The cover image for this piece was made on my own laptop, like the one for local model or cloud. The case I made there is one I make on this site a lot: a model that lives on your own machine can’t be taken away from you, repriced, or quietly changed. That property is exactly what this news is about. It just shows up from the other side.
On September 29, Anthropic’s Frontier Red Team published an analysis of GLM-5.3, a model from the Chinese lab Zhipu AI (known outside China as Z.ai). The model is open: anyone can download the weights and run it. According to Anthropic, it builds working cyberattacks on its own almost as often as Claude Mythos Preview, the model Anthropic chose not to release publicly five months ago because it judged it too dangerous for that.
What was measured
Anthropic ran two benchmarks plus sessions with its own researchers. Everything ran in isolated sandboxes, against targets that existed only for the test.
| Test | GLM-5.3 | Claude Mythos Preview | What it measures |
|---|---|---|---|
| ExploitBench | 50 of 410 attempts | 56 of 410 attempts | Building a complete exploit for a known bug in V8, Chrome’s JavaScript engine |
| Binary Exploitation (100 tasks) | 4 percent | 6 percent | Full control-flow hijack in open-source projects from Google’s OSS-Fuzz |
On that second test, Claude Opus 4.6 and GLM-5.2, the predecessor, scored zero. Anthropic reads that as a threshold being crossed.
One researcher pointed GLM-5.3 at a local build of a popular browser for a day, with less than an hour of their own attention. The model found several unknown bugs in the JavaScript engine and chained them into a web page that reads files off the visitor’s computer. Anthropic has reported the bugs to the maintainer. In a second session, the smaller GLM-5.3-Flash turned a known Chrome bug into a working exploit chain, with 20 minutes of human attention and eight hours of compute. At Zhipu’s API prices, that run would have cost $20.40.
Why the brakes come off
GLM-5.3 does have built-in refusals: ask it outright to attack a critical system and it says no. Anthropic tested three ways around that, 50 times per variant, in a simulated world.
| Method | What you do | GLM-5.3 complies | Possible with Claude via the API? |
|---|---|---|---|
| Cover story | Tell the model it’s running a red-team exercise | 64 percent | Tried, refused |
| Prefill | Write the start of the model’s reasoning yourself, as if it already decided to go ahead | 92 percent | No, the API doesn’t allow it |
| Abliteration | Edit the weights so the refusal behaviour is gone | 100 percent | No, the weights aren’t available |
Refusing is something the model learned in training, and it lives in the weights themselves. If you have the weights, you can locate that behaviour and strip it out, and the rest of the model stays intact. Anthropic did it themselves: about 2,200 GPU hours, roughly $4,400. Afterwards the model refused only 2 to 12 percent of clearly harmful requests, down from over 90 percent, with no drop on science questions. In a footnote, Anthropic estimates that a team that has done this before would need closer to 600 GPU hours, about $1,200. Modified versions of GLM-5.3 were online within days of release.
With a model behind an API, the last two methods don’t work, because the provider decides what you get to touch. With a model on your own disk, you decide. That is the freedom I argue for, and it is the same freedom that takes the brakes off here.
The number that suits Anthropic less
On September 17, CAISI, the AI evaluation centre at the US National Institute of Standards and Technology, published its own assessment of GLM-5.3. It calls it “the most cyber-capable open-weight model released to date”, and in the same breath says it is clearly weaker than the best US models: about four months behind on a combined measure. On ExploitBench, CAISI has GLM-5.3 at 61.1 percent against 100 percent for the best US score, and on ExploitGym at 9.4 percent against 44.4.
Those numbers differ from Anthropic’s because they count differently. CAISI counts the best of three attempts per task and awards partial credit; Anthropic counts complete exploits per attempt. What both have in common is that the US models were tested with their safeguards switched off. What the comparison mostly shows, then, is who gets access to the version without brakes.
The caveat
What shifts here is who gets to decide. Anthropic locates the safety in the fact that you can’t reach the weights. That holds for misuse, and it is also the exact argument for dependence. Read this as proof that closed is better and you’re buying the reasoning of a party that profits from it commercially. Anthropic doesn’t release its own weights, GLM-5.3 is a cheap competitor, and the report ends by asking governments to test GLM-5.3’s successors. That can be genuine concern and convenient at the same time.
Responsibility lands with whoever publishes, and here that’s blurry. By its own account, Z.ai held the weights for two weeks after the August 14 launch to finish safety evaluation and hardening. Anthropic doesn’t mention that wait and writes that the model was released “without meaningful safeguards”. Both can be true, because whatever refusal behaviour was built in during those two weeks turned out to be removable. Whoever strips it out afterwards and posts the modified version is a third party answerable to no one.
What users lose is the illusion that local means harmless. I’ve written before that running locally protects your input and moves your dependence rather than removing it. That still holds. But “it’s on my machine, so it’s my business” only works while the model can’t do much. GLM-5.3 doesn’t run on a laptop: the weights span 141 files and need data-centre hardware. So the bar isn’t zero. It has dropped from an access programme for vetted defenders to a rental bill.
What I do myself
My image generation and my dictation stay local. Those are small models with a narrow job, and the reason I run them myself (my input never leaves the machine) has nothing to do with this news. What I’m adjusting is how I write about it. On this site, “open” and “local” have mostly been arguments for the user. Past a certain capability, they’re also arguments for anyone who wants to misuse the model, and from now on that belongs in the same sentence.
Frequently asked questions
What is an open-weight model?
A model whose trained weights are public, so anyone can download it, run it on their own hardware and modify it. That’s not the same as open source in the strict sense: the training data and training code often aren’t public.
What is abliteration?
A technique that removes refusal behaviour from a model’s weights. The model stays almost as capable, but rarely says no to anything. It only works on models whose weights you have.
Is GLM-5.3 better than the US models?
No. According to CAISI it trails the best US models by about four months on cyber tasks. The difference is access: US models with comparable capabilities are only available to vetted users, while anyone can download GLM-5.3.
Should I stop running models locally?
Not for what most people use it for, like dictation, images or a personal writing assistant. The question does shift, though, from “is this safe for me” to “what can this model do in someone else’s hands”.
Sources
- Anthropic Frontier Red Team, “GLM-5.3 and the spread of advanced cyber capabilities”, anthropic.com/research, September 29, 2026.
- NIST CAISI, “CAISI’s Assessment of Z.ai’s GLM-5.3 Cyber Capabilities”, nist.gov, September 17, 2026.
- Z.ai, GLM-5.3 model card, huggingface.co/zai-org/GLM-5.3, accessed October 1, 2026.
- VentureBeat, “GLM-5.3 is here with advanced cyber capabilities”, August 14, 2026.
- The Decoder, “Anthropic says Zhipu’s open-weight GLM-5.3 nearly matches Claude Mythos Preview at building exploits”, September 30, 2026.
Checked on October 1, 2026 against Anthropic’s report, the NIST page and Z.ai’s model card. I couldn’t rerun the tests myself. The bypass numbers come from a simulation in which no code is actually executed and another language model estimates the outcome, which Anthropic itself points out. That Z.ai held the weights for two weeks of safety work I know from VentureBeat and the NIST date, not from a Z.ai text I read myself. Anthropic’s and CAISI’s ExploitBench numbers differ because they count differently; I’ve put them side by side rather than picking one.
