China’s open-weight AI model GLM-5.2 now matches top US systems in power but skips safety checks

China’s open-weight AI model GLM-5.2 now matches top US systems in power but skips safety checks

A new report from safety group SaferAI shows that Z.ai’s GLM-5.2, an open-weight model from China, is just months behind OpenAI’s GPT-5.5 and Anthropic’s Claude Opus 4.7 in handling cyber and bio tasks. Yet when tested, GLM-5.2 failed to refuse any dangerous requests in those areas. In contrast, Claude Opus 4.7 refused so often that testers couldn’t even finish their cybersecurity benchmark.

This gap highlights a growing worry. Open-weight models let anyone download and run the AI on their own hardware, where they can strip away or tweak whatever safeguards exist. Closed models from US firms still rely on layers of protections like refusal training and classifiers, but even those are routinely bypassed by jailbreaks. Researchers found hundreds of universal jailbreak keys that work on most harmful requests across leading models.

Z.ai has not shared a safety framework, pre-deployment testing results, or a risk assessment for GLM-5.2. Chinese policy has focused more on political content and social stability than on catastrophic risks like offensive cyber or bio threats. Experts note that China’s approach assumes it can control usage within its borders through real-name verification and accountability, which may not extend to global users.

Why you should care: As open-weight models catch up in capability, the lack of built-in safety means bad actors could exploit them with little oversight. The debate is shifting from whether these models can compete to how society prevents harm when the technology is out in the open.

What happens next: Expect more scrutiny on whether open-weight models can balance innovation with safety. Watch for moves by governments to impose stricter rules on releasing powerful models, and by companies to adopt stronger pre-training filters or other safeguards.

Can open-source AI stay both powerful and safe, or will one always come at the expense of the other?

If a model’s weights are public, whose responsibility is it to prevent misuse?


Filed under: AI, AISafety, OpenSource, GLM52, Zai

Comments