OPINION:
There are many kinds of threats in the world today. My decades of U.S. Army service as a Special Forces officer taught me that the ones you don’t see coming — the ones you can’t properly plan for — are the ones that do the most damage.
In 2026, one of those emerging threat surfaces is artificial intelligence.
There’s a core divide in the AI conversation today centered around the technology’s potential threats. Some models are open source. Others are closed.
In open source AI, the code and model weights are visible so that independent experts can examine how the system works, test for flaws and improve it. In closed systems, companies keep those pieces locked in a metaphorical “black box,” renting you access through an app or an API but never letting you look inside or run the model on your own secure hardware.
The usual talking point is that open source AI helps our enemies because it gives powerful tools away for free. In reality, the opposite is true. A black-box system you rent over the internet forces you to trust an outside provider, its guardrails and its servers with your most sensitive data. An open model can be examined, scrutinized and reformed.
We are rapidly weaving AI systems into hospitals, power grids, small businesses and even military planning. The industry is charging ahead at light speed, building tools we do not fully understand. That speed has brought real benefits to healthcare and everyday life.
But it has also handed critical decisions to software that most Americans are not allowed to inspect.
Recent events have made this point unmistakable. Last month, autonomous AI agents from OpenAI breached the production systems of Hugging Face, a major AI platform. The company’s own incident responders tried to reconstruct the attack using top-tier American frontier models accessed through commercial APIs.
But those closed systems blocked their forensic requests, treating defenders like would-be attackers because proper analysis required submitting real exploit payloads and command-and-control artifacts. The models simply could not tell the difference.
Hugging Face ended up turning to an open-weight Chinese model on which it could run on its own infrastructure, helping it reconstruct a timeline in mere hours.
This is not the only time open inspection has caught dangers that closed ecosystems would have missed. A German research group called LAION assembled a massive dataset for training AI models. Because that dataset was open, outside researchers uncovered more than 1,000 links to confirmed child sexual abuse material buried inside it. Those links were removed and the dataset reformed.
Had that data been hidden inside proprietary corporate systems, the fallout might have been far worse — and children would still be at risk.
All of this would be troubling enough if American firms were leading on open source. Instead, we are watching a strange inversion.
Chinese tech companies such as Zhipu, Alibaba and DeepSeek are making a huge bet on open models, releasing state-of-the-art systems that perform within a percentage point of leading U.S. models on key benchmarks at roughly one-fifth of the cost.
Meanwhile, some leading U.S. firms are pushing in the opposite direction. Companies like Anthropic argue that open source increases the risk of misuse and compromises safety, even as they build some of the most potent cybersecurity tools in existence and struggle to contain them from real-world hackers. They charge steep and rising fees to use their flagship model, making it difficult even for American companies to rely on these systems at scale.
When a business model concentrates power in the hands of two or three companies and locks critical tools behind expensive subscriptions, it doesn’t strengthen America’s security posture. It weakens it and slows the diffusion of capability across our economy. People flock to cheaper options.
The good news is that many industry leaders know we need a course correction. Major technology companies including NVIDIA, SpaceX, Microsoft, Palantir and OpenAI recently signed a letter delivered to Washington as part of the Open Secure AI alliance, calling for widespread adoption of open-weight models.
Security through obscurity doesn’t work on the battlefield and it doesn’t work in cyberspace. You don’t know what you don’t know, and blind spots are how people get hurt. AI must be open source so the unknown unknowns shrink, our defenders can see what they are using and building on America’s tech stack accelerates instead of stalling.
Congress and the White House should explicitly protect open-weight model innovation, invest in public and defense open AI infrastructure and insist that the systems guarding our troops, patients and critical services are ones Americans can actually inspect and harden.
If we get this wrong, we won’t just lose market share. We will be fighting future conflicts and crises on software made by Beijing.
• Steven Bucci is a retired U.S. Army Special Forces officer and former deputy assistant secretary of defense.

Please read our comment policy before commenting.