Open-Weight AI Models Now Close the Dangerous Cyber Gap
Open-weight AI models now trail the closed-model frontier on offensive cybersecurity tasks by just four to seven months, down from six to ten months in the previous assessment, the UK AI Security Institute (AISI) found in a report published July 19. No major AI lab scored above a C+ on the institute’s safety grading scale.
The institute’s findings arrive as the first large-scale academic study of pretraining data poisoning confirms that open models are especially difficult to audit for deliberately introduced harmful behaviors.
The Gap That Keeps Closing
Open-weight AI models are AI systems whose trained weights are released publicly, allowing anyone to download, run, and modify them without restriction. Unlike proprietary closed models such as GPT-4o or Claude, open-weight systems cannot be updated remotely, monitored at inference time, or patched against misuse once released.
The AISI found these dynamics have accelerated significantly since the previous assessment period.
The AISI’s measurement covers the ability of AI models now deployed across research and commercial contexts to assist with real cyberattack tasks: finding software vulnerabilities, writing exploit code, and automating reconnaissance. The four-to-seven-month lag means a researcher or attacker who downloads a leading open-weight model today gets roughly the same cyber capability that the best closed model offered around the start of this year.
That window is shrinking fast.
Six months ago, AISI measured the same gap at six to ten months. The rate of compression suggests open-weight cyber capability could match today’s closed frontier within a year.
What a C+ Safety Grade Actually Means
The institute’s grading reflects how well each lab’s model resists elicitation of dangerous outputs across a standardized battery of tests.
A C+ is the ceiling any lab achieved in this round.
Grades this low do not mean models are freely generating attack code on request. They mean that with moderate effort, adversarial prompting techniques routinely extract outputs that cross safety thresholds the labs themselves set.
The AISI grades are calibrated against each lab’s own published policies, making a C+ particularly striking. Labs are being marked against their own stated standards and still falling short.
The grading also showed the most safety-committed labs are, paradoxically, the ones retreating from publishing their methodology.
AISI noted that several top-performing labs on safety metrics declined to share evaluation details that would allow independent replication.
AI Models Now Pose a Distinct Infrastructure Risk
A separate strand of research published this week sharpens the concern. A paper in the primary source corpus examines how pretraining data for large language models can be deliberately poisoned through what the authors call computational propaganda.
Poisoning pretraining data can introduce harmful behaviors that survive subsequent fine-tuning and are difficult to detect through standard safety evaluations.
The interaction matters for open-weight models specifically. When a closed model is found to carry poisoned behaviors, the operator can issue a silent patch.
When an open-weight model is found to carry them, every downloaded copy remains compromised indefinitely. The research notes that prior poisoning work focused on narrow, well-curated sources like Wikipedia, which do not reflect the scale and heterogeneity of real pretraining corpora.
AI models now trained on web-scale data and then released publicly carry a poisoning risk that cannot be recalled, and open-weight AI models now represent the sharpest edge of that problem.
How the Capability Compression Happened
Three forces drive the gap’s compression.
First, the open-weight ecosystem has professionalized. Meta’s Llama series, Alibaba’s Qwen family, and Mistral’s releases now undergo optimization at a scale that was only possible at closed labs two years ago.
Second, post-training techniques such as reinforcement learning from human feedback and direct preference optimization have become commodity knowledge, accessible to any fine-tuner. Third, benchmark-driven development means open-weight builders are explicitly targeting performance parity on the same evaluations that AISI uses.
The result is a dynamic where closed-model safety investments buy less and less time before equivalent capability diffuses to the open-weight ecosystem.
AI models now advance so rapidly on shared benchmarks that the gap between open and closed development cycles compresses with each new release cycle.
The Dual-Use Dilemma AISI Cannot Resolve
AISI’s report does not recommend restricting open-weight releases. The institute has consistently acknowledged the research, economic, and geopolitical arguments for open model development.
What the report does is sharpen the timeline problem.
Regulators and labs have operated on the assumption that a meaningful capability lag between closed and open models creates a window for safety interventions. The AISI finding that AI models now compress that window to as little as four months challenges the core premise of that strategy, and the recognition that open-weight AI models now operate near the frontier makes that challenge especially acute.
The Illinois AI Safety Act, which passed in June this year, targets exactly this scenario by imposing disclosure requirements on frontier developers.
But frontier-developer mandates do not reach the researchers downloading and deploying open-weight models outside any regulatory perimeter.
The gap between what the governance frameworks cover and what the capability curve is doing has rarely looked wider.
