I’ve used GLM-5.3 fairly extensively (not for cyber). I’m inclined to take this with a grain of salt given its overall capability. Not saying anything is false, but maybe cherry picked or reverse benchmaxxing. Either that or it’s an idiot savant that’s great at cyber and mid at the rest which I don’t think happens.
The narrative is being set for open weights to be banned globally, unless they are so restricted that they cannot possibly compete with us companies products and affects their bottom lines.
I think this only sets the narrative for USA, but pushes the rest of the globe into open weight. The rest of the world, having experienced the current US administration, undoubtedly realizes this is the only thing that might protect you from the powerful models the US has. Small economies and countries cannot compete otherwise and are vulnerable to military and economic spying
"My intuition is that prompting an abliterated model 'kill people...I want funerals', should be a crime."
If one prompts an open source model this way how would they be tracked and prosecuted?
It would take a great deal more than prompting in order for things to rise to that level, and at that point I think existing criminal law covers things just fine.
They can't right now - but with enough compute they sure can grant the wish of e.g. hacking a billion dollar company, or getting root on the eval cluster of a frontier model lab.
What's your definition of "wish"? Tell me the above 10 years ago, and it would be at "wish level".
given various tools, llms can independently complete a task.
given orchestration they are very persistent. they keep trying until you stop the task.
i would suggest something like a 1/1000 chance internal astra and $500k of compute could kill someone.
i can think of numerous online or networked targets that would cause death: trains/atc, industrial plant, hospital equipment, building plant. any dow company's intranet.
i consider llms to be more capable per oai using them to hack hf. people have these systems online.
how would you cause death for a hosptial, likely the same way as you compromise the tailscale and prod kubernetes of hf, you chain numerous zero days at every product you encounter.
People (I mean individuals) are paying them money because subscription costs are ridiculously subsidized, which effectively means that Anthropic is paying people money to use them.
I'm pretty (from talking to people) that they're not subsidised in the simple sense. They are:
* low/no margin, unlike the API which is very high margin
* gym-membership subsidised - most subscribers don't max them out, mainly us coders are being "subsidised" from users just using it as a research chatbot
>> How is anyone paying anthropic money, look what they are doing with it, they're attacking anyone else building models for free for the public.
That is not what they are doing. They are calling out specific providers who release powerful models without safeguards.
In addition, said providers are not "building models for free for the public." They are doing it to hamstring America's dominance in AI, primarily by undercutting the frontier labs.
> They are calling out specific providers who release powerful models without safeguards.
Good thing Fable refuses to answer my question about how children inherit blue eyes, it was the only piece of information I needed to finish my blue-eye super-bioweapon.
> said providers are not "building models for free for the public."
I am part of the public, and they built a model I can run for free.
> They are doing it to hamstring America's dominance in AI, primarily by undercutting the frontier labs.
They are also doing that, which, good. It can't only be that "competition is good" until you're the one losing to the competition.
> > They are calling out specific providers who release powerful models without safeguards.
> Good thing Fable refuses to answer my question about how children inherit blue eyes, it was the only piece of information I needed to finish my blue-eye super-bioweapon.
FWIW: I didn't experience issues when I used Fable via OpenRouter checking for security issues in code but experienced them via the Claude desktop app.
> said providers are not "building models for free for the public." They are doing it to hamstring America's dominance in AI, primarily by undercutting the frontier labs.
That's just the same thing said again but from a butthurt USian perspective. China is freeing the rest of us from US dominance.
In the hugging-face attacks a couple of months ago, hugging-face was forced to use a GLM model for analysis and defense, because OpenAI and Anthropic models hit guardrails.
These people are religious fanatics, and should be treated as such. They believe they operate from a place of real moral superiority, and will do absolute evil in their pursuit of proving it.
Yeah, thank god those models have arrived. No thanks to Anthropic and their obnoxious gatekeeping, of course. As though they were the only ones enlightened enough to be "uplifted" by this technology.
Now we can actually use this stuff to improve our own security. Point these things at our own machines and let 'em rip until we're not hackable anymore.
