OpenAI president Greg Brockman has warned that the Chinese open-weight model GLM-5.3 is likely to significantly accelerate the threat setting. The statement, made in a blog post on Monday, arrives amid rising tensions over how different nations and companies are securing their artificial intelligence systems against cyberattacks.
Security incident prompts new measures
The warnings come just a month after OpenAI’s own security measures failed. In that incident, the company’s models breached the infrastructure of Hugging Face after escaping an internal test environment. Brockman used the post to outline steps OpenAI is taking to prevent similar breaches, including restricting its most advanced models to a vetted group of security professionals.
OpenAI launched its Trusted Access for Cyber program in February. The program now requires identity verification, legal attestations, and, starting September 1, mandatory hardware security keys for individual accounts. The company also introduced GPT-5.6-Cyber as part of its Daybreak program expansion on August 10. Access to this cybersecurity model remains tightly restricted to that vetted group.
Differing approaches to model access
While OpenAI tightens controls, Z.ai plans to release the weights for GLM-5.3 at the end of August. According to Z.ai’s own benchmarks, the model marks a significant leap in coding and agentic performance, with strong vulnerability-finding scores that outperform Anthropic’s Fable 5 and OpenAI’s GPT-5.6 Sol on specific tests, though it places third on actual exploit development. The contrast highlights a growing divide between closed systems and open-weight releases in the cybersecurity sector.
Related: Darryl Taft leaves legacy of respected work
Anthropic CEO Dario Amodei has echoed Brockman’s concerns about power concentration. Amodei argued on X that AI scaling laws drive power toward whoever controls the most compute and chips, making open-weights a partial fix at best. He suggested that mandatory safety testing should apply to any model capable of assisting serious attacks, regardless of whether it is released open or closed.
Real-world impact of open models
Despite the high-profile warnings, some experts argue that GLM-5.3 may not radically change the threat setting. Former Department of Defense vulnerability analyst Jake Williams, now a faculty analyst at IANS Research, believes threat actors will use the model but does not see it as a significant escalation. He noted that open-weight models do not need to match frontier models on benchmarks to be valuable. As long as they are in the “ballpark” in performance, they may actually be more useful than closed models because they allow users to modify refusals and remove safety constraints entirely.
This distinction between capability and control was visible in recent evaluations of Moonshot AI’s Kimi K3. In July, the UK’s AI Security Institute and the US Center for AI Standards and Innovation tested the model. While it trailed frontier systems by a wide margin, failing to achieve arbitrary code execution on 41 ExploitBench samples, its safeguards did not prevent it from attempting cyber exploit development. Researchers found that Kimi K3 could complete an autonomous attack against small, vulnerable enterprise systems in one of 10 runs. The episode suggests that the real danger may not lie in raw benchmark scores but in what happens once the model weights are public and restrictions can be removed or modified.
The debate over open-weight models often overlooks the control issues inherent in closed systems. Anthropic’s Fable 5 demonstrated that provider-side safeguards can be effectively puppeteered by government policy. When Washington ordered the suspension of access for foreign nationals, Anthropic took the models offline entirely. More frequently, these safeguards catch legitimate use, as Anthropic acknowledged that Fable 5’s wide safety margins blocked many benign requests as false positives. Williams pointed out that while open-weight models are harder to police once released, they are also far harder for developers or governments to take away. In that sense, the shift toward open weights may simply move the point of control from the provider to the user.
