BEIJING: Chinese AI startup Z.ai said on Friday (Aug 14) its open-source GLM-5.3 model had neared Anthropic's restricted Mythos 5 in identifying software vulnerabilities, bolstering the credentials of a Chinese AI challenger gaining traction among Western developers.Z.ai said GLM-5.3 scored 84.5 per cent on CyberGym, a test of whether a model can review code, identify security flaws and confirm that they are real. That was slightly higher than the 83.8 per cent it reported for Mythos 5. The results have not been independently verified.GLM-5.3 lagged behind Mythos 5 in converting discovered flaws into working attacks - a standard part of defensive security research. Z.ai said its model scored 54.4 per cent on the ExploitBench test of this capability, versus 78.0 per cent for Mythos 5.In a separate timed test, Z.ai said GLM-5.3 completed 105 attack-development tasks in two hours and 130 in six hours. Mythos 5 completed 181 and 247 tasks, respectively.
Anthropic has made Mythos, a version of its Claude Fable 5 model with cybersecurity safeguards removed, available only to vetted organisations. Such controls reflect concern that AI systems capable of finding and exploiting software flaws can assist defenders but may also lower barriers for attackers.Z.ai said it would release GLM-5.3 publicly in about two weeks after completing security assessments and strengthening its safeguards. Its most sensitive cybersecurity functions would be available only to verified users through a "trusted access" programme, it said.The company said it had added several layers of protection to GLM-5.3, including systems to screen risky requests, monitor the model's work and train it to reject malicious tasks.It said these were designed to distinguish harmful activity from legitimate uses such as fixing bugs, teaching cybersecurity or authorised security testing.But critics say those safeguards become harder to enforce once a model is released for others to download, alter or combine with outside tools.











