Newsletter · · Ashutosh Agarwal

Ben Horowitz Says Building on Anthropic Is Dangerous - Platform Watch - Week of July 31, 2026

Platform Watch for the week of July 31, 2026. a16z's Ben Horowitz warns that building applications on Anthropic is 'dangerous' as the labs move up into the application layer, while cheap Chinese open-weight models take roughly half of all AI usage and hand founders an exit.

Platform Watch

Week of July 31, 2026: Ben Horowitz Says Building on Anthropic Is Dangerous


For a year, the worry that a foundation-model lab would wake up one morning and eat your startup was mostly whispered at dinners and hedged in board decks. This week one of the most powerful investors in Silicon Valley said it into a microphone, by name: building on Anthropic is "already fairly dangerous," because "every time an application category starts to do well, they move into that category," and then charge you full price while subsidizing their own copy. In the same seven days, the escape hatch got a lot wider: cheap Chinese open-weight models quietly took roughly half of all AI usage, and the founders who used to spend six and seven figures a month renting intelligence from the labs started walking out the door. This is the week the platform fight stopped being a theory.


This Week's Platform Move: A Top VC Names the Lab-Cannibalization Playbook, and Open Source Becomes the Founder's Exit

If you build a product on top of a big AI model from OpenAI, Anthropic, or Google, here is the single thing to take from this week. The risk that these labs compete directly with their own customers is no longer a nervous hypothetical whispered among founders. It is now being described bluntly, on the record, by the people who fund the ecosystem, and in the same breath, those same people are pointing founders toward the way out.

The clearest statement came from Ben Horowitz, co-founder of the venture firm a16z, on his own show. Asked what an application company should safely build on, he did not hedge:

"It's been already fairly dangerous to build on Anthropic because they, every time an application category starts to do well, they move into that category. And then… we've seen them do like very aggressive things where, you know, the price for the application provider is full price and then they subsidize their version of the application."

His historical analogy is worth sitting with, because it tells you how far along he thinks this is. Horowitz argues Anthropic has "fast-forwarded… the Microsoft playbook from the old days," but skipped a step: "skipping the platform generation and just going straight to the monopoly generation." In plain terms, a healthy platform makes money by helping the companies built on top of it succeed; a monopoly makes money by becoming those companies. His question for any founder is the one every reader of this newsletter should ask this weekend: "How can I safely build on a proprietary model if that company is going to come attack me and then charge me much more than they're charging themselves to do the same thing?" He even extended it to robotics: "If you were to build your robot on Anthropic, then at some point… Anthropic's going to go into the robot business. And put you out of business just by either cutting you off or overcharging you." Horowitz was careful to say he isn't even angry about it, "that's their business approach," but the consequence, "if they're able to ban their competitors, is not good" (The a16z Show, "Ben Horowitz: The Fight Over Open Source AI," July 26, 2026).

That is not one grumpy investor. On All-In, Jason Calacanis said the same thing from the customer's chair, and named names: "if you are… Lovable, which I talk to, and they're paying a ton of money, or you're ElevenLabs and you're paying them a ton of money and they say, hey, we got our latest and greatest, you can't use it because we're going to compete with your company, they would stop using it and they go to open source." His claim about what's already happening: startups "that were spending hundreds of thousands of dollars with them every quarter, just [as of] 6 months ago, they have all moved en masse [to open models like] GLM-5.2, making their own models. The cat's out of the bag" (All-In, "The Fight Over Open Source AI, Anthropic's $1.5B Payout, NYC Socialists: Evictions = Violence?," July 24, 2026).

And here's the twist that makes this a genuine turning point rather than just louder complaining: even the labs' defenders now agree the labs should go up the stack and compete with you. On the same All-In episode, David Sacks, usually the most bullish voice on the frontier labs, made the argument for Anthropic and OpenAI moving into applications: "The best answer… is they're gonna go up the stack to the application layer. Well, they already have… These end-user apps are really good. And they should just own that." He even coached them on the pricing move founders fear most: "There may be a version of a model that I don't release and just keep for myself, and I'll just use in my own applications." When the bull case and the bear case agree that the labs will eat the application layer, the debate is over. The only open question is which applications survive it.

The Mechanism, Made Concrete: The Models Are Absorbing the Work Startups Used to Do

The scary version of platform risk isn't just "a lab might launch a competitor." It's that each new model release quietly swallows an entire category of engineering that a startup used to sell. This week's model gave the cleanest example yet.

