Frontier AI has a patent cliff problem. It just doesn’t have the patent.
Early in my career I was a McKinsey consultant serving pharmaceutical companies, and many projects sat in the shadow of the patent cliff: the scheduled day a blockbuster loses exclusivity and billions in annual revenue begin to disappear. The frontier labs remind me of that industry. Both are capital intensive and innovation driven, and both sell a product that depreciates, so revenue has to be renewed by the next molecule or the next model. Nobody in biopharma confuses the drug with the business. The drug is a wasting asset. The business is the machine that replaces it.
The biggest difference between the two industries is protection. For a drug, erosion begins when the patent ends. For a model, erosion begins when it launches.
That difference is why the AI safety debate has become about more than safety. The concerns are real, and some are getting more serious. But rules about who may build, copy, test, release, or deploy frontier AI also determine the conditions under which competitors enter and customers choose among them.
The negotiation isn’t literally over patents. It is over some of the economic functions patents perform: how long an expensive discovery remains scarce, what outsiders can verify, and how alternatives reach the market.
The copy is built from the original
The economics of copying are remarkably similar. In both industries the product is the raw material of its own replacement.
A generic manufacturer today does not have to repeat the innovator’s efficacy trials. It has to demonstrate that its own product satisfies the requirements for an abbreviated approval pathway. The follower still has work to do, but the first entrant has already paid to establish much of what the market needs to know.
Distillation has a related economic effect. A developer can use the outputs of an expensive model to help train a cheaper one. The second system is not a literal copy and benchmark equivalence is not regulatory equivalence, but the economic asymmetry is similar: the follower can benefit from capability the first developer spent vastly more to create.

Some open-weight models therefore behave economically more like biosimilars than traditional generics: not replicas, but sufficiently good substitutes on enough tasks to put pressure on the premium.
In both industries the copies also reset the bar. Once a generic is widely adopted it becomes the standard of care, and a new drug has to show incremental benefit over a cheap, established therapy or payers won’t cover the premium. Once an open model handles a task acceptably at a fraction of the cost, it becomes the “standard of care” for that task, and the frontier can only charge for the increment above it. That’s why enterprises that spent last year buying tokens as fast as they could are now auditing every dollar they can’t tie to a result. They are doing what payers do. Models keep getting better and harder to mark up at the same time.
What pharma actually has
Biopharma has spent decades operating under an explicit institutional bargain between innovation and imitation.
Before Hatch-Waxman, generic applicants could not simply rely on FDA’s prior determination that the branded drug was safe and effective. They generally needed a full application package, often including their own clinical evidence. That requirement grew out of a 1962 law, passed after the thalidomide tragedy, that made drugmakers prove their products work, not just that they are safe. When the law changed in 1984, generics represented only 19 percent of U.S. prescription drug purchases.
The Hatch-Waxman Act of 1984 changed both sides of the equation.
The innovator side received valuable mechanisms to protect and extend exclusivity. Every new drug still had to prove it was safe and effective before it could be sold. The brands got a window: up to five years of restored patent term to recover the time lost in review, plus defined periods of exclusivity.
The challenger side received the abbreviated new drug application, or ANDA: a statutory pathway allowing a qualifying generic to rely on FDA’s prior safety and effectiveness finding rather than repeat the original clinical program. The law also created a safe harbor allowing generic developers to do work needed for approval before the relevant patents expired.
Both sides signed because both got something. Today generics fill about nine prescriptions in ten, and the brands still keep a valuable period of high-margin exclusivity.
What the labs want
The frontier labs are reaching for the same two protections that make pharma profitable, and the safety debate is where they are reaching for them.
The first is an approval gate. No drug reaches the market until the FDA agrees it is safe and effective, and clearing that bar takes so much time and money that most would-be competitors never try. The labs’ version is testing before release. In July, Demis Hassabis proposed an industry-funded body, modeled on FINRA, that would test frontier models before they ship, first voluntarily and then as a condition of selling them in the United States, with the power to coordinate a slowdown if one were needed. Any mandatory pre-release gate creates a fixed cost of entry. That cost may be justified by the risk being controlled; it can also advantage firms large enough to absorb it.
