Hi,
Picture a toll booth. Not a speed limit, which applies to everyone equally and mostly gets ignored. A toll booth is a physical structure, and somebody chose exactly where to put it: on the one road where the traffic worth charging actually passes.
That is what arrived on open AI models this week. The best of them are still free to download and still free to use, right up until your business makes fifty million dollars a year from serving them. Past that line you stop being a downloader and start being someone who has to come and negotiate.
Hobbyists pass underneath the barrier. Researchers pass underneath. Startups pass underneath. The only people who cross the line are the ones with a legal department, a corporate address and audited books, which is exactly who a toll booth is built to catch, and it is honestly a reasonable way to stop a cloud provider reselling a hundred-million-dollar model for nothing.
Now drive a permissionless network up to it. Not a company: a few hundred strangers with machines, each running a slice of the model, each paid by an automatic ledger. No parent company, no address, no books, and nobody at the wheel to hand a signature to.
The toll booth cannot see them at all. That turns out to be a worse place to be than it sounds, and this week's Pulse is about why.
Listen:
Spotify: https://open.spotify.com/episode/4zd4J3C4p8mCT7tME0ExK4
Apple Podcasts: https://podcasts.apple.com/kg/podcast/plain-strata/id6783455764?i=1000784156917
YouTube: https://youtu.be/F8Bm-C_CdTw
The full piece, no need to click through:
On August 12 a lab in Hangzhou put its largest model on the internet. On August 14 the same lab put its smallest new model on the same website, behind the same download button, on the same page layout, with the same green tick beside the file list.
The first one is Qwen3.8, 2.4 trillion parameters, the model behind Alibaba's flagship service and the first of its size the company has ever made downloadable. The second is Qwen3.8-27B, twenty-seven and a half billion parameters, small enough to run on hardware a person can own.
The small one ships under Apache 2.0. Download it, change it, sell it, build a company on it, and Alibaba has no further claim on you. That is the license the Qwen family has used for years.
The large one does not. It ships under a new document written for it, and inside that document is a number. If you or your affiliates run a model-as-a-service or an AI assistant business whose revenue passes fifty million dollars over any twelve consecutive months, you stop being a downloader and start being someone who has to come and negotiate a separate agreement before you may serve it commercially. Below the line, free. Above the line, a conversation.
That number is this week's story, and the story is not really about Alibaba.
A license is not a technology. It is a promise between two named parties, and it works because each of them can find the other. That has never mattered in this field before, because the thing standing between people and the best open models was always physical: the memory to hold them, the machines to run them, the electricity to feed them. This week the constraint at the top of the range became legal instead, and a legal constraint has a property none of the physical ones had. It requires somebody to sign it.
The one structure in this field that has nobody who can sign is a permissionless network, which is the entire architecture the decentralized side of AI is built on.
Weights are just numbers. Billions of them, each one saying how strongly one small piece of the network pulls on another. Training is the long, expensive process of finding good values for those numbers, and once they are found, the numbers are the model. Copy them and you have copied it. That is why "open weights" was ever a meaningful phrase: it is a claim about a file you can hold.
Here is what the two files actually are. The 27B is a complete, ordinary, permissively licensed model: text, images and video in, a context window of about 262,000 tokens, an official quantized build published beside it. The 2.4-trillion one is a bigger object with pieces missing. The published checkpoint is text-only, though the paid service it powers handles images and video. The million-token context the service advertises is not in it either.
So the same lab, in the same week, made two decisions. It gave away everything about the small model and kept commercial optionality on the large one. Set those two side by side and the question "is this company committed to open weights" stops being answerable, because the license is not a philosophy the company holds. It is a control surface, applied at the size where the money is.
License comes from the Latin licentia, from licere, to be permitted. It means, quite literally, permission. Someone with the standing to say no has said yes to you, in particular, in writing.
Permissionless is built from the other half of the same idea. Permit is per, through, plus mittere, to send: to let through. A permission is somebody at a door letting you through it. A permissionless network is one with no door and nobody standing at it, and that absence is the whole design. It is what lets an anonymous operator in Lagos or Lisbon plug a machine into a network at two in the morning and start serving requests without an application, an approval, or a name anyone checks.
Now put the two words together and the collision is obvious. A permissionless network cannot be granted a license for exactly the same reason it cannot be refused one. There is nobody standing there to be handed the paper.
The move Alibaba made this week is the third or fourth instance of a shape that has been forming for two years, and naming the earlier ones makes clear this is a direction rather than a decision.
Meta's Llama license has carried a line since 2023: the free grant is revoked for any company serving more than 700 million monthly active users, who must then negotiate separately. Moonshot AI, whose Kimi K3 was the subject of an earlier episode of this show, attaches a similar condition: sell it as a service above roughly twenty million dollars a year and you owe a commercial agreement, one that reportedly can run to a revenue share as high as thirty percent.
