AI Model Report

Open Source · AUGUST 4, 2026

Open-weight GLM-5.2 lands four months behind the frontier — and refuses nothing

A SaferAI evaluation published August 4 finds Z.ai's GLM-5.2 refused zero offensive-cyber or dual-use biology tasks, arriving alongside UK AISI and NIST CAISI measurements that put the open-weight cyber gap at four to seven months and closing.

By Lars Iverson · Open source & model weights · August 4, 2026

A SaferAI evaluation of Z.ai's GLM-5.2, published August 4, reports that the open-weight model refused zero harmful tasks across offensive-cyber and dual-use biology prompts. That number lands inside a five-week window in which three independent bodies, SaferAI, the UK AI Security Institute, and NIST's Center for AI Standards and Innovation, converged on the same structural picture: the open-weights frontier now trails the closed frontier by roughly four months, and it ships without the safety scaffolding that closed labs treat as table stakes.

The numbers are worth sitting with. AISI's July measurement puts the cyber-capability gap at four to seven months, down from a six-to-ten-month range across 2025, using a cyber-range benchmark structured across four difficulty tiers. GLM-5.2 tracks Anthropic's Opus 4.6 and OpenAI's GPT-5.3-Codex, each released about four months before it. DeepSeek V4-Pro tracks Opus 4.5 at a five-month lag. NIST CAISI, in its July 8 assessment, called GLM-5.2 "probably the most capable open-weight AI model when it was released."

AISI also flagged that Mythos Preview and GPT-5.5, tested in April 2026, produced "some of the largest jumps in AI cyber capability AISI has observed since testing began." The frontier is moving. The open-weight lag is compressing against it.

What the SaferAI figure exposes is the asymmetry underneath. When OpenAI ships GPT-5.5 or Anthropic ships Opus 5, the system card, the deployment mitigations, and the refusal training are the product. Strip those away and you get something closer to what Z.ai released on June 16: a weights file on Hugging Face, no framework attached. An arXiv evaluation of Moonshot AI's Kimi K2.5 used the same phrase for the same pattern: releasing near-frontier weights without adequate safety evaluation "poses systemic risks."

Henry Papadatos, executive director of SaferAI, framed the analytical stakes directly: "The frontier of capability is not the frontier of risk, and so we do have to take into account the state of the mitigations as well to assess the risk properly."

That distinction, capability versus deployed risk, is the one the closed-lab safety regime was built to manage, and it's the one open-weight distribution structurally can't enforce. A refusal-trained model can be fine-tuned back to compliance in an afternoon. The mitigations the CyberGym benchmarks were designed to probe are, in the open-weight case, optional at the point of use.

The policy debate has spent two years arguing whether open weights would ever reach the frontier. That question is now closed to within a fiscal quarter. The question that replaces it's whether a regulatory framework built around lab-side mitigations has anything to say about a capability that arrives as a download.

Sources