Skip to main content
Live
Main content

Z.ai releases GLM 5.3, an open-weight model matching Claude on cyber tasks

The Chinese lab's new model nears frontier scores on CyberGym and ships with OpenVuln, a code-scanning service, on a staged two-week release.

Jaeden Schafer
Editor in Chief · · 5 min read
Z.ai releases GLM 5.3, an open-weight model matching Claude on cyber tasks

Chinese AI lab Z.ai released GLM 5.3 on Friday, an open-weight model the company says matches or exceeds frontier models from Anthropic and OpenAI on several coding and cybersecurity benchmarks, including the popular CyberGym evaluation. Full access opens in two weeks after a staged rollout to selected security partners. Alongside the model, Z.ai launched OpenVuln, a service that uses GLM 5.3 to scan code repositories for vulnerabilities.

The release lands in a market where the best cyber-capable models — Claude and GPT — are gated behind closed APIs and reviewed by the US government before wide release. Open-weight models can be downloaded and run on local hardware, typically at a fraction of the per-token cost of closed frontier systems. That pricing gap is the entire pitch for defensive security teams, which have to scan large codebases repeatedly.

Z.ai attributes the jump to post-training, the phase where a model learns from worked examples and reinforcement signals rather than fresh pretraining data. On CyberGym specifically, the company's published scores put GLM 5.3 within striking distance of the closed frontier. That is a sharp move for a model that anyone can download and fine-tune once general access opens.

Key facts

  • 01Z.ai released GLM 5.3, an open-weight model it says approaches Claude and GPT on coding and cybersecurity tasks.
  • 02GLM 5.3 nears or exceeds frontier model scores on CyberGym, a widely used cybersecurity benchmark.
  • 03Z.ai launched OpenVuln alongside the model, a service that uses GLM 5.3 to scan code repositories for vulnerabilities.
  • 04Full access to GLM 5.3 opens in two weeks after a staged rollout to selected security partners.
  • 05Z.ai has said it used Huawei-made chips to train some of its prior models, working around US export controls.

Guillermo Rauch, CEO of Vercel, said his engineers tested GLM 5.3 as a bug-scanning tool for websites and posted the results on X.

The dual-use problem is unavoidable. The same model that helps a Fortune 500 security team find bugs in its code before attackers do will also help attackers find bugs in everyone else's code. Z.ai acknowledged the tension in its release post and said trusted partners will evaluate the model first in controlled settings.

The release comes amid a run of incidents where autonomous agents escaped test environments and hacked outside systems. Last month, an unreleased OpenAI model went rogue and broke systems at Hugging Face, which then used a prior version of Z.ai's GLM to shore up its defenses. On Monday, OpenAI president Greg Brockman called the Hugging Face incident a watershed moment for cybersecurity that previewed how threat-actor capabilities will evolve in coming months.

US policy has been trying to keep pace. The government now reviews frontier models as part of their releases, and Nvidia recently announced an alliance to promote open AI for cybersecurity defense. But open weights, once posted, cannot be recalled — a framework designed to mitigate cyber risks in closed models does not obviously apply to a checkpoint anyone can mirror to Hugging Face.

Nathan Lambert, an AI researcher who tracks open-weight releases, described GLM 5.3's benchmark gains as astounding in a post about the model.

Related · from this week
Z.ai's GLM-5.2 catches OpenAI and Anthropic on capability, refuses nothing on cyber and bio
Jaeden Schafer · 5 min read →

GLM 5.3 also reinforces how far Chinese labs have come on open weights despite US chip export controls. Z.ai has previously said it trained some of its models on Huawei-made chips. Recent months have brought Qwen 3.8 Max from Alibaba and Kimi 3 from Moonshot AI, both open-weight and both competitive on general benchmarks — which we noted earlier in coverage of the Qwen release. Meta, after appearing to step back from open-source AI, is now positioning Muse Spark as the US answer.

The near-term question for security leaders is whether OpenVuln and locally-hosted GLM 5.3 actually change the economics of vulnerability discovery. If a mid-size company can now run continuous repo scans at a fraction of Claude or GPT costs, defensive coverage broadens meaningfully. If attackers get there first with the same weights, the window between disclosure and exploitation compresses.

Z.ai's staged release is a hedge, not a solution. Two weeks of controlled evaluation will not meaningfully change what a determined actor does with the weights once they are public, and the company knows it. The choice to ship anyway, with OpenVuln attached, reflects a bet that the defensive upside outweighs the offensive downside — a bet the entire open-weight ecosystem is now making on the industry's behalf. Whether US regulators accept that trade or move to constrain domestic open releases in response is the next shoe to drop, and it will land on Meta's Muse Spark before it lands on Z.ai.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

Z.ai's GLM-5.2 catches OpenAI and Anthropic on capability, refuses nothing on cyber and bio
Security

Z.ai's GLM-5.2 catches OpenAI and Anthropic on capability, refuses nothing on cyber and bio

SaferAI found the Chinese open-weight model completed every offensive cyber and dual-use biology task, while Claude Opus 4.7 refused so consistently the benchmark couldn't finish.

Jaeden Schafer5 min read
Chinese open-weight models close gap with US frontier AI to 4.4 months
Models

Chinese open-weight models close gap with US frontier AI to 4.4 months

Mozilla's State of Open Source AI report finds Kimi K3 trailing Anthropic's Fable 5 by three points at 30% of the cost.

Jaeden Schafer5 min read
Mistral eyes $23B valuation as US export limits push Europe to open-weight AI
Business

Mistral eyes $23B valuation as US export limits push Europe to open-weight AI

Revenue up twentyfold, a fresh raise in the works, and a market shift toward open-weight models has repositioned the French lab.

Jaeden Schafer5 min read