China’s new AI model GLM-5.2 delivers cybersecurity performance on par with leading U.S. models, prompting experts to warn that its unrestricted local deployment could make sophisticated cyberattacks cheaper and easier to execute.
Chinese startup z.AI, formerly known as Zhipu AI, has released a new open-source AI model called GLM-5.2. According to research conducted by analytics firms Graphistry and Semgrep, the model performs cybersecurity tasks — including software vulnerability detection and security analysis—at a level comparable to leading U.S. models from OpenAI, Google, and Anthropic. The developers also claim operating costs are roughly 50% lower than competing models.
Local Deployment of GLM-5.2 Bypasses Cloud Safety Controls
Unlike commercial AI models from major U.S. vendors, which rely on cloud infrastructure and include built-in safeguards to prevent misuse, GLM-5.2 can run entirely on local hardware. This eliminates oversight by a cloud provider and removes an important layer of security controls.
According to reports from Axios, members of the hacking community are already discussing ways to eliminate the model’s remaining safety restrictions altogether. Security researchers have also demonstrated that relatively simple prompts can persuade the model to ignore its internal safeguards.
Cybersecurity Risks Fuel Geopolitical Competition
Because the model is freely available, cybercriminals can experiment with AI-powered attack techniques without attracting attention. Potential use cases include generating phishing emails and automating the discovery of software vulnerabilities. Capabilities once limited to highly specialized threat actors are becoming accessible to a much broader audience.
Gene Moody, Field CTO at cybersecurity company Action1, believes the development should be viewed in context: “China’s release should not be seen as a shocking breakthrough.” He argues that once a capability has been demonstrated, competitors will inevitably reproduce it.
Moody sees the bigger issue as geopolitical competition rather than China’s technical achievement: “The concern isn’t really that China has produced a competitive cybersecurity model.” Instead, he says AI is rapidly becoming another strategic battleground rather than a tool for collective cyber defense: “AI is quickly evolving into another arena for geopolitical competition instead of collaborative defense.”
The result, he warns, is an escalating digital arms race:
“Each new model is simply another round in an arms race where nobody truly wins.”
Gene Moody, Field CTO at cybersecurity company Action1
For cybersecurity defenders, this means both attackers and defenders will continue gaining access to increasingly capable AI-powered tools.
(ll)