Z.ai Delays GLM-5.3 Open Weights After Cybersecurity Tests

Z.ai Delays GLM-5.3 Open Weights After Cybersecurity Tests

August 16, 2026

BEIJING, August 17, 2026, 04:47 CST

  • Z.ai plans to hold GLM-5.3’s public weights for about two weeks.
  • The model nearly matched Anthropic on bug finding but trailed in exploit development.

Z.ai Co. Ltd. (HKG:2513) is delaying the public release of GLM-5.3’s open weights while it completes security reviews. The Chinese AI developer expects the review to take about two weeks.

The decision matters because GLM-5.3 can both find software flaws and help turn them into attacks. Open weights would let users run and modify the model outside Z.ai’s direct control.

Z.ai’s headline result came from CyberGym, which tests code review and vulnerability confirmation. GLM-5.3 scored 84.5%, against 83.8% for Anthropic’s restricted Mythos 5. The 0.7-point lead remains a company claim.

CyberGym resultGLM-5.3Anthropic Mythos 5Difference
Confirmed vulnerability score84.5%83.8%GLM-5.3 +0.7 points
Independent verificationNot availableNot available in Z.ai’s comparisonUnverified vendor results

The picture changed on ExploitBench. GLM-5.3 converted 54.4% of discovered flaws into working attacks. Mythos 5 reached 78.0%, leaving a 23.6-point gap.

ExploitBench resultGLM-5.3Anthropic Mythos 5Difference
Working-exploit score54.4%78.0%Mythos 5 +23.6 points
What it measuresTurning found flaws into attacksTurning found flaws into attacksComparable task

Timed trials showed a similar gap. Z.ai reported 105 completed attack-development tasks after two hours and 130 after six. Mythos 5 completed 181 and 247, respectively.

Timed attack-development testGLM-5.3Anthropic Mythos 5GLM-5.3 gap
Tasks completed in two hours10518176 fewer
Tasks completed in six hours130247117 fewer

Those results suggest separate strengths. GLM-5.3 appears competitive at spotting likely defects. It is materially weaker at producing usable exploits, based on Z.ai’s own figures.

The release plan also separates ordinary access from sensitive capabilities. Initial access will go to selected launch partners. Advanced cybersecurity functions will require verified users under a trusted-access program.

ModelCurrent statusWeightsCybersecurity access
GLM-5.3Pre-release security reviewPlanned public release in about two weeksSensitive functions limited to verified users
Anthropic Mythos 5Available to vetted organizationsNot publicly downloadableRestricted-access program
GLM-5.2Available nowOpen weights on Hugging FaceNo GLM-5.3 controls announced for this model
Release status as reported on August 14 and checked on August 17.

Z.ai said access would expand through “a consistent and responsible process.” The approach resembles Anthropic’s limited distribution of Mythos 5, though Z.ai still intends a wider weights release.

Gabriel Wagner, an AI governance researcher at Concordia AI, called it “the first time a Chinese lab is publicly justifying a delayed open release of model weights.” His assessment points to a change in how Chinese labs discuss dual-use risk.

The company has already built a large open-model audience. Z.ai says its model series has passed 40 million downloads worldwide. Its official Hugging Face organization currently lists GLM-5.2 as a 753-billion-parameter model.

GLM-5.3’s architecture, parameter count, context window, license and API pricing remain undisclosed. Buyers therefore cannot yet compare deployment costs or hardware needs with existing models.

The rollout may test whether trusted access can survive a later open release. Once model weights circulate, centralized account checks and usage monitoring become difficult to enforce.

Risks: The benchmark results are not independently verified. Cybersecurity models can assist defenders, but they may also lower technical barriers for attackers. Final safeguards and release terms could change.

BEZ KABLI • EXTENDED COVERAGE

Further analysis

What did Z.ai announce about GLM-5.3?
Z.ai disclosed cybersecurity benchmark results for GLM-5.3 and delayed the model's public weights. The company expects roughly two weeks of additional security reviews. Initial access will go to selected partners.
How does GLM-5.3 compare with Anthropic's Mythos 5?
GLM-5.3 scored 84.5% on CyberGym, slightly above Mythos 5 at 83.8%. It trailed sharply on ExploitBench, scoring 54.4% against 78.0%. The results came from Z.ai and remain independently unverified.
Can developers download GLM-5.3 now?
No. Z.ai has not released the GLM-5.3 weights, full specifications, license or API pricing. It plans a wider release after security checks, while reserving sensitive cybersecurity functions for verified users.
Why is the release considered a security risk?
The model can identify software vulnerabilities and assist exploit development. Those skills help defenders test systems. They can also reduce the time and expertise attackers need to weaponize flaws.
Should companies plan to deploy GLM-5.3?
Not yet. Organizations lack independently verified performance, hardware requirements, licensing terms and prices. Security teams should also wait for details about the trusted-access controls and final safeguards.

Artur Ślesik

Artur Ślesik is a technology and financial markets journalist at Bez-kabli.pl, covering artificial intelligence, semiconductors, technology stocks and emerging innovations. A graduate of Warsaw University of Technology, he combines a technical background with market analysis to explain how new technologies are shaping industries, businesses and investment trends worldwide.