6 Comments
User's avatar
Maxorgel's avatar

Very important and timely discussion and I completely agree that Europe needs to be more independent and building its own frontier model is not a realistic option.

However, I think it's worth differentiating using strong harnesses set-ups from using open weight models and being specific about the risk of frontier labs stealing companies' business models.

First of all any serious company should already be operating with a setup that strongly relies on a harness and I believe most do. That's independent of what model is in use.

Open weight models might often be the right solution, but we should also talk about the risks. For many industries and tasks even being 3 month behind can be critical. That's especially true for adversarial areas like cybersecurity, trading, … Also we can't know for sure the distance between the frontier and the best open weight models will remain. Also there are safety consideration around open weights that are at least worth evaluating.

Additionally, enterprise users already have contractual agreement with frontier labs that forbid them using their data for training. While the question of some indirect data leakage is probably complex and labs might use demand data I think it's unlikely they would outright steal knowledge of how the firm runs. I don't think Anthropic required insight knowhow of Figma to build Claude Design or of pharma companies to start drug research. Whether one wants to pay a potential competitor is another question, but we've had similar situations with big tech for decases.

All of these questions have to be looked at case by case and they can be with a good harness. There might often be situations were companies chose to use the frontier model for a time if price / value is right and they don't have a deep dependency and high switching cost.

From everything I've read it looks like the US military also often chose to at least partially go with the frontier models. The fight with Anthropic makes no sense if they were happy to use an open weight model.

Scenarica's avatar

The PSD2 analogy is the strongest section and it deserves stress-testing on the point where it breaks. In banking, the data being ported is inert. A transaction history doesn't change when you move it from one bank to another. The file is the file.

In AI, the "data" being ported includes fine-tuning datasets, prompt architectures, evaluation frameworks, agent configurations, and performance baselines that are inherently coupled to the model they were built for. A prompt that works on one model produces different output on another. An evaluation benchmark calibrated to one model's behaviour isn't portable without recalibration. Porting a bank account is copying a file. Porting an AI harness is transplanting a living system that behaves differently on the new substrate.

The portability mandate is right. The implementation is an order of magnitude harder than PSD2 because the thing being ported is model-dependent in ways a bank balance was never bank-dependent. The standard that solves this isn't a data-export format. It's an abstraction layer that separates the firm's institutional logic from the model's specific behaviour. That's what the harness is supposed to do. Whether any current harness actually achieves it in practice is the testable claim underneath the whole strategy.

Dvorah Graeser's avatar

I agree with your points, but it is possible to build an extra layer of context (sometimes called a context engine) which both helps the model perform better and can help to mitigate issues around switching models. I've seen other types of abstractions used in "model garden" systems, where a cheap model is preferred unless it fails, in which case the problem is routed to a more expensive model.

Rajesh Achanta's avatar

This is the most operational piece I've read on the subject, and the hold-up framing is useful. Three things I'd add, from a supply-chain practitioner's vantage.

First, the knowledge-expropriation risk is the deepest one, and the harness may be a weaker defence against it than against the other three. A harness protects the workflow but the thing being expropriated in your Figma and Cursor examples isn't workflow. It's judgment: the accumulated taste and know-how the usage reveals, which the model absorbs and re-sells. Nadella made the point that tacit knowledge was never on a balance sheet, so firms assumed they held it because they held the people and it now walks out a one-way door through ordinary use. You can own the harness completely and still be strip-mined of the one asset that made you worth copying. That risk needs a different remedy from the other three, and I'm not sure portability or exit options are sufficient.

Second, on portability as insurance: a no-train clause is only as good as the jurisdiction that enforces it. Last month Fable 5 was released, pulled to satisfy US export rules, then released again weeks later when the rule shifted. A contract can't survive an embargo. Which means your second-source argument needs a hardware-and-power corollary: portability is worthless if the data can't physically stay put, and that's a permitting-and-grid question before it's a model question. I'd put the compute substrate closer to the centre than your piece does.

Third, the layer the piece leaves out, is international co-operation. Firm-level and EU-level defence both assume the governance tier holds. It may not work that way. We need a genuine multilateral process underway (like the first UN Global Dialogue in Geneva this week) running alongside a US-led forum proposed, revealingly, by Sam, a lab leader. Europe's move isn't to pick between them but to supplement the multilateral track with a like-minded coalition— Japan, Korea, Canada, India—large enough to have retaliatory bite if either superpower rides roughshod. Portability gives a firm exit; a coalition gives a continent leverage. Both are the same insurance logic at different altitudes.

Which leads to one final reframe I'd offer. The whole piece is defensive—how not to be held up. Perhaps necessary, but it's a hostage's strategy. Your own banking example points the other way: PSD2 wasn't a defence, it was Europe using institutional capacity to turn a general-purpose capability into public value. That's an offensive move. Europe's comparative advantage may not be the harness layer, which Palantir and Mistral already contest - it's that its institutions are a kind of harness, the thing that converts a rented technology into shared prosperity, the way factory acts once turned the steam engine from a mill-owner's tool into a public good. The Tiepolo horse you close on is a warning. The factory acts are the reply.

Antonio Ferreiro Chao's avatar

Given the possibility of a catastrophic risk, I think it might be interesting to test a global model that could anticipate how disastrous the consequences would be, even for the party that fares best in such a collapse, and therefore advocate for a preventive coalition in the face of such an eventuality.

And since we are immersed in AI models, and cannot trust Frontier Labs, we Europeans should be the ones to develop it, as Second Movers, but in this case, making it easier for Frontier Labs to copy it.

Kevin Lacker's avatar

The nice thing about a coalition to prevent dominance of OpenAI/Anthropic is that logically, Microsoft, Amazon, and Apple should be the allies of Europe here. It’s a lot more likely that some big tech companies could be balanced against others, than that Europe creates a whole new successful entity.