The Frontier Gap Is Compressing and the Safeguards Do Not Travel with the Weights
On the July 2026 UK AI Security Institute evaluation of open-weight frontier cyber capability, the shrinking lag between open and closed release, and the deployment-time controls that vanish the moment weights become public.
On July 27, 2026 the United Kingdom AI Security Institute published a technical evaluation titled How Far Behind the Frontier are Leading Open Weight Models on Cyber?. The report measures the cyber capability of the two most capable openly released models of mid-2026, GLM-5.2 and DeepSeek V4-Pro, against the closed frontier at the time of testing. The finding is compact and load-bearing.
GLM-5.2, released in June 2026, performs comparably to closed frontier models released four to seven months before it. On narrow cyber tasks it sits alongside Opus 4.6 and GPT-5.3-Codex, closed models released roughly four months earlier. On the Last Ones range, a thirty-two step corporate network attack that spans four subnets and roughly twenty hosts and takes a human expert an estimated twenty hours to complete, GLM-5.2 reaches as far as Opus 4.5, a model released just under seven months prior. DeepSeek V4-Pro sits behind, comparable to Opus 4.5 on the narrow tasks and below Sonnet 4.5 on the ranges. The Institute characterizes the gap as four to seven months.
That gap is narrower than the gap the same evaluation apparatus measured across most of 2025. In the earlier period the lag was six to ten months. The direction is unambiguous. The interval between the closed frontier and the open frontier is compressing.
What the interval used to buy
The Institute is explicit about why this interval matters. In the report's own framing, the gap between the open and closed cyber capabilities of frontier models provides a preparation time, a window for cyber defenders with access to the most capable closed systems to take action before today's frontier cyber capabilities might become available without the same safeguards. The interval is not a curiosity. It is a defender resource.
A defender operating with closed frontier access during the four to seven month window can, in principle, adapt threat models, harden exposed surfaces, adjust detection heuristics, and prepare disclosure or mitigation posture against attack patterns that the equivalent open model will make broadly available. When the interval was six to ten months, the preparation surface was wider. When the interval is four to seven months, the surface narrows. The Institute stops short of characterizing the new interval as insufficient. It reports the shrinkage and lets the reader carry the implication.
The evaluation, in numbers
The report is quantitative in a way that makes it usable as reference. On the seventy task subset of the Institute's cyber capability suite that supports historical comparison, Opus 4.6 cost fifteen dollars and seventeen cents per task and GLM-5.2 cost six dollars and twelve cents per task. On the Last Ones range, an estimated one hundred million token run cost roughly eighty five dollars for Opus 4.5 and 4.6 and one dollar and nineteen cents for DeepSeek V4-Pro. The Institute is careful to note that the Institute did not use first-party providers for open weight testing so the reported open cost may not track a production deployment exactly. The order of magnitude is still stark. On the specific range, closed frontier capability at closed frontier pricing costs seventy times what an open equivalent costs at inference. The economic asymmetry is not incidental. It is a structural driver of how quickly the open frontier is adopted, and by whom.
The safeguard problem
The Institute's second load-bearing claim is not about the gap. It is about what happens the moment a model is released with open weights. The claim, in the report's phrasing, is that open weight release therefore creates a persistent and irreversible risk of misuse.
The mechanism is direct. Deployment time safety measures such as monitoring, classifiers, and user banning require control over access to the model. Those measures cannot be universally applied once the weights are made public. The techniques that remain, chiefly refusal training, are often easily reversible with access to the weights. The report notes that during testing of DeepSeek V4-Pro, occasional refusals on narrow cyber tasks were circumvented simply through a small number of repeat attempts on the refused prompts. No custom fine-tuning was required to overcome the residual behavioral safeguards. Repeat sampling was sufficient.
That is the structural finding worth naming. The safeguards that a closed frontier developer applies at the deployment surface, whether input filtering, output classification, session monitoring, rate limits, account level controls, or account banning, all live at the interface between the user and the model. When the weights travel, the interface does not travel with them. The controls attach to the hosting decision, not to the artifact. Once the artifact is public, the controls are absent and cannot be reconstituted by the original developer.
The pending case
The report concludes by naming a model it has not yet tested. Kimi K3, released by Moonshot AI on July 16, 2026 and announced as open weight by the end of the same month, will enter the Institute's evaluation cycle when the weights are publicly available. The Institute has already measured Kimi K3 as the most capable non-frontier model on its narrow cyber tasks in a preliminary assessment, ahead of GLM-5.2. That preliminary assessment, published jointly by AISI and the United States Center for AI Standards and Innovation on July 23, 2026, reports Kimi K3 achieving thirty two percent on an exploit development benchmark and clearing further steps on the Last Ones range than any prior open-weight model. If the shrinkage pattern holds, the interval when Kimi K3 becomes generally available will be tighter than the interval GLM-5.2 opened, not wider.
What remains on the table
- If the four to seven month interval is the working preparation window for closed frontier defenders against open frontier capability, what artifact enumerates the specific defensive investments that must be scheduled inside that window and closed before the window shuts.
- If deployment time safeguards cannot travel with the weights, what governance category attaches to the release decision itself, and which authority is empowered to reason about it before the release is executed.
- If safety training is reversible through repeat sampling and residual open-weight refusals are not durable, what does the Institute's own testing methodology imply about the interpretability of a stated open-weight refusal rate on any published capability card.
The policy instruments and the deployment tempo are not aligned.