Site navigation

Chinese Z.ai Challenges US Frontier Models

Graham Turner

,

Z.ai GLM-5.2
Z.ai’s GLM-5.2 has delivered competitive coding and cybersecurity results at – supposededly – a fraction of the cost of leading US models.

Chinese AI Z.ai plans to use proceeds from a domestic stock market listing to support its pursuit of AGI, after its latest model approached the performance of leading systems from Anthropic and OpenAI.

The Beijing-based company, also known as Zhipu AI, said its flagship GLM-5.2 model had delivered strong results across public intelligence, coding and cybersecurity benchmarks.

“Our mission is to obtain AGI, so right now our focus is how to improve our model to achieve the upper bound of intelligence. So all these resources are helping us,” said Qinkai Zheng, technical lead of the company’s CodeGeeX team.

Z.ai announced this month that it plans to pursue a dual listing in Shanghai, although it has not disclosed how much it intends to raise.

Its shares have risen by more than 2,000% since the company’s Hong Kong debut in January, taking its market capitalisation above HK$1 trillion, equivalent to around $128bn.

GLM-5.2 currently sits fourth on Artificial Analysis’ LLM intelligence leaderboard and second on Code Arena’s front-end coding leaderboard. It reportedly operates at roughly one-sixth of the cost of leading closed US frontier models.

“This model is comparable to the top closed models,” Zheng said.

“It’s the first time that an open-source model really delivers very solid coding and agent performance that can compare with the leading proprietary AI companies like Anthropic and OpenAI.”

GLM-5.2 specialises in coding and complex, long-running tasks. The mixture-of-experts model has around 750 billion total parameters and a one-million-token context window.

Z.ai said the model had been adapted to work across domestic Chinese chip infrastructure, including Huawei Ascend clusters, after the US tightened China’s access to advanced Nvidia processors.

“We are trying our best to improve our infrastructure and to make the model more efficient on different kinds of chips,” Zheng said, without confirming whether GLM-5.2 had been trained using Chinese or foreign hardware.

The model was released shortly after Anthropic suspended worldwide access to its Fable 5 and Mythos models following new US export controls restricting their use by foreign nationals.

Z.ai co-founder Tang Jie described Anthropic’s withdrawal of the models as “deeply regrettable” and reiterated the company’s commitment to open-source AI.

Despite intense price competition in China, Z.ai has increased prices for its frontier models several times this year, reflecting growing adoption among enterprises and public sector organisations.

Cybersecurity Capabilities Draw Attention

GLM-5.2 has also generated concern over its performance on cybersecurity tasks and the ease with which its open weights can be downloaded and modified.

Security company Semgrep found that the model achieved a 39% F1 score when detecting insecure direct object reference vulnerabilities, ahead of Claude Code’s 32%, although below Semgrep’s own multimodal system.

A separate evaluation by Graphistry found that GLM-5.2 matched Anthropic’s Opus 4.8 model on a capture-the-flag cybersecurity benchmark.

The results point to parity in some narrowly defined vulnerability-detection tasks rather than across general reasoning or multimodal performance.

However, unlike proprietary US models, GLM-5.2 can be operated locally under an MIT licence without subscription gates, geographical restrictions or centralised safety controls.


Recommended reading


Russian-language hacking forums were reportedly circulating jailbreak techniques for the model within days of its release, with users discussing its potential use for phishing, fraud and vulnerability-specific attack payloads.

Graphistry researchers also raised questions about whether knowledge distillation had contributed to the model’s rapid gains.

They found that GLM-5.2’s answers correlated unusually closely with outputs from GPT-5.5 and Opus 4.8. Graphistry said the pattern was consistent with knowledge distillation, where one model is trained using responses generated by another.

Z.ai has not confirmed or denied the characterisation, and the findings do not establish that unauthorised distillation took place.

The model’s release nevertheless raises questions about the effectiveness of export controls focused on closed US systems, particularly when comparable capabilities can be made available through unrestricted open-weight alternatives.

Zheng said Z.ai’s future models would focus on long-horizon tasks and self-evolving autonomous agents. Its next system, GLM-5.5, is expected to be released in August.

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data