Where Reciprocity Stops
Enterprise AI has not rejected the doctrine of software freedom. It has replaced reciprocity with sovereignty.
On 24 July, Microsoft published Open Weights and American AI Leadership. Thirty-five companies signed it. The argument is that open-weight models should stay available and that policymakers should not restrict them.
I agree with the policy ask. Governments should not ban weight releases. Weight releases have put real capability in the hands of teams that could never train a model from scratch. They work where connectivity is poor and where there is no budget for metered inference. They give institutions somewhere to go besides one vendorโs API.
What follows is about the justification, not the policy.
The letter opens in the 1980s. It credits the open-source pioneers with most of the internet, with the systems inside the largest technology companies, and with US military and federal science work. In that account of why free software succeeded, the licence never appears.
That absence is the whole thing.
Free softwareโs invention was not sharing. Sharing is a disposition, and dispositions decay. Its invention was enforceable reciprocity: copyleft, the ban on field-of-use restrictions, four freedoms written as a checklist you can test. It turned goodwill into an obligation that travels with the artifact and binds people who feel no generosity at all.
Take the licence out of the story and openness becomes a mood. It has to, because a weights file is compiled output. You can run it and fine-tune it, the way you can run and patch a binary. What does not ship is the preferred form for modification: the corpus, the pipeline, the training code, the hyperparameters, the evaluation harness. So you cannot study how the system works, and you cannot rebuild it from source. Several widely used releases add acceptable-use policies and user-count thresholds, which are field-of-use restrictions and fail the first freedom before the source question arises. The Open Source AI Definition is explicit about this: the preferred form for modification includes data information sufficient for a skilled person to build a substantially equivalent system, and parameters alone do not supply it. Mozilla, the Linux Foundation and Hugging Face signed this letter. The OSI and the Free Software Foundation did not.
The letter is not an openness document
It is an enterprise sovereignty document, and the doctrine was written down before the letter appeared.
Since December, Satya Nadella has been publishing on a personal site โ a plain GitHub Pages template, no byline, his name nowhere on the pages, as Bloomberg reported at launch. On 14 June he set out the thesis: every firm holds human capital and token capital, models will commoditise, and the prize is owning the learning loop on top of them. The workflows, traces, corrections, memory and private evaluations that compound into institutional knowledge. From that follow portability, private evals, a hard trust boundary nothing crosses without consent, and a test of sovereignty โ can you lose the model and keep the capability?
On 29 June, Palantir and NVIDIA announced a deal to run NVIDIAโs Nemotron open models inside Palantirโs sovereign environments for US government agencies and critical infrastructure. The listed capabilities are worth reading closely: explicit data authorization, secure perimeter enforcement, customer-specific isolation, data portability, right to erasure, full auditability. On 30 June, Palantir published nine theses on AI sovereignty, the central one being that โcontrolling your weights is controlling your fate.โ On 12 July, Nadella cited the Palantir argument approvingly, by name and by link. On 24 July, Microsoft published the letter.
One premise is never defended.
Every document in this sequence takes the firm as the unit sovereignty belongs to. None defends the choice. Why the firm rather than the ecosystem, the protocol, the community, or the person a system is used on?
The question is never raised. The unit is inherited. And that assumption decides everything downstream of it.
So Palantirโs signature is not the irony everyone is reading. Twelve days earlier, the letterโs publisherโs chief executive had endorsed Palantirโs position in writing. Read the letterโs paragraphs on avoiding lock-in and owning the value you create, and they stop looking like passing remarks. They are the compressed public form of a worked-out doctrine.
Same disease, opposite cure
The doctrineโs diagnosis is free softwareโs diagnosis. Improvements flow one way. Corrections travel upward and never come back. Value settles with whoever owns the infrastructure, not with whoever produced the knowledge. That is stated in these documents with more precision than most licensing advocates manage, and it is exactly the problem copyleft was built to solve.
The cures are opposites. Free software answered with reciprocity: take from the commons and you extend the commons, improvements return by force of licence, one-way flow becomes structurally impossible. The doctrine answers with a boundary. Each firm builds a private perimeter and keeps its learning inside. The flow is not made reciprocal. It is dammed, one dam per tenant, at whatever height a party has the leverage to build.
The pattern repeats. Per-token metering drains whoever pays it: agreed, and the answer here is a tenant boundary, where the older answer is inference running on the clinicโs own server, unmeterable because nobody else operates it. Public benchmarks measure the wrong thing: agreed, and the answer here is proprietary evaluations held as firm IP, where the older answer is a specified harness, repeated runs and published transcripts, so the party bearing the consequences can check the claim.
So the fracture is not that these firms rejected the tradition they cite. They kept its vocabulary, changed its beneficiary, and inverted its mechanism. The commons became a moat, one per paying customer, and kept the old name.
Every firm
The distillation paragraph makes the substitution visible.
Policymakers should not confuse legitimate model development with misappropriation, the letter says. Training one model on anotherโs outputs belongs to a long tradition of building on existing technology, a tradition it traces to open source. The next sentence asks for legal protection against extracting value from closed models without permission.
But in free software that permission comes from a licence. One sentence claims an unlicensed freedom to learn. The next claims a licensed right to exclude.
The asymmetry is never named.
The letter leaves that premise unstated. The 12 July note does not. There, providers holding โfair use rights to train models on public dataโ is called necessary innovation, and what is called ironic is that providers then restrict distillation of their own models. Extraction from the public: needed. Extraction from the enterprise: the irony to correct. Note where each version sits โ the concession on an unbranded personal page, the version without it on microsoft.com under thirty-five signatures, addressed to policymakers.
The same note then states the principle better than I could. If learning flows in one direction, value converges on whoever owns the learning infrastructure rather than whoever created the knowledge. That is the publicโs objection to being trained on, stated exactly. It is applied one tier up, where the authorโs own firm is the party losing out.
The proposed remedy is to distribute learning infrastructure to every firm.
Every firm. The word is not โeveryone.โ
Read the signatures against the letterโs own theory of value, which is that wide model circulation creates rivalry across cloud, chips, applications and services. Chips: NVIDIA. Cloud: Microsoft. Hardware: Dell, Cisco. Security: CrowdStrike, Palo Alto Networks, Palantir. Applications and tools: GitHub, Box, ServiceNow, Replit, Perplexity, DoorDash, Telnyx. Capital in the application layer: Andreessen Horowitz, Y Combinator, Emergence. Every category in that sentence has signatories. This is not hypocrisy. It is coherent industrial strategy argued in public, which is the honourable way to do it. It is simply not a transparency commitment, and the two should not be scored on the same card.
Free software made the commons larger. This makes the moat smaller and calls that freedom. Both are answers to the same question about one-way extraction, and only one of them produced an obligation that anybody outside the room could enforce.
And there is a harder question underneath, which this letter is not the place to settle. Copyleftโs lasting innovation was not reciprocity on its own. It was defining a counterparty the mechanism could always identify: whoever receives a copy, automatically, by the act of distribution. Enterprise AI has inherited the language of reciprocity without that. Copyleft worked because it always knew who the counterparty was. Until the party an automated action is taken upon can be represented as a first-class role in the architecture, reciprocity has nowhere to land.
Sources: the letter is here. The two posts referenced are A frontier without an ecosystem is not stable (14 June) and The Reverse Information Paradox (12 July). The PalantirโNVIDIA announcement is here, with NVIDIAโs own account here. The layered view of openness this piece assumes is set out in the Open Small Models Accord.



