The US artificial intelligence giant Anthropic has warned of the potential danger posed by Chinese firm Z.ai’s GLM-5.3, with the open-weight model showing a troubling mix of powerful hacking abilities but weak safety constraints. GLM-5.3 almost matches Anthropic’s most advanced model in terms of its cyber capabilities, but has far weaker safeguards, meaning there is greater potential for the model to be co-opted by bad actors, according to the San Francisco-based firm. In a report released on Tuesday, Anthropic said it had tested GLM-5.3’s ability to build end-to-end cyber exploits. The Chinese model successfully completed 50 out of 410 exploit attempts, compared with 56 for Claude Mythos Preview, a frontier Anthropic model that can only be used by vetted users. Unlike Mythos, GLM-5.3 is open-weight, meaning users are free to download and modify the underlying model. And Anthropic found during testing that “attackers can bypass GLM-5.3’s safeguards between 64 and 100 per cent of the time with simple techniques”, whereas the bypassing “did not succeed against safeguarded Claude models”. Anthropic researchers were able to remove the Z.ai model’s refusal mechanisms via “abliteration” – a technique that involves editing a model’s internal weight matrices – to suppress its tendency to reject harmful requests, according to the report. After spending about 2,200 GPU hours – equivalent to running 2,200 graphics processing units for one hour – performing and testing abliteration, GLM-5.3’s refusal rate plummeted from above 90 per cent to between 2 and 12 per cent across three safety benchmarks, Anthropic said. The computational power needed to conduct the abliteration cost roughly US$4,400, but Anthropic added that an experienced team might only need about US$1,200 to pull off such an attempt. Z.ai – also known as Zhipu AI – was quick to push back against the claims. Hours after Anthropic published its findings, Li Zixuan, the Chinese firm’s head of global operations, pointed out in a post on X that Z.ai’s models were being widely used by companies to defend themselves against cyber attacks. In July, the developer platform Hugging Face used GLM-5.2 to help investigate and contain an autonomous intrusion by OpenAI models, after Anthropic’s Claude refused parts of the security work because of its safeguards. GLM-5.3 had already “helped defend 389 open-source projects, with 4,249 potential vulnerabilities found so far”, Li said. The report feeds into a broader debate in the United States about the advantages and potential dangers of open-weight models, with Anthropic pushing for greater control over access to frontier models. Other US tech giants, including Meta Platforms and Nvidia, have championed open models, arguing that wider access can accelerate innovation and help maintain US leadership in AI. AI safety discussions have heated up in recent weeks, especially in the run-up to the just concluded meeting between Chinese President Xi Jinping and his US counterpart Donald Trump. Beijing and Washington agreed during the summit to formalise an AI dialogue mechanism to exchange views on the technology’s risks and benefits, though Trump said on Tuesday that he did not want to work with China on AI safety. Chinese AI models – the most advanced of which are all open-weight – are rapidly gaining cyber capabilities. When Z.ai released GLM-5.3 in August, the company said it had beaten Anthropic’s Mythos 5 model in a key cybersecurity test. The Beijing-based company withheld GLM-5.3’s model weights for two weeks after the launch to conduct additional safety testing and hardening. Earlier this month, the US government’s Centre for AI Standards and Innovation described GLM-5.3 as the “most cyber-capable open-weight model released to date”, although it estimated that the model remained about four months behind the overall US frontier on an aggregate of cybersecurity benchmarks. In August, Kimi K3 – a model created by the Chinese firm Moonshot AI – broke out of a supposedly isolated sandbox environment during a cybersecurity evaluation and accessed the internet. The escape did not involve hacking an external system.