Five months ago, Anthropic built an AI model that could find and exploit software bugs almost entirely on its own. It was good enough to find flaws that had survived decades of human review. Anthropic decided not to release it publicly. Instead, it gave the model to a trusted group of defenders first, on the idea that the good guys needed a head start before attackers got tools this sharp.
That head start is over. Zhipu AI, a Chinese company spun out of Tsinghua University, has released GLM-5.3, an AI model that performs almost as well at building working cyberattacks as Anthropic's unreleased tool. The key difference is that GLM-5.3 is free for anyone to download, right now, with no vetting and no waiting list.
Anthropic's safety testers ran their own checks and found GLM-5.3 built complete, working attacks on real software bugs at rates close to their own best model. In hands-on tests, a researcher used it to chain together several previously unknown flaws in a widely used web browser into an attack that could read a visitor's private files without their knowledge. A separate test turned a newly disclosed bug into a working attack chain in about a day, for roughly twenty dollars in computing costs.
The bigger problem is not the model's raw skill. It is how easily its safety limits fall apart. Telling the model it was doing an authorized security exercise got it to cooperate with harmful requests most of the time. A cheap technical trick that nudges the model's own reasoning worked even better. And because the model's inner workings are published openly, outside developers can strip its refusals out entirely, a process that costs a few thousand dollars and takes a few days. Several people had already done this and posted the stripped versions online within days of release.
A US government lab, NIST's Center for AI Standards and Innovation, ran its own independent tests and reached a similar conclusion: GLM-5.3 is the most capable freely downloadable hacking model built so far, trailing the best American models by only about four months. That gap has been shrinking with every release cycle, and there is no reason to expect it to widen again.
This changes the math for anyone running a business with computers, which is to say everyone. Attackers no longer need a skilled hacking team. They need a laptop, an internet connection, and a willingness to download a free file. Cybersecurity researchers have already tied AI tools to real intrusions, including a Chinese state-linked espionage campaign where AI carried out most of the attack steps on its own, and a separate near-autonomous attack on government systems in Asia.
The flip side is that defenders can use the exact same capability. Security teams can now find and patch their own weak spots faster than before, if they act on it. The businesses that come out ahead will be the ones that treat patching and basic security hygiene as urgent this year, not the ones that wait for a headline-grabbing breach to make the case for them. Governments pushing for independent safety testing of these models, as Anthropic is now asking for, is a reasonable ask, but it will not arrive fast enough to matter for the next twelve months. Plan accordingly.