The UK AI Security Institute (AISI) has published its first public measurement of how far open-weight models trail the closed cyber frontier, and the answer is roughly four to seven months, narrowed from six to ten months across most of 2025. For anyone running a high-consequence estate, that is not a technology story. It is a planning horizon. Whatever cyber capability is controllable at the frontier today should be assumed freely available, without the same safeguards, within about two quarters. The operators who cope with that window are the ones who already know which of their assets matter most.

A number that turns risk into a date

Cyber risk usually arrives as an abstraction. It is a category on a board risk register, a colour on a heat map, a line in an assurance report. It is rarely a date.

The AI Security Institute has now given the sector something closer to a date. In work published on 17 July 2026, it measured the distance between leading open-weight models and the closed frontier on cyber tasks. On a set of seventy narrow cyber evaluations, spanning four difficulty levels from technical non-expert through to expert, the best current open-weight models sit roughly four to seven months behind the closed models they most resemble. Through most of 2025 that gap was six to ten months. The trailing edge is catching up.

The narrow evaluations are only half of it. On a long-horizon simulation of a thirty-two-step attack chain, GLM-5.2 matched one of the closed frontier models outright, placing it under seven months behind on sustained, multi-stage operations rather than isolated tasks. Sustained operations against an estate are what asset owners actually have to survive.

The Institute was careful about what this does and does not mean, and so are we. This is a measurement of a moving gap, not a prophecy. The Institute also noted that its testing likely slightly underestimates the maximum capability of open-weight models, and that its conclusions apply only to the cyber domains tested. Both caveats point the same way. But the direction is legible, and the Institute framed the implication plainly: there is a short window to prepare before today's frontier cyber capabilities may become accessible without the same safeguards. When the people who run the national evaluations describe a window, the right response is to ask how wide yours is.

Why this lands on asset owners, not just security teams

It would be easy to file this under cyber and move on. That would be a mistake, because the consequence is operational, and it lands squarely on whoever owns the estate.

A shrinking capability gap does not threaten every asset equally. It threatens the ones that matter most: the systems whose failure carries safety, mission or continuity consequences, and the data flows that keep them running. The whole task of defending against a shortening window is a prioritisation task. You cannot concentrate defensive effort, patching discipline or monitoring on your most consequential assets if you cannot say, with confidence and evidence, which those assets are.

This is where the readiness question stops being about tools and starts being about foundations. Prioritising defence across an estate assumes three things are true. That the asset hierarchy is complete and current, so nothing consequential is missing from the picture. That criticality is recorded against those assets, so effort can be ranked rather than spread evenly across everything. And that the data describing how those assets connect is trustworthy enough to reason from. Where those conditions hold, a shortening window is a manageable planning input. Where they do not, the same window is a scramble, because the first task under time pressure becomes working out what you are defending.

Where the window bites first, and where it bites anyway

For Defence, this is not theoretical. Availability, sustainment and operational security all rest on a maintained, classified record of the estate. Through-life management assumes you know the criticality of what you hold. A diffusion timeline measured in months, rather than years, rewards the programmes that have already done the unglamorous work of getting their asset data into a state they can reason from, and exposes the ones that have deferred it.

The read-across to Critical Infrastructure is direct. Transport, energy and water estates carry enormous asset volumes and correspondingly complex data. When frontier-adjacent capability becomes cheap and widely available, the defensive advantage shifts to operators who can rank intervention by asset criticality and whole-life consequence rather than treating every asset as equal.

And it is becoming cheap. The Institute priced comparable runs. A hundred million tokens of evaluation cost around $85 on the closed frontier models tested, $46 on GLM-5.2, and $1.19 on DeepSeek V4-Pro. At the extreme that is a seventyfold difference for capability that is four to seven months behind. Cheap capability at scale changes who can afford to try.

For Central Government, the same logic applies to departmental and arm's length estates where accountability for the record is often the weakest link. The question an accountable officer should be able to answer is not whether the department has a cyber strategy. It is whether it could name its most consequential assets, and evidence the state of the data underneath them, if asked this quarter rather than next year.

None of this is confined to those three, and it would be a mistake to read it that way. A facilities management provider holding the asset record for dozens of client sites has the same exposure, multiplied by the number of clients. A manufacturer whose production depends on a supplier tier it has never mapped has it in a different shape, as the Jaguar Land Rover attack demonstrated in 2025 at a cost the Cyber Monitoring Centre modelled at £1.9 billion across more than 5,000 UK organisations. A local authority managing a property portfolio it inherited rather than built has it too, usually with the thinnest data of any of them. The regulatory pressure arrives at different times in different sectors. The underlying question arrives at the same time for everyone, because it is set by the capability curve rather than by a regulator.

What competent organisations do with a horizon

A planning horizon is a gift, if you use it as one. It converts an open-ended anxiety into a finite, ordered set of actions.

The disciplined response is not to buy a defensive tool and point it at the estate. A model or a control trained or deployed against an incomplete, out-of-date record inherits every gap in that record. The disciplined response is to use the window to get the foundations into shape: confirm the hierarchy, record criticality where it is missing, and establish clear ownership of the data so that when defensive effort is prioritised, it is prioritised against reality.

This is old discipline, not new panic. The practice of classifying an estate by asset criticality so that effort can be sequenced against consequence is exactly what ISO 55000 asset-management practice exists to support, and it remains entirely defensible ground to stand on. Our founder has been doing that work since 2000, first delivering hard facilities management into power generation, water and manufacturing estates, then in full facilities management from 2010, and on Ministry of Defence estates since 2017. The instinct it builds is simple. When a threat gets a timeline, you defend the crown jewels first, and you have to know which they are.

The Institute has given the sector a rare thing: a risk with a rough date attached. The organisations that treat it as a headline will read it, nod, and change nothing. The organisations that treat it as a horizon will spend the next two quarters making sure they can answer one question. Do we know which of our assets matter most, and can we prove the data underneath them is sound?

Foundations before automation. And, increasingly, foundations before the window closes.

Sources and further reading