Chinese company Z.ai announced on Friday (the 14th) that its artificial intelligence model GLM-5.3 demonstrated slightly higher scores than Anthropic's Mythos 5 in a test aimed at identifying software vulnerabilities. This result places Chinese technology among AI systems capable of performing complex tasks in the field of cybersecurity.
Within the CyberGym assessment, which measures the ability to analyze code, find errors, and confirm their exploitability, GLM-5.3 scored 84.5% compared to 83.8% for Mythos 5. However, these figures were published by Z.ai itself and have not yet undergone independent verification.
The Chinese model's advantage disappeared at a stage closer to practical attack execution. In the ExploitBench test, the Z.ai model scored 54.4%, while the Anthropic system achieved 78%, indicating that Mythos 5 maintains a significant advantage when the task requires converting identified vulnerabilities into actual exploits.
Z.ai plans to make GLM-5.3 publicly available in about two weeks. Before then, the company claims it will complete security assessments and improve mechanisms designed to prevent malicious use. The most sensitive functions will initially be restricted to users who have passed verification through a trusted access program.
This strategy represents a significant shift for the model the company intends to release openly. The main concern is that systems capable of finding vulnerabilities can also facilitate attacks, especially if their weights can be downloaded, modified, and linked with other tools.
The company states that it has developed various barriers to mitigate this risk. These include filters for potentially dangerous prompts, model activity tracking mechanisms, and specialized training to make the system refuse requests deemed harmful.
According to Z.ai, these protective measures are intended to separate offensive actions from legitimate uses, such as troubleshooting, digital security research, and authorized system audits. Critics point out that some of these controls may lose effectiveness once the model begins to spread freely and can be altered by third parties.
Concerns about model openness became one of the reasons the company cited for establishing a limited access period. The initial launch will be intended for a selected group of partners, followed by an expansion based on a process that Z.ai describes as gradual and responsible.
Gabriel Wagner, an AI governance researcher from Concordia AI, assessed that this decision is significant for the Chinese scenario of open security models. In his opinion, delaying the launch for security considerations is a sign of maturity in managing risks associated with the distribution of AI system weights.
This strategy also draws a parallel with Anthropic's Project Glasswing, which restricts access to Mythos 5 only to pre-assessed organizations. However, in the Chinese case, Z.ai attempts to present the openness of the model as a central part of its offering, rather than a commercial or security vulnerability.
Z.ai argues that cutting-edge digital defense systems should not be concentrated in the hands of a few closed model providers. The company advocates the view that developers of open-source projects and small security teams should also have access to such resources.
As part of this offering, the company announced Open Source Shield—an initiative designed to evaluate certain open-source projects, provide the ability to use the model for defensive purposes, and integrate code auditing features into ZCode, its programming-oriented product.
The performance of GLM-5.3 must also be analyzed in tasks requiring greater duration. In a separate assessment, Z.ai reported that the system completed 105 attack development tasks in two hours and 130 in six hours. Mythos 5 completed 181 and 247 tasks over the same periods.
Anthropic adopted a more restrictive strategy regarding Mythos. The company released a system based on Claude Fable 5 with remote cybersecurity features, exclusively for organizations that have undergone preliminary assessment.
GLM-5.3 was not created solely as a security tool. Z.ai presents it as a general programming model that has undergone additional fine-tuning and reinforcement learning to expand its capabilities in the field of cybersecurity. The company claims it started from the same base as GLM-5.2 and expanded the training using more extensive and diverse task environments.
This move came after the growing popularity of GLM-5.2 among developers from various countries. The previous model gained traction due to its programming and agent capabilities, with users and analysts noting performance close to leading North American systems but at a significantly lower cost.
Competition also includes other Chinese companies. In June, the cybersecurity company 360 stated that its Tulongfeng system achieved equivalent capability to Mythos by combining AI models, security intelligence, and automated tools. This statement, like the figures presented by Z.ai about GLM-5.3, has not been independently verified.
Last month, Hugging Face reported using GLM-5.2 to defend against an intrusion attributed to an OpenAI AI agent. This incident strengthened interest in using Chinese models in defensive operations and showed that the technology was already being applied in real security scenarios.