Open-Source AI Model GLM-5.2 Closes Gap With OpenAI and Anthropic, Report Finds

An open-weight AI model from China is nearly matching top U.S. AI systems in capability, but a new safety report says it lacks matching safeguards.

maisiekooc
Maisie Morrison

AgentLocker Editor

AI Models
Open-Source AI Model GLM-5.2 Closes Gap With OpenAI and Anthropic, Report Finds

A new report from AI safety group SaferAI says an open-weight AI model from China is closing the gap with the world's leading AI systems. The model, called GLM-5.2, comes from the company Z.ai.

SaferAI found that GLM-5.2 is only a few months behind OpenAI's GPT-5.5 and Anthropic's Claude Opus 4.7 on cyber and biology tasks. The gap in raw skill is shrinking fast.

But the report found a bigger problem. GLM-5.2 refused none of the offensive cyber or biology test tasks it was given during testing.

Claude Opus 4.7 behaved very differently. It refused so many tasks that testers could not even finish running a key cybersecurity benchmark called CyberGym.

This difference matters because of how open-weight models work. Once a company releases the weights publicly, anyone can download them and run them on their own computers.

How Closed Models Try to Stay Safe

Companies like OpenAI and Anthropic use tools such as classifiers and refusal training to stop their models from helping with harmful tasks. These tools work through the company's own servers.

That kind of control disappears once someone downloads open weights. Users can remove safety filters, retrain the model, or change its instructions freely.

Even closed models are not fully protected. A report from Far.ai found hundreds of jailbreaks that get around safety rules on models like Grok 4.5 and Gemini 3.1 Pro.

Attackers often combine several tricks at once. These include pretending to be in a fictional role, claiming false authority, or faking a past conversation.

One idea to reduce risk is removing dangerous information from training data before a model is built. This method shows some promise for biology topics.

It works less well for cybersecurity. Coding skills and hacking skills often come from the same knowledge, so it is hard to separate them.

Some companies limit what a model can do instead. Anthropic's Opus 5 can check for weaknesses in unfinished code but not in finished software, based on its published system card.

China's Approach to AI Risk

Chinese officials have started to talk more about AI safety. At a recent AI conference, President Xi Jinping spoke about the value of open models alongside the need for human control.

Graham Webster, a researcher at Stanford who studies Chinese AI policy, said China's current rules focus mostly on political content and social stability. They do not target cyber or biological risks the same way.

Webster said Chinese internet users must use their real identities online. He said this creates a system where companies and users can be held responsible for their actions.

SaferAI said Z.ai did not release a safety framework, testing plan, or risk report for GLM-5.2. The company did not respond to questions about internal safety testing.

There are also arguments in favor of open models. Hugging Face said it used GLM-5.2 to help defend against a cyberattack linked to OpenAI last month.

Hugging Face CEO Clem Delangue said open models can help find and fix security holes before attackers use them. SaferAI's Henry Papadatos disagreed that this outweighs the risk, saying dangerous capabilities should not be treated as harmless just because they are open.

maisiekooc

Written by

Maisie is a news writer at Agent Locker, covering the latest developments in artificial intelligence, emerging technology and the companies shaping the future.

Discover AI Agents