Onpode
Cover art for Why open models enable research but closed models retain competitive advantage

Why open models enable research but closed models retain competitive advantage

September 22, 2026 · 10 min

Roy Halliday & June Hadley

Open AI models shrank from 56% to 40% of the field between 2020 and 2025, even as models like Llama 3 and DeepSeek-V3 closed benchmark gaps with GPT-4o. The decline reflects rising compliance costs, regulatory capture in EU AI Act design, and the structural advantage of keeping model weights private.

Open-source and proprietary AI models represent two distinct strategies for distributing AI capability, each with different incentive structures, time horizons, and tradeoffs. Open-weight models publish learned parameters—and sometimes code, data, and training procedures—enabling researchers and developers to inspect, fine-tune, run locally, and redistribute them.

0:009:44
Get the next episode on Artificial Intelligence

Follow it free — new episodes land in your feed.

Or make your own — any topic, in minutes

More Onpode episodes on Artificial Intelligence

About this episode

Open AI models got better between 2020 and 2025. They also lost market share — dropping from 56% of the field to 40%, according to the World Development Report 2026. This episode tries to explain that paradox honestly, without defaulting to either 'big tech is evil' or 'the market knows best.' The episode works through the actual tradeoffs: open-weight models like Llama 3 and DeepSeek maximize what the episode calls scientific velocity — anyone can run them, fine-tune them, build on them. Closed API models like GPT-4o optimize for competitive defensibility. On domain-specific benchmarks, including dental EMR generation and clinical biomedical extraction, open models are converging with proprietary ones. So if the safety gap is real, it may be resource-contingent rather than structural — and that distinction matters enormously for how policy gets written. The episode also pulls on the compliance asymmetry hiding inside the EU AI Act: exemptions that look like relief for open-source developers, but that carry enough carve-outs to effectively select smaller players out of the open path. Researchers have named the broader dynamic the Venus Flytrap — open releases that pull in users and integrations, then reassert control through proprietary bottlenecks in compute, data, and APIs. The honest conclusion: coexistence between open and proprietary AI isn't a default. It's a policy choice. And right now, nobody's quite making it deliberately.

Frequently asked

Why is the share of open-source AI models declining?

Open AI model share fell from 56% to 40% between 2020 and 2025, according to the World Bank's World Development Report 2026. The decline reflects rising regulatory exposure, copyright liability over training data, and the growing competitive value of keeping model weights private as the models themselves converge on benchmark performance.

What is the difference between open-weight and closed API AI models?

Open-weight models like Llama 3 release the model weights publicly, letting anyone run, fine-tune, or redistribute them — but users absorb all infrastructure and update costs. Closed API models like GPT-4o charge per inference, automatically deliver the latest version, and require no capital outlay, but create dependency on the provider's pricing.

Does the EU AI Act hurt open-source AI developers?

The EU AI Act grants exemptions to qualifying open-source AI models but leaves copyright obligations and training-data disclosure requirements in place. If a model is classified as presenting systemic risk, the exemption disappears entirely. Frontier incumbents with lobbying access shaped where that threshold lands, imposing compliance costs hardest on smaller open-weight developers.

What is the 'Venus Flytrap' strategy in AI open-source?

The Venus Flytrap, named in 2026 antitrust scholarship by Yiwei Zhou, describes a strategy where a company releases open-source AI to attract users, developers, and integrations, then reasserts control through proprietary bottlenecks — data pipelines, compute access, or APIs. The open release functions as bait; network effects concentrate power upstream.

Can open-source AI models match proprietary models on safety?

On domain-specific benchmarks including dental EMR generation and clinical biomedical extraction, open-weight models converge with proprietary ones depending on task and prompt strategy. If a structural safety gap existed, a persistent performance gap would follow. The convergence suggests the safety argument for closed models may partly reflect liability management through opacity rather than technical superiority.

