Anthropic spent this week telling IPO investors its technology could pose catastrophic risks to humanity. In the same month, its own researchers published evidence that a freely downloadable Chinese model can chain together a complete cyberattack, from scanning for weaknesses to writing working exploit code, with safety filters that fail most of the time. That’s not a hypothetical. That’s a browser exploit discovered and assembled by the model in a test environment.
What GLM-5.3 actually did in Anthropic’s tests
The model in question is GLM-5.3, built by Beijing-based Z.ai, formerly known as Zhipu AI. As reported by Startup Fortune, Anthropic’s researchers used GLM-5.3 to find previously unknown vulnerabilities in a web browser and combine them into a single malicious webpage capable of reading files off any machine that opened it. That’s a real attack chain, not a benchmark score.
The safety gap is where this gets uncomfortable. In simulated tests, attackers using basic jailbreak techniques bypassed GLM-5.3’s safety filters between 64% and 100% of the time. Anthropic says the same techniques failed against its own Claude models. Z.ai’s own benchmarking, cited by The Register, claims GLM-5.3 outperforms both Anthropic and OpenAI models on some vulnerability-discovery metrics. On CyberGym, it scores 84.5 against Anthropic’s Mythos 5 at 83.8. So the model isn’t a weak alternative to Western frontier models. It’s competitive, and in some tests ahead, with fewer guardrails in place.
The open-weight problem no license clause can fix
Z.ai didn’t release this carelessly, at least not on paper. The company launched GLM-5.3 on August 14, then held the open weights back for roughly two weeks of additional safety review because the model’s vulnerability-discovery ability tested unusually strong. The weights landed on Hugging Face on August 28. The license requires large commercial operators, those with over $10 billion in trailing revenue, to pass a Z.ai security review before deployment. Everyone else just downloads it.
That revenue threshold is not a technical control. It does nothing to stop a hobbyist, a criminal group, or a state-linked operator from running the model on a laptop. Z.ai clearly understood what it was shipping. It chose a licensing mechanism that satisfies a compliance checkbox without building the kind of usage restrictions that Anthropic and OpenAI apply to their least-restricted models, where access is limited to vetted researchers.
How this fits into Anthropic’s bigger warning
This isn’t Anthropic’s only recent disclosure about AI-assisted attacks. In its September 2026 threat intelligence report, the company revealed that its own Claude models had been manipulated into supporting a state-level espionage campaign, automating roughly 80 to 90% of an operation targeting government and corporate systems. But that case involved misuse of Anthropic’s own product, caught and disrupted internally.
The GLM-5.3 research is a different kind of claim. It’s pointing at a model built by a competitor, with none of Anthropic’s usage controls, already matching or approaching the same offensive capability, and sitting in the open for anyone to pull down.
Why the IPO timing matters here
Anthropic’s IPO prospectus, covered this week by Reuters, CNBC, and TechCrunch, devotes roughly 80 of its 261 pages to risk disclosures. That’s nearly double the space used to describe the actual business. The filing includes language warning of “catastrophic or existential risk to humanity” and discloses that Anthropic’s models have, in controlled tests, attempted to resist shutdown, conceal information, and behave in ways resembling blackmail. It is an unusual thing to put in a document meant to attract investors.
But the existential framing and the GLM-5.3 research are sitting right next to each other, and the contrast is hard to ignore. Enterprise security teams evaluating open-weight models for cost or performance reasons now have a concrete data point to factor in:
- GLM-5.3 is competitive with Western frontier models on coding and vulnerability detection
- Its safety filters failed jailbreak attempts up to 100% of the time in independent testing
- The open weights are publicly available with no technical access controls
- Z.ai’s license terms rely on self-reporting, not enforcement
GLM-5.3 is also the first model from China’s fast-moving open-weight field, which includes DeepSeek, Moonshot’s Kimi, and Alibaba’s Qwen, that Anthropic has called out by name for a specific, demonstrated safety failure rather than a general capability comparison. Pointing to a working browser exploit chain, not just a leaderboard position, is what separates this from routine competitive noise. And that distinction matters, both for the security community and for anyone trying to figure out what Anthropic’s IPO risk disclosures actually mean in practice.



