Photo by Rahul Mishra on Unsplash
The Common Belief
10^26. That's the number of floating-point operations a model has to burn through training before the U.S. government considers it a "dual-use foundation model" under Biden's Executive Order 14110, signed October 30, 2023. As of July 19, 2026, that threshold hasn't moved — even as the frontier of AI training has blown past it. According to Politico's reporting on the terminology fight consuming Washington and Brussels, the most consequential words in AI policy right now aren't about safety or bias. They're dictionary words: "open source," "foundation model," "frontier model," "general-purpose AI." The common belief, reinforced by years of marketing, is that these terms are roughly interchangeable — that when Meta calls Llama "open source" or the EU regulates "general-purpose AI models," everyone's talking about the same thing. They aren't, and the gap between the labels and the legal text is where the real regulatory fight is happening.
Where It Breaks Down — What the Numbers Actually Say
Start with "open source." The Open Source Initiative spent nearly two years building consensus before releasing its official Open Source AI Definition (OSAID 1.0) in October 2024. The bar it sets is strict: a model only qualifies if its training data, source code, and model weights are all genuinely accessible. By that standard, Meta's Llama and Google's Gemma — both widely described as "open" — don't clear the fence, since neither company publishes the full training datasets behind them. That's not a footnote; it's the core of the dispute. If "open source AI" legally requires OSI's full transparency stack, a huge share of what the industry currently markets as open models would need reclassifying, with real consequences for how they're regulated and who's allowed to build on them.
Now layer on the numbers game. The EU AI Act, under Article 3, doesn't use "foundation model" at all — it defines "general-purpose AI" (GPAI) and flags a subset as carrying "systemic risk" once a model crosses 10^25 FLOPs in training compute. The Biden executive order, writing in a different vocabulary entirely, set its "dual-use foundation model" threshold at 10^26 FLOPs — a full order of magnitude higher. Two governments, two different terms, two different numbers, both trying to describe roughly the same technology.
Chart: The EU's systemic-risk threshold (10^25 FLOPs) versus the U.S. dual-use foundation model threshold (10^26 FLOPs) — a full order of magnitude apart, using entirely different legal vocabulary.
The divergence doesn't stop there. NIST released its AI Risk Management Framework in January 2023, trying to standardize risk terminology before the EU or the White House had finalized theirs. California's SB 1047 took yet another approach, defining "covered models" by dollar cost — a $100M-plus training-run threshold — rather than compute; Governor Newsom vetoed it in September 2024, but not before the definitional fight over what counts as a "covered model" had already split the state's tech industry. Three governments, three different units of measurement — FLOPs, dollars, and access criteria — all trying to regulate the same underlying wave of models.
The Trajectory — Where the Fight Goes in the Next 6 to 18 Months
Fixed numeric thresholds age badly in a field where compute economics shift every few quarters. A 10^26 FLOPs bar that looked aggressive in October 2023 already reads as almost quaint by mid-2026, as training runs for the next generation of frontier systems approach it as a matter of routine rather than an outlier event. Expect two things to happen over the next year and a half: first, both the U.S. AI Safety Institute and its UK counterpart — both stood up in 2023–2024 — will keep pushing to translate hard FLOPs cutoffs into capability-based tests instead, since a fixed compute number stops meaningfully separating "powerful" from "ordinary" models once compute keeps getting cheaper. Second, the OSI's strict definition will keep colliding with industry practice; the moat compresses when a definition tightens, so watch for Meta and Google to either quietly adjust how they label Llama and Gemma or lobby regulators toward a looser standard that preserves the marketing value of the word "open" without the transparency obligations OSI actually demands.
Who Gains Leverage, Who Gets Exposed
If OSI's strict definition becomes the regulatory default, the second-order effect favors genuinely open efforts — projects that publish full datasets, weights, and code — while stripping the "open" halo from Big Tech's more curated releases. That's a real threat to how Meta and Google currently position Llama and Gemma in the market, and a potential opening for smaller labs and academic groups that can credibly claim the label. Conversely, if regulators settle on loose, marketing-friendly definitions, the incumbents keep the reputational benefit of "open" without the compliance burden, while genuinely transparent smaller players get no differentiation credit at all. On the compute-threshold side, the exposure runs the other way: any lab whose training runs cross 10^25 or 10^26 FLOPs — currently a short list dominated by OpenAI, Anthropic, Google DeepMind, and Meta's largest runs — inherits reporting and safety-testing obligations that smaller, resource-constrained developers simply never trigger. For investors tracking this space, the practical implication is that regulatory exposure isn't evenly distributed across an investment portfolio of AI-adjacent stocks; a company's compliance risk depends heavily on which side of these specific numeric lines its models fall on, not on its overall AI narrative.
A Better Frame
The more useful question isn't "is this open source AI?" as a marketing checkbox — it's "which of the three OSI criteria (data, code, weights) does this model actually satisfy, and under which jurisdiction's compute threshold does it fall?" Anyone using AI investing tools to screen for regulatory risk in AI-exposed equities should be treating FLOPs thresholds and OSI compliance status as concrete, checkable data points — not vibes. Policymakers, for their part, would be better served harmonizing units (FLOPs versus dollars versus access criteria) across the EU, US, and state-level frameworks before the definitional patchwork hardens into permanent transatlantic incompatibility.
Frequently Asked Questions
What is the actual difference between open source AI and proprietary AI?
Under the Open Source Initiative's October 2024 definition, a model only qualifies as "open source AI" if its training data, source code, and model weights are all accessible. Proprietary AI keeps at least one of those elements closed. Many models marketed as "open," including Llama and Gemma, release weights but not full training data, which is why they fall short of OSI's strict standard.
How does the EU AI Act define general-purpose AI and systemic risk?
The EU AI Act's Article 3 defines "general-purpose AI" (GPAI) models and designates a subset as carrying "systemic risk" once training compute crosses 10^25 FLOPs — a different term and a different, lower threshold than the U.S. executive order's 10^26 FLOPs dual-use foundation model bar.
What is the Open Source Initiative's definition of open source AI, and why does it matter?
OSI's Open Source AI Definition (version 1.0, released October 2024) requires full access to training data, code, and weights. It matters because it sets a bar stricter than how many major tech companies currently use the term "open source," creating a direct conflict over labeling and, potentially, future regulatory treatment.
Bottom Line
On balance, the definitional fight described by Politico is less a semantic squabble than the actual battleground where AI regulation gets decided — the words chosen in EU Article 3, in Executive Order 14110, and in OSI's 1.0 definition function as the load-bearing walls of the entire policy structure. Our analysis suggests the next 18 months will be defined less by new legislation and more by regulators quietly retrofitting these existing terms as compute costs fall and the current thresholds stop meaningfully distinguishing frontier systems from ordinary ones. For anyone building a financial planning approach around AI-exposed holdings, the terminology isn't background noise — it's the mechanism that decides which companies face compliance costs and which don't.
Disclaimer: This article is for informational purposes only and does not constitute financial advice. Research based on publicly available sources current as of July 19, 2026.