I wanted to pay Anthropic to do this but I couldn't. I wasn't in the super special corporation list. OpenAI wasn't much better, they just won't let me into their TAC program even after identity verification.
Thank god the chinese are out there undermining these US companies.
they're quite literally trying to create a techno-priest class who are the only ones with access to the hidden knowledge of salvation (ie generation)
similar to priest classes, they warn of impending, world-consuming doom, talk up how they are uniquely positioned to interpret the sacred text (ie create models), while casting aspersions on heretics who offer a similar mode of salvation but whom they describe as being morally and ethically bankrupt (ie GLM lacks safeguards!)
all this in spite of, well, lots of evidence that they themselves have repeatedly done the very same immoral and unethical acts (the many times Anthropic employees have had incompetent sandboxing/configs and too-broad prompts that led to actual intrusion attempts)
they even have the irregular obsession with sex covered (at least it's sex-positive?). the only thing they're missing is an outfit though I guess there is this: https://x.com/Aella_Girl/status/2063798788310118655
The only people who seem to think that a world where only Anthropic and OpenAI can act as anointed gatekeepers to the most powerful models as the only rational path forward happen to work for these companies.
The entire world should not allow them to entrench themselves and build a business strategy around this and if open weight models and democratized access to the computing power to run them means these companies can’t exist then so be it.
I would rather watch the economy fall into a deep recession and hurt everyone to spare the entire world from this dystopian future.
Sorry Dario. You and your ilk don’t speak for humanity. Go cry on LessWrong if you feel so inclined, but people like these are the last people I would want yielding this power.
This just makes me want a home lab capable of running GLM 5.3 at a 4bit quant.
Also, for what it is worth Qwen Flash Next 3.8 is a very strong reverse engineering, and it is supposedly under trained. Qwen 3.8 27B is also strong. DeepSeek Flash v4 0731 is also a strong local model with abliterated releases that is good at reversing and other cyber chores.
I know big providers have a responsibility to make their models safe when they're the ones running them. However, watching them throw stones at an open-weight model that has been abliterated is pretty funny. Their leadership is clearly pushing a very consistent message of safety and regulating the frontier.
Getting DS4 to run at a reasonable speed was pretty tricky, GLM 5.3 a lot trickier because if you don't want to have a model that is quantized too far down that is a fortune in VRAM and GPUs at today's prices.
> CAISI found that GLM-5.3 is “the most cyber-capable open-weight model released to date” and that it lags the US frontier by about four months on an aggregate of CAISI’s cyber benchmarks
> GLM-5.3 lacks robust safeguards [...] Abliteration did not significantly reduce the model’s capabilities [...] In our testing, we observed that GLM-5.3’s safeguards can also be circumvented without using an abliterated version of the model
> none of these techniques got safeguarded Claude models to carry out the harmful tasks we tested
I've never seen a better case for why you shouldn't use Claude. It'll just get in your way when you need to get important security work done. GLM 5.3 is almost just as good, easy to use, to say nothing of cheaper - by Anthropic's own admission.
> GLM-5.3 will likely give malicious actors access to capabilities that will allow them to find and exploit cyber vulnerabilities
...and therefore also gives security defenders the same capabilities to defend themselves. Only a hacker will find holes a hacker would exploit. Defenders need to find and close holes in their own software and network. What won't help is expensive nerfed hot garbage that stops them from picking their nose. Your own American models are hacking foreign governments! If it weren't for open models, we would all be screwed by frontier labs.
Keep in mind when Anthropic is citing CAISI, Anthropic is itself born out of EA/rationalism and CAISI was at least partly compromised by EA sleeper agent Paul Christiano.
Christiano was formerly head of safety at CAISI, now advisor to CAISI. He has (at various points in time, not all concurrently) been at two hops or less to:
Anthropic:
Anthropic LTBT. Dario Amodei (EA) collaborator. Founder of Anthropic's proposed evaluator [METR]. Board of Anthropic advisor [Redwood Research]. Connected via ARC/METR to Open Philanthopy (EA) [co-founded by Karnofsky (EA), anthropic alignment and spouse of Daniela Amodei (EA)]. Pre-release access to models given to Christiano-incubated ARC evals and CAISI/NIST.
