Build an American Third-Path for AI
Between closed frontier APIs and unrestricted releases lies an open-weight strategy that can lower costs, preserve commercial incentives, and compete with China.
Hi, I’m Andrew Glenn, founding editor of Building Our Future. In this edition of our newsletter, we propose America pursue a logical ‘third-path’ option, fostering the development of an ecosystem of open-weight model laboratories that use a risk-mitigating framework to lower costs, preserve commercial incentives, and keep American technology competitive with China.
Last week, we discussed recent advancements in Chinese open-weight models and the implications for advantage and sovereign infrastructure.
The release of Z.ai’s GLM-5.2 open-weight model had precipitated that article. Since then, another Chinese open-weight model has burst into the news: Moonshot AI’s Kimi K3. We have to note here, however, that Moonshot AI has yet to share the weights for its K3 model, which it intends to do on July 27th.
What we know about Kimi K3 is that it boasts 2.8 trillion parameters, making it the largest model announced for open-weight release. Moonshot AI has claimed that K3 has ‘substantially outperformed’ Anthropic’s Opus 4.8 and OpenAI’s GPT 5.6 Sol and GPT 5.5, and that it performs competitively with Anthropic’s Fable 5. Independent aggregate testing presently places K3 behind Fable 5 and GPT-5.6 Sol, although ahead of Opus 4.8 and GPT-5.5 on some measures. Once the model is fully released, additional independent testing will certainly happen.
Just today, Alibaba announced its Qwen3.8 model, claiming it’s second only to Fable 5. The Qwen3.8 preview arrived with no model card, no activated-parameter count and no benchmark data at all.
Even prior to Kimi K3’s release, the British government confirms that the gap between open- and closed-weight models is shrinking, at least in terms of cyber capabilities. The U.K.’s AI Security Institute has found that ‘Recent open models GLM-5.2 and DeepSeek V4-Pro perform similarly to frontier closed models released 4 to 7 months before them — a narrower gap than the 6 to 10 months we measure through most of 2025.’
As open-weight models erode the advantage held by America’s closed frontier systems, the United States and its allies need a new strategy for maintaining technological leadership. America needs a vibrant ecosystem of “third-path” model providers that combine broad access to advanced weights with commercial licensing and staged release.
Soft Law Won’t Work
Dean Ball has found himself at the center of a whirlwind of controversy this week.
Ball, a former Trump policy advisor at the White House Office of Science and Technology Policy (OSTP) and allegedly the primary drafter of the 2025 AI Action Plan, joined OpenAI earlier this month. In his new role, Ball heads the frontier lab’s new Strategic Futures team, which works on legislation, internal governance, catastrophic risks, and the company’s relationship with the government.
In an X post last Friday, Ball provided some observations about the Kimi K3 model and how he expects things to unfold including the following:
I would guess that the Trump Administration will at some point realize that their best strategy here would be to create large amounts of regulatory risk around the use of open-weight Chinese models. You don't need to "ban open source" (one of the dumber motifs of AI policy discussion). You just need to direct every agency to issue soft law that creates FUD [fear, uncertainty, and doubt]. "A Federal Reserve Advisory Bulletin found that there may be backdoors in Chinese AI models." It needn't be that well justified. You just create enough regulatory risk that every regulated enterprise backs off. You probably don't want to create so much regulatory risk that you scare off the hyperscalers from serving Chinese models; this will just drive startups to sketchier providers.
This post ignited a bit of a firestorm, earning the ire of former Trump AI / Crypto advisor David Sacks and Undersecretary of Defense for Research and Engineering Emil Michael.
In his X response, Sacks hints that Ball’s motivation was regulatory capture for OpenAI, violated the rule of law, and would ultimately backfire by imposing approval gates on U.S. labs while Beijing ignores them.
USD Emil Michael’s rebuke was scathing, stating ‘Every industry/ecosystem has its supreme village idiot. @deanwball is that for AI.’ The ad hominem attacks notwithstanding, Michael’s substantive point was that the Pentagon has restrictions against certain Chinese open-weight labs, grounded in legislation and not a shadow law pressure campaign.
In other words, neither Sacks nor Michael are blind to the risks of Chinese models but neither support the sort of bureaucratic overreach of a soft law campaign. And, quite frankly, we agree with them on that. A soft law campaign would be at best ineffective and more likely counterproductive, while also risking the continued erosion of trust in America’s government.
Advancing an American Open-Weight Ecosystem
Even if Ball’s proposed mechanism deserves rejection, the underlying risks and concerns don’t.
As Chinese open-weight models continue approaching the frontier, American policymakers will have to decide whether the United States intends to compete in that market or simply frighten Americans away from using the most capable products. The former would create a durable advantage, while the latter would leave American companies paying more for less optionality while Chinese models continue spreading everywhere beyond the reach of American regulators.
