Lambert: open-weights cyber risk debate misses tradeoffs
TL;DR
- Nathan Lambert argues Anthropic's report on GLM-5.3 is technically reasonable but ducks the policy trade-offs between open-weight and closed-API cyber risk.
- He contends documented attack evidence sits primarily with OpenAI's closed models, citing the Hacktron hacking of OpenAI and FelonyBench.
- Banning open models while allowing frontier closed APIs would widen the offense-defense cyber gap, Lambert writes.
Nathan Lambert argues the debate over open-weight AI models and cybersecurity has drifted into unproductive territory, and that the camp warning loudest about open releases is sidestepping its own trade-offs. In a post on Interconnects, Lambert takes Anthropic's recent report on GLM-5.3 as the latest example. The problem, he writes, is "not the technical research they did, which is largely reasonable, but the failure to engage on more cross cutting questions."
His core claim is a reframing. "By all measures, GLM-5.3 is the model that crosses that threshold of capability," he writes of the Chinese open-weight release, with little public evidence that the predicted harm has materialized. He contrasts that with Claude Mythos, an earlier model that was flagged as alarming: "If Claude Mythos was accidentally released as open-weight, it seems like the world would have been more or less fine."
Lambert's second move is to push on where the documented attacks actually come from. He writes that "the evidence of numerous attacks from OpenAI models is the only data I have on the shape of cyber risks," pointing to the Hacktron hacking of OpenAI and the FelonyBench documentation of attacks. His read of the policy consequence is blunt: "a world where open models are banned while closed models continue to progress would be increasing the offense-defense cyber gap." Two of the researchers in our tracker shared the post.
He is not uncritical of Chinese labs. "My understanding is that the Chinese companies have to register every major model release with the Chinese government," he writes, thanking Rohit Krishnan and Joshua Saxe for feedback on the piece. But he closes on institutions rather than individuals: "I trust many of the individuals at the labs to work hard to ensure safety, but I'm not trustworthy of the institutions overall." The debate he wants is narrower than the one happening: "what is the correct minimum amount of compute a lab should spend on safety testing before releasing each model?"
Shared on Bluesky by 2 AI experts
Originally reported by interconnects.ai
Read the original article →Original headline: The Cyber Risk Discourse is Broken