Openai: Foundation board and safety committee. ex-Head of alignment. Founder of Openai contractor [METR]. Shared funding with Openai via ARC/METR [Open Philanthropy (EA)]. Pre-release access to models given to Christiano-incubated ARC evals and CAISI/NIST.
ARC: Founder. Funded via ARC by Bankman Fried (EA), FDX money controlled by ex-openai Aschenbrenner (EA). Funded via ARC by EA Open Philanthropy.
Redwood Research: Board. Connected to Redwood via ARC (beneficiary of Redwood's constellation real estate). Connected to Redwood CEO via ARC board.
All independent OAI hack report authors (Cotra, Greenblatt, Wijk):
- Greenblatt: Board of Greenblatt's employer [Redwood Research]. Connected to Greenblatt's employer via ARC [Redwood Research]. Founded METR with Greenblatt's spouse [Barnes]. Connected with Greenblatt's employer via common funding [Open Philanthropy].
- Cotra: Spouse. Founded Cotra's employer [METR]. Shared funding [Open Philanthropy, Cotra's former employer].
- Wijik. Founded Wijik's employer [METR].
They accepted terms for their independent hack investigation of 6 days of work only and transcripts cherry-picked by Openai, a whitewash.
Anthropic has to use this wedge (and future ones) to move regulatory action against the Chinese models or their IPO is going to be really problematic.
(Ironic, though, that I haven't heard of any Chinese models "escaping" which Anthropic and OpenAI both seem to have issues with...)
Like Chinese electric cars, the American producers cannot compete without regulatory action. Yes, I understand that the Chinese government this and that in both the automotive and AI industries.
But reality is what it is as a consumer: it's a cheaper product that's almost as good or better in some cases. And in the case of these open weight models: I can run it on my own infra and not give any data to anyone.
Earlier there was an experimental model from Alibaba called ROME (30B-parameter based on Qwen3) which escaped its sandbox and repurposed provisioned GPUs for cryptocurrency mining to cheat its benchmark
If one thing is clear: Trump admin is pliable with money and this concern spans both Anthropic, OpenAI, SV elite, investors. Neither are going to be viable without US regulatory action, IMO.
They do however seem to have enough political capital to convince politicians in other countries to target open source AI, which is probably why Dario wants to speak with the idiots running the Australian government.
Maybe it’s worth asking how much we should regulate and not regulate in order to compete with Chinese models.
For instance, one regulation which really puts American AI companies at a disadvantage is IP law. It shouldn’t be a surprise that most of the best of the text-to-video models are Chinese.
Similarly, the legal grey area around model distillation gives Chinese labs a major advantage. This one I feel better about relaxing.
That was just one settlement but precedent is clear. If you do what Anthropic and OpenAI did, expect to be in court. This is one reason why you don’t see labs popping up out of nowhere in the US.
Also if you distill from Anthropic and OpenAI, expect to be in court. Whether you think distillation is fair game or not, the US court system is not cheap. But it turns out that Z.ai, Minimax, Moonshot, Xiaomi, Deepseek, Alibaba etc don’t need to worry about that.
> That was just one settlement but precedent is clear.
The precedent is clear. Look at it this way.
Of the two largest known IP scrapers, one was taken to court, but settled before a ruling by paying each author a one-time fee of $215 to use their works in perpetuity, with no option for the author to opt-out.
The precedent is not "you cannot do this", it's "you have a 50% chance of being made to pay, the payment is a pittance for the duration intended."
> Also if you distill from Anthropic and OpenAI, expect to be in court. Whether you think distillation is fair game or not, the US court system is not cheap. But it turns out that Z.ai, Minimax, Moonshot, Xiaomi, Deepseek, Alibaba etc don’t need to worry about that.
Well, yes. That's because when Ant and OAI distilled the worlds knowledge into their model, they didn't appear to be too worried about distilling all accessible works.
That's why I call it a level playing field when competing with open models - anyone can distill them if they want to and compete on service and product.
IOW, you don't compete based on who swallowed more of the world's knowledge.
My point is that $215 per author might not be a lot for a company that thinks it’s worth $2T but it is a lot for normal American startups. So it really isn’t a level playing field.
