Chips & compute
What GLM-5.3's cyber-hunting open-weight release means for you
A Chinese lab delayed its own model's public release to check how good it had got at finding software bugs, then added new rules for big companies that want to host it.
The answer
Z.ai released GLM-5.3's open weights after a safety delay over its bug-finding skill.
A Chinese AI lab called Z.ai has released the open weights (the underlying files anyone can download and run) of its latest model, GLM-5.3, but only after pausing for two weeks to check how dangerous its new skills might be. The model has become unusually good at finding and exploiting flaws in software, and Z.ai has now attached new rules to stop the biggest companies from hosting it without a check first.
What happened
Z.ai launched GLM-5.3 through its API on 14 August 2026. It then delayed releasing the open weights, the free, downloadable version of the model, for two weeks while it finished a safety evaluation. The reason: GLM-5.3 turned out to be much sharper at spotting security holes in code. In testing, it turned up 2,436 findings across 269 open-source projects.
The weights went public on Hugging Face on 28 August, available in two formats (BF16 and FP8) and compatible with several common tools for running AI models. The full model is a mixture-of-experts system with about 753 billion parameters, though only a fraction are active at once. A smaller version, GLM-5.3-Flash, came out two days earlier under a fully open MIT licence.
The full-size model, though, ships under a new, stricter licence. Companies earning more than $10 billion in revenue over any 12-month period must now pass a Z.ai security review before they can host the model themselves, rather than just accessing it through an API. Individuals and smaller companies face no such restriction.
On Z.ai's own benchmarks, GLM-5.3 scored 84.5% on CyberGym, a test of cyber skills, up from 77.2% for the previous version, and ahead of rival models Claude Mythos 5 (83.8%) and GPT-5.6 Sol (83.6%). On another test, ExploitGym, it completed 130 exploitation tasks in six hours, compared with 39 for its predecessor. Z.ai said these gains came from more intensive post-training, the tuning stage after a model is first built, rather than from retraining the model from scratch, as reported by The New Stack.
What it means for you
If you're an individual developer or run a smaller company, you can download and use GLM-5.3 freely, same as before. The new licence restriction only applies to companies with more than $10 billion in annual revenue that want to host the model on their own infrastructure.
The model's sharper bug-hunting ability cuts both ways: it could help developers find and fix security flaws faster, but the same skill could be misused to find flaws to exploit. That risk is why Z.ai held the release back and why it says it found a serious vulnerability in the coding tool Cursor during testing, according to VentureBeat.
What happens next
Some critics question whether the new licence is really about safety or more about controlling how large firms use the model commercially. Rival Chinese labs Moonshot and DeepSeek still release their models under more permissive terms, so it isn't yet clear whether other labs will follow Z.ai's approach of staged, safety-reviewed releases.
Sources
- Z.ai's GLM-5.3 goes open weight, but its new license aims at hyperscalers — The New Stack, 28 August 2026
- GLM-5.3 is here with advanced cyber capabilities — VentureBeat, 14 August 2026