This summer, the Chinese artificial intelligence firm Z.ai demonstrated the growing capabilities and risks of open-access AI technologies by powering Tenzai, a cybersecurity company, to victory in a three-month-long hacking competition. The contest, organized on the HackerOne platform, challenged participants to identify vulnerabilities across networks operated by government agencies, banks, airlines, hotels, and various other enterprises.

Unlike other competitors who used AI systems developed by American companies such as Anthropic and OpenAI, Tenzai relied on Z.ai’s open-weight AI models—software architectures freely available without restrictive guardrails. This lack of control enables users to apply the AI systems in any manner they choose, including potentially malicious activities, raising concerns among some experts about the broader security implications.

American AI companies increasingly emphasize strict usage controls and regulatory oversight to prevent abuse, but critics argue that these limitations may hamper legitimate cybersecurity defenses. In contrast, proponents of open-weight models suggest that unrestricted AI technologies empower defenders as much as attackers. “When these models are properly leveraged, they can help Americans defend themselves,” one cybersecurity professional said.

Tenzai’s winning approach utilized a coordinated ensemble of up to 30 AI agents working collectively to probe target networks. These agents included “thinking” units orchestrating the attack, “action” agents scanning for vulnerabilities, exploit agents chaining together security flaws, and “rebuttal” agents verifying successful breaches. In a notable example, the AI team accessed a web server managed by an airline without proper credentials, subsequently locating customers through the airline’s mobile application.

Experts highlight that the accessibility of open-weight AI models places advanced cyberattack capabilities previously held by nation-states into the hands of ordinary hackers, significantly complicating defensive efforts. Researchers from Hinoki, another cybersecurity firm, demonstrated that guardrails embedded in Chinese AI systems can be removed within a day at minimal cost, making it easier for malicious actors to repurpose these models.

Despite the ominous outlook for near-term cybersecurity, many professionals anticipate that defensive measures will evolve in response. “Cybersecurity always comes in waves,” said one expert. “In the short term, we expect more attacks and service disruptions that will affect everyday Americans. But defensive capabilities will catch up.”

As open-weight AI systems become increasingly prevalent, industry leaders stress that the technology is “here to stay.” “You can’t put the genie back in the bottle,” said Pavel Gurvich, Tenzai’s chief executive. This reality underscores ongoing debates over how to balance AI openness, innovation, and security in an interconnected digital landscape.