The first serious AI incident will likely occur inside frontier AI labs due to testing errors or insider actions, not through open models.
Closed models can be leaked by a single person with access, making them as risky as open models, while open models are released after testing and lag behind API-accessible models.
Open models can be trained on datasets ablated of dangerous domains like biology, limiting their risk even if highly capable.
Restricting access to LLMs for cybersecurity creates a defensive gap, as open-source maintainers cannot find bugs while adversaries can fine-tune open models.