Krikorian Says Skip the Permission Slip. Beijing Is Already Writing the Next One.

Krikorian Says Skip the Permission Slip. Beijing Is Already Writing the Next One.

AI Policy
Mozilla's chief technology officer makes the case for open weights in today's Wall Street Journal. The argument holds against Washington. It has not accounted for Beijing.
By Shashi Bellamkonda · July 28, 2026
19 days
Fable 5 and Mythos 5 offline after the June 12 export order
113,000+
Derivatives of Qwen and Kimi K3 already downloaded (Krikorian, 2026)
€200B
Planned EU spend on sovereign AI infrastructure (Krikorian, 2026)
Key takeaway: Open weights survive an American export order because the file is already on the buyer's server. They do not survive a Chinese one, because the roadmap behind that file still lives in Hangzhou and Beijing. Krikorian's column argues the first point and skips the second.

Amodel you rent can be switched off by whichever government licenses the lab that built it. That is the case The Wall Street Journal ran under Raffi Krikorian's byline this morning, and it is not a new argument for him. Mozilla's chief technology officer has been building it since June, when the Commerce Department gave Anthropic seventy-two hours to disable Fable 5 and Mythos 5 for every foreign national on the planet. His fix is unchanged: buy the kind of AI a government cannot reach into and turn off. Download the weights. Run them on hardware you own. The file does not phone home, so there is nothing for an agency to switch.

The Case He Makes Well

Krikorian's strongest point is arithmetic, not ideology. More than 113,000 derivatives of Alibaba's Qwen and Moonshot's Kimi K3 are already sitting on servers worldwide, and Washington cannot claw a single one of them back (Krikorian, 2026). A ban on the category Meta invented with Llama would need to reach every fork, every fine-tune, and every enterprise cluster running one, three years after the boom started. That is not a policy problem with a clean edge. It is a proliferation problem, and proliferation is the one thing export control was never built to reverse.

He extends the point to procurement. Corporate boards, he argues, can no longer answer a basic question: which models run their production systems, and who controls the switch behind them. The European Union is reportedly planning to spend €200 billion building AI infrastructure it owns outright rather than rents, and Canada is pursuing something similar, both on the logic that a permission-based supplier relationship is a fine way to buy excellence and a poor way to buy the ordinary, everyday inference a business runs on (Krikorian, 2026). Open weights, on this reading, are not a workaround. They are the plumbing.

Proliferation is the one thing export control was never built to reverse.

The Government He Does Not Mention

Read his column against my own reporting from three weeks ago and the gap opens fast. Chinese authorities have held talks with Alibaba, ByteDance, and Z.ai about restricting foreign access to their most capable models, including ones not yet released, with options ranging from a bar on public release to domestic use only. Alibaba has already begun shipping closed, proprietary versions of Qwen alongside the open ones. Krikorian is right that the 113,000 derivatives already downloaded cannot be recalled. He does not say what happens to the enterprise that standardized on Qwen for the next version, the next safety patch, the next context-window jump, none of which arrive if Beijing decides the open branch stops here.

Ownership of a file and control of its future are different assets. The Commerce Department can freeze a rented model in a weekend, and did. A government on the other side of the supply chain can freeze the pipeline behind a downloaded one just as easily, on a slower clock and with no seventy-two-hour notice required, because nothing needs to be switched off. It needs to stop shipping.

What This Changes for the Board Question

Krikorian's board question is the right one, asked with half the risk map. Which model runs your stack still matters. So does which government licenses the lab on the other end of that model's release schedule, whether that lab sits in Mountain View, Hangzhou, or somewhere Washington has not yet drafted a rule for. A vendor-risk register built only around API dependency treats the open-weight column as solved. A vendor-risk register built only around API dependency marks the open-weight column solved when it has only been handed to whichever ministry holds authority over the next update.

Second takeaway: The permission slip Krikorian wants companies to escape has two issuers, not one. Escaping the American one by downloading a Chinese one trades a fast, visible kill switch for a slow, quiet one.
CIO/CTO Viability Question
If your team moved a workload onto an open-weight model because a foreign government showed it would pull the plug on a rented one, who on your vendor-risk team is tracking whether that model's home government can pull the plug on the download instead, and what is the plan for the day it does?

Sources:
Krikorian, Raffi. "AI Shouldn't Require a Permission Slip." The Wall Street Journal, 28 July 2026, wsj.com.
Bellamkonda, Shashi. "Why Anthropic Never Built an On-Device Claude." Shashi.co, July 2026, shashi.co.
Bellamkonda, Shashi. "Two Governments Can Freeze Your AI Model. One Router Won't Save You." Shashi.co, July 2026, shashi.co.
Reuters. "China Weighs Curbs on Overseas Access to Homegrown AI Models." Reuters, 2026, reuters.com.
Disclaimer: This blog reflects my personal views only. Content does not represent the views of my employer, Info-Tech Research Group. AI tools may have been used for brevity, structure, or research support. Please independently verify any information before relying on it.