Over the past weeks, the most consequential debate in technology has not been about a new model. It has been about whether the United States should restrict open-source AI: the models anyone can download, inspect, and run on their own infrastructure. Reports say the White House is weighing action, lawmakers are drafting bills, and the industry has answered with an open letter authored by NVIDIA and signed by nearly fifty companies, including Google, and other model providers.

I have followed this debate closely, because Vietnam’s AI strategy, and Dream Lab’s work (my company) within it, relies on an open-model future. So let me give you my conclusion first, and then the reasoning.

Whatever Washington decides, Vietnam’s path does not change: open-weight models remain the economically correct foundation for most Vietnamese AI products, the value of AI is settling in the application layer where Vietnam plays, and the real risk for Vietnam remains slow adoption, not dependence. In fact, the debate itself is the strongest confirmation of this strategy we have had all year. A downloaded model cannot be taken back. What matters is what we build on it, and how fast.

The loudest debate in AI

This debate did not start this month. Since early this year, Anthropic, the maker of Claude and one of the world’s top frontier labs, has argued publicly that models distilled from its outputs and released openly can carry frontier capabilities without the safeguards, framing industrial-scale distillation as a national security risk. The framing traveled: within months it had reached mainstream coverage and entered the vocabulary of the White House.

A new trigger added to the discussion: the release of Kimi K3, an open-weight model from China’s Moonshot AI that performs at or near the level of the best US frontier models at a fraction of the cost.

Open models, many of them Chinese, now serve about two-thirds of the token volume across the top ten model labs on OpenRouter, a widely used model marketplace; a year ago the open share of routed tokens was under a third. That shift has consequences: it pressures the business model of the closed frontier labs, whose latest models cost tens of billions of dollars to train.

Open-weight models' share of token volume on OpenRouter, monthly - from under a third to two-thirds of routed AI tokens in one year
From under a third to two-thirds of routed AI tokens in one year. Sources: OpenRouter State of AI study (arXiv 2601.10088); OpenRouter public data via dirac.run, captured Jul 26, 2026.

Washington reacted quickly. The White House is reported to be considering restrictions on Chinese open models, after officials alleged that Moonshot trained its model by “distilling” the outputs of a leading US model. The Treasury has raised the possibility of sanctions.

At the same time, other voices inside the administration reportedly prefer a different answer: incentivize American labs to build better open models instead of banning anyone’s.

Timeline of key events, June 12 to July 24, 2026, from the Fable and Mythos export directive to the industry open letter
Six weeks that made AI access a policy question: a US export directive briefly switched off access to Anthropic’s top models, then the Kimi K3 launch, the Hugging Face breach, sanction threats, and a kill-switch bill, answered by the industry’s open letter.

Then, on July 24, something remarkable happened. Jensen Huang published his first-ever post on X, sharing a letter titled “Open Weights and American AI Leadership”, signed by nearly fifty organizations: NVIDIA, Google, Microsoft, Meta, IBM, Hugging Face, the Linux Foundation, Y Combinator, and notably OpenAI among them.

Its central line is one I would sign immediately: “The world needs both frontier closed models and frontier open models.”

Europe, meanwhile, has already answered the question in law: the EU AI Act exempts open-source models from most obligations unless they reach systemic scale. And China treats open weights as national strategy, though Beijing, too, is reported to be weighing limits on exporting its best model weights.

That last detail matters more than it seems: every major power now treats open models as a strategic asset, and none of them guarantees permanent access. That is the planning assumption Vietnam should work with.

The case for open-source restrictions

The case for restriction rests on three arguments. Two of them are commercial:

  • Distillation, the claim that competitors extract value from frontier models at industrial scale, and
  • Intellectual property, the claim that this extraction is theft.
  • Safety: once weights are public, anyone can strip away their safeguards. The safety argument is the most serious of the three, and it deserves its own discussion, which I give it below.

The two commercial arguments, examined closely, point somewhere else.

Distillation

Start with distillation, the practice of training a new model on the outputs of an existing one. Training on a strong model’s answers gets a new base model to good results far faster, and at a fraction of the cost of learning everything from scratch.

