Near-frontier capability is open-weight and everywhere; no one can gate it.
Probability this is the dominant trajectory by 2035
10–16%
10–16%
1 revision · 0/2 tripwires crossed
The scenario
The lag between gated frontier capability and open weights stays under a year. Any state, company or well-funded group can run a near-frontier model on its own hardware, fine-tune away safeguards, and deploy without oversight. Benefits diffuse widely (research, small business, non-English users), and so does misuse. Governance shifts from controlling models to defending targets.
Preconditions
Open-weight releases continue from at least two major players (China, Meta, or others)
Distillation from closed models stays practical
No effective international control on weight release
Leading indicators
Months of lag between top closed and top open model on agentic and cyber benchmarks
Number of open models above a capability threshold
Government stance on open weights (US currently supportive)
Tripwires
Observable thresholds. When one crosses, the scenario's status changes and the weekly re-run is brought forward.
clearop-t1
An open-weight model matches a gated frontier tier on its defining cyber or bio benchmark
Metaculus 95% by Jul 2027.
clearop-t2
A major open-weight release is stopped by government order
Would weaken this branch.
Playbook
Prevent
Not preventable as a whole; the leverage is on what gets released with what safeguards, and on hardening targets.
Detect
Track open releases against the gated frontier on cyber and bio evaluations.
Respond
individuals
Patch everything, use hardware security keys, assume phishing is now indistinguishable from real communication
Benefit: run capable models locally for privacy and independence
organizations
Move to assume-breach security; AI-driven vulnerability discovery makes every unpatched system a target within days
Adopt open models where data sovereignty matters
governments
Shift budget from model control to target defense: CERTs, critical-infrastructure patching, biosecurity screening
Fund open safety tooling so safeguards travel with the weights
Recover
After a major open-model misuse incident, resist blanket bans that only the law-abiding follow; invest in defense.
Probability history
Every change is logged with its reason and the signals that drove it. Moves are bounded per week; a jump beyond the bound is flagged as a shock.
Probability range over time
Your estimate
Disagree with our range? Set yours. Estimates feed a community view that appears once enough people weigh in, and the weekly run reads the gap between our number and yours.
13%
2026-09-16
10–16%
seed
Seed estimate, set to active as an ongoing process: GLM-5.3 (744B, MIT-licensed variant) shipped with strong cyber capability, Meta keeps an open agentic line, and Metaculus gives 95% that an open model matches the gated Mythos cyber benchmark by July 2027. Probability as the dominant trajectory is moderate because the very top stays closed.
Treasury Secretary Bessent: no liability exemptions for AI labs; supports domestic open source
Follows an August administration stance that frontier open models will need government collaboration, with an October deadline for standardized testing methods.
Z.ai releases GLM-5.3 open weights (744B) with strong cyber capability
Released after a two-week self-imposed cyber-safety hold. Vendor-reported 84.5% on CyberGym and thousands of real vulnerabilities found in open-source projects. Flash variant MIT-licensed.
Open-weight matches Mythos cyber benchmark by Jul 2027: 95%. Another sandbox escape by Jan 2027: 50%. AI hacks third party: 41%. Weight exfiltration confirmed: 7%. Kill-switch bill passes both houses by Sept 2027: 24%.