The pattern is stable across all of them. The weights are genuinely public. The threshold is set high enough that hobbyists, researchers, startups and ordinary companies fall underneath it and feel nothing. Only the people making real money from serving the model cross the line, and they are precisely the people with a legal department, a corporate address, and audited revenue figures. The license is a toll booth positioned exactly where a toll booth is collectible.
Which is a well-designed toll booth, and it is worth saying that plainly rather than sourly. A lab that spends a hundred million dollars training something and then publishes it has to answer the question of why a cloud provider should be allowed to resell it for nothing. This is a reasonable answer. It just has a blind spot with a specific shape.
Ask who the licensee is on a decentralized inference network.
The revenue threshold is written against an entity: you, and your affiliates, aggregated over twelve months. A network of a few hundred independent operators, each running a slice of a model, each paid in a token by an automatic ledger, has no such entity. No participant is anywhere near fifty million dollars. There is no parent company to aggregate them into. There is no signatory. There is no address to send the letter to, and no set of books to audit if you did.
The honest reading of this is not that decentralized networks have found a clever exemption. It is that they are outside the mechanism entirely, and outside is a less comfortable place than it sounds. Unenforceable is not the same as permitted. A subnet can serve the model, and the enterprise customer who was going to buy that inference has a lawyer who will ask which license covers it, and the answer will be a shrug. The toll booth does not stop the traffic. It stops the traffic being sold to anyone who reads contracts.
So the constraint lands in a strange place. It barely touches the individuals running the machines, and it lands squarely on the one thing this side of the field has been slowly building toward, which is being a real supplier to customers who care about paperwork.
Two weeks ago this show covered the release of a 2.8-trillion-parameter model that was free to download and that almost nobody could run, because every parameter has to sit in fast memory at once and the memory bill runs to hundreds of thousands of dollars a month. The pattern there was permission without capacity, and its oldest statement is A. J. Liebling's line from 1960: freedom of the press is guaranteed only to those who own one. You have the right. You do not have the press.
The answer that pattern always produces, historically, is that people buy a press together. And that is what happened: a subnet assembled a couple of terabytes of gaming-card memory out of parts anyone can order and served the thing.
This week is the mirror image. Capacity without permission. The press has been bought co-operatively, the machines are on the floor, the model is on the disk, and the constraint that arrived is the one thing a co-operative cannot resolve by pooling more resources, because you cannot pool your way into being a signatory. The two patterns are a matched pair and they arrived six weeks apart, which is the actual news: the binding constraint at the top of the open-model range moved from silicon to paper in a month and a half.
On August 11, one day before the Qwen release, Nvidia published Nemotron 3.5 Lightning with not only its weights but its training datasets and its methodology, which is a stricter and rarer claim than open weights. Meta shipped a model of its own the week before. The supply of genuinely unencumbered models is growing at the same time the top of the range is acquiring tolls, and both things are true at once.
And the limits on this week's story deserve saying out loud. The revenue-share rate has not been published and is reportedly still being negotiated. The license text has mostly been read through secondary reporting rather than in full. Fifty million dollars is a very high bar, and there is no decentralized inference network on earth currently anywhere near it, so nobody has received a bill and nobody is going to this year.
This is a story about the direction a ratchet turns, not about a payment that came due.
For most of the past two years, the argument for decentralized inference was an argument about cost and control: the same open model, served cheaper, by people no government can switch off. That argument assumed the models would keep arriving unencumbered, because they always had.
If the best open models increasingly arrive with a revenue line drawn through them, then permissionlessness stops being purely an advantage and starts also being a disqualification for a particular kind of customer. A network with nobody to sign is a network that can never produce the one piece of paper an enterprise buyer asks for first.
The open question the field now has to answer: does that make a permissionless network a haven or a ghetto? Either it becomes the place where the encumbered models get served anyway, quietly, to people who do not ask, or it becomes the place that structurally cannot compete for the customers who pay the most. The mechanism does not decide which. The next twelve months of who actually buys decentralized inference does.
Two concrete things. First, the actual text of the Qwen license when it is read in full rather than summarized: whether the threshold triggers on serving revenue, on derived-model revenue, or on total company revenue decides whether a decentralized network's operators could ever individually cross it, or whether the question is structurally unreachable for them.
Second, whether any decentralized inference network publicly states a license policy at all. Right now none of them has had to. The first one that publishes a rule about which models its operators may serve, and how it knows, will be the first time this side of the field admits that a legal layer exists above the machines it spent three years building.
The two voices are AI. The research and writing are mine.
Decentralized AI, layer by layer.
Dastan,
You just read issue #16 of Plain Strata. You can also browse the full archives of this newsletter.