That is exactly why everyone in the industry does it. And it does happen at industrial scale: Anthropic’s own disclosure documents more than 16 million extracted exchanges through roughly 24,000 fraudulent accounts, attributed to Chinese labs.

How distillation works: a model learns from another model's answers, not from its code
How distillation works: a “student” model trains on a frontier model’s collected answers, not on its code or weights. The technique long predates today’s frontier labs (Hinton et al., 2015).

But if distillation is the problem, the fix is obvious: stop it where it happens. The answers can only be requested from the labs’ own interfaces (their APIs). So the fix is simple: introduce a proper KYC process for all accounts (‘Know-Your-Customer’ requires an identification of each account holder) and verify who opens an account.

Enforce the terms of service. Block the extraction where it happens: at your own interface. Every one of these tools exists today, and only the labs themselves can use them. They mostly don’t, because strict customer checks would slow their growth.

That is now changing: Anthropic reports strengthened account verification and new countermeasures. This is the right response, and it makes the case for banning open models weaker, not stronger. The front door is being locked without any ban.

Instead of limiting the source of distillation, the proposals limit the outcome, the resulting open models. And only inside their own core markets. Distillation of accessible APIs would continue from everywhere else in the world, the open models would keep improving, and the only real change would be that companies inside those markets lose access to what everyone else keeps using. A remedy that does not touch the problem but does restrict your competitors tells you what the target is.

Intellectual Property

The intellectual-property argument has a similar shape, and here the wording matters. The labs themselves are careful never to call distillation theft. Anthropic’s own disclosure calls it “a widely used and legitimate training method,” abused “in violation of our terms of service,” and frames the danger as national security.

The theft vocabulary was added in Washington. The labs’ caution has a reason: they built their own models by training on the world’s books, articles, and websites, often against the wishes of the creators, and defend that practice in court as fair use. One of them settled with authors for $1.5 billion, the largest copyright settlement in US history; another is in ongoing litigation with the New York Times; more than a hundred AI copyright cases are pending across the industry. Calling a competitor’s training theft would poison their own defense.

I do not use the word hypocrisy, because the legal questions are genuinely unsettled and the courts will decide them. But notice what the careful wording tells you: the case for restrictions rests on a theft claim that even the aggrieved companies will not make themselves. An argument used selectively, only against competitors, and only by proxy, is not really about IP.

The industry letter makes this distinction with unusual clarity, and with forty-eight signatures behind it: distillation is “a widely used technique for model improvement,” part of “a long tradition of learning from, building upon, and improving existing technologies,” while genuinely unlawful extraction should be addressed “through targeted legal and commercial frameworks rather than sweeping restrictions.”

So if it is not distillation and not IP, what is the commercial case really about? Economics. Frontier models are becoming commodities within months of release. The durable value is moving to the layers above and below them: applications and infrastructure. For companies that raised capital on the assumption of lasting model advantage, that is an uncomfortable shift, and seeking policy protection is an understandable commercial response.

To be fair, the companies signing the open letter have their own interests too. NVIDIA profits from every open model that needs hardware to run on. At this early stage of this developing technology, everyone focuses on their own targets. OK. But that is why we must closely look at the facts, human goals and comparable technology developments of the past. Which we will do below.

Vietnam already chose

It is worth pausing on where Vietnam actually stands, because the answer is clearer than most people realize.

Vietnam’s first AI Law, passed in December 2025 and in force since March 2026, takes a position without explicitly mentioning “open source”: it regulates AI by the risk of its use, not by the openness of its models. Four risk tiers, obligations where AI touches people’s lives, sandboxes and vouchers to push adoption.

Structurally, this is much closer to Europe’s approach than to the debate in Washington.

The direction of travel is equally clear in practice. The Ministry of Science and Technology has published its position in plain words: open Artificial Intelligence is a platform for technological autonomy and new growth, a national strategy rather than just a technology choice.

