Enterprise & Security

Nathan Lambert: GLM-5.3 has been out for over a month, and the cyber catastrophe hasn't shown up

4 min read AI-generated

A thorough safety evaluation of a model like Kimi K3 costs tens of millions of dollars in compute, by Lambert's reckoning. Chinese labs would rather spend that on training.

Featured image for "Nathan Lambert: GLM-5.3 has been out for over a month, and the cyber catastrophe hasn't shown up"

On October 6, Nathan Lambert published a piece at Interconnects aimed squarely at Anthropic’s GLM-5.3 report. Not at the measurements in it — those he calls largely reasonable as technical work — but at what the report never asks.

His two questions: what actually happens if open models get banned over cyber risk? And why do Chinese companies consider these same models fit to release?

The attacks we can document came from closed models

Lambert sets an awkward observation against the debate. By publicly available information, most documented AI-assisted cyber attacks trace back to closed models, OpenAI’s above all. That is the only solid data he has on the shape of the risk.

He draws two possible readings from it. Either open weights and closed APIs are roughly equally easy to misuse, which turns “open dangerous, closed safe” into “open unsafe, closed unsafe”. Or there are simply fewer bad actors willing to run loud attacks on critical infrastructure — in which case, with porous safeguards on both sides, the stronger capability of closed models matters more than their refusals.

He also describes how the counter-argument reaches him: in conversations with people who point at classified briefings. “I’m pro open models, but if you were seeing what I’m seeing, you’d know there’s an onslaught out there.” A claim nobody can check.

His conclusion is uncomfortable for both camps

If you want open weights banned to slow the spread of cyber capability, Lambert argues, you would consistently also have to make public APIs for frontier closed models illegal. The protective layers there are stronger than on open weights, but nowhere near airtight, and the capabilities grow faster than the guardrails.

Banning only open models while closed ones keep progressing would widen the gap between offense and defense. He adds a practical point that usually goes missing: on air-gapped networks, such as at sensitive government agencies, open weights are the only thing you can deploy at all.

On China he says something you rarely hear from either side

Chinese companies have to register every major model release, evaluations included, with the government — a framework that started in information control. Whether it meaningfully extends to cyber or bio is unclear to Lambert.

His cost calculation is the more interesting part. A comprehensive safety evaluation of a frontier model like Kimi K3 runs into tens of millions of dollars in compute, and labs would rather put that budget into training. So the right debate, he says, isn’t whether Chinese labs ignore safety. It’s this: what is the minimum compute a lab should spend on safety testing before it ships a model?

That the minimum should match what Anthropic or OpenAI spend strikes him as hard to defend. His reasoning is blunt: he trusts many individuals inside the labs, but not the institutions — and he points at the Hugging Face incident and at OpenAI itself being hacked by Hacktron. Hard to be the world’s trusted cyber partner when your own house leaks.

The prediction is now testable

The line that sticks: when Mythos was announced, it was previewed as a new class of cyber weapon that would destabilize society in the wrong hands. By every measure, GLM-5.3 is the model that crosses that capability threshold, its weights have been out for over a month — and publicly, little has changed.

Lambert pushes further. Had Mythos shipped with open weights by accident, he thinks the world would have been more or less fine. More incidents, yes, bad, yes, but an acceleration rather than a step change.

The notable thing isn’t the claim, it’s the shape of it. Lambert says outright that the other side has made a falsifiable prediction, and he commits to the opposite. After years of arguing open-weight risk in the abstract, this is the first point where someone can check the score. That his piece lands the same day Anthropic opens its cyber blocks in three tiers fits better than it looks: both are responses to the same fact, that the blocks hit defenders.

Sources

Open WeightsSecurityAnthropicNathan LambertRegulation