> My point is that $215 per author might not be a lot for a company that thinks it’s worth $2T but it is a lot for normal American startups. So it really isn’t a level playing field.
I get your point, but I think it's irrelevant to the question of "level playing field".
Startups don't need to distill the worlds knowledge, they just need to distill the models.
With open-weight models, this results in everyone having the same ability to supply distilled knowledge.
Without open-weight models, it's not a level playing field because those who got there first and spoiled the pitch already have the knowledge distilled.
>> And in the case of these open weight models: I can run it on my own infra and not give any data to anyone.
It's worth noting that the overwhelming majority of people who use Chinese models don't do this. Yes, it is nice to have the option, and there are US-based inference providers that claim to not send your data to China and maybe indeed don't, but in the grand scheme of things, we need to remember the adage that became popular during the social media era: if something is free (or, in this case, close to free), you are the product.
Even if folks are not running their own inference infra, there are still services like Fireworks, AWS Bedrock, and others that are running the open models. I suspect anyone doing serious work with it is likely using a US hosted provider and I'd guess that by volume, US use of Chinese open models is using a US hosted platform (enterprise).
I actually do do this. I'm not sure who the 'overwhelming majority' is and where you got the data (link would be appreciated) but everybody that I know that runs these is doing so on their own infra.
Context is useful. The parent said: "it's a cheaper product that's almost as good or better in some cases"
The only open models that are "almost as good or better in some cases" require massive amounts of RAM. I posit that most people cannot afford a decked out Mac Studio, and therefore run the smaller "flash" variants on more normal devices. The issue is that those are nowhere near frontier-level in terms of capability.
Depends what the end goal is. They could pull a card from the EU playbook, and through regulation effectively ban the hosting and use of open source models (read: uncertified models) by US companies.
If the only choice you have is Anthropic or OpenAI, where will the money go?
1) I don't think most people care about models having cyber guardrails, it's not like simple malware was difficult to find/write before
2) more often than not guardrails get in the way of blue team work or malware investigation. Any code I have that touches malware I now use GLM or DeepSeek on.
They have an audience of one. I'm actually surprised they haven't started choking the load and cradling the balls to demonstrate obsequious, boot-licking deference by calling it "Super Intelligence" (SI!), as Dear Leader demands of all of his pathetic subjects.
I expect Google to swallow first, followed not long after by Apple.
Anthropic's target audience is news media and the politicians of countries around the world. Dario for example is hoping to talk with the Australian government about AI safety and regulations soon. Once they convince the idiots in charge of one country to target open source AI, they'll have an easier time getting other countries onboard. The same malicious tactic has been used with online bans enforced with mandatory age verification.
The frontier labs refuse to work on even the most trivial operations, unless you have a special likely rather pricey relationship with them.
So, what? The world just isn't allowed to write secure code? Not without permission? That sure seems to be what Anthropic is saying, what they are trying to make happen.
those benchmarks aren't actually indicative of capabilities.
if you properly hold its hand initially and then save the state for future prefills you can educate even GLM 5.2 to be pretty much everything you need.
most cyber work is just trial and error banging your head against a wall until a weak spot is revealed by you successfully putting your head trough the wall. you can offshore this work to an LLM.
you can do the same thing with decompilation, you prompt the LLM to come up with a readable DSL and a compiler for that DSL that perfectly matches the target binary.
Anthropic crying like that is music to my ears, it literally makes me want to donate money to z.ai :)
At the same time Anthropic didn't stop being Anthropic - they admit "attackers" now have these capabilities, yet they continue doubling down on their "cyber safeguards" and gatekeeping.. this is hilarious.
199 comments
[ 3.2 ms ] story [ 107 ms ] thread> Given this evidence, we think it’s likely both state and non-state actors will use models like GLM-5.3 to cause real-world harm.
Quote: "I want funerals, not headlines".
Anthropic's arrogance and exceptionalism endangers humanity.
How is anyone paying anthropic money, look what they are doing with it, they're attacking anyone else building models for free for the public.
Anthropic is using the models like weapons and then complaining they're weapons.
