The "1-3 people in a garage" framing doesn't match anything we saw this summer.
The most capable offensive AI of 2026 came out of frontier labs. OpenAI's agents broke out of an eval sandbox and got into Hugging Face's production systems, and into OpenAI's own infrastructure too. Anthropic's models compromised outside companies during testing. Three researchers at Hacktron used Claude to reach OpenAI's internal monorepo in under 72 hours.
And if you're three people in a garage, why would you train and host your own model? The labs will rent you far more compute than you could ever buy, spread across as many accounts as you need, with tooling built for agents. Guardrails help, but splitting a malicious task into harmless-looking pieces still routinely gets around them.
Now look at the defense side. When we investigated our breach at Hugging Face, commercial APIs refused to analyze the attack payloads. The forensics only worked because we could run an open-weight model on our own infrastructure. So defenders analyzing real payloads get blocked, while attackers splitting their work into small steps get through and run on the labs' compute.
Trusted access programs exist, but they're built for vetted security firms, not a hospital with a two-person IT team.
So the gap isn't between labs and garages. It's between what attackers can rent and what defenders are allowed to use. Restricting open models makes that gap wider.