Anthropic shipped Claude Opus 5, a near-frontier model priced at $5 per million input tokens and $25 per million output tokens (a "token" is roughly a word-fragment; you pay by how many go in and come out; a million tokens is about 750,000 words). Crucially, that's the exact same price as the prior Opus 4.8, and it's now the default on Claude's paid consumer plans. As one show explained, that flat pricing removes the usual friction: "The engineering team doesn't even have to ask for more money. They just go into the code and swap the model string from Opus 4.8 to Opus 5," and "their capabilities expand overnight without writing a single new contract" (Elon Musk Podcast, "Claude Opus 5 delivers affordable frontier intelligence," July 26, 2026).

What that extra capability does to startups is the point. The same episode walked through a project by Instagram co-founder Mike Krieger: he handed Opus 5 a binary save file from a 1994 game and a four-sentence prompt, and the model ran on its own for an eight-hour session, wrote 70,000 lines of code, and built a working 3D browser viewer that loads a 4.2-million-tile world in under six seconds at 60 frames per second, even adding a day-night lighting cycle nobody asked for. Then the part founders should underline:

"A year ago, a project of this size required really complex scaffolding… you had to build a system of agents. A builder agent writing the code, and a separate critic agent checking the builder's work… The software company's value was literally in building that communication layer between the agents. But now, Opus 5 simply verifies its own work… And if a startup's entire product value lives in the scaffolding they built around an API to manage those junior agents, that value is evaporating. Because the models are absorbing those functions natively."

A second example on the same show: Christian Rivera at Stripe gave Opus 5 a "chief of staff" role over his development environments for an entire weekend, unsupervised, and it built its own monitoring scripts and only pulled humans in for judgment calls like deleting a database table. The lesson for a founder isn't "AI is impressive." It's that a whole class of "agent orchestration" and "AI reliability" startups just watched their core feature ship for free inside a $5-per-million model (Elon Musk Podcast, "Claude Opus 5 delivers affordable frontier intelligence," July 26, 2026). The creator of Claude Code made the flip-side point on YC's podcast: there is still a lot of "product overhang" (room to build on top), but he's describing headroom above the model, not the scaffolding just around it (Y Combinator Startup Podcast, "Boris Cherny: Building Claude Code," July 28, 2026).

The Counterweight: Open Source Quietly Ate Half the Market, and It's the Founder's Leverage

Here's why this was a turning-point week and not just a scary one. The same forces squeezing founders from above are handing them a genuine escape hatch from below, and the numbers behind it are striking.

According to a detailed breakdown, twelve months ago US frontier models (ChatGPT, Claude) carried about 70% of all AI traffic. As of the week measured, Chinese open-weight models were processing more tokens than the US labs, as tracked by OpenRouter, the largest neutral routing service. DeepSeek alone drove 16.3% of token volume, more than Google's Gemini, Anthropic, or OpenAI individually. Together, Chinese providers (DeepSeek, Z.ai, Moonshot, Minimax, Tencent) accounted for 45% to 61% of top-tier model traffic depending on the week. At the end of 2024, Chinese models were 2% (AI to ROI, "Chinese Open Weight Models Overtake US Frontier AI: What Every Enterprise Executive Needs to Know," July 30, 2026).

The reason is price, and the gap is not incremental, it's a different category:

  • DeepSeek made a 75% price cut permanent in May on its V4 Pro model, taking it to roughly a third of a cent per million tokens. For comparison, the hosts pegged GPT-5 at $2.50 per million tokens. As one put it: "That's not a discount. That's like a whole different category."
  • MiniMax's coding model performs similarly to a GPT-5.5-class model at "5% to 10% of the cost."
  • The switching is already happening at name-brand scale: Coinbase publicly said it migrated to Z.ai's 5.2 and Moonshot's Kimi 2.7 models and cut its AI spending in half even as usage climbed. Uber, Microsoft, and Walmart are imposing hard usage limits and governance on frontier-model spend, not as an experiment but as permanent policy. Microsoft is even weighing offering a version of DeepSeek on Azure inside its own security wrapper (AI to ROI, July 30, 2026).

And this isn't just enterprises, it's startups specifically. The same episode noted a16z's own estimate that 80% of its portfolio companies are already using open-weight models in their AI products. Even the coding tools are doing it: Cursor shipped a version of its flagship built on Moonshot's Kimi to offer a low-cost alternative to running on Anthropic or OpenAI (AI to ROI, July 30, 2026; corroborated on Super Data Science, "1012: The Open-Weight 2.8-Trillion Parameter Competing at the Frontier," July 24, 2026, which noted Kimi is embedded in Cursor's Composer and that DoorDash routes work to Kimi K2.6).

