News · 2026-08-23
OpenAI says open models will enable persistent cyber-attacks
OpenAI's chief global affairs officer, Chris Lehane, told the Guardian on August 23 that freely downloadable AI models -- many developed in China and, he says, only months behind closed frontier systems -- will soon let attackers run continuous, automated cyber campaigns that defenders will need comparably strong models to repel. He made the argument days after OpenAI paused development of its most advanced internal models over safety concerns, and used it to call for a U.S. law making pre-release safety proof mandatory.
Key facts
- Lehane's warning: attackers with open models will be able to mount "ongoing, persistent attacks," requiring "really superior models to fend them off."
- OpenAI announced a pause in development of its most advanced internal models this week, according to the same reporting.
- His policy ask: a national U.S. law under which models cannot be released without proving a level of safety, with a legislative window he places in early 2027.
- Primary source: the Guardian interview, August 23, 2026.
The technical claim underneath the politics is worth separating out. Lehane's concern is not that a model can write an exploit -- that has been true for a while, and five U.S. agencies recently warned that AI-written scripts are already probing American industrial controllers. His concern is about persistence. A hosted model has a provider who can rate-limit an account, refuse a request, or shut it off. A downloaded one has none of that. Once weights are on a machine, an attacker can run them against a single target continuously, for weeks, at whatever pace their hardware allows, and nobody upstream can intervene.
The analogy is the difference between renting a locksmith and owning the tools. The rented locksmith has a business to protect and can decline the job. The tools do not decline anything.
Lehane was blunt about how that sounds: "People are going to be able to access these open-source models and be able to have ongoing, persistent attacks on you, and you're going to need to have really superior models to fend them off and defend yourself. That's not necessarily going to make the public feel great about things. It is just the reality of where we're going." He added that the most advanced unreleased models appear to be improving cyber offence faster than defence -- which is the actual reason he thinks legislation is urgent rather than desirable.
The proposal is specific. He wants a national statute creating "mandatory required safety standards," under which "you would not be able to release or deploy models unless you're proving and guaranteeing a level of safety before they get out into the public," with the pause mechanism written into the process rather than left to company discretion. He puts the realistic legislative window in the first part of next year, with a new Congress. The current U.S. approach is a June executive order encouraging pre-deployment testing of frontier and open-weight models -- voluntary, and criticized for opacity. Google DeepMind president Demis Hassabis has proposed a standards body modeled on the financial industry's self-regulator, an idea Anthropic's Dario Amodei has backed.
The conflict of interest is obvious enough that it should be said out loud: a company that sells closed API access is arguing that downloadable models are dangerous, weeks before an expected market listing at a reported valuation above $850 billion. Both frontier labs have filed to go public, and mandatory pre-release proof is a compliance burden that falls hardest on the people who publish weights for free.
The sharpest counter-argument in the same piece does not come from open-source advocates but from safety researchers who think the framing is self-serving in the other direction. David Krueger, a former founding director of the UK's AI Security Institute, said: "Nobody should be building more powerful AI systems, because we don't know how to control them, align them, and look inside and see what they're thinking well enough," calling the labs' approach "unconscionable" and adding that they are "being really reckless and increasingly taking their hands off the wheel." Daniel Kokotajlo, who left OpenAI in 2024, said frontier lab leaders have "painted the world into a corner."
Why it matters: the case for restricting open-weight models has usually been made in the abstract. Framing it around automated, unstoppable, always-on intrusion is the most concrete version yet -- and the most likely to move legislators.
The caveat is that the claim is a projection, not a measurement. Nobody has published a study showing that open-weight models sustain persistent campaigns better than closed ones, and the strongest documented AI-enabled intrusions to date have run on commercial models. Lehane's response to the recklessness charge -- "the fact that we've actually hit pause on this stuff speaks for itself" -- is also the only evidence offered for it.
Key questions
What did OpenAI actually pause?
Why does Lehane single out open-source models?
What law is he asking for?
Cite this
APA
Ground Truth. (2026, August 23). OpenAI says open models will enable persistent cyber-attacks. Ground Truth. https://groundtruth.day/news/openai-says-open-models-will-enable-persistent-cyber-attacks.html
BibTeX
@misc{groundtruth:openai-says-open-models-will-enable-persistent-cyber-attacks,
title = {OpenAI says open models will enable persistent cyber-attacks},
author = {{Ground Truth}},
year = {2026},
month = {aug},
url = {https://groundtruth.day/news/openai-says-open-models-will-enable-persistent-cyber-attacks.html}
}
Comments are replies to this story on Bluesky — reply with any Bluesky account to join in.