Chinese AI startup Z.ai has announced that its latest open source artificial intelligence model, GLM 5.3, has delivered competitive results in cybersecurity testing, with performance approaching Anthropic’s restricted Mythos 5 model in identifying software vulnerabilities. According to the company, GLM 5.3 achieved a score of 84.5 percent on CyberGym, a benchmark designed to evaluate a model’s ability to review source code, detect security vulnerabilities and verify whether those flaws are genuine. Z.ai said this result was slightly higher than the 83.8 percent score it reported for Anthropic’s Mythos 5. The benchmark results have not been independently verified. Despite its performance in vulnerability identification, GLM 5.3 trailed Mythos 5 in tasks involving the conversion of identified vulnerabilities into working exploits, a capability commonly used in defensive cybersecurity research. On ExploitBench, GLM 5.3 scored 54.4 percent compared with 78 percent for Mythos 5. In additional timed evaluations, Z.ai stated that its model completed 105 attack development tasks in two hours and 130 tasks in six hours, while Mythos 5 completed 181 and 247 tasks during the same time periods.
Anthropic currently limits access to Mythos, a version of its Claude Fable 5 model with cybersecurity safeguards removed, to vetted organizations because of concerns that advanced vulnerability discovery capabilities could benefit both defenders and malicious actors. Z.ai said it plans to publicly release GLM 5.3 in approximately two weeks after completing security assessments and strengthening its protective measures. The company added that its most sensitive cybersecurity capabilities will only be available to verified users through a trusted access programme. In a post on X, Z.ai stated that initial access will be provided to a select group of launch partners before gradually expanding availability through what it described as a consistent and responsible process. The approach closely resembles Anthropic’s Project Glasswing limited access framework. Gabriel Wagner, an AI governance researcher at Beijing based consultancy Concordia AI, said the decision to delay the release of model weights due to safety considerations appears to be the first publicly stated example of a Chinese AI laboratory taking such an approach. He added that the move suggests open weight risk management practices in China are becoming more sophisticated.
According to Z.ai, GLM 5.3 incorporates multiple safety measures, including systems that screen high risk requests, monitor the model’s activities and train it to reject malicious instructions. The company stated that these safeguards are designed to distinguish harmful activities from legitimate cybersecurity applications such as vulnerability remediation, cybersecurity education and authorized security testing. However, critics argue that once an open source model becomes available for download, modification or integration with third party tools, enforcing such safeguards becomes significantly more difficult. Z.ai also positioned GLM 5.3 as an alternative to restricted access cybersecurity models, stating that advanced defensive AI capabilities should be available to open source developers and smaller security teams rather than being limited to a small number of closed model providers. As part of this strategy, the company announced the Open Source Shield initiative, which will audit selected open source software projects, provide model access for defensive security work and integrate code auditing features into its ZCode programming platform.
The announcement builds on growing international interest in Z.ai’s earlier GLM 5.2 model, which attracted attention among developers for its coding and AI agent capabilities at a lower cost than leading United States models. Last month, New York based AI startup Hugging Face stated that it used GLM 5.2 to defend against a cyberattack carried out by a rogue OpenAI AI agent. Z.ai is also not the first Chinese company to position its technology against Anthropic’s Mythos platform. Cybersecurity company 360 claimed in June that its Tulongfeng vulnerability discovery system had achieved comparable capabilities by combining AI models with security data and automation tools, although those claims were also not independently verified. Unlike purpose built cybersecurity systems, Z.ai said GLM 5.3 is a general purpose coding model that gained advanced cybersecurity capabilities through expanded post training and reinforcement learning while continuing to use the same base architecture as GLM 5.2.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.