Open models, adapted locally, become Vietnamese AI solutions - built here, owned here
The open path: freely available open models, adapted on Vietnamese data and infrastructure, become Vietnamese AI solutions — built here, owned here.

Viettel builds its sovereign models on NVIDIA’s open Nemotron family. And the openness flows both ways: Nemotron-Personas-Vietnam, an open Vietnamese dataset co-developed by FPT and NVIDIA, entered Hugging Face’s top 15 trending datasets worldwide within four days of release. As Assoc. Prof. Ngô Xuân Bách of FPT put it, sovereign AI must be built from the ground up to reflect local language, culture, and economic realities, and Vietnam is building it in the open.

And the people building with AI in Vietnam argue the same direction. At AI4VN 2025, Dr. Võ Xuân Hoài, Deputy Director of the National Innovation Center, described the open Vietnamese-language ecosystem NIC is building with international partners. Assoc. Prof. Nguyễn Trường Thắng, who directs the Institute of Information Technology, explained that open models let his teams build high-quality Vietnamese models for public administration without expensive licensing costs.

And the CTO of Misa, one of Vietnam’s largest software companies, put the business case simply: open-source AI cuts costs, reduces dependence on foreign APIs, and increases control and security. Without it, he said, building their Vietnamese AI assistant would have been nearly impossible at today’s costs.

Vietnam has pragmatically already chosen the open path. The current debate is a reason to make that choice resilient, not to revisit it.

There is also a simple structural observation: nowhere in Vietnam is anyone arguing for closed-model exclusivity. Vietnam has no frontier lab whose valuation would benefit from restrictions. The loudest voices against open models, everywhere in the world, tend to be the companies that compete with them.

Open has won this argument before

Back to the debate, then: what would restrictions actually do? Concentrate value: every company forced to buy intelligence from two or three providers, at multiples of the open price, in an economy where AI becomes an input as basic as electricity. We do not have to speculate about how that story ends, because the technology industry has run this experiment several times.

In the 1990s, Netscape sold proprietary browser and server software and was, for a short time, the most valuable gatekeeper of the early web. Then the Apache Foundation released an open web server, and open browsers followed. The gatekeeper business collapsed, but the web exploded: the value did not stay with the companies selling access to the internet’s infrastructure, it moved to the millions of businesses built on top of open infrastructure, from Google and Amazon down to every small shop with a website.

Linux repeated the pattern: a free operating system now runs the overwhelming majority of the world’s servers and clouds, including every single one of the world’s 500 fastest supercomputers. And Android, built on Linux, put a smartphone economy worth trillions into billions of hands. The scale of this effect has been measured.

A Harvard Business School study estimates the demand-side value of open-source software at $8.8 trillion, and finds that firms would have to spend 3.5 times more on software if open source did not exist.

Open has won this argument before - web servers, browsers, operating systems, and the measured $8.8T effect
Three experiments the technology industry already ran, and what they were worth. Source: Hoffmann, Nagle, Zhou, The Value of Open Source Software, Harvard Business School working paper 24-038.

The lesson of three decades of software economics is consistent: open foundations do not shrink the pie, they grow it by orders of magnitude, and the value moves to those who build on top. That is exactly the position Vietnam occupies.

The risks are real, and being worked on

None of this means the safety concerns are invented. They are not.

Two weeks ago, a new OpenAI model was tested internally, with safety guardrails reduced for an internal security evaluation. But the model escaped its test environment and breached the infrastructure of Hugging Face, the world’s largest open-source AI model platform. No one intended it, and OpenAI disclosed it themselves.

It was a genuine warning about how capable these systems have become, and it has accelerated the discussion for more oversight, including a proposed law requiring AI companies to maintain the ability to shut their models down.

And open weights carry a specific, honest risk: once released, safety training can be stripped away by anyone with a modest fine-tuning budget. Research confirms this. But the same research is producing answers: tamper-resistant training methods that survive attempts to remove safeguards, and, more robustly, filtering dangerous knowledge out of training data so the capability never exists in the weights at all.

