Mozilla’s CTO thinks AI should be built like the internet

The open AI fight is no longer only about model access. The harder question is whether the next control layer gets built as shared infrastructure or rented back through private choke points.

Share
Mozilla’s CTO thinks AI should be built like the internet

AI is starting to inherit the internet’s old promise at the exact moment the internet’s old failure has become impossible to ignore. The promise was that shared protocols could let small actors build without permission from the largest institutions. The failure was that open rails did not prevent power from concentrating higher up the stack. Browsers, app stores, clouds, payment systems, ad markets, identity providers: each became a gate after the gate supposedly disappeared. That is the tension inside the new push for open AI infrastructure. The question is not whether AI should be more open. It is where control settles once models move from demos into the operating layer of schools, clinics, governments, factories, media systems, and small businesses.

The tension inside AI should be built like the internet

When Mozilla’s CTO says AI should be built like the internet, the phrase works because it carries a moral memory: interconnection, permissionless entry, public standards, resilience through distribution. In the Rest of World interview, the argument is not just nostalgia for open protocols. It is a warning that AI is becoming infrastructure before the governance around that infrastructure has hardened.

That matters now because deployment is outrunning theory. A model in a lab is a capability. A model wired into procurement, customer service, moderation, border systems, credit decisions, or classroom software becomes a decision environment. Whoever defines that environment decides what can be built cheaply, what requires permission, what gets audited, what becomes compatible, and what remains dependent.

The internet analogy therefore cuts two ways. It points toward openness, but it also reminds us that openness at one layer can still produce dependency at another. The web was not enclosed because TCP/IP disappeared. It was enclosed because users, developers, and institutions gradually became dependent on the interfaces where daily action happened. AI can repeat that pattern faster because the interface is no longer only a screen. It is a reasoning service embedded inside work.

Why the easy reading is too small

The easy reading is that this is another open-source AI debate: open weights versus closed models, community builders versus Big Tech, transparency versus secrecy. That framing is not wrong. It is too small.

Open weights help. Meta’s release of an open agentic model shows why large firms increasingly want the political and developer advantages of openness without surrendering every point of control. A released model can lower experimentation costs, seed developer habits, and shape standards around the releasing company’s assumptions. Openness becomes both a gift and a distribution strategy.

The same tension appears in the broader state of open-source AI discussion: access to model artifacts is only one part of the system. Training data, compute, evaluation methods, deployment tooling, cloud credits, safety rules, app distribution, and institutional procurement all determine whether openness turns into real capacity. A model can be downloadable and still be unusable for a hospital, newsroom, ministry, or small manufacturer without reliable hosting, monitoring, fine-tuning, compliance help, and people who know how to operate it.

That is why the Global South lens is essential here. If openness means “you may inspect the artifact, but you must rent the infrastructure from us,” power has not moved very far. It has changed costumes.

The control mechanism underneath the announcement

The mechanism is dependency by deployment. AI power concentrates wherever organizations cannot realistically substitute providers without breaking their workflows.

That mechanism has several parts. First, compute becomes the tollbooth. Even when model access improves, serious deployment requires GPUs, inference capacity, latency guarantees, and cost predictability. This is why the argument in The AI Budget Is Hiding Inside the Cloud Contract matters: the AI bill is not only a line item called “AI.” It is often buried inside cloud architecture, vendor commitments, data-transfer fees, and managed services that quietly decide who can afford to scale.

Second, evaluation becomes a control layer. Institutions do not just need a model that works in a benchmark. They need proof that it works for their language mix, legal context, risk tolerance, user base, and failure modes. If the tools for measuring those things are proprietary, then even open models become dependent on closed judgment systems. The open-source AI report points toward this wider stack problem: the artifact is only one piece of what must be governed.

Third, defaults become policy. If the most convenient hosted version of an open model carries a particular moderation regime, data-retention setting, ranking preference, or integration path, that default travels into local institutions before anyone votes on it. Mozilla’s internet comparison in Rest of World becomes sharp here: the internet was not only a technical architecture. It was a settlement over who could connect, publish, route, and interoperate. AI needs a similar settlement, but the stakes are now cognitive and administrative, not merely communicative.

The real issue is not whether open AI exists. It is whether open AI can be operated without quietly re-importing closed dependency through compute, tooling, governance, and distribution.

Who inherits the deployment constraint

Builders inherit it first. A startup can prototype on open models and still discover that its real moat belongs to the cloud vendor, the app platform, the payment provider, or the compliance wrapper. The more AI becomes agentic, the more every product depends on permissions outside the product: API access, data connectors, browser control, identity systems, enterprise approvals. Meta’s open model release should be read through that lens. Agentic systems do not merely answer. They act across other people’s rails.

Operators inherit it next. Schools, local governments, hospitals, logistics firms, and civil-society organizations do not need philosophical openness. They need systems they can afford, inspect, adapt, and leave. Exit rights are underrated because procurement tends to reward visible features over long-term autonomy. But when AI is fused into institutional process, exit is governance. If a ministry cannot move models without losing workflows, training data, audit history, or staff competence, then sovereignty is mostly decorative.

States inherit the constraint at national scale. In Orbital Connectivity Is Becoming the AI Sovereignty Layer, the connectivity question was not just about bandwidth. It was about whether countries could control the pipes through which future intelligence services travel. AI infrastructure extends that problem upward. The pipe, the compute, the model, the interface, and the audit system all become parts of one sovereignty stack.

Investors inherit a different version of the same question. The durable companies may not be the ones with the flashiest model demo. They may be the ones that reduce deployment dependency for real institutions: portable evaluation, local-language adaptation, sovereign hosting, observability, governance tooling, and procurement-grade support. The opportunity sits where openness becomes operational, not where it remains ideological.

The test for whether power actually moves

The test is not whether a model is released. The test is whether a capable institution outside the dominant cloud-and-platform orbit can use it, govern it, improve it, and leave its provider without starting over.

That is a higher bar than most open AI arguments use. It forces a move from access to agency. Can a university in Lagos fine-tune a system for local languages without exporting sensitive data? Can a public hospital run AI triage support with auditability it understands? Can a newsroom adapt a model to its editorial standards without handing its archive to a vendor? Can a regulator inspect not only the model card but the deployment chain? The justice problem in Justice-Centered AI Has to Leave the Workshop was exactly this: principles that cannot survive deployment are not yet governance.

Mozilla’s internet analogy is useful only if it stays uncomfortable. The internet did lower barriers for creation. It also taught us that open beginnings can end in concentrated control when convenience, capital, and distribution compound in the same hands. AI is approaching that fork early. Builders, operators, investors, and states should stop asking only who has the best model. The harder question is who can change providers, change defaults, change rules, and still keep working. That is where power will either move, or merely get renamed.