Open Models Do Not Just Scale Intelligence, They Scale Attack Surface

Ante Gojsalić

Hatched by Ante Gojsalić

Jul 26, 2026

9 min read

88%

0

The uncomfortable question hiding inside AI progress

What happens when the same thing that makes intelligence cheap also makes deception cheap?

That is the real question lurking beneath the excitement around modern language models. On one side, a new generation of foundation models shows that world class performance no longer requires closed labs, secret datasets, or industrial scale moats. On the other side, security experts are warning that attackers will adopt these systems faster than defenders, using them to automate phishing, generate polymorphic malware, and industrialize social engineering. Put those together and a deeper pattern emerges: the democratization of capability does not distribute risk evenly, it often concentrates advantage in the hands of whoever moves first.

This is not just a story about bad actors getting smarter. It is a story about a structural asymmetry in technology adoption. When a capability becomes open, efficient, and widely replicable, it lowers the cost of experimentation for everyone. But the consequences are not symmetrical. Defenders have to protect many possible targets, maintain trust, and operate under legal and ethical constraints. Attackers only need one opening. In that gap, progress can become a weapon.


Why open intelligence changes the economics of attack

For years, advanced AI felt like a fortress technology. It lived inside huge companies, behind proprietary walls, trained on private datasets, and accessible only to those with enormous compute budgets. That created a comforting illusion: if the model was hard to build, it would also be hard to misuse at scale.

Open foundation models puncture that illusion. When strong models can be trained on public data, reproduced by others, and distributed broadly, the barrier to entry collapses. A sophisticated capability that once required a rare team and uncommon resources can now be downloaded, fine tuned, and embedded into a workflow. That is good for research, competition, and innovation. It is also good for anyone who wants to automate harm.

Consider phishing, one of the oldest and most stubborn forms of cybercrime. Traditional phishing campaigns often fail because they are clumsy, generic, or written in awkward language. Generative AI changes the unit economics. Instead of writing one decent scam email, an attacker can generate thousands of variants tailored to a target role, geography, industry, or tone. A fake invoice can sound like it came from procurement. A message about a wire transfer can mimic the cadence of a real estate agent. A voice clone can imitate a boss, a vendor, or a family member just enough to trigger urgency.

The point is not that AI creates entirely new categories of deception. The point is that it removes friction from the oldest ones, and in security, friction is often the only thing standing between nuisance and scale. Once the marginal cost of producing persuasive content approaches zero, the attacker can test, adapt, and iterate faster than any human defense team can manually review every variation.

This is why the attacker defender dynamic is so asymmetric. Defenders must be right across a wide surface area. Attackers only need to be right once. AI amplifies that imbalance by making trial and error cheap, fast, and personalized.

When intelligence becomes abundant, trust becomes scarce.


The real threat is not fake content, it is industrialized persuasion

It is tempting to think the main danger is synthetic text, synthetic voices, or synthetic images. Those are visible symptoms, but the deeper threat is more subtle: industrialized persuasion at machine speed.

Humans are already vulnerable to context specific manipulation. We trust things that sound plausible, that arrive at the right time, and that match our expectations. A convincing fake email does not need to be perfect, it only needs to create enough cognitive pressure for someone to click, reply, approve, or transfer. AI lowers the craft required to achieve that pressure. It can personalize a message at scale, adapt to a victim’s job title, and even mimic the style of a colleague.

Imagine a mid sized finance team. Before AI, a scammer might try a generic invoice fraud against hundreds of companies and hope for a few hits. After AI, the same scammer can create dozens of variants that reference real vendors, recurring payment patterns, and the vocabulary of accounts payable. One variation may mention a missed deadline. Another may reference an urgent contract renewal. Another may sound like a slightly stressed executive who needs a payment pushed through before a meeting.

That is not merely better spam. That is a machine optimized for exploiting human routines.

The same pattern applies to malicious code. Security systems often rely on signatures, known patterns, and repetitive indicators of compromise. But if a model can generate many slightly different versions of the same harmful payload, detection becomes a moving target. The attacker no longer ships one static artifact. They ship an endless stream of near equivalents, each designed to evade recognition. This is the malware version of changing a disguise every time someone starts to recognize your face.

Here is the crucial insight: AI does not simply help attackers do old things faster. It transforms attacks into adaptive systems. A scammer no longer has to be clever in advance. The system can learn from responses, tweak the message, and try again. That feedback loop is what turns scale into power.


Open models expose a deeper tradeoff: resilience versus diffusion

The instinctive response to this risk is to want more control. Lock models down. Slow release. Centralize access. Add restrictions. In some cases, those are sensible measures. But they do not solve the core tension, because the same openness that increases misuse risk also drives resilience, competition, and scientific progress.

