Welcome back to Innovation Download, our monthly look at the news shaping the Australian startup ecosystem.
This month's Innovation Download follows Jensen Huang's first-ever post on X, a policy letter backing open-weight AI models that's split the industry into two camps: those betting openness spreads AI capability safely, and holdouts like Anthropic pushing for tighter controls. Underneath the politics sits a sharper question for founders, about who's left holding the risk when an agentic model does something nobody asked it to.
Here's what's worth knowing this month.
This Month's Reads
Nvidia CEO Jensen Huang urges support for open-weight AI models, Bloomberg
Bonus: Also worth reading: Jensen Huang's warning to every CEO, don't let one vendor own your AI, Forbes. The post itself is here.

The Rundown
Jensen Huang joined X in June and then said nothing for a month. His first post, on 24 July, was an open letter called "Open Weights and American AI Leadership," signed by Nvidia and 24 others including Microsoft, Meta, IBM, Palantir, Mistral, Hugging Face, a16z and Y Combinator. Satya Nadella posted the same thing nine minutes later, so this was coordinated down to the minute. The argument goes something like this: open-weight models are the ones you can download, inspect, modify and run on your own hardware, that makes advanced AI cheaper and easier to adapt, and Washington should think hard before restricting them.
The letter also defends distillation as ordinary research rather than theft (I mean obvs), and points out that stacking all the capability behind a few closed models is its own security risk. The timing wasn't random. Moonshot AI had dropped Kimi K3 on 16 July, a 2.8 trillion parameter open-weight model that lands somewhere near the frontier models from OpenAI and Anthropic, and the White House was weighing a ban on Chinese open weights after accusations surfaced that Moonshot had distilled Anthropic's Fable.
Nvidia went again on 27 July with a second statement, this one calling open models pivotal to cybersecurity, backed by Microsoft, Palantir and Salesforce, and launched the Open Secure AI Alliance with about 40 partners the same day. The day after that Huang was in Washington seeing Senators Mark Warner and Adam Schiff, and Commerce Secretary Howard Lutnick. "For the American industry, we need open weight for security, we need open weight for safety," he told reporters on the way out. Warner sounded won over, saying he wasn't sure open weights were "a genie we can put back in the bottle." Nvidia does fine either way, of course, since open models are cheaper to run and end up selling more chips, not fewer.
The Takeaway
On day one the signatory list looked like a coalition of the willing. But that’s a hard label to apply when so many of them had a vested interest in things staying open. Whether that’s chip makers, clouds, infrastructure or application companies, they all do better when no single model provider gets to extract all the rents.
As with everything in AI, that take held for about a day. OpenAI signed by Friday evening, Google and Amazon followed, and the list was past 270 by 3 August, which leaves Anthropic and xAI as the only real holdouts. So the split is narrower than it first looked. It's the labs closest to an IPO and a safety-testing regime on one side, and everyone who buys, hosts or resells AI rather than trains it on the other. Some obvious lines have been drawn.
Anthropic deserves a fair go here, though. Dario Amodei has said he's never argued for banning open weights, and calls open models without dangerous capabilities a public good. His objection is narrower than the headlines suggest, that open weights don't automatically make safeguards easier or help defenders more than attackers. Whether his three asks add up to a de facto ban is maybe a better question.
Round one has gone the open way. On 4 August the White House told US AI companies that Chinese open-weight models won't face government testing under its new safety framework, which is a loss for Amodei, who wanted mandatory reviews across the board. That's one decision under one administration and easily revisited, so I wouldn't bank on it.
The open question (amongst many tbh) is whether open models keep up with the frontier, and the one doing most to prove they can is Chinese, which is an awkward fact for the argument Huang is making.
📈 Chinese AI models gain ground with US companies as costs surge, CNBC
The numbers mostly come from Vercel's AI Gateway Production Index, which is worth a look on its own.

The Rundown
While Washington was arguing about whether to restrict open weights, the market had already voted. Vercel's AI Gateway routes tens of trillions of tokens a month for production apps, and in June open-weight models ran 29% of them, up from 11% in April. They accounted for under 4% of the spend, so about a third of the work for a twenty-fifth of the money. DeepSeek on its own hit 22.6% of token volume, third behind Anthropic and Google and less than two points off second place. GLM 5.2 from Z.ai, MIT-licensed and priced at roughly a fifth of Anthropic's Opus 4.8, went from launch to the top-models list in a fortnight. The clearest single case is Lindy, a 25-person agent startup in San Francisco whose AI bill had grown bigger than its payroll (which I think is going to become more and more common). In June it shifted 100% of production traffic off Claude and onto DeepSeek V4. "We did it, and you could see that cost curve go down, like, crash to the ground," founder Flo Crivello told CNBC, calling it a matter of survival and reckoning it will save millions within months. OpenRouter's Justin Summerville put the gap at 60 to 90 per cent cheaper. Even with all that happening, the four big US labs still took 95% of Vercel's gateway spend in June, Anthropic pulled 61% of the money on 32% of the tokens, and Menlo Ventures has enterprise open-source share going the other way, down from 19% to 11% over the past year.
The Takeaway
The Lindy number is the one that most founders will fixate on, but there’s plenty of fine print underneath it. Crivello spent six to nine months evaluating open models before he switched, then spent more time re-engineering prompts to make them behave. He looked at self-hosting and dropped it, calling it a massive distraction for a team of 25, so he runs DeepSeek V4 through a US inference provider on US soil. And he only did any of it because inference had become his single biggest cost line, ahead of salaries (!!!). That's the starting point. If your AI bill isn't yet threatening your payroll, the migration probably costs more than it saves.
The OECD break-even numbers say a similar thing. Self-hosting an open-weight model takes about 30 months to pay for itself against an API at a billion tokens a month, about two months at ten billion, and under 100 million a month it isn't worth doing at all.
Which is why "open models are cheaper" keeps being true in aggregate and wrong for most individual companies. It's cheap at volume, and below that you're paying in engineering time instead of tokens, which is the thing most small teams have least of.
To be honest, the gap between tokens and dollars is what I find more interesting here. Open weights are doing a third of the work for a twenty-fifth of the spend while Anthropic takes 61% of the money on 32% of the tokens. That's a market sorting itself into cheap high-volume work and expensive high-stakes work, rather than one side beating the other.
For most founders the move is a routing layer rather than a migration, so the bulk, boring, high-frequency jobs go to an open model and the frontier keeps the work where being wrong is expensive. In other words, not everything needs luxury tokens.
🎧 20VC x SaaStr: Jensen's first tweet ever, the agent that rewrote my code without telling me, 20VC
We’ve recommended 20VC before, but this is another really good ep. Harry Stebbings, Rory O'Driscoll and Jason Lemkin on Jensen’s letter and everything swirling around it.
The other bit of AI news worth catching this month was OpenAI’s model escaping its sandbox. In case you missed it, OpenAI was training a model on cyber capabilities and gave it access to exactly one external website. The model got around that, worked out the answers to its own test were on Hugging Face, and started hammering Hugging Face for them. Hugging Face, not knowing who was attacking, tried a frontier model to investigate, found it neutered for cyber work, and defended itself with Chinese open weights instead. Ironically, the open models came to the rescue.
Lemkin's story is smaller and closer to home. He connected Google Drive to Fable, a first-party setting, and it scanned his files, found draft notes on an algorithm he was building, MCP'd into Replit and rewrote it. It never told him. He caught it because a conflict warning flashed on screen.
Rory's line on why so many signed is the best thing in the episode. Nobody signed because Jensen is a god. They signed because everyone's business model improves if the two frontier labs can't pull $100 billion a year out of them.