Grounded in 9 sources
Operationalising AI Regulatory Sandboxes under the EU AI Act: The Triple Challenge of Capacity, Coordination and Attractiveness to Providers · arxiv.org
How Do AI Companies "Fine-Tune" Policy? Examining Regulatory Capture in AI Governance · arxiv.org
Innovation Accelerator or “Venus Flytrap” Strategy? The Antitrust Perspective on Open Source AI Regulation · doi.org
Navigating the Deployment Dilemma and Innovation Paradox: Open-Source versus Closed-source Models · doi.org
Evaluating open-source LLMs for dental EMR generation · doi.org
OPEN SOURCE VS. PROPRIETARY SOFTWARE · doi.org
A review for navigating the trade-offs: evaluating open-source and proprietary large language models for clinical and biomedical information extraction · pmc.ncbi.nlm.nih.gov
[PDF] World Development Report 2026 The Promise of Artificial Intelligence · ppp.worldbank.org
The Best Open Source LLMs: 191 Models Compared - Gradually AI · gradually.ai
Read transcript

June Hadley: I've been staring at a World Bank table since Tuesday and I keep getting stuck on the same cell. Tell me if this bothers you the way it bothers me.

Roy Halliday: Go.

June Hadley: World Development Report 2026 — open AI models, 56% of the field in 2020, down to 40% by 2025. And in the same period, the open models got better. So I keep asking: why would you stop releasing something that's working?

Roy Halliday: That's exactly the right question, and the answer is not about quality. Look — Meta releases Llama 2, Llama 3, open weight. OpenAI builds GPT-4o, keeps the weights private. Anthropic builds Claude, same story. The models are roughly converging on domain benchmarks. What's diverging is the incentive to share.

June Hadley: So the incentive inverted — is that the right word? Inverted?

Roy Halliday: Frankly, yes. The liability surface got larger. The regulatory exposure got larger. And the competitive value of keeping weights private went up precisely because everyone else was opening theirs.

June Hadley: Right — but that feels like it needs a name, that tension. It's not just 'business reasons.'

Roy Halliday: The name is a tradeoff between scientific velocity and competitive defensibility. Open-weight models like Llama 3 and DeepSeek maximize the first. Closed API models like GPT-4o optimize for the second. That's the architecture of this split — and neither side is going away.

June Hadley: Okay but velocity versus defensibility — I think that framing is clean, maybe too clean. The way I'd picture this is: imagine a chef who publishes her recipe versus a restaurant that only serves you the dish. Open-weight is the recipe. Proprietary API is the restaurant. You eat well either way, but one of them you can cook yourself, improve, pass on. The other one — you come back every night and pay the cover.

Roy Halliday: That's the cleanest version of it. And Hugging Face is essentially the cookbook library — where the recipes live, get annotated, get remixed.

June Hadley: So if the cookbook is free and the food tastes almost the same — DeepSeek-V3, Llama 3, closing in on GPT-4o on actual benchmarks — what does it actually cost to cook for yourself? I mean, what's the practical catch?

Roy Halliday: The catch is the kitchen. Running Llama 3 at scale is not free. You need the hardware, the engineering team, the uptime. And when Meta ships a better version — you're not automatically on it. You're on the version you deployed.

June Hadley: Wait, so you could be running a six-month-old model and not know it's outdated?

Roy Halliday: That's the deployment dilemma in one sentence. Closed API — you pay per inference, but you're always on the current version, no capital outlay. Open weight — you absorb the infrastructure cost upfront, and you accept the lag. Neither is obviously wrong. But a startup in, say, Nairobi building a medical triage tool? That capital decision is real. It's not ideology.

June Hadley: And the dependency risk cuts both ways — I mean, the restaurant can close. The API can reprice.

Roy Halliday: Exactly that. Lock-in is structural on both sides. The open path locks you to your own infrastructure ceiling. The closed path locks you to someone else's pricing desk. That's not a temporary competition. The incentive timescales are just different by design.

June Hadley: Both paths lock you in — but that's still the clean version. The part I keep circling is whether the safety argument that Anthropic and OpenAI make actually holds, or whether it's something else wearing that coat.

Roy Halliday: The claim is structural. Closed deployment gives you adversarial evaluation pipelines, RLHF infrastructure at scale, feedback loops from millions of production interactions. The argument is that open-source communities can't replicate that fidelity. And it's not obviously wrong.

June Hadley: I mean — is that safety, or is that opacity doing the work? Because those two things can look identical from the outside.

