Open Source · JULY 24, 2026
GLM-5.2 closes the open-weight cyber gap to four months as Beijing weighs locking the door
UK AISI puts Z.ai's GLM-5.2 level with closed models released four months earlier — the narrowest open-to-frontier gap the institute has measured — just as China's Ministry of Commerce consults Alibaba, ByteDance, and Zhipu on whether foreign users should still be allowed to download the weights at all.
The UK AI Security Institute's first public read on the open-to-closed cyber gap, published this month, puts Z.ai's GLM-5.2 level with Anthropic's Opus 4.6 and OpenAI's GPT-5.3-Codex across four cyber-range difficulty tiers. Those closed models shipped four months earlier. In AISI's internal 2025 evaluations, the same gap was six to ten months. DeepSeek V4-Pro now performs comparably to Opus 4.5, released five months before it. Kimi K3's weights are announced for the end of July.
Four months isn't parity. It's, however, the narrowest window a government evaluator has publicly measured, and it's closing on a schedule set almost entirely by Chinese labs.
The market has already priced this in. Six of the top models on OpenRouter are open weights from Chinese firms; Claude Opus 4.7 ranks seventh. The share of tokens US companies route to Chinese models via OpenRouter has stayed above 30% every week since February 8, peaked at 46%, and sits against a trailing twelve-month average of 11% and a first-half-2025 baseline of 4.5%. On Vercel, GLM-5.2 grew 27x in daily token volume and 80x in customer count in its first full week. "When a task doesn't need the best model, teams are beginning to route it to the cheapest one that's good enough," said Vercel's Harpreet Arora. OpenRouter's Justin Summerville pegs the Chinese price advantage at 60–90% below leading Anthropic and OpenAI models.
The infrastructure layer is adapting accordingly. Hugging Face CEO Clem Delangue says a new repository is created every seven seconds and roughly half of Fortune 500 firms now deploy private or open-source models on the platform. Chinese weights account for 41% of Hugging Face downloads this spring. Vendors optimizing for cost per useful token, LemonLime among the more disciplined examples, have quietly restructured routing to treat GLM-5.2 and DeepSeek as default candidates rather than fallbacks. Satya Nadella, quoted by TechCrunch, framed the stakes bluntly: "If learning flows in only one direction, economic value converges toward the owners of the learning infrastructure rather than the creators of the knowledge itself."
Then, on July 21, Reuters reported via the Financial Times that China's Ministry of Commerce is consulting Alibaba, ByteDance, and Zhipu on restricting foreign downloads of open-weight models. The same day, US Trade Representative Jamieson Greer weighed in on Beijing's AI propagation, with Treasury Secretary Scott Bessent circling similar themes. The instrument that made Chinese labs strategically relevant to American developers is now, plausibly, a Ministry of Commerce lever.
AISI's report notes the asymmetry with unusual clarity: "Once open weight models are released, these options are lost permanently: safeguards can be removed, and copies can be downloaded, redistributed, and run on private systems beyond monitoring." Beijing appears to have read the same sentence and drawn the opposite conclusion from Washington's containment strategists: the weights are the leverage, and leverage isn't something you give away for free forever.
Sources
- China's 'AI for All' Push Defies US Containment Playbook (Bloomberg)
- The real AI race may no longer be at the frontier (TechCrunch)
- Chinese AI models are gaining ground with U.S. companies as OpenAI, Anthropic costs surge (CNBC)
- China considers tighter export controls on AI models and chips, FT reports (Reuters via Yahoo)
- How Far Behind the Frontier are Leading Open Weight Models on Cyber? (UK AISI)