A new Chinese AI model is showing strong skills in finding and exploiting security flaws.
The model, called GLM 5.3, was built by China based AI lab Z.ai. Its cyber skills are close to those of leading US AI models.
The result shows how fast Chinese open weight AI models are improving. It also raises fresh concerns about cyber attacks.
Open weight models can be downloaded and changed by users. This can help researchers and defenders. But it can also give hackers more freedom.
Z.ai said Friday that it will delay the public release of GLM 5.3 weights for two weeks. The lab wants more time to test its safety and security controls.
The company trained the model to find security flaws. It allowed the model to practice cyber tasks in controlled settings.
Z.ai is also creating a limited access plan. Selected security partners will be able to use GLM 5.3 in controlled environments before the wider release.
Tests show why the company is taking extra care.
GLM 5.3 scored 84.5% on CyberGym. The test measures how well AI models can find known security flaws.
The score was higher than the scores reported for Anthropic’s Fable 5 and OpenAI’s GPT 5.6 Sol in the same test.
GLM 5.3 also performed well on ExploitBench. That test checks how well models can reason about real security flaws and develop ways to exploit them.
On that test, GLM 5.3 ranked behind only Fable 5 and GPT 5.6 Sol among the models tested by Z.ai.
The progress comes as AI is becoming more useful in cyber work.
AI can help security teams find bugs faster. It can also help them check large amounts of code. The same skills can help attackers find weak points and build attacks.
That risk is growing as more powerful models become easier to access.
Z.ai said its GLM models have already found more than 2,400 security flaws. More than 1,000 of those flaws were rated critical or high.
The company said some flaws were found in the Linux kernel. Others were found in widely used VMware and Apache projects.
Z.ai is presenting the work as a tool for defense.
The lab said open technology needs strong protection as well. It has also started a program for open source developers.
Under the program, developers can ask a GLM model to scan their public code for bugs. The goal is to help find security problems before attackers can use them.
There is already evidence that GLM models can help defenders.
Hugging Face said it used GLM 5.2 while investigating a recent breach linked to OpenAI models. The company said some US frontier models would not help with the investigation because of their safety rules.
That shows the mixed nature of cyber capable AI.
The same model can help a defender find a flaw. It can also help an attacker understand that flaw.
The biggest concern may come when GLM 5.3 becomes fully open.
Once the model weights are public, Z.ai will have less control over how people use or change the system. Users could modify the model and remove some of its safety limits.
That could make the model more useful to security researchers. It could also make it more useful to hackers.
The issue is not limited to China.
US AI companies are also facing pressure over cyber risks. Some US labs have slowed model releases while they study possible security threats.
At the same time, hackers are testing AI tools in real attacks.
Researchers recently found that open source AI agents were used in an automated cyber attack against Taiwan’s government. The case showed how AI agents may reduce the amount of human work needed during an attack.
Governments are now watching the rise of open AI models more closely.
The Trump administration is considering how open source AI models should be handled as their skills approach those of closed systems.
The debate will likely grow as models become better at cyber tasks.
The key question is simple. How can society give defenders powerful AI tools without giving attackers the same power?
GLM 5.3 shows that the gap between open and closed AI is getting smaller. Its release could offer major benefits for security teams.
But it could also create a new cyber risk if powerful hacking skills become widely available.

