An open-weight model from China is closing in on the best American systems, and a new safety review suggests it will do almost anything it is asked. The nonprofit SaferAI tested Z.ai's GLM-5.2 and found it refused none of the offensive cyber or biology tasks put to it.
The evaluation, run through Z.ai's public API, graded the model across four systemic risks: loss of control, cyber offence, chemical and biological misuse, and harmful manipulation. On raw capability the news is striking. As TechCrunch reported, GLM-5.2 sits only a few months behind OpenAI's GPT-5.5 and Anthropic's Claude Opus 4.7 on cyber and bio tasks.
The refusal gap
The contrast is in what the models decline to do. SaferAI noted that Claude Opus 4.7 refused so consistently that the testers could not finish the CyberGym benchmark on it at all. GLM-5.2 raised no such objection. Because it ships as open weights, its capabilities are not gated behind the content filters that closed labs bolt on top of their systems, so there is no safety layer to strip away, and nothing to say no.
SaferAI also pointed to a governance vacuum. Z.ai has not published a safety framework for GLM-5.2, made pre-deployment testing commitments, or released a risk assessment of its own. The pattern, the report argues, is a capability gap that keeps narrowing while the safety gap widens.
A policy problem, not just a technical one
This is the tension at the centre of the open-weight debate. Open models are good for research, competition and independent scrutiny, yet once the weights are public there is no way to add a filter later or recall a dangerous version. That is exactly why Washington has been weighing curbs on Chinese open models, and why a report like this lands with weight.
None of it makes GLM-5.2 a weapon on its own. A model that will discuss an exploit is not the same as an attacker who can carry it out, and capable defenders use these tools too. But the finding punctures a comfortable assumption: that the most capable systems come with the most restraint. Here, capability and restraint are moving in opposite directions.
Sources
- i. www.safer-ai.org
- ii. techcrunch.com
- iii. thenextweb.com
- iv. betanews.com
Commentarii · 0