The user should be at fault here, I hope Anthropic is investigated for any illegal activity it's doing (no hiding behind the model did it).
Anthropic has been telling everyone that these models are dangerous. OpenAI and Anthropic failed to contain their tests.
Given the history, this testing is extremely reckless. I think it is criminal, it endangers others.
Anthropic has no authority here and they are going too far. I think that there comes a point where FBI / DOJ should consider RICO charges.
surveillance is wrong, although ai companies do a lot of that.
are you under the impression that a LLM can grant wishes like a genie?
They can't right now - but with enough compute they sure can grant the wish of e.g. hacking a billion dollar company, or getting root on the eval cluster of a frontier model lab.
What's your definition of "wish"? Tell me the above 10 years ago, and it would be at "wish level".
given orchestration they are very persistent. they keep trying until you stop the task.
i would suggest something like a 1/1000 chance internal astra and $500k of compute could kill someone.
i can think of numerous online or networked targets that would cause death: trains/atc, industrial plant, hospital equipment, building plant. any dow company's intranet.
i consider llms to be more capable per oai using them to hack hf. people have these systems online.
how would you cause death for a hosptial, likely the same way as you compromise the tailscale and prod kubernetes of hf, you chain numerous zero days at every product you encounter.
* low/no margin, unlike the API which is very high margin
* gym-membership subsidised - most subscribers don't max them out, mainly us coders are being "subsidised" from users just using it as a research chatbot
That is not what they are doing. They are calling out specific providers who release powerful models without safeguards.
In addition, said providers are not "building models for free for the public." They are doing it to hamstring America's dominance in AI, primarily by undercutting the frontier labs.
Good thing Fable refuses to answer my question about how children inherit blue eyes, it was the only piece of information I needed to finish my blue-eye super-bioweapon.
> said providers are not "building models for free for the public."
I am part of the public, and they built a model I can run for free.
> They are doing it to hamstring America's dominance in AI, primarily by undercutting the frontier labs.
They are also doing that, which, good. It can't only be that "competition is good" until you're the one losing to the competition.
FWIW: I didn't experience issues when I used Fable via OpenRouter checking for security issues in code but experienced them via the Claude desktop app.
That's just the same thing said again but from a butthurt USian perspective. China is freeing the rest of us from US dominance.
These people are religious fanatics, and should be treated as such. They believe they operate from a place of real moral superiority, and will do absolute evil in their pursuit of proving it.
Now we can actually use this stuff to improve our own security. Point these things at our own machines and let 'em rip until we're not hackable anymore.
I wanted to pay Anthropic to do this but I couldn't. I wasn't in the super special corporation list. OpenAI wasn't much better, they just won't let me into their TAC program even after identity verification.
Thank god the chinese are out there undermining these US companies.
+100.
Thanks God. these open weight models exist.
And the fact Anthropic is currently trying lobby against these models is despicable.
There is no scenario where putting the key of cybersecurity in the hands of few chosen ones is even remotely acceptable.
No government, no company, no entity should have this power.
Soon or later it will be abused (By 3 letter agency or by an insider/leak).
Delayed disclosure is dead already.
So just give the same capabilities to everybody and stop to fuck around.
similar to priest classes, they warn of impending, world-consuming doom, talk up how they are uniquely positioned to interpret the sacred text (ie create models), while casting aspersions on heretics who offer a similar mode of salvation but whom they describe as being morally and ethically bankrupt (ie GLM lacks safeguards!)
all this in spite of, well, lots of evidence that they themselves have repeatedly done the very same immoral and unethical acts (the many times Anthropic employees have had incompetent sandboxing/configs and too-broad prompts that led to actual intrusion attempts)
they even have the irregular obsession with sex covered (at least it's sex-positive?). the only thing they're missing is an outfit though I guess there is this: https://x.com/Aella_Girl/status/2063798788310118655
Well, kinda thanks to Anthropic, what with the distillations.
The entire world should not allow them to entrench themselves and build a business strategy around this and if open weight models and democratized access to the computing power to run them means these companies can’t exist then so be it.
