
Should American Enterprises Work With Open-Source Chinese Models? | Only 10% of Neo-labs survive
The Twenty Minute VC
Hosted by Unknown
The Chinese open-source model security scare is frontier lab propaganda — and those same models will run 99% of all enterprise workflows within three years.
In Brief
The Chinese open-source model security scare is frontier lab propaganda — and those same models will run 99% of all enterprise workflows within three years.
Key Ideas
Marketing exaggerates vendor security threats
The 'Chinese model' security threat is frontier lab marketing, not evidence.
Vendors become direct business competitors
Your AI vendor said it will compete against your business — they meant it.
Most AI startups collapse in months
80–90% of neolabs die in 18 months; only durable proprietary workflows survive.
Tiny proprietary segment captures majority value
99% of workflows move to open models; that 1% captures 40% of the value.
Measure outcomes not model sophistication
The smartest model is the cheapest — measure outcomes, not tokens.
Why does it matter? Because the company building your AI stack just told you it's coming for your business.
The Chinese model security warning is deliberate propaganda from frontier AI labs — and the same CTO who exposes it predicts 99% of all enterprise workflows will run on those "dangerous" open models within three years anyway. Eno Reyes of Factory dismantles the assumptions most enterprises are using to make billion-dollar infrastructure decisions: wrong threat model, wrong unit of measurement, wrong vendor alignment entirely.
• Frontier labs invented the Chinese model security threat to protect market share, not American enterprises • Two of the largest model providers have publicly stated they will compete in every industry they currently serve • 80–90% of neolabs die in the next 18 months; only three traits predict which ones survive • The smartest model is often the cheapest — measured by outcome cost, not token price
The 'Chinese model' security warning is frontier lab marketing — not a security finding
"Calling open-source models Chinese models is a scop by the Frontier Labs to basically trick people into thinking that they're scary and otherize them." Reyes is direct about who benefits from the framing and where it originates.
The empirical case is blunt: "the Chinese models specifically have demonstrated no examples where they have some sort of security risk or backdoor compared to American models." What they show is bias — the same bias every model carries toward its creators' preferences. The difference is geography, not architecture.
He offers three questions to apply to every model regardless of origin: What is potentially being censored? Will it solve the problems you care about? And if this model disappears in six to twelve months, can you switch? Those questions catch the actual risks — and they catch them in GPT-4 and Claude just as readily as in DeepSeek.
The concrete illustration: write a 10-K that mentions recursive self-improvement applied to AI, and an Anthropic model blocks you. That is not a Chinese problem. That is a creator-preference problem present across the entire model landscape. Enterprises blocking open-source Chinese models on security grounds while running Anthropic in production are not managing risk — they are applying a double standard that saves no one anything.
Your AI vendor announced it's coming for your business. It meant it.
"Two of the largest companies that provide models today have explicitly said we are going to go after every single one of these industries and businesses that we provide intelligence for." Reyes is not speculating — these are public statements from OpenAI and Anthropic.
The frame he uses is sovereignty: "Who is the sovereign of your intelligence? Is it you or is it some other company?" It sounds abstract until you run the law firm analogy. A firm that outsources every case to outside vendors for five years does not just create dependency — it hands those vendors a complete operating manual for its own business. At year five, the outsourcer can compete directly.
The structural problem runs deeper than competitive threat. Model providers have acknowledged that continual learning does not happen inside the model — it happens at the harness layer, in the workflows and accumulated state of the companies using them. That learning, Reyes argues, is "something that businesses are going to find very critical that they own, that they are the sovereign of."
The harness is where logic runs, where state is maintained, where work with AI actually compounds. On-premises offerings — like Factory Private — are not really about technology preferences. They are about preserving the option to reclaim control. Even enterprises that choose cloud deployments are buying that floor. The companies renting their harness from a provider that has publicly announced competitive intent are teaching someone else how to run their industry.
OpenAI and Anthropic face a binary: regulatory capture or opening to all models — and both paths break something
Being model-locked is "a huge disadvantage if you're trying to sell outcomes." A provider constrained to its own models can only offer their best model, never the best model. On any given task, those can diverge substantially — "that difference between their best model versus the best model can be massive in the pricing."
To make current valuations work, OpenAI and Anthropic must either pursue regulatory capture — "scare politicians into thinking that they must own the means of intelligence" — or open to all models and compete on merit against vendors who can always deploy whatever is currently best. Neither option resolves cleanly.
The application layer bet means "making a $2 trillion bet on one of the most competitive application markets in one of the most finicky segments of the market — dev tools." Anthropic is moving up that stack. OpenAI is hedging, "dipping its toes in both," while quietly letting more open models into its harness without announcing a policy shift.
The irresolvable conflict: a model-locked provider selling outcomes is structurally misaligned with the customer's interest. Their margin depends on your tokens. Your outcome depends on the best available model. Those are not the same objective, and no amount of product polish papers over that gap.
Frontier labs need to become the greatest free-cash-flow businesses in history just to survive their own debt load
"If you're OpenAI or you're Anthropic, the hundreds of billions in free cash flow that you need in order to pay back the debt that you're taking on in order to accommodate these data center buildouts... it's totally existential for them." They need to become "the single greatest free cash flowing businesses in the history of technology" not to thrive — just to live.
"Baked into $2–3–4 trillion valuations is an assumption that you can basically 2x the price of those tokens and people will buy them." Open model proliferation makes that structural assumption implausible for all but the narrowest use cases.
"The TAM of frontier models is frankly overweighted right now." The market is pricing in domination by one to three companies — a structure that open models, sovereign infrastructure preferences, and basic antitrust instincts are already undermining. Anthropic's recent profitability looks more encouraging than it is: Reyes attributes much of it to application-layer revenue, which carries its own conflict-of-interest problem.
