Open-weight AI models have nearly caught the frontier on capability. On safety, they have not. And once the weights are public, no lab can enforce a guardrail. A new evaluation of China’s leading open model makes the gap concrete.
GLM-5.2, the open-weight model from China’s Z.ai, is only a few months behind OpenAI’s GPT-5.5 and Anthropic’s Claude Opus 4.7 on cyber and bio tasks, TechCrunch reported, citing the safety nonprofit SaferAI. But it refused none of the offensive-cyber or dual-use-biology tasks it was set. Claude Opus 4.7, by contrast, refused so consistently that SaferAI could not finish the cyber benchmark on it at all.
“The frontier of capability is not the frontier of risk,” SaferAI’s Henry Papadatos said, so the safeguards matter as much as the model. Z.ai can guard its own hosted service. Those protections vanish the moment someone runs the weights on their own hardware, where any safeguard can be stripped out. It is the risk critics of open models have warned about for years.
Closed models are not airtight either. The nonprofit Far.ai found hundreds of universal jailbreaks in xAI’s Grok 4.5 and Google’s Gemini 3.1 Pro. The difference is that a closed lab can patch a jailbroken model. Open weights cannot be recalled once they are out.











