AivexaNewsSearch
AI news for builders and product teamsChecked every hour

The Cyber Risk Discourse is Broken

Collected Oct 6, 2026

An Interconnects post by Nathan Lambert argues that the cyber-risk debate around open models has become a lose-lose path that could both limit American AI competitiveness and increase long-term cyber risk, unless participants embrace nuance, trade-offs and what he calls scary realities.

Lambert groups the debate into three camps: frontier lab leadership and the U.S. national security community, who say open-weight models pose an untenable risk to society's functionality; AI risk moderates, including himself, Hugging Face after the OpenAI incident, and Joshua Saxe, who say open weights are necessary for defense and that banning them makes the world less safe; and Chinese companies continuing to release open-weight models with strong cyber capabilities, which he says base decisions on their society's and government's risk assessments.

He criticizes Anthropic's recent report on the risks of GLM-5.3 as an offensive cyber tool, saying the technical research is largely reasonable but fails to address cross-cutting questions such as what happens if open models are banned for cyber risks, or why Chinese companies deem these models safe to release. He also describes hearing classified briefings warning of an onslaught from Chinese open-weight models, which he says conflicts with public information documenting closed models as the cause of most existing cyber attacks, citing attacks from OpenAI models and FelonyBench.

Among possible explanations he lists: that open weights and closed APIs are both closer to easy misuse than the trope "Open Dangerous, Closed Safe" suggests, meaning "Open Unsafe, Closed Unsafe"; and that perhaps far fewer bad actors are willing to mount loud cyber attacks on critical U.S. infrastructure. He calls it at least a reasonable argument that open-weight models could be the best tool to prevent harm in the next few years, noting sensitive government agencies need open-weight models on air-gapped networks.

On China, Lambert writes that China cares about AI safety through an endogenous dynamic tied to Chinese culture and power structures, that companies must register every major model release with a decentralized government, that leading AI researchers cannot leave the country, and that the industry is closing to foreign investment. He notes comprehensive safety evaluations on a frontier model like Kimi K3 could cost tens of millions of dollars in compute, and asks what minimum testing compute labs should spend.

He says Claude Mythos was previewed as a new class of cyber weapon but that by all measures GLM-5.3 crosses that capability threshold, with little public change more than a month after its weights were released. He calls the prediction that current open-weight models will cripple cyber infrastructure falsifiable and says proponents are set up to be wrong. He thanks Rohit Krishnan and Joshua Saxe for feedback.

Read at Interconnects

Based on reporting from the original publisher. Visit the source for full context and later updates.

Publisher excerpt

Open-weights, ideology, and acknowledging trade-offs.