The open-source AI panic is a business model, not a security briefing
Every cycle, a closed lab discovers that weights on a torrent are an existential risk — right after a competitor ships them. The threat is real. The timing is the tell.

There is a ritual. A lab that sells access by the token announces that open weights will arm criminals, destabilize elections, and collapse the biosecurity perimeter. The slides are excellent. The citations are a mix of real papers and scenarios that would also be true of a search engine, a chemistry set, and a motivated undergraduate.
Then you look at the calendar. The sermon landed the same week a rival released a model that makes the sermonizer’s mid-tier SKU look overpriced.
If your safety case is indistinguishable from your pricing case, you do not have a safety case.
Dual-use is not a plot twist
Of course capable models are dual-use. So are compilers. The honest version of the argument is: some capabilities should not be one git clone away, and democratic governments should be in that fight in public, with statutes, not with a vendor’s acceptable-use policy.
The dishonest version is: only we can be trusted with the weights, and the proof is that we have a safety team and a comms team that share a Slack channel.
Open weights do increase the number of people who can fine-tune a model toward a bad end. They also increase the number of people who can inspect, evaluate, and refuse a vendor’s story about what the model cannot do. That second effect is why the panic is so selectively timed.
Concentration is the unfashionable risk
The risk that does not get a keynote is simpler. A handful of firms control the best closed models, the best chips, and the best distribution into workplaces that have already surrendered their documents. If those firms also succeed in making “open” sound like a moral failing, we will have outsourced a public capability to a private helpdesk.
I am not asking you to romanticize a Discord full of quantized checkpoints. I am asking you to notice who benefits when “responsible” means “ours.”
Governments can restrict specific uses, require evals, and punish reckless release. They should. What they should not do is deputize the incumbent price list as a national security agency.
The next time a lab warns you about open source, read the release notes next to the op-ed. If they were published in the same news cycle, you are not the audience. The regulator is — and so is your CFO.