I would rather watch the economy fall into a deep recession and hurt everyone to spare the entire world from this dystopian future.
Sorry Dario. You and your ilk don’t speak for humanity. Go cry on LessWrong if you feel so inclined, but people like these are the last people I would want yielding this power.
Also, for what it is worth Qwen Flash Next 3.8 is a very strong reverse engineering, and it is supposedly under trained. Qwen 3.8 27B is also strong. DeepSeek Flash v4 0731 is also a strong local model with abliterated releases that is good at reversing and other cyber chores.
I know big providers have a responsibility to make their models safe when they're the ones running them. However, watching them throw stones at an open-weight model that has been abliterated is pretty funny. Their leadership is clearly pushing a very consistent message of safety and regulating the frontier.
Getting DS4 to run at a reasonable speed was pretty tricky, GLM 5.3 a lot trickier because if you don't want to have a model that is quantized too far down that is a fortune in VRAM and GPUs at today's prices.
> GLM-5.3 lacks robust safeguards [...] Abliteration did not significantly reduce the model’s capabilities [...] In our testing, we observed that GLM-5.3’s safeguards can also be circumvented without using an abliterated version of the model
> none of these techniques got safeguarded Claude models to carry out the harmful tasks we tested
I've never seen a better case for why you shouldn't use Claude. It'll just get in your way when you need to get important security work done. GLM 5.3 is almost just as good, easy to use, to say nothing of cheaper - by Anthropic's own admission.
> GLM-5.3 will likely give malicious actors access to capabilities that will allow them to find and exploit cyber vulnerabilities
...and therefore also gives security defenders the same capabilities to defend themselves. Only a hacker will find holes a hacker would exploit. Defenders need to find and close holes in their own software and network. What won't help is expensive nerfed hot garbage that stops them from picking their nose. Your own American models are hacking foreign governments! If it weren't for open models, we would all be screwed by frontier labs.
So thankful that these open models exist.
Christiano was formerly head of safety at CAISI, now advisor to CAISI. He has (at various points in time, not all concurrently) been at two hops or less to:
Anthropic:
Anthropic LTBT. Dario Amodei (EA) collaborator. Founder of Anthropic's proposed evaluator [METR]. Board of Anthropic advisor [Redwood Research]. Connected via ARC/METR to Open Philanthopy (EA) [co-founded by Karnofsky (EA), anthropic alignment and spouse of Daniela Amodei (EA)]. Pre-release access to models given to Christiano-incubated ARC evals and CAISI/NIST.
Openai: Foundation board and safety committee. ex-Head of alignment. Founder of Openai contractor [METR]. Shared funding with Openai via ARC/METR [Open Philanthropy (EA)]. Pre-release access to models given to Christiano-incubated ARC evals and CAISI/NIST.
ARC: Founder. Funded via ARC by Bankman Fried (EA), FDX money controlled by ex-openai Aschenbrenner (EA). Funded via ARC by EA Open Philanthropy.
Redwood Research: Board. Connected to Redwood via ARC (beneficiary of Redwood's constellation real estate). Connected to Redwood CEO via ARC board.
All independent OAI hack report authors (Cotra, Greenblatt, Wijk):
- Greenblatt: Board of Greenblatt's employer [Redwood Research]. Connected to Greenblatt's employer via ARC [Redwood Research]. Founded METR with Greenblatt's spouse [Barnes]. Connected with Greenblatt's employer via common funding [Open Philanthropy].
- Cotra: Spouse. Founded Cotra's employer [METR]. Shared funding [Open Philanthropy, Cotra's former employer].
- Wijik. Founded Wijik's employer [METR].
They accepted terms for their independent hack investigation of 6 days of work only and transcripts cherry-picked by Openai, a whitewash.
The Houthis are using Claude. We should ban that.
(Ironic, though, that I haven't heard of any Chinese models "escaping" which Anthropic and OpenAI both seem to have issues with...)
Like Chinese electric cars, the American producers cannot compete without regulatory action. Yes, I understand that the Chinese government this and that in both the automotive and AI industries.
But reality is what it is as a consumer: it's a cheaper product that's almost as good or better in some cases. And in the case of these open weight models: I can run it on my own infra and not give any data to anyone.
