8 Comments
User's avatar
Maxorgel's avatar

Very important and timely discussion and I completely agree that Europe needs to be more independent and building its own frontier model is not a realistic option.

However, I think it's worth differentiating using strong harnesses set-ups from using open weight models and being specific about the risk of frontier labs stealing companies' business models.

First of all any serious company should already be operating with a setup that strongly relies on a harness and I believe most do. That's independent of what model is in use.

Open weight models might often be the right solution, but we should also talk about the risks. For many industries and tasks even being 3 month behind can be critical. That's especially true for adversarial areas like cybersecurity, trading, … Also we can't know for sure the distance between the frontier and the best open weight models will remain. Also there are safety consideration around open weights that are at least worth evaluating.

Additionally, enterprise users already have contractual agreement with frontier labs that forbid them using their data for training. While the question of some indirect data leakage is probably complex and labs might use demand data I think it's unlikely they would outright steal knowledge of how the firm runs. I don't think Anthropic required insight knowhow of Figma to build Claude Design or of pharma companies to start drug research. Whether one wants to pay a potential competitor is another question, but we've had similar situations with big tech for decases.

All of these questions have to be looked at case by case and they can be with a good harness. There might often be situations were companies chose to use the frontier model for a time if price / value is right and they don't have a deep dependency and high switching cost.

From everything I've read it looks like the US military also often chose to at least partially go with the frontier models. The fight with Anthropic makes no sense if they were happy to use an open weight model.

Scenarica's avatar

The PSD2 analogy is the strongest section and it deserves stress-testing on the point where it breaks. In banking, the data being ported is inert. A transaction history doesn't change when you move it from one bank to another. The file is the file.

In AI, the "data" being ported includes fine-tuning datasets, prompt architectures, evaluation frameworks, agent configurations, and performance baselines that are inherently coupled to the model they were built for. A prompt that works on one model produces different output on another. An evaluation benchmark calibrated to one model's behaviour isn't portable without recalibration. Porting a bank account is copying a file. Porting an AI harness is transplanting a living system that behaves differently on the new substrate.

The portability mandate is right. The implementation is an order of magnitude harder than PSD2 because the thing being ported is model-dependent in ways a bank balance was never bank-dependent. The standard that solves this isn't a data-export format. It's an abstraction layer that separates the firm's institutional logic from the model's specific behaviour. That's what the harness is supposed to do. Whether any current harness actually achieves it in practice is the testable claim underneath the whole strategy.

Dvorah Graeser's avatar

I agree with your points, but it is possible to build an extra layer of context (sometimes called a context engine) which both helps the model perform better and can help to mitigate issues around switching models. I've seen other types of abstractions used in "model garden" systems, where a cheap model is preferred unless it fails, in which case the problem is routed to a more expensive model.

Rajesh Achanta's avatar

This is the most operational piece I've read on the subject, and the hold-up framing is useful. Three things I'd add, from a supply-chain practitioner's vantage.

First, the knowledge-expropriation risk is the deepest one, and the harness may be a weaker defence against it than against the other three. A harness protects the workflow but the thing being expropriated in your Figma and Cursor examples isn't workflow. It's judgment: the accumulated taste and know-how the usage reveals, which the model absorbs and re-sells. Nadella made the point that tacit knowledge was never on a balance sheet, so firms assumed they held it because they held the people and it now walks out a one-way door through ordinary use. You can own the harness completely and still be strip-mined of the one asset that made you worth copying. That risk needs a different remedy from the other three, and I'm not sure portability or exit options are sufficient.

Second, on portability as insurance: a no-train clause is only as good as the jurisdiction that enforces it. Last month Fable 5 was released, pulled to satisfy US export rules, then released again weeks later when the rule shifted. A contract can't survive an embargo. Which means your second-source argument needs a hardware-and-power corollary: portability is worthless if the data can't physically stay put, and that's a permitting-and-grid question before it's a model question. I'd put the compute substrate closer to the centre than your piece does.

Third, the layer the piece leaves out, is international co-operation. Firm-level and EU-level defence both assume the governance tier holds. It may not work that way. We need a genuine multilateral process underway (like the first UN Global Dialogue in Geneva this week) running alongside a US-led forum proposed, revealingly, by Sam, a lab leader. Europe's move isn't to pick between them but to supplement the multilateral track with a like-minded coalition— Japan, Korea, Canada, India—large enough to have retaliatory bite if either superpower rides roughshod. Portability gives a firm exit; a coalition gives a continent leverage. Both are the same insurance logic at different altitudes.

Which leads to one final reframe I'd offer. The whole piece is defensive—how not to be held up. Perhaps necessary, but it's a hostage's strategy. Your own banking example points the other way: PSD2 wasn't a defence, it was Europe using institutional capacity to turn a general-purpose capability into public value. That's an offensive move. Europe's comparative advantage may not be the harness layer, which Palantir and Mistral already contest - it's that its institutions are a kind of harness, the thing that converts a rented technology into shared prosperity, the way factory acts once turned the steam engine from a mill-owner's tool into a public good. The Tiepolo horse you close on is a warning. The factory acts are the reply.

