Should Open-Weight AI Be Regulated? A Conversation with Robert Graham @unsupervised-learning
Should Open-Weight AI Be Regulated? A Conversation with Robert Graham  @unsupervised-learning
Uploaded September 2026 | Updated September 2026, 3 weeks ago
📝 I finally got to talk to Robert Graham after about twenty-five years of interacting with him online and somehow never once actually chatting. Turns out he's the guy who built BlackICE, the little icon in my dock in college that got me into security in the first place, and I only found that out years after we'd started arguing on the internet. This one came out of him pushing back on my endorsement of Greg Brockman's cyber defense letter, and we went four hours on whether open-weight models should ship with any controls at all.

What we talk about:

✓ Kerckhoffs's principle vs. "responsible model access": Rob's core objection is that you can't hand frontier capability to defenders and withhold it from attackers, and that the crypto wars already settled this. I agree with the principle and still think the letter is fine.

✓ Don't put handguns in the 7-Eleven: My whole argument is friction. The mainstream distribution point carries the version with basic controls, and the uncensored one is still a search away for anyone who wants it.

✓ The 14-year-old who says "ruin her life": The scenario I keep coming back to, where an agentic model takes the goal and just runs with it. Rob's answer is that Lori Drew already did exactly this in 2006 with a fake social media account and no AI at all.

✓ "That's a police state": Where we deadlock. I say we already authenticate for cars, guns, and prescriptions; Rob says any ID requirement to download open weights is a civil-liberties violation.

✓ Foxy Raccoon: Rob's thought experiment for why regulating Hugging Face wouldn't do anything: the model goes viral on TikTok by name, and everyone just finds it somewhere else.

✓ Let the forest burn: His view that harm shows up, gets patched, and burns itself out (sidejacking, Firesheep, Mirai), plus the paperclip problem, which is the thing that worries him.

⏱️
00:00 – Twenty-five years online, and the BlackICE shout-out
00:56 – How we got here: Brockman's letter and Rob's pushback
03:51 – Rob's case: a two-tiered cybersecurity, and Kerckhoffs's principle
12:07 – The 14-year-old, Cindy, and the coffee machine
17:32 – Lori Drew, 2006: the scenario already happened
20:28 – "This isn't cynicism, it's thirty years of experience"
42:08 – What I actually want Hugging Face to require
45:17 – "You're advocating for a police state"
50:39 – Metasploit is a hammer, an agent is a carpenter
1:12:30 – Would you build a model for Ukraine's drones?
1:44:28 – Is Hugging Face actually mainstream distribution?
2:02:44 – Foxy Raccoon goes viral on TikTok
2:24:29 – Let the forest burn
2:44:35 – The paperclip problem, and where we land

👥 Robert Graham has been doing this longer than almost anyone. He built BlackICE and masscan, and he coined sidejacking.

Rob's blog:
https://ul.live/ytgrahamblog

Rob on Mastodon:
https://ul.live/ytgrahammastodon

Rob's code, including masscan:
https://ul.live/ytgrahamgithub

Also mentioned: Greg Brockman, whose letter started this: https://ul.live/ytbrockman · Bruce Schneier, on why crypto had to be public: https://ul.live/ytschneier · Kerckhoffs's 1883 principle, which Rob builds his whole case on: https://ul.live/ytkerckhoffs · Thoreau's Civil Disobedience: https://ul.live/ytthoreau · the Lori Drew CFAA case: https://ul.live/ytloridrew · Firesheep: https://ul.live/ytfiresheep · and Bostrom's original paperclip maximizer: https://ul.live/ytpaperclip

📚 More on this topic:

Responding to Rob Graham's "Your Threat Model is Wrong" Post:
https://ul.live/ytgrahamthreatmodel

Should We Control Open Source AI?:
https://ul.live/ytcontrolopensource

The OpenAI Hack Was a Mini Paperclip Maximizer:
https://ul.live/ytminipaperclip

Who Will AI Help More—Attackers or Defenders?:
https://ul.live/ytattackersdefenders

Could Suddenly-Great Open Source AI Crash the US Economy?:
https://ul.live/ytoscrasheconomy

ATHI — An AI Threat Modeling Framework for Policymakers:
https://ul.live/ytathi

🔗 Subscribe to the newsletter at:
https://ul.live/ytnl

Join the UL community at:
https://ul.live/ytcommunity

Follow on X:
https://ul.live/ytx

Follow on LinkedIn:
https://ul.live/ytli
Should Open-Weight AI Be Regulated? A Conversation with Robert GrahamEverything in AI is vibes. Thats a problem.Venture Capitalists Want Risk-Taking FoundersIs OpenCode as Smart as Claude Code?A conversation with Neatsun Ziv At OX.SecurityClaude Code + Neovim via Ghostty PanesThe Missing Piece Is Ideal StateUnderstand AI ROI with Harmonic Securitys Alastair PatersonMuah.ai Database Breached & Users Info LeakedAI Upgrade Skill: Stay Ahead of Updates Automatically #shorts
Unsupervised Learning |

Should Open-Weight AI Be Regulated? A Conversation with Robert Graham

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER