Chinese artificial intelligence company Z.ai is delaying the public release of the weights for its latest GLM-5.3 model by two weeks after internal testing showed advanced capabilities in identifying and exploiting software vulnerabilities.
The company said it will use the additional period to test and strengthen safety and security controls before making the model more widely available. In the interim, Z.ai is adopting a tiered-access approach, providing selected security partners with access to GLM-5.3 in controlled environments.
The decision places the Chinese AI developer within a broader industry debate over how increasingly capable AI models should be released when the same technology can potentially support both cybersecurity defence and malicious activity.
Z.ai specifically trained GLM-5.3 to improve its vulnerability-discovery capabilities by allowing it to perform cybersecurity tasks in controlled environments. According to results disclosed by the company, the model scored 84.5% on CyberGym, a benchmark designed to evaluate the ability of AI systems to identify known security vulnerabilities.
The model also demonstrated the ability to reason through and construct exploits for vulnerabilities on ExploitBench. Independent reporting indicates that GLM-5.3 remained behind some leading US models on exploit generation despite its stronger performance in vulnerability discovery.
Z.ai said its GLM models have identified more than 2,400 security vulnerabilities so far, including over 1,000 classified as critical or high severity. The company said some of the vulnerabilities were found in widely used software projects, including the Linux kernel and software from VMware and Apache. These figures are company-reported.
Alongside GLM-5.3, Z.ai has introduced an initiative that allows open-source software maintainers to have repositories scanned for potential vulnerabilities using its models. The company is positioning the cybersecurity capabilities primarily as tools that can help defenders identify weaknesses before they are exploited.
However, the planned open-weight release introduces a separate security consideration. Unlike closed models accessed through centrally controlled services, publicly available model weights can potentially be modified and deployed independently. Z.ai has acknowledged that it will not be able to control how GLM-5.3 is modified or used once the weights become public.
The concern mirrors warnings from executives at major US AI companies. OpenAI CEO Sam Altman and Anthropic CEO Dario Amodei have previously raised concerns about releasing highly capable AI models without sufficient safeguards, particularly as models develop stronger cybersecurity capabilities.
Z.ai's move is notable as Chinese developers continue to increase the capabilities of open-weight models. Companies including Alibaba, Moonshot AI and Z.ai have expanded their model portfolios as competition with US AI developers intensifies.
The two-week delay does not represent a cancellation of GLM-5.3's open-weight release. Instead, Z.ai is maintaining its planned release while introducing additional testing and controlled access before the weights become publicly available.
The decision illustrates an emerging challenge for AI developers as models become increasingly capable in cybersecurity: expanding access to technology while managing capabilities that can potentially be used by both security researchers and attackers.
Disclaimer: This article may include information derived from interviews, press releases, public statements, research, company communications and other publicly available or third-party sources. Such material may be summarised, paraphrased or contextualised for journalistic and editorial purposes. All rights in third-party content remain with their respective owners.