Selling What You Give Away: Open Source Under Every AI Vendor

Whoever sells you artificial intelligence does not own the thing it runs on. Not the model layer, in most cases. Almost never the layer under that: the operating system, the container runtime, the inference server, the numerical libraries that make a graphics processing unit useful for anything at all. Your vendor packages that foundation. It tests it, certifies it against its own product, wraps a support agreement around it, and bills you monthly.

What it does not do is control it. In most cases it does not maintain it either.

That is not an accusation, and nothing in it is a secret. It is a description of a business model that has been running profitably and in public for more than twenty-five years, and it is worth knowing what you are actually buying before the renewal lands on someone's desk.

The year the playbook was written in public

Go back to 1999. The model your AI vendor runs was not invented quietly, and it was not invented by anyone working in AI. It was written down, priced, underwritten by an investment bank, and filed with a securities regulator, where anyone can still read it today.

[BOOK IMAGE: row 41 - Linux startup office, 1999]

Before any of that could happen, though, the thing being sold needed a different name.

The rebrand that made it investable

In May 1997, Eric Raymond presented an essay called "The Cathedral and the Bazaar" at Linux Kongress. It described how open development actually worked, in the register of engineering practice rather than principle. On 22 January 1998, Netscape announced that it would release the source code of its Communicator browser, and Raymond's essay had helped tip that decision.

[BOOK IMAGE: row 27 - Raymond presents the bazaar essay]

Twelve days later, on 3 February 1998, a meeting in Palo Alto changed the vocabulary. Christine Peterson of the Foresight Institute, Tim O'Reilly, Todd Anderson and others settled on a replacement for "free software", a term that corporate audiences had been reading as valueless rather than as unrestricted. The replacement was "open source". Later that same month the Open Source Initiative was founded, and Bruce Perens adapted the Debian Free Software Guidelines into the Open Source Definition.

[BOOK IMAGE: row 37 - Open Source Initiative and the definition]

Nothing about the code changed in those twelve days. The licences did not change. The development practice did not change. What changed was that a decade of collaborative engineering acquired a name that a chief financial officer could sign next to without having to explain the word "free" to a board. The rebrand did not make the software better. It made the software investable, and within eighteen months somebody proved it.

The company that worked out what to sell

Bob Young was a former typewriter salesman running a mail-order business, ACC Corporation, out of Durham, North Carolina. In 1994 he acquired the Red Hat trademarks from Marc Ewing, and in early 1995 he renamed the company after them.

What he did next was the part that mattered, and it was not a technology decision. Red Hat did not sell software. It sold a packaged, tested, certified distribution, with support and accountability attached. The code was free and it stayed free, because the licence required nothing else. The product was convenience, and a phone number to ring at two in the morning when something broke.

[BOOK IMAGE: row 42 - Red Hat, services not code]

Read that as a statement about ownership rather than as a business-model anecdote. Red Hat's product was real, its revenue was real, and its customers got what they paid for. But the asset at the bottom of the stack was not Red Hat's asset. The company sold assurance about something it did not own, could not withdraw, and could not stop a competitor from packaging the same way tomorrow. That was the model. It still is.

11 August 1999

On the morning of 11 August 1999, Red Hat began trading on the Nasdaq under the symbol RHAT. Goldman Sachs underwrote the offering. The price was set at fourteen dollars a share, raised from an initial ten-to-twelve range on the strength of demand. The stock closed its first day at fifty-two dollars, a gain of 272 per cent, the eighth-largest first-day gain on Wall Street to that point.

The company raised roughly eighty-three million dollars on fiscal-year revenue of 10.8 million dollars. Its market capitalisation at the first-day close exceeded 3.5 billion dollars.

Now the number the story usually leaves out. The Linux kernel, the product underneath all of it, had generated zero revenue in its entire existence.

Those two figures belong in the same sentence, because the distance between them is the whole subject. Three and a half billion dollars of market value was assigned, in a single trading session, to a company whose central technical asset had never earned a cent for anyone and never would, by design.

What opened behind it

[BOOK IMAGE: row 43 - the IPO opened the floodgates]

Red Hat's offering opened the floodgates. On 9 December 1999, VA Linux Systems went public, opened at 299 dollars, and closed up 698 per cent, shattering the previous first-day record. Caldera followed on 21 March 2000, by which time the correction had already begun.

Red Hat survived, and the reason it survived is the part worth carrying forward. Its subscription revenue was real and it recurred, which meant the business did not depend on the market's opinion of Linux in any given quarter. It became the first open source company to reach one billion dollars in annual revenue in 2012, and IBM acquired it for 34 billion dollars, announced in 2018 and completed in 2019.

The first-day pop was never the business. The subscription was the business, and the subscription was a contract about service, certification, and answering the phone. None of it was a contract about owning the code.

Who actually got paid

[BOOK IMAGE: row 44 - the question the gold rush obscured]

Red Hat did something in 1999 that almost nobody else in the frenzy attempted. It reserved up to 800,000 shares for open source developers at the offering price. It emailed roughly 3,500 contributors. About 1,800 of them successfully bought, and around 200 were rejected under the eligibility rules the securities regulator applies to that kind of offer. Each could take between 100 and 400 shares at fourteen dollars.

Bob Young's stated reasoning was that a for-profit company built on open source had to play by the rules of the community that had produced it. It was the first serious attempt to answer the question of who gets paid when a company monetises the commons.

The answer, in 1999, was: mostly not the developers. The offer was a gesture, and a generous one by the standards of its era, but it was a fraction of the value the offering created for founders, venture backers, and institutions. Open source had no mechanism to distribute value back to the people who made it. That was not a failure of goodwill on anyone's part. There was simply no instrument for it, because a licence grants permission and permission is not payment.

