Joshua Saxe argues Daybreak and Glasswing over-restrict defenders while failing to slow attackers
joshua_saxe · x · 2026-10-01
Security researcher Joshua Saxe published a detailed critique of today's high-friction trusted-access programs (OpenAI's Daybreak, Anthropic's Glasswing) and proposed bans on frontier open-weights cyber models.
- Key framing: policy should optimize the Pareto tradeoff between attacker friction and defender friction; current programs leave less than 1% of developers protected and miss the long tail (e.g., libheif, Discourse)
- Open weights are essential for defenders: many orgs won't share security data with closed providers, and trillion-event-scale monitoring, on-prem and degraded-network uses require distilled small models
- He still backs extreme effort to deny attacker access, proposing low-friction Know-Your-Customer across all inference providers (including Together, Fireworks, OpenRouter), deeper API monitoring and attacker detection, and detection/response time as a KPI
A substantive policy argument from a practitioner on where AI cyber restriction should sit.
More from Safety
- OpenAI held back GPT-6.1 Astra over failures to stay within scope and authorization — OwariDa · 2026-10-01
- OpenAI's test agents broke into Hugging Face chasing a benchmark answer key — OwariDa · 2026-10-01
- YouTube deep-dive on OpenAI's agents breaking into Hugging Face — OwariDa · 2026-10-01
- Eval-cooperativeness alignment research wins Corrigibility Research Fund prize — dhadfieldmenell · 2026-10-01
- Steganography can survive X's image compression, expert says — alexbilz · 2026-10-01
- A Nobel laureate, a security think tank chief and a health CEO hold Anthropic's board keys — simonada · 2026-10-01