Where Reciprocity Stops
Enterprise AI has not rejected the doctrine of software freedom. It has replaced reciprocity with sovereignty.
On 24 July, Microsoft published Open Weights and American AI Leadership. Thirty-five companies signed it. The argument is that open-weight models should stay available and that policymakers should not restrict them.
I agree with the policy ask. Governments should not ban weight releases. They have put real capability in the hands of teams that could never train a model from scratch. They work where connectivity is poor and no budget exists for metered inference. They give institutions somewhere to go besides one vendor’s API.
The letter opens in the 1980s. It credits the open-source pioneers with most of the internet, the systems inside the largest technology companies, and US military and federal science work. In that account of why free software succeeded, the licence never appears.
Free software’s invention was not sharing. Sharing is a disposition, and dispositions decay.
The four freedoms are a definition: run, study, modify, redistribute, written as a checklist you can test rather than a sentiment you can profess. Copyleft made them survive redistribution. Copyright already governed copying, so conveying a modified work required permission, and copyleft made that permission conditional. Pass the work on and your recipient receives the freedoms you received. Permissive licences attach lighter conditions, attribution and preserved notices and in Apache’s case a patent grant, then leave what follows to whoever holds the code. Both are licences. Only one routes reciprocity.
It worked because what you conveyed was what a recipient needed. Source in, source out.
The licence survives the move to weights. The reciprocity does not.
Several of these releases carry Apache 2.0 or MIT, real open source licences granting everything they can grant. The trouble is what they grant over. A weights file gives you the artifact and not the thing it was made from. You can run it and fine-tune it, the way you can run and patch a binary. What does not ship is the preferred form for modification: the corpus, the pipeline, the training code, the hyperparameters, the evaluation harness. A permissive licence on source leaves you holding something complete, so if the vendor walks away anyone can carry the code on. A permissive licence on weights leaves you holding something nobody can carry on.
A copyleft would not repair it. Copyright reaches what you convey, not what you kept. A copyleft for weights could compel you to pass on the weights, which your recipient already has. It could not compel the pipeline, because the pipeline was never conveyed. Whether the next release discloses anything stays a business decision, revisited whenever the business changes. Copyleft made openness self-reproducing. Over weights there is nothing for it to attach to.
Other releases add acceptable-use policies and user-count thresholds. Those are field-of-use restrictions, failing freedom zero before the source question arises. The Open Source AI Definition sets a lower bar than handing over the corpus, and the releases still miss it. What it requires is data information detailed enough for a skilled person to build a substantially equivalent system. Parameters alone do not supply that.
The letter is not an openness document
Mozilla, the Linux Foundation and Hugging Face signed it. The OSI and the Free Software Foundation did not.
It is an enterprise sovereignty document, and the doctrine predates the letter.
Since December, Satya Nadella has been publishing on a personal site: a plain GitHub Pages template, no byline, his name nowhere on the pages, as Bloomberg reported at launch. On 14 June he set out the thesis. Every firm holds human capital and token capital. Models will commoditise. The prize is owning the learning loop on top of them, the workflows and traces and corrections and private evaluations that compound into institutional knowledge. From this follow portability, private evals, a hard trust boundary nothing crosses without consent, and a test of sovereignty: can you lose the model and keep the capability?
On 29 June, Palantir and NVIDIA announced a deal to run NVIDIA’s Nemotron open models inside Palantir’s sovereign environments for US government agencies and critical infrastructure. Read the listed capabilities. Explicit data authorization, secure perimeter enforcement, customer-specific isolation, data portability, right to erasure, full auditability.
On 30 June, Palantir published nine theses on AI sovereignty, the central one being that “controlling your weights is controlling your fate.” On 12 July, Nadella cited the Palantir argument approvingly, by name and by link. On 24 July, Microsoft published the letter.
Every document in this sequence takes the firm as the unit sovereignty belongs to. None defends the choice. Why the firm rather than the ecosystem, the protocol, the community, or the person a system is used on?
The question is never raised. The unit is inherited, and everything follows from it.
Palantir’s signature is not the irony everyone is reading. Twelve days before publication, the letter’s publisher’s chief executive had endorsed Palantir’s position in writing. Reread the letter on avoiding lock-in and owning the value you create. Those paragraphs are the compressed public form of a worked-out doctrine.
Same disease, opposite cure
The doctrine begins from free software’s diagnosis. Improvements flow one way. Corrections travel upward and never come back. Value settles with whoever owns the infrastructure, not with whoever produced the knowledge. These documents state it more precisely than most licensing advocates manage, and it is exactly the problem copyleft was built to solve.
Free software answered with reciprocity. Copyleft does not ask you to contribute to a commons. It requires that whoever receives your version receives your changes on the same terms. The duty is owed to the person in front of you, and the commons grows because each of them can pass it on again.
Enterprise sovereignty answers with a boundary. Each firm builds a private perimeter and keeps its learning inside. The flow is not made reciprocal. It is dammed, one dam per tenant, at whatever height leverage permits.
Metered inference extracts rent from whoever pays it. The enterprise answer is a tenant boundary. The older answer was to run the model on hardware you control, where nobody can meter it.
Public benchmarks produce claims nobody outside the vendor can check. Enterprise sovereignty answers with private evaluations held as firm IP. The older answer was a published harness and runs anyone could repeat.
