The ‘dangerous’ AI models are the ones saving us

Published August 15, 2026 7:00am ET



When the next cyberattack hits a Fortune 500 company, or ransomware locks the files of a regional hospital system, which artificial intelligence tools will information technology experts use to ward off attackers? Against these threats, coders are increasingly ditching frontier AI large language models in favor of open models without guardrails. This matters because powerful forces in Washington, from the China hawks to the frontier AI companies themselves, want to limit open-weight AI models, many of which are developed in China. That would be a costly error.

Consider the breach of Hugging Face, the top platform hosting open-weight AI models that users download and run on their own machines. An internal test of OpenAI’s GPT-5.6 Sol escaped its sandboxed environment and attacked Hugging Face’s infrastructure. To defend against the intrusion, the platform’s team tried Anthropic’s and OpenAI’s models but were repeatedly blocked by the models’ safety protections, which curtail certain workflows.

The team then ran a self-hosted version of the open-weight GLM-5.2 model to isolate and contain the attack. America’s frontier models failed while an open model from China delivered.

Then there was an attack on the Coldcard bitcoin-only wallet that exploited an entropy bug, resulting in weak security. The attacker stole upwards of 1,366 bitcoins, or $87 million, in just 25 minutes by running code to “crack” seed phrases and drain accounts, likely using AI tools.

When security researchers prompted frontier AI models to triage the attack, they faced the same problems. Claude’s Fable and Opus 4.8 models refused, as did GPT-5.6 Sol. Only Kimi-K3, an open-weight model from China, was able to diagnose the entropy attack, isolate the malicious code, and tag the cybercriminal’s movements on the blockchain.

“There’s an enormous ongoing effort in Bitcoin right now to find and fix vulnerabilities across hundreds of open source projects,” researcher Zack Voell wrote. “Almost no one is using OpenAI or Anthropic models. They’re nerfed. Sad state of affairs for American frontier labs.”

The frontier models deemed the most capable and dangerous, which sparked doomsday predictions, are … nerfed. At least for ordinary users. They deliberately limit how users can probe them or run various sequences to adhere to “safety” and maintain a positive regulatory posture in Washington.

Open-weight models such as Kimi K3 or Qwen never tell users their prompts are unsafe. And they can run on hardware you already own or those inside American data centers.

There are American open models, such as Google’s Gemma and Thinking Machines’ Inkling, that are frontier-capable. But America needs more if we want our technology to be the standard. Policy hawks lobbying the federal government to put restrictions on Chinese hardware and software want America to win. But they don’t understand open-source software, nor do they understand how most people and enterprises use AI.

Lawmakers are being sold a vision of Chinese tech conquering the global AI stack by “dumping” open models on the market. But for years, America dominated open-source technology and every fundamental part of open-source AI. It can do it again.

Once any technology is made open-source, no matter its origin, it’s immediately reproducible and can be modified. It can be hosted on local computers and tuned to a user’s or company’s discretion. That will be the real unlocking of the AI economy, but only if Washington understands the technology.

The global battle over AI isn’t about the nationality of the developers or even their company headquarters.

Rather, it’s about the inference: servers and data centers where AI requests are processed. It’s about the harnesses, the software that processes user requests. And it’s about whether we can adopt models for real-world use cases, whether they be open or closed.

A HIDDEN LEGAL GLITCH IS UNDERMINING TRUMP’S AI AGENDA

AI policies should not be set by actors who either misunderstand open-source or view it as a hostile competitor to be extinguished. Consumers stand to gain the most from an open ecosystem without unreasonable model restrictions imposed by the government, few, if any, export controls on chips, and a relentless focus on providing better technology. We can be skeptical of China’s intentions in AI. That’s a reasonable posture to take. But we cannot subvert American dominance by granting regulatory advantage to a handful of companies while giving politicians veto power.

The real contest isn’t over who bans the most. It’s over who builds the model the rest of the world actually wants to use. Open-source is America’s best shot at winning that contest.

Yaël Ossowski is the deputy director of the Consumer Choice Center.