Beijing-based AI agency Z.ai on Friday unveiled GLM-5.3, an open-weights mannequin that claims top-tier programming benchmarks and aggressive vulnerability-detection scores towards main U.S. methods from Anthropic and OpenAI.
Built on the identical 700-billion-parameter base mannequin as its June predecessor, GLM-5.2, the corporate stated all efficiency beneficial properties stem from expanded reinforcement studying and artificial post-training environments.
Public launch of the mannequin’s weights shall be delayed for 2 weeks whereas security evaluations and safety hardening are accomplished, in accordance with the corporate.
Benchmark beneficial properties and cybersecurity leaps
Z.ai reported that GLM-5.Three delivers a 50% enchancment over GLM-5.2 on its inner Z.ai Code Bench. On public evaluations, the system reached 88.2 on Terminal Bench 2.1, 28.Three on Terminal Bench 3.0, and 66.9 on DeepSWE v1.1.
The firm highlighted emergent cybersecurity capabilities that advanced throughout post-training. On the CyberGym vulnerability-detection benchmark, GLM-5.Three scored 84.5%, edging out Anthropic’s Mythos 5 at 83.8% and OpenAI’s GPT-5.6 Sol at 83.6%.
However, the mannequin lags behind U.S. closed-frontier methods in constructing energetic exploits. On ExploitBench, GLM-5.Three scored 54.4%, trailing Mythos 5‘s 78.0%. In a six-hour timed take a look at on ExploitGym, GLM-5.Three accomplished 130 attack-development duties in comparison with 247 duties logged by Mythos 5.
Alongside the announcement, Z.ai launched the Z.ai Security Disclosure Ledger, documenting 2,436 vulnerabilities recognized throughout 269 open-source software program tasks, together with Linux kernel elements and Apache tasks.
Controlled entry and security measures
To handle offensive dangers, Z.ai stated it’s implementing a tiered rollout that retains delicate exploit options restricted to vetted safety companions beneath a trusted entry program.
The firm acknowledged on X that it added safeguards to reject malicious requests whereas supporting official defensive testing, writing: “An open world cannot have only open attack surfaces. It must also have an open shield.”
“To the best of my knowledge, this is the first time a Chinese lab is publicly justifying a delayed open release of model weights with safety considerations,” stated Gabriel Wagner, an AI governance researcher at Concordia AI, per Reuters.
Strong technical outcomes haven’t erased questions on Z.ai’s industrial place.
Despite the product claims, shares of Hong Kong-listed Z.ai fell practically 4% Friday. Bloomberg Intelligence analyst Robert Lea famous that “This firm remains on a completely unsustainable commercial footing,” including that “Rising agentic AI will drive Z.ai’s inference costs and losses higher.”
What the launch means
GLM-5.3’s significance is much less about whether or not it has overtaken each main U.S. mannequin than about how aggressive Chinese methods have gotten in specialised coding and cybersecurity duties.
Z.ai is displaying that stronger coding fashions can emerge by way of post-training with out changing the underlying mannequin. At the identical time, its cybersecurity outcomes counsel that general-purpose coding methods can develop offensive capabilities sooner than anticipated as coaching turns into extra refined.
The harder query is what occurs when these enhancements attain security-sensitive duties. Z.ai is delaying the open launch of GLM-5.3’s weights whereas it completes security work, underscoring the stress between open entry and the danger that stronger defensive capabilities can be repurposed for assault.
Other News: DeepSeek’s V4 Pro is difficult Anthropic’s Claude Opus 5 for builders, intensifying competitors over which AI fashions carry out finest on coding duties.