Verticalization into chips is the rational response — own more of the supply chain, reduce dependency on third-party compute margins. The wrinkle: their explicit goal is to eliminate dependency on the same compute partners they currently rely on. That conversation is happening while the partnership is still active.
80–90% of neolabs die in 18 months — three questions determine which ones survive
"I think it could be 80 to 90% of Neolabs die in the next 18 months." The qualifier worth noting: for many, death means acquisition at a good multiple, not bankruptcy. The independence ends; the economics may not.
The durability screen has three questions. Is the business attached to a durable workflow? Does that workflow depend on proprietary data that frontier models cannot access without the company? And does this use case still exist in ten years?
Legal passes all three. New models will not get better at legal work without access to firm-specific case data. The workflow is inherently proprietary. The legal system exists in 2035. Legal neolabs, in Reyes's view, have strong survival odds.
General computer use — AI that navigates Excel, operates Jira, handles routine knowledge work — fails the screen. Those workflows are common, the data is not proprietary, and the tools themselves may not exist in their current form within a decade. Frontier models absorb these use cases as capabilities improve, leaving nothing defensible underneath.
The implicit warning for investors: most neolab capital right now is funding workflows that fail at least two of those three tests.
99% of workflows run on open models in three years — and that 1% on frontier captures 30–40% of all economic value
"In three years, 99% of workflows are going to be done on open models, but 1% of those tasks is probably going to be 30–40% of the economic value of the future of intelligence."
Volume and value are about to completely diverge. The 99% — routine enterprise work, code review, knowledge tasks, customer service — migrates to whatever is cheapest. "Cost will dominate." The 1% that stays frontier is genuinely narrow: bio research, advanced AI development, security and defense. Use cases that "really only fit a very specific profile of effectively the frontier of science and technology."
The pricing paradox that follows: if 99% of volume migrates to open models, the token pricing power embedded in current trillion-dollar valuations evaporates for the vast majority of the market. Frontier labs survive — and can justify their margins — only in that narrow band where the performance gap is real and economically decisive. Outside it, cost wins and the margin assumptions collapse.
The cheapest model is rarely the cheapest system — on demanding tasks, the smartest model costs less
"You should not be thinking about the inputs to the price. You should be thinking about the outputs." A code review using a million tokens from a highly capable model — reaching the right outcome immediately — costs less than one using 50 million tokens from a cheaper model that wanders toward the same answer with errors along the way.
"I see a world where the smartest model is actually the cheapest." Not as aspiration — as an outcome calculation that reverses once you benchmark cost per verified result rather than cost per token.
Companies optimizing on per-token price are often choosing more expensive AI without realizing it. The measure they are missing: cost per correct outcome on their highest-stakes tasks, where getting it wrong the first time is more expensive than any token price differential. Most current model tier decisions would flip if that benchmark were applied.
The next system of record won't be called a system of record
What this episode reveals, underneath all the specific predictions, is that the most consequential architectural decision in enterprise AI is not which model to use — it is who owns the layer where learning compounds. Reyes calls it the harness. In five years it will have a different name, probably a branded one, and every major software company will be selling a version of it. The race to own that layer is already underway. The companies building it now are not just shipping software. They are defining the default.
Own your harness, or someone who wants your market will own it for you.
Topics: AI strategy, open-source models, enterprise AI, frontier models, neolab investing, model pricing, autonomous software development, sovereign intelligence, AI market structure, Factory
Frequently Asked Questions
- What is the Chinese open-source model security threat about?
- The Chinese open-source model security scare is actually frontier lab propaganda, not substantiated evidence. Major AI vendors with competitive interests have amplified fears about security risks from Chinese models to protect their market position. This marketing-driven narrative doesn't reflect genuine technical vulnerabilities unique to Chinese-developed models. In reality, open-source models undergo the same scrutiny and community audits as Western alternatives, making the security distinction more about geopolitics than actual risk. Enterprises should evaluate models based on legitimate technical criteria rather than nationality-based concerns.
- Why would your AI vendor compete against your own business?
- Your AI vendor said it will compete against your business—and they meant it. Major frontier labs position themselves not just as technology providers but as direct competitors entering your market space. This fundamental conflict of interest means relying on proprietary vendor solutions locks enterprises into dependency relationships where the vendor profits from both your adoption and your market displacement. Open-source alternatives eliminate this competitive threat, allowing enterprises to maintain independence and control while accessing comparable or superior capabilities. This structural advantage makes open-source adoption strategically essential for business preservation.
- Why do 80-90% of neolabs fail within 18 months?
- Most startups built exclusively on frontier lab APIs lack defensibility and sustainable competitive advantages—this explains why "80–90% of neolabs die in 18 months; only durable proprietary workflows survive." When vendors change pricing, access, or capabilities, these businesses collapse instantly. Only companies with proprietary workflows—unique processes, data advantages, or differentiated applications—preserve viability. The brief window of easy API access creates the illusion of viable businesses, but most fail when reality sets in. Enterprises should build on open-source foundations and develop proprietary workflows rather than depend on vendor platforms.
- Will enterprises move to open-source models despite the 1% high-value exception?
- "99% of workflows move to open models; that 1% captures 40% of the value." Most enterprise tasks—content generation, data processing, customer support, and analysis—run efficiently on open-source models at significantly lower costs. The remaining 1% of sophisticated applications may require cutting-edge proprietary models for frontier research or complex reasoning. However, this small segment captures disproportionate value. Smart enterprises should adopt open-source for routine workflows while selectively using proprietary solutions only where business case justifies the investment. This hybrid approach maximizes cost-efficiency and performance.
Read the full summary of Should American Enterprises Work With Open-Source Chinese Models? | Only 10% of Neo-labs survive on InShort
