A few weeks ago, on the sidelines of an event at La Felicita (Station F), I got into a conversation with the CEO of Aiven about open-source business models. His take was clear and, frankly, well-earned: the managed cloud is the correct way to monetize open source. Let the community build the moat, put a hosted layer on top, and sell the operational convenience.
He's not wrong. That model has minted real companies. But I think it's already starting to look like the previous era's answer to a question the AI era isn't asking anymore.
The moat that keeps collapsing
Here's the pattern, and it's not subtle if you look at it in sequence.
MongoDB relicensed its server from AGPL to the Server Side Public License in October 2018, a little over a year after going public. The trigger was AWS DocumentDB, a compatible managed service competing directly with MongoDB's own cloud offering. Debian, Red Hat, and Fedora dropped the package, and by 2021 the Open Source Initiative had gone on record saying SSPL doesn't actually meet the Open Source Definition.
Elastic followed in January 2021, dual-licensing under SSPL and its own Elastic License, again in direct response to AWS launching a competing managed service, this time OpenSearch, forked straight from the codebase Elastic had just locked down.
HashiCorp was next, moving Terraform and its other tools from MPL 2.0 to the Business Source License in August 2023. The company framed the move as protecting continued investment in the community while keeping the products freely available, but the practical effect was the same: commercial competitors got restricted, and the community forked Terraform into OpenTofu almost immediately. Eighteen months later, HashiCorp itself was acquired by IBM and stopped being an independent company.
Redis did the same dance in 2024.
Four different companies, four different boardrooms, the same move, the same trigger every time: a hyperscaler builds a managed version of your open project, captures the revenue you were counting on, and you respond by taking rights away from your own community.
The part everyone skips over
What's more interesting than the relicensing itself is what happened next. In August 2024, Elastic added AGPLv3 back alongside SSPL, specifically so Elasticsearch could be called open source again. Redis did the same thing in May 2025, adding AGPLv3 as an option starting with Redis 8. Two of the four companies that walked away from open licensing walked straight back to it within two years. No clear evidence has emerged that the license changes actually improved revenue for any of them, and the one company that never reversed course, HashiCorp, is the one that no longer exists as an independent company.
That's the tell. The open-core bet wasn't really that open source doesn't work as a business model. It was that these companies were worried a bigger company would out-execute them on hosting. And when the fear turned out to be manageable, or the acquisition happened anyway, the license restriction had bought nothing but community backlash and a permanent asterisk next to the company's name.
Why we're not making that bet with ZizkaDB
We built ZizkaDB under AGPLv3 from day one, and our primary deployment model is VPC-based: we run the software inside the enterprise's own cloud, not ours. No managed multi-tenant layer holding customer data as the thing that makes us sticky.
I know the standard objection. If you don't control the data, how do you build a moat? The prevailing wisdom in AI right now is almost the inverse of the open-source-cloud thesis: the more data flows through you, the stronger you get. Every relicensing decision above was, underneath the legal language, an attempt to protect a moat built on being the only place your data could go.
I think that's precisely the wrong instinct for AI infrastructure, and Europe is where you can see why fastest. The EU AI Act is pushing enterprises toward auditability, data residency, and the ability to actually explain what a system does with their information. A vendor whose pitch is trust us with your data and trust our binary is fighting the regulatory current, not riding it. A vendor whose infrastructure runs inside the customer's own environment, in the open, isn't just compliant. It's the more honest sell.
There's also a simpler, less philosophical reason. The moment your differentiation depends on customers being unable to leave, you've told them exactly what you think your product is worth without the lock-in. Every company on that relicensing list eventually discovered that a locked license didn't stop AWS, didn't stop the fork, and didn't stop the acquisition. It just spent the trust of the community that had built the product's early value in the first place.
Radical transparency as the actual moat
So here's the bet we're making instead: in an AI infrastructure market that's about to be flooded with vendors asking enterprises to hand over their data for the privilege of using AI, the company that says run this yourself, inspect the code, keep your data where it already lives has a moat that doesn't depend on legal restriction at all. It depends on being genuinely good enough that customers choose to stay, and on being positioned exactly where regulation is heading rather than one license change behind it.
We'll keep evolving how we protect ZizkaDB's IP. That's a legitimate business need, not something I'm waving away. But the mechanism for capturing value can't be that the customer's data is the leash. That's not a technology decision. It's a bet on what enterprises will tolerate in a market where the alternative, genuine data control, is now actually on the table.
The AI era needed new infrastructure. I think it needs a new answer to who gets to hold the data, too. And increasingly, open source with the data staying put isn't one option among several. It's becoming the only credible one.
Use our Open-source database here : https://github.com/Zizka-ai/ZizkaDB