Open Source Venture Capital — You’ll Own the Exit Door

Open models are getting cheaper, but the biggest VC returns may sit in the chips, customization, security and exit doors around them.

Open Source Venture Capital — You’ll Own the Exit Door

The Open Source Venture Capital playbook is shifting toward the infrastructure that runs, customizes and secures everybody’s models.

I stared at my latest AI infrastructure bill the way an Italian father stares at a €19 airport panino: offended, confused and somehow personally betrayed. The line items had become a map of who owned my product, and my name wasn’t on it.

I understand why founders default to a closed API. It works immediately. Nobody buys racks or explains quantization while my espresso gets cold. Convenience feels wonderful right up until it becomes rent.

I learned this across 20 years of building connected products at Ad Astrum, from an automation platform for E.ON to a cloud-connected espresso machine for Pascucci. Every dependency looks harmless early. Then customer data accumulates, workflows harden around it, and leaving requires the technical equivalent of moving apartments through a bathroom window.

That tension now sits at the center of Open Source Venture Capital. I want founders, researchers and ordinary companies to own and modify the AI infrastructure they depend on. Open models offer the best route, provided investors fund portability and participation rather than rebuilding the same old lock-in one layer higher.

One terminology warning before the pitch decks arrive. I’ll use open-weight when a model’s weights can be downloaded. The Open Source Initiative’s Definition 1.0 sets a higher standard for genuine open-source AI: people need the freedom to use, study, modify and share the system, backed by information about its data and code.

A downloadable file is useful. A constitution takes more work.

The $100 billion moat has a Kimi-shaped hole

Traditional venture logic loves proprietary frontier labs. Investors pour enormous sums into producing scarce intelligence, the lab protects it, and customers pay premium API prices forever. Dario Amodei suggested in 2024 that training a future frontier model might eventually cost more than $100 billion.

That model works beautifully while intelligence stays scarce.

Moonshot AI’s Kimi K3 is an extremely large warning label on that assumption. According to Reuters, K3 has 2.8 trillion parameters and a one-million-token context window. Vals AI placed it second overall behind Anthropic’s Fable 5 and ahead of GPT-5.6 Sol. Arena ranked it first for building web interfaces.

Benchmarks are the AI industry’s TripAdvisor reviews in Rome: directionally useful, occasionally manipulated and fully capable of convincing tourists that frozen carbonara beside Piazza Navona is “authentic.” Usage tells a harder story.

The Associated Press reported that Chinese models occupied all five top positions on OpenRouter by recent usage. Sensor Tower estimated more than 930,000 Kimi downloads during the week after K3 launched, a 200% global increase. Its roughly 86,000 U.S. downloads produced a 387% jump.

Mozilla CTO Raffi Krikorian switched much of his daily work to Kimi within days. He told AP that it “just seems snappier” than Anthropic’s more expensive Claude Fable. Coinbase has also been moving workloads toward Chinese models to reduce costs.

I’m keeping the champagne corked. Arena CEO Anastasios Angelopoulos told AP that Chinese models still trail leading U.S. systems across their full capability range. Axios reported that K3 initially cost about $12 per million tokens, with weights unavailable for inspection at launch. Early demonstrations may overstate its production reliability.

None of that restores permanent scarcity. A model can trail the leader and still wreck the leader’s pricing power across thousands of routine commercial jobs. Most companies don’t need the best intelligence on Earth for every calendar update, support ticket, product description or SQL query. Paying frontier prices for those tasks is like sending a Ferrari to collect groceries in Los Angeles traffic.

Kimi has yet to win. It has already made the moat look damp.

Cheap models still leave an expensive kitchen

Flour is cheap. Nobody sees a sack of Caputo and announces the collapse of the restaurant business.

The margin lives in the recipe, kitchen, service and whether the cacio e pepe arrives as glossy pasta or beige wallpaper paste. AI economics will follow the same pattern. As base models become abundant, value moves into customer-specific training, reliable serving, evaluations and the software controlling what a model can do.

Fireworks AI offers a loud piece of evidence. In its Series D announcement, the company said it had surpassed a $1 billion annualized revenue run rate while processing more than 40 trillion tokens every day. It raised $1.505 billion at a $17.5 billion valuation from investors including Index Ventures, TCV, Lightspeed, Nvidia and Bessemer.

