Anthropic report claims Chinese GLM-5.3 model rivals its own Mythos AI at cyber exploits

Report says Zhipu AI's open-weight model can automate attacks with weak safeguards, citing a US standards body's findings

edit
By LineZotpaper
Published
Read Time2 min
Anthropic has released a report claiming that Zhipu AI's GLM-5.3 open-weight model can be used to generate malicious content and automate cyber exploits at a level comparable to its own unreleased Claude Mythos model, citing a US government-aligned standards body as support. The findings arrive as Anthropic pushes for AI governance while releasing new models of its own.

Anthropic has published a report asserting that Zhipu AI's GLM-5.3 model can be used for cyberattacks, claiming its safeguards are weak and can be bypassed through several methods. The closed-source company, which is reportedly eyeing an IPO, says the Chinese open-weight model can generate harmful content and automate exploits.

Anthropic draws on a report from the Center for AI Standards and Innovation (CAISI), published in late September, which claims GLM-5.3 can fully automate exploits at a level similar to Anthropic's own unreleased Claude Mythos model. Mythos earlier spurred Anthropic to launch Project Glasswing, an effort giving developers access to a Mythos-class AI model to patch bugs and fix vulnerabilities before such models are widely released.

In Anthropic's own benchmarks, GLM-5.3 developed end-to-end exploits in Google Chrome 50 times across 410 runs in the sandboxed Exploitbench environment, while Mythos led with 56 successful exploits in 410 attempts. In a separate internal benchmark targeting "full control-flow hijacks", GLM-5.3 achieved a 4% success rate against Mythos's 6%. Other popular open-weight models, including Kimi K3 and DeepSeek V4.1 Flash, scored 0% on the same measures.

Anthropic further notes that GLM-5.3 developed chained exploits autonomously, and that its lighter Flash variant can develop chained exploits against known bugs at a tokenised price of around $20.40.

The report comes amid wider calls for a slowdown in AI development, with Anthropic itself seeking governance and regulation. However, CEO Dario Amodei's calls for pacing the AI frontier coincided with the release of Claude Opus 5.5 and Claude Sonnet 5.5 just days after alarms were raised.

§

Analysis

Why This Matters

  • The report suggests advanced cyber capabilities are no longer confined to a few frontier labs, potentially widening the pool of actors able to conduct automated attacks.
  • Open-weight models can be downloaded and modified, making safeguards hard to enforce once a model is released publicly.
  • The dispute surfaces again the tension between Anthropic's public calls for AI regulation and its own rapid deployment of new models.

Background

Anthropic is a major US AI company known for its Claude family of models. This report is part of a broader, ongoing debate about the risks of open-weight AI models, which are released publicly and can be fine-tuned or stripped of safeguards, versus closed-source models. The claimed capabilities also feed into earlier alarm about Mythos-class models, which Anthropic has said can identify thousands of vulnerabilities across major operating systems and browsers, prompting defensive projects like Glasswing.

Key Perspectives

Anthropic: Argues that GLM-5.3's performance shows advanced cyber capabilities spreading, and that governance and regulation are needed to manage the risk. Its own internal testing places the Chinese model just below its unreleased Mythos model. Zhipu AI (implied): As the developer of an open-weight model, it benefits from a community that values openness and accessibility. Its position would likely be that open-weight models enable research and competition, and that claims about abuse need to be weighed against their legitimate uses. Critics and skeptics: May question Anthropic's motives given it markets its own closed models and has been accused of slowing competitors. Independence of the CAISI report and the methodology of Anthropic's benchmarks could also be scrutinised, along with whether headline percentages translate into real-world capability.

What to Watch

  • Whether Zhipu AI or other open-weight developers respond to the report and alter their safeguard or release practices.
  • Any regulatory response, including from US agencies, prompted by the CAISI assessment.
  • Whether Anthropic proceeds with its reported IPO and how this report factors into its positioning on AI safety.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.