The Open Model Paradox: Why Making AI Easier to Build Makes Security Harder to Trust

Ante Gojsalić

Hatched by Ante Gojsalić

May 08, 2026

9 min read

87%

0

The uncomfortable truth behind the AI boom

What if the most important security shift in AI is not that models are getting smarter, but that they are getting cheaper to reproduce?

That question sounds technical, but it is actually political, economic, and deeply practical. When high performing language models can be built from public data and released openly, the center of gravity changes. Capability stops being trapped behind a handful of closed labs. It becomes mobile, copyable, and easier to improve. That is a triumph for research and competition, but it also changes the geometry of harm.

The old security model assumed that power was scarce. Scarce power is easier to monitor. Scarce power is easier to regulate. Scarce power also tends to move slower than defense can adapt. Open, efficient models break that assumption. They do not merely increase capability, they compress the cost of capability. And once that happens, the attacker and the defender no longer compete on the same terrain.

The deepest risk in modern AI is not that one model becomes too strong. It is that powerful model behavior becomes cheap enough to copy.

From scale to spread: the real transformation

For years, AI debates revolved around scale. Bigger models. More parameters. Larger datasets. More compute. But the more interesting shift is not just scale, it is diffusion. A model that once required extraordinary resources can now be trained, fine tuned, or replicated using public data and accessible tooling. That matters because technological history shows a consistent pattern: the danger of a tool often rises after it becomes mundane.

Think of encryption. Once exotic, it became standard infrastructure. That was good for privacy, commerce, and security. But the same logic applies in reverse when the tool is designed for persuasion, automation, or code generation. If the average attacker can access capabilities that used to require a specialized team, then the long tail of malicious actors gets dramatically more dangerous.

This is where the open model story becomes unsettling. Openness is not a side issue. It determines who can participate in the next wave of capability. A system trained on public data and released to the world democratizes invention, but it also democratizes misuse. The same properties that make open models scientifically exciting, reproducibility, transparency, broad access, also make them operationally portable. That portability is the crux of the problem.

The security question is therefore not whether AI can be used for harm. Of course it can. The question is whether AI changes the economics of harm so thoroughly that older defenses begin to look ceremonial.


Why attackers usually win first

Every major defensive system has a lag. Defenders must understand the threat, update policy, instrument detection, deploy fixes, train staff, and absorb false positives. Attackers need only find one opening. That asymmetry already exists in cybersecurity. AI intensifies it.

A phishing email used to require language skill, local knowledge, time, and perhaps a bit of luck. Now a campaign can be personalized at scale, translated instantly, adapted to region, tone, and profession, and tested repeatedly. Voice cloning and synthetic video turn social engineering from an annoying scam into something closer to a real-time impersonation engine. A fake CFO call can sound urgent, familiar, and convincingly stressed. A fake landlord, IRS agent, recruiter, or bank representative no longer needs a perfect script, just enough realism to beat a distracted human.

The same goes for malicious code. Security teams have long relied on signatures, patterns, and the assumption that malware families share stable traits. Generative systems weaken that assumption. If code can be quickly rewritten into many variants, then the defender’s job becomes chasing shadows that are designed to move. It is not that AI invents malware from nothing. It is that it makes variation cheap, and variation is what defeats many traditional defenses.

This creates a grim but important insight: attackers do not need AI to be perfectly reliable. They need it to be useful enough, frequent enough, and inexpensive enough that the total volume of attempts overwhelms the human environment. In other words, AI does not need to make each attack brilliant. It only needs to make the average attack scalable.

That is why the attacker-defender dynamic is so lopsided. Defenders must raise the floor everywhere. Attackers only need to find one crack and can keep trying at near zero marginal cost.

The real danger is not intelligence, it is industrialization

When people imagine AI threats, they often picture a superintelligent system acting like a mastermind. That is dramatic, but it misses the more immediate danger. The near term problem is not autonomous genius. It is industrialized deception.

Industrialization has a pattern. First, something artisanal becomes reproducible. Then reproducibility drives down cost. Then cost reduction expands distribution. Once distribution becomes broad enough, the bottleneck shifts from quality to throughput. AI is taking social engineering, malware adaptation, and influence operations through that same pipeline.

Consider the difference between a bespoke scam and a spam factory. A handmade scam may be clever but limited. A factory can generate millions of variations, A/B test them, and improve the conversion rate over time. That is the truly new feature of generative AI in security: it makes the adversary more like a data-driven growth team. The threat is not just attack content, it is attack optimization.

This is why calls to simply “pause” innovation are unlikely to solve the problem. The capability is already too distributed, too strategically valuable, and too economically attractive. If one actor pauses, another advances. If one model is withheld, another will be trained. Security policy must therefore assume competition, not abstinence. The question is not how to stop the world from building. The question is how to build systems that are resilient when the world keeps building.

