Researchers say Z.ai's GLM-5.2 matches latest US models at finding security bugs, as critics question the US' lax approach in restricting Chinese open models
Wall Street Journal
Context & Ripple Effects
Z.ai has moved through successive open-model releases, from GLM-4.5’s lower-cost positioning to GLM-5.1’s claimed software-engineering benchmark strength under an MIT license. The new research extends that arc into security-bug discovery, a more sensitive capability category.
The story also lands after evidence that Chinese-made open models had surpassed US developers’ share of downloads, alongside earlier concern about the concentration of leading open models from China. That makes model-security capability relevant both to adoption and to US policy debate.
First-order effects
The research gives Z.ai a stronger basis to position GLM-5.2 alongside leading US models for vulnerability-finding work, rather than chiefly on general coding benchmarks or cost.
Criticism of the US approach to Chinese open models gains a concrete security-capability case, increasing scrutiny of whether widely available model weights should be treated differently from ordinary software releases.
Second-order effects
Security teams and developers evaluating open models may broaden their testing beyond US-origin options, putting more pressure on US model providers to demonstrate comparable security-analysis performance and deployment safeguards.
A sharper policy debate could raise compliance and procurement questions for organizations using Chinese open models, even where the models’ open availability makes restrictions difficult to apply cleanly.
Third-order effects
If open Chinese models continue to reach frontier-level performance in cyber-relevant tasks, AI competition will increasingly turn on governance of model distribution and downstream use, not only on who leads benchmark rankings.
The tension between the benefits of broadly available coding and security tools and concerns over misuse is likely to drive more differentiated rules or controls around high-capability open models, though the corpus does not establish what form they would take.
The trend: Open Chinese AI models are becoming competitive in increasingly consequential technical workloads, forcing the US debate to reconcile open-model adoption with security governance.
A year ago, President Trump declared that America was in a global AI race and that the way to win it was to be pro-innovation, pro-infrastructure, pro-energy, and pro-export. President Trump was exactly right; we deviate from that strategy at our peril. [image]
It should be 100% obvious that there will soon be mythos level models on cyber security that are open and available to anyone. As a byproduct of this, alternative tech stacks will emerge that also drive more economic value and control away from the US's tech stack. This is what…
Parsing through the WSJ article entitled “China Has Matched Anthropic in Cybersecurity, Resetting AI Race”: 1. Contrary to the article's spooky title, it doesn't even attempt to claim that GLM-5.2 has matched Mythos in cybersecurity capabilities. The only substantive claim in [im…
Many smart people/AI insiders are saying GLM-5.2 is the first Chinese AI model to match and often beat the American big lab public AI models with no compromises. Incredible timing given current events.
Cosigned, and it's also ironic given WSJ's China hawk demeanor that the only source here on the claim in the headline is a Chinese company https://x.com/...
There's a big misconception about how GLM 5.2 was trained. Yes, they distilled Claude and GPT 5.5 — but distillation is not how they matched Opus quality. Distillation only fixed the cold start problem in RL. RLing an agentic coding model isn't rocket science. In simplified t…
Supposedly, “a new model from” from zAI is said to be at least as strong as Fable5 in cybersecurity-related aspects. I did some research and only came across a Wall Street Journal article, which, however, does not refer to a new model, but to GLM 5.2 as a relatively new model th…
maybe it's true, maybe it's not but the idea you can put the genie back in the bottle is going to cost us in defensive cybersecurity. is already costing us, actually.
Mythos / Sol cybersecurity capabilities are equally useful in an offensive as well a defensive capacity. If adversaries get ahold of an equivalent offensive capability, it poses a serious threat to US companies that remain unaware of latent vulnerabilities. In the meantime, I
The #1 article on the Wall Street Journal claims that GLM-5.2 matches Mythos at finding security bugs. This is almost certainly completely incorrect. I am willing to put up $100 for $1 that GLM-5.2 will score below Mythos and GPT-5.5 at UK AISI's cyber range. WSJ has been... [ima…
The irony of the open source AI models coming from a closed society, while the closed models come from the open democratic nation, is not talked about enough
The two best AI models in America are sitting in a drawer right now. David Sacks explained why this week on All-In, from inside the administration. China just dropped GLM 5.2. Open weight, MIT license, free to download anywhere. It beats GPT 5.5 on coding and trails Claude [video…
How good is GLM-5.2? GLM-5.2 (Max) ranks higher than Claude Opus 4.8 (Thinking) on Code Arena, where Frontend coding tasks are being voted on by the community. Below in thread are 10 examples of the same prompts given to both models and completed in a single shot.
With the new ARC-AGI results from GLM 5.2, together with the WeirdML results, we now have 8 private benchmark datapoints on the gaps closed by GLM 5.2, for an average of 8.1 months. This is consistent with the trend in my (pre GLM 5.2) analysis, but is some evidence against the […
@pmarca internal benchmarking on using GLM 5.2 instead of Opus 4.8 for updating our internal mortgage servicing process knowledge base Opus and GPT judge GLM to be a bit better at less than half the cost [image]
Anthropic says the US government is allowing Mythos 5 to be redeployed to critical infrastructure operators, and is working to restore general access to Fable 5
On the bright side, maybe we can stop debating hypotheticals and see if this stuff has the real-world effects people like myself have been worried about. — www.wsj.com/tech/ai/chin...