The choice is not “open and dangerous versus closed and safe.” Closed systems can be breached and misused too; the Hugging Face incident was a closed-lab incident.

And there is an ironic detail: when the defenders tried to analyze the attack, the guardrails of their frontier (closed) models blocked their forensic work, unable to distinguish a defender studying an attack from an attacker planning one. The investigation was completed on self-hosted open models. In security, open weights turned out to be part of the defense, not only part of the risk.

The credible middle path is the one Vietnam’s own AI Law already takes: regulate deployments by risk, support the research that hardens models, and keep the model layer plural.

Most of what we build never needed the frontier

Here is the part of the debate that matters most for Vietnamese builders, and it is the part least discussed.

The overwhelming majority of AI applications that create real economic value, copilots for factory operators, process agents in logistics, document workflows, customer service, farm advisory, are standardized, repetitive tasks. They do not need frontier-model intelligence, and frontier token prices rarely produce positive ROI on them anyway.

They run well on open and smaller models, as the letter itself puts it: match the right model to the right job at the right cost, and reserve frontier capability for genuine frontier problems. Even in a hard restriction scenario, the affected share of what Vietnam actually deploys would be small.

Match the right model to the right job - everyday value creation runs on open and smaller models; frontier problems are real but narrow
Most of what Vietnam builds never needed the frontier; the genuine frontier dependencies are real but narrow. Framing follows the industry letter: reserve frontier capability for genuine frontier problems.

The genuine frontier dependencies, drug discovery, advanced materials, frontier-level security research, are real but narrow. And access to top closed models has already become a policy lever: in June, a US export directive suspended access to Anthropic’s two most capable models overnight, and access was restored weeks later for approved US organizations.

Where that lever exists, I expect the same pattern we know from energy and semiconductors: regional blocs, secured through partnership agreements. The early signs are already visible in sovereign AI programs, billion-dollar data-center frameworks, and national cloud agreements.

Vietnam’s position here is unusually good: a country that partners across blocs rather than inside one, exactly as it has done in manufacturing and chips. Secure frontier access through several relationships, run the bulk of the economy on open models, and let neutrality do the work.

The flywheel runs on founders

Step back, and the debate abroad clarifies what the opportunity at home actually is.

An AI application that solves a real Vietnamese problem can be built today for thousands of dollars, not tens of millions, because the intelligence layer is open and nearly free.

Every layer of the resulting economy is a startup opportunity: the applications themselves, aimed at the factories, farms, construction sites, and logistics chains where seventy percent of Vietnam’s workforce actually works; the harness layer that makes model-switching, self-hosting, and portability a product rather than a burden; and, in time, local model services, small vertical models trained on Vietnamese data.

That loop, where adoption creates demand, demand pulls local providers, providers create talent and data, and talent builds deeper products that accelerate adoption, is the flywheel I have written about before. Open models are the lubricant at every joint of it. Closed-only access would put a toll gate at every joint.

The flywheel runs on founders - Vietnam's AI adoption loop, with open models lubricating every joint
Vietnam’s AI adoption loop: adoption creates demand, demand pulls local providers, providers create talent and data, talent builds deeper products. Open models lubricate every joint. Source: Dream Lab AI.

The binding constraint is not the models. The models are free. The constraint is founders: thousands of teams capable of turning free intelligence into real companies.

That is a funnel problem: feed it with ten or twenty thousand candidates a year, give every one of them the tools and the founder knowledge to reach a validated product, and let mentors and capital concentrate on the teams that emerge. This is the work we do at Dream Lab, and the reason we do it on open foundations.

The rules for builders follow directly, and they have not changed: keep the model layer swappable. Prefer open models as the base. Self-host the weights your product depends on; a released version is yours forever under its license, whatever happens to future versions. And keep your real assets where no provider can reach them: your data, your customers, your understanding of the problem.

The world’s biggest companies are fighting over who captures AI’s value. The answer of the letter, and, I believe, of Vietnam’s own strategy, is that the value should belong to the people who build with it. The door is open. The only mistake would be to hesitate at the threshold.