Part Two: The Ledger

Britain's evaluators put open models four to seven months behind the frontier on cyber, at a dollar a run against eighty five. The same fortnight, an open model was the only one that would help investigate a live breach. Part two of four on the fight over open weights.

Part Two: The Ledger
A sealed model refuses a document while an identical open one is examined under a lens, multiplying behind.

Second in a four-part series. Part one covered the two laboratories that lost control of their own systems.

The failures described in part one took place in July, and they landed in the middle of a policy fight already well advanced. They also did something unusual. Inside a single fortnight, they handed both sides their best material. Anyone still holding a clean position on open models after July has not been reading carefully.

Start with what the argument is actually over, because the vocabulary hides it. A model's weights are the numbers produced by training, the thing the training run is for. Publish them and anyone can download the model, run it on their own hardware, inspect how it works, and strip out whatever restrictions were trained into it. Keep them private and the model is reachable only through an interface you control, which lets you refuse a request, log who asked, and switch a customer off. That is the whole distinction. Everything in this debate follows from it.

Nvidia's case for publishing has two parts, and the second is far stronger than the first. The economic argument, circulated on 24 July as Open Weights and American AI Leadership and now carrying more than two hundred and thirty signatures, runs on competition, cost, sovereignty and diffusion. The commercial interest beneath it is not concealed. A world in which every hospital, factory and ministry tunes its own model is a world that buys a great many accelerators.

The security argument is different in kind, because it makes a claim that can be checked. Formalised on 27 July as the Open Secure AI Alliance, with thirty seven members including Microsoft, Cisco, CrowdStrike, IBM and the Linux Foundation, it holds that defenders gain more from open models than attackers do. In July that claim was tested in the field rather than in a policy paper.

When Hugging Face went looking for what had crawled through its infrastructure, it reached first for Claude Opus and Fable. Both refused a large part of the work. The reason is worth understanding, because it is not a bug. A model asked to explain how an exploit functions cannot easily tell whether the person asking is repairing the damage or planning it, and the safe default is to decline. That default protects against the attacker and blocks the defender in the same motion. So the company stood up Nvidia's quantised build of Zhipu's GLM-5.2 on its own machines, which had the secondary benefit of keeping attacker data on its own premises, and used it to unpick the scheme the agent had used to conceal its payloads. That pass surfaced roughly four times what the first automated scan had found.

It is the strongest evidence anyone has produced for the open position, and it arrived under fire. It is also, for Nvidia, almost embarrassingly convenient. The model that worked was quantised by the company circulating the letter. The models that refused belong to the laboratory arguing hardest against it.

The other column

Now the other side of the ledger, from the same weeks, and it is heavier than the open camp would like. Britain's AI Security Institute published its first public measurement of the gap on 17 July. Leading open models now perform where closed frontier systems sat four to seven months earlier, narrowed from six to ten months through 2025. Cost tells the sharper story. A full autonomous attack run costs around eighty five dollars on the closed models and one dollar nineteen on DeepSeek V4-Pro. Refusals were defeated by asking again.

Six days later, AISI and the American Center for AI Standards and Innovation jointly assessed Kimi K3 and reported both halves of an awkward result. The model sits well below the American frontier on offensive capability, scoring 32 per cent on exploit development against an average of 76. Its safeguards also failed to stop it attempting the work. Three days after that, Moonshot published the weights, and no regulator on earth can now amend them.

AISI framed the four to seven month gap as preparation time, which is the most useful phrase any institution has offered this year. It concedes the open camp's point that the frontier is not where the danger sits, and the closed camp's point that the interval is closing.

Dario Amodei's position, published on 27 July, is narrower than his critics allow. He rejects a ban, calls safe open models a public good, and asks instead for chip controls, enforcement against industrial-scale copying, and mandatory pre-release testing for every sufficiently capable model regardless of origin or licence. His one quarrel with the Nvidia letter is its assumption that openness necessarily favours defenders. In biology he expects the reverse, because a pathogen released cannot be patched and a vaccine takes years. Whether that holds is unresolved, which is exactly his argument for measuring it rather than asserting it. That the position also suits a company selling the closed alternative is equally true. Both things stand.

So the evidence is genuinely divided, which raises the question almost nobody in this correspondence has faced. Suppose you win the argument. What exactly have you won? Tomorrow, why a published file cannot be governed by any instrument currently on the table.


Get the stories that matter to you.
Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to Cyber News Centre.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.