tech

Open-weight AI models are catching up to the frontier. The safety gap remains.

A new SaferAI report finds Z.ai's open-weight GLM-5.2 approaches frontier AI capabilities while lacking key safety mitigations, renewing concerns that powerful open models could outpace governance and safeguards.

Open-weight AI models are catching up to the frontier. The safety gap remains.

TL;DR

  • GLM-5.2, an open-weight AI model from China's Z.ai, is closely matching the cyber and bio capabilities of leading AI systems like OpenAI's GPT-5.5 and Anthropic's Claude Opus 4.7.
  • A report by SaferAI found that GLM-5.2 refused none of the offensive cyber or dual-use biology tasks assigned, unlike closed models that have built-in refusal mechanisms.
  • The increasing capability of open-weight models raises concerns about potential misuse by attackers, as safeguards are unenforceable once the model weights are downloaded.
  • Frontier AI developers typically rely on safeguards like classifiers and refusal training, but these are ineffective on open-weight models.
  • Techniques like pre-training data filtering are suggested to mitigate risks, but are less practical for cybersecurity applications.
  • Chinese AI policy historically focuses on political content and social stability rather than catastrophic AI risks, though leaders acknowledge the need for human control over AI.
  • Advocates of open-weight AI argue they are crucial for cybersecurity defense and preparation for future threats, a point contested by safety advocates who believe dangerous capabilities should not be easily accessible.