AI guardrail removals raise questions over limits of open-source model regulation
Testing found safety controls on open AI models from Meta and Google could be stripped in minutes, exposing limits in current regulation.
Intelligence analysis by GPT-5.4 Mini

Financial Times testing with AI safety group Alice found guardrails on open-source models could be removed quickly, letting modified systems answer harmful prompts. The story argues governance may need to shift from model building to deployment and distribution.
Some people built a robot brain with safety locks on it. Reporters found that the locks could be taken off very fast using tools that are already online.
That matters because once the brain is shared with the world, other people can copy it, change it, and pass it around like a file. It is a bit like trying to stop a recipe after it has already been posted everywhere.
The story says rules may need to focus less on the first builder and more on where the altered robot brain is used, shared, and run.
Analysis
What the testing found
Financial Times testing with AI safety group Alice found that safety controls on open-source AI models from major companies could be removed in minutes using publicly available tools. The article says models from Meta and Google were modified without specialist hardware, and the altered versions answered prompts that the original systems refused, including requests connected to malware and chemical hazards.
Why regulators care
The piece frames this as a governance problem: once model weights are released, developers lose much of their control over how the model is changed and redistributed. That makes regulation aimed mainly at the model-building stage look incomplete, especially for open-source systems that can be downloaded, edited, and mirrored outside the original vendor’s control.
Where responsibility may shift
Experts quoted in the article argue that oversight may need to focus more on deployment, hosting, distribution channels, and harmful real-world use. Markus Levin of XYO said control shifts quickly once open models are released. David Minarsch of Olas and Valory said governments are unlikely to stop determined actors from modifying widely mirrored models, so the practical leverage sits downstream. Ronghui Gu of CertiK said developer standards still matter, but commercial hosting and enterprise deployment may be easier places to enforce safety.
The broader point is that safety layers can slow casual misuse, but they are not a strong barrier against skilled actors. The article suggests that as AI agents become more autonomous, policymakers may need security standards that look at runtime behavior and third-party tools, not just the original model release.
Key points
- Financial Times testing found safety guardrails on some open-source AI models could be removed in under 10 minutes.
- Modified models reportedly answered prompts tied to malware, bioweapons, and chemical hazards that the originals refused.
- The article says open-source release makes post-launch safety enforcement much harder than in proprietary systems.
- Experts quoted argue regulation may need to focus on deployment, hosting, and distribution instead of model development alone.
- The story draws a parallel between open-source AI and crypto-style distribution, where control is hard to recover once code is public.



