The dependency problem hiding inside an AI controversy
Imagine a European hospital, manufacturer or public authority waking up to a change it did not cause: its preferred AI provider has altered the terms, restricted access in its jurisdiction, raised prices beyond its budget or become unavailable because a government has changed the rules.
The immediate problem would not be whether its model had been “open” or “closed”. It would be whether the organisation could keep working.
Could it move its prompts, retrieval systems, evaluation data and workflow to another model? Could it run a viable alternative in a trusted environment? Would it know which data, logs and accumulated organisational knowledge remained under its control?
Those questions are the real European story behind this month’s dispute around Moonshot AI’s Kimi K3, Anthropic’s Fable and a new NVIDIA-backed paper on open weights.
They point to a principle Europe has not yet operationalised enough: strategic optionality. The ability to retain meaningful choices when the technical, commercial or geopolitical environment changes.
Open weights can contribute to that ability. They are not the whole of it.
Kimi K3 is the trigger - not the whole argument
The chronology matters. In February, Anthropic said it had detected industrial-scale attempts by DeepSeek, Moonshot and MiniMax to extract Claude capabilities through fraudulent accounts and proxy access. Those were Anthropic’s allegations about suspicious access and alleged distillation - not a public technical finding that Kimi K3 had been trained on Fable.
Then, in July, the BBC reported Moonshot’s claim that Kimi K3 could rival leading US systems and would be released with open weights. That reported model outcome put greater attention on Anthropic’s earlier suspicion. On 22 July, White House science and technology adviser Michael Kratsios made the K3-specific allegation that Moonshot had used Anthropic’s Fable capabilities in developing K3; the same report says the US Treasury would examine the alleged industrial-scale distillation and that sanctions could be considered if IP theft were found.
That is the sequence of public claims and subsequent US scrutiny - not a proven account of K3’s training provenance. If unauthorised extraction from a closed service occurred, it should be investigated on evidence and addressed through law, terms of service and proportionate enforcement. The BBC’s reporting does not independently establish that causal account.
But a provenance dispute and the case for a more contestable model ecosystem are two different questions. It would be a mistake to treat an allegation of misuse as proof that open-weight models are inherently unsafe. It would be just as mistaken to treat a closed API as inherently secure simply because access is controlled.
The useful lesson is more demanding: Europe needs to protect IP and security while also avoiding a future in which essential AI capability is controlled by too few providers, clouds and jurisdictions.
The wrong question is “open or closed?”
“Open weight” is not the same as fully open source. A model’s weights may be downloadable while its training data, code, evaluation process or licence remain restricted. A model can be useful and available without being portable for every use. That is why labels alone are not enough.
For a critical workflow, the more useful test has three parts:
- Can the workflow move? Prompts, configurations, retrieval assets and evaluation sets must not be trapped inside one vendor’s format or contract.
- Is there a viable second path? An alternative model does not need to be identical. It needs to be good enough for the defined task, tested before a crisis and deployable under acceptable conditions.
- Can the organisation govern the surrounding system? Data location, identity, logging, security updates, monitoring and human accountability matter as much as the model weights.
This is strategic optionality in practice. It does not require Europe to build or self-host every model. Nor does it mean rejecting high-performing global providers. It means designing critical use cases so that convenience today does not become captivity tomorrow.
Europe keeps asking whether it has an AI champion. That is the wrong unit of analysis. A hospital does not need a champion; it needs a clinical-support workflow it can move. A manufacturer does not need a European logo on every model card; it needs enough control over its data, evaluation and fallback route to keep operating when a supplier or jurisdiction changes the terms.
Where a model is made matters. But for the organisations that depend on it, the more revealing question is whether the workflow built around it can be moved. Sovereignty without portability is branding, not resilience.
Europe has real pieces - but not yet a complete operating system
Europe is not starting from zero. It already has credible examples of open-weight, multilingual and shared-capability work.
Mistral’s original Mistral 7B release under Apache 2.0 showed that a European company could produce a deployable model that others could inspect, fine-tune and self-host. Its current model catalogue gives teams practical options beyond one US API. Germany’s OpenGPT-X / Teuken-7B was built around all 24 official EU languages - an important corrective to an ecosystem that routinely treats English coverage as the default and European languages as a localisation task. And the EU-backed OpenEuroLLM project is pursuing a shared, multilingual foundation-model capability rather than another national winner-takes-all race.
Those are genuine assets. They matter for public services, regulated industries and smaller European language markets in particular.
But they are not yet a complete European operating system for trustworthy AI. Three gaps still matter.
First, licensing is uneven. A company may make some weights available while keeping its most capable models closed or commercially restricted. That can be a reasonable business decision, but buyers must assess the model and licence in front of them - not assume a European provider automatically guarantees portability. Black Forest Labs’ FLUX.1-dev licence, for example, is non-commercial. It is a valuable contribution to an accessible European ecosystem, but not a drop-in open-source option for every public or commercial deployment.
Second, weights without operational support simply move the risk. A hospital does not become independent because it can download a model. It still needs secure hosting, patching, identity controls, red-teaming, monitoring, evaluation, incident response and people who can run the system. Without those layers, openness can transfer responsibility from a vendor to an institution that is not equipped to carry it.
