Anthropic Warns Chinese AI Model GLM-5.3 Combines Advanced Hacking Capability With Weak Safeguards
If the findings hold under independent review, the combination of near-frontier offensive cyber capability and limited safety constraints in an open-weight model represents a concrete policy test...
US artificial intelligence company Anthropic has published a warning about Chinese firm Z.ai's open-weight model GLM-5.3, stating that the model demonstrates cyber capabilities approaching those of Anthropic's own most advanced systems while carrying significantly weaker safety constraints, according to a report by the South China Morning Post published September 30, 2026.
Anthropicsaid GLM-5.3 "almost matches" its most capable model in terms of cyber offensive potential. The firm characterized the pairing of high capability with low safety guardrails as posing a heightened risk of the model being co-opted by malicious actors, according to the South China Morning Post's account of Anthropic's findings.
The term "open-weight" refers to AI models whose underlying numerical parameters are publicly released, allowing any individual or organization to download, modify, and deploy the model without oversight from the original developer. This distinguishes GLM-5.3 from closed commercial models, where access is mediated by the developing company and subject to usage policies and monitoring.
The practical consequence of open-weight distribution is that safety restrictions built into a model at release can be removed or circumvented after download. Security researchers and policymakers have debated for several years whether open-weight frontier models pose qualitatively different risks than closed ones, precisely because the original developer loses control over downstream use once parameters are public.
Anthropicis itself a party with commercial interests in the AI safety debate, as its business model centers on positioning its Claude models as safer alternatives to competitors. Readers and policymakers should note that independent, third-party replication of Anthropic's capability and safety benchmarks for GLM-5.3 has not been confirmed in the source material available at time of publication.
Z.ai is a Chinese AI company. The GLM model series has been developed in part through collaboration with Tsinghua University's Knowledge Engineering Group, according to prior public documentation of the GLM model lineage, though the specific institutional relationships for GLM-5.3 as assessed by Anthropic were not detailed in available source material.
The US government has in recent years taken a series of steps to restrict Chinese firms' access to advanced semiconductors used in AI training, most recently through export controls administered by the Commerce Department's Bureau of Industry and Security. Whether those controls have materially slowed the development of models like GLM-5.3 is an open question; the South China Morning Post report does not address the hardware used in GLM-5.3's development.
The finding arrives at a moment of active diplomatic tension between Washington and Beijing over technology and security matters. A separate report by the South China Morning Post, also published September 30, 2026, noted that US and Chinese officials offered differing characterizations of discussions about crisis communication and conflict prevention mechanisms following a recent summit between President Xi Jinping and US counterparts, suggesting that channels for managing technology-related security disputes remain unsettled.
No US government agency response to Anthropic's warning was included in available source material. The relevant oversight bodies would include the Commerce Department, the National Security Council, and the Cybersecurity and Infrastructure Security Agency, whose positions on GLM-5.3 specifically are unknown at time of publication.
The Congressional Times has previously reported on related developments in AI governance and safety, including AI Safety Group Sues OpenAI Over Autonomous System Access to Hugging Face, which addressed questions of model access controls in a domestic legal context.
What would clarify the policy significance of Anthropic's findings is independent benchmark replication by a neutral third party, a response from Z.ai addressing the safety characterization, and a public statement from relevant US regulatory agencies on whether GLM-5.3 triggers review under existing AI or export control frameworks.