Antirez: the real AI risk is inside the labs

A sharp counter-position to Anthropic's open-weights policy post, arguing that the most serious AI risk surface is concentrated inside frontier labs rather than in public releases.

Original source

Logged at IST: 2026-07-28 18:18 IST

What it is: Antirez responds to Dario Amodei's Anthropic post on open-weights models.

Gist: Antirez says he does believe AI may become very dangerous, but he thinks open weights are the mildest part of the risk picture. His central claim is that the first serious incident is more likely to happen inside a frontier lab: during private testing, through employee or privileged-user misuse, or through a leak of closed model weights that are only a few TBs of data.

He also argues that open releases generally come after testing and after similar capabilities have already been available behind an API. For cyber, he flips the risk framing: limiting access to defensive and bug-finding LLMs can strengthen the “LLMs as a weapon” problem because maintainers outside special programs get less help than better-resourced attackers.

The broader governance point is that once models become dangerous enough, safety should not be left to a single company’s internal evaluation. Antirez wants common rules and a joint AI safety organization recognized by governments. He is also skeptical of framing China as the decisive risk and argues that slowing AI has its own hidden security cost if medical and scientific benefits are delayed.

Newsletter angle: Strong companion to the Anthropic piece. Anthropic emphasizes the irreversibility of open-weight releases; Antirez shifts the danger surface back to frontier labs, leaks, private model access, and unelected CEOs making civilization-scale calls.