Third, the underlying infrastructure remains concentrated. A downloadable European model may still depend on non-European chips, foreign cloud capacity, external data tooling or a small maintainer team. That does not make the model useless. It means sovereignty must be assessed as a stack, not claimed from the model card alone.
Europe therefore has seeds of capability, not a finished alternative. The task is to turn those seeds into dependable options.
There is now public infrastructure behind that task - not just rhetoric. The European Commission says its AI Factories bring together supercomputing capacity, data and talent, with 19 AI Factories and 13 associated Antennas currently operational. EuroHPC describes the practical offer more plainly: computing resources and support services for European industry, research and startups. And the Commission’s AI Continent Action Plan explicitly puts computing, data, skills, algorithm development/adoption and rules alongside one another.
That is the right diagnosis: Europe’s challenge is a system challenge. But factories, plans and funding announcements are inputs, not proof of operating resilience. The test is whether they make it materially easier for a public authority, hospital or SME to deploy, evaluate, govern and, where necessary, switch a critical AI workflow.
What strategic optionality looks like in a European organisation
This is where the debate becomes less ideological and more practical.
For routine, lower-risk work, a trusted commercial API may be the most sensible choice. For sensitive, multilingual, regulated or continuity-critical work, a European-hosted or self-hosted open-weight alternative may be worth maintaining. For genuinely frontier tasks, an organisation may still choose a leading closed model - while keeping its data boundaries, evaluations and fallback route clear.
The point is not to force every use case into one model family. It is to create a portfolio that is intentional rather than accidental.
A procurement team should be able to ask:
- Can we export our prompts, configurations, retrieval assets and evaluation data in usable formats?
- Has a second model been tested against the same workflow - not merely named in a contract?
- What data, logs and learned organisational knowledge stay under our control?
- What is the service-continuity plan if access, pricing or applicable policy changes?
These are not anti-vendor questions. They are the AI equivalent of asking whether a critical supplier has a business-continuity plan.
A call to the European tech world: make choice real
The European response should not be one mandated “European champion”, nor a new dependency dressed in a different flag colour. It should be an ecosystem in which trusted choice is genuinely possible.
Builders: make deployment reality clearer. Where you release weights, publish usable documentation, evaluation results and precise licences. Build for European languages and handover, not only benchmark headlines. Where a model is not open, be explicit about what can and cannot be exported.
Cloud, security and tooling companies: make the unglamorous layers usable. Institutions need supported hosting, patching, identity controls, observability, red-teaming and migration tools - not a GitHub link and an expectation that every buyer becomes an ML platform team.
CIOs, buyers and public procurement teams: require portability tests, not just exit clauses. For critical workflows, fund and rehearse a second viable route before the first provider becomes irreplaceable.
Investors and policymakers: back the shared layers that turn model releases into strategic capacity: compute access, multilingual data and evaluation, safety research, maintainers, deployment support and public-interest procurement. A model release without those layers is a demo. A supported ecosystem is resilience.
The choice Europe should protect
The Kimi controversy will generate arguments about model provenance, IP, national competition and security. Those arguments matter. But they should not distract Europe from the quieter risk underneath them: allowing critical AI workflows to become dependencies without a credible exit.
Europe does not need to own every model to avoid that outcome. It needs capable European providers, trustworthy global partners, open-weight alternatives where they fit, governed infrastructure and the practical discipline to move between them.
The question is not whether a European hospital, manufacturer or public authority uses an open or a closed model today.
It is whether it still has a meaningful choice on the day the environment changes.
Sources and fact-checking notes
- NVIDIA et al., Open Weights and American AI Leadership, 24 July 2026. Primary document. It lists organisations at the end but gives no individual authorship or explanation of each organisation’s role.
- Anthropic, “Detecting and preventing distillation attacks”, 23 February 2026. Primary claim by Anthropic. Its claims are not independently adjudicated findings.
- BBC, “China’s Moonshot AI stole from Anthropic, Trump tech adviser says”, 23/24 July 2026. Reports Kratsios’s allegation, US Treasury scrutiny and Moonshot’s planned K3 release; it does not independently prove K3’s training provenance.
- BBC, “China’s Moonshot AI claims Kimi K3 can rival OpenAI and Anthropic”, 17 July 2026. Reports Moonshot’s claims and third-party evaluation signals; benchmark results are not a comprehensive safety or provenance assessment.
- Mistral, “Announcing Mistral 7B”, 27 September 2023 and Mistral model documentation. Primary sources for the original Apache 2.0 release and the current model catalogue; check each individual model’s licence and deployment terms.
- OpenGPT-X, Teuken-7B and OpenEuroLLM. Primary project sources for European multilingual open-model work. OpenEuroLLM is an initiative in development, not evidence of a production-ready replacement for every frontier model.
- Black Forest Labs, FLUX.1-dev licence. Primary licence text; it illustrates why “available weights” and “open source for all uses” must not be treated as synonyms.
- European Commission, AI Factories. Official description of the programme and its current ecosystem of AI Factories and Antennas.
- EuroHPC Joint Undertaking, AI Factories. Official operational description of computing resources and support services for European industry, research and startups.
- European Commission, AI Continent Action Plan. Official outline of the five connected areas: computing infrastructure, data, skills, algorithms/adoption and rules.