That's the whole Platform Watch thesis crystallized in one week. The labs are moving up into your product, and the open-weight flood is the reason you no longer have to sit still and take it. As Ben Horowitz framed the strategic logic: open source is "a way that the ecosystem gets built," a hedge against "a monopoly model where there's one company that owns all the applications and all the robots and all of everything" (The a16z Show, July 26, 2026).

One important caveat to keep your head level. Not everyone thinks the labs are actually in trouble, and the skeptics have a point. On All-In, Sacks argued the "China caught up" panic was overdone, citing analyst Ben Thompson's cost work suggesting Kimi K3 "is not that much cheaper to run," and noting the US labs' revenue is still exploding: OpenAI's run-rate revenue rose from about $33 billion in May to $41.3 billion in July and is now guided toward roughly $75 billion exit run-rate, while Anthropic went from about $10 billion at the start of the year to over $70 billion by mid-year, chasing an internal target of $100 billion. His read on the labs' sudden lobbying for government protection against open source: it's a "flop," drawing a foul while they're in the middle of IPO roadshows (All-In, July 24, 2026). Chamath Palihapitiya's synthesis is the one worth taping to your monitor: it's not that 95% of tasks need the frontier model, it's that "95% of the tasks can be done by many different models." That's not doom; it's commoditization. And commoditization is exactly what shifts value away from the model and toward whatever you build around it.


Exposed vs. Defensible (as called out this week)

Exposed

  • "Scaffolding" and agent-orchestration startups. If your product is the reliability layer, the multi-agent manager, or the glue that makes a raw model usable, this week's model release is your warning shot. Opus 5 "self-verifies" work that a year ago required a builder-plus-critic agent system, "if a startup's entire product value lives in the scaffolding they built around an API… that value is evaporating" (Elon Musk Podcast, "Claude Opus 5 delivers affordable frontier intelligence," July 26, 2026).
  • AI companies whose entire business is reselling tokens. The sharpest version of this call landed on Anthropic itself. By public estimates cited on Everyday AI, roughly 80% of Anthropic's revenue comes from just selling tokens, versus about 20% for OpenAI and low single digits for Google, Microsoft, Amazon, and Meta, which have broad ecosystems. The host's blunt verdict: "Anthropic built this massive business. And if I'm being honest, there's not a big moat… their entire business is inference. And inference is just a commodity that's getting cheaper." He noted some open models produce output "roughly 10 times cheaper than Opus," and that on OpenRouter's usage tracker Anthropic had fallen from dominant to around seventh. If it's true of the lab, it's doubly true of anyone one layer up whose only asset is convenient access to that lab (Everyday AI, "Ep 828: Anthropic Responds: Why Claude's CEO didn't sign the open model pact and the real reasons why," July 28, 2026).
  • Named application companies paying the labs a fortune. Lovable and ElevenLabs were both cited by name as customers paying "a ton of money" who would bolt to open source the moment a lab competes with them, and startups spending "hundreds of thousands of dollars… every quarter" reportedly already have (All-In, "The Fight Over Open Source AI, Anthropic's $1.5B Payout…," July 24, 2026).
  • Coding tools with weak pricing power. The Claude Code vs. Codex vs. Cursor fight produced hard data this week. Per usage numbers from routing startup Weave, when Anthropic's shift to usage-based pricing raised the cost per user of Claude Code, customers kept increasing usage anyway, but when Cursor's cost per user climbed, usage fell 17%. That's the tell: Claude Code has pricing power, Cursor has leakage. The reporting also noted enterprises are switching away from Cursor toward Claude Code and Codex, and that Cursor is being folded into the SpaceX AI family, meaning "enterprise buyers now have to evaluate software" tied to an aerospace company's ambitions (The Information's TITV, "Trump Admin Nears AI Rules Framework, Microsoft's Mythos Alternative, Why Claude Code is King," July 28, 2026).
  • Software valued only on the current model's limits. BlackRock's Helen Jewell described how the market is pricing much of software as if "the terminal value of these companies is going to be zero and zero quite soon." She thinks that's wrong for a subset, but it's the default the market is applying to anyone who can't prove otherwise (Making Sense, "Momentum vs. fundamentals in the AI trade: Insights from BlackRock," July 28, 2026).

