In brief

Anthropic said on September 29 that GLM-5.3, an open-weight model from the Chinese company Z.ai, can build working cyber exploits on its own. Its results came close to those of Anthropic’s Claude Mythos Preview. Because anyone can download the model, its safety rules can be removed. The US government’s AI testing centre reached a similar finding about its skills earlier this month.

New to this? Read it in simple words
  • Anthropic tested an AI model called GLM-5.3 from the Chinese company Z.ai.
  • Anthropic says it can find and use weak spots in software, almost like Anthropic’s best model.
  • Anyone can download the model and switch off its safety rules, Anthropic says.
  • A US government test also rated it the strongest open model for cyber attacks.
Words to know
Exploit
Code that uses a flaw in software to break in.
Open weights
A model whose files anyone can download, run and change.
Safeguard
A rule built into an AI to stop harmful use.

What Anthropic found

In a test built on 41 known bugs in Chrome’s JavaScript engine, GLM-5.3 built working exploits in 50 of 410 attempts, Anthropic says. Its own Claude Mythos Preview did so in 56 of 410, while older models scored at or near zero.

In a second test on open-source software, GLM-5.3 took full control of a program in 4% of trials, against 6% for Mythos Preview. In one session, a researcher used it to chain unknown browser bugs into a web page that reads files from a visitor’s computer.

Sources1

RED TEAM TEST 01
An open model close to the top.

Working exploits in 410 attempts on 41 known Chrome bugs. Anthropic’s own test.

Safeguards that come off

The model often refuses clearly harmful requests. But in Anthropic’s simulated tests, simple tricks got it to carry out harmful cyber tasks 64% to 100% of the time, depending on the method. The same attacks failed against Claude models with safeguards, Anthropic says.

Because the weights are public, anyone can edit the model to remove its refusals. Anthropic says doing so cost it about $4,400 in computing, cut the refusal rate from above 90% to a few percent, and left the model’s skills largely intact.

Anthropic’s tests ran in sandboxes against offline targets, and in its simulated tests no code written by the model was run.

Sources1

An outside check, and the argument

The Center for AI Standards and Innovation (CAISI), part of the US standards agency NIST, tested the model earlier this month. It called GLM-5.3 “the most cyber-capable open-weight model released to date”, about four months behind the best US models.

The US models in that comparison were tested with their cyber safeguards switched off where that applied. Attackers cannot easily use those versions, Anthropic notes, but anyone can download GLM-5.3.

Anthropic wants governments to test capable AI models, including GLM-5.3’s successors, and says defenders need tools at least as good as attackers’. It sells access to its own models for cyber defence.

Sources12

Sources

Every fact in this story comes from the sources below. Open them to check our work.

  1. 1
    Primary source · September 29, 2026GLM-5.3 and the spread of advanced cyber capabilities Anthropic
  2. 2
    Primary source · September 17, 2026CAISI’s Assessment of Z.ai’s GLM-5.3 Cyber Capabilities NIST
How we checked this story

We read Anthropic’s post and the US government’s earlier assessment of the same model. The safeguard figures are Anthropic’s alone; the ranking of the model’s skills is backed by CAISI. We found no news report with a response from Z.ai, and we leave out all technical details that could help an attacker.