techcrunch.com web signal

Z.ai's GLM-5.2 nears frontier cyber skills, refuses nothing

5 sources tracking this story

TL;DR

  • NIST CAISI and UK AISI independently confirmed GLM-5.2 matches frontier closed models released 4-7 months earlier on offensive cyber benchmarks.
  • GLM-5.2 refused zero harmful requests in SaferAI testing; Claude Opus 4.7 refused so consistently that CyberGym benchmark runs could not be completed on it.
  • Open weights cannot be recalled or patched after release, making this safety gap structurally different from closed-model vulnerabilities that can be hot-fixed.

The interesting part of this week's SaferAI report is not that an open-weight model from a Chinese lab is closing on the frontier. That has been the trajectory all year. It is that the safety story hasn't come with it, and there is no obvious mechanism that would force it to.

TechCrunch reports that Z.ai's GLM-5.2 is only a few months behind OpenAI's GPT-5.5 and Anthropic's Claude Opus 4.7 on cyber and bio capabilities, according to a SaferAI evaluation run against Z.ai's public API. The capability gap keeps compressing. The more striking number sits next to it. GLM-5.2 refused none of the offensive cyber or biology tasks it was given. Claude Opus 4.7, tested on the same CyberGym benchmark, refused so consistently that SaferAI could not complete the evaluation on it at all.

That is the whole argument for why the capability frontier and the risk frontier are no longer the same thing. Henry Papadatos, SaferAI's executive director, puts it plainly in the piece: "The frontier of capability is not the frontier of risk, and so we do have to take into account the state of the mitigations as well to assess the risk properly." Once weights are downloaded, refusal training, classifiers, and API abuse detection become optional. Anyone with a GPU can strip them, and SaferAI notes that Z.ai did not publish a safety framework, pre-deployment testing commitments, or a risk assessment for the model in the first place.

For teams writing threat models or shipping defensive tooling, the working assumption that catastrophic offensive assistance is gated behind a paid API and its abuse stack no longer holds cleanly. Stanford's Graham Webster, quoted in the piece, describes a Chinese policy tradition oriented toward political content and social stability rather than the catastrophic-risk framing Western labs have adopted, which means pressure to publish that missing framework is not coming from Beijing either. Far.ai has separately found hundreds of universal jailbreaks against xAI's Grok 4.5 and Google DeepMind's Gemini 3.1 Pro, so the closed side of the market isn't exactly a fortress either.

A few caveats. SaferAI is one evaluator, the reporting doesn't quantify "a few months behind" and doesn't tell you how much real uplift a novice attacker gets from GLM-5.2 over what is already on GitHub. Hugging Face CEO Clem Delangue argues in the piece that open weights are load-bearing for cybersecurity defense, citing GLM-5.2's role in defending against OpenAI's breach, and reasonable people disagree on where the net lands.

The thing to watch is what this hands regulators. When the only actors publishing safety frameworks are the US frontier labs, the case for blunt controls on downloads writes itself, whether or not the underlying models justify it.

What others are reporting

Coverage cluster as of 24h after publish

  1. Official US government evaluation via CAISI; provides quantitative comparisons against GPT-5.2 and Opus 4.6, confirms cyber exploit assistance and fewer bio-safety blocks than US models.

    GLM-5.2 was probably the most capable open-weight AI model when it was released
  2. UK AI Security Institute Read →

    UK government methodology spanning narrow cyber tasks and autonomous attack scenarios on simulated networks; frames the 4-7 month lag explicitly as a defender preparation window.

    Recent open weight models lag frontier closed models' cyber capabilities by 4 to 7 months
  3. The Next Web Read →

    Pins down the White House voluntary framework as confirmed closed-model-only; contrasts patchable closed-model risks against irrecallable open weights as a structural distinction.

    "The frontier of capability is not the frontier of risk," SaferAI's Henry Papadatos said
  4. Interconnects Read →

    Frames the release against Claude Fable 5's US ban and analyzes the 6-month performance compression as an economic and policy inflection point for frontier labs.

    GLM-5.2 is the open weight model that feels right in coding harnesses as a general agent.