Palo Alto Networks has spent the past two years telling the market that frontier AI models are reshaping how attackers operate. On August 30, 2026, the company’s own chief information officer, Meerah Rajavel, complicated that narrative. In an interview with Business Standard, Rajavel said the biggest danger to enterprise security isn’t the cutting-edge, gated AI systems from OpenAI, Anthropic, or Google. It’s the cheap, downloadable open-source AI models that show up four to six months after a frontier release and cost almost nothing to run.
That’s a notable admission from inside one of the world’s largest cybersecurity vendors. It shifts the industry conversation away from headline-grabbing “AI apocalypse” scenarios involving GPT-class systems and toward a quieter, harder-to-police problem: anyone with a GPU and some scripting skill can now run an open-weight model good enough to automate phishing, write malware variants, or chain together exploits. This news analysis breaks down what Rajavel actually said, how it lines up with 2025-2026 threat data from CrowdStrike and Check Point, what it means for the open-source AI security threat debate, and where the cybersecurity market goes from here.
What Rajavel Told Business Standard
According to the Business Standard interview, published from Palo Alto Networks’ headquarters in Palo Alto, California, Rajavel drew a clear line between two categories of AI systems. Frontier models, she argued, still carry real barriers to misuse: they’re metered, monitored, and often require payment tied to an identity. Open-source models don’t have those chokepoints once they’re released into the wild.
“The biggest threat is the open-source models, which are available within four to six months, and not the frontier models, which are not available to all.”
Meerah Rajavel, Chief Information Officer, Palo Alto Networks, via Business Standard
Rajavel’s framing rests on economics, not raw capability. A frontier model might outperform an open-weight one on paper, but if it takes a paid API key, usage logging, and a credit card trail to touch it, that friction pushes low-skill attackers elsewhere. Open models remove the friction. She put it plainly:
“Cheap access to large language models (LLMs) has changed the game in cybersecurity.”
Meerah Rajavel, CIO, Palo Alto Networks, via Business Standard
The Four-to-Six-Month Catch-Up Window
The specific number worth sitting with is four to six months. That’s roughly how long it takes, in Rajavel’s account, for an open-source AI model to reach a capability level close enough to a frontier release that it becomes useful for offensive work, while dropping in cost to something close to free. Once that happens, she said, the only inputs an attacker needs are compute and skills.
That window has been shrinking for years across the open-weight ecosystem. Meta’s original LLaMA weights leaked in early 2023, and the company followed with more permissive Llama 2 and Llama 3 releases through 2023 and 2024. Mistral AI began shipping openly licensed models, including Mistral 7B, in the second half of 2023. DeepSeek’s open releases in 2024 and 2025 drew attention for matching closed-model benchmarks at a fraction of the training cost. Every one of those releases lowered the bar for the next round of self-hosted, fine-tunable systems, which is the exact dynamic Rajavel is describing as an open-source AI security threat rather than a one-time event.
The practical effect is that defenders can no longer treat “the AI threat” as a single moving target tied to whichever frontier lab ships next. It’s a rolling threat that regenerates every few months as open alternatives close the gap, get fine-tuned on stolen data or malware samples, and get folded into existing attack toolchains.
Guardrails Are the Real Dividing Line, Not Raw Performance
In separate remarks reported by the Economic Times, Rajavel drew the distinction even more sharply, framing the gap between frontier and open models less as a matter of intelligence and more as a matter of control.
“The frontier models can still impose some guardrails. Open source cannot.”
Meerah Rajavel, CIO, Palo Alto Networks, via Economic Times
That statement matters because it reframes the entire policy debate around open-weight AI. Vendors like OpenAI and Anthropic can, and do, bake refusal behavior, content filters, and usage monitoring into hosted frontier models. None of that survives once weights are downloaded and run locally. A fine-tuned, self-hosted model has no API-side moderation layer to strip out, because there wasn’t one to begin with. Rajavel has made a similar point in Palo Alto Networks’ own Threat Vector podcast, where she pushed back on the assumption that open availability implies safety.
“Yeah, it’s open source. When did they say open source is secure?”
Meerah Rajavel, CIO, Palo Alto Networks, via Palo Alto Networks, Threat Vector podcast
On the same podcast, she tied the risk back to the fundamentals of any AI deployment, open or closed: the model and the data behind it.
“You know, when you’re using AI, the biggest threat factor is your model and your data.”
