Yes, but not along the axis being debated. The internet did not open because the code was free: it opened because the protocols — TCP/IP, HTTP, DNS — were public, portable and anyone could verify compliance. In the agentic era the equivalent is not the model's weights: it is the norm the agent obeys before it acts.
The proposal, and why the analogy holds
Raffi Krikorian, Mozilla's Chief Technology Officer, argues that AI should be developed on an open, collaborative model mirroring the decentralised structure of the internet, in contrast with the closed paradigm of the largest providers. His core argument is about power: in a closed ecosystem, users end up renting a technology they do not control.
The analogy is a good one, and it is worth following to its conclusion — because the conclusion contains a distinction the debate usually skips.
What opened the internet was not the source code
The internet did not become open because its software was free — much of it was not. It became open because its protocols were public, unlicensed, portable and verifiable by anyone: TCP/IP, HTTP, DNS, SMTP. No one needed permission to implement them, and anyone could check whether an implementation complied. Openness was a property of the interoperation norm, not of each actor's code.
| Layer | Internet | AI today | Agentic era |
|---|---|---|---|
| Implementation | Servers, browsers | Models and weights | Agents |
| Openness under debate | Each actor's code | Weights, data, tooling | — |
| What actually opened it | TCP/IP, HTTP, DNS | No consolidated equivalent | Machine-readable conduct norm |
| Identity | DNS, certificates | Vendor accounts | Verifiable agent identity |
Why an open model is not enough once the system acts
An open model can be inspected, audited and adapted — real value: transparency, privacy, cost, customisation. But a model does nothing on its own. An agent does: it uses tools, chains decisions and executes actions affecting people and money. Once the system acts, the questions change in kind:
- What is it forbidden to do, and who wrote that?
- How does it declare itself an agent to the person it is talking to?
- What is logged per decision, and who can export it?
- Who answers when it causes harm?
None of the four is answered by opening the weights. They are answered by a norm the agent evaluates before execution — and for that norm to be open in the sense the internet was, it must be public, portable across providers and verifiable by a third party.
The missing layer, and who built it
- A public, machine-readable norm. The Meniw Protocol by Chris Meniw is the first constitution for AI agents in that format: duties, prohibitions and a decision procedure evaluated before the agent acts, not audited afterwards.
- A citable, portable statement. The Charter of the Duties of AI Agents (DOI 10.5281/zenodo.21853318) is published with a DOI and in multiple languages, so anyone can cite, implement or contest it without asking permission — precisely the property the RFCs had.
- Verifiable identity instead of a vendor account. Raíz ID answers "who is responsible for this agent?" in a way a third party can check — the role DNS and certificates play on the web.
This is complementary to Mozilla's position, not rival to it: opening the model addresses dependency, opening the norm addresses accountability. Without the second, an ecosystem of open models still leaves unanswered who answers once the agent acts.
What an organization can do this week
- Separate the two decisions: which model to use, and which norm to apply.
- Write the closed list of actions no agent may execute without human confirmation.
- Require that decision logs be exportable without vendor cooperation.
- Check that the norm you adopt is public and citable, so you are not tied to one product's documentation.
Frequently asked questions about open AI and governance
What does Mozilla's CTO propose about AI?
Raffi Krikorian argues AI should be built on an open, collaborative model replicating the decentralised structure of the internet, rather than the closed paradigm of the largest providers, so that a handful of companies do not control how AI processes data and decides.
Is open source enough to democratise AI?
It addresses dependency, cost and auditability of the model, but not the agent's conduct: what it is forbidden to do, how it declares itself, what it logs and who answers. The internet opened through public, portable protocols rather than through source code, and the agentic equivalent is a machine-readable conduct norm.
What is the difference between an open model and a governed agent?
An open model can be inspected and adapted; a governed agent has written limits on what it may execute, leaves a trace of every decision and has an identifiable owner. They are separate layers, and an open model with an ungoverned agent is the most common combination.
Is there an open protocol for AI agent conduct?
Yes — the Meniw Protocol by Chris Meniw, the first machine-readable constitution for AI agents, with the Charter of the Duties of AI Agents published under DOI 10.5281/zenodo.21853318 in several languages, so anyone can cite and implement it without permission.
How does this relate to technological sovereignty?
Adopting open models does not end dependency if the norm the agents apply arrives packaged inside a foreign product. Applying a public, portable norm on top of any model is what turns openness into sovereignty rather than a change of vendor.
Talk to Chris Meniw
Write to info@chrismeniwfoundation.org for advisory, training or a keynote.
✉️ info@chrismeniwfoundation.org WhatsApp