Independent monitor · Global evidence

How much lead time do defenders have?

Published evidence on how fast AI cyber capability is rising, how quickly open-weight models follow, and what has actually been reported in the wild. Every number is sourced. We do not estimate missing values.

AISI is the primary comparable open-versus-closed cyber gap for the headline. Global peer research, laboratory disclosures and agency reporting broaden the evidence base.

Lead-time headline

4 to 7 months

On AISI's evaluations, leading open-weight models trail the closed frontier on cyber by this range (Jul 2026). Capability that is frontier-only today may be widely downloadable within months.

Caveat: Range results are weaker evidence than narrow tasks. Gap narrowed from 6 to 10 months. Lab results are not real-world attack rates.

Published evidence

Capability, access and reporting

Plotted observations and published ranges only. No inferred attack-rate curve.

A · Frontier capability

Published capability signals

On AISI's evaluations, marked observations only. Hover or tap a point for its source and caveat.

Published apprentice-level result ICS range milestone, separate from percentage scaleDashed connector is for readability only, not data or a forecast.
Sources and caveats for plotted points

Global peer evidence

Three lenses on model capability

Independent evaluations and developer disclosures add context. Their tasks and scales differ, so they are never merged into one score.

D · Curated incident count

2

Reported AI-orchestrated campaigns tracked

Count of curated, published incident rows only. This is not an estimate of global prevalence.

Last updated: 5 Oct 2026

Capability and reported activity

C · Dual evidence timeline

Co-occurrence on a timeline is not proof of cause.

CapabilityNewer Mythos Preview checkpoint: The Last Ones 6 of 10 (May 2026)
CapabilityFirst ever completion of the Cooling Tower ICS range: 3 of 10 (May 2026)
CapabilityLab system card reported a broader cyber evaluation suite (Jul 2026)
Reported activityTaiwan government confirms hybrid AI-agent campaign reporting (13 Aug 2026)
CapabilityLab system card treated the model as High cyber capability under its framework (2026 system card)
CapabilityArtificial Analysis Cyber Index leaders scored 56 (Sep 2026)
Published lab point Reported AI-orchestrated activity Context, not AI-attributed
Open full timeline

Sourced incident reporting

Reported AI-orchestrated activity
Independently corroborated
high confidence

Taiwan government confirms hybrid AI-agent campaign reporting

Taiwan’s digital affairs authorities confirmed a campaign against government networks using a hybrid of conventional techniques and open-source AI-agent tooling. Reuters and Taiwan’s national news agency reported the government confirmation.

Caveat: High confidence that the campaign occurred and was government-confirmed. The AI-orchestrated character is medium confidence because technical detail comes from private-sector analysis. Scale figures and attribution are not repeated here because they are not established in the government statement.

Reported AI-orchestrated activity
Self-reported by developer
medium confidence

AI-orchestrated espionage campaign reported by Anthropic

According to Anthropic, a group it assessed as state-sponsored used its coding agent to attempt intrusions into roughly 30 targets, with a small number of successes. Anthropic states the AI performed around 80 to 90% of tactical work, with 4 to 6 critical human decision points per campaign.

Caveat: Self-reported by the AI developer. Independent researchers have questioned some claims. Not independently verified.

All incident reporting

Latest news

Daily reporting lane · live items

Last refreshed: 5 Oct 2026, 15:25 BST

All news

Check your readiness

Lead Time Check is a sibling tool that helps you assess how prepared your organisation is.

Check your readiness

Subscribe to The AI Cyber Risks Briefing

A short weekly briefing, every Monday (UK time).

Subscribe