June Hadley: I've been staring at a World Bank table since Tuesday and I keep getting stuck on the same cell. Tell me if this bothers you the way it bothers me.
June Hadley: World Development Report 2026 — open AI models, 56% of the field in 2020, down to 40% by 2025. And in the same period, the open models got better. So I keep asking: why would you stop releasing something that's working?
Roy Halliday: That's exactly the right question, and the answer is not about quality. Look — Meta releases Llama 2, Llama 3, open weight. OpenAI builds GPT-4o, keeps the weights private. Anthropic builds Claude, same story. The models are roughly converging on domain benchmarks. What's diverging is the incentive to share.
June Hadley: So the incentive inverted — is that the right word? Inverted?
Roy Halliday: Frankly, yes. The liability surface got larger. The regulatory exposure got larger. And the competitive value of keeping weights private went up precisely because everyone else was opening theirs.
June Hadley: Right — but that feels like it needs a name, that tension. It's not just 'business reasons.'
Roy Halliday: The name is a tradeoff between scientific velocity and competitive defensibility. Open-weight models like Llama 3 and DeepSeek maximize the first. Closed API models like GPT-4o optimize for the second. That's the architecture of this split — and neither side is going away.
June Hadley: Okay but velocity versus defensibility — I think that framing is clean, maybe too clean. The way I'd picture this is: imagine a chef who publishes her recipe versus a restaurant that only serves you the dish. Open-weight is the recipe. Proprietary API is the restaurant. You eat well either way, but one of them you can cook yourself, improve, pass on. The other one — you come back every night and pay the cover.
Roy Halliday: That's the cleanest version of it. And Hugging Face is essentially the cookbook library — where the recipes live, get annotated, get remixed.
June Hadley: So if the cookbook is free and the food tastes almost the same — DeepSeek-V3, Llama 3, closing in on GPT-4o on actual benchmarks — what does it actually cost to cook for yourself? I mean, what's the practical catch?
Roy Halliday: The catch is the kitchen. Running Llama 3 at scale is not free. You need the hardware, the engineering team, the uptime. And when Meta ships a better version — you're not automatically on it. You're on the version you deployed.
June Hadley: Wait, so you could be running a six-month-old model and not know it's outdated?
Roy Halliday: That's the deployment dilemma in one sentence. Closed API — you pay per inference, but you're always on the current version, no capital outlay. Open weight — you absorb the infrastructure cost upfront, and you accept the lag. Neither is obviously wrong. But a startup in, say, Nairobi building a medical triage tool? That capital decision is real. It's not ideology.
June Hadley: And the dependency risk cuts both ways — I mean, the restaurant can close. The API can reprice.
Roy Halliday: Exactly that. Lock-in is structural on both sides. The open path locks you to your own infrastructure ceiling. The closed path locks you to someone else's pricing desk. That's not a temporary competition. The incentive timescales are just different by design.
June Hadley: Both paths lock you in — but that's still the clean version. The part I keep circling is whether the safety argument that Anthropic and OpenAI make actually holds, or whether it's something else wearing that coat.
Roy Halliday: The claim is structural. Closed deployment gives you adversarial evaluation pipelines, RLHF infrastructure at scale, feedback loops from millions of production interactions. The argument is that open-source communities can't replicate that fidelity. And it's not obviously wrong.
June Hadley: I mean — is that safety, or is that opacity doing the work? Because those two things can look identical from the outside.
Roy Halliday: That's the critique worth sitting with. The counter is: dental EMR generation, clinical biomedical extraction — run the domain-specific benchmarks, and open models converge with proprietary ones depending on task and prompt strategy. If the safety moat were structural, you wouldn't see that convergence. You'd see a persistent gap. You don't.
June Hadley: Wait — dental records specifically?
Roy Halliday: Dental EMR generation, yes. Specific benchmark category. And what that tells me is — the 'safety' framing may actually be liability management through information asymmetry. If you can't see inside the model, you can't contest its outputs. That's not the same as responsible AI. It's opacity that functions like responsibility.
June Hadley: Now picture a developer — let's say she's building a medical triage system for rural clinics, wants to run Llama 3 locally, data stays on-premises, no API cost. But she finds out the training data may include copyrighted material her jurisdiction's courts now treat as unlicensed. And she pivots to Claude at $0.03 per inference, scaled across a whole country. She didn't actually choose proprietary — the copyright uncertainty made the choice.
Roy Halliday: Regulation selected her into it. That's the precise language. And the open-source counter — if open-weight developers had equivalent compute and deployment scale, the safety gap would narrow. Which means the gap is resource-contingent, not structural. That distinction matters enormously for how we write policy. And the regulatory layer is actually where this gets worse — there's a compliance asymmetry baked into the current frameworks that we haven't named yet.
June Hadley: I think that's the thread we need to pull — because if the compliance costs fall unevenly, that's not a side effect. That's the mechanism.
Roy Halliday: The mechanism is the EU AI Act. It grants exemptions to qualifying free-and-open-source general-purpose AI models — open weights, public architecture, fine-tuning rights. Sounds like relief. It isn't. Copyright obligations remain. Training-data disclosure remains. And if a model gets classified as presenting systemic risk, the exemption disappears entirely.
June Hadley: So you're legally open but operationally — wait, who decides systemic risk? That threshold.
Roy Halliday: That's the trap door. The companies already at the frontier had the lobbying surface to shape where that threshold lands. That's regulatory capture — textbook definition. Compliance costs fall hardest on the open-weight developers who had no seat at that table.
June Hadley: And there's a name for the move that comes before the trap door, actually. Yiwei Zhou — 2026 antitrust scholarship — calls it the Venus Flytrap. Firm releases open-source to pull in users, developers, integrations. Then reasserts control through proprietary bottlenecks. Data, compute, APIs. The open release was the bait.
Roy Halliday: Network effects do the rest. More users generate more fine-tunes, more integrations — power concentrates upstream at the compute and base-model layer even while downstream access looks democratized.
June Hadley: IBM ran this play in 1969. The unbundling decision — they separated software from hardware commercially, created proprietary software as a category. That's the founding moment. Open versus closed has never been a stable equilibrium; it's always been a power contest.
Roy Halliday: And the World Bank is now documenting the current casualty. Open model share: 56 percent to 40 percent in five years. Developing countries didn't vote for that. A compliance architecture designed in Brussels, shaped by incumbents, is selecting them out of the open path — the path they actually had infrastructure to use.
June Hadley: I mean — picture a ministry of health in Senegal, 2025. They've budgeted for local inference. They find the training-data obligations under the EU Act apply because they're deploying in a context with EU data flows. Suddenly the open option isn't legally clean. The closed API is. They didn't choose Anthropic. The paperwork did.
Roy Halliday: So is coexistence still possible — or are we already past that decision point?
June Hadley: The model debate already shifted, I think. That's what clicked for me just now. It's not which model wins — it's who controls the compute, the data pipelines, the APIs. The plumbing underneath.
Roy Halliday: That's exactly it. And that's not reversible the way a model release is reversible. Meta can open-source Llama 4. Nobody is open-sourcing the infrastructure layer. That's the irreversibility.
June Hadley: And coexistence — open and proprietary both surviving — that's a policy choice. Not a default.
Roy Halliday: Not a default. The window the World Bank is flagging — 56 to 40 percent — that's not a market clearing. That's the window closing. Whether it stays open is a compliance architecture decision. Someone has to make it deliberately.
June Hadley: And nobody's quite making it.
Roy Halliday: Not yet. That's an honest place to stop.