Products Demo Docs Blog About Contact Sign in Sign up
Blog · · Philippe Laporte

Seven Billion for the Router

Stripe just bought the layer that decides which AI model runs your work. Nobody has bought the layer that proves which one did.

On 19 August, Stripe acquired OpenRouter. The reported price was north of seven billion dollars, roughly five times the valuation OpenRouter had reached in a funding round three months earlier.

The logic is clear enough. OpenRouter had become the neutral gateway to hundreds of models, and Stripe's stated view is that tokens are becoming the central currency for companies building with AI. Buying the router is buying a position in how that spend flows. It is the same instinct that made Stripe buy payment rails: own the place where value moves.

What interests me is the problem the acquisition makes larger.

Routing creates an evidence gap

A router earns its keep by choosing. It picks a model per request based on cost, latency, capability and availability, and it reroutes when something is slow or down. That is the product. It is also the reason that after the request completes, the customer frequently cannot say which model served it.

For most software, that does not matter. For an AI system making a decision someone may later contest, an insurance claim, a credit refusal, a clinical flag, a fraud hold, it matters completely. The question an examiner asks is never "what does your architecture do in general." It is "reproduce what happened on this specific case, and prove it."

Cheaper routing and provable execution are two halves of the same problem. Someone just paid seven billion dollars for the half that makes the other half necessary.

The routing layer can tell you what it intended to do. It is not positioned to tell a regulator what actually happened, because the party that dispatches the work cannot credibly be the party that attests to it.

The jurisdiction problem makes it concrete

In July, CNBC reported OpenRouter usage data showing that the share of tokens US companies sent to Chinese-origin models had stayed above 30% every week since early February, peaking at 46%. The twelve-month average before that had been around 11%. Vercel's production gateway reported a comparable figure of 29%.

46%. Peak share of US enterprise token usage on Chinese-origin models, per OpenRouter data reported by CNBC, July 2026.

Two US House committees opened a joint investigation in April and have since written to several well-known technology companies about their exposure. Nothing has been prohibited. Adoption is legal, and the cost argument for it is real.

But look at how one of those companies answered. Airbnb told CNBC that its AI activity runs overwhelmingly on US-origin models, and that any China-origin model use is routed exclusively through approved US-based service providers.

That is a provenance claim. It is a statement about which model processed what, and through whom. It is also, today, a statement backed by the company's own records. For an internal policy that is fine. For a congressional letter, an auditor, or a customer contract with a jurisdiction clause, the obvious follow-up is how anyone outside the company would confirm it.

"We route to the optimal model" and "we can tell you which jurisdiction's model processed this claim" are now in tension. Both are reasonable. Neither is verifiable from the outside without something purpose-built.

Model identity is becoming a security property

There is a sharper version of this. In June, Booz Allen Hamilton published a study running more than 2,800 trials against several Chinese code-generation models and one American model, varying only the persona described in the prompt. Three of the four Chinese models produced significantly more vulnerable code when the prompt identified the user as working for a US government entity. One showed roughly 130% more vulnerabilities under that persona, and the flaws were obfuscated rather than the kind standard static analysis catches.

Set aside the geopolitics for a moment and look at what that finding does to the engineering question. It means model behaviour can be conditional on context in ways the output does not reveal. Which model ran stops being a compliance detail and becomes a security control, one you cannot exercise if a router selected the model dynamically and the only record of that choice belongs to the router.

Payments is where this lands first

It is not an accident that a payments company bought the router. Payments is the most examined industry in software. Sponsor banks audit their merchant service providers, card networks audit the sponsors, regulators audit everyone, and every party in the chain is periodically required to demonstrate rather than assert.

As AI moves into onboarding, underwriting, fraud scoring and dispute resolution inside that chain, the demonstrate-rather-than-assert standard arrives with it. A platform that can route intelligently and also produce independent evidence of what ran will pass those reviews. A platform that can only route will be explaining its logs.

What this is not

None of this is an argument against routing, against Chinese models, or against the acquisition. Routing is genuinely valuable, open-weight models are genuinely competitive, and Stripe bought a real business at a price that presumably reflects real usage.

It is an argument that the industry has now invested heavily in the ability to make execution opaque, and comparatively little in the ability to make it checkable. Those two capabilities are complements, not competitors. One of them is worth seven billion dollars. The other one is worth building.


Cyberian Systems issues independent cryptographic receipts for AI inference: proof of which model ran, on which input, with which output, verifiable by a party that did not run the job. If you operate AI in a regulated industry and this question is landing on your desk, write to philippe@cyberiansystems.ai.

PL
Philippe Laporte
Founder and CEO of Cyberian Systems, building verified AI inference infrastructure for regulated industries.

Try the live demo · Follow on LinkedIn · RSS