← Feed
@DaveMWilburn@infosec.exchange
Post #4144710
2026-07-27 18:22 UTC
@mttaggart@infosec.exchange
I think the issue is more around the infeasibility of managing an embargo that large with so many stakeholders with conflicting requirements. It's similar to the problem of closed CTI sharing circles.
You know that the Trump regime is going to demand access, and also have opinions about who else gets access and who doesn't (mostly revolving around who grovels and pays them enough). And other governments with sometimes-conflicting interests will also demand access. And defense contractors, spy agencies, law enforcement, research institutions, infosec vendors, software vendors, etc.
If your circle of who gets access to frontier models with unrestricted guardrails gets so large that it includes the security team from a company like Hugging Face, then who DOESN'T get access? You're maybe talking about millions of people by that point.
How would you vet any of them? You'd need to stand up a whole department of 24x7 support personnel dedicated to managing this kind of access, probably subcontracting with a major data broker for identity verification, plus active monitoring for abuse.
And if we've learned anything at all from the Flock scandal, it should be that a user base that large is going to have a LOT of people engage in misconduct. At least some of that misconduct will render the embargo functionally useless.
Replies (1)
-
@DaveMWilburn@infosec.exchange I am confused why we're talking specifically about getting access to no-guardrail models when that's not what happened. Hugging Face wasn't enrolled in Anthropic's Cyber Verification Program, which is a far cry from "no guardrails." Whether the specific implementation of the CVP is effective, well, anecdotally it's still rather cautious. But the onboarding process is what it is. I don't see that as the direct issue here.
If you're talking about no-guardrails models like the one OpenAI created and getting access to that, well, I agree that nobody should have access to them. I'd much rather we didn't build them at all. But here they are.
And if states are interested, as they obviously are, then the solution to access should not be the domain of corporations.
Fundamentally we need to decide if these things are weapons or can be used as weapons, or if they're not. And if they are, we need a system of laws and policies to handle them.
Will that happen before major harm? I'm not optimistic.
Open ##4144709