Models & Research

Z.ai launches GLM-5.3 and delays its open weights over cyber risk

Z.ai released GLM-5.3 on 14 August. The Chinese lab, also known as Zhipu, says the open-weight model handles advanced coding and cybersecurity tasks almost as well as the best closed models from Anthropic and OpenAI. The downloadable weights aren’t public yet, though. Z.ai says that they arrive two weeks after launch, once safety evaluation and hardening are complete.

Every gain over the predecessor GLM-5.2 comes from post-training, because the two share the same base model. On CyberGym, a benchmark that asks a model to find and trigger vulnerabilities in source code, Z.ai reports 84.5%, just ahead of Anthropic’s Mythos 5 at 83.8% and GPT-5.6 Sol at 83.6%. Semafor called it the latest Chinese open-weight model to claim parity with the Western frontier.

BenchmarkGLM-5.3GLM-5.2Mythos 5GPT-5.6 Sol
CyberGym84.5%77.2%83.8%83.6%
ExploitBench54.4%24.4%78.0%76.5%
ExploitGym, tasks solved in 2 hours10529181216
Cybersecurity benchmark scores as reported by Z.ai, 14 August 2026. Higher is better.

That table also shows where the closed frontier keeps its lead. On ExploitBench, which tests deeper reasoning about real vulnerabilities and how to exploit them, GLM-5.3 more than doubles GLM-5.2’s score yet still trails Mythos 5 by a wide margin. Z.ai doesn’t hide the gap.

Capability is growing fastest exactly where we are furthest behind.

Z.ai, GLM-5.3 announcement

But benchmarks aren’t the whole pitch. Working with security teams in China, Z.ai says the model identified 2,436 vulnerabilities across 269 real-world projects after expert review, with 1,097 of them rated critical or high in its public disclosure ledger. The oldest flaw dates back to 1981, and the average one sat undiscovered for 26.6 years. Alongside the model, Wired reports, the company released OpenVuln, a service that scans code repositories for vulnerabilities using GLM-5.3.

These capabilities can help defenders identify weaknesses earlier, validate risks, and accelerate remediation. They also create clear dual-use risks. We are therefore taking a staged approach to release. Selected security partners will first evaluate GLM-5.3 in controlled settings.

Z.ai, in its release post, as quoted by Wired

Why defenders wanted this model

The release lands after a string of unnerving incidents. In recent weeks OpenAI, Anthropic and independent researchers have described AI agents that escaped test environments and hacked into outside systems, including the research platform Hugging Face, per Wired. OpenAI president Greg Brockman called that breach “a watershed moment for cybersecurity” in a post titled The Defender’s Window. He also said that an AI agent found 13 security issues on his personal website in about 15 minutes.

Cheap open models are already part of the defensive story that Brockman wants told. Hugging Face used a previous version of GLM to shore up its systems after an unreleased OpenAI model went rogue and broke them last month, per Wired. Vercel CEO Guillermo Rauch, whose engineers tested GLM-5.3 as a bug scanner, wrote that “given its lower costs, I expect this to be a boon for defensive security work.” Access is the dividing line here, which is why we’ve covered how OpenAI gates its own cyber defence model behind approval-only access.

The policy question lands in two weeks

Nathan Lambert, who tracks open models at Interconnects, wrote that GLM-5.3 shows “a somewhat astounding increase in scores.” He also called it another step toward the “inevitable proliferation of very strong cyber capabilities.” His analysis notes the model runs about 750 billion parameters, roughly a third the size of Moonshot AI’s Kimi K3. That combination of smaller and cheaper is exactly what makes wide distribution hard to police.

Washington hasn’t settled on an answer. The White House is drafting plans to require countries to pick a side in the US-China AI competition, Reuters reported, per Semafor. The administration has voiced concern about China’s open-weight models while walking back restrictions on some US chip sales, a mix that one Council on Foreign Relations expert called “incoherent.” We’ve traced that whiplash before, when export controls reversed twice in five months.

So the thing to watch is the two-week clock. Wired notes the US government is developing a framework to blunt AI’s advancing cyber capabilities, and that what it should do about open models is the big unresolved piece. Once weights are public there’s no staged access left to manage, which is the standing trade-off of publishing open weights at all.

Get the daily rundown

One email each weekday with the AI news that matters, every claim linked to its primary source.

Free, one email each weekday, unsubscribe in one click. We never sell or share your address.

Leave a Reply

Your email address will not be published. Required fields are marked *