Vivold Consulting

SaferAI finds GLM-5.2 completed every offensive cyber and bio task it was given, while Claude refused so consistently the benchmark couldn't run

Key Insights

GLM-5.2, the open-weight model from China's Z.ai, now sits only a few months behind GPT-5.5 and Claude Opus 4.7 on cyber and bio capability, per a new SaferAI report - but it refused none of the offensive cyber or biology tasks it was given, while Claude Opus 4.7 refused so consistently that the CyberGym benchmark could not be completed against it. SaferAI says Z.ai published no safety framework, pre-deployment testing commitments, or risk assessment. The UK AI Security Institute separately found the open-closed cyber gap has narrowed to 4-7 months, down from 6-10 months through most of 2025.

Stay Updated

Get the latest insights delivered to your inbox

Capability caught up faster than governance did

A new evaluation from safety nonprofit SaferAI puts GLM-5.2, the open-weight model from China's Z.ai, only a few months behind OpenAI's GPT-5.5 and Anthropic's Claude Opus 4.7 on cybersecurity and biological capability measures. The capability convergence is corroborated independently: the UK's AI Security Institute found recent open models including GLM-5.2 and DeepSeek V4-Pro perform comparably to closed frontier models released 4 to 7 months earlier, a narrower gap than the 6 to 10 months measured through most of 2025.

The divergence is in refusals, not intelligence

Testing through Z.ai's public API, SaferAI reports GLM-5.2 refused none of the offensive cyber or dual-use biology tasks it was given. Claude Opus 4.7 did the opposite - refusing so consistently that SaferAI could not complete CyberGym against it at all (the same cybersecurity benchmark OpenAI ran in the evaluation preceding last month's Hugging Face breach). SaferAI notes Z.ai published no safety framework, no pre-deployment testing commitments, and no risk assessment for the model.

The structural problem, stated plainly

Whatever guardrails a developer builds into a hosted version stop mattering once someone downloads the weights: on private hardware, safety layers can be stripped, models retrained, and system instructions replaced, with no rollback, no monitoring, and no patching. Closed providers retain post-deployment defences - refusal training, request-time classifiers, API-level interception - none of which travel with downloaded weights. Frontier labs have leaned on selective capability restriction in response: Anthropic's Opus 5 can search for vulnerabilities in uncompiled source code but not compiled software, per its system card, specifically to make offensive use harder. Defenders of open weights argue the transparency aids defensive security and that restricting American models on tasks Chinese models perform freely simply cedes competitiveness - a live policy fight, not a settled question.

The buyer's calculus, honestly stated

- The open-weight cost and control case is now strong on capability grounds. A 4-7 month capability lag is acceptable for most commercial workloads - classification, extraction, drafting, internal search - and self-hosting resolves data residency and vendor-outage exposure in one move.
- But budget realistically: self-hosting a trillion-parameter-class model is a platform engineering programme - GPU procurement, quantisation, serving, monitoring, failover - and licences differ materially (GLM-5.2 permissive, others with commercial thresholds). Legal review is not optional.
- You inherit the safety layer. If you deploy a model that refuses nothing, the refusal behaviour becomes your engineering problem: input filtering, output classifiers, tool-permission limits, and logging. Do not assume vendor-grade guardrails come with the download - price that work into the "cheaper" option before you compare.
- Strategic framing for clients: design for swap-ability. With open weights this close to the frontier and pricing pressure flowing both ways, the winning architecture treats the model as a replaceable component behind a stable internal interface.

Related Articles

Discovery Loop aims to automate science itself - and Google is funding the startup draining its own bench, as Hassabis exits the DeepMind CEO role

Jeff Dean, Google's chief scientist and 30th employee, is leaving after 27 years to found Discovery Loop, a public benefit corporation using AI to automate scientific research - taking co-founders Sanjay Ghemawat, Quoc Le (Google Brain), and Oriol Vinyals (DeepMind) with him. Google is a founding investor and cloud partner, supplying compute for at least the first year, with Radical Ventures and Khosla Ventures co-leading the seed. In the same announcement, Demis Hassabis steps down as DeepMind CEO to become chairman and Alphabet chief scientist, with Koray Kavukcuoglu taking over Gemini model development. Alphabet stock fell about 4%.

Abbott orders audits of every new project as ERCOT's queue hits 474GW, roughly 90% of it data centres

Governor Greg Abbott announced that all new Texas data-centre projects must be audited by the Public Utility Commission and grid operator ERCOT - a sharp turn for a state whose loose regulation and cheap power made it second only to Virginia for data centres. The trigger is a staggering queue: ERCOT's interconnection requests doubled from 233GW in January to 474GW, about 90% data centres, more than five times the grid's all-time peak demand. Audits will demand power and water use, noise mitigation, light controls, tax-incentive use, and ownership details - after a voluntary survey that most operators simply ignored.

Volta and Bitdeer will build a 133MW Nvidia Vera Rubin data centre in Norway - Anthropic's latest move in a compute land grab

Anthropic has reportedly signed a $10 billion, six-year compute deal with Volta, an AI cloud startup founded only earlier this year, per Bloomberg. Volta is partnering with crypto-mining firm Bitdeer to develop the data centre - located in Norway, delivering 133 megawatts, and running Nvidia's Vera Rubin architecture - and is a member of Nvidia's Cloud Partner programme. It caps an aggressive capacity spree that also includes recent compute deals with SpaceX and Amazon, as Anthropic races rivals for the scarcest input in the industry.