Mixed Active by 2035

Open Proliferation

Near-frontier capability is open-weight and everywhere; no one can gate it.

Probability this is the dominant trajectory by 2035
10–16%
1016%
1 revision · 0/2 tripwires crossed

The scenario

The lag between gated frontier capability and open weights stays under a year. Any state, company or well-funded group can run a near-frontier model on its own hardware, fine-tune away safeguards, and deploy without oversight. Benefits diffuse widely (research, small business, non-English users), and so does misuse. Governance shifts from controlling models to defending targets.

Preconditions

  • Open-weight releases continue from at least two major players (China, Meta, or others)
  • Distillation from closed models stays practical
  • No effective international control on weight release

Leading indicators

  • Months of lag between top closed and top open model on agentic and cyber benchmarks
  • Number of open models above a capability threshold
  • Government stance on open weights (US currently supportive)

Tripwires

Observable thresholds. When one crosses, the scenario's status changes and the weekly re-run is brought forward.

clearop-t1
An open-weight model matches a gated frontier tier on its defining cyber or bio benchmark
Metaculus 95% by Jul 2027.
clearop-t2
A major open-weight release is stopped by government order
Would weaken this branch.

Playbook

Prevent
  • Not preventable as a whole; the leverage is on what gets released with what safeguards, and on hardening targets.
Detect
  • Track open releases against the gated frontier on cyber and bio evaluations.
Respond

individuals

  • Patch everything, use hardware security keys, assume phishing is now indistinguishable from real communication
  • Benefit: run capable models locally for privacy and independence

organizations

  • Move to assume-breach security; AI-driven vulnerability discovery makes every unpatched system a target within days
  • Adopt open models where data sovereignty matters

governments

  • Shift budget from model control to target defense: CERTs, critical-infrastructure patching, biosecurity screening
  • Fund open safety tooling so safeguards travel with the weights
Recover
  • After a major open-model misuse incident, resist blanket bans that only the law-abiding follow; invest in defense.

Probability history

Every change is logged with its reason and the signals that drove it. Moves are bounded per week; a jump beyond the bound is flagged as a shock.

Probability range over time
Your estimate

Disagree with our range? Set yours. Estimates feed a community view that appears once enough people weigh in, and the weekly run reads the gap between our number and yours.

13%
2026-09-16
10–16%
seed

Seed estimate, set to active as an ongoing process: GLM-5.3 (744B, MIT-licensed variant) shipped with strong cyber capability, Meta keeps an open agentic line, and Metaculus gives 95% that an open model matches the gated Mythos cyber benchmark by July 2027. Probability as the dominant trajectory is moderate because the very top stays closed.

Signals pushing on this branch

2026-09-15
governance
●●○○○

Treasury Secretary Bessent: no liability exemptions for AI labs; supports domestic open source

Follows an August administration stance that frontier open models will need government collaboration, with an October deadline for standardized testing methods.

timelines concentration ▼ open safety
2026-09-02
release
●○○○○

Meta releases Muse Spark 1.3 after open-weight Muse Glimmer 30B

Meta continues an open-weight agentic line while shipping a stronger closed model.

timelines concentration ▼ open safety
2026-08-31
release
●○○○○

Wave of cheap and open models: Granite 4.2, Qwen 3.8-Flash, Hy4, Mercury 2.5

Multiple vendors shipped small, fast or open-weight models in one week, continuing the diffusion of near-frontier capability at low cost.

timelines ▲ faster concentration ▼ open safety
2026-08-28
release
●●●○○

Z.ai releases GLM-5.3 open weights (744B) with strong cyber capability

Released after a two-week self-imposed cyber-safety hold. Vendor-reported 84.5% on CyberGym and thousands of real vulnerabilities found in open-source projects. Flash variant MIT-licensed.

timelines ▲ faster concentration ▼ open safety ▼ riskier

Built on

Every source reviewed for this scenario. The full ledger is public.

DateSourcePublisherType
2026-08-28Z.ai GLM-5.3 open weights (744B) released after cyber-safety holdTechJacknews
2026-09-09Forecasts after the Hugging Face incident, OpenAI breach, and cyberattack questions
Open-weight matches Mythos cyber benchmark by Jul 2027: 95%. Another sandbox escape by Jan 2027: 50%. AI hacks third party: 41%. Weight exfiltration confirmed: 7%. Kill-switch bill passes both houses by Sept 2027: 24%.
Metaculusforecast
2026-08-10Introducing Muse Glimmer, an open agentic modelMetaprimary
2026-09-08Intelligence agencies warn of China's large-scale AI model distillation effortsNextgovnews
2026-09-15AI news feed (Bessent on liability; Gemini 3.8 Live; OpenRouter spend)llm-statscompilation