Zhipu AI’s GLM‑5.2 rivals Anthropic Mythos in cyber‑security, testing US export bans
Beijing‑based Zhipu AI released the open‑weight model GLM‑5.2 on 13 June 2026. Independent benchmarks (Semgrep and Graphistry) show the model matches Anthropic’s restricted Claude Mythos in software vulnerability detection – scoring an F1 of 39 % on IDOR tests, surpassing Mythos’s 32‑37 % and doing so at roughly one‑sixth the cost per vulnerability.
The result intensifies questions about the effectiveness of the United States’ AI export‑control regime. The Trump administration had, on 12 June, ordered a blanket suspension of Anthropic’s advanced models Mythos 5 and Fable 5 for all foreign users, citing national‑security risks. After negotiations, the U.S. Commerce Department later authorized limited access to Mythos 5 for roughly a hundred trusted U.S. organizations that operate critical infrastructure, while Fable 5 remains fully blocked.
Because GLM‑5.2 is released under a permissive open‑weight licence, anyone can download and run it on consumer‑grade hardware, bypassing export controls. Security experts warn that such freely available models could be weaponised by threat actors, while also offering defenders a low‑cost tool for bug‑finding. One analyst quoted in a Portuguese report said that “prohibiting models while selling chips that China needs… is a gift to China.”