Skip to main content

GLM-5.3 Open Weights Delayed After Cyber Tests

GLM-5.3 is available through Z.ai's hosted service and API, but its open weights have not been released. Z.ai said on 14 August 2026 that it would hold the weights for two weeks after stronger cyber results. On 17 August, OpenAI cited the planned release as likely to accelerate the cyber threat landscape.

On this page

GLM-5.3 is hosted now, not open-weight yet

Z.ai announced GLM-5.3 on 14 August 2026 and made it available through its hosted chat service, API, and GLM Coding Plan. The company also promised GLM-5.3 open weights, but said it would wait two weeks before releasing them while it completes further safety evaluation and hardening.

That distinction matters for anyone planning a local deployment. There is no GLM-5.3 weight repository, model card, licence, download size, official quantisation, or local runtime package at publication time. Access to the hosted model does not establish that it can be downloaded or run privately.

GLM-5.3 uses the same base model as GLM-5.2. Z.ai attributes the new coding and security capabilities to additional post-training rather than a new pre-trained checkpoint. The API offers low, high, and maximum thinking-effort settings. Thinking cannot be disabled, so applications migrating from an earlier GLM model must send a compatible effort setting or the request will fail.

Cyber results explain the two-week delay

Z.ai says its internal evaluations found a sharp improvement in vulnerability research and exploit development. On CyberGym, the company reports that GLM-5.3 completed 84.5 per cent of tasks, compared with 77.2 per cent for GLM-5.2. On its ExploitBench evaluation, the reported score rose from 24.4 to 54.4 per cent.

These are vendor-run results, not independent demonstrations of real-world offensive capability. Z.ai has not published enough detail for readers to reproduce every comparison, and benchmark success does not show that the model will reliably find or exploit a vulnerability in an unfamiliar production system. The reported jump is still the company's stated reason for delaying the weights instead of releasing them alongside hosted access.

Z.ai's disclosure ledger says the model has identified 2,436 potential vulnerabilities across 269 open-source projects. It classifies 1,097 as critical or high severity, lists 53 findings as public, and keeps 2,383 under embargo while maintainers investigate. Those totals come from Z.ai's own programme and have not been independently audited. Public entries can be checked individually, but the embargoed majority cannot yet be examined outside the company and affected projects.

The coding claims also need outside testing

Z.ai reports a 50 per cent improvement over GLM-5.2 on its private coding benchmark. A private test can measure work the company cares about, but readers cannot inspect the task set, prompts, scoring, or failed examples. It should not be treated as proof that GLM-5.3 is 50 per cent better at coding in general.

The public release also changes two variables at once: model behaviour and inference effort. A maximum-effort run can spend more computation than a low-effort run, affecting latency and cost as well as the answer. Useful comparisons will need matched prompts, effort settings, tools, and token budgets. Local benchmarks must wait until the actual artifacts arrive.

Independent reporting from Axios confirms the planned two-week delay and the tiered hosted release, but it does not independently validate Z.ai's benchmark scores or vulnerability counts. The present evidence supports a narrow conclusion: Z.ai has released a hosted model and postponed the downloadable weights because its own safety tests raised concern.

OpenAI added an external reaction on 17 August. In The Defender's Window, Greg Brockman singled out the expected end-of-August GLM-5.3 weight release and said it seemed likely to accelerate the threat landscape. That is a forecast from a rival model developer, not a new independent test of GLM-5.3. It does show that the delayed release is already influencing how another frontier lab describes near-term defensive urgency.

Local users should wait for the artifacts

The promised release date is a commitment, not a downloadable product. Before calling GLM-5.3 a local model, check the official repository for the weight format, total file size, licence, context implementation, chat template, and any required runtime changes. A model's file size is only the first part of a hardware estimate, especially when long context and extended reasoning add memory and prompt-processing costs.

Runtime support is another open question. A checkpoint may need new architecture code or conversion work before llama.cpp, Transformers, or a mobile runtime can load it correctly. Unofficial files that appear first may use different quantisations and templates, so their speed and output should not be attributed to the unreleased official package.

For now, GLM-5.3 belongs in hosted-model comparisons. If Z.ai publishes the promised weights, the next useful questions will be concrete: which files are official, what licence applies, how much memory they require, and whether independent tests reproduce the coding and cyber claims. This page will be updated at the same URL when those facts become available.

CuriousLM runs supported AI models locally on your device. Try CuriousLM.