UK AI Security Institute Analyzes Cybersecurity Gaps in AI Models

As open AI models narrow the gap with proprietary ones, expect strategic shifts in cybersecurity policy by 2027.
Key Points
- 1First public analysis by AISI on performance gaps in cybersecurity models.
- 2Shrinking gap suggests open models nearing proprietary capabilities.
- 3Potential shift in national cybersecurity strategies with open model advancements.
What Changed
In 2026, the UK government's AI Security Institute (AISI) conducted a comprehensive analysis comparing the cybersecurity capabilities of proprietary and open weight AI models. The focus was on models such as GLM-5.2, DeepSeek V4-Pro, Claude Opus 4.6, and GPT-5. This marked the first public analysis by AISI examining the performance gap. Previously, the gap was measured at 6 to 10 months, indicating how far behind open models were from their proprietary counterparts. However, recent evaluations show this gap has reduced to 4 to 7 months. Specifically, GLM-5.2 was released 4.3 months after Claude Opus 4.6, while DeepSeek V4-Pro's release fell between Claude Opus 4.5 and GPT-5, both launched in 2025.
The analysis involved 70 evaluations targeting narrow cyber capabilities. AISI noted that the gap widens for complex, long-horizon tasks, where models must integrate multiple capabilities for complete operations. This suggests that while open models are closing the gap, they still face challenges in complex generalization tasks.
Strategic Implications
The narrowing gap between open and proprietary models could significantly impact global cybersecurity strategies. As open models like GLM-5.2 and DeepSeek V4-Pro approach the capabilities of proprietary giants such as Claude and GPT, the balance of power in cybersecurity could shift. This development may necessitate revisions in regulatory frameworks to ensure security as these models become more accessible.
Countries relying on proprietary models for their cybersecurity defenses might need to reconsider their strategies. The open models' advancement could democratize access to cutting-edge AI capabilities, potentially altering the dynamics between nations with robust proprietary AI industries and those leveraging open-source models.
What Happens Next
In the near term, we can expect increased scrutiny and possibly regulatory interventions as open models continue to evolve. Policymakers may introduce new guidelines to manage the risks associated with the broader availability of advanced AI capabilities. Additionally, proprietary model developers might accelerate innovation to maintain their competitive edge.
By mid-2027, governments could implement policies emphasizing collaboration between proprietary and open-source entities to ensure cybersecurity defenses remain robust. This could lead to joint research initiatives and shared security frameworks.
Second-Order Effects
The shrinking gap may influence the AI supply chain, particularly in sectors like defense and technology. Companies developing proprietary models might face pressure to lower costs or open some of their technologies to remain competitive. This shift could also impact funding dynamics, with investors potentially redirecting resources towards promising open-source projects.
Moreover, regulatory spillover could affect adjacent markets, such as cloud computing and data privacy, as the integration of advanced AI capabilities demands new compliance standards and security protocols.
Expert Perspective
Analysts suggest that while open models are closing the gap, the true test will be their performance in real-world applications beyond controlled evaluations. The interplay between open and proprietary models could redefine AI sovereignty, with nations potentially gaining more autonomy by leveraging open-source advancements.
In the broader context, this development mirrors past shifts in technology, such as the rise of open-source software in the 2000s, which democratized access to technology but also required new governance models. Unlike the software revolution, the stakes in AI are higher due to its profound impact on national security and global power structures.
Free Daily Briefing
Top AI intelligence stories delivered each morning.