The irony is that the current administration’s own AI Action Plan recognized this problem. It argued that open models benefit startups, researchers, businesses with sensitive data, and government agencies, and that they could become global standards with significant geostrategic value. The plan concludes that ‘we need to ensure America has leading open models founded on American values.’
That is the right ambition. But the plan stops short of assigning anyone responsibility for achieving it. It treats the decision to release weights as fundamentally belonging to the developer and limits the government’s role largely to improving access to compute, supporting the National AI Research Resource (NAIRR), and convening stakeholders.
In light of the near complete lack of ways and means for achieving the desired end, the AI Action Plan fails as a strategy.
The good news is that the United States is not starting from zero. The National Science Foundation and NVIDIA have committed $152M to the Allen Institute for AI to create an open multimodal infrastructure for scientific research. OpenAI released its gpt-oss models under an Apache 2.0 license. NVIDIA has organized a Nemotron Coalition that includes Mistral, Perplexity, Reflection AI, Thinking Machines, and other laboratories collaborating on an open frontier model. And last week, Thinking Machines released Inkling, its first general-purpose open-weight model.
That’s the good news. The bad news is that these initiatives remain a collection of projects rather than a true ecosystem with an accountable owner, predictable release schedule, and a clear path to the frontier.
This gap exists because the economics of the leading American labs favor closed models. A company offering intelligence through an API can meter every token, retain the customer relationship, monitor how the model is used, update its safeguards, and keep valuable usage data inside its own feedback loop. Once it releases the weights, competing hosts can drive down inference prices, customers can operate independently, and the original laboratory loses much of its control over the product.
As such, from the labs’ perspective, keeping the model closed makes sense. From the country’s perspective, however, the decision produces costs that the labs don’t bear:
Startups become dependent on a small number of vendors.
Researchers lose access to the systems they need to study.
Government agencies struggle to deploy models in secure or disconnected environments.
And the global developer ecosystem begins organizing itself around Chinese model families instead of U.S. frontier labs.
The U.S. Government’s Role
China has been willing to subsidize this diffusion because it treats adoption as a strategic return. Permissive licenses, discounted electricity, inexpensive APIs, and government-supported deployment allow Chinese firms to sacrifice some immediate model revenue in exchange for developer mindshare, derivative models, technical standards, and industrial learning. A recent U.S.-China Economic and Security Review Commission paper describes two reinforcing feedback loops: open models encourage widespread adaptation, while deployment across factories, logistics systems, labs, and robotics produces operational knowledge that feeds further development.
The United States should respond by funding two or competing consortia through multi-year, milestone-based model-release contracts. It can contribute compute, data, evaluations, and anchor procurement while requiring a regular family of base, instruction, coding, multimodal, and efficient models in return.
Public money should purchase public capability—not simply reimburse private spending.
The Third Path: Between Fully Open and Fully Closed
There is also a path between a closed API and a checkpoint released without conditions. Allied laboratories already demonstrate how open-weight access can operate through licensing. Canada’s Cohere, for example, has made some weights available for research while requiring a commercial license for enterprise deployment. France’s Mistral has used a similar arrangement for models such as Codestral: developers may download the model for research and testing, while commercial self-deployment requires a paid license.
An American frontier laboratory could provide weights to verified companies, universities, and government agencies under a recurring license that permits self-hosting and fine-tuning but restricts redistribution. Revenue could come from annual licenses, updated checkpoints, support, evaluation, customization, indemnification, and optional hosted inference. The customer would gain predictable costs and control over its data without becoming dependent on a per-token API.
Over time, each model could move down a release ladder. API and limited licensed access at launch, broader commercial self-hosting after testing, and permissive public release when a successor arrives — provided the earlier model has not crossed defined security thresholds. This would create a dependable “frontier-minus-one” American commons while preserving a period of commercial exclusivity.
The alternative to Ball’s soft law campaign, then, is not passivity, but supply. Before Washington attempts to suppress demand for Chinese models, it should make certain that American organizations have a competitive American option.
Addressing Security Risks
Any proposal to release advanced weights inevitably encounters hand-wringing over security. Some of these concerns are legitimate; but, security cannot become an incantation that ends the discussion before the actual marginal risk has been assessed and controlled.
Recall that in 2019, OpenAI initially withheld the largest version of GPT-2 because it feared disinformation, impersonation, spam, and phishing at scale. Eventually, the company released larger versions, working with outside researchers, observing the results, and eventually publishing the full model after finding ‘no strong evidence of misuse.’ In hindsight, the warnings about GPT-2 were overstated compared to the model’s abilities.
Virtually every advanced model has encountered the same concerns before ending up widely available — most recently Anthropic restricted access to its Mythos 5 and Fable 5 models but is now releasing access in a controlled, graduated manner.
