As near as I can figure there's only a few remotely plausible attack vectors for "fishy" models. One is if they're granted unrestricted access to a system, device, network, or the Internet. And two is through dubious code that isn't properly double checked.
And I suppose there's also a slim possibility that an image generation model could spit out personal information embedded into it, but again, that would require some level of unrestricted access to obtain that data.
That leaves most of the security risks with whatever frontend and backend is being used, and user setup (for self-hosted in particular). And plenty of extra security measures can be applied from the user including firewall restrictions and sandboxing.
If anything, Windows 11 has a greater chance of becoming a giant security risk given how much code is written by AI, and given how invested Microsoft is in embedding AI more and more deeply into central functions of the OS.
I'm not saying there are not backdoors, but Chinese AI models are also in most cases open source. Someone can look for backdoors.
Then there's the other scenario, let's say closed source and cloud based. I mean I don't want the Chinese government to have anything on me either, but it's much less actionable against me too. If they've decided I'm a racist and not progressive and pro government enough, they can sit over there in China and think it, or I suppose they could sell it outside of China. In the US, it's only a matter of time before it's used against me. Even if I'm not going into any sort of social credit conspiracy, it will be sold to corporations as data as much as possible. Ask about a movie, guess what is advertised to you. Ask about how to fix your car after a crash....it's on an insurance company report. The thing is China has only risk of using it against me, and American corporations have shown time and time again to have done it, and then say yeah we will do it again.
I would guess that the Trump Administration will at some point realize that their best strategy here would be to create large amounts of regulatory risk around the use of open-weight Chinese models. You don't need to "ban open source" (one of the dumber motifs of AI policy discussion). You just need to direct every agency to issue soft law that creates FUD. "A Federal Reserve Advisory Bulletin found that there may be backdoors in Chinese AI models." It needn't be that well justified. You just create enough regulatory risk that every regulated enterprise backs off. You probably don't want to create so much regulatory risk that you scare off the hyperscalers from serving Chinese models; this will just drive startups to sketchier providers. There's a happy middle ground here. I'd assume they will do some version of this.
Chink malice is a given but it's small potatoes compared to OpenAI's kikery.
OpenAI went from a “non-profit” to - “let’s abuse regulators to create a monopoly”
This is the 2020 version of "Terrorists might have bank accounts" so we need the Patriot Act.
As near as I can figure there's only a few remotely plausible attack vectors for "fishy" models. One is if they're granted unrestricted access to a system, device, network, or the Internet. And two is through dubious code that isn't properly double checked.
And I suppose there's also a slim possibility that an image generation model could spit out personal information embedded into it, but again, that would require some level of unrestricted access to obtain that data.
That leaves most of the security risks with whatever frontend and backend is being used, and user setup (for self-hosted in particular). And plenty of extra security measures can be applied from the user including firewall restrictions and sandboxing.
If anything, Windows 11 has a greater chance of becoming a giant security risk given how much code is written by AI, and given how invested Microsoft is in embedding AI more and more deeply into central functions of the OS.
https://x.com/kimmonismus/status/2078761134119927969
Another open model:
Qwen 3.8 supposedly ahead of GPT-5.6 and only slightly behind Fable 5!
More usable :
I have a report full of security issues of a software I'm working on.
Codex won't fix them because of Cyber guardrails Fable won't fix them because of Cyber guardrails
Kimi K3 fixed them all. No restrictions, just gets the job done.
This will end badly for OpenAI & Anthropic.
https://x.com/callebtc/status/2078574362316165611
I'm not saying there are not backdoors, but Chinese AI models are also in most cases open source. Someone can look for backdoors.
Then there's the other scenario, let's say closed source and cloud based. I mean I don't want the Chinese government to have anything on me either, but it's much less actionable against me too. If they've decided I'm a racist and not progressive and pro government enough, they can sit over there in China and think it, or I suppose they could sell it outside of China. In the US, it's only a matter of time before it's used against me. Even if I'm not going into any sort of social credit conspiracy, it will be sold to corporations as data as much as possible. Ask about a movie, guess what is advertised to you. Ask about how to fix your car after a crash....it's on an insurance company report. The thing is China has only risk of using it against me, and American corporations have shown time and time again to have done it, and then say yeah we will do it again.
Ah, the "civil rights" model.
ChatGPT is garbage these days. Completely useless. Pure propaganda, muh safety, garbage guidelines, 100% DEI.
Claude is better for code, gemini is a better conversationalist (but is still crap, even the "pro" version). Deepseek lol, grok is trash.
Dont know what that leaves us.