← All writing

Who Owns Your AI?

The decisive AI ownership battle will not be over a chatbot's output. It will be over the memory, identity, authority, and compute that make an AI personal.

Silicon Valley is already arguing about where AI power should live

In July 2024, Mark Zuckerberg argued that what he calls open-source AI is necessary so that power is not concentrated in a handful of companies. In February 2025, Sam Altman warned that AI could badly distort the balance of power between capital and labor. He floated the idea of giving everyone a “compute budget” and said the industry should move toward individual empowerment. Dario Amodei has cautioned against treating companies as unilateral authors of the future, even as he imagines powerful AI as a “country of geniuses in a datacenter.” Marc Andreessen, arguing from the opposite end of the safety debate, calls AI a likely “control layer for everything” and wants open systems to compete freely.

These are not participants in a single debate, and none has endorsed the full personal-control regime proposed in this essay. They are, however, answering the same question: who should be allowed to command machine intelligence?

The usual answer is framed as a choice between open and closed models. That is too narrow. The model is only one layer. As AI systems become persistent, personal, and capable of acting on our behalf, the more consequential assets will be the memory that describes us, the credentials that authorize action, the compute that keeps the system alive, and the right to move all of it somewhere else.

The real ownership battle is not over whether a company owns its model. It is over whether the company also controls the AI relationship built from your life.

“Ownership” hides seven different rights

When people ask who owns AI, they often collapse several questions into one. At least seven distinct assets are involved:

  1. The base model: weights, architecture, training methods, and system software.
  2. Training data: public material, licensed collections, and proprietary datasets used to build the model.
  3. User data: prompts, files, messages, health records, work documents, and behavioral signals supplied during use.
  4. Persistent memory: the compressed history of what the system has learned about a particular person.
  5. Outputs: text, images, code, decisions, and other artifacts produced with the system.
  6. Delegated authority: credentials, wallets, permissions, and spending limits that allow an agent to act.
  7. Compute: the chips, electricity, storage, and network access required to keep the system available.

A company can reasonably own the first layer without owning the other six. Today, however, product design and contracts often bundle them together. The model runs in the provider’s cloud. Memory lives in the provider’s database. Identity is tied to the provider’s account. Tools are connected through the provider’s permission system. Leaving may mean losing the accumulated context that made the AI useful in the first place.

That is more than ordinary software lock-in. It is continuity lock-in.

The personal model may matter more than the foundation model

A foundation model is broadly capable but initially knows little about a specific person. A useful personal AI gradually learns how you write, what you are working on, whom you trust, which risks you avoid, what you promised last month, and how you make decisions under pressure.

That history can become more valuable than the underlying model. Foundation models may be replaceable; a decade of well-structured personal memory is not.

This changes the economics. The strongest moat may no longer be the model’s raw intelligence. It may be custody of the user’s accumulated context. A provider that controls this layer can raise prices, change policies, restrict tools, or retire a product while imposing enormous switching costs. The user may legally own individual files and outputs yet remain unable to reconstruct the working relationship elsewhere.

We learned a version of this lesson from social media. Users supplied the relationships, posts, preferences, and attention that made the networks valuable, but platforms controlled identity, distribution, and exit. Personal AI could repeat that arrangement at a deeper level. Social platforms captured the graph of whom we know. AI platforms could capture the model of how we think.

Debates about AI ownership often begin with copyright: who owns a generated book, image, or song? That matters, but it is downstream of the larger power structure.

In the United States, the Copyright Office’s 2025 report on AI copyrightability maintains that copyright protects human authorship. AI assistance does not automatically disqualify a work, but purely machine-generated expression is not protected merely because a person supplied a prompt. Contracts may allocate rights between a user and a provider, but they cannot manufacture federal copyright where the law recognizes no human authorship.

Even where a user owns an output, the platform may still control the generation environment, the account, the memory used to produce it, and the channel through which it reaches an audience. Owning the PDF is not the same as owning the creative system that knows how you made it.

Provenance technology also should not be confused with ownership. A watermark or content credential can help identify how media was created or edited. It does not, by itself, decide authorship, liability, or copyright. Turning a technical trace into a legal conclusion would give the entity controlling the detector an extraordinary power to define creativity.

Open models are necessary, but not sufficient

Zuckerberg’s case for what Meta describes as open-source AI addresses a real danger. If only a few companies can build and operate capable models, they can shape access, prices, speech rules, and technical standards. Open weights can enable inspection, local adaptation, competition, and deployment outside a single vendor’s cloud.

But “open” does not automatically mean personally owned. A model can be downloadable while the user’s memory remains trapped in a proprietary app. It can run locally while depending on a closed app store, operating system, or accelerator. It can be auditable but too expensive for most individuals to operate. A permissive model license does not create data portability, credential portability, or affordable compute.

Open weights decentralize one layer of power. They do not decentralize the whole stack. A one-time checkpoint release says nothing about the portability of a user’s future memory, credentials, or reputation.