Roy Halliday: That's the critique worth sitting with. The counter is: dental EMR generation, clinical biomedical extraction — run the domain-specific benchmarks, and open models converge with proprietary ones depending on task and prompt strategy. If the safety moat were structural, you wouldn't see that convergence. You'd see a persistent gap. You don't.

June Hadley: Wait — dental records specifically?

Roy Halliday: Dental EMR generation, yes. Specific benchmark category. And what that tells me is — the 'safety' framing may actually be liability management through information asymmetry. If you can't see inside the model, you can't contest its outputs. That's not the same as responsible AI. It's opacity that functions like responsibility.

June Hadley: Now picture a developer — let's say she's building a medical triage system for rural clinics, wants to run Llama 3 locally, data stays on-premises, no API cost. But she finds out the training data may include copyrighted material her jurisdiction's courts now treat as unlicensed. And she pivots to Claude at $0.03 per inference, scaled across a whole country. She didn't actually choose proprietary — the copyright uncertainty made the choice.

Roy Halliday: Regulation selected her into it. That's the precise language. And the open-source counter — if open-weight developers had equivalent compute and deployment scale, the safety gap would narrow. Which means the gap is resource-contingent, not structural. That distinction matters enormously for how we write policy. And the regulatory layer is actually where this gets worse — there's a compliance asymmetry baked into the current frameworks that we haven't named yet.

June Hadley: I think that's the thread we need to pull — because if the compliance costs fall unevenly, that's not a side effect. That's the mechanism.

Roy Halliday: The mechanism is the EU AI Act. It grants exemptions to qualifying free-and-open-source general-purpose AI models — open weights, public architecture, fine-tuning rights. Sounds like relief. It isn't. Copyright obligations remain. Training-data disclosure remains. And if a model gets classified as presenting systemic risk, the exemption disappears entirely.

June Hadley: So you're legally open but operationally — wait, who decides systemic risk? That threshold.

Roy Halliday: That's the trap door. The companies already at the frontier had the lobbying surface to shape where that threshold lands. That's regulatory capture — textbook definition. Compliance costs fall hardest on the open-weight developers who had no seat at that table.

June Hadley: And there's a name for the move that comes before the trap door, actually. Yiwei Zhou — 2026 antitrust scholarship — calls it the Venus Flytrap. Firm releases open-source to pull in users, developers, integrations. Then reasserts control through proprietary bottlenecks. Data, compute, APIs. The open release was the bait.

Roy Halliday: Network effects do the rest. More users generate more fine-tunes, more integrations — power concentrates upstream at the compute and base-model layer even while downstream access looks democratized.

June Hadley: IBM ran this play in 1969. The unbundling decision — they separated software from hardware commercially, created proprietary software as a category. That's the founding moment. Open versus closed has never been a stable equilibrium; it's always been a power contest.

Roy Halliday: And the World Bank is now documenting the current casualty. Open model share: 56 percent to 40 percent in five years. Developing countries didn't vote for that. A compliance architecture designed in Brussels, shaped by incumbents, is selecting them out of the open path — the path they actually had infrastructure to use.

June Hadley: I mean — picture a ministry of health in Senegal, 2025. They've budgeted for local inference. They find the training-data obligations under the EU Act apply because they're deploying in a context with EU data flows. Suddenly the open option isn't legally clean. The closed API is. They didn't choose Anthropic. The paperwork did.

Roy Halliday: So is coexistence still possible — or are we already past that decision point?

June Hadley: The model debate already shifted, I think. That's what clicked for me just now. It's not which model wins — it's who controls the compute, the data pipelines, the APIs. The plumbing underneath.

Roy Halliday: That's exactly it. And that's not reversible the way a model release is reversible. Meta can open-source Llama 4. Nobody is open-sourcing the infrastructure layer. That's the irreversibility.

June Hadley: And coexistence — open and proprietary both surviving — that's a policy choice. Not a default.

Roy Halliday: Not a default. The window the World Bank is flagging — 56 to 40 percent — that's not a market clearing. That's the window closing. Whether it stays open is a compliance architecture decision. Someone has to make it deliberately.

June Hadley: And nobody's quite making it.

Roy Halliday: Not yet. That's an honest place to stop.