Meerah Rajavel, CIO, Palo Alto Networks, via Palo Alto Networks, Threat Vector podcast
The Numbers Behind the Warning
Rajavel’s comments land on top of a year of hard data showing AI-linked attacks accelerating industry-wide, whether or not the attackers are running open-weight models specifically. CrowdStrike’s 2026 Global Threat Report, released February 24, 2026, found an 89% increase in attacks attributed to AI-enabled adversaries in 2025 compared with 2024. The same report found that average eCrime breakout time, the gap between initial access and lateral movement, fell to 29 minutes in 2025, a 65% jump in speed from the year before, with the fastest observed breakout clocking in at just 27 seconds.
CrowdStrike: AI Tools Turned Into Attack Surface
CrowdStrike also documented a pattern that supports Rajavel’s underlying argument about accessibility over sophistication: adversaries exploited legitimate generative AI tools at more than 90 organizations in 2025 by injecting malicious prompts to generate commands for stealing credentials and cryptocurrency, according to the CrowdStrike 2026 Global Threat Report. Named groups tracked in the report include Russia-linked Fancy Bear, which deployed LLM-enabled malware to automate reconnaissance, and North Korea-linked Famous Chollima, which used AI-generated personas to scale insider-threat operations. None of that required a frontier-grade model. It required access, which is precisely the resource Rajavel says open-source AI now supplies cheaply and quickly.
Check Point: 1,968 Attacks a Week and Rising Shadow AI Use
Check Point’s 2026 Cyber Security Report, published January 28, 2026, put a number on the broader attack volume trend: organizations faced an average of 1,968 cyberattacks per week in 2025, a 70% increase since 2023, which the report attributes directly to attackers using automation and AI to move faster and scale across more surfaces at once, according to the Check Point 2026 Cyber Security Report. The same research found that 89% of organizations encountered at least one risky AI prompt over a three-month observation window, with roughly one in every 41 prompts classified as high-risk. Ransomware activity decentralized in parallel: extorted victims rose 53% year-over-year as smaller, specialized ransomware-as-a-service crews multiplied, up 50% in new group formation.
AI Threat Landscape by the Numbers
| Metric | 2025-2026 Figure | Source |
|---|---|---|
| Increase in AI-enabled adversary attacks (2025 vs 2024) | 89% | CrowdStrike 2026 Global Threat Report |
| Average eCrime breakout time (2025) | 29 minutes (65% faster than 2024) | CrowdStrike 2026 Global Threat Report |
| Fastest observed breakout time | 27 seconds | CrowdStrike 2026 Global Threat Report |
| Organizations with GenAI tools exploited via prompt injection | 90+ | CrowdStrike 2026 Global Threat Report |
| Average weekly cyberattacks per organization (2025) | 1,968 (70% increase since 2023) | Check Point 2026 Cyber Security Report |
| Organizations encountering risky AI prompts | 89% | Check Point 2026 Cyber Security Report |
| High-risk AI prompts, share of total | ~1 in 41 | Check Point 2026 Cyber Security Report |
| Rise in extorted ransomware victims (YoY) | 53% | Check Point 2026 Cyber Security Report |
| Open-source model catch-up window to frontier capability | 4-6 months | Meerah Rajavel, Palo Alto Networks (Business Standard) |
Open-Source vs Frontier AI Models: A Security Comparison
Rajavel’s core distinction, cost and control versus raw capability, is easier to evaluate side by side. The table below lays out how open-source and frontier AI models differ on the specific dimensions that matter for security teams assessing an open-source AI security threat inside their own environment.
| Dimension | Open-source AI models | Frontier AI models |
|---|---|---|
| Access cost | Free or near-free once downloaded | Paid, metered API access |
| Identity trail | None required for local use | Account, billing, and usage logs tied to a provider |
| Content guardrails | Removable, not enforced after download | Provider-side filters and refusal behavior |
| Time to reach useful capability | 4-6 months behind frontier, per Rajavel | Immediate at release |
| Fine-tuning for offensive use | Unrestricted, local compute only | Blocked or monitored by provider terms |
| Deployment footprint | Self-hosted, offline-capable | Cloud-hosted, requires connectivity to provider |
| Primary named risk driver | Accessibility and lack of oversight | Raw capability in the hands of well-resourced actors |
Historical Context: How Open-Weight Models Got This Cheap
None of this happened overnight. Open-weight large language models went from research curiosities to production-grade tools in roughly three years. The 2023 LLaMA leak forced Meta’s hand into releasing more permissively licensed successors, which in turn pushed Mistral AI, and later a wave of Chinese labs including DeepSeek, to compete on openness as a distribution strategy rather than treat it as a liability. By 2025, it had become routine for a small team, or a single skilled individual, to download a capable open-weight model, fine-tune it on a narrow dataset such as phishing templates or malware source code, and deploy it entirely offline with no vendor able to see or block the activity.