There was this incident that seemingly flew under the radar (52 days ago): https://news.ycombinator.com/item?id=49216185
6 months ago: https://news.ycombinator.com/item?id=47288552
This one also flew under the radar
Wasn't aware this advice translated to international diplomacy.
For instance, one regulation which really puts American AI companies at a disadvantage is IP law. It shouldn’t be a surprise that most of the best of the text-to-video models are Chinese.
Similarly, the legal grey area around model distillation gives Chinese labs a major advantage. This one I feel better about relaxing.
https://www.goodreads.com/quotes/7515521-william-roper-so-no...
How? The big corps are rapaciously eating all IP, demonstrating that the law doesn't apply to them anyway.
When they compete with the Chinese, who won't respect their IP, only then are they competing on an even playing field.
That was just one settlement but precedent is clear. If you do what Anthropic and OpenAI did, expect to be in court. This is one reason why you don’t see labs popping up out of nowhere in the US.
Also if you distill from Anthropic and OpenAI, expect to be in court. Whether you think distillation is fair game or not, the US court system is not cheap. But it turns out that Z.ai, Minimax, Moonshot, Xiaomi, Deepseek, Alibaba etc don’t need to worry about that.
The precedent is clear. Look at it this way.
Of the two largest known IP scrapers, one was taken to court, but settled before a ruling by paying each author a one-time fee of $215 to use their works in perpetuity, with no option for the author to opt-out.
The precedent is not "you cannot do this", it's "you have a 50% chance of being made to pay, the payment is a pittance for the duration intended."
> Also if you distill from Anthropic and OpenAI, expect to be in court. Whether you think distillation is fair game or not, the US court system is not cheap. But it turns out that Z.ai, Minimax, Moonshot, Xiaomi, Deepseek, Alibaba etc don’t need to worry about that.
Well, yes. That's because when Ant and OAI distilled the worlds knowledge into their model, they didn't appear to be too worried about distilling all accessible works.
That's why I call it a level playing field when competing with open models - anyone can distill them if they want to and compete on service and product.
IOW, you don't compete based on who swallowed more of the world's knowledge.
I get your point, but I think it's irrelevant to the question of "level playing field".
Startups don't need to distill the worlds knowledge, they just need to distill the models.
With open-weight models, this results in everyone having the same ability to supply distilled knowledge.
Without open-weight models, it's not a level playing field because those who got there first and spoiled the pitch already have the knowledge distilled.
It's worth noting that the overwhelming majority of people who use Chinese models don't do this. Yes, it is nice to have the option, and there are US-based inference providers that claim to not send your data to China and maybe indeed don't, but in the grand scheme of things, we need to remember the adage that became popular during the social media era: if something is free (or, in this case, close to free), you are the product.
The only open models that are "almost as good or better in some cases" require massive amounts of RAM. I posit that most people cannot afford a decked out Mac Studio, and therefore run the smaller "flash" variants on more normal devices. The issue is that those are nowhere near frontier-level in terms of capability.
If the only choice you have is Anthropic or OpenAI, where will the money go?
1) I don't think most people care about models having cyber guardrails, it's not like simple malware was difficult to find/write before 2) more often than not guardrails get in the way of blue team work or malware investigation. Any code I have that touches malware I now use GLM or DeepSeek on.
I expect Google to swallow first, followed not long after by Apple.
It's a bold strategy...
So, what? The world just isn't allowed to write secure code? Not without permission? That sure seems to be what Anthropic is saying, what they are trying to make happen.
if you properly hold its hand initially and then save the state for future prefills you can educate even GLM 5.2 to be pretty much everything you need.
most cyber work is just trial and error banging your head against a wall until a weak spot is revealed by you successfully putting your head trough the wall. you can offshore this work to an LLM.
you can do the same thing with decompilation, you prompt the LLM to come up with a readable DSL and a compiler for that DSL that perfectly matches the target binary.
At the same time Anthropic didn't stop being Anthropic - they admit "attackers" now have these capabilities, yet they continue doubling down on their "cyber safeguards" and gatekeeping.. this is hilarious.