[Photo: AI Safety Institute website capture]

More than half of the AI models assessed by the AI Safety Institute this year were open-weight, according to the institute. Chinese models such as DeepSeek, Qwen and Kimi made up 58 percent of the open-weight models assessed.

According to the AI Safety Institute and others on Sept. 18, there were 34 unique AI models assessed by the institute from January to August this year, excluding duplicates. By disclosure type, 19 were open-weight, or 55.9 percent, while 15 were closed models, or 44.1 percent.

Of the 19 open-weight models, 11 were Chinese, accounting for 57.9 percent. The assessed models included major Chinese open-weight models such as Kimi, DeepSeek, Qwen, GLM, InterVL and MiniMax. The list also included 4 South Korean models, 3 U.S. models and 1 French model.

Depending on the target and timing, the institute examined prompt injection attacks, sensitive information leakage, abuse of computing resources and the potential spread of malicious behavior. It also assessed cybersecurity, web exploits, malicious links and harmfulness of responses.

For multimodal models, it checked capabilities such as advance prediction of harmful behavior, classification of risk types and detection of jailbreak attacks. More recently, it has also been assessing whether recommendations or answers become biased in a particular direction when AI agent memory is contaminated.

The institute assesses not only open-weight models but also closed frontier models such as GPT and Claude. It is difficult to verify every model released in a uniform way, so it selects targets for assessment by considering importance and policy issues. It is currently assessing GPT-6 Astra, the latest frontier model, in line with responses to pending issues by the Ministry of Science and ICT.

The industry sees open-weight models as carrying safety risks different from closed models because users can modify them directly or conduct additional training by making weights public.

An official at a company developing open-weight-based AI services said, "With open-weight, users can directly touch the weights, so it is also possible to weaken guardrails or protective devices," and added, "Unlike closed frontier models, the fact that users can arbitrarily remove safety devices is a risk factor."

Global AI developers are also warning of cybersecurity risks in open-weight models.

Wana Tun (와나 툰), an applied AI security specialist at OpenAI, said at the recent 'AI Risk Conference Seoul 2026' that attackers could cause significant damage if they fine-tune non-frontier models and open-weight models with relatively weaker guardrails and invest sufficient time and tokens. Tun said the intelligence level of these models is only about 6 to 8 months behind frontier models.

Jang Gwang-un (장광운), a security strategy adviser at Microsoft Korea, also said at the same event that the cyberattack capabilities of open-weight models are rapidly narrowing the gap with frontier models. He said accessibility and ease of use could popularise advanced cyberattack capabilities.

The issue is that staffing and computing resources are insufficient compared with the number of models that need to be assessed. The AI Safety Institute currently uses 16 Nvidia H200 GPUs for its in-house assessments. GPU utilisation for assessments runs at about 70 to 80 percent, and some assessments run continuously for several days once they start. As Chinese open-weight models have recently grown larger and repeated model runs have become necessary for AI agent assessments, the burden on computing resources has also increased.

Kim Myung-joo (김명주), head of the AI Safety Institute, said, "Some of the Chinese open-weight models being released these days are so large that they will not run on most GPUs, and agent evaluation requires a lot of resources and time," and added, "If possible, it would be good to evaluate all major models, but in reality we are short of both manpower and GPU resources."

He added, "New models are also being released rapidly, so it is difficult to verify every model right away," and said, "In the end, we have no choice but to set priorities and conduct selective evaluations depending on importance and pending issues."

Keyword

#AI Safety Institute #DeepSeek #Qwen #Kimi #Ministry of Science and ICT
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.