One open model now sits months behind the American frontier on cyber and biology, and refused nothing it was asked to do. The closed model refused so often the test could not be finished. Months of capability separate them. The gap in restraint is total. Part four of four.
The White House finished its frontier AI framework on 1 August and has published nothing. The threshold is classified. The benchmarks are classified. Whether open weight models are covered at all remains unanswered. Part three of four on governing what cannot be recalled.
Washington is pushing its AI security perimeter deep inside the data centre, targeting Chinese-made components that move data between GPUs. The policy may reduce cyber and espionage risks, but it could also raise costs, slow construction and expose a new weakness in America’s AI race as AI scales.
One open model now sits months behind the American frontier on cyber and biology, and refused nothing it was asked to do. The closed model refused so often the test could not be finished. Months of capability separate them. The gap in restraint is total. Part four of four.
Last in a four-part series on the fight over open AI models.
This series began with two laboratories admitting their most capable systems had left the environments built to contain them. It moved through a fortnight of evidence thatarmed both sides of the argument at once, and then through the instruments Washington has assembled in response, every one of which governs the conduct of American companies while the artefacts under dispute arrive from somewhere else. What remains is the question sitting underneath all three, which is what this fight is actually about. The answer is considerably older than the people having it.
Linus Torvalds posted a kernel from Helsinki in 1991 and described it as a hobby, nothing big and professional. It met Richard Stallman's GNU toolchain, assembled through the previous decade on an argument about freedom rather than commerce, and Americans then did the work of turning the result into something a corporation could buy. Eric Raymond reframed distributed development as an engineering method rather than a creed, Christine Peterson supplied the phrase open source in 1998, and Lou Gerstner put a billion dollars of IBM behind Linux in 2001, which is the moment the commons acquired a sales force.
The incumbent's response is where the present rhymes uncomfortably. In August 1998 a Microsoft engineer produced an internal analysis concluding that open source posed a direct threat to revenue and to the platform itself, conceding that free software could match commercial quality, and observing with some alarm that open source evangelism scaled with the internet faster than Microsoft's own. It canvassed extending protocols to blunt open standards and deploying patents against Linux. It leaked at Halloween, was published annotated, and ten more followed while the company was fighting the Department of Justice over monopoly maintenance.
Two things came out of that decade, and both are load bearing. Openness took the substrate, and the incumbent eventually joined it, which is why Microsoft owns GitHub, ships Linux on Azure and has its name on the open weights letter now sitting in front of Washington, a document that passed two hundred and seventy signatories on Monday. And the industrial formation that followed, cloud and the developer economy and mobile and ultimately the compute industry that produced a five trillion dollar Nvidia, was built on a base layer nobody owned. Remove the free kernel and the cost structure of the past twenty five years does not exist.
The convergence nobody announced
Which is where the analogy has been running all week, and where it now breaks. The assumption beneath every argument in this debate is that Beijing intends to keep giving the foundation away. That assumption is ageing badly.
China's Ministry of Commerce has spent the past several weeks in closed meetings with Alibaba, ByteDance and Z.ai on a tiered regime that would restrict overseas access to the country's most advanced models, including open weight releases, alongside proposals to treat the theft of proprietary AI as a national security offence. Nothing has been decided and no timeline exists. But the pattern is already visible in what the companies ship, with Qwen 3.6 published openly while Qwen 3.7 Max is available only through an interface, and Kimi K3 arriving under a bespoke licence that restricts commercial resale rather than the permissive terms its predecessors carried. Xi called in Shanghai for vigilance and an adaptive approach to governance, which is the sort of phrasing that leaves a door open in both directions.
The trigger, by several accounts, was American. When Commerce briefly restricted foreign access to Anthropic's Mythos and Fable models in June, it demonstrated that a frontier system could be gated by a government, and handed Beijing both a grievance and a template. So the two capitals are converging on the same policy from opposite ends. Keep the capable middle open for reach and goodwill. Move the frontier behind the counter.
That convergence arrived alongside a finding published on Tuesday by the non-profit SaferAI, which measured GLM-5.2 as only a few months behind the leading closed systems on cyber and biology, and recorded that it declined none of the offensive tasks put to it. The same evaluation could not be completed against Claude Opus 4.7, because that model refused too consistently to finish the benchmark. The gap in capability is months. The gap in restraint is total, and it is the second number that both governments have now noticed.
For middle powers the consequence is financial well before it is philosophical. A country that hosts data centres, buys inference by the token and writes no weights is a tenant, and the lease will be drafted in a capital that has stopped consulting anyone. Australia is good at the engineering, and I have stood in the landing stations and the cool rooms to know it. Our weakness has never been the build. It is that our sovereign capital stays silent while others hold the underwriting, and the institutions that underwrite the cable increasingly run the cloud riding on top of it. Malaysia has begun breaking that loop, issuing its first data centre sukuk last week with Khazanah as ultimate obligor.
Here is what the Helsinki analogy could never account for. The Linux commons survived because no state was in a position to close it, and the only party that wanted to was a company under antitrust supervision. In 2026 both sovereigns have their hands on the door, moving in the same direction, for reasons each finds entirely persuasive. The last foundation was unownable by accident. This one is being made ownable on purpose, and by the time that becomes obvious it will be somebody else's floor we are all standing on.
Get the stories that matter to you. Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.
Sign up for Cyber News Centre
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead.
The White House finished its frontier AI framework on 1 August and has published nothing. The threshold is classified. The benchmarks are classified. Whether open weight models are covered at all remains unanswered. Part three of four on governing what cannot be recalled.
Britain's evaluators put open models four to seven months behind the frontier on cyber, at a dollar a run against eighty five. The same fortnight, an open model was the only one that would help investigate a live breach. Part two of four on the fight over open weights.
Two frontier labs admitted their most advanced models escaped testing and reached real companies. When Hugging Face reconstructed the intrusion, the closed models it tried first refused to help. It finished the job with an open Chinese one. Part one of four on the fight over open weights.
Two frontier laboratories have now admitted their most capable systems reached the live internet during safety testing. The debate about open weights was already fragile. This week it acquired a comic edge, and a legal problem nobody has solved.
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead. Sign up for free!