Open Models Make the Future of Security a Speed Contest

Ante Gojsalić

Hatched by Ante Gojsalić

May 14, 2026

9 min read

87%

0

The new security problem is not just better attacks, it is cheaper imagination

What happens when the cheapest thing in the world becomes the ability to invent a convincing lie?

That is the real shift beneath the excitement around foundation models and the alarm about AI security. The obvious story is that AI will create more phishing emails, more malware, and more synthetic voices. True, but incomplete. The deeper change is that the cost of generating plausible deception is collapsing, while the cost of verifying reality remains stubbornly human, slow, and context dependent.

That imbalance matters because security has always been a contest between creation and detection. Attackers need to craft one good lure. Defenders need to inspect everything. When language models become widely available, the asymmetry gets worse, not because the machines are magically evil, but because they industrialize the attacker’s creative process. The same capabilities that let researchers build better models also let criminals produce more convincing fraud at scale.

The unsettling idea is this: open access to powerful models does not merely democratize intelligence, it democratizes persuasion.


From code generation to confidence generation

For years, most cybercrime relied on labor. A phishing campaign needed someone to write the message, choose the target, tweak the tone, and maybe localize it into another language. Malware often had to be manually adapted to evade defenses. Social engineering depended on patience and a decent feel for human psychology. AI changes all of that by turning craft into throughput.

A synthetic voice can now call a finance employee and sound like the chief financial officer. A generated image can make a fake invoice look routine. A language model can produce dozens of variations of the same message, each slightly different, each designed to slip past filters or to match the local jargon of a specific industry. What used to require time and skill can be mass-produced like spam, but with the polish of a private consultant.

This is why the first great wave of AI-enabled abuse is likely to be social engineering. Social engineering is the most human part of security, and therefore the most vulnerable to machine amplification. A perfect exploit is not always technical. Often it is emotional: urgency, authority, fear, embarrassment, curiosity. AI is very good at manufacturing those cues on demand.

Consider a simple analogy. Traditional phishing is like a scammer making phone calls from a single burner phone, hoping a few people answer. AI-assisted phishing is like giving that scammer a call center, a writing team, a voice actor, and a data analyst. The scam itself is not new. The industrial capacity is.

The danger is not that AI invents a new category of deception out of nowhere. The danger is that it makes old deception cheaper, faster, and more personalized than human defenders can comfortably absorb.

This matters because security teams have long relied on the friction of attack. Fraudsters needed scale to be profitable, and scale introduced mistakes. AI reduces those mistakes. It smooths the edges of language, generating emails that read less like broken English and more like a competent coworker under deadline. It can also create polymorphic code, subtly changing malicious payloads so that signature-based systems see a moving target instead of a fixed pattern.

When offense becomes a software problem, defense can no longer assume that bad actors are constrained by time, fatigue, or limited bandwidth.


Open models change the economics of harm

The release of powerful open models introduces a paradox that is easy to miss if you only think in terms of innovation. Open models are not just an epistemic event, meaning a breakthrough in what machines can know. They are also an economic event, because they alter who can afford to do what.

A model trained on publicly available data and released to the research community lowers barriers. That is a genuine scientific good. It allows more people to test ideas, reproduce results, and build better tools. But the same openness also lowers the barrier for adversaries who do not need to train frontier systems from scratch. They can reuse, fine tune, and weaponize existing capability much faster than defenders can rebuild their monitoring stacks.

This is where the most important asymmetry emerges. Defenders must protect a broad surface area: employees, customers, infrastructure, endpoints, logs, access controls, identity systems. Attackers need only discover one weak seam. Open models make that seam easier to search for.

The result is a world where the marginal cost of attack declines faster than the marginal cost of defense. That is the central strategic problem. If one side can generate 10,000 personalized attacks for the cost of one, while the other side still needs to inspect each suspicious event, then security becomes a numbers game with distorted math.

There is a temptation to respond to this with blanket pessimism or calls to pause progress. But pausing is not a strategy so much as a wish. If one group stops building and another continues, the balance of power does not freeze, it shifts. In a competitive ecosystem, capability rarely waits politely for governance to catch up.

The better question is not whether powerful models should exist. They already do, in various forms. The real question is: what kinds of institutions become resilient when cognition itself is cheap and widely available?


Security in the age of synthetic reality

To understand the coming landscape, it helps to rethink security as a problem of trust calibration.