Defensible

  • Proprietary data your customer generates that no one else can touch. The cleanest example this week was Encore AI, which raised $30 million to build voice agents trained on each client's own closed sales calls. The moat is data isolation: "if they go to Chase Bank… we're going to use your transcripts… and they can just keep that data with just Chase Bank, and they're not… giving it to Bank of America," each bank gets the benefit of its own best salespeople without leakage, something a centralized incumbent like Salesforce doesn't offer out of the box (AI Chat, "Microsoft Bug Hunting AI Outpaces Engineers," July 29, 2026).
  • Structured datasets built up over years. BlackRock's Jewell named the two software categories she thinks the market is wrongly writing off: those with "valuable datasets" and those with "a really, really useful use case for the end consumer." Her point on data: "data that has been collated in a structured way over a very, very long period of time is very difficult to replicate quickly," even a model that can do the task can't conjure the history (Making Sense, "Momentum vs. fundamentals in the AI trade," July 28, 2026). The same logic underlies the classic "We Have No Moat" argument revisited this week: with model quality commoditizing, the durable moats are "proprietary data, distribution networks, workflow integration, and speed of iteration" (A Beginner's Guide to AI, "Google's 'We Have No Moat' Memo - Or Do They?," July 24, 2026).
  • Owning "the harness," not the model. In coding, the durable layer is shifting from the model to the software that wraps and directs it. As The Information put it, companies increasingly adopt open-source harnesses (KiloCode, OpenCode, Cline) that let them swap models freely, and "the harness becomes a lot more important than the actual model for coding work." If you own the layer customers live in every day and can point it at whichever model is cheapest or best, you're insulated from any single lab's price hikes (The Information's TITV, "…Why Claude Code is King," July 28, 2026).
  • Regulated verticals with compliance built in. Encore's edge isn't only data, it plugs into the call-recording and compliance infrastructure financial institutions already run, so adopting it doesn't force a renegotiation of how sensitive data is handled (AI Chat, "Microsoft Bug Hunting AI Outpaces Engineers," July 29, 2026).
  • The physical world and specialized domains the labs won't fully own. Frontier lab WorldLabs (Fei-Fei Li's two-year-old "spatial intelligence" company) acquired robotics startup SceniX this week to build a "real-to-sim-to-real" pipeline for training robots, a reminder that the hardest, most physical problems still command acquisition premiums rather than getting absorbed by a text model (The a16z Show, "Fei-Fei Li on Spatial Intelligence and Robotics," July 28, 2026).

Founder Takeaway

The platform question got sharper and more honest this week. It's no longer "might a lab someday compete with me?" It's that the ecosystem's own kingmakers, including the ones usually cheering the labs on, now openly expect the labs to move up into the application layer, and openly point founders toward open source as the counter-move. Both halves of that are actionable.

  1. Assume the lab will build your feature, and ask what's left when it does. Run Ben Horowitz's test on your own product this weekend: if the model you build on "moves into your category and charges you full price while subsidizing its own version," what do you still have that they don't? If the honest answer is "a clever wrapper" or "agent scaffolding," this week showed that layer getting absorbed into a $5-per-million model. Build above the model or beside it, not in the thin band right around it.

  2. Own data or a customer relationship the labs physically cannot reach. Encore's isolated per-client call data, BlackRock's "structured datasets built over years," a regulated vertical's compliance plumbing, these survive a price war because a model can't manufacture them. A prompt cannot. If your only asset is skill at calling someone else's API, that skill is being commoditized in real time.

  3. Turn open source from a threat into your leverage, deliberately. The most important number this week is that Chinese open-weight models quietly took roughly half of all AI usage, and names like Coinbase cut their AI bill in half by switching. You don't have to wait to be squeezed. Route the ~95% of tasks that don't need the frontier model to cheap or open models now, keep your architecture model-agnostic (own the harness), and make sure that if a lab raises prices (or competes with you) you can swap the engine without rebuilding the car. As Jason Calacanis put it, the startups that already did this "moved en masse."

  4. Don't over-read the doom, but respect the direction. The labs are still growing at a pace no software company ever has ($33B to $41B run-rate for OpenAI in two months; $10B to $70B+ for Anthropic in half a year), and the "China caught up" panic is partly an IPO-roadshow performance. But the underlying current, models commoditizing, value migrating to data, distribution, workflow, and the harness, is real and it's accelerating. Build for the world where the model is cheap, abundant, and interchangeable, because that's the world this week's numbers say we're already in.

The labs told you what they're building this week, not just tools for you to build with, but the applications themselves. And the open-source flood told you what you can do about it. The founders who win from here won't be the ones renting intelligence most cleverly. They'll be the ones who own the data, the customer, and the switch.