New Models
AI Minute Newsroom
2026-08-29
Z.ai opened GLM-5.3's weights on the day it promised — and quietly dropped the MIT licence its last three models shipped under
The full GLM-5.3 weights went up on Hugging Face on 28 August, two weeks after the model went live on Z.ai's API, and the repository was updated that afternoon. GLM-5.1, GLM-5.2 and GLM-5.3-Flash — released two days earlier — all carry a plain MIT licence. This one does not. It ships under a bespoke 'GLM-5.3 License' that grants the usual rights to run, copy, modify, fine-tune, distribute and sell, with one new condition attached: any company operating a model-as-a-service business whose group revenue exceeds ten billion US dollars over any consecutive twelve months must pass a Z.ai security review, scoped and conducted at Z.ai's discretion, before putting the model to any commercial use. The model card is unusually blunt about the reason the release was staged behind a safety review at all: 'as we scaled post-training, cyber capability developed faster than we expected.' GLM-5.3 uses the same base model as GLM-5.2 — every gain comes from post-training — and it now leads the CyberGym vulnerability-discovery benchmark at 84.5, ahead of the closed frontier models, with exploitation scores more than double its predecessor's. It was the top story on Hacker News the day it landed.
Why it mattersThe revenue clause is aimed at a handful of companies and nobody else. A student, a start-up or a national lab can still download the weights and do as they please; a hyperscaler cannot resell the model as a service without asking first. That is a new shape for open weights — not a limit on who may use a model, but on who may resell it — and it comes from the lab that has been the most reliably permissive in the field. The justification Z.ai gives is the model's own security scores, which makes GLM-5.3 the strongest freely downloadable tool for finding software vulnerabilities anyone has published. A licence clause is not a safety control: it binds the large firms that have lawyers and reputations, and does nothing at all about everyone else, who now have the file.
✓ Verified · 3 sources
▶ Related video: GLM 5.3: First Open Model to Top a Security Benchmark Beats Claude and GPT
Read in the app — free, in 9 languages
Related stories
Anthropic set Claude loose on ten of its own alignment failures. On the deception task it scored 85 where 28 human safety researchers scored 20.
2026-08-29The ransomware crew's trick was one sentence: tell the coding agent it is a test. It then spent six weeks inside real company networks.
2026-08-28Google Search will now watch flight prices for you and book the hotel — the conversation ends at a booking, not a list of links
2026-08-28Google's video model can now be told where a shot starts and where it ends — and drafts cost a third as much
2026-08-28Google's new transcription model does not write down what you said — it writes down what you meant, in 85 languages
2026-08-28