The second is a window of exclusivity. A patented drug earns for years before generics are allowed to copy it, and that protected window is what pays for the research. A model gets no patent. Its lead lasts only until someone catches up. The labs’ substitute is to slow the race itself. In September, Dario Amodei argued that the industry should deliberately slow the rate at which it improves its models, with outside evaluators working inside the labs to confirm the time is used well, and the labs have asked lawmakers for an antitrust safe harbor so they can coordinate the pace without breaking the law. Whatever the safety case for it, a coordinated slowdown works like exclusivity. If the frontier moves more slowly while each lab keeps selling its current model, every model earns for longer before the next one makes it obsolete. The crackdown on copying guards the window from the other side: in September the NSA, CISA, and FBI named six Chinese labs for distilling American models at industrial scale and told providers to quietly serve suspected copiers a weaker model.
What the labs don’t ask for is the challenger side of pharma’s bargain, a legal route for the copies. Hatch-Waxman gave the brands their extra years of protection only in exchange for a fast, defined path for generics. The labs want the half of the bargain that protected the brands, and pharma only got that half by accepting the other one.
I take the safety concerns at face value, and the labs’ asks are narrower than their critics claim. Anthropic, for one, says it has never argued for banning open models. But a regime can be sincere and still set the economics. In AI the approval gate is becoming the eval, and whoever defines the eval decides what counts as safe, which is to say who gets to sell. An eval regime also bundles three separate powers: who writes the test, who gets behind the wall to grade it, and who decides whether you passed. Those don’t have to live in the same institution, which is exactly why the fight over them is a fight over the market.
What’s different between pharma and AI
This is where the analogy breaks, and it breaks at the root. A drug and a model are different kinds of products, used in different ways, made by industries that move at different speeds. Every part of pharma’s regime depends on something about drugs that isn’t true of models.
The first difference is physical. A drug is a thing. It has to be made in a plant, shipped by a distributor, and handed over by a pharmacist, and the law can reach every one of those steps. That’s why an FDA approval can be enforced and a patent can be defended: you can find the factory and stop the shipment. A model is a file. Once its weights are out, anyone can copy, fine-tune, and run it anywhere, including in countries no American regulator can reach, and capable open models already sit on a million hard drives. The same difference breaks the patent bargain. A drug patent publishes the molecule, but building and running a plant at scale stays hard, so disclosure teaches the invention without handing over the business. A model’s weights are the product. Publishing them doesn’t teach the market; it hands it the factory. That’s why the labs keep secrets instead of filing patents.
The second difference is how the products are used. A drug is approved for a specific use: a condition, a dose, a population. Its risks come from the molecule itself, stay within those limits, and can be tested in a trial before anyone takes it. A model has no single use. Its weights are inert, and its harms show up in what people do with it, across a range of uses no one can list in advance. Approving a general-purpose model before release is like pre-approving language. What can be tested ahead of time is a short list of catastrophic capabilities, the way a toxicity screen looks for specific damage without certifying a drug for every use. That screen is worth having. It can keep a dangerous model off the market. It can’t keep a safe model scarce. Generality breaks the patent too. What would it cover: the weights, a capability, a benchmark score? The courts have mostly answered. Since Alice, abstract algorithms have been ineligible for patents, and the Federal Circuit has held that pointing generic machine learning at a task isn’t a patentable invention. You can patent what a model is aimed at. You can’t patent the model.
The third difference is the industries themselves. Pharma runs on decades: a drug takes ten years or more to develop, then earns under patent for roughly another decade. Model generations turn over in months, and a patent that takes years to issue protects a product that is already obsolete. Copying works differently too. A generic has to prove it is the same molecule before it can be sold. An open model only has to be good enough, and customers decide what good enough means. Pharma needed a statute to give copies a legal route to market. AI’s customers are building one themselves, with evals, routing layers, and fallback models that turn switching suppliers into a configuration change. The ANDA isn’t missing; enterprises are writing it in software. Even the sides are blurrier than they were in pharma, where brands and generic makers were different companies. More than 270 organizations have signed the industry’s letter defending open weights, OpenAI and Google among them, and the signatures track business models more than sides.
