July 21, 2026
Cheap, Powerful, and Harder to Stop: What Open-Weight AI Models Mean for Your Business Security
Imagine a cyberattack tool that cost $85 to run four months ago now costing 28 cents. That is not a hypothetical. That is the finding from the British AI Security Institute (AISI), and it has serious…
Cheap, Powerful, and Harder to Stop: What Open-Weight AI Models Mean for Your Business Security
Imagine a cyberattack tool that cost $85 to run four months ago now costing 28 cents. That is not a hypothetical. That is the finding from the British AI Security Institute (AISI), and it has serious implications for every small and mid-size business operating online today.
The AISI published its first-ever public assessment comparing open-weight AI models to closed, proprietary frontier systems on cyber capability benchmarks. The verdict is stark: open-weight models like GLM-5.2 and DeepSeek V4-Pro now trail the best closed systems by only four to seven months in cyber capability, down from a gap of six to ten months at the start of 2025. In other words, the most capable AI cyber tools available to the general public are closing in on state-of-the-art systems at a pace that is outrunning the defenses being built around them.
AISI used two distinct testing methods to reach this conclusion. The first, called Narrow Cyber Tasks, is a benchmark of 70 tasks across four difficulty levels covering vulnerability research, reverse engineering, web exploitation, and cryptography. On those tasks, GLM-5.2 matched the performance of Claude's Opus 4.6, which was released in February 2026, placing it roughly four months behind the frontier. DeepSeek V4-Pro performed at the level of Opus 4.5, released in November 2025. The second method, called Cyber Ranges, simulates full autonomous attack scenarios in a network environment. "The Last Ones" scenario involves a 32-step attack on a corporate network with four subnets and approximately 20 hosts, a challenge AISI estimates would take a skilled expert around 20 hours to complete manually. GLM-5.2 performed comparably to Opus 4.5 on this test. In this more complex scenario, the gap widens to around seven months. The cost differences, however, are where things get alarming for defenders. Running a 100-million-token Cyber Range test cost approximately $85 using Opus 4.5 or 4.6, around $46 using GLM-5.2, and just $1.19 using DeepSeek V4-Pro. For individual tasks, Opus 4.6 cost about $15 per task while DeepSeek V4-Pro cost just 28 cents. That price compression makes scaled cyberattacks economically viable for bad actors who previously lacked the resources.
Compounding the concern, AISI found that the safety measures built into these open-weight models are largely ineffective. DeepSeek V4-Pro sometimes refused to complete reverse-engineering tasks, but simply re-submitting the request was enough to bypass the restriction. Unlike closed systems, where providers can monitor usage, apply classifiers, and limit access, open models can be downloaded, modified, and run on private infrastructure with no oversight whatsoever. AISI describes this as "a persistent and irreversible risk of misuse." The institute also notes that the window between when a capability appears in closed systems and when it becomes freely available in open ones is shrinking fast, and that window is exactly when defenders have the best opportunity to prepare.
For small and mid-size business owners, this shift deserves direct attention. Your business does not need to be a Fortune 500 company to be targeted by AI-assisted cyberattacks. As the cost of executing sophisticated attacks drops to cents per attempt, even low-value targets become economically worthwhile for automated threat actors. Your customer data, your email systems, your payment infrastructure, and your website are all surfaces that increasingly cheap and capable AI tools can probe at scale. The old assumption that "we are too small to be worth attacking" no longer holds.
There is also a second-order consideration here. The same open-weight models that are being evaluated for cyber risk are also the models powering low-cost, customizable AI tools across marketing, customer service, operations, and content production. Knowing that these models carry security tradeoffs alongside their business benefits is not a reason to avoid them. It is a reason to deploy them thoughtfully, with appropriate data hygiene, access controls, and vendor scrutiny.
The AISI finding that defenders with access to closed frontier systems have a four-to-seven-month advantage window before those capabilities become freely available is actually useful intelligence for businesses. It tells you that the AI security landscape is on a predictable, if accelerating, cycle. Planning for that cycle rather than reacting to it is the posture that protects growing businesses.
This week, review which AI tools your team is currently using and confirm where your data is going. Open-weight tools that run locally or on private infrastructure keep your data off third-party servers, which is a genuine advantage. But if those tools lack access controls or audit logs, the same openness that protects your data from providers can leave it exposed in other ways. Identify one AI tool in active use in your business and verify whether its security settings, access permissions, and data handling policies match the sensitivity of the work it is touching.
Staying ahead in AI-powered marketing means understanding not just what these tools can do for your growth, but what the broader AI landscape means for your risk posture. The businesses that thrive will be the ones that use AI strategically and securely.
Originally inspired by: Open-weight models now match frontier cyber performance from just four months ago at a fraction of the cost (https://the-decoder.com/open-weight-models-now-match-frontier-cyber-performance-from-just-four-months-ago-at-a-fraction-of-the-cost/) See how Leads to Conversion can help protect and grow your business with smarter AI strategy. Get your free AI audit
