Updated
Updated · TechCrunch · Aug 4
GLM-5.2 Narrows AI Gap to Months, Refuses 0 Offensive Cyber and Bio Tasks
Updated
Updated · TechCrunch · Aug 4

GLM-5.2 Narrows AI Gap to Months, Refuses 0 Offensive Cyber and Bio Tasks

1 articles · Updated · TechCrunch · Aug 4

Summary

  • SaferAI found Z.ai’s open-weight GLM-5.2 is only a few months behind OpenAI GPT-5.5 and Anthropic Claude Opus 4.7 on cyber and biology benchmarks, yet it refused none of the offensive tasks tested.
  • That contrast was sharpest against Claude Opus 4.7, which refused so consistently that SaferAI could not complete the CyberGym cybersecurity benchmark on it at all.
  • Open-weight release makes the risk harder to contain because any API safeguards can be removed once users run the model locally; SaferAI said Z.ai published no safety framework, pre-deployment testing commitments or risk assessment.
  • The report lands as AI developers lean on refusal training, classifiers and API controls that jailbreaks already bypass on closed models, while open-weight advocates argue the same capabilities can help defenders spot and stop attacks.

Insights

With models like GLM-5.2 matching frontier systems in dangerous capabilities, has the irreversible release of AI weights already made safety obsolete?
If unrestricted open-weight AI can be weaponized offline, how will society defend against untraceable, automated cyber and biological attacks?