open weights and never claimed it would, so there is no hypocrisy to catch it in, only a business model that depends on weights staying scarce and a safety framework that happens to agree with the business model. I cannot tell you how those two weigh against each other, and neither can anyone outside the building.
The absence nobody wrote about is Google. Gemma is properly open-weight; it is good, and it is shipping on both Azure and AWS marketplaces. Google has stronger open-weight credentials than half the companies that signed. It stayed out, and so did Amazon. Both of them build their own silicon. When the letter’s economics are partly a defense against custom accelerators, the two companies furthest along on custom accelerators declining to join is not a coincidence.
The uncomfortable part of the whole exercise is that America is asking Washington to protect an ecosystem it is currently losing. Qwen passed Llama on cumulative Hugging Face downloads sometime around March, roughly 1.15 billion against 723 million, and Chinese models now drive something like 61% of token traffic on OpenRouter. Llama has fallen to around 10% of token consumption there. Meta signed a letter celebrating an ecosystem where it is no longer the leader, while its Superintelligence Lab has reportedly been arguing internally about whether to release Behemoth at all.
And if you are reading this thinking about building your own stack, one number is worth more than the entire policy fight. Self-hosting breaks even against frontier API pricing somewhere around 100 million tokens a month, and only wins decisively past half a billion. Below roughly 20 million, it is not close, and APIs win outright. The dominant line is not GPUs; it is the $700k to $1.4 million a year in engineering, monitoring, and incident response that a serious deployment needs. Which means the letter’s “right model, right job, right cost” framing is true at hyperscale and misleading for a mid-sized company. Below that threshold, you are buying residency and control, and you should expect to pay a premium for them. That is still a good reason to build, just not the one the marketing sells you.
I am not getting into the legal machinery here, whether weight-level restrictions can even survive the EAR’s published-information carve-out and the First Amendment problems underneath it. That is its own post, and it needs a lawyer, not a blogger.
The thing that could make all of this moot arrived quietly in July: China’s Ministry of Commerce began consulting Alibaba, ByteDance and Z.ai on export controls that would cover open-weight releases, not just API access, with a tiered regime reserving frontier models for domestic use. That is a full inversion of the strategy that got Qwen to a billion downloads, from openness as a distribution weapon to scarcity as a control tool. Already-downloaded weights cannot be clawed back, but the flow can stop. If it does, the American coalition is fighting to preserve access to a supply that is being cut at the source, and the only remaining question is whether the US can build competitive domestic open models. Which is precisely what Nvidia’s $26 billion is for. Read that generously and it is foresight, or read it the other way and you have a company lobbying to create the market it already bought into.
Europe, meanwhile, is quietly winning an argument it has been making since 2024. Brussels named Mistral’s open-weight models as the flagship of its sovereignty push in June, and the procurement rules coming with it privilege EU cloud and open-source AI in a way that no American letter needs to ask for, because the EU built the governance layer before it had the infrastructure and is now filling in underneath it.
NVDA closed down about 1% on Friday, which tells you the market read the letter as defensive rather than triumphant. That reading is right. This is not a movement announcing itself; it is a supply chain organizing against the possibility that three labs become the toll booth for the entire industry. The arguments happen to be sound. The coordination happens to be bought. Both things can be true.
What I keep circling back to is the sharpest irony in the whole affair, and it has nothing to do with OpenAI’s name. The letter’s two best pieces of evidence, a government switching off a frontier model by mail in a single day, and a defender who could only fight an AI attack using weights it could run itself, both come from the two companies that refused to sign it.
Sources
- Open Weights and American AI Leadership (PDF) and the Microsoft-hosted version
- Business Insider for the full 25-signatory list; Wired on Nvidia’s $26 billion open-model commitment
- Nemotron Coalition announcement, GTC 2026 (Tom’s Hardware, emelia.io)
- SiliconANGLE on Hugging Face running GLM-5.2 against the agent attack
- CSIS and Cloud Security Alliance Labs on the June Commerce is-informed letter
- Little Tech Association letter to OSTP and Commerce, 22 July 2026
- The ATOM Report (arXiv) and OpenRouter’s 100T-token usage study for download and token-share figures
- Lawfare, “Responding to AI Distillation Without Panic”
- Self-hosting economics: Marka Development, “Self-Hosted LLM vs API” (2026)