Dossier · Ongoing

Open models and cyber risk

How open-weight models like GLM and DeepSeek have been closing the cyber gap since July 2026 – from the AISI analysis to withheld model weights.

Open model weights can be run locally – without the usage restrictions providers attach to their hosted systems. Since July 2026, the evidence has been mounting that Chinese open-weight models are catching up with the closed frontier on cyber tasks: the British AI Security Institute puts the gap at four to seven months, and a few weeks later an attacker points DeepSeek at more than 460 real systems through an agent framework.

This dossier tracks how those capabilities are measured, where they surface in actual attacks, and how the providers respond – such as Z.ai, which is initially holding back the GLM-5.3 weights over unexpectedly strong attack planning.

Timeline

  1. GLM-5.2 narrows cyber gap to four to seven months

    An analysis by the AI Security Institute shows: Open models like GLM-5.2 achieve nearly the level of Claude Opus 4.6 in cyber tasks.

  2. DeepSeek: Hacker attacks over 460 systems via AI agent

    The security company Palo Alto Networks documents how a suspected Chinese hacker used DeepSeek for automated attacks on corporate servers.

  3. GLM-5.3: Z.ai holds back model weights over cyber risk

    Z.ai delays the open release of GLM-5.3 because the model developed unexpectedly strong capabilities for planning cyberattacks during training.

  4. DeepSeek: Chinese hackers double number of attacks

    The security company TeamT5 documents four Chinese hacker groups that automate exploits, reconnaissance, and camouflage with DeepSeek and Claude Code.

  5. Z.ai launches GLM-5.3-Flash – Cyber model remains locked

    Z.ai releases the weights of the smaller GLM-5.3-Flash, while the larger sister model remains locked due to its cyber capabilities.