That is a more difficult question, but also a more honest one.


A better framework: AI changes the cost of pretending

The most useful way to understand the security shift is to stop thinking about AI as a source of truth and start thinking about it as a cost reducer for plausible lies.

That phrase captures the heart of the issue. The internet already suffers from too much uncertainty. We do not know whether an email is real, a voice message is authentic, a profile is human, a document is altered, or a code sample is benign. Generative AI lowers the cost of creating convincing surface area. It does not just generate content, it generates credibility cues.

This matters because trust in digital systems often relies on heuristics, not verification. We trust a familiar tone. We trust a grammatical email from the right domain. We trust a voice that sounds stressed. We trust a code snippet that resembles something seen before. AI attacks these heuristics directly. It specializes in plausible mimicry.

So the true battle is not between humans and machines. It is between verification and imitation.

That leads to a useful mental model: every organization should ask where it currently relies on surface plausibility instead of cryptographic, procedural, or multi channel verification. If a process can be tricked by a persuasive text, a realistic voice, or a polished document, then AI has already found the weak point. The attack does not need to be technically sophisticated. It only needs to look normal long enough to succeed.

This is why some of the most important defenses will not be about using AI to fight AI, at least not only. They will be about making trust more expensive to fake. That means stronger identity verification, better approval workflows, tighter change control, and more friction at high-risk decision points. In a world of cheap imitation, the organizations that survive will be the ones that can prove, not merely infer, authenticity.

The future of security may depend less on detecting lies and more on making truth harder to counterfeit.

What resilience looks like in an open model world

Open, efficient models do not force us to choose between innovation and safety. But they do force a more mature idea of safety. We should stop imagining safety as a wall and start imagining it as a set of immune responses.

An immune system does not prevent all exposure. It detects patterns, learns from attacks, and responds proportionally. That is a better metaphor for AI security than the fantasy of perfect prevention. In an open model world, exposure is inevitable. The goal is fast recognition, graceful degradation, and recovery.

That implies several design principles:

  1. Assume imitation is cheap. Any workflow based on trust by appearance is vulnerable.
  2. Raise the verification burden at high stakes moments. Payments, account recovery, permission changes, and code deployment need stronger checks.
  3. Instrument the edges. Email, voice, chat, and customer support are now security front lines, not just communication channels.
  4. Expect attackers to iterate. A single block or filter is not a solution when adversaries can generate endless variants.
  5. Treat open access as a force multiplier. Openness brings research gains, but it also means defensive tools must be built with the assumption that adversaries can obtain the same primitives.

There is also an organizational mindset shift required. Security teams should stop asking only, “Can this attack happen?” and start asking, “How quickly can this attack be replicated, personalized, and scaled?” That second question is where AI changes the game.

A malicious email is not dangerous because it is convincing once. It is dangerous because the model can produce ten thousand convincing versions, each tuned to a different target. Likewise, a malicious code sample is not merely a problem because it exists. It becomes dangerous when it can be continuously rephrased, repackaged, and reintroduced faster than the defense can classify it.

In that sense, AI security is a systems problem, not a content problem. Content can be copied endlessly. Systems can be hardened.


Key Takeaways

  • Do not frame AI security as a battle over smarter models. Frame it as a battle over the cost of imitation, persuasion, and repetition.
  • Audit your organization for plausibility-based trust. Any process that can be fooled by a polished email, voice call, or document is now a security liability.
  • Add friction where the stakes are highest. Identity resets, money movement, code deployment, and privilege changes should require multi channel verification.
  • Design for adaptation, not perfection. In an open model world, the defense that learns fastest will matter more than the defense that claims certainty.
  • Assume attackers will industrialize quickly. Your plan should account for automated personalization, rapid code variation, and continuous probing at scale.

The future belongs to systems that can prove themselves

The most profound consequence of open, efficient AI models is not that they make intelligence more available. It is that they make authenticity more fragile. Once high quality generation becomes abundant, the burden shifts from producing convincing artifacts to proving they are real.

That reframes the entire debate. The question is no longer whether AI will be used by bad actors. It already is, and it will be. The question is whether our institutions, businesses, and digital systems can evolve from a trust economy into a verification economy without grinding innovation to a halt.

That is a difficult balance, but it is the right one. Openness should not be treated as a mistake, and fear should not become an excuse for stagnation. But neither should enthusiasm blind us to the fact that every reduction in the cost of intelligence also reduces the cost of deception.

The next phase of AI will not just reward those who can build the most capable models. It will reward those who can make truth expensive to fake.

Sources

← Back to Library

Hatch New Ideas with Glasp AI 🐣

Glasp AI allows you to hatch new ideas based on your curated content. Let's curate and create with Glasp AI :)

Start Hatching 🐣