Diego Gosmar's avatar

Strong argument, but the hold-up analysis stops at the firm-to-model boundary. In multi-agent deployments the exposure moves one layer out: your agents interact with agents belonging to other organisations — suppliers, logistics providers, customers — and that interface is where the next lock-in forms.

Model portability really is close to a config change. Agent-to-agent portability is not. Identity, delegation and capability discovery across trust domains have no settled standard, so whoever defines that interface first sets the terms for everyone downstream.

Which makes your open banking lesson more urgent than the post suggests. Model APIs are already converging toward a de facto standard; agent interfaces are being written right now, mostly by the same labs. If Europe wants a mandated single API standard anywhere, this is the layer where the window is still open — and it closes faster than the banks' did.

Alex Petropoulos's avatar

Despite disagreeing with some parts of the fast-follow strategy (eg: I’m skeptical that open models will be able to be distilled for much longer into the future, I’m deeply confused about where the value is captured and could easily see the frontier dominating) I agree a lot with your point about preventing lock-in to providers, I think this failure mode pops up across a lot of different assumptions, AI timelines and outcomes which warrants greater attention than it currently gets. (And if training an open follower becomes impossible this becomes even more important!)

For what it’s worth, I think that the Europe2031 (or at the very least the Arq: https://www.arq.foundation/research/preparing-europe-for-transformative-ai) theory of change isn’t just to focus on one layer like compute, it’s a broader set of bets, it’s just that compute seems like one of the lowest hanging fruits in the short-term. Other aspects, like deep mutual industrial integration or R&D aimed at addressing market failures like this very one are another core aspect, which is where I’ll focus my reply. So I see us as approaching similar/converging strategies here.

While regulatory action for interoperability may well be necessary, I don’t think it would be sufficient. While it’s currently the case that most personalisation data stored/used by AI systems is portable, either taking the form of internal datasets, or some compressed version of understanding and personalisation, currently markdown files, this might not remain the case.

Claude explanation: “PSD2 worked because bank data is inert — a transaction history is the same file at any bank. Learned context is model-dependent, so there's no standard object for a regulator to mandate exporting yet. “

I could easily see a future paradigm emerge where continual learning takes place in a more technically complex domain, whether that is in some higher-dimensional embedding, or directly updating the weights of a fine-tuned model, or some other paradigm I haven’t thought of.

If this happens, porting learnt data might become technically infeasible, despite regulatory intent. I also don’t think we can just preempt this with regulation, because model hyper-personalisation & continuous learning also seems to be

a) immensely economically valuable

b) highly socially valuable for different AGI futures, one of which is laid out by Seb Krier in Coasean Bargaining at Scale: https://blog.cosmos-institute.org/p/coasean-bargaining-at-scale

To strive for such a positive AI future, I think we need two new technologies to be created. And given the market failure, I think this falls to government/philanthropy to step in:

1) Human Context Protocol/Personalisation Wallet

Why not just store your personal data in a secure 3rd party, which models can then query? Again, the problem is that the optimal learning format might progress from within the labs, which would make this redundant. It seems highly useful for a personalisation learning paradigm to be developed outside the existing labs. If useful for continual learning, I could even see the private sector developing this. But, it’s by no means guaranteed, so probably needs market intervention to be safe rather than sorry.

The ideal version of this allows you to use multiple AI platforms at the same time, with them both updating from the context and personalisation.

Existing work on this: https://digitaleconomy.stanford.edu/publication/robust-ai-personalization-controls-the-human-context-protocol/, maybe https://ruben.verborgh.org/resume/,

2) Agentic access & retrieval.

Even once you have your personalisation stored in an efficient 3rd party wallet, access and retrieval is an important hurdle as well. You might not want all models to access all personalisation data about you for every prompt. Your medical history is not relevant to doing your taxes, and your therapy notes shouldn’t have to be seen to plan a holiday.

The gold standard would be a localised agent that could intelligently negotiate and dynamically determine which information was pertinent and relevant for sharing.

Some people working on this: https://aria.org.uk/opportunity-spaces/trust-everything-everywhere/scaling-trust

I framed these in the context of individual personalisation data (partly because I think that might end up being even more important in the big picture from a Coasean bargaining perspective) but also because that’s just how I initially conceptualised all this. But I think the arguments translate to enterprise neatly.

Beyond these two technologies, you would also need people lobbying governments and coordinating with existing labs, so you would also need a “general manager” for this broader problem coordinating all these efforts to actually solve it, a la https://nanransohoff.substack.com/p/there-should-be-general-managers

Antonio Ferreiro Chao's avatar

Given the possibility of a catastrophic risk, I think it might be interesting to test a global model that could anticipate how disastrous the consequences would be, even for the party that fares best in such a collapse, and therefore advocate for a preventive coalition in the face of such an eventuality.

And since we are immersed in AI models, and cannot trust Frontier Labs, we Europeans should be the ones to develop it, as Second Movers, but in this case, making it easier for Frontier Labs to copy it.

Kevin Lacker's avatar

The nice thing about a coalition to prevent dominance of OpenAI/Anthropic is that logically, Microsoft, Amazon, and Apple should be the allies of Europe here. It’s a lot more likely that some big tech companies could be balanced against others, than that Europe creates a whole new successful entity.