Below the model line, the stack is closing
Start at the bottom. NVIDIA's advantage, as TechCrunch put it last week, is moving beyond the GPU. The new Vera Rubin architecture pairs the GPU with a dedicated orchestration CPU, inference acceleration, and its own storage and networking racks — an integrated system where, in the words of NVIDIA's own storage VP, data orchestration alone delivers "upwards of 3x improvement." The line that sums up the strategy: "If the GPU is the engine, these are the rest of the car." Competitors spent three years trying to match the chip. The moat quietly moved to the whole vehicle.
One layer up, the compute-rental business built on that hardware is booming precisely because nobody can build it themselves. CoreWeave posted $2.58 billion in quarterly revenue, up roughly 110%, with a backlog over $100 billion; Nebius grew 454% year over year. Above that, the gigafactories — nation-scale compute programs measured in gigawatts and public billions.
Here's the uncomfortable arithmetic under all of it: no enterprise will ever own any of this. Not the silicon, not the rack, not the orchestration layer, not the gigawatt datacenter. These layers are closing — consolidating into a handful of vertically integrated vendors — and every quarter the integration gets deeper, because that's what a moat is. Renting them isn't a compromise. It's the only option, the way you rent the power grid.
That would be a bleak map, if it were the whole map.
Above the model line, the stack is opening
Now look at the layer where the model itself lives, and the direction reverses completely.
Open-weight models closed the capability gap with proprietary frontiers — at a fraction of the compute it cost to open that gap in the first place. Parameter-efficient methods made tuning them cheap enough that industry commentators are calling 2026 the year of fine-tuned small models. The most-funded new AI lab in history shipped, as its very first product, an API for fine-tuning open-weight models. And the behavioral evidence is in: McKinsey's new State of AI survey found that 32% of organizations skipped a software purchase entirely and built the capability in-house with agentic coding tools — a number Retool independently corroborates at 35% of enterprises replacing SaaS with custom software.
The pattern behind that number is older than AI: build-vs-buy flips wherever building gets cheap. It just flipped for software. Model-building — open weights, cheap tuning, federated training when the data can't pool — got cheap on exactly the same curve. The flip is coming for the model layer, and for a third of the market it has evidently already arrived.
The only layer you can own
Draw the stack, then, from bottom to top: silicon — closed. Integrated systems and orchestration — closed. Rented compute — booming, and rented by definition. The application layer at the top — already yours; it always was. And between them, one layer where the door is open: the model layer. Weights, training data, build pipeline, build record.
This is also — not coincidentally — the layer where enterprise value actually concentrates. A model fine-tuned on your claims history, your patient pathways, your fraud patterns is your institutional knowledge distilled into behavior. It is the single most valuable artifact your AI effort will produce. And it is the only artifact in the whole stack whose ownership is genuinely available to you.
Which reframes the rent-vs-own question. Renting the closed layers is rational — there is no alternative, and the vendors renting them to you are very good at their jobs. Renting the open layer is a choice. And it's a choice with a track record now: rented model capability has been repriced, deprecated, and redirected on vendors' schedules, not their customers'. When a layer is closed, dependency is the cost of participation. When a layer is open, dependency is voluntary.
Rent the layers that are closed. Own the one that's open.
What owning it properly means
Owning the model layer is not downloading a checkpoint. A checkpoint you can't rebuild, can't account for, and can't legally stand behind is a rented posture with extra storage costs. Ownership, done properly, is three things — the same three we keep returning to, because they keep being the answer:
Own the weights. Not access to weights — the ability to rebuild the model without anyone's permission: the base pinned by hash, the data, the training configuration, the pipeline. If the rebuild path runs through a vendor, the vendor owns the model and you own an invoice.
Own the build record. Every model you build or fine-tune is a fork with a history — what data went in, what training ran, what was checked, in what order. Written down, signed, and verifiable by someone who doesn't trust you, that history is model-build lineage: the deed that makes ownership provable rather than asserted. It's what your auditor, your regulator, and your acquirer will ask for — and it's the difference between answering with a document and answering with archaeology.
Own the exit. The test of every dependency above the model line: could you walk away and keep working? No license that expires into a brick, no inference quietly routed through someone else's cloud, and — when a data partner leaves — verifiable unlearning, so the exit works in both directions.
How CID does it
CID is built to make model-layer ownership operational rather than aspirational. Models are built and trained in your environment — on-premises, air-gapped, or sovereign cloud — on whatever compute you rent from the closed layers below; ownership of the model layer doesn't require owning the metal under it. Every stage of the build runs through a pipeline with quality gates that fail closed, and every stage is signed into a tamper-evident record: base model in by hash, data gated before it trains, evaluations before anything ships. The finished model deploys through the same pipeline that produced the evidence — so the model serving traffic is provably the model the record describes, and the whole chain is verifiable by an outside auditor without trusting our dashboard or yours.
Why this matters now
The closed layers will keep closing — deeper integration is the entire strategy, and it's working. The open layer, meanwhile, is open now: the weights are available, the tooling is cheap, and a third of the market has already switched its default from buy to build. Layers don't stay open forever; they consolidate, the way every infrastructure layer eventually has. The window to establish real ownership — weights, records, exits — is while the door is open.
You will never own the engine, and you will never own the rest of the car. That was never the prize. The model is.
Rent the layers that are closed. Own the one that's open.