Open weights are not owned weights
The letter Jensen Huang signed is right about the country. It is silent on the distance between open weights and enterprise sovereignty.

Jensen Huang shared an open letter arguing that open-weight models are national infrastructure worth defending. The argument holds, and it stops one layer above the enterprise. Open weights describe a license anyone can download and modify. Sovereignty describes where a model runs and who owns the copy trained on the outcomes a company feeds it. A data-sensitive enterprise needs the second, and open weights alone do not deliver it.
An open-weight model you reach through someone else's login is a rental with a good origin story. You can read how it was built. You cannot decide where it runs, and you do not own the copy that learns from your work.
Jensen Huang made his first post on X this week to share a letter he had signed. It is titled Open Weights and American AI Leadership, and around two dozen companies and institutions put their names next to NVIDIA's, from open-model labs to cloud providers to a venture firm or two. The case is that open models, the kind anyone can download, inspect, and run on their own hardware, are national infrastructure, and that walling them off would surrender ground the country cannot get back. The letter is right. It was also written for a country, and a country is not the party that has to live inside the answer. A Fortune 500 carrier is.
What the letter gets right
Strip the politics and the letter makes three claims worth keeping. Open weights widen the on-ramp. The letter puts it plainly: "Open weights expand access to the AI economy." A small team can build on a capable model instead of raising the money to train one from scratch. Wider access to capable models is a public good. Diffusion is the point, and diffusion needs models a school or a startup can run on its own hardware. Open weights keep the field competitive, which is what stops the gains from pooling inside three or four companies. And open weights can be safer than the closed alternative, because a model thousands of people can inspect has fewer places to hide a flaw than one only its maker ever sees.
The letter reaches back to the 1980s, when open-source software went from fringe to the foundation most of the internet now runs on, and argues that open models sit at the same fork today. Every line of that holds. None of it is the question a company has to answer before it deploys.
Open is a license, owned is an address
Open is a property of the license. It says anyone may download the weights, study them, fine-tune them, and run them without asking permission. That is real, and it is worth defending at the altitude the letter is fighting on.
Owned is a property of the deployment. It answers two things the license never touches: what address the model runs at, and whose name is on the copy that has been trained on your data. A model can carry the most permissive license ever written and still run in a tenancy you do not control, on an instance you share with strangers, improving on your corrections while the improved copy stays on the far side of a login. Openness bought you the right to a copy. It did not put the copy inside your walls.
For most of the country this distinction is academic. For a carrier, a bank, or a hospital system, it is the whole review. The data these companies would feed a model, how their best people actually perform, what they were paid, who they turned down, is exactly the data a security review will not let out of the building. An open model reached over an API asks that data to leave the building on every call. The permissive license did nothing to change that, because the license was never the thing standing in the way.
The sovereignty a company can hold
So what does sovereignty mean one floor down, where the work happens? Sovereignty here is not a slogan on a slide. It is an address and a title.
The address: the model runs inside the company's own cloud, single-tenant, the only workload on that instance, with customer data processed inside that boundary and nothing crossing it. The title: the weights fine-tuned on the company's own outcomes are the company's property, trained in the company's environment and available to it if the vendor walks away. That is the version of sovereignty a buyer can hold in their hand, because both halves are things a reviewer can check rather than adjectives a vendor can print on a deck. The architecture either does this or it does not, and a review finds out in an afternoon.
Openness helps this story. A model whose weights you are allowed to possess and fine-tune is a precondition for owning the copy at all. A closed model you can only call through someone else's API can never sit inside your walls with your name on it. So the letter's fight matters to the enterprise, as the floor. It is the floor, not the building.
Where the letter stops
The letter argues at the level of the model ecosystem: which models exist, who may use them, whether the country stays in front. That is the right altitude for a national argument. It sits one floor above the question a company opens its laptop to. That question is not which models exist. It is where this one will run, and what leaves the building when it does.
This is the same gap that showed up when a16z argued the value in enterprise software was moving to the intelligence layer above the systems of record. The thesis was precise about where value moves and quiet about where that layer runs. For a company whose data cannot leave, where it runs is the entire decision. Open weights have the same shape of blind spot. They settle what you may do with the model and say nothing about where the model sits while it does it.
There is a second thing the letter cannot see from its altitude. The value an enterprise gets out of a model is not the base weights everyone downloads. It is what the model becomes after months of the company's own corrections. Rent that loop and the compounding accrues to whoever hosts it. Own it, inside your boundary, and the compounding is yours to keep. Openness makes the base model available to everyone equally. What happens after the download is where sovereignty is won or lost, and the letter's argument ends exactly where that part begins.
The proof is already running
None of this is theory for us. At a Fortune 500 insurance carrier, the intelligence layer runs inside the carrier's own cloud, reads across the systems the carrier already owns, and logs every recommendation with the evidence behind it. The study behind that deployment covers four years of production data and 10,765 agents. The weights were fine-tuned on the carrier's own outcomes, in the carrier's environment, and they stay the carrier's property. The methodology, including how each decision is recorded and reconstructed, is published: Decision Traces.
The base model underneath all of that could be the most open set of weights on the internet or a private fine-tune of one. Swapping between them would not touch the part that mattered to the carrier's security review. What mattered was that the model ran where the data already lived, and that the copy trained on four years of the carrier's work carried the carrier's name. An open base would have been welcome. It would not have been sufficient, and a closed base sitting in the same place would have passed the same review.
What survives the download
Open weights are worth fighting for, and the letter is a good fight. Win it and a company earns the right to hold a capable model in its own hands. That right is the beginning of the work, and not the end of it. The model still has to be brought inside the walls, run where the data lives, and trained into a copy the company owns outright. The download is the easy part. The address and the title are the rest.
So take the letter's win and ask the next question it does not reach, the same question a buyer should run against every AI vendor in the pipeline. Not whether the model is open. Whether it is yours: running in your cloud, learning on your data, owned in your name once the contract is over. A model can be open to the entire world and still not be yours. Sovereignty is the second word, and it is the one a company signs for and keeps.
Sources
Saad Bin Shafiq is the founder of Nodes, serving data-sensitive enterprises. Methodology: Decision Traces.