There is a straightforward way to understand what the UK's AI Security Institute just published. Until recently, the most capable AI tools for cyberattacks were locked behind paid services controlled by companies like Anthropic and OpenAI. Those companies could monitor how their tools were used, cut off bad actors, and update safety filters. That control is the key word. It meant the most dangerous capabilities stayed somewhat contained.
That model is breaking down. The AISI has now confirmed, for the first time in a public report, that freely downloadable AI models have caught up to where the best paid systems were four to seven months ago. For most of 2025, the gap between free and paid was six to ten months. It is narrowing fast.
The cost numbers explain why this matters so much. Running a simulated 32-step attack on a corporate network, the kind involving multiple internal systems and around 20 machines, cost about $85 using a leading paid model. The same test using DeepSeek V4-Pro, a free model anyone can download, cost $1.19. For individual attack tasks, a paid model ran about $12.50 per task. DeepSeek V4-Pro ran the same task for 28 cents. Cheap enough to run thousands of attempts and only need one to succeed.
The safety filters on these free models do not compensate for this. AISI found that when DeepSeek refused a task, simply trying again bypassed the restriction. This is not a surprise: safety measures on free models depend on whoever built the model choosing to include them, and anyone can remove them after downloading. There is no provider watching over a private server in someone's office or data centre.
This sits alongside a separate and troubling finding from Cambridge University researchers: terrorist groups including Boko Haram are already using mainstream AI chatbots such as ChatGPT, Claude, Gemini, and others for attack planning, weapons troubleshooting, and building explosive devices. Islamic State operatives have reportedly been running internal AI training programmes since 2023. These groups are not waiting for better tools; they are using the tools that exist right now.
The UK's National Cyber Security Centre has responded with unusual directness. In June 2026, its head confirmed that more than 200 serious cyber incidents affecting UK critical infrastructure were managed in a single year, with around three-quarters linked to hostile foreign states. The agency has warned of a coming surge of software vulnerabilities being discovered by AI tools, forcing organisations to apply updates faster than ever before. Its message to business leaders is plain: this is no longer something to delegate to an IT team and forget.
For any organisation that stores customer data, runs financial systems, or relies on digital infrastructure, the practical shift is this: the cost and technical skill required to attempt a serious cyberattack on your systems has dropped dramatically in 2025 and 2026, and it will keep dropping. A criminal group or hostile actor who previously needed expensive tools and significant expertise can now access equivalent capability for almost nothing.
AISI is treating the remaining gap between free and paid models as a window. Defenders who have access to the strongest paid systems can, in theory, test their own networks against attack scenarios before those same capabilities are freely available without any guardrails. But that window is measured in months, not years. AISI plans to test a new model called Kimi-K3, whose public release is expected in late July 2026, and early indicators suggest it could close the gap further.
The practical response for non-technical business leaders does not require understanding how any of this works under the hood. What it requires is treating cyber resilience as a leadership responsibility now, not a technical problem sitting in an IT queue. That means knowing which systems are critical, having a plan for continuing operations if those systems are disrupted, and making sure your organisation is applying security updates promptly. The NCSC has said directly that preparation cannot be improvised during a crisis. The organisations that will be most exposed are those still treating a major cyber incident as something that happens to other people.