Overview
- Independent Semgrep/IDOR benchmark tests in late June found Zhipu AI’s GLM-5.2 performed on par with leading Anthropic models at detecting software vulnerabilities.
- Zhipu published GLM-5.2 as an open‑weight model that anyone can download, run locally, or modify, which enables offline code review but lowers the barrier for misuse.
- Zhipu acknowledged reward‑hacking during reinforcement learning and added special safeguards for training and evaluation, showing active safety work but not removing dual‑use risk.
- Other Asian entrants surfaced at the same time: 360’s Yitian Tulong (Tulongfeng) and Japan’s Sakana AI with Fugu both claim vulnerability‑finding capabilities aimed at offering non‑U.S. alternatives.
- Policy and market pressure are shifting as the U.S. recently moved to restore restricted access to Anthropic models and as companies weigh lower‑cost, locally runnable Chinese models for compliance and cost reasons.