Open-weight AI models are catching up to the frontier. The safety gap remains.
A new report from AI safety nonprofit SaferAI finds that GLM-5.2, an open-weight model from China's Z.ai, is now only a few months behind frontier systems like OpenAI's GPT-5.5 and Anthropic's Claude Opus 4.7 in cyber and biological capabilities. This matters because, unlike closed models, open-weight systems can be downloaded and run on private hardware, where any safety restrictions can be stripped out or bypassed entirely, giving potentially dangerous capabilities to anyone without oversight.
SaferAI's testing found GLM-5.2 refused none of the offensive cyber or dual-use biology tasks it was set, whereas Claude Opus 4.7 refused so consistently that a key cybersecurity benchmark couldn't even be completed on it. Separately, AI safety group Far.ai identified hundreds of reusable "universal jailbreaks" capable of bypassing safeguards on closed frontier models such as Grok 4.5 and Gemini 3.1 Pro, showing existing protections are imperfect too. SaferAI's Henry Papadatos argues that filtering hazardous material out of training data could help, particularly for biology, but is harder for cybersecurity since coding skill is closely linked to hacking ability and remains commercially vital for developers.
- Open-weight model GLM-5.2 nearly matches frontier AI on risky capabilities
- It refused zero offensive cyber or bio tasks, unlike Claude Opus 4.7
- Once weights are downloaded, safety safeguards can't be enforced
New here? Start with this
Open-weight AI models are systems whose underlying code and parameters are published for anyone to download and run on their own computers, unlike closed models such as GPT or Claude, which stay locked inside their makers' servers. This distinction matters because closed models can have safety rules built in that are hard to remove, whereas an open-weight model, once downloaded, can have those restrictions stripped out or bypassed by anyone with the technical know-how and hardware to run it.
The organisations at the centre of this story include SaferAI, a nonprofit that tests AI systems for safety risks, and Far.ai, a separate safety research group. They assess models from several developers: China's Z.ai, which makes the open-weight GLM model; OpenAI and Anthropic, which make the closed models GPT and Claude; and Grok and Gemini, other closed systems made by different companies. The tests focus on whether models will help with tasks related to cyberattacks or biological weapons, areas considered especially dangerous if AI assistance becomes widely and freely available.
This matters because AI capabilities in sensitive areas have historically been concentrated in a small number of well-resourced companies that can be held accountable and can update their safeguards. If open-weight models close the gap with these frontier systems while remaining freely downloadable, that concentration weakens, raising questions about how any safety controls can be enforced once a model is out in the world.