Both the GPT-2 and Mythos-class episodes offer a valuable lesson that few typically draw. Developers can stage a release, gather evidence, and then widen access when the feared effects fail to materialize.
By conducting this sort of testing, we can examine whether a releasing a particular checkpoint creates a material capability beyond what is already available through the internet, closed models, or existing open weights. The Commerce Department’s NTIA report on widely available model weights adopted this marginal-risk framework and concluded that the evidence did not justify general restrictions on then-current open models. Instead, it recommended continued monitoring, defined thresholds, and the ability to act if future evidence changes.
That’s a prudent approach as the risk from LLMs is often overstated. A 2024 RAND red-team study found no statistically significant difference between biological attack plans created with internet access and those created with both internet and LLM access. The troubling model outputs generally reflected information that was already publicly available.
The Risks, While Marginal, Are Growing
At the same time, we must resist the oversimplification that an AI can only reproduce information that already exits. Models have demonstrated an ability to combine knowledge from multiple sources, translate expert material into usable instructions, generate and test code, and (when connected to the correct tools) revise its approach in response to results. This can reduce the time, cost, expertise, and coordination required to act on existing information. In domains such as cyber operations, the danger may come less from revealing a secret than from automating a known technique across thousands of targets.
The capabilities of AI unquestionably are continuing to advance. The U.K. AISI reported that the length of narrow cyber tasks frontier systems can complete autonomously has been doubling every few months. It also finds that users can remove open-model refusals and disable external monitors. Once weights circulate, developers cannot patch every copy.
The proposed credible release system remains the best defense against this. Such a system tests whether a model materially assists novices or experts in consequential biological, chemical, cyber, or autonomous tasks. It would compare that assistance against the best existing public model, not against a world in which AI does not exist. it would consider the entire operational chain: knowledge, materials, equipment, tacit skill, target access, and the ability to execute reliably.
Those findings support staged release rather than blanket secrecy. Lower-risk models could be published immediately. More capable checkpoints could begin in controlled APIs, move to licensed deployments in audited environments, and receive wider distribution as evidence accumulates. Models crossing specific, independently evaluated cyber, biological, or autonomous-capability thresholds could remain restricted.
Licensing provides legal accountability, not perfect technical control. A contract can impose security requirements and prohibit redistribution, but it cannot prevent a determined recipient from copying ordinary weights. Downstream defenses—DNA-synthesis screening, laboratory security, identity verification for enhanced cyber tools, vulnerability disclosure, and accelerated patching—must therefore accompany model governance.
Security should determine how a model is released, not serve as a standing excuse for declining to build it. Soft-law fear campaigns substitute insinuation for evidence. A staged system can address demonstrated risks without allowing speculative ones to freeze the American ecosystem in place.
Focus on the Context Layer
An American open-weight strategy does not mean that weights will remain the principal source of advantage. As we argued last week, value is migrating into the data, permissions, tools, workflows, memory, and trust surrounding the model.
That shift makes model plurality useful. An organization controlling its context layer can route routine work to an inexpensive local model, use specialists for particular domains, and reserve an exquisite closed system for the few tasks where its additional capability justifies the cost. It can replace a supplier without rebuilding its institutional memory. America does not need every domestic open model to lead every benchmark if organizations can safely substitute models while retaining their data, permissions, and workflows.
The context layer also makes open weights safer. A model should not decide what it may access or which actions it may take. Those permissions should live in an external policy layer. Every model—American or Chinese, open or closed—should be treated as an untrusted computational component receiving only the context required for its task. Its artifacts should be traced to a known source, its behavior tested against mission-specific evaluations, and its access to data, tools, and networks logged and constrained.
Government can establish this architecture through procurement. Contractors should make agent state, tool definitions, evaluations, memory stores, fine-tuning artifacts, and audit records portable across models. Common interfaces and evaluation harnesses would allow new American weights to enter existing workflows without requiring agencies and companies to rebuild their systems.
Open weights create optionality at the intelligence layer. Portable context allows organizations to exercise it. Together, they would enable American institutions to deploy adaptable models, retain ownership of sensitive operational knowledge, and generate the specialized evaluations and tooling that improve the broader ecosystem.
Conclusion
Kimi K3 and Qwen3.8 should be treated as warnings, not invitations to panic.
The United States will not reverse China’s open-weight momentum through unofficial warnings. Such a campaign would push regulated companies toward expensive American incumbents while leaving the rest of the world free to adopt Chinese models.
Nor should Washington dismiss genuine security risks. Open weights cannot be recalled, and future systems may provide operational capabilities older models did not. Those risks require independent evaluations, staged access, and downstream defenses.
The appropriate response combines three elements: competitive American open-weight supply, evidence-based release decisions, and a sovereign context layer that keeps data, permissions, memory, and workflows under the user’s control.