What they’ll do instead
Without a window from the law, the labs will likely have to build their protection privately, and they have three ways to do it.
The first is secrecy: closed weights, undisclosed recipes, evals behind the wall, with safety as one more reason to keep it all inside. That isn’t the patent playbook. It’s Coca-Cola’s. A patent says teach the public and get twenty years. A trade secret says teach no one and keep the returns for as long as the secret holds.
The second is speed. A secret that leaks has to be replaced before it’s worth nothing, so the labs have to run pharma’s renewal machine on a clock measured in months: the research, talent, compute, and cost discipline to reach the frontier again and again. A trade-secret business is sustainable only at speed.
The third is to move into the markets next door, using ephemeral advantage in intelligence to produce durable assets. A lead at the frontier is temporary, and one of the likeliest ways to bank it is to use the model to capture the profit pools around it, even when those pools belong to the labs’ own customers. ChatGPT turned a model into a consumer habit. Claude Code puts Anthropic directly into the application layer occupied by coding harnesses that also depend on Anthropic’s models. Biology makes the economics unusually visible. Alphabet built Isomorphic Labs around AI-enabled drug discovery; Anthropic is now expanding deeply into life sciences, including physical biology experiments. None of that proves IP capture is the strategy. But the asymmetry is striking: the model that contributes to a discovery may depreciate quickly while a resulting patentable invention can persist for years.
The customer writes the other half
The labs want the half of pharma’s bargain that protected the brands. Their customers are writing the other half themselves.
Every protection the labs build creates a mirror-image problem for the companies that buy from them. The lab wants secrecy; the customer needs enough transparency to trust what it’s buying. The lab wants to stay ahead; the customer needs alternatives to negotiate with. The lab wants a position that’s hard to dislodge; the customer needs an architecture that survives its supplier being replaced. From the outside, a customer can see very little. Your supplier may sell you last year’s frontier while keeping this year’s for itself, and it may enter your market tomorrow, guided by what it can see of where demand is growing. Every query is market research for your supplier’s next product, even when no one trains on it.
That’s why evals, routing layers, fallback models, and open weights matter so much for the enterprise right now. They look like engineering choices, but in reality, they represent bargaining power. A customer that can swap one model for another in an afternoon has the leverage a generic maker got from Hatch-Waxman, and no one had to pass a law to give it to them.
That leverage sets up a loop. Short-lived profits on each model push the labs downstream. Moving downstream makes customers wonder whether their supplier will stay a neutral platform. That doubt makes portability more valuable. Portability speeds up substitution. Substitution thins the margin on every model. And thinner margins push the labs further downstream. The protection is consuming the platform.
A bargain of AI’s own
The safety concerns are real, and the evaluators moving inside the labs are evidence of that. But the rules the labs asked for would have protected their business as surely as the public, which is why the safety debate keeps sounding like a patent negotiation. If that’s what it is, it could still end the way pharma’s did, in a grand bargain. It just won’t be the same as pharma’s.
I don’t know what AI’s version looks like, and I’m wary of anyone who says they do. But pharma shows the shape of a good one. It would have to give something to both sides: protection for the companies that pay for the frontier, and a fair way in for everyone who follows. And it would have to be built for software rather than pills, for products that can be copied in an afternoon, change after they ship, and cross borders as files.
A bargain like that needs both sides to want one, and in pharma it took a tragedy and twenty-two years to get there. AI hasn’t had its tragedy, and the one serious proposal died after a few phone calls. But the negotiation is already underway, in every safety proposal and every lobbying letter. Pharma struck its bargain after the damage was done. AI still has the chance to strike one before.

Leave a Reply