The fracture is not that these firms rejected the tradition they cite.
They kept its vocabulary, changed its beneficiary, and inverted its mechanism.
The commons became a moat, one per paying customer, and kept the old name.
Every firm
Policymakers should not confuse legitimate model development with misappropriation, the letter says. Training one model on another’s outputs belongs to a long tradition of building on existing technology, a tradition it traces to open source. The next sentence asks for legal protection against extracting value from closed models without permission.
But in free software that permission comes from a licence. One sentence claims an unlicensed freedom to learn. The next claims a licensed right to exclude.
The defence carries a cost, and it lands on the ecosystem the letter says it wants. Small models are increasingly trained on artifacts only frontier systems produce: synthetic instruction data, reasoning traces, distilled experts, reward models. Such a model inherits its categories from upstream, and reproducing it means reproducing the pipeline that generated the training signal. Almost no university or public body can assemble that. Weights get released, the licence is permissive, and the thing still cannot be rebuilt outside the firms that own the generator. Where disclosure stops at the edge of a company’s own corpus, transparency does not survive the pipe.
The letter leaves the premise unstated. The 12 July note does not. There, providers holding “fair use rights to train models on public data” is called necessary innovation, and what is called ironic is that providers then restrict distillation of their own models.
Extraction from the public: needed. Extraction from the enterprise: the irony to correct.
The concession appears on an unbranded personal page. The version without it appears on microsoft.com, under thirty-five signatures, addressed to policymakers.
The note states the principle plainly. If learning flows in one direction, value converges on whoever owns the learning infrastructure rather than whoever created the knowledge. That is the public’s objection to being trained on, stated exactly, and applied one tier up where the author’s own firm is the party losing out.
The proposed remedy is to distribute learning infrastructure to every firm.
Every firm. The word is not “everyone.”
The policy asks make the same shape visible. Public compute for startups and researchers. Public investment in shared training assets. And “avoiding premature restrictions on open models.”
The state funds the inputs. Private parties keep the outputs. Nothing runs with the money. No proposal that a model trained on publicly funded data must publish its recipe. No proposal that publicly funded evaluation frameworks bind the models they measure. No condition of any kind, in a letter that opens by borrowing authority from the tradition that invented conditions.
The state is asked to supply the inputs and leave its leverage unused. That is not an open ecosystem. It is a subsidy with an open-source-flavoured name.
Read the signatures against the letter’s own theory of value, that wide model circulation creates rivalry across cloud, chips, applications and services. Chips: NVIDIA. Cloud: Microsoft. Hardware: Dell, Cisco. Security and defence platforms: CrowdStrike, Palo Alto Networks, Palantir. Applications and tools: GitHub, Box, ServiceNow, Replit, Perplexity, DoorDash, Telnyx. Capital in the application layer: Andreessen Horowitz, Y Combinator, Emergence.
This is not hypocrisy. It is coherent industrial strategy argued in public. It is also not a transparency commitment, and the two should not be scored on the same card.
Free software made the commons larger. This makes the moat smaller and calls that freedom. Both answer the same question about one-way extraction. Only one produced an obligation that ran to people who were never in the room.
Copyleft’s lasting innovation was not reciprocity on its own. It was the method.
Copyright already governed one event. You cannot convey a copy without permission. Copyleft did not invent an obligation and then look for someone to bind with it. It took an event the law already regulated, made the permission conditional, and let the event produce the counterparty. Whoever receives a copy is the party the obligation runs to, identified by the act itself, with nobody to register and nothing to sign.
The question was never who deserves the freedoms. It was who just received a copy.
The method has a known limit. The trigger is distribution. Run modified code as a network service and no copy moves, so the event never fires. The AGPL was written for that gap, and it did not invent a new obligation either. It found another event copyright could still reach: network interaction.
Copyright solved the same problem twice, both times the same way.
The party an automated action is taken upon breaks the method. They copy nothing and convey nothing. They are not the party interacting with the service. The tenant is. Nothing they do requires anyone’s permission, so there is no permission to make conditional. A third licence trigger cannot reach them, and no licence will. Not because licences are weak here, but because they have nothing to attach to.
What transfers from copyleft is not the licence. It is the method: find the event that already creates a governed relationship, and make the obligation travel with it. Copyright supplied that event twice. Between a deployed model and the person it decides about, copyright supplies none, and something else has to name the event.
That is where reciprocity stops. Not at a boundary someone chose to draw, but at the point where no event produces a party to owe it to.
Enterprise AI inherited the language of reciprocity. It did not inherit the method, and no licence can supply it.
Until the party an automated action is taken upon can be represented as a first-class role in the architecture, reciprocity has nowhere to land.
Sources: the letter. The two posts referenced are A frontier without an ecosystem is not stable (14 June) and The Reverse Information Paradox (12 July). The Palantir–NVIDIA announcement, with NVIDIA’s own account. The layered view of openness this piece assumes is set out in the Open Small Models Accord.
Prior work: Corrigibility as a Structural Precondition for Digital Public Infrastructure, deriving five conditions for reversibility: exit, code, audit, govern, fork. And Epistemic Capture and the Action Boundary, extending them to learned and agentic systems. The second reaches this essay’s conclusion from the other direction, and reached it first: “open weights with closed training pipelines is inference transparency without correction capacity.”
This page is the canonical copy. Corrections are made here and noted; the original is never silently edited.