On June 9 two new frontier models shipped. On June 12 a US export-control order took them away, effective immediately, and it did not take them from a country. It barred access by any foreign national anywhere, inside or outside the United States, including the lab's own foreign-national staff. Nationality cannot be checked in real time at an API endpoint, so selective compliance was impossible, and the only compliant move was to switch the models off for everybody. One came back on June 26 for about a hundred vetted US organizations. The controls lifted June 30, and the other returned globally on July 1.
Nineteen days. Every company building on that endpoint watched the decision to cut and the decision to restore from the outside, with no say in either.
Nineteen days is survivable, and that is not the lesson. The lesson is that the switch was never in the building.
A rented model has an off switch you cannot reach.
Someone who has never heard of your company can turn it off, for reasons that have nothing to do with you. It can also be deprecated on the vendor's schedule, whatever you built on it. Open weights have no such lever, because there is nothing to pull. A published file keeps working through an export order, a policy change, a bad quarter, and a bankruptcy.
Nobody in those stories asked permission.
Mozilla's CTO, Raffi Krikorian, opens their 2026 open source report with three of them. A Māori broadcaster in New Zealand training speech models for te reo, a language too small for any market, under a license that keeps the data with its people. East African farmers diagnosing cassava disease on the phone itself, offline, in fields the cloud has never reached. A Swiss public consortium that trained a national model on public supercomputers and released all of it: weights, data, training code.
His line about the three is the one worth keeping. None of them could have rented this.
Forty-seven countries have already made this call.
Forty-seven nations restrict foreign processing for critical workloads. More than seventy have a national AI strategy. Europe treats open weights as industrial policy: France committed 109 billion euros, the AI Act carved out exemptions for qualified open source, and Portugal shipped a fully open national model for five and a half million. Ursula von der Leyen's argument: Europe cannot afford to depend on others for the technologies keeping its hospitals running and its grids secure. India empanelled thirty-eight thousand GPUs at roughly forty percent below market and added five million developers in a year.
That is a hedge, taken by people who can read a timeline.
Closed is not the same as private.
Developers associate closed models with privacy and security more than open ones, 41 percent against 29. That number measures who does the work, not where the risk sits. A closed API ships its safeguards switched on by default. Self-host and you wire in the same controls yourself.
Look at what actually broke last year. Zero-click exfiltration through a Slack integration. A Copilot leak from an email the victim never opened. A five-dollar expired domain turned into a trusted channel out of a CRM. Full impersonation with MFA bypassed. Every one rated critical, and every one a closed system, which is what you would expect when closed is most of what ships. That is the point. Every one was authorized retrieval reaching an unauthorized recipient, and the secrecy of the weights prevented none of it.
This stopped being a hobby.
Developers run open models across more use cases than closed ones, 5.1 against 4.6, and seventy-eight percent pair a small task-tuned open model alongside or in place of a general-purpose one. Half of all teams run both. The interesting number is the half. Most teams are not picking a side. They are routing each job to the thing shaped for it.
The money agrees. Open weights route about a third of all tokens on OpenRouter, the largest public router, up from two percent in late 2024, and the five highest-volume models there are all open weight. That is routed traffic only, excluding first-party ChatGPT and Gemini, but it is where the open lead concentrates: token-heavy coding and agentic work, which is where the spend is. DeepSeek has raised 7.4 billion dollars. Mistral's revenue grew twentyfold in a year. Six of the largest technology companies are all in: Microsoft and Amazon have invested in open labs, Meta ships its own weights, and NVIDIA, Google and IBM do both.
Keep the switch in the building.
Open still deploys hard, and that is the honest caveat. About half of open adopters reach production against nearly two thirds for closed, and scale does not close the gap, so it is not a money problem. It is tooling and trust, and it is the work. Renting also buys you a counterparty to hold liable, which is a real product. Own it and the liability is yours. That is the trade.
So make the trade on purpose. Homeroom's text model is a file we are licensed to run anywhere, and today a provider runs it for us on US infrastructure. We do not hold the disk. If that provider went dark we would lose a day moving, not a quarter waiting for someone else to decide. We were not on the models that went dark in June, and that is luck rather than foresight. Luck is not a strategy. The part worth defending is the part that does not depend on it.
You never find out what you leased until the day you need it to be yours. That day sends no warning, and by the time it arrives the answer has already been decided by whoever holds the switch. Own the part you cannot afford to lose, rent the rest, and know at all times which is which.