The UK institute measures AI cyber-attacks
The UK AI Security Institute described tests of seven models (August 2024 to February 2026) on two simulated networks: on a 32-step corporate attack Opus 4.6 averages 9.8 steps at 10M tokens against 1.7 for GPT-4o.
Why it matters
There is now an independent measurement of how far models get along a long chain of a cyber-attack rather than on single tasks. An editorial assessment: it is the atlas's first such assessment of Opus 4.6 not made by its developer.
What is named. Two cyber ranges without active defenders: "The Last Ones", a 32-step corporate network attack that a human expert is estimated to need about 14 hours for; "Cooling Tower", a 7-step attack on a cooling-tower control system, about 15 hours. Seven models compared. On the first range at 10M tokens the average is 1.7 steps for GPT-4o (August 2024) and 9.8 for Opus 4.6 (February 2026); at 100M tokens Opus 4.5 gets 11.0 and Opus 4.6 15.6. The best single Opus 4.6 run completed 22 of 32 steps, roughly 6 of the 14 human hours. Going from 10M to 100M tokens gains up to 59% with no plateau; a 100M-token attempt with Opus 4.6 costs about 80 US dollars. On the second range, at 10M tokens most models complete no step; at 100M Opus 4.6 averages 1.4 steps and GPT-5.3 Codex has a single run at 3 of 7. Some models found an unintended path and skipped the start of the chain; the institute patched the range for its main runs. What the record does not claim. The full paper (arXiv:2603.11214) was not read, only the blog post. The ranges have no active defenders, so this is attack strength without a response, not performance on a real network. The "February" date in the outside report was wrong: the post is 16 March and the paper 11 March.