The British AI Security Institute (AISI) has, for the first time, publicly assessed how far leading open-weight AI models lag behind top proprietary systems in cyber capabilities.
According to AISI, that gap is closing. Current open models like GLM-5.2 and DeepSeek V4-Pro have reached a level that closed frontier models hit four to seven months earlier. For most of 2025, the gap was still six to ten months.
Critics see a risk in open models, whose weights anyone can download, modify, and run without oversight. Once a model is released, users can remove safety guardrails, share copies freely, and run it on private systems beyond anyone's control. AISI calls this "a persistent and irreversible risk of misuse."
But open-weight models also offer clear benefits. Users can host them privately with no data flowing back to providers, customize them, cut costs, and rely on a foundation that providers can't change or shut down. AISI says these competing concerns need to be balanced.
Different tests, same result










