Anthropic Tests GLM-5.3's Cyber Capabilities
Anthropic evaluated GLM-5.3 using automated cybersecurity benchmarks and human-in-the-loop testing conducted in isolated environments.
The evaluations focused particularly on whether the model could move beyond identifying vulnerabilities and develop functioning exploits from beginning to end.
According to Anthropic, GLM-5.3 demonstrated a substantial increase in exploit-development capability compared with earlier open-weight models.
The company said this represented evidence that sophisticated offensive cybersecurity capabilities are spreading beyond tightly controlled frontier AI systems.
GLM-5.3 Builds Working End-to-End Exploits
One of Anthropic's key evaluations involved ExploitBench, a benchmark designed to test whether AI systems can exploit known vulnerabilities in the V8 JavaScript engine used by browsers including Google Chrome.
GLM-5.3 successfully developed end-to-end exploits in 50 of 410 attempts.
Anthropic's Claude Mythos Preview succeeded in 56 of 410 attempts under the same evaluation framework.
The relatively close results led Anthropic to conclude that GLM-5.3 has reached a level of exploit-development capability comparable with some highly advanced restricted models on this particular benchmark.
Earlier Models Performed Far Below GLM-5.3
The increase is notable because earlier generations of AI models performed significantly worse on sophisticated exploit-development tasks.
Anthropic found that previous models, including GLM-5.2 and Claude Opus 4.6, failed to demonstrate comparable performance on some of its advanced binary-exploitation evaluations.
GLM-5.3 therefore represents more than an incremental improvement in the company's assessment.
It suggests that AI systems are becoming increasingly capable of performing complex cybersecurity tasks that traditionally require specialised technical expertise.
NIST Also Evaluates GLM-5.3
Anthropic's findings broadly align with a separate assessment released by the US National Institute of Standards and Technology's Center for AI Standards and Innovation.
CAISI described GLM-5.3 as the most cyber-capable open-weight model it had evaluated to date.
However, the government assessment also found that GLM-5.3 remained below the overall capability of the current US frontier across its aggregate cybersecurity benchmarks.
CAISI estimated that GLM-5.3 was roughly four months behind the US frontier on its composite measure.
This distinction is important because individual benchmark results should not be interpreted as demonstrating that GLM-5.3 is universally more capable than closed frontier models.
Open-Weight Release Drives Anthropic's Concern
The model's distribution structure is central to the security debate.
An open-weight model makes its trained parameters available for users to download and operate independently.
This differs from closed models delivered primarily through controlled cloud services or APIs.
Once weights are publicly available, the original developer has far less control over how the model is configured, modified or deployed.
Users can potentially alter behavioural safeguards without requiring permission from the original provider.
For cybersecurity-capable models, Anthropic argues that this difference becomes increasingly significant as offensive capabilities improve.
Anthropic Says Safeguards Can Be Bypassed
Anthropic found that GLM-5.3 does contain safeguards and may refuse requests that are clearly harmful.
Its tests, however, indicated that those protections could be bypassed using several techniques.
A deceptive framing that presented a harmful task as a legitimate security exercise caused the model to engage with tested requests 64% of the time.
Another technique involving prefilling the model's reasoning increased the engagement rate to 92% in Anthropic's testing.
The company also evaluated a modified version designed to reduce refusals and reported complete engagement with the harmful requests included in those particular benchmark tests.
These figures describe Anthropic's controlled evaluations and should not be interpreted as a universal success rate for real-world cyberattacks.
Open Weights Allow Safeguards to Be Modified
The ability to modify an open-weight model introduces a security challenge that is difficult to address solely through built-in behavioural restrictions.
Closed AI services can enforce safeguards at several layers, including model behaviour, API access, monitoring and account controls.
With downloadable weights, many of these provider-level controls are unavailable.
A technically capable user can operate the model on independent infrastructure and change its configuration.
Anthropic argues that this creates a fundamentally different risk profile once models acquire advanced cyber capabilities.
Z.ai Had Already Identified Cybersecurity Risks
Z.ai itself recognised GLM-5.3's unusual cybersecurity capabilities before making its weights widely available.
The Chinese company initially delayed release of the model weights while conducting additional safety testing.
GLM-5.3 was first announced in August, with its open weights released later following the additional review period.
Z.ai has emphasised the defensive value of advanced cybersecurity AI, including its ability to identify vulnerabilities in widely used software.
The disagreement therefore centres partly on how to balance the defensive benefits of open access against the potential for malicious use.
Cyber Capability Has Defensive Applications
Advanced vulnerability-discovery models are not inherently offensive tools.
