BEIJING, August 17, 2026, 04:47 CST
- Z.ai plans to hold GLM-5.3’s public weights for about two weeks.
- The model nearly matched Anthropic on bug finding but trailed in exploit development.
Z.ai Co. Ltd. (HKG:2513) is delaying the public release of GLM-5.3’s open weights while it completes security reviews. The Chinese AI developer expects the review to take about two weeks.
The decision matters because GLM-5.3 can both find software flaws and help turn them into attacks. Open weights would let users run and modify the model outside Z.ai’s direct control.
Z.ai’s headline result came from CyberGym, which tests code review and vulnerability confirmation. GLM-5.3 scored 84.5%, against 83.8% for Anthropic’s restricted Mythos 5. The 0.7-point lead remains a company claim.
| CyberGym result | GLM-5.3 | Anthropic Mythos 5 | Difference |
|---|---|---|---|
| Confirmed vulnerability score | 84.5% | 83.8% | GLM-5.3 +0.7 points |
| Independent verification | Not available | Not available in Z.ai’s comparison | Unverified vendor results |
The picture changed on ExploitBench. GLM-5.3 converted 54.4% of discovered flaws into working attacks. Mythos 5 reached 78.0%, leaving a 23.6-point gap.
| ExploitBench result | GLM-5.3 | Anthropic Mythos 5 | Difference |
|---|---|---|---|
| Working-exploit score | 54.4% | 78.0% | Mythos 5 +23.6 points |
| What it measures | Turning found flaws into attacks | Turning found flaws into attacks | Comparable task |
Timed trials showed a similar gap. Z.ai reported 105 completed attack-development tasks after two hours and 130 after six. Mythos 5 completed 181 and 247, respectively.
| Timed attack-development test | GLM-5.3 | Anthropic Mythos 5 | GLM-5.3 gap |
|---|---|---|---|
| Tasks completed in two hours | 105 | 181 | 76 fewer |
| Tasks completed in six hours | 130 | 247 | 117 fewer |
Those results suggest separate strengths. GLM-5.3 appears competitive at spotting likely defects. It is materially weaker at producing usable exploits, based on Z.ai’s own figures.
The release plan also separates ordinary access from sensitive capabilities. Initial access will go to selected launch partners. Advanced cybersecurity functions will require verified users under a trusted-access program.
| Model | Current status | Weights | Cybersecurity access |
|---|---|---|---|
| GLM-5.3 | Pre-release security review | Planned public release in about two weeks | Sensitive functions limited to verified users |
| Anthropic Mythos 5 | Available to vetted organizations | Not publicly downloadable | Restricted-access program |
| GLM-5.2 | Available now | Open weights on Hugging Face | No GLM-5.3 controls announced for this model |
Z.ai said access would expand through “a consistent and responsible process.” The approach resembles Anthropic’s limited distribution of Mythos 5, though Z.ai still intends a wider weights release.
Gabriel Wagner, an AI governance researcher at Concordia AI, called it “the first time a Chinese lab is publicly justifying a delayed open release of model weights.” His assessment points to a change in how Chinese labs discuss dual-use risk.
The company has already built a large open-model audience. Z.ai says its model series has passed 40 million downloads worldwide. Its official Hugging Face organization currently lists GLM-5.2 as a 753-billion-parameter model.
GLM-5.3’s architecture, parameter count, context window, license and API pricing remain undisclosed. Buyers therefore cannot yet compare deployment costs or hardware needs with existing models.
The rollout may test whether trusted access can survive a later open release. Once model weights circulate, centralized account checks and usage monitoring become difficult to enforce.
Risks: The benchmark results are not independently verified. Cybersecurity models can assist defenders, but they may also lower technical barriers for attackers. Final safeguards and release terms could change.