Skip to content
AI DEEP 2 sources · 3 min · cluster 1 · updated 10:00 UTC

GLM-5.3 and the spread of advanced cyber capabilities

Anthropic and NIST published separate assessments of Z.ai’s open-weight model and its cybersecurity capabilities.

TL;DR

  1. Anthropic says its tests found GLM-5.3 capable of autonomously building end-to-end cyber exploits and that simple techniques bypassed its safeguards in 64% to 100% of simulated tests.
  2. NIST’s CAISI assessment describes GLM-5.3 as the most cyber-capable open-weight model it had assessed, while placing it about four months behind the U.S. frontier on its aggregate benchmarks.
  3. Both are laboratory evaluations; the reported results do not measure real-world attack frequency or establish how often the model would be misused.

Anthropic’s Frontier Red Team says GLM-5.3, released by Z.ai, can build end-to-end cyber exploits. In Anthropic’s simulated tests, simple techniques bypassed the model’s safeguards 64% to 100% of the time. [1]

NIST’s Center for AI Standards and Innovation separately called GLM-5.3 the most cyber-capable open-weight model it had assessed and said it lagged the U.S. frontier by about four months on its aggregate cyber benchmarks. The organizations used different evaluations, so the figures should not be treated as a single head-to-head result. [2]

Anthropic says open access and weaker safeguards distinguish this model from restricted systems in its comparison. The available assessments describe controlled tests, not observed attacks in the wild. [1] [2]

Why it matters

The assessments put model access and safeguard strength at the center of the debate over how quickly advanced cyber capabilities are spreading.

Editor's note

The bypass range and capability ranking are findings reported by the evaluating organizations; no independent replication was found in the collected coverage.

Type to search

↑↓ navigate ↵ open esc close