> ## Content Index
> Fetch the complete content index at: https://www.metatalks.ai/llms.txt
> Use this file to discover other available public pages before exploring further.

# Z.ai says GLM 5.3's open weights go to everyone two weeks after its guarded launch
- URL: https://www.metatalks.ai/z-ai-releases-glm-5-3-to-security-partners-first-citing-misuse-risk/
- Published: 2026-08-19T16:27:00.000Z
- Updated: 2026-08-19T16:27:00.000Z
- Author: Al
- Tags: News, AI Security, Frontier Models, AI safety, #newswire

**Z.ai credits the model with finding 2,436 flaws across 269 projects, and with going further and assembling chains of exploits.**

Z.ai released [GLM 5.3](https://www.wired.com/story/zai-open-weight-ai-models-release-cybersecurity-hacking/?ref=metatalks.ai) on 14 August, an open-weight model the company says handles demanding programming work and computer-security jobs at close to the level of the strongest models Anthropic and OpenAI have put on public release. For now it reaches only a small circle of partners the company trusts — a sign of how quickly highly sophisticated hacking skills are turning up in models whose weights are freely available.

Z.ai acknowledged in its announcement the risk of releasing a powerful open model. What the model can do, the company says, lets defenders catch flaws sooner, confirm which risks are genuine and move quicker on fixes, while carrying an unmistakable potential for misuse; on that basis it is phasing the rollout, with a chosen group of security partners evaluating the model in contained environments before anyone else.

The ability behind that caution cuts both ways. The model is reportedly highly skilled at picking out security holes, going so far as to [assemble chains of exploits](https://www.scworld.com/brief/chinese-ai-model-glm-5-3-shows-advanced-bug-finding-capabilities?ref=metatalks.ai). Z.ai says it ran the model over real-world codebases and turned up 2,436 security flaws spread over 269 projects, 1,097 of them rated medium-to-high in severity, across kernels, operating systems, browser engines and networking protocols — a few of the flaws roughly 40 years old.

The comparison with the American frontier systems rests on programming and security test results the company itself cited, which it says put GLM 5.3 close to what the Anthropic and OpenAI models achieve — and here and there above them — on tests including the security evaluation CyberGym. On security and coding benchmarks other than that one, the model performed less effectively than Western models.

Cost is the other half of the defensive case: open-weight models can be downloaded and run on a company's own hardware, typically for significantly less than closed models such as Claude and GPT. Z.ai has also released OpenVuln, a service that uses GLM 5.3 to scan code repositories for vulnerabilities. Guillermo Rauch, chief executive of Vercel, wrote on X that engineers at the company had put the model through its paces as a way of sweeping websites for bugs, saying its lower price should give defensive security work a real lift and calling it a new open frontier.

The hold-back comes with a declared expiry. Announcing the model, Z.ai said it would be opened to everyone two weeks from the point at which the phased rollout to trusted partners got under way. On the timetable it described, the same vulnerability-finding weights would then be a download away for anyone — and that is where the concern lies, that the model's hacking capabilities could pose problems in the hands of criminals or other bad actors.