China's Z.ai Challenges Anthropic With New AI Cybersecurity Model GLM-5.3
Key Takeaways
- •The reported model, GLM-5.3, is said to have slightly outperformed Anthropic’s Mythos 5 in CyberGym vulnerability-finding tests.
- •The claims have not been independently verified and were circulated on social media.
- •The development described resembles distillation, where a model is trained using outputs from a stronger system.
- •GLM-5.3 is being positioned as an open-source model, unlike Anthropic’s restricted-access systems.
- •Zhipu AI was added to the US Commerce Department’s Entity List in January 2025, which limits access to US technology suppliers.

China's Zhipu AI, better known as Z.ai, has reportedly developed a cybersecurity model that rivals Anthropic's Mythos 5, according to information circulated on social media.
The company is said to have achieved this by extensively questioning Anthropic's AI and using the responses to construct a comparable model. The claims have not been independently verified. The approach described resembles what AI researchers call distillation, in which a model is trained on the outputs of a more capable system. Major AI providers, including Anthropic, generally restrict the use of their models' outputs to develop competing systems under their terms of service.
The new model, GLM-5.3, is said to have slightly outperformed Mythos 5 in CyberGym vulnerability-finding tests — a benchmark designed to measure how well AI models identify security vulnerabilities — a result described as a significant leap in China's AI capabilities achieved with fewer resources. Unlike Anthropic's restricted-access model, GLM-5.3 is positioned as an open-source offering. In practice, open-source AI releases let developers download model weights, inspect them, run them on their own infrastructure, and adapt them to specific tasks — a contrast with restricted-access systems that users cannot examine directly. That distinction carries particular weight in cybersecurity, where vulnerability-finding tools are dual-use by nature: the same capability that helps defenders patch flaws can also help attackers locate them.
Zhipu AI is one of China's best-known AI developers, founded as a spin-off from Tsinghua University, and its GLM series ranks among the country's most prominent model families. In January 2025 the company was added to the US Commerce Department's Entity List, a measure that requires US suppliers to obtain a license before selling it American technology, and Chinese AI developers broadly operate under US export controls on the advanced chips used to train large models. Anthropic, based in the United States, is known for its Claude model family and restricts access to some of its most capable systems. Open-weight releases have become a competitive strategy for several Chinese labs, including DeepSeek, whose openly published models drew international attention in early 2025.
The report suggests the development could mark a shift in the competitive landscape of AI cybersecurity, with Z.ai emerging as a formidable challenger to Anthropic's position in the field.
Upcoming evaluations and benchmark releases are expected to further clarify the impact of Z.ai's advancements on Anthropic's market standing. Both Anthropic and Z.ai may release additional performance data or updates that could influence market dynamics, and strategic moves by Anthropic — such as updates to its Mythos model or partnerships with new vetted partners — could also affect the competitive landscape.