If frontier-class models are this capable, why aren't companies getting popped? Three theories
joshua_saxe · x · 2026-10-08
Building on a hot take from Nat Lambert, the author — who has hands-on experience with GLM 5.3 and GPT-5.6 Sol — argues the capability gap between open and closed frontier models is nearly gone, meaning any company could be popped with enough effort. Yet mass attacks aren't happening.
Three possible explanations:
- There are fewer real bad actors than cyber vendors claim;
- Popping a Fortune 100/500 firm is hard to monetize — data doesn't sell easily and raises the odds of getting caught, whereas crypto hacks and reselling LLM tokens have much cleaner paths to money, which is why attackers chase tokens rather than source code or IP;
- Or valuable lab IP is being quietly sold off.
The takeaway is open-ended: even if open models fully match closed frontier capability, the world may not get meaningfully more vulnerable.
More from AGI Musings
- "Mathematicians did not ask for this work to be done": pushback on AI proofs — prof_g · 2026-10-08
- Roko: pretraining vs RL compute split shifted massively since late 2025 — 'two different species' — yacineMTB · 2026-10-08
- Robotics Won't Take Your Trade Job—But a 10x Plumber Supply Might — clemnt · 2026-10-08
- Data scientist career advice: dashboard work has zero ROI, agent-workflow roles pay $200K — mdancho84 · 2026-10-08
- Bezos says AI could enable 3-day workweeks and one-income families — rand_longevity · 2026-10-08
- AI ethicist: practical irrelevance precedes existential irrelevance for unaugmented humans — danfaggella · 2026-10-08