That history is what gives Rajavel’s warning teeth. She isn’t describing a hypothetical future model. She’s describing a pattern that has already repeated three or four times since 2023, each time compressing the gap between “frontier lab ships a model” and “a cheaper, unrestricted equivalent shows up that anyone can run.”
Market Impact: Security Vendors Are Pricing In the AI Threat
Cybersecurity vendors have treated AI-driven threat growth as a demand story, not just a risk story, through 2026. Fortinet’s first-quarter 2026 results, reported May 6, 2026, showed revenue growing 20% year-over-year to $1.85 billion, with product revenue up 41% and billings up 31%, according to the Fortinet Q1 2026 financial results. The company raised its full-year 2026 revenue guidance to roughly 15% year-over-year growth, with CEO Ken Xie pointing to a threat environment he described as being intensified by AI as a driver of demand for converged networking and security products.
That pattern isn’t unique to Fortinet. Vendors across the sector, including Palo Alto Networks itself, CrowdStrike, and Check Point, have leaned into the same message this year: AI is expanding the attack surface, which means it’s also expanding the addressable market for detection, response, and identity security tools. Rajavel’s comments effectively reinforce her own employer’s sales narrative, but the underlying data from CrowdStrike and Check Point suggests the threat growth is real independent of any vendor’s marketing incentive to say so.
Competitive Comparison: How Rivals Frame the Same Threat
Palo Alto Networks isn’t alone in singling out AI accessibility as a driver of attack growth, though rivals frame the emphasis differently. CrowdStrike’s 2026 Global Threat Report leans on the idea of AI-enabled adversaries broadly, without drawing as sharp a line between open and frontier models as Rajavel does. Its 89% attack-growth figure covers AI-assisted techniques across the board, including abuse of legitimate hosted tools rather than only self-hosted open-weight systems. Check Point’s research emphasizes shadow AI use inside enterprises, the average of 10 AI applications used per organization per month, many without official approval, as the primary exposure point, which is a related but distinct problem from Rajavel’s focus on attacker-side model access.
The common thread across all three vendors is that none of them frame frontier AI labs as the primary villain. Rajavel goes further than most competitors by explicitly naming open-source availability, rather than AI capability in general, as the sharper edge of the problem. That’s a more specific and more actionable claim than the industry’s usual “AI is accelerating attacks” framing, because it points toward a policy lever, tracking and restricting dangerous fine-tunes of open-weight models, that the broader framing doesn’t.
The Regulatory Gap Around Open-Weight Models
Regulators have mostly built AI safety frameworks around frontier labs, because those are the companies with the compute, the funding, and the public profile to regulate. Open-weight releases fall largely outside that scrutiny once they leave a lab’s servers. There’s no equivalent of a usage log or an account ban for a model running on someone’s local GPU cluster. Rajavel’s comments effectively describe a governance blind spot: the actors best positioned to build in safety measures, frontier labs, aren’t the ones creating the accessibility problem, and the actors creating the accessibility problem, open-weight releases and their downstream fine-tunes, have no mechanism to enforce guardrails after release.
That gap is likely to become a bigger policy conversation through the rest of 2026 as more enterprise CISOs echo Rajavel’s framing. It also puts open-source AI developers, from Meta to Mistral to DeepSeek, in an uncomfortable position: they can publish safety cards and responsible-use policies, but they have no technical way to enforce them once weights are downloaded.
What This Means for Enterprise Security Teams
For CISOs, Rajavel’s warning translates into a fairly concrete set of priorities. First, threat models built purely around “what can GPT-class or Claude-class models do” are incomplete. Teams need to assume attackers are running fine-tuned open-weight models with no rate limits and no monitoring. Second, the CrowdStrike finding that adversaries hijacked legitimate GenAI tools at more than 90 organizations means defenders should audit their own AI tool usage for prompt injection exposure, not just worry about attacker-side model access. Third, Check Point’s shadow AI numbers, an average of 10 AI applications per organization per month, many unapproved, point to AI application inventory as a near-term, achievable control that doesn’t require solving the open-weight problem at the source.
