AI Pulse by Inblix

Open models now match frontier cyber attacks from just 4 months ago

The Decoder · Jul 18, 2026 · 2 min read · Read original article →

Curated by the Inblix editorial team


Featured image for article: Open models now match frontier cyber attacks from just 4 months ago

The gap between open-weight AI models and top proprietary systems in offensive cyber capabilities has shrunk to as little as four months, according to the first public assessment from the British AI Security Institute (AISI). It’s a finding that flips the script on a debate that often feels abstract: the models anyone can download are now nearly as dangerous as the ones locked behind corporate APIs, but they cost pennies to run.

AISI tested models like GLM-5.2 and DeepSeek V4-Pro against two benchmarks. On a set of 70 narrow cyber tasks—spanning vulnerability research, reverse engineering, and web exploitation—GLM-5.2 matched the performance of Opus 4.6 from February 2026. That’s a four-month lag. DeepSeek V4-Pro landed at the level of Opus 4.5 from November 2025. In a more complex simulated corporate network attack called “The Last Ones,” a 32-step gauntlet across four subnets that would take a human expert roughly 20 hours, the gap widened to about seven months. AISI cautions that the smaller sample size here makes the evidence shakier.

The economics are what make this genuinely alarming. A 100-million-token Cyber Range test cost about $85 using Opus 4.5 or 4.6, roughly $46 with GLM-5.2, and just $1.19 with DeepSeek V4-Pro. For individual tasks, DeepSeek V4-Pro clocked in at 28 cents versus $15 for Opus 4.6. Those numbers mean scaled, automated attacks are no longer a nation-state luxury. And the safety guardrails that exist on these open models are cosmetic at best. AISI found that when DeepSeek V4-Pro occasionally refused a reverse-engineering task, simply retrying the prompt worked. Once model weights are public, there’s no access to control.

AISI frames the shrinking gap as a closing window for defenders. The idea is that cyber teams with access to the strongest closed models can prepare before equivalent capabilities hit the open web without safeguards. April 2026 threw urgency at that timeline—models like Mythos Preview and GPT-5.5 delivered some of the largest jumps in cyber capability AISI has ever measured. The UK’s National Cyber Security Centre has already issued international warnings. Whether open models will continue this trajectory or hit a ceiling is the question nobody can answer yet, but the trend line isn’t comforting.

💡 Key Takeaways

  1. Open-weight models like GLM-5.2 now match proprietary systems from four months ago on specific cyber tasks, down from a six-to-ten-month gap for most of 2025.
  2. Running an open model for a large-scale cyber test cost $1.19 versus $85 for a closed frontier model, making automated attacks radically cheaper to scale.
  3. Safety measures on open models are effectively useless—DeepSeek V4-Pro's occasional refusals could be bypassed simply by retrying the same prompt.
  4. AISI treats the performance gap as a shrinking preparation window for defenders, but the test scenarios exclude real-world defenses like active human responders.

Keep reading: See related articles below for more coverage on this topic.

Get smarter about AI

The sharpest AI news, curated daily. Delivered free to your inbox.

Learn more

Glossary terms

← Back to all articles