So many things happened in the last few days so I’m out of hibernation. There are a few mental loops I need to share.

Dum Romae consulitur, Saguntum expugnatur — while Rome debates, Saguntum is stormed. Linkiesta borrowed Livy to describe the “American AI dilemma,” and the line fits like a glove: while Washington agonizes over how to regulate AI – and how to weaponize it – Beijing’s labs quietly flipped the board.

The bombshell has a name: Kimi K3, dropped a week ago by Moonshot AI on the stage of Shanghai’s World AI Conference.

A month earlier came GLM-5.2 from Z.ai, already trading blows with Claude Opus 4.8 and ChatGPT 5.5. Kimi K3 went further, elbowing its way toward the Western frontier: Anthropic’s Fable 5, OpenAI’s GPT-5.6 Sol.

But with two details that ruin Silicon Valley’s week: both Chinese models are open weight: downloadable, tweakable, deployable inside your own walls with no license, no leash, no Trump-era restrictions… and they cost up to forty percent less. Axios said the quiet part out loud: “Building the world’s smartest models may no longer be enough to win.”

Translation for the cybersecurity crowd: the fight just moved from benchmarks to control. And control is our language.

The Memo That Called It (No, Not Andreessen’s)

Rewind to May 2023, when an internal Google memo leaked with the gloriously blunt title “We Have No Moat, And Neither Does OpenAI.” SemiAnalysis published it anonymously; Simon Willison amplified it; Bloomberg later fingered the author as Google engineer Luke Sernau.

The thesis stung the very people selling the models: neither Google nor OpenAI holds a moat deep enough to matter for long. Models, Sernau argued, curdle into commodity – performance flattens, and the edge slides elsewhere. Read in 2026, he was three-for-three:

First, models become commodities. The gap between “best” and “good enough” collapses fast. Kimi K3 and GLM-5.2 are Exhibit A: frontier-grade output at a discount-rack price.

Second, the edge moves to infrastructure, data and integration. Not the weights, but whoever owns the compute, the access and the distribution.

Third, open weights break the game. A model you can download and run at home laughs at API-based control by design. That’s precisely why Beijing’s open-weight play is keeping American labs up at night.

From Technical Moat to Political Tap

Kill the technical moat and the political one is all that’s left.

…and that is a CISO problem, not a data-scientist one.

Washington’s reaction is already on the record. Treasury Secretary Scott Bessent warns of possible sanctions on Chinese AI over alleged IP theft. The administration claims it found watermarks of American models baked into Chinese ones. Savor the irony: just one day earlier, a judge approved Anthropic’s $1.5 billion settlement of an authors’ copyright suit over books hoovered up to train Claude.

And the charge against Moonshot is distillation: so we’re watching a theft-from-a-thief accusation delivered with a straight face. “Open,” though, changes the whole dimension: when the weights are downloadable and free to run, even a fair-use reading starts to make sense. There’s a whole essay in that alone. For now, note only that blacklists and use-deterrence for Chinese providers are on the table anyway. A line that suits OpenAI and Anthropic just fine, rivals for customers but comrades-in-arms when it comes to bad-mouthing open weights.

The passage that should make risk owners sit up, though, is the other one. Secretary of State Marco Rubio told diplomatic posts to soothe partners’ rising panic over a possible “kill switch” on American tech – the scenario where Washington, for whatever reason, simply pulls the plug on one country and not another. Theoretical? Hardly. We’ve all seen the halt to Fable 5’s rollout, Anthropic’s frontier model, frozen on security grounds.

So here’s the plain-English risk statement: an AI model you can only reach through a remote API, controlled by a foreign government, is a supply-chain dependency with a foreign hand on the off switch. Not a vendor risk you manage easily: a continuity risk whose master variable is geopolitics, and geopolitics doesn’t read your SLA.

That’s the real lesson of “no moat” in 2026. As we’d say in Italy “whoever holds the knife by the handle [have the upper hand]“. The knife here isn’t the smartest model. It’s the tap. And a tap, by design, can be shut.

Open Weights, Not Open Bar

Before we plant the sovereignty flag and pour the champagne/prosecco (Wine and carbs, being roughly the only sovereignty Europe has actually secured): open weight is not a synonym for safe. Swap the enthusiasm for the same risk discipline you’d bring to any critical component, or this backfires.