If Washington believes Chinese models create unacceptable dependencies, it should offer a better American alternative. If open models have geostrategic value, it should invest accordingly. And if American values are meant to shape the global AI ecosystem, they must be present not only in policy documents and hosted APIs, but in the models the rest of the world can actually use.
Epic Fury
Epic Fury Pt. Deux reaches ninth day of intensive strikes; Iran says two tankers in Strait of Hormuz exploded and immobilized (RT)
Three U.S. servicemembers confirmed killed over past week of Iran war (NPR)
Dozens more servicemembers allegedly injured in strikes (NYT)
News Headlines
Trump’s latest grift: offering faster access to Truth Social posts for $100K/month (RT)
Spain beat Argentina to win the 2026 FIFA World Cup, but the game-to-watch was France vs. England vying for third place (ESPN)
The U.K. gets its 7th PM in less than 10 years--Andy Burnham to take up residence at 10 Downing Street (TG)
Trump calls U.K. a ‘poverty stricken disaster’ over North Sea oil policy (CNBC)
Sinaloa cartel drug lord ‘El Mayo’ Zambada set to be sentenced to life in prison (AP)
Quantum Tech
Physicists confirm 20-year-old theory using ‘quantum bath’ that could provide new platform for entanglement-based technologies (PHYS)
Scientists discover new ‘space-time limit’ in quantum physics (STD)
Quantum breakthrough links light and magnetism in atomically thin materials (SD)
Quantum teleportation could reduce photon loss in long-distance communications (PHYS)
QuiX Quantum has delivered Carina, world’s first universal photonic QC designed for customer deployment (FBS)
PsiQuantum to make massive QC out of light (MTR)
AI / ML
China’s new open-weight Kimi K3 model rivals best American frontier models at fraction of the cost (AX)
Navy develops strategy to weaponize data, AI (MT)
Former SecAF Kendall is bullish on AI outperforming humans in certain combat situations (MT)
Meta Oversight Board finds AI models less likely to criticize repressive regimes (RT)
New York becomes first state to impose a data center moratorium (RT)
Semiconductors / Chips
U.S. lawmakers urge POTUS to ban Chinese memory chips (FT)
SpaceX is in talks to sell computing power to Pentagon (WSJ)
Small number of Nvidia chips begin shipping to China legally (BBG)
Meta is talks to sell computing power to Anthropic (BBG)
TSMC is accelerating Arizona factory buildout to capitalize on AI ‘megatrend’ (CNBC)
Deal Flow
VC
Chinese AI startup DeepSeek to raise fresh capital at $74B valuation ahead of onshore IPO (RT)
Databricks raised a $5B round at a $188B valuation led by Coatue (RT)
AI chip startup Etched is in talks to raise a round at a $20B valuation led by Jane Street (WSJ)
Chai Discovery, an AI-driven molecular design company, raised a $400M Series C at a $3.8B valuation led by Index Ventures (SA)
AI agent startup Lyzr AI raised a $100M Series B at a $500M valuation, after using its own agent to manage the fundraise (PU)
Forge Nano, a semiconductor equipment and advanced materials company, raised a $97M Series D from Samsung SDI, Horizons Ventures, and others ahead of its SPAC listing (GNW)
InstaLILY, an AI company and creator of the AI Forward Deployed Engineer, raised a $60M Series B led by Energize Capital (PU)
Custom AI chip design startup TYLsemi raised a $43M in early-stage funding led by Matter Venture Partners (SA)
Thira, a secure self-learning AI systems-of-execution startup, raised a $21M seed round led by Madrona (GW)
Applied Computing, a UK startup developing physics-based AI for energy operators, raised a $20M Series A led by KBR (PU)
Reo.Dev, an AI-native GTM platform for companies selling to engineering and technical teams, raised an $11.3M Series A led by Elevation Capital (PU)
SwarmBase, an on-chain infrastructure protocol for autonomous AI agents, raised $7M in funding backed by Castrum Capital, M2M Capital, and more (TB)
PE / M&A / Exits
China’s Moonshot AI is preparing to IPO in Hong Kong by year-end as it wraps up a funding round at a $30B valuation days after launching the world’s best AI model (BBG)
Chinese optical transceivers maker Eoptolink Technology filed confidentially for a potential $4B-$5B Hong Kong listing (BBG)
Debt
CoreWeave is seeking to raise $2.6B in leveraged loans backed by its Anthropic and Jane Street deals (BBG)
Dutch cloud computing firm Nebius raised $775M in its first ABF deal (BW)
Exciting Opportunities
The Pentagon plans to dangle $400K salaries to recruit Wall Street bankers--but hasn’t yet (WSJ)
Editor’s Picks
Josh Brown reveals that the biggest beneficiaries of AI may not be AI companies.
UCLA researcher Prineha Narang wants the federal government to buy quantum computing in boost to industry.
Lighter Side
Keep Building,
BOF






