# Z.ai Opens the Weights of GLM-5.3, Its Strongest Coding and Cyber Model

The Chinese lab delayed the download for two weeks after the model scored 84.5% on the CyberGym vulnerability benchmark, a score it says beat Anthropic's Mythos 5.

- Published: 2026-08-29T06:21:15.195Z
- Canonical: https://polylog.news/ai/2026-08-29/z-ai-opens-the-weights-of-glm-5-3-its-strongest-coding-and-c
- Publisher: Polylog (AI desk)
- Section: tech
- Sources: [Polylog editors](https://polylog.news), [Interconnects](https://www.interconnects.ai/p/glm-53-how-chinese-labs-keep-stride), [Implicator](https://www.implicator.ai/z-ai-delays-glm-5-3-weights-two-weeks-after-cyber-score-beats-mythos-5/)

Zhipu AI, which sells internationally as Z.ai, has published the weights of GLM-5.3 for download, according to the Russian-language technical channel [AI ML Big Data](https://t.me/ai_machinelearning_big_data/10799), which reported that the model can now be run locally and fine-tuned instead of being reached only through the company's hosted service. The release follows through on a delay the company set for itself. GLM-5.3 launched on August 14 with hosted access only, and Z.ai said at the time that downloadable weights would follow in roughly two weeks, once a safety review finished.

The reason for the pause was the model's performance on offensive security tasks. Z.ai reported a score of 84.5% on CyberGym, a benchmark that tests the ability to find and exploit software vulnerabilities, and [said that result placed GLM-5.3 ahead of Anthropic's Mythos 5](https://www.implicator.ai/z-ai-delays-glm-5-3-weights-two-weeks-after-cyber-score-beats-mythos-5/). The company also said its post-training run produced exploit-chain reasoning it had not intended to build, and that the model found [more than a thousand critical bugs](https://www.techtimes.com/articles/324426/20260814/glm-53-post-training-produced-exploit-chains-zai-never-planned-finds-1097-critical-bugs.htm) across Linux, WebKit and FreeBSD. Those counts come from Z.ai and have not been independently verified.

On coding, the improvement over the previous release is large by the lab's own accounting. GLM-5.3 keeps the same 744-billion-parameter base as GLM-5.2 and adds only post-training, more task environments and longer training runs, yet [Terminal-Bench 3.0 rises from 4.6 to 28.3](https://www.interconnects.ai/p/glm-53-how-chinese-labs-keep-stride), with 28.5% on the command-line track of Agents' Last Exam. Z.ai calls that the state of the art among open-source models. Two days before releasing the flagship weights, the company released GLM-5.3-Flash, a 320-billion-parameter mixture-of-experts model with 18 billion active parameters, under the MIT license at $0.15 per million input tokens and $0.50 per million output tokens.

The sequence matters more than any single number. A lab measured a dangerous capability, delayed publication, strengthened the model's defenses, and then released the weights anyway. Once weights are downloadable, the safety work becomes a starting point rather than a lasting control, because anyone with the right hardware can fine-tune it away.

## What this means

Open-weight releases now carry offensive security capability close to the frontier, and the decision to release sits with a lab outside United States jurisdiction, so American export policy cannot control it. Closed vendors selling coding agents lose pricing power against a model buyers can host themselves, and enterprise security teams gain both a defensive tool and a new threat model in the same download. The pattern of delaying and then publishing anyway also sets a template other labs will be measured against.

## What to watch

- Whether independent researchers reproduce the CyberGym and Terminal-Bench numbers on the downloaded weights, which is what separates a real capability jump from vendor-run scoring.
- How quickly fine-tuned variants of GLM-5.3 appear that strip the safety hardening, which would show whether a delayed release buys any durable protection.
- Whether United States policymakers respond to a downloadable model with strong exploit-finding ability, since export controls were designed for chips and hosted access rather than files.
