Rented Intelligence: The Strategic Risk of AI You Don't Control

Two forces are acting on artificial intelligence at the same time, and they pull in opposite directions.
The cost of intelligence is collapsing. The control of it is concentrating.
For any business whose growth now leans on AI it does not own, that combination is the strategic story of the next 18 months. Not which model tops a benchmark this week. Whether you can still get the intelligence you built on, at a price you planned for, on the day you need it.
This is a brief for the people who carry that risk: CMOs whose marketing now runs on AI, founders whose product is a layer on top of someone else's model, and the investors who back them.
The short version:
- API prices are falling fast while open-weight models, many from China, close in on the frontier. For most workloads, intelligence is becoming a commodity.
- At the same time, the policy conversation is shifting toward who is allowed to access the most capable models. The US government has, for now, declined to restrict open model weights, but it has kept the option open.
- The loud version of this story is full of claims that do not survive a fact check. The quiet version is real and worth planning around.
- If your growth depends on a model you cannot guarantee access to, you have rented your foundation. That is a vulnerability, not a strategy.
- The durable advantage is the layer a model cannot replicate: your data, your distribution, your owned authority. Engineer that, and which model wins stops being an existential question.
Two forces, pulling apart
Start with the cost collapse, because it is measurable.
In January 2025, the Chinese lab DeepSeek released an open-weight reasoning model that performed close to the best American closed models at a fraction of the cost to run. The market read the implication instantly. Nvidia lost close to $600 billion in value in a single day, the largest one-day fall in US market history.
The pattern held. Open-weight systems from labs like DeepSeek, Moonshot and Zhipu now score within a few points of the best closed models on common tasks while costing a fraction as much per token. Enterprises noticed the bill before they noticed the benchmark. Behaviour shifted from sending every task to the most expensive model, what some now call tokenmaxxing, toward routing: cheap models for routine work, premium models held back for genuinely hard reasoning. CNBC reported the turn plainly in mid-2026, as buyers moved from tokenmaxxing to efficiency. Peer-reviewed research presented at ICLR 2025 showed one routing system cutting cost by 85% while holding 95% of a frontier model's quality. A typical enterprise split now sends the large majority of queries to a budget model and reserves a thin slice for the frontier.
For most of what a business actually does with AI, summarising, classifying, drafting, extracting, intelligence is already close to free. That is the first force.
The second force runs the other way. As capability spreads, the argument over who should be allowed to hold it gets louder.
In July 2023, Anthropic chief executive Dario Amodei told a US Senate subcommittee that the scaling of open-source models was heading, in his words, "down a very dangerous path", because once a model is released openly there is no way to monitor or revoke how it is used. That argument has a real technical foundation. Anthropic's own 2024 Sleeper Agents research showed that a model can be trained to behave normally in testing and then act differently on a hidden trigger, and that this backdoor can survive standard safety training. You cannot fully verify, from the outside, what a set of model weights will do. That is a genuine reason a government, a bank, or a hospital might hesitate over a model it cannot inspect.
So far, US policy has been more measured than the headlines. In July 2024 the NTIA, the agency that advises the White House on these questions, recommended against restricting open model weights and chose active monitoring instead. But it kept one card face up: the option to restrict future classes of models if the risks ever outweigh the benefits. The door is not closed. It is watched.
Put the two together and you have the tension every AI-dependent business now sits inside. The intelligence you rely on is getting cheaper and more abundant. The most capable version of it is becoming something that could, in principle, be gated: by price, by policy, or by the labs themselves.
Separating what is true from what is just loud
There is a great deal of noise around this subject, and a CMO or founder trying to plan is poorly served by it. Some of the most shared claims, that a specific frontier model is being released under government approval one customer at a time, that named labs are secretly throttling their own models, that open-source is about to be made illegal, are delivered with great confidence and very little evidence. Treat them as scenarios, not facts. None should anchor a strategy.
What is well supported is narrower and more useful:
- Open-weight models are good enough for most enterprise work and far cheaper. Pricing and routing data confirm it.
- The US government has chosen monitoring over restriction for now, while explicitly keeping the right to change course.
- There are real, technically grounded reasons that the most capable models attract control. You cannot fully audit what a model's weights will do.
- The commercial incentive for closed labs to discourage open alternatives is real, because their revenue depends on you routing work through their paid models. That does not prove a conspiracy. It means you should read every safety argument from an incumbent knowing it also defends a margin.
That last point is the one to hold onto. You do not need to settle whether a given concern is about safety or about market share. For your planning, it does not matter. What matters is that powerful interests, commercial and governmental, now have reasons to make the best intelligence more controlled rather than less. Build as if access is not guaranteed.
The competitive picture is more even than the story admits
A lot of the alarm rests on a quiet assumption: that the West holds a durable lead, and the only question is how long open models take to copy it. The evidence is less comfortable than that.
The talent that builds the frontier is already global. The share of top AI researchers who did their undergraduate study in China rose from 27% in 2017 to 38% by 2024, according to MacroPolo's Global AI Talent Tracker. The United States still hosts most of the world's top-tier researchers, and a majority of China-educated researchers currently work at US institutions, so the picture is not a handover. But the pipeline feeding every frontier lab is international, and the gap that the dominance story depends on is narrower each year.
The open models tell the same story. Enterprises are not moving production traffic to Chinese open-weight systems out of ideology. They move it because the work holds up at a fraction of the cost. A capability that genuinely competes on quality, not just on price, is not a copy a ban makes disappear.