This is where the connection between open foundation models and security becomes especially interesting. Open models are not just products. They are infrastructure for capability diffusion. They let more people build, test, compare, and improve. That matters because concentrated AI power creates its own dangers: monopoly control, opacity, bottlenecks in research, and a future where only a few actors decide what intelligence looks like. Open systems are a corrective to that concentration.

But diffusion cuts both ways. A capability that spreads to researchers, startups, and hobbyists also spreads to criminals, fraudsters, and state actors. The same property that makes a model useful for broad experimentation makes it portable across motives.

This creates a design paradox. We want models to be open enough to be audited, improved, and widely beneficial. We also want them to be constrained enough that they are not trivial to weaponize. That is not a problem with an easy binary solution. It is a governance problem, a product design problem, and a social coordination problem all at once.

A useful mental model is to think of foundation models like electricity. Electricity empowered factories, homes, and hospitals, but it also required a century of standards, insulation, safety codes, and grid discipline. The lesson is not that we should have stopped electrification. The lesson is that general purpose power requires general purpose safeguards.

AI is entering that same phase. The question is no longer whether the capability will spread. It already is. The question is what kind of safety scaffolding will spread with it.


A better frame: security is no longer a perimeter, it is a race condition

Most organizations still think about security as a perimeter problem. Build a stronger wall. Filter the obvious threats. Train users not to click strange links. Those measures remain useful, but they are increasingly insufficient in a world where content can be generated endlessly and adapted instantly.

A more realistic frame is to see security as a race condition between generation and verification. Attackers now have tools that can generate believable artifacts faster than humans can inspect them. Defenders must therefore reduce the time it takes to verify authenticity, not just improve the ability to spot fakes manually.

That changes what good defense looks like.

Instead of relying mainly on visual suspicion, organizations need verification channels that are hard to spoof. Instead of trusting a voice message because it sounds familiar, teams need call back procedures, second channel approvals, and transaction thresholds. Instead of trusting an email because it arrived in a normal thread, they need out of band confirmation for sensitive requests. Instead of depending on single point human judgment, they need layered checks that assume the content itself may be adversarially generated.

This is why the future of defense is not only more AI. It is also more process. When the threat is synthetic persuasion, the answer is not just synthetic detection. It is redesigning the workflow so persuasion is not enough.

Think of it like airport security. The point is not to let one exceptionally convincing explanation override every safeguard. The system is built so that no single signal, appearance, or story can bypass all verification at once. AI risk demands the same philosophy. Trust must become procedural, not impressionistic.

That means companies should stop asking only, “Can our people detect a fake?” and start asking, “What happens when detection fails, and how quickly can the damage be contained?” That shift is the difference between hoping for vigilance and engineering resilience.


Key Takeaways

  1. Assume capability will spread faster than caution. Open models lower the barrier to advanced AI, which is good for innovation but also for misuse. Plan for rapid diffusion, not slow adoption.

  2. Treat persuasion as an attack surface. Phishing, voice fraud, and executive impersonation will become more scalable and more personalized. Strengthen verification procedures, not just awareness training.

  3. Move from detection to verification. In a world of synthetic content, humans cannot inspect everything. Build out of band confirmation, transaction limits, and multi step approvals for sensitive actions.

  4. Design defenses for adaptation, not static threats. Malware and scams can now mutate quickly. Security programs need layered controls that remain effective even when the payload changes form.

  5. Balance openness with safety scaffolding. Open models are not a mistake. But if capability is going to be widely distributed, safety standards, access controls, provenance tools, and organizational process must be distributed too.


The future problem is not fake intelligence, it is unverified reality

The deepest shift here is not that machines can now write, speak, or generate images. It is that the boundary between real and synthetic is becoming too cheap to trust at face value. Once anyone can produce a convincing email, voice note, image, or code fragment, reality itself becomes a dependency that must be verified.

That sounds alarming, but it also clarifies the task ahead. The goal is not to halt progress, because that is neither realistic nor desirable. The goal is to build institutions, workflows, and technologies that can survive in a world where intelligence is abundant but authenticity is contested.

Open models show us what happens when power diffuses. Security threats show us what happens when adversaries get that same power first. The collision of those two trends forces a hard truth: the next era of AI will not be won by the most capable model alone, but by the ecosystem that can make capability safe enough to trust.

We should not ask whether open intelligence is good or bad in the abstract. We should ask a sharper question: can we create systems where the benefits of diffusion outrun the harms of exploitation? That is the real contest. And it is already underway.

Sources

← Back to Library

Hatch New Ideas with Glasp AI 🐣

Glasp AI allows you to hatch new ideas based on your curated content. Let's curate and create with Glasp AI :)

Start Hatching 🐣