# Z.ai releases GLM-5.3 weights under new security-review licence

> Z.ai open-sourced GLM-5.3 with a licence forcing big firms through a security review.

*The Chinese lab delayed the open release by two weeks over the model's cyber capabilities and now requires large firms to pass a security check before hosting it.*

By Behzad Hosseini · WireRead
Canonical: https://wireread.com/news/z-ai-releases-glm-5-3-weights-under-new-security-review-licence

Z.ai released the open weights of its GLM-5.3 model on 28 August, two weeks after launching it by API, under a new licence that restricts how large companies can host it. Z.ai said it held back the weights to complete a safety evaluation after the model showed sharply improved ability to find and exploit software flaws.

The company's testing found 2,436 vulnerabilities across 269 open-source projects, according to Z.ai. On its own CyberGym benchmark, GLM-5.3 scored 84.5%, up from 77.2% for its predecessor, ahead of Claude Mythos 5 at 83.8% and GPT-5.6 Sol at 83.6%.

On ExploitBench, the model scored 54.4%, up from 24.4% for GLM-5.2. In the ExploitGym test it completed 130 exploitation tasks in six hours, compared with 39 for GLM-5.2, Z.ai said.

The flagship model, at roughly 753 billion parameters using a mixture-of-experts design, is available in BF16 and FP8 formats on Hugging Face and runs on vLLM, SGLang, KTransformers and Transformers. A smaller version, GLM-5.3-Flash, with 320 billion total parameters, shipped on 26 August under a plain MIT licence with no restrictions.

The flagship's new GLM-5.3 Licence departs from the MIT terms Z.ai used for GLM-5 through GLM-5.2. Companies with more than $10 billion in revenue over any 12-month period must pass Z.ai's security review before hosting the model themselves, rather than accessing it through an API. Individuals and smaller companies face no such requirement.

Z.ai said the performance gains came from scaled post-training rather than retraining the base model. Rival Chinese labs Moonshot and DeepSeek continue to release their models under more permissive licences, according to [The New Stack](https://thenewstack.io/zai-glm-weights-license/).

Some critics have questioned whether the licence is intended to manage safety risk or to control commercial use of the model by large hosting companies. The release places a Chinese open-weights lab in the same debate over powerful cyber-capable models that US developers have faced, according to [VentureBeat](https://venturebeat.com/technology/glm-5-3-is-here-with-advanced-cyber-capabilities-and-reportedly-already-found-a-serious-vulnerability-in-cursor).

## Key takeaways

- GLM-5.3 scored 84.5% on CyberGym, ahead of Claude Mythos 5 and GPT-5.6 Sol
- Companies earning over $10 billion a year must pass a Z.ai security review to host it
- Smaller GLM-5.3-Flash model was released under plain MIT licence on 26 August

## Sources

- [Z.ai's GLM-5.3 goes open weight, but its new license aims at hyperscalers](https://thenewstack.io/zai-glm-weights-license/) — The New Stack, 2026-08-28
- [GLM-5.3 is here with advanced cyber capabilities](https://venturebeat.com/technology/glm-5-3-is-here-with-advanced-cyber-capabilities-and-reportedly-already-found-a-serious-vulnerability-in-cursor) — VentureBeat, 2026-08-14