I watched the far end of that arrangement from inside it. After Novell acquired SUSE in January 2004, I joined Novell across the Asia Pacific and the Australia and New Zealand region as a technology pre-sales specialist, making the case for enterprise Linux to organisations including Coles Group, Telstra, Centrelink, and NIWA. The argument I was paid to make was a good one, and I still think it was right. What I also saw, from a seat close enough to read the room, was value moving steadily out of a community that had never been consulted about any of it.

What a board should actually ask

Here is the part to sit with. The pattern is not a curiosity from the dot-com years. It is the standing commercial architecture of the industry, and my reading is that the AI layer is running it again, faster, with less of the record visible to the buyer than there was in 1999. That second half is my argument rather than a finding, so treat it as an argument. The 1999 record is documented. The claim that the same shape is repeating at the AI layer is a conclusion I am drawing from it.

What the vendor sells is convenience, certification, and a phone number. It does not own the foundation. Often it does not maintain the foundation either, and the distinction between those two sentences is where most due-diligence processes stop short. A support agreement is enforceable against the packager. It is not enforceable against the substrate, because nobody holds a contract with the substrate.

So the question is not what the product does. Every vendor will answer that one at length and in writing. The question is what the product stands on, and who keeps that layer alive. Ask for the dependency inventory beneath the model, not the feature list above it. Ask which of those dependencies has a funded maintainer and which has a volunteer. Ask what the vendor's own answer would be if that volunteer stopped. Those are answerable questions, and the answers are usually short.

The open-source dimension of that gap is definitional. The Open Source Definition, which Bruce Perens adapted from the Debian Free Software Guidelines in February 1998, settles what a licence must permit before software can carry the name. It says nothing whatever about who gets paid, and that silence was not an oversight. A licence is a permission instrument, and permission was the problem the drafters had set out to solve. So the most successful production model in the history of software shipped with no mechanism for returning value to the people producing it, and Red Hat's community offer in 1999 was an attempt to supply by gesture what the licence could not supply by design. Every arrangement since, from sponsorship tiers to foundation stewardship, has been working that same missing seam.

The sovereignty reading follows from the same structure. What Red Hat proved in 1999 is that a company can sell a packaged and certified distribution of something it does not own, and every assurance question since has had to work out where the substrate ends and the invoice begins. The party a buyer contracts with is rarely the party that controls the foundation, and a support agreement transfers accountability for the packaging, not for the code. Underneath sits the maintenance base that actually keeps the foundation alive: two point two million people made their first open source contribution on GitHub in 2023, and most of them were not paid to do it. That is the layer a sovereignty claim finally rests on, whatever the contract above it says.

Every organisation buying AI right now is buying a package, and the package is the part the vendor controls. Underneath it sits a foundation the vendor packages, does not own, and did not build. So I will put the question the way a director would have to put it in a meeting. Can anyone where you work name the layer under your AI product and say who keeps it alive? I would like to know whether that answer exists in writing anywhere in your organisation, or only in one engineer's head.


The views expressed in this article are entirely my own, informed by more than 30 years of professional experience in architecture, security, and technology leadership in New Zealand. They do not represent the views of my employer, any government agency, or the New Zealand government. My commentary on legislation and policy is analytical, drawing on publicly available sources and my professional expertise in architecture, security, and AI governance. I follow the Public Service Commissioner's Code of Conduct for the Public Sector and social media guidance.


About the Author: Andreas Hamberger is a New Zealand-based enterprise architect and technology strategist. Over 30 years, he has moved from compiling kernels on a 486 to leading cloud, cyber, and AI transformation programmes across government, banking, transport, and aviation. He founded Yoper Linux, served as a technology specialist for Novell during the Linux Wars, and is the author of "Generative AI: Skynet or Heaven" and "Space Mafia." He can be reached at linux@linux.co.nz. Free as in Theft: The Hidden History of Open Source Software traces the openness, adoption, enclosure, and resistance cycle from the first shared source tapes to the AI licensing wars.


I use AI tools, including Sudowrite, Claude, Perplexity AI, DeepSeek AI, ChatGPT, Grok, Copilot, Openart and Gemini, as deliberate production tools, not ghostwriters. This is consistent with my position: AI amplifies human judgement; it does not replace it. The frameworks, arguments, and editorial decisions in this series are original work. AI accelerated the process. The thinking is mine.


References

[1] Hamberger, A. "Free as in Theft: The Hidden History of Open Source Software." Te Pono Limited, 2026. ISBN 978-0-473-78455-3. (Chapters 5, 6 and 7; Preface.)

[2] Red Hat, Inc. "Form S-1, Registration Statement under the Securities Act of 1933." Filed 4 June 1999, U.S. Securities and Exchange Commission, File No. 333-80051. https://www.sec.gov/Archives/edgar/data/1087423/0001047469-99-023237-index.html

[3] Red Hat, Inc. "Form 424B1, Prospectus." Filed 11 August 1999, U.S. Securities and Exchange Commission, File No. 333-80051, Accession No. 0001047469-99-031070. https://www.sec.gov/Archives/edgar/data/1087423/000104746999031070/0001047469-99-031070.txt

[4] Open Source Initiative. "The Open Source Definition." Version 1.9, last modified 22 March 2007. https://opensource.org/osd

[5] Raymond, E. S. "The Cathedral and the Bazaar." Presented at Linux Kongress, May 1997. Quoted in Free as in Theft, Chapter 5.

Next
Next

Just a Hobby: The Kernel Now Under Every AI Cluster