Open-Weight AI Models Now Match Frontier Cyber Skill From Four Months Prior, AISI Finds

Techtimes
Open-weight AI models are catching up to closed‑model cyber capabilities, narrowing the gap to four to seven months and lowering attack costs to under two dollars.

Summary

The UK’s AI Security Institute (AISI) released its first public measurement of the open‑weight cyber capability gap, finding that freely downloadable AI models now trail the top closed systems by only four to seven months on offensive cybersecurity tasks. This represents a significant compression from the six to ten‑month gap measured through most of 2025, and it has immediate operational implications: organizations with networked infrastructure face a shrinking window before near‑frontier AI‑powered cyberattacks become accessible to anyone with modest compute resources. AISI’s July 2026 report evaluated two Chinese open‑weight models—GLM‑5.2 from Z.ai and DeepSeek V4‑Pro—using a suite of 70 narrow cyber tasks and a multi‑step autonomous attack range called "The Last Ones." GLM‑5.2 matched Anthropic’s Opus 4.6 on narrow tasks, placing it roughly four months behind the frontier, while DeepSeek V4‑Pro tracked Opus 4.5, about five months behind. On the autonomous range, GLM‑5.2 reached step 7, a gap of up to seven months, whereas DeepSeek V4‑Pro performed below even sub‑frontier models. The report also highlighted that open‑weight models can be run for a fraction of the cost of closed models: a full 100‑million‑token autonomous attack costs approximately $1.19 on DeepSeek V4‑Pro and $46 on GLM‑5.2, compared to roughly $85 for closed‑model counterparts. Narrow‑task costs were similarly lower, with DeepSeek V4‑Pro at $0.28 per task versus $12.50 for Opus 4.5. AISI noted that open‑weight models lack the safety safeguards of closed APIs; refusal training can be removed, and no central authority can revoke access once weights are distributed. The report also discussed regulatory asymmetries: closed‑model governance can impose export controls and recalls, whereas open‑weight models, already globally distributed, cannot be recalled. AISI identified Kimi K3 from Moonshot AI as the next open‑weight model, slated for release in late July 2026, with 2.8 trillion parameters and a one‑million‑token context window. The findings underscore the urgency for organizations to invest in AI‑enhanced defensive tools and cybersecurity fundamentals, as the preparation window narrows and the cost of autonomous attacks drops to single‑digit dollars.

(Source:Techtimes)