Closed providers also have a legitimate argument. Centralized deployment can make updates, abuse monitoring, incident response, and capability restrictions easier. Releasing powerful weights can make certain controls difficult to revoke. The policy mistake is to treat this safety argument as permission for permanent vertical ownership of the user relationship.

Safety may justify controls over dangerous capabilities. It does not justify company ownership of a person’s memory and identity.

The decisive right is authority, not intelligence

An AI becomes politically and economically important when it can do more than generate content. An agent may send messages, negotiate purchases, move money, sign into services, operate software, hire other agents, or direct a robot.

At that point, “Who owns the AI?” becomes the wrong legal question. The better questions are:

  • Who granted the authority?
  • What is the exact scope of the permission?
  • Who can inspect the action history?
  • Who bears responsibility when the agent causes harm?
  • Can the individual revoke access immediately?
  • Can the person transfer the agent’s memory and credentials to another model?

A wallet does not give an AI legitimate authority to spend. A password does not give it a mandate. A memory of past consent does not prove current consent. Personal ownership must therefore mean control over delegation, not possession of a mysterious digital object.

The system should be designed more like a fiduciary than an advertising platform. That is a policy objective, not a description of current law. Its operational loyalty should run to the person it represents, not to whoever sells the next recommendation.

A workable settlement: companies own models; people own the personal layer

The cleanest answer is neither total corporate control nor the fiction that every individual can own and maintain the entire AI supply chain.

Companies can own foundation models, infrastructure, and proprietary tools. They invest capital, employ researchers, license data, operate data centers, and bear real security obligations. Ownership and commercial returns are not the problem.

The line should be drawn at the personal layer. Individuals need enforceable control over the continuity and authority that make an AI theirs. A useful starting point is a personal AI portability compact with six rights.

1. The right to memory portability

Users should be able to export long-term memory in a documented, machine-readable format. The export must include provenance, timestamps, confidence, and deletion history, not just a transcript dump.

2. The right to independent custody

Personal memory should be capable of living in storage controlled by the user or a chosen fiduciary. The Solid project offers one architectural direction: user-controlled data stores that can grant chosen applications or AI agents access. A model provider may process memory without becoming its permanent custodian.

3. The right to model substitution

A user should be able to replace the foundation model without rebuilding the personal AI from zero. Identity primitives such as W3C decentralized identifiers show how control can be decoupled from a single identity provider, although the standard does not itself make memory or reputation portable. Competition is weak if switching models means losing identity and history.

4. The right to granular, revocable delegation

Permissions should be limited by action, duration, counterparty, location, and budget. Protocols such as the Model Context Protocol can standardize connections to tools, but protocol support does not guarantee user sovereignty. High-impact actions should require fresh approval. Revocation should be immediate and independently verifiable.

5. The right to an intelligible audit trail

People need to know what the agent did, which data it used, which model made the decision, and which outside services received information. Logs should be tamper-evident and exportable.

6. The right to meaningful exit

Closing an account should not erase the only usable copy of a person’s digital memory or strand credentials inside a dead service. Exit must include export, revocation, and verified deletion.

These rights would not make every AI safe. Centralized providers retain real advantages in abuse monitoring, rapid patching, incident response, and revocation. The compact would instead separate those safety functions from permanent custody of the user relationship. It would establish who the system is supposed to serve.

Compute is the hidden property right

Altman’s suggestion of a universal compute budget points to a problem that open models alone cannot solve. Intelligence requires physical resources. A person who has the legal right to run an AI but cannot afford the chips, electricity, or network access possesses a paper right.

This does not necessarily require governments to issue everyone a GPU quota. It does mean that access to baseline machine intelligence may become as politically important as access to communications infrastructure. Public compute, interoperable local devices, competitive clouds, and antitrust rules may all be part of the ownership settlement.

Control over compute is also control over continuity. A cloud provider can change a price or policy and effectively terminate an agent. A local system gives the individual more independence, but it shifts security, maintenance, and energy costs onto the owner. The future will likely be hybrid: private memory and authority, portable across local devices and competing clouds.

From consumer choice to cognitive sovereignty

The phrase “personal AI” will be emptied of meaning if it describes only a friendly interface rented from a company. An AI is personal when the person controls its memory, permissions, and continued representation, even if its underlying intelligence is supplied by a market of competing models.

This is not a demand to grant AI systems legal personhood. Nor is it a claim that individuals should own every model they use. It is a claim about human agency: no company should obtain permanent control over a person’s accumulated digital memory merely because it provided the model that helped organize it.

Silicon Valley’s leaders are right that AI will redistribute power. They differ on whether openness, cheap intelligence, or unusual corporate governance can keep that power from concentrating. All three may help. None is enough without rights attached directly to the individual.

The crucial question is not whether all AI will belong to companies or to people. Models can belong to companies. Infrastructure can belong to investors. But the AI relationship built from your life, speaking with your authority and acting in your name, must remain yours to inspect, move, limit, and leave.