The UK AI Security Institute (AISI) published a finding on 17 July 2026 that will be read by some as the strongest case yet for restricting open-weight AI: open models like Zhipu's GLM-5.2 and DeepSeek's V4-Pro now trail the most capable closed frontier models on cyber offense benchmarks by only 4 to 7 months — down from a 6-to-10-month gap through most of 2025. Once a model's weights are public, AISI notes, "safeguards can be removed, and copies can be downloaded, redistributed, and run on private systems beyond monitoring." That is a real and permanent property of open release: there is no recall button (AISI blog, 17 July 2026).
The strongest version of the case for concern
Take the finding on its own terms first. AISI's "Narrow Cyber Tasks" benchmark — 70 tasks spanning vulnerability research, reverse engineering, web exploitation and cryptography across four difficulty tiers — found GLM-5.2 performing comparably to Anthropic's Opus 4.6, released just four months earlier, and DeepSeek V4-Pro matching Opus 4.5 from five months prior. AISI's companion Frontier AI Trends report shows why the trend line matters: models could barely complete apprentice-level cyber tasks in late 2023 (under 9% success), but hit roughly 50% by 2025, with autonomous task length doubling every eight months (AISI Frontier AI Trends Report). Layer cost onto capability and the picture sharpens further: AISI estimated a 100-million-token autonomous cyber run at roughly $85 on a closed frontier model versus $1.19 on DeepSeek V4-Pro. A capability that recently required frontier-lab compute budgets is becoming available at consumer-hobbyist prices, with no vendor-side kill switch once the weights leave the building. Regulators who want a legal lever to slow that down, or at minimum to mandate pre-release safety testing for the largest open releases, are not inventing a problem.
Why AISI itself doesn't reach for that lever
What's notable, reading the actual report rather than the headline version of it, is what AISI does not say. It does not call for export-style controls on model weights, a licensing regime for open releases, or a ban on publishing models above a capability threshold. Its concrete recommendation is that the UK's National Cyber Security Centre push organisations to invest in cybersecurity baselines and AI-enhanced defences during the window before capabilities proliferate — a defensive posture, not a restrictive one. That's consistent with the framing AISI has used since its 2025 rebrand from "Safety" to "Security" Institute: evaluate and warn, but leave the policy lever to ministers and regulators.
And the UK's ministers and regulators have, so far, chosen not to reach for a weights-control lever either. There is still no UK AI Act. The government's operative document remains the March 2023 white paper, A pro-innovation approach to AI regulation, which explicitly rejected a new cross-sector statute in favour of existing regulators applying five non-statutory principles within their remits (gov.uk white paper). As of this summer, a House of Commons Library briefing confirmed no AI bill was before Parliament. That is the right call, and AISI's own report is evidence for why: a body built to measure capability precisely so that policy doesn't have to guess at it just measured this gap without recommending the sledgehammer response.
Where the caution is actually warranted
The steelman case doesn't disappear just because AISI declined to act on it. "Beyond monitoring" is the load-bearing phrase in the report, and it's true regardless of what any single regulator does next: once GLM-5.2 or DeepSeek V4-Pro weights are downloaded, no UK statute, EU rule, or US export control reaches the copy sitting on a private server in a jurisdiction with no interest in enforcing any of them. That argues for two things the UK is already doing reasonably well and one it should do more of. First, AISI's own pre-release evaluation access to frontier labs — voluntary, but taken up by every major closed-model developer — should be extended, on a similarly voluntary basis, to the open-weight labs (Zhipu, DeepSeek, Meta) whose releases are now closing the gap; a testing regime that only sees half the frontier is only half a warning system. Second, NCSC's baseline-defence push deserves funding, not just encouragement, since the honest read of "the gap is narrowing" is that defenders' runway is shrinking too. What the UK should not do is treat a capability-gap number as a mandate for the one policy AISI itself avoided proposing: restricting publication of open-weight models. That would hand a durable advantage to the two or three labs that can already meet any plausible compute or licensing threshold, while doing nothing to stop weights already circulating from being fine-tuned to strip whatever safeguards remain. Proportionate regulation here means matching the actual, narrow finding — a shrinking capability gap with permanent unmonitorability once released — rather than the broader anti-open-source case that report is sometimes recruited to support.
The bottom line
AISI did its job: it measured a real trend precisely and said so plainly, including the uncomfortable part about safeguards being unenforceable post-release. The UK government's job now is to resist treating that measurement as a ready-made case for restricting open publication, a position AISI itself never took, and instead to fund the defensive side of the ledger the report actually recommends.