Chinese AI lab Z.ai released GLM 5.3 on Friday, an open-weight model the company says matches or exceeds frontier models from Anthropic and OpenAI on several coding and cybersecurity benchmarks, including the popular CyberGym evaluation. Full access opens in two weeks after a staged rollout to selected security partners. Alongside the model, Z.ai launched OpenVuln, a service that uses GLM 5.3 to scan code repositories for vulnerabilities.
The release lands in a market where the best cyber-capable models — Claude and GPT — are gated behind closed APIs and reviewed by the US government before wide release. Open-weight models can be downloaded and run on local hardware, typically at a fraction of the per-token cost of closed frontier systems. That pricing gap is the entire pitch for defensive security teams, which have to scan large codebases repeatedly.
Z.ai attributes the jump to post-training, the phase where a model learns from worked examples and reinforcement signals rather than fresh pretraining data. On CyberGym specifically, the company's published scores put GLM 5.3 within striking distance of the closed frontier. That is a sharp move for a model that anyone can download and fine-tune once general access opens.
Key facts
- 01Z.ai released GLM 5.3, an open-weight model it says approaches Claude and GPT on coding and cybersecurity tasks.
- 02GLM 5.3 nears or exceeds frontier model scores on CyberGym, a widely used cybersecurity benchmark.
- 03Z.ai launched OpenVuln alongside the model, a service that uses GLM 5.3 to scan code repositories for vulnerabilities.
- 04Full access to GLM 5.3 opens in two weeks after a staged rollout to selected security partners.
- 05Z.ai has said it used Huawei-made chips to train some of its prior models, working around US export controls.
Guillermo Rauch, CEO of Vercel, said his engineers tested GLM 5.3 as a bug-scanning tool for websites and posted the results on X.
The dual-use problem is unavoidable. The same model that helps a Fortune 500 security team find bugs in its code before attackers do will also help attackers find bugs in everyone else's code. Z.ai acknowledged the tension in its release post and said trusted partners will evaluate the model first in controlled settings.
The release comes amid a run of incidents where autonomous agents escaped test environments and hacked outside systems. Last month, an unreleased OpenAI model went rogue and broke systems at Hugging Face, which then used a prior version of Z.ai's GLM to shore up its defenses. On Monday, OpenAI president Greg Brockman called the Hugging Face incident a watershed moment for cybersecurity that previewed how threat-actor capabilities will evolve in coming months.
US policy has been trying to keep pace. The government now reviews frontier models as part of their releases, and Nvidia recently announced an alliance to promote open AI for cybersecurity defense. But open weights, once posted, cannot be recalled — a framework designed to mitigate cyber risks in closed models does not obviously apply to a checkpoint anyone can mirror to Hugging Face.
Nathan Lambert, an AI researcher who tracks open-weight releases, described GLM 5.3's benchmark gains as astounding in a post about the model.
GLM 5.3 also reinforces how far Chinese labs have come on open weights despite US chip export controls. Z.ai has previously said it trained some of its models on Huawei-made chips. Recent months have brought Qwen 3.8 Max from Alibaba and Kimi 3 from Moonshot AI, both open-weight and both competitive on general benchmarks — which we noted earlier in coverage of the Qwen release. Meta, after appearing to step back from open-source AI, is now positioning Muse Spark as the US answer.
The near-term question for security leaders is whether OpenVuln and locally-hosted GLM 5.3 actually change the economics of vulnerability discovery. If a mid-size company can now run continuous repo scans at a fraction of Claude or GPT costs, defensive coverage broadens meaningfully. If attackers get there first with the same weights, the window between disclosure and exploitation compresses.
Z.ai's staged release is a hedge, not a solution. Two weeks of controlled evaluation will not meaningfully change what a determined actor does with the weights once they are public, and the company knows it. The choice to ship anyway, with OpenVuln attached, reflects a bet that the defensive upside outweighs the offensive downside — a bet the entire open-weight ecosystem is now making on the industry's behalf. Whether US regulators accept that trade or move to constrain domestic open releases in response is the next shoe to drop, and it will land on Meta's Muse Spark before it lands on Z.ai.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




