SYNTHESIS NOTE
Topics›Alignment›this note

Can we measure how much risk open models actually add?

Whether current evidence adequately quantifies the marginal misuse risk of openly released foundation models compared to existing technology. This matters because policy decisions depend on knowing if open release meaningfully worsens real-world harm vectors.

Synthesis note · 2026-06-03 · sourced from Alignment

The open-vs-closed release debate is heated and under-evidenced. This position paper clarifies it by defining open foundation models (broadly available weights — Llama 2, Stable Diffusion XL) via five distinctive properties (greater customizability, deeper inspectability, poor monitoring, etc.) that drive both their benefits (innovation, competition, distributed decision-making power, transparency) and risks. Its analytical contribution is a marginal-risk framework: assess misuse not in absolute terms but relative to pre-existing technology (search engines, prior models). Applying it across vectors (cyberattacks, bioweapons, disinformation), it finds current research insufficient to characterize the marginal risk — and shows that past disagreements stem from focusing on different parts of the framework under different assumptions.

The keeper is the marginal reframing: the policy question is not "could an open model help a bad actor?" but "how much does it help beyond what they could already do?" — and on that question the evidence is mostly missing, which is itself the finding.

This is a discourse/governance anchor for the vault. It complements the empirical risk register of Where do frontier AI models actually pose the greatest risk today? — both insist on measured marginal risk over speculation — and informs the open-weights side of the alignment-and-society conversation.

Inquiring lines that read this note 10

This note is a source for these research framings, grouped by the broader line of inquiry each explores. Scan the bold lines of inquiry; follow any specific question forward.

What capability trade-offs arise from domain specialization through fine-tuning? Can local safety checks guarantee system-level behavioral safety? What determines whether deployed AI systems can actually be stopped in practice? Do backend defenses obscure real attack effectiveness in reported metrics? What attack surfaces do reasoning traces and chains introduce?

Related concepts in this collection 3

This note in its neighbourhood — explore the map, then jump to a related concept in the list below.

Concept map
12 direct connections · 116 in 2-hop network ·dense cluster Open in graph ↗

Click a node to walk · click center to open · click Open in graph to see this note in the full knowledge graph

your link semantically near linked from elsewhere

Related papers in this collection 8

Papers most semantically related to this note, ranked by cosine similarity in the embedding space.

Original note title

open foundation models need a marginal-risk framework because current evidence cannot characterize their misuse risk relative to existing technology