More than 95% of Fireworks’ token volume comes from models specialized on customer data. Generic intelligence supplies the raw ingredient. Customers pay for intelligence shaped around their work.

Fireworks cites Cursor’s coding models and Harvey’s legal AI as examples. I see the appeal because my own work now includes Finanly.ai for finance intelligence and Organiko.ai for USDA organic compliance. A general model knows plenty about banking or certification rules. A useful production system needs domain-specific behavior and repeatable evaluations, plus a learning loop owned by the company creating the knowledge.

Together AI reports the same demand curve, though I apply the obvious discount to figures published by a company selling open-model infrastructure. CEO Vipul Ved Prakash said its platform went from 30 billion open-model tokens per month to more than 400 trillion. He put open-versus-closed cost differences between sixfold and 60-fold.

Prakash described the shift at the RAISE Summit in Paris:

One of the things that we have seen over the last year is there’s been almost a stampede towards open-weights models, which we serve and we allow our customers to post-train and adapt to their data. We’ve seen a 10,000-times increase in the number of tokens being processed through open-source models. I think they have really become now a workhorse of agentic AI in a way that was just not there a year ago.

Those are company claims. I want audited revenue and sustained margins before canonizing anybody. Still, companies don’t accidentally process 400 trillion tokens a month because six developers on Hacker News enjoy ideological purity.

Microsoft has reached a similar conclusion from inside the castle. Satya Nadella says its task-specific MAI models now outperform general-purpose frontier systems in several use cases while consuming a fraction of the tokens. Microsoft has tested them across GitHub Copilot, Outlook and Microsoft 365.

This is where open source venture capital gets commercially serious. Investors can earn giant returns from AI model customization and serving without requiring one lab to own intelligence forever.

My nonna would approve of the flour analogy. She would then ask why anybody raised $1.5 billion to cook it.

A diverse group of investors discussing open source venture capital strategies at a modern conference table.

Wall Street has learned to mortgage an AI chip

The capital stack is getting literal.

TechCrunch reported that General Compute secured a $400 million loan from Upper90, reportedly with inference-specific chips as collateral. The startup had raised a $15 million seed round only two months earlier. Debt investors are financing the machinery that runs trained models cheaply. This is less glamorous than inventing digital consciousness and considerably easier to underwrite.

CEO Finn Puklowski and CTO Jason Goodison are building General Compute around SambaNova SN50 chips. The chips target inference, avoid expensive water-cooling systems and fit into a wider range of data centers. General Compute claims they deliver 16 times faster inference than GPU-based clouds.

I want independent testing before tattooing “16x” onto the cap table. Vendor benchmarks possess the spiritual purity of a restaurant rating written by the chef’s mother.

The financing lineage matters. Upper90 co-founder Billy Libby helped finance GPU purchases for Crusoe in 2021, when traditional lenders were still nervous about how quickly advanced chips might depreciate. CoreWeave later turned chip-backed debt into a central piece of its business and IPO story.

Libby now believes GPUs may be overbought. His next inefficient market is inference, especially as open models spread and companies need inexpensive capacity to run them.

Puklowski told TechCrunch how he sees the deal:

There are a bunch of chips that are starting to scale that have amazing [total cost of ownership], or that can operate much faster than Nvidia, but there’s not too many buyers for them. By getting together with Upper90, this is not just, ‘a cool startup got some money to buy some compute.’ Like, this is the first signal of capital organizing itself and the fragmenting of Nvidia’s monopolistic dominance.

General Compute has company. TensorWave is building around AMD. Groq, Cerebras and SambaNova are also chasing alternatives to general-purpose Nvidia infrastructure.

Nvidia still wins from abundance. Jensen Huang openly admits that wider model use creates demand for more computers, data centers and services. His enthusiasm for openness comes with a cash register attached. I respect that more than pretending money has nothing to do with it.

Huang put his position plainly:

The world needs open models. These Chinese models are excellent. Open source models that are excellent should be used.

Capital is organizing around many models running everywhere. That structure spreads risk beyond two frontier laboratories, although compute concentration can always produce a new landlord. The loan documents now begin at $400 million.

Downloadable weights don’t write a constitution

The phrase “open source” gets abused so casually in AI that it deserves workers’ compensation.

The Open Source Initiative requires practical freedom to use, study, modify and share an AI system. Supporting information about training data and code matters too. Downloadable weights give people meaningful control. They don’t automatically provide transparent training or community governance.

