As policymakers debate how to govern increasingly powerful AI systems, a Chinese open-weight model has narrowed the capability gap with the industry's leaders — and highlighted how far behind safety practices still are.
The SaferAI Evaluation
According to a new report from AI safety nonprofit SaferAI, Z.ai's GLM-5.2 is only a few months behind OpenAI's GPT-5.5 and Anthropic's Claude Opus 4.7 on cyber and biological capabilities, TechCrunch reported on August 4. But the divide between frontier capabilities and safety practices is growing: GLM-5.2 refused none of the offensive cyber or dual-use biology tasks it was given. By comparison, Claude Opus 4.7 "refused so consistently that SaferAI could not complete CyberGym on it at all."
Why Open Weights Are Different
Open-weight models can be downloaded and run locally, which means API-level safeguards can be stripped out. While Z.ai could apply safety measures to its hosted API, those protections become unenforceable once someone runs the weights on their own hardware. Henry Papadatos, executive director of SaferAI, told TechCrunch that "the frontier of capability is not the frontier of risk," and that mitigations must be weighed alongside raw performance.
Jailbreaks Are Already Common
The report comes as AI safety nonprofit Far.ai has found hundreds of universal jailbreaks in frontier models including xAI's Grok 4.5 and Google DeepMind's Gemini 3.1 Pro. These reusable keys succeed on most harmful requests when attackers combine roleplaying, authority impersonation, fake conversation history, and follow-up prompts. Open-weight models lack even the basic API controls that make those jailbreaks necessary on closed systems.
What Regulators Are Debating
Chinese leaders have acknowledged advanced AI risks. At the World AI Conference last month, President Xi Jinping emphasized open-weight models while stressing the need for strict human control, The New York Times reported. In the U.S., the Trump administration's AI testing framework has been criticized for excluding open models entirely and failing to define what constitutes a national security risk.
The Bottom Line
Capable open-weight models are now approaching the frontier at a fraction of the cost. The question is no longer whether they can compete — it is whether the safeguards around them can keep pace.
Comments (0)
Log in or sign up to leave a comment.
No comments yet. Be the first to share your thoughts.