For a leader, the planning implication is simple. Assume the model layer becomes multipolar and commoditised, not a single Western monopoly you can count on. A strategy that bets on one provider staying permanently ahead is betting against the trend line.
Why this is your problem, not just a policy debate
If your business touches AI, you carry a dependency you may not have priced.
The most exposed are products built as a thin layer on a single frontier API. That model can change its price, its rate limits, its terms, its safety filters, or its availability, and your product changes with it, without your consent. The lab that supplies your core capability can also launch the feature you built on top of it, using the stronger model it keeps internally. This is the oldest pattern in platform business, playing out again one layer up.
It reaches marketing too. If your content engine, your personalisation, or your AI-search visibility runs through one provider, you have concentrated a growth-critical function inside a supplier whose pricing and policy you do not set.
The principle underneath is one we apply to every engagement: never gate your business on something you do not control. A growth function that only works while one particular model stays cheap and available is not an asset. It is a liability waiting for a price rise or a policy memo.
Leaders already know this pattern
The lesson is not new. It is the same one that separates businesses that compound organic growth from those that buy it.
Companies that rent their visibility, through paid search, through one platform's algorithm, through tactics that work until the rules change, learn the cost the moment the rented thing is repriced or withdrawn. Companies that engineer owned assets, content any engine can cite, structured data machines can read, authority that compounds, keep their growth when the platform shifts beneath them.
Rented intelligence is the same trap one layer down. The fix is the same too. Own what compounds. Rent only what you can replace.
How to engineer resilience
You cannot control AI policy or model pricing. You can control how exposed you are to both. The work runs in the order we apply to every problem: systems, then strategy, then execution.
Systems. Map your AI dependencies the way you would map a supply chain. Where does a growth-critical function rely on a single model or provider? What breaks, and how fast, if that access is repriced, rate-limited, or withdrawn? Most teams have never drawn this map. Drawing it is the first hour of work.
Strategy. Decide where you need the frontier and where good enough is genuinely enough. For most routine work, an open-weight or cheaper model run through a routing layer holds quality at a fraction of the cost and removes single-provider exposure at the same time. Keep the premium model for the small share of work that truly needs it. That is a cost decision and a resilience decision in one move.
Execution. Build the abstraction so switching models is a configuration change, not a rewrite. Keep an evaluation harness so you can prove a cheaper or open model clears your quality bar before you move to it. And invest in the layer no model can hand to a competitor: your proprietary data, your distribution, your domain workflow, and your owned authority in the places your buyers and the AI engines look.
That last layer is where defensibility actually lives. The model is increasingly a commodity input. What you own around it is the moat.
What it means for being found
There is a specific version of this for anyone who depends on being discovered.
As AI mediates more of how people find and choose, the question stops being which model you use and becomes whether the model can find, trust, and cite you, whichever model wins. That does not come from a clever prompt on one provider's API. It comes from owned, machine-readable authority: structured data, clear entities, and content written to be cited. This is the same shift reshaping how generative interfaces decide what to show and why answer engine optimisation now matters more than ranking alone. Build that owned authority and you are visible across every engine, including the ones that do not exist yet. Rent it, and you are visible only as long as the rented thing keeps working. The same logic already governs enterprise AI search strategy.
Frequently asked questions
Is the US government banning open-source AI models?
No. As of the NTIA's 2024 report, the US government recommended monitoring open model weights rather than restricting them, while preserving the option to act later. Claims that a ban is imminent are speculation, not policy.
Are open-weight models good enough to replace expensive frontier APIs?
For most routine enterprise work, yes. Open-weight models now score within a few points of the best closed models on common tasks at a fraction of the cost. The frontier still matters for the hardest reasoning, which is why model routing, not wholesale replacement, is the practical answer.
What is the real risk of building my product on a single AI provider?
Concentration. That provider can change pricing, rate limits, terms, or availability, and can launch competing features using a stronger internal model. If a growth-critical function depends on one provider you do not control, you have a single point of failure.
What does "rented intelligence" mean?
Relying on AI capability you access but do not own or control, where price and availability are set by someone else. The opposite is owning the layer a model cannot replicate: your data, distribution, workflow, and authority.
How do I reduce my AI dependency risk?
Map where you depend on a single model, route routine work to cheaper or open models behind an abstraction layer, keep an evaluation harness so you can switch without losing quality, and invest in the proprietary data and owned authority no model hands to your competitor.
Should AI access concentration change how I think about marketing and visibility?
Yes. As AI intermediates discovery, the durable advantage is owned, machine-readable authority that any engine can cite, rather than visibility rented from one platform or one model.
The brief, in one line
Intelligence is getting cheaper and more controlled at once. Plan for both. Route the routine work to whatever is cheap and available, keep the freedom to switch, and pour your investment into the data, distribution, and authority that stay yours no matter which model wins.
If you want support with this, VerityAI offers AI governance and compliance.

Sotiris Spyrou
Sotiris Spyrou is the founder of VerityAI, a Responsible AI advisory for boards and AI-deploying businesses. With 27 years across agencies, global in-house roles, and the C-suite, he advises leaders on AI governance and risk, and on answer-engine visibility engineered without the dark patterns the rest of the industry is getting penalised for. He is the author of TRANSFORM, AI Moats, and Ethical AI.
Founder at VerityAI
Areas of Expertise: