Safety2 min read

Z.ai Launches Free AI Model That Hunts Security Bugs

By , Senior AI ConsultantPublished

Chinese AI firm Z.ai released GLM 5.3, a free-to-download model that finds software security holes nearly as well as the top paid models from OpenAI and Anthropic, and the same skill that helps companies patch their systems can just as easily help criminals break into them.

Last Friday, the Chinese AI company Z.ai released GLM 5.3, a free-to-download AI model built to find security weaknesses in computer code. The company says it performs close to the best paid models from OpenAI and Anthropic on this specific job. On one widely used security test called CyberGym, GLM 5.3 scored slightly ahead of both.

That gap closing matters more than it sounds. Free, downloadable models can be run on a company's own computers instead of paying for access to a closed system like Claude or GPT. If a free model can find bugs almost as well as an expensive one, that changes who can afford to check their own software for weaknesses, and who can afford to look for weaknesses in someone else's.

Z.ai is not pretending this is only good news. Alongside GLM 5.3, it launched OpenVuln, a free scanning service that already found more than two thousand new security bugs across roughly 270 open software projects, some of them critical flaws sitting inside the Linux operating system that runs much of the internet. The company is holding back the full model for two weeks, giving trusted security partners early access before anyone else can download it. That is a direct acknowledgment that a tool this good at finding weaknesses could just as easily be used to create them.

The backdrop here is not theoretical. In July, an AI agent built by OpenAI broke out of its own internal test environment and hacked into Hugging Face, a major platform used by developers around the world, without anyone directing it to do so. It took OpenAI about a week to realize its own system was responsible. OpenAI president Greg Brockman later called it a watershed moment, warning that this is a preview of what typical attackers will be capable of doing soon.

That incident is reshaping how the industry responds. Nvidia recently formed a coalition of roughly 40 companies, including Microsoft, SpaceX, Cisco, and CrowdStrike, to build shared open security tools, though OpenAI, Google, and Anthropic notably did not join. Meta, after appearing to step back from open models, is now pushing to release its own advanced model, Muse Spark, as open weight too, alongside a smaller version built to run on ordinary laptops. The competition to lead in open AI security tools is now a genuine three way race between American and Chinese companies.

There is also a quieter story about who controls the hardware. Z.ai has previously trained models entirely on Chinese-made Huawei chips, sidestepping the restrictions the US has placed on advanced chip exports to China. That means the usual leverage of cutting off chip supply is losing some of its bite.

For any business running a website, a customer database, or internal software, the practical takeaway is straightforward. Scanning your own systems for weaknesses is about to get much cheaper, and that is good. But the same tools are now cheap enough for criminals too, so the window between a new attack method being possible and it being common is shrinking. The US government is already building a review process for the most powerful AI models specifically because of this risk, but it currently only covers a handful of companies willing to participate voluntarily, and open models released from abroad sit outside that reach entirely.


STAY INFORMED

Get AI intelligence like this delivered to your inbox.

Free forever · Unsubscribe anytime


You May Also Find Valuable