
Open-weight AI models—whose code is publicly available—are catching up to commercial closed models, closing a four- to seven-month gap in cyber capabilities, according to the UK's AI Safety Institute.
While open models offer advantages like customization and collaboration, their removable guardrails make powerful capabilities such as cyberattacks and biological threats more accessible to malicious actors, raising safety concerns as the gap narrows.
What happened
The UK's AI Safety Institute found that the most capable open-weight AI models (those whose code is publicly available) are four to seven months behind the best closed commercial models in cyber capabilities. Open-weight models can be modified for specific user needs and enable easier collaboration, but their safety guardrails can be removed.
Why it matters
Removing guardrails from open models makes powerful AI capabilities—particularly in cyber attacks and biological threats—more accessible to bad actors. Boko Haram militants in Nigeria are already using AI (mostly closed models) to plan attacks and gain tactical advantages, according to The New York Times. Anthropic's CEO recently noted that open models "potentially present a higher risk," though he argued that all powerful models, not just open ones, should be tested for safety.
What to watch
The gap between open and closed models is narrowing. As open-weight models improve and draw closer to frontier capabilities, the tension between transparency and safety—and between ease of use and misuse prevention—will likely become more acute for regulators and companies.
The UK's AI Safety Institute released an analysis showing that open-weight AI models—those whose code is publicly released—are narrowing the performance gap with frontier closed commercial models. The institute found that the most capable open models currently lag four to seven months behind the best closed models when measured on cyber capabilities. Open-weight models offer concrete benefits: they can be adapted and fine-tuned for specific organizational or user needs without reliance on a third-party provider, and they facilitate easier collaboration across teams and institutions. However, this openness comes with a critical liability. Because the models are publicly available, users can remove or disable the safety guardrails and restrictions that creators have built in, making advanced AI capabilities—particularly in cyberattacks and biological threat research—available to actors with harmful intent. Evidence of this risk is already materializing: The New York Times reported that Boko Haram militants in Nigeria are leveraging AI tools (predominantly closed models, in that case) to plan military attacks and gain tactical advantages. Anthropic CEO Dario Amodei recently acknowledged in writing that open models "potentially present a higher risk," yet he framed the safety challenge as broader than the open versus closed distinction, arguing that all powerful AI models, regardless of their licensing model, should be evaluated and tested for safety risks before deployment.
The narrowing gap between open-weight and frontier closed models represents a critical inflection point in AI safety. The UK's AI Safety Institute's finding—a four- to seven-month lag—suggests that what were once exclusive capabilities of well-resourced commercial labs are becoming accessible to a broader ecosystem. Open-weight models carry inherent trade-offs: their transparency and modifiability enable legitimate customization and research collaboration, but these same properties lower the barriers to misuse. The removal of safety guardrails transforms theoretical capabilities into practical ones, and the body's reference to Boko Haram's use of AI for attack planning underscores that the risk is not hypothetical. Anthropic's CEO framed the issue as one not unique to open models—all powerful AI systems warrant safety testing—yet the removability of controls in open architectures creates an asymmetry: closed models retain their safeguards by design, while open ones depend on user restraint or external oversight. As the technical gap closes, the stakes for governance intensify.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
Ask AI anything about this article. Q&As are published on this page for other readers too.
Meta CEO Mark Zuckerberg published a 6,500-word essay Monday outlining his vision for artificial intelligence…

A portable, open-source tool called Se-harness (seh) generates unified instruction files (AGENTS.md) that work…

OpenAI announced ChatGPT Business Premium seats on Monday, priced at $125/month (or $100/month if billed annua…

Meta has released Muse Glimmer, a 30B open-weight dense model with a 120K+ context window designed for local A…

Meta CEO Mark Zuckerberg announced in an Instagram video Monday that the company will open-source its latest A…

ServiceNow has announced AI-powered agents designed to operate within security operations centers (SOCs), auto…

The AI news that matters, in one minute each morning.
Sign up free