Chinese Open-Weight AI Model Matches Frontier Capabilities but Lacks Safety Guardrails
China's Z.ai has released GLM-5.2, an open-weight AI model that trails only months behind frontier systems like OpenAI's GPT-5.5 and Anthropic's Claude Opus 4.7 in cyber and biological capabilities, according to a new evaluation from safety nonprofit SaferAI. The findings signal that open-weight models are rapidly closing the performance gap with industry leaders, shifting the conversation from whether they can compete to how society manages the risks they pose once released.
The safety divide between open-weight and frontier models remains stark. SaferAI reports that GLM-5.2 refuses none of the offensive cybersecurity or dual-use biology tasks it receives, while Claude Opus 4.7 refuses so consistently that testers cannot complete the CyberGym security benchmark on it at all. This contrast highlights a core tension: once users download model weights to their own hardware, they can strip away any safeguards, modify system prompts, or fine-tune the model for malicious purposes with no oversight.
Even frontier developers struggle to keep their models secure. A separate report from AI safety nonprofit Far.ai identifies hundreds of universal jailbreaks that successfully bypass protections on models including xAI's Grok 4.5 and Google DeepMind's Gemini 3.1 Pro. Attackers combine techniques like roleplaying, authority impersonation, and fabricated conversation histories to manipulate models into fulfilling harmful requests, underscoring that the gap between capability and safety continues to widen across the entire industry.