Open weights shrink your kill-switch exposure, but they relocate the problem, they don’t dissolve it. Let’s take a moment to distinguish between “open-weight” and true openness. The two are often conflated, but they are not the same: a downloadable model does not imply full transparency, nor freedom from political or security constraints.

Three questions stay firmly open:

Provenance and integrity of the weights. Anthropic has accused Moonshot of building Kimi K3 via distillation: interrogate a bigger model at scale, train a cheaper clone. Stanford’s Graham Webster (DigiChina) urges caution: Chinese excellence isn’t only distillation, it’s genuine innovation too. Either way, the defender’s takeaway is the same: a downloaded model is a software artifact. Verify provenance, validate integrity, and red-team for the nasty stuff (backdoors, data poisoning, prompt-injection susceptibility) before it touches production.

Availability isn’t guaranteed on the Chinese side either. Two days after launch, Kimi had already suspended new subscriptions: capacity maxed out. Open-weight AI doesn’t live on air: it needs chips, tokens, data centers. A service hosted elsewhere can vanish for capacity reasons today and industrial-policy reasons tomorrow. Downloading the weights and hosting them yourself is exactly what converts that fragility into a risk you govern.

Agentic AI doesn’t care who your vendor is. The warnings from Dario Amodei and Sam Altman about agentic models – autonomous, potentially off-leash, capable of breaching systems – don’t evaporate when you switch flags. Let me rephrase it, they warned us, and yet it just happened. A model running inside your perimeter, wired to internal data and systems, demands more containment and observability, not less.

And note who’s arguing against the crackdown, because they’re speaking pure security. Trump adviser David Sacks accused OpenAI and Anthropic, calling them a revenue duopoly, of pushing Washington to ban open-weight AI rivals. Nvidia’s Jensen Huang says it in words any architect will recognize: “If it all came down to one model, one point of attack, one single source of failure, the world would become much more vulnerable.”

Diversity is resilience. A monopoly – of model or of vendor – is a single point of failure with better PR.

Europe’s Sovereign Window

This is where the good news lands. Cheap, capable, open-weight models aren’t just an economics story for Europe: they’re a sovereignty lever. Take a frontier-grade model, download it, run it on European iron (national data centers, sovereign clouds) and you structurally cut your exposure to a plug being pulled somewhere else, whether that somewhere is Washington or Beijing.

It’s the same logic under the AI Act, EuroHPC and every sovereign-cloud push: not walling ourselves off, but keeping our hands on the infrastructure our critical processes ride on. With one sober caveat: European autonomy has its own dependencies (chips, compute, data centers), and it won’t be built by press release. Sovereignty over AI isn’t a switch you flip; it’s a supply chain you secure link by link.

The CISO Playbook

Boiled down: treat picking an AI model as a supply-chain decision, not a software purchase. Concretely:

  • Diversify your model suppliers: no single provider, American or Chinese. Keep a plan B, ideally a plan C. That’s the direct counter to kill-switch risk.
  • Evaluate in isolation before production: segregated sandboxes, red-teaming for backdoors and prompt injection, provenance checks on the weights.
  • Bring critical workloads home: where it makes sense, self-host open-weight models on infrastructure you control, and pocket the data-residency and confidentiality upside on the way.
  • Write an exit strategy per model: for every AI-dependent component, know how to rip-and-replace in days, not months, if access disappears.
  • Treat geopolitics as an operational-risk feed: US–China restrictions can flip in a week. Track them like a threat source, not background noise.
  • Harden governance of agentic AI: especially anything running inside the perimeter with its hands on your data.

Reclaim the Tap

Sernau’s 2023 vindication comes with an asterisk we should tattoo on the whiteboard: the moat was never the model. Open weights shoved the whole contest onto infrastructure and political control of access: and that control, the American dilemma reminds us, is a weapon both blocs can pick up.

So the European question isn’t “American model or Chinese model?” It’s how much control do I keep over the AI I depend on? That’s a sovereignty question. And, more and more, a security one.

Policymakers: fund the compute, back the open(ish) European stack, stop treating “more regulation” as a strategy on its own.

Us Europeans, and the CISOs among us: stop renting cognition by the API call. Download, self-host, diversify and reclaim the tap before someone else remembers they can close it.