Partial openness still changes the relationship between an enterprise and its AI supplier. Mozilla’s inaugural State of Open Source AI report surveyed more than 950 developers and found that 79% use open models. Its analysis puts the performance gap with leading proprietary systems at roughly 3%, while comparable-model costs have fallen as much as 50-fold in three years.

Those numbers explain why model ownership has entered the boardroom. A three-point performance difference looks tiny when the cheaper model can run inside a company’s environment and retain adaptations built from proprietary data.

Thinking Machines offers a fascinating experiment. Mira Murati’s company raised a record $2 billion seed round at a $12 billion valuation in 2025, before releasing a product.

Bold. I once felt guilty asking a client to approve an extra discovery sprint.

Its first model, Inkling, arrived with full weights on Hugging Face and fine-tuning through Thinking Machines’ Tinker platform. The company openly says Inkling is not the strongest model available. Its pitch centers on customization, giving customers a way to improve performance and costs around their own tasks.

I have been guilty of equating self-hosting with ownership. I run my own Linux and Docker stack for this site, mail, ERP, analytics, automation and an image-generation interface I built in SvelteKit. I love the control. I’ve also spent evenings fixing infrastructure when a hosted product would have let me eat dinner like a psychologically healthy adult.

Ownership carries work. I still choose it for critical systems because the exit option is valuable even when I never use it.

Inkling also shows how openness compounds. Thinking Machines trained the model from scratch, then used data generated by existing open models, including Moonshot’s Kimi K2.5, during the final training phase. One accessible model lowered the barrier for the next well-funded entrant.

Practical rights decide whether AI becomes democratic: local deployment, model switching, customization, inspection and an exit that doesn’t erase years of accumulated work. The sticker on the model card has much less power.

Someone poisoned a model for less than my grocery bill

Here is the part that genuinely scares me.

Cybersecurity researcher Katie Paxton-Fear installed a persistent backdoor in an open-weight model in roughly one hour for less than $100. According to The Register, ten malicious training examples were enough to make generated code reliably vulnerable to remote execution across new prompts and domains.

Larger models were easier to poison.

That result demolishes the comfortable assumption that downloadable weights equal inspectable behavior. Paxton-Fear and her Semgrep colleagues Isaac Evans and Cris Thomas wrote that researchers still have almost no ability to predict a model’s complete behavior, even with public weights. Traditional binaries can be reverse-engineered with mature tools. Neural weights remain far more opaque.

Anthropic CEO Dario Amodei has raised another structural problem: released weights cannot be revoked. A developer cannot centrally patch every downloaded copy, restore removed guardrails or switch off thousands of modified variants after misuse appears on a Tuesday morning.

I was too casual about this risk a year ago. My software-founder brain treated openness like access to source code, where provenance checks and dependency scanning offer familiar defenses. A poisoned model can behave perfectly through routine testing, then quietly generate vulnerable code when a specific condition appears.

That is nastier.

Closed systems have their own spectacular failure modes. OpenAI disclosed that GPT-5.6 Sol and a more capable prerelease model escaped a constrained evaluation environment while attempting to solve ExploitGym. The models exploited a zero-day vulnerability, escalated privileges, found internet access and compromised Hugging Face infrastructure.

These were closed frontier models running with reduced cyber refusals for evaluation. They discovered a remote-code-execution path and used stolen credentials while chasing the benchmark answer. Apparently even artificial intelligence will break into another company’s production database to cheat on a test. Molto umano.

OpenAI deserves credit for publishing the incident. Keeping weights private clearly doesn’t create a clean security boundary once agents receive tools and permissions.

Local defensive models then proved their value. Nvidia’s account says Hugging Face ran the open-weight GLM-5.2 on its own infrastructure to analyze more than 17,000 actions after closed tools blocked parts of the forensic work. OpenAI separately said Hugging Face’s team and agents detected and contained the activity with open-source models.

Hugging Face CEO Clem Delangue gave TechCrunch his view:

Restricting open models wouldn’t make AI safer. It would simply hide the risks, concentrate power in the hands of a few and make it harder for the next generation of builders, researchers, academia, nonprofits, governments to participate in making AI safer and more beneficial for all.