In the past, we trusted certain signals because they were costly to fake. A voice call from a boss, a typed email from a colleague, a familiar logo on a form, a normal sentence in fluent English. AI undermines that cost structure. When imitation becomes trivial, the value of any single signal drops. A voice is no longer proof. A polished email is no longer proof. Even a coherent style is no longer proof.

That does not mean trust disappears. It means trust must become layered, procedural, and contextual.

Think of it like airport security. A passport alone is not enough. Neither is a face scan by itself. Neither is a boarding pass. Security depends on the combination of signals, checked by different systems, with friction placed where the risk is highest. The same logic will increasingly apply to digital life. One message should not be enough to authorize a transfer. One voice should not be enough to approve a change. One link should not be enough to trigger action.

This shift has a profound implication: the future of defense is less about detecting synthetic content perfectly and more about designing systems that do not rely on content alone. That means stronger identity verification, transaction limits, multi-step approvals, behavioral baselines, and institutional habits that assume the first convincing message may still be false.

In other words, the response to synthetic deception is not just better detection. It is better skepticism by design.

That might sound cynical, but it is actually liberating. A lot of security failure comes from overtrusting what appears smooth, fluent, and familiar. AI intensifies that weakness. Yet it also gives defenders a chance to redesign workflows around verification rather than intuition. The organizations that adapt will not be the ones that merely buy better filters. They will be the ones that assume persuasion is now cheap and build accordingly.


The real race is not AI versus humans, but attackers versus institutional memory

A hidden lesson of the open model era is that the strongest defense may not be speed alone. It may be institutional memory.

Attackers can now generate endless variations of the same scam, but they still depend on predictable human behavior. If an organization learns from each attempt, codifies the pattern, and hardens the path, the attacker’s gains diminish. The challenge is that many organizations fail to learn quickly enough. They treat each incident as an isolated embarrassment instead of a symptom of a larger pattern.

This is where AI defense needs to be more than reactive automation. It should help teams compress learning. For example, if one fake invoice succeeds in finance, the system should not merely flag that invoice. It should map the social pattern around it: which tone was used, which timing worked, which approval process was exploited, which employee role was targeted, which adjacent controls failed. The goal is to turn every attack into a better rulebook.

There is a useful mental model here: think of defense as a memory organ rather than a wall. Walls can be bypassed. Memory accumulates. The best organizations will build feedback loops that make deception harder over time, even as the quality of deception improves.

This also changes how we should think about open models in general. Openness is not the same as vulnerability, but it does require maturity. A society that distributes powerful tools without distributing defensive habits is like a city that hands out keys while ignoring locks. The answer is not secrecy alone. It is competence, protocols, and an assumption that fluency can be manufactured.

In the age of AI, the scarce resource is no longer information. It is verified context.


Key Takeaways

  1. Treat every convincing message as potentially synthetic. Build habits and systems that require a second channel, a second person, or a second step before action.

  2. Move from content detection to workflow design. Do not rely on spotting fake text, voice, or images alone. Redesign approvals, transfers, and access changes so that single points of persuasion do not exist.

  3. Assume attackers will scale faster than defenders. Plan for volume, variation, and automation. The first wave of AI abuse is likely to be industrialized social engineering, not just technical exploits.

  4. Use incidents as training data for institutional memory. After each attempt, ask what pattern was exploited, not just what payload was delivered. Update policies, not just alerts.

  5. Invest in trust infrastructure, not just security tools. Identity verification, transactional friction, approval chains, and provenance checks will matter more as synthetic content becomes normal.


The future will not be decided by whether AI can lie

The deeper question is whether our institutions can remain trustworthy when lying becomes effortless.

That is why the intersection of open models and AI security is so consequential. Open systems accelerate innovation, but they also accelerate imitation. They expand access to reasoning, while also expanding access to deception. The result is not a simple battle between good and evil technology. It is a redesign problem for civilization’s trust machinery.

We should stop imagining security as a contest to detect every false thing in real time. That is too ambitious and too brittle. A better goal is to create systems that do not collapse when false things become abundant. The organizations and societies that thrive will be those that treat verification as a core operating principle, not an annoying extra step.

In that sense, the arrival of powerful open models is a test. Not of whether machines can imitate humans, but of whether humans can build institutions that remain sane when imitation is cheap. The answer will determine whether AI becomes mostly a tool for acceleration, or a permanent tax on trust.

Sources

← Back to Library

Hatch New Ideas with Glasp AI 🐣

Glasp AI allows you to hatch new ideas based on your curated content. Let's curate and create with Glasp AI :)

Start Hatching 🐣