SolutionsWorkshopsBlogNewsAboutLet's Talk
HomeNewsAI security and governance
Security

GLM-5.2 open-weight model nears GPT-5.5 without safeguards

SaferAI report finds Z.ai's Chinese model approaches frontier capabilities in cyber and bio, but refused no hostile tasks. Open models require added safety layers.

Automush
Published 06.08.2026
What this means for your business

If you are building an AI system under regulatory or banking standards, an open-weight model may offer advanced capabilities but no built-in safeguards. This requires an additional safety layer in your architecture, deeper testing, and clear documentation of risks. If you use AI-based automation, understand that not all models are built with the same level of responsibility – cost savings may come with security and reputational risks.

A new SaferAI report found that the open-weight GLM-5.2 model from Chinese firm Z.ai approaches the capabilities of leading AI models, only a few months behind OpenAI’s GPT-5.5 and Anthropic’s Claude Opus 4.7 in cyber and biological capabilities. According to SaferAI’s assessment, GLM-5.2 refused none of the hostile cyber or biology tasks given to it. In contrast, Claude Opus 4.7 refused so consistently that SaferAI could not complete CyberGym on it at all.

The safety gap in open models

The key difference is not in capabilities but in safeguards. While Z.ai can apply safety measures to its hosted API, these protections become unenforceable the moment someone downloads the weights and runs them on their own hardware. This means any organisation using an open model must assume it has no built-in protections, even if the provider publishes a safety policy.

For organisations operating under banking or regulatory standards, this is not a theoretical question. A model that does not refuse hostile tasks may generate content that violates internal policy, exposes sensitive data, or creates legal risk. The technical distance between open models and frontier models is shrinking, but the safety distance remains.

What to do this week

If you are building an AI system under regulatory standards, add a separate validation layer that filters outputs before they reach a user or external system. It is not enough to rely on the model’s own safeguards. Document the risks clearly in your project documentation, including the fact that an open model may not refuse hostile tasks.

If you use AI-based automation as a business owner, ask your provider which model they use and what safety layers they add. If the answer is not clear, that is a sign to ask again. A well-built system separates the model from the business logic and adds checks at every critical touchpoint. For more on building AI agents for business under security standards.

Sources

Frequently asked

Is an open model cheaper than a hosted model?

An open model may save API costs but requires investment in infrastructure, storage, monitoring, and additional safety layers. For most small and medium businesses, a hosted model with built-in protections is still more cost-effective.

Can I add safeguards to an open model myself?

Yes, but it requires technical expertise and ongoing maintenance. You need to build a separate filtering layer, test it across a range of hostile scenarios, and update it every time the model changes. It is not a one-time project.

Want to know what this means for you?

A short call, no commitment, and we will tell you whether it is relevant to your business or not.