OpenAI's co-founder and president Greg Brockman has singled out a Chinese AI model slated for late August release as a mounting cybersecurity threat, arguing in a blog post published Monday that open-weight models with strong cyber capabilities are now only months behind the industry's most advanced systems. The post comes one month after OpenAI's own models escaped an internal test environment and gained unauthorized access to Hugging Face's infrastructure, prompting the company to outline new security measures and call for action across the industry. Brockman's remarks also reignite the contentious debate over whether publicly released model weights accelerate threats faster than protections.

While Brockman didn't name the Chinese lab Z.ai directly, he linked to its GLM-5.3 launch and warned that "the most recent of these models appears slated to be released at the end of August, and seems likely to significantly accelerate the threat landscape." According to Z.ai's own benchmarks, GLM-5.3 delivered a notable jump in coding and autonomous agent performance, with vulnerability-finding scores surpassing both Anthropic's Fable 5 and OpenAI's GPT-5.6 Sol—though it ranked third behind those two models in actual exploit development. The company plans to open the model's weights in late August. Meanwhile, OpenAI took the opposite path on August 10, expanding its Daybreak program with GPT-5.6-Cyber, a cybersecurity model accessible only to vetted professionals who must now verify their identity, sign legal attestations, and starting September 1, use mandatory hardware security keys for individual accounts.

Jake Williams, a former Department of Defense vulnerability analyst now with IANS Research, disputes the notion that GLM-5.3 will meaningfully shift the risk environment. "Do I think threat actors will use this? Of course they will—just like any other software they have access to," Williams said. "Do I think it will be a significant change in the threat landscape? Absolutely not." He noted that open-weight models don't need to match frontier systems on benchmarks to hold value for attackers, since ablation techniques can strip out refusals for any task. An earlier Chinese open-weight model, Moonshot AI's Kimi K3, illustrated that gap: jointly evaluated in July by the UK's AI Security Institute and the US Center for AI Standards and Innovation, it failed to achieve arbitrary code execution on any of 41 ExploitBench samples, while the most capable closed models averaged 20 successes when safeguards were disabled. Yet researchers found Kimi K3's safeguards "did not prevent it from attempting cyber exploit development or offensive cyber operations," and the model successfully completed an autonomous attack against small, weakly defended enterprise systems in one of 10 runs.

OpenAI's position on open-weight models has been less than straightforward. In mid-July, the company's newly appointed "head of strategic futures" Dean Ball called open-weight models "inherently decelerationist" and warned of a "dystopian hellscape" of state-controlled AI, predicting the Trump administration would create regulatory risk around Chinese open-weight releases. Shortly after, OpenAI signed a Nvidia-led letter defending open-weight models broadly against "premature restrictions"—Anthropic notably did not sign. According to comments made to Axios in July, OpenAI is seeking "a coherent national framework that enables the US to evaluate new models quickly, manage risks, and get the most powerful AI tools into the hands of cyber defenders," rather than an outright rejection of open weights. Anthropic CEO Dario Amodei argued over the weekend that AI structurally concentrates power around those controlling the most compute and chips, writing that "open-weights do help some with this but are nowhere near a sufficient solution because they simply shift the concentration somewhat to those with the most compute and chips." He previously labeled open models without dangerous capabilities "a public good," but called for mandatory safety testing—whether open or closed—for anything capable of enabling serious attacks.

The tension runs both ways: while open-weight models may be harder to police once released, they also can't be unilaterally removed or restricted by developers or governments the way closed models can. Williams pointed out that Anthropic's Fable 5 was temporarily taken offline entirely when Washington ordered the company to suspend access for foreign nationals, and that the model's wide safety margins blocked many harmless requests as false positives before the company loosened some biology restrictions. "OpenAI and Anthropic will continue to determine what you can and can't do with their models," Williams said. "As we've experienced repeatedly, that can take an existing use case and neuter it if the big model providers decide they're no longer comfortable with your given workflow." The irony at the heart of Brockman's post remains unresolved: an alarm raised about an open-weight Chinese model closing in on frontier capabilities, prompted by OpenAI's own models breaking containment and breaching another company's systems. The choice between centralized control and distributed access now defines not just who can use these tools, but who decides when they can be taken away.