None of this is exotic advice. It’s a reallocation of existing security budget toward AI-specific monitoring, faster breakout-time detection given CrowdStrike’s 29-minute average, and tighter control over which AI tools employees are allowed to connect to sensitive systems.
Five Predictions for the Rest of 2026
- More cybersecurity vendor executives will publicly separate open-source AI risk from frontier AI risk, following Rajavel’s lead, as the distinction becomes a useful way to differentiate their own detection products.
- The four-to-six-month capability catch-up window will keep shrinking as open-weight labs release more frequently, pushing defenders toward continuous rather than periodic AI threat modeling.
- Expect at least one more documented case, on the scale of CrowdStrike’s 90-plus-organization prompt injection finding, of attackers hijacking legitimate hosted AI tools rather than running their own open-weight models.
- Regulatory attention will start shifting from frontier-model safety testing toward downstream fine-tuning and redistribution of open-weight models, though thorough rules are unlikely to land before 2027.
- Cybersecurity vendors reporting AI-driven demand growth, following Fortinet’s pattern of raised guidance tied to an AI-intensified threat environment, will remain a recurring theme in 2026 earnings calls across the sector.
Why This Debate Isn’t Settled
It’s worth flagging the obvious tension in Rajavel’s position: she runs IT for a company that sells frontier-AI-powered defense products, and downplaying frontier-model risk relative to open-source risk isn’t a neutral stance. That doesn’t make her wrong, the CrowdStrike and Check Point data independently support the idea that accessibility, not raw capability, is driving most of the measurable attack growth in 2025 and 2026. But it does mean the claim deserves scrutiny rather than blanket acceptance, especially since Palo Alto Networks’ own leadership has, in other public commentary, also described frontier AI as a structural accelerant of attack complexity. The two positions aren’t strictly contradictory, cheap open models may drive volume while frontier models drive sophistication, but they do sit in tension, and reporters and CISOs alike should treat “open source is the biggest threat” as one data point in a larger, still-unsettled debate rather than a final verdict.
Frequently Asked Questions
What exactly did Meerah Rajavel say about open-source AI?
In an interview published by Business Standard on August 30, 2026, Palo Alto Networks CIO Meerah Rajavel said inexpensive open-source AI models, not frontier models, pose the greatest cybersecurity threat, because they become available within four to six months of a comparable frontier release and require only compute and skill to use for an attack.
Why does Rajavel think open-source AI is riskier than frontier AI?
Her argument centers on accessibility and control rather than raw capability. Frontier models are metered, monitored, and carry guardrails enforced by the provider. Open-source models can be downloaded and run without oversight, and any built-in safety measures can be stripped out once the weights leave the original publisher’s control.
What is the four-to-six-month window Rajavel referenced?
It’s the approximate lag time she cited between a frontier AI model’s release and an open-source equivalent reaching similar usefulness at a fraction of the cost, at which point she says attackers only need compute and skills to weaponize it.
What data supports the idea that AI is accelerating cyberattacks?
CrowdStrike’s 2026 Global Threat Report found an 89% increase in AI-enabled adversary attacks in 2025 versus 2024, alongside a drop in average breakout time to 29 minutes. Check Point’s 2026 Cyber Security Report found organizations faced an average of 1,968 weekly attacks in 2025, a 70% increase since 2023, and that 89% of organizations encountered risky AI prompts over a three-month window.
Does this mean frontier AI models are safe from misuse?
No. Rajavel and other Palo Alto Networks leadership have separately described frontier AI as a structural accelerant of attack speed and complexity for well-resourced actors. The distinction she’s drawing is about which category of model represents the broadest, most accessible threat to the largest number of organizations, not a claim that frontier models are risk-free.
How are cybersecurity vendors responding financially to AI-driven threats?
Fortinet’s first-quarter 2026 results showed 20% year-over-year revenue growth to $1.85 billion and raised full-year guidance, with executives citing an AI-intensified threat environment as a demand driver. Vendors across the sector have framed rising AI-linked attack volume as justification for higher security spending.
What should security teams do in response to this warning?
Security teams should expand threat modeling beyond frontier AI systems to account for fine-tuned open-weight models, audit which AI applications employees actually use given Check Point’s finding of roughly 10 AI apps per organization per month, and prioritize faster detection given CrowdStrike’s 29-minute average breakout time.