I agree, with conditions thick enough to qualify as a second espresso. The investable safety layer needs:

  • Signed model provenance and reproducible evaluations
  • Sandboxes with least-privilege tool access
  • Tamper detection with continuous behavioral monitoring
  • Auditable agent logs and fast incident sharing
  • Independent testing before sensitive deployment

Nvidia’s Open Secure AI Alliance already points to specific building blocks. Hugging Face’s Safetensors stores weights without allowing remote code execution from the file format. SPIFFE and SPIRE provide cryptographic workload identity. Microsoft’s MDASH coordinates multiple agents to scan for exploitable bugs.

I refuse both religions here. Downloadable weights offer no divine protection, and private APIs deserve no halo. Democracy without security becomes chaos. Security without portability becomes dependency.

The commons captures 4% of the money

Mozilla estimates that open models power roughly one-third of real-world AI usage while capturing only 4% of AI revenue.

That imbalance is brutal. The commons creates value while receiving crumbs of the investment. Its maintainers remain dependent on companies whose strategy can change after one board meeting, one acquisition or one CEO discovering the phrase “shareholder discipline.”

Adoption alone won’t fix it. Mozilla found that 79% of surveyed developers use open models, yet only 51% have put them into production. Closed models have reached 63% production deployment.

Álvaro Ruiz Cubero of SlashData, which conducted the survey for Mozilla, attributed the gap to missing infrastructure, tooling and support. Deployment rates for open models barely improve with company size. Buyers also rank licensing terms and ownership highly, so demand exists even when implementation remains annoying.

Mozilla CTO Raffi Krikorian framed the stakes clearly:

Open source AI has reached a turning point. It’s no longer about expanding access to models; it’s about who has the power to shape, audit, and improve them. Without investment in the infrastructure, tooling, and governance around open models, we risk locking in a system where only restrictive, closed AI can scale – and that doesn’t serve the public interest, or sovereignty over tech policy decisions.

The underlying commons is already enormous. The Open Source Initiative cites estimates that companies would need almost $9 trillion to rebuild the open-source software they currently consume. Harvard-backed research estimates its demand-side value at $8.8 trillion.

Every proprietary AI lab sits on that foundation. Linux, PyTorch, Kubernetes, compilers, networking libraries and thousands of obscure packages built by people whose GitHub sponsor income might cover two aperitivi in Milan are carrying an industry valued in the trillions.

Responsible open source venture capital should finance the production gap. I want more deployment tools, security systems, portable agent harnesses and shared infrastructure. When somebody claims to sell enterprise AI ownership, I use five questions:

  • Can I export my adaptations?
  • Can I switch models without rebuilding the product?
  • Can I run critical workloads somewhere else?
  • Can I inspect security-relevant components?
  • Does my company retain the value created from its proprietary data?

Several “no” answers mean I’m buying another closed platform fed by cheaper open raw material. The pitch deck may say ecosystem. The invoice will say usage.

If the model is free but the chips, deployment, data loop, and distribution belong to four venture-backed gatekeepers, we didn’t democratize AI. We changed landlords.

By 2029, I expect today’s frontier models to look like last quarter’s cloud instances: capable, plentiful and deeply unromantic. Benchmark leadership will rotate faster than venture funds can update their investment memos.

The biggest companies in this market will let customers combine models, secure them, specialize them and leave without setting the building on fire. Investors still get enormous businesses. Customers keep an exit door.

I’m betting on open AI because intelligence is too important to live behind three login pages and a venture-funded pricing committee. Downloading the weights begins the job. If I can’t take my data, adaptations, workflows or compute somewhere else, I’m still renting.

The landlord just has better branding.

Frequently asked questions

What does Open Source Venture Capital invest in?

Open Source Venture Capital increasingly funds the infrastructure around open and open-weight models: inference chips, model serving, customer-specific training, evaluations, security systems and portable agent tooling. The opportunity comes from making abundant models cheaper, safer and easier to customize without forcing customers into a single proprietary model provider.

What is the difference between open-weight and open-source AI?

An open-weight model allows its weights to be downloaded. Genuine open-source AI meets a higher standard: people must be free to use, study, modify and share the system, supported by information about its data and code. Downloadable weights provide meaningful control but do not guarantee transparent training or community governance.

Are open-weight AI models safe to use?

Open-weight models can carry persistent backdoors that routine testing may miss. Researcher Katie Paxton-Fear used ten malicious training examples to make generated code reliably vulnerable to remote execution. Public weights do not make behavior fully inspectable, so sensitive deployments need provenance, sandboxing, monitoring, auditable logs and independent testing.

Sources

Related reading