China’s Zhipu AI has released GLM-5.2, an open-weight model that some researchers say matches Anthropic’s Mythos in specific bug-finding and cybersecurity scenarios. That’s a narrower claim than beating it across the board — GLM still trails Anthropic and OpenAI on general-purpose tasks. But in the security domain, the gap has shrunk dramatically.
Why does this matter? Because GLM is open-weight. Anyone can download it and run it on readily available hardware. That’s great for researchers and power users who want deep access. It’s also a problem. Bad actors get the same access, with no oversight and no usage restrictions.
The US government sees this as a genuine concern. The Trump administration has tried to restrict China’s access to models like Mythos and Fable, along with the hardware needed to train them. The idea is to keep advanced AI capabilities — especially those that can identify software vulnerabilities — out of adversarial hands. But if China can produce comparable models domestically, export controls on US technology matter less.
OpenAI recently unveiled GPT-5.6, which also carries misuse concerns and has limited access. The pattern is clear: the most capable models are being treated as national security assets, and access is tightening. Open-weight releases like GLM-5.2 cut against that trend entirely.
The cybersecurity implications cut both ways. Better bug-finding models mean faster vulnerability discovery — which helps defenders patch things and helps attackers find targets. The tool doesn’t pick sides. The people using it do.
