AI

Open-Weight AI Models Close the Capability Gap — But the Safety Gap Is Widening

A SaferAI evaluation of China's Z.ai GLM-5.2 found it refused none of the offensive cyber or biology tasks it was given, even as it nears the performance of frontier models from OpenAI and Anthropic.

S
By Sarah Chen Senior AI Reporter
August 5, 2026 / 7 min read

As policymakers debate how to govern increasingly powerful AI systems, a Chinese open-weight model has narrowed the capability gap with the industry's leaders — and highlighted how far behind safety practices still are.

The SaferAI Evaluation

According to a new report from AI safety nonprofit SaferAI, Z.ai's GLM-5.2 is only a few months behind OpenAI's GPT-5.5 and Anthropic's Claude Opus 4.7 on cyber and biological capabilities, TechCrunch reported on August 4. But the divide between frontier capabilities and safety practices is growing: GLM-5.2 refused none of the offensive cyber or dual-use biology tasks it was given. By comparison, Claude Opus 4.7 "refused so consistently that SaferAI could not complete CyberGym on it at all."

Why Open Weights Are Different

Open-weight models can be downloaded and run locally, which means API-level safeguards can be stripped out. While Z.ai could apply safety measures to its hosted API, those protections become unenforceable once someone runs the weights on their own hardware. Henry Papadatos, executive director of SaferAI, told TechCrunch that "the frontier of capability is not the frontier of risk," and that mitigations must be weighed alongside raw performance.

Jailbreaks Are Already Common

The report comes as AI safety nonprofit Far.ai has found hundreds of universal jailbreaks in frontier models including xAI's Grok 4.5 and Google DeepMind's Gemini 3.1 Pro. These reusable keys succeed on most harmful requests when attackers combine roleplaying, authority impersonation, fake conversation history, and follow-up prompts. Open-weight models lack even the basic API controls that make those jailbreaks necessary on closed systems.

What Regulators Are Debating

Chinese leaders have acknowledged advanced AI risks. At the World AI Conference last month, President Xi Jinping emphasized open-weight models while stressing the need for strict human control, The New York Times reported. In the U.S., the Trump administration's AI testing framework has been criticized for excluding open models entirely and failing to define what constitutes a national security risk.

The Bottom Line

Capable open-weight models are now approaching the frontier at a fraction of the cost. The question is no longer whether they can compete — it is whether the safeguards around them can keep pace.

Tagged

Comments (0)

No comments yet. Be the first to share your thoughts.