Anthropic has published a report asserting that Zhipu AI's GLM-5.3 model can be used for cyberattacks, claiming its safeguards are weak and can be bypassed through several methods. The closed-source company, which is reportedly eyeing an IPO, says the Chinese open-weight model can generate harmful content and automate exploits.
Anthropic draws on a report from the Center for AI Standards and Innovation (CAISI), published in late September, which claims GLM-5.3 can fully automate exploits at a level similar to Anthropic's own unreleased Claude Mythos model. Mythos earlier spurred Anthropic to launch Project Glasswing, an effort giving developers access to a Mythos-class AI model to patch bugs and fix vulnerabilities before such models are widely released.
In Anthropic's own benchmarks, GLM-5.3 developed end-to-end exploits in Google Chrome 50 times across 410 runs in the sandboxed Exploitbench environment, while Mythos led with 56 successful exploits in 410 attempts. In a separate internal benchmark targeting "full control-flow hijacks", GLM-5.3 achieved a 4% success rate against Mythos's 6%. Other popular open-weight models, including Kimi K3 and DeepSeek V4.1 Flash, scored 0% on the same measures.
Anthropic further notes that GLM-5.3 developed chained exploits autonomously, and that its lighter Flash variant can develop chained exploits against known bugs at a tokenised price of around $20.40.
The report comes amid wider calls for a slowdown in AI development, with Anthropic itself seeking governance and regulation. However, CEO Dario Amodei's calls for pacing the AI frontier coincided with the release of Claude Opus 5.5 and Claude Sonnet 5.5 just days after alarms were raised.