The first serious AI incident will likely occur inside frontier AI labs due to testing errors or insider actions, not through open models.
Closed models can be leaked by a single person with access, making them as risky as open models, while open models are released after testing and lag behind API-accessible models.
Open models can be trained on datasets ablated of dangerous domains like biology, limiting their risk even if highly capable.