There has been an intense debate about cyber risks from open-weight AI models. The author reports repeated conversations in which positions polarize: some argue open models pose an unacceptable societal risk and should be banned; others say openness is needed for defense and that banning models would make the world less safe. The author places himself among the defenders of openness, alongside voices such as Hugging Face and Joshua Saxe.
Who is saying what
- The “open-weights are dangerous” viewpoint is largely held by some frontier lab leadership and parts of the U.S. national security community. Reports such as Anthropic’s analysis of GLM-5.3 have become focal points for that argument.
- Western proponents of open weights argue that open release is necessary for defenders and that prohibition would reduce global safety.
- Chinese companies continue to release open-weight models and make those decisions based on their society’s and government’s risk assessments.
In Western AI discourse, risk-focused narratives have been disproportionately visible. There has been relatively little substantive effort to understand how Chinese firms assess risk; instead debates sometimes default to ad hominem‑style claims such as “Chinese labs don’t care about safety.”
Critiquing the anti open-weight alliance
Anthropic’s report on GLM-5.3 is technically defensible in many respects, but the author’s main critique is that it fails to engage with system-level questions: what would happen if we banned open models for cyber reasons, and why do Chinese companies decide to release their models? These are the kinds of questions needed to understand the broader ecosystem perspective on AI risks. Policy choices are trade-offs; rarely does a single action produce a universally better outcome.
Closed APIs vs open weights — what public data shows
Public evidence to date attributes most documented cyber incidents to closed models or their APIs. The author, basing his view on available incidents (including those linked to OpenAI models and collections like FelonyBench), offers a set of possible explanations, acknowledging that it may take years to determine the true causes:
- It may be that both open weights and closed-model APIs (even with safeguards) are relatively easy to misuse, so the simple “open = dangerous, closed = safe” trope is misleading. A more accurate description could be “open unsafe, closed unsafe.”
- Alternatively, there may be fewer bad actors willing to conduct loud attacks on critical infrastructure; in that case, closed models’ greater raw capabilities (even with theoretical guardrails) could produce more net harm if safeguards are porous.
The author does not fully endorse a specific policy, but suggests it is reasonable to consider that open-weight models—by spreading defensive capability—might be the best short-term tool to reduce harm in some domains. For example, in sensitive government or air-gapped environments, open-weight models may be the only immediately deployable strong AI tools.
Regulatory implications
If policymakers conclude that the latest open-weight models should be banned to slow the diffusion of cyber capabilities, the author argues they would likely also have to prohibit public-facing APIs for frontier closed models. Today, closed-model safeguards are generally stronger than those around open weights but are far from perfect. It is plausible closed models’ offensive capabilities could rise faster than guardrails improve. A world that bans open weights while allowing closed models to advance could therefore widen the offense–defense gap. Building mitigations that enable defenders to run powerful models on private infrastructure will take time if access to strong open weights is removed.
Explaining China’s AI risk posture
China does care about AI safety, but its approach is endogenous to Chinese political and cultural structures. The author’s understanding is that Chinese companies must register major model releases with the government, including evaluations that originally centered on information control. It’s unclear whether that framework has meaningfully expanded to include cyber or bio risks. China’s political system is decentralized; lab reporting must flow through existing structures.
Chinese researchers and firms also face stronger social and personal risks: leading AI researchers may be restricted from leaving the country and the industry has been closing off to foreign investment. On balance, the author suspects individual and social consequences for causing domestic harms are likely higher in China than the worst-case corporate consequences in the U.S.
At the same time, Chinese labs are incentivized—sometimes pushed publicly by the government—to compete. Comprehensive safety evaluations for frontier models (examples such as Kimi K3) can cost tens of millions of dollars in compute, which labs would often prefer to allocate to training. The correct policy question is thus: what is the minimum amount of compute a lab should spend on safety testing before releasing a model? It may be reasonable to argue that Chinese labs should spend more or be more transparent, but it’s not obvious that the required minimum would match the scale of Anthropic’s or OpenAI’s internal investments. Moreover, large Western labs also balance risk-understanding institutions against business and economic priorities.
The Claude Mythos example
When Claude Mythos was announced, it was portrayed by many as a new class of cyber weapon that could cause massive societal destabilization if leaked. The author considers that portrayal mistaken. GLM-5.3 has high capability, but more than a month after the open-weight release there is little public evidence of a step-change in infrastructure collapse. If Claude Mythos had been accidentally released as open weights, the world would likely have been worse off in terms of accelerated cybersecurity incidents, but not in a qualitatively different, civilization‑crippling way. The strongest proponents of extreme open-weight alarmism have effectively offered a falsifiable prediction—that these models will cause unprecedented, infrastructure‑crippling harms—and the author believes current evidence does not support that prediction.
Conclusion: accept nuance and trade-offs
The author concludes that the current polarized debate risks producing policies that both weaken American AI competitiveness and increase long-term cyber risk. Instead of assuming monolithic answers (ban open weights or keep everything open), policymakers should embrace nuance, examine trade-offs, and seek system-level understanding—including how Chinese companies judge risk, how closed-model APIs have been implicated in incidents, and how offense/defense dynamics evolve. The author thanks Rohit Krishnan and Joshua Saxe for feedback on the piece.



