Open-weight Chinese models narrowed the cyber-capability warning window.
The newest open systems are no longer only a pricing threat; current evaluations put them close enough to frontier cyber capability to change defender timing.
What happened
The UK's AI Security Institute reported that leading open-weight models are now much closer to frontier closed systems on cyber ranges than they were through most of 2025. NIST's CAISI assessment said Z.ai's GLM-5.2 was probably the most capable open-weight model at release and tested it on cyber, autonomy, and safeguard dimensions. The Financial Times reported the same finding as a narrowing China-US cyber gap, with GLM-5.2 showing strong performance while using fewer tokens than some US rivals.
Why it matters
Open weights change the control model. A closed lab can rate-limit, monitor, patch safeguards, or withdraw a dangerous system. Once a capable open model is public, defenders lose those central controls and the practical question becomes how quickly ordinary organizations can find and patch flaws before attackers automate the same search.
What to watch
AISI and CAISI follow-up benchmarks, GLM-5.2 and DeepSeek deployment in security tooling, evidence of autonomous exploit chains in the wild, procurement rules for open-weight models, incident-response use of local models, and whether closed labs use cyber-capability thresholds to justify restricted releases.
The caveat
The evaluations measure benchmarked capability, not observed global attack volume. The FT story describes a competitive and policy implication; it does not prove that Chinese open-weight models are being used in live attacks at scale.