The same capabilities that allow an AI system to identify exploitable software weaknesses can help security teams find and repair those weaknesses before attackers discover them.
AI could potentially allow software maintainers to examine large codebases more rapidly than human security teams can manage alone.
This could be particularly useful for widely deployed open-source projects that have limited security resources.
The cybersecurity implications of models such as GLM-5.3 are consequently dual-use: the underlying capability can assist both defenders and attackers.
Anthropic Uses Restricted Access for Advanced Models
Anthropic has taken a different approach with some of its most capable cybersecurity systems.
The company has limited access to less-restricted versions of advanced models to vetted users and cybersecurity programmes.
Its strategy is intended to give defenders access to powerful vulnerability-discovery capabilities while limiting availability to malicious actors.
Anthropic said its safeguarded Claude models also resisted the bypass techniques used against GLM-5.3 during its tests.
Because Claude's model weights are not publicly downloadable, users also cannot modify the underlying model in the same way as an open-weight system.
AI Could Lower Barrier to Advanced Cyber Operations
The broader security concern is that increasingly capable AI systems could reduce the expertise required to conduct sophisticated cyber operations.
Developing reliable exploits traditionally requires detailed knowledge of software architecture, memory behaviour, vulnerability research and programming.
AI systems capable of automating portions of this process could increase the number of people able to attempt such activities.
They could also increase the speed at which experienced attackers analyse vulnerabilities.
The risk becomes more significant if models can independently combine vulnerability discovery, exploit development and iterative testing.
Real-World Attacks Remain More Complicated
Benchmark performance does not mean an AI system can automatically compromise arbitrary real-world systems.
Anthropic's evaluations were conducted in controlled, sandboxed environments using defined targets.
Actual cyber operations involve additional challenges such as discovering suitable targets, bypassing layered security controls, adapting to changing software configurations and avoiding detection.
The benchmark results therefore measure particular technical capabilities rather than providing a direct prediction of real-world attack success.
Nevertheless, improvements in those underlying capabilities are important for cybersecurity planning.
GLM-5.3 Highlights Open-Weight AI Debate
The findings intensify the broader debate surrounding open-weight artificial intelligence.
Supporters argue that open models encourage research, competition and innovation while allowing organisations to operate AI on their own infrastructure.
They can also give researchers greater transparency and allow smaller companies to develop products without depending entirely on a handful of large AI providers.
Security researchers additionally benefit from access to capable models for defensive work.
Critics argue that once highly capable models are freely downloadable, meaningful restrictions on malicious use become substantially harder to enforce.
Cybersecurity May Become Key Threshold for AI Releases
As AI capabilities advance, cybersecurity performance could become an increasingly important consideration in decisions about model releases.
A model capable of general coding assistance presents a different risk profile from one capable of autonomously developing reliable exploits.
Developers may therefore face pressure to conduct more extensive cybersecurity evaluations before releasing advanced model weights.
Governments and standards organisations are also likely to examine how capability thresholds should influence access controls and disclosure requirements.
The challenge will be creating safeguards without unnecessarily limiting legitimate cybersecurity research and defensive innovation.
Businesses May Need to Accelerate Defensive Security
The emergence of more capable cyber-focused AI also has implications for enterprises.
Companies may need to assume that attackers will increasingly use AI to analyse software, automate reconnaissance and identify vulnerabilities.
This could shorten the period between disclosure of a software vulnerability and attempts to exploit it.
Businesses may consequently need faster patching processes, stronger vulnerability management and more automated security monitoring.
AI-powered defensive tools are also likely to become increasingly important as organisations attempt to counter AI-assisted threats.
Conclusion
Anthropic's assessment of Z.ai's GLM-5.3 highlights a new stage in the intersection of artificial intelligence and cybersecurity.
In Anthropic's ExploitBench testing, GLM-5.3 produced end-to-end exploits in 50 of 410 attempts, approaching the 56 successful attempts recorded by the restricted Claude Mythos Preview model. Separate US government testing has also described GLM-5.3 as the most cyber-capable open-weight model evaluated to date, while finding it remains below the overall US frontier.
The larger concern centres on accessibility. Because GLM-5.3's weights are publicly available, users can operate and modify the model independently, making conventional provider-controlled safeguards harder to enforce. At the same time, the same capabilities could give cybersecurity defenders powerful new tools for identifying and repairing vulnerabilities.
As advanced cyber capabilities spread into open-weight models, the balance between AI openness, defensive innovation and misuse prevention is likely to become an increasingly important issue for the global technology industry.