# Z.ai releases GLM-5.3 weights with cyber-review licence for big firms

> Z.ai open-sourced GLM-5.3 with a licence gating hosting by firms over $10bn revenue.

*The Chinese lab held back the open weights for two weeks after its model topped a cyber-exploit benchmark.*

By Behzad Hosseini · FeaturedDaily
Canonical: https://featureddaily.com/news/z-ai-releases-glm-5-3-weights-with-cyber-review-licence-for-big-firms

**What happened:** Z.ai (Zhipu AI) released the open weights of its GLM-5.3 model on Hugging Face on 28 August, two weeks after launching it by API. The delay let the Chinese lab finish a safety evaluation of the model's cyber capabilities.

**The numbers:** GLM-5.3 scores 84.5% on CyberGym, up from 77.2% for GLM-5.2, and ahead of Claude Mythos 5 (83.8%) and GPT-5.6 Sol (83.6%). On ExploitBench it jumps to 54.4% from 24.4%. In testing, Z.ai says the model produced 2,436 vulnerability findings across 269 open-source projects, and completed 130 exploitation tasks in six hours versus 39 for its predecessor.

**The details:** The flagship model is a mixture-of-experts system with around 753 billion parameters, available in BF16 and FP8, and runs on vLLM, SGLang, KTransformers and Transformers. A smaller variant, GLM-5.3-Flash (320 billion total, 18 billion active), shipped on 26 August under a plain MIT licence. Z.ai says the cyber gains came from scaled post-training, not a retrained base model.

**The catch:** The flagship no longer uses the permissive MIT terms of GLM-5 through 5.2. Its new GLM-5.3 Licence requires any company with more than $10 billion in revenue over a 12-month period to pass a Z.ai security review before hosting the model themselves. Individuals and smaller firms face no restriction; routing to the model via API is also unaffected.

**The rivals:** Moonshot and DeepSeek, two other major Chinese open-weights labs, keep more permissive licensing terms, according to [The New Stack](https://thenewstack.io/zai-glm-weights-license/).

**Why it matters:** A Chinese open-weights lab is now staging releases and gating access on safety grounds, the same debate US labs have been having over increasingly capable cyber models.

**Who's affected:** Large hyperscalers wanting to self-host GLM-5.3 face the new review; everyone else, from individual developers to smaller firms, can download and run it freely.

**What's next:** Critics are questioning whether the licence is genuinely about safety or about controlling commercial use by big players, a tension unresolved as rivals stick with looser terms, per [VentureBeat](https://venturebeat.com/technology/glm-5-3-is-here-with-advanced-cyber-capabilities-and-reportedly-already-found-a-serious-vulnerability-in-cursor).

## Key takeaways

- GLM-5.3 tops CyberGym at 84.5%, beating Claude and GPT rivals
- New licence forces $10bn+ firms through a security review to host it
- Smaller GLM-5.3-Flash shipped separately under plain MIT

## Sources

- [Z.ai's GLM-5.3 goes open weight, but its new license aims at hyperscalers](https://thenewstack.io/zai-glm-weights-license/) — The New Stack, 2026-08-28
- [GLM-5.3 is here with advanced cyber capabilities](https://venturebeat.com/technology/glm-5-3-is-here-with-advanced-cyber-capabilities-and-reportedly-already-found-a-serious-vulnerability-in-cursor) — VentureBeat, 2026-08-14
