Skip to main content
Live
Main content

China's Z.ai claims GLM-5.2 matches Anthropic's Mythos on bug-finding

The open-weight model lags on general tasks but reportedly closes the gap on cybersecurity — the exact capability US export curbs were meant to contain.

Jaeden Schafer
Editor in Chief · · 4 min read
China's Z.ai claims GLM-5.2 matches Anthropic's Mythos on bug-finding

Chinese AI lab Zhipu AI, which operates as Z.ai, released its open-weight GLM-5.2 model on June 28, and researchers testing it report that it matches Anthropic's Mythos on certain bug-finding and cybersecurity tasks. GLM-5.2 still trails frontier models from Anthropic and OpenAI on broader general-purpose benchmarks, but the narrowing gap on offensive-security capability is the part that matters to Washington. It is precisely the capability US export controls were designed to keep out of Chinese hands.

GLM-5.2 ships as open weights, meaning anyone can download the model and run it on readily available hardware without going through an API gatekeeper. That design choice gives developers deep access and flexibility, and it also makes the model impossible to retract once it is in the wild. Mythos, by contrast, is gated: the US recently cleared Anthropic to ship Mythos 5 to roughly 100 vetted enterprise and government customers under a controlled-distribution regime.

The cybersecurity claim is the headline. Bug-finding — the ability to read a codebase and identify exploitable vulnerabilities — has been the specific capability that the Trump administration has flagged as a national security concern in frontier models. It is the reason Mythos and OpenAI's GPT-5.6 have both been pulled into government review before broader release, coverage AI Chat Daily has tracked across the past two weeks.

GLM-5.2 can't match Anthropic or OpenAI on general tasks, but the gap has closed on finding bugs.
Terrence O'Brien, Weekend Editor

Key facts

  • 01Zhipu AI released GLM-5.2 as an open-weight model, downloadable and runnable on readily available hardware.
  • 02Researchers claim GLM-5.2 matches Anthropic's Mythos in certain bug-finding and cybersecurity scenarios.
  • 03GLM-5.2 still lags Anthropic and OpenAI models on broader general-purpose tasks.
  • 04The US recently cleared Anthropic to ship Mythos 5 to roughly 100 vetted firms and agencies, citing national security risk.
  • 05OpenAI's GPT-5.6 rollout has also been gated under US government request over similar concerns.

Zhipu AI has been one of China's most aggressive open-weight publishers, releasing successive GLM generations into public model hubs while US labs have moved in the opposite direction. The previous releases lagged Anthropic and OpenAI by a clear margin on most evaluations. GLM-5.2 is the first time independent researchers have credibly placed a Chinese open model at parity with a US frontier model on any capability that the US government has explicitly tried to contain.

The policy backdrop here is sharp. Earlier this month the US gave Anthropic the green light to export Mythos 5 to a controlled list of buyers, with Commerce Secretary Howard Lutnick framing the approval as a way to extend US AI reach while keeping the underlying capability inside an allied perimeter. The Trump administration has separately leaned on OpenAI to slow the GPT-5.6 rollout. Both moves assume that gating the model gates the capability.

An open-weight Chinese model that performs comparably on the exact task being gated breaks that assumption. Once GLM-5.2 is downloaded, there is no off switch and no audit log. The model runs locally for any operator with a modest GPU cluster, and the weights propagate through mirrors and torrents faster than any export-control regime can respond to.

Caveats are worth stating plainly. The parity claim comes from researcher reports, not a published benchmark with a standardized methodology, and bug-finding is a narrow slice of cybersecurity work. GLM-5.2 has not been shown to match Mythos on the broader chain of tasks an offensive operator would need — exploit development, post-exploitation reasoning, evasion. Anthropic and OpenAI have also not publicly responded to the specific comparison, and the GLM-5.2 weights have only been in researchers' hands for days.

Still, the trajectory is the story. Zhipu AI has gone from clearly trailing to credibly matching on a national-security-relevant capability in roughly one model generation. The argument that US export controls buy meaningful time on frontier AI rests on the gap between US closed models and Chinese open models staying wide. GLM-5.2 is the first concrete data point suggesting that on at least one axis, the gap is now narrow enough to matter — and the open-weight distribution model means the US controlled-release strategy for Mythos and GPT-5.6 may be solving the wrong problem.

Related · from this week
Z.ai's GLM-5.2 catches OpenAI and Anthropic on capability, refuses nothing on cyber and bio
Jaeden Schafer · 5 min read →
ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Models

Z.ai's GLM-5.2 catches OpenAI and Anthropic on capability, refuses nothing on cyber and bio
Security

Z.ai's GLM-5.2 catches OpenAI and Anthropic on capability, refuses nothing on cyber and bio

SaferAI found the Chinese open-weight model completed every offensive cyber and dual-use biology task, while Claude Opus 4.7 refused so consistently the benchmark couldn't finish.

Jaeden Schafer5 min read
Trump delays AI security executive order citing US competitiveness concerns
News

Trump delays AI security executive order citing US competitiveness concerns

The president scrapped a planned signing after objecting to language requiring advance model sharing with government.

Jaeden Schafer4 min read
OpenAI gates GPT-5.5 Cyber after mocking Anthropic for doing the same with Mythos
Security

OpenAI gates GPT-5.5 Cyber after mocking Anthropic for doing the same with Mythos

Sam Altman called Anthropic's Mythos rollout 'fear-based marketing.' Now OpenAI is shipping its own cyber tool only to vetted defenders.

Jaeden Schafer4 min read