The Open Stack Is Missing Its Identity Layer

The Open Stack Is Missing Its Identity Layer

Rene Reinsberg, CEO

Rene Reinsberg, CEO

Published

Mozilla just published its first State of Open Source AI report, and it is a great assessment of where this ecosystem actually stands. Open models have closed the capability gap; they now route the majority of tokens on OpenRouter, and inference costs have collapsed fiftyfold in three years. The question is no longer whether open models are good enough.

But the report's real contribution is naming where the fight has moved. It has moved above the weights, to what Mozilla calls the agentic harness: the layer of orchestration, tools, permissions, and memory that sits between a model and the world. And in that layer, three problems stand out. All three are problems we have been working on at Self, which is why I want to walk through them.

  1. Memory is where lock-in lives

The report documents something subtle and important: harnesses tuned to one lab's weights quietly degrade on everyone else's. Lock-in arrives as a side effect of optimization, not as a decision anyone makes. Your agent's memory, your context, and your accumulated history with a model become the thing that keeps you from leaving.

It does not have to work that way. Shared memory can live outside any single provider, in trusted execution environments, or TEEs: encrypted in hardware, verifiable through attestation, portable by design. You switch models, and your memory comes with you. The TEE guarantees that no lab can read it and no cloud operator can read it, and you can cryptographically verify both claims instead of taking someone's word for it. My co-founder Remi wrote about this recently, and the principle carries over directly: Don't Trust, Attest.

  1. Permissions need a root

Mozilla calls the write surface the single highest leverage gap in the stack: there is no portable standard for what an agent may do unattended, what needs approval, and what is forbidden. The report puts it well. Knowing who an agent is says nothing about what it may do.

This is true, but flip it around. What an agent may do means nothing if you cannot prove who it acts for. Every permission chain has to terminate in a person, and today that terminus is a leaked API key or a session cookie. A privacy-preserving proof of personhood, one human, one identity, no documents disclosed, is the root of the permission stack that is missing. There must be authentication before authorization. We built Self for exactly this.

  1. Evals run on humans, and the humans are leaking

The report lists evaluation as one of the top reasons teams churn off open models. I believe the situation is worse than that. The humans producing ground truth labels and safety assessments are increasingly not humans at all. The eval supply chain is being polluted by the same synthetic identity attacks the industry spends billions to defeat everywhere else, which I wrote about last month.

Verified human attestation is not a nice-to-have for evals. It is the load-bearing wall.

Sovereignty runs on identity

If you zoom out, you can see that the report's sovereignty chapter tells the same story I told after the Fable 5 export controls. Access to the most powerful model on earth was sorted by passport, in a single directive, with no other capital consulted. Sovereign AI is no longer a forecast; it's a policy.

Every sovereign deployment will need to answer the same question: who gets access, and how do you check without building a surveillance apparatus to do it?

Zero-knowledge identity is how you gate access to citizenship or personhood while learning nothing else about the person. Once compute becomes something governments allocate, Universal Basic Compute (UBC) stops being a thought experiment. You cannot distribute compute to everyone without privately knowing that each recipient is a real and unique person.

Mozilla ends the report with a warning that the window for open is closing slowly enough that we can pretend it isn't. I read the same data with more optimism. The gaps they found are not mysteries. They are an unbuilt identity and trust layer, and it is being built now: with open weights, self-owned identity, memory in TEEs, and attested compute.

That is the stack where a builder in Nairobi gets the same shot as one in San Francisco, and it is the one worth fighting for.

Rene Reinsberg, CEO

Rene Reinsberg, CEO

Published

Stay updated

Join us on the road to privacy-first identity.

Identity infrastructure for the digital world.

As society moves toward digital-first infrastructure, people need secure, privacy-preserving credentials to represent every part of their identity online.

Verify your digital identity seamlessly and securely. Prove who you are – onchain or offchain. Prove where you’re from. All without sharing any private information with any third parties.