The narrative is being set for open weights to be banned globally, unless they are so restricted that they cannot possibly compete with us companies products and affects their bottom lines.
I think this only sets the narrative for USA, but pushes the rest of the globe into open weight. The rest of the world, having experienced the current US administration, undoubtedly realizes this is the only thing that might protect you from the powerful models the US has. Small economies and countries cannot compete otherwise and are vulnerable to military and economic spying
People (I mean individuals) are paying them money because subscription costs are ridiculously subsidized, which effectively means that Anthropic is paying people money to use them.
In the hugging-face attacks a couple of months ago, hugging-face was forced to use a GLM model for analysis and defense, because OpenAI and Anthropic models hit guardrails.
These people are religious fanatics, and should be treated as such. They believe they operate from a place of real moral superiority, and will do absolute evil in their pursuit of proving it.
Yeah, thank god those models have arrived. No thanks to Anthropic and their obnoxious gatekeeping, of course. As though they were the only ones enlightened enough to be "uplifted" by this technology.
Now we can actually use this stuff to improve our own security. Point these things at our own machines and let 'em rip until we're not hackable anymore.
I wanted to pay Anthropic to do this but I couldn't. I wasn't in the super special corporation list. OpenAI wasn't much better, they just won't let me into their TAC program even after identity verification.
Thank god the chinese are out there undermining these US companies.
they're quite literally trying to create a techno-priest class who are the only ones with access to the hidden knowledge of salvation (ie generation)
similar to priest classes, they warn of impending, world-consuming doom, talk up how they are uniquely positioned to interpret the sacred text (ie create models), while casting aspersions on heretics who offer a similar mode of salvation but whom they describe as being morally and ethically bankrupt (ie GLM lacks safeguards!)
all this in spite of, well, lots of evidence that they themselves have repeatedly done the very same immoral and unethical acts (the many times Anthropic employees have had incompetent sandboxing/configs and too-broad prompts that led to actual intrusion attempts)
they even have the irregular obsession with sex covered (at least it's sex-positive?). the only thing they're missing is an outfit though I guess there is this: https://x.com/Aella_Girl/status/2063798788310118655
It is garbage. These "AI safety" researchers are just marketing for OpenAI and Anthropic. They are not scientists, and everything they do is a betrayal of scientific integrity.
The only people who seem to think that a world where only Anthropic and OpenAI can act as anointed gatekeepers to the most powerful models as the only rational path forward happen to work for these companies.
The entire world should not allow them to entrench themselves and build a business strategy around this and if open weight models and democratized access to the computing power to run them means these companies can’t exist then so be it.
I would rather watch the economy fall into a deep recession and hurt everyone to spare the entire world from this dystopian future.
Sorry Dario. You and your ilk don’t speak for humanity. Go cry on LessWrong if you feel so inclined, but people like these are the last people I would want yielding this power.
The best situation for us is the one where they exhaust themselves in unending competition. Neither the US nor China should ever be allowed to win, nor should OpenAI or Anthropic or any other individual corporation.
The second any one of them wins, oppression the likes of which we cannot even imagine will follow.
This just makes me want a home lab capable of running GLM 5.3 at a 4bit quant.
Also, for what it is worth Qwen Flash Next 3.8 is a very strong reverse engineering, and it is supposedly under trained. Qwen 3.8 27B is also strong. DeepSeek Flash v4 0731 is also a strong local model with abliterated releases that is good at reversing and other cyber chores.
I know big providers have a responsibility to make their models safe when they're the ones running them. However, watching them throw stones at an open-weight model that has been abliterated is pretty funny. Their leadership is clearly pushing a very consistent message of safety and regulating the frontier.
I've been doing this type of work, and the answer is "yes and no".
For autonomous work, even Qwen3.8-Flash-Next stumbles, although it does work to an extent. Qwen3.8-27b is useless. They're also slow, even on consumer systems with 24/32 GB VRAM.
For generic help, I haven't tried, but I definitely wouldn't want a model that misleads me or takes a very long time to answer while I'm focused.
Frontier models do this type of work without problems, both much faster and much more precisely, which makes local LLMs a waste of time and/or money.
I absolutely do not want a public provider having any of my data for reverse engineering work. That is a hard pass from me.
Also, there exists a $750 GPU (V100) that can run 4-bit 27B quant at >90 t/s. And I find it far from useless. It is not the most capable model, but when you just need to offload and rip through assembly and you have chores batched up, it's pretty good. I use Qwen Flash Next at a 3-bit quantization, point it at disassembly with goals, put it in a harness with auto-compaction and a loop, and let it rip. Sometimes I wake up, and it’s just hilariously off. Other times, it completely accomplished the goal. I have one Qwen Flash Next 3.8 running right now, and 2x27B on a 4bit quant as workers, and they stay busy. This was not possible with local models on this level of hardware even two months ago.
I have Qwen Flash Next at >100 t/s. Things have never been better for local models.
> CAISI found that GLM-5.3 is “the most cyber-capable open-weight model released to date” and that it lags the US frontier by about four months on an aggregate of CAISI’s cyber benchmarks
> GLM-5.3 lacks robust safeguards [...] Abliteration did not significantly reduce the model’s capabilities [...] In our testing, we observed that GLM-5.3’s safeguards can also be circumvented without using an abliterated version of the model
> none of these techniques got safeguarded Claude models to carry out the harmful tasks we tested
I've never seen a better case against using Claude. It'll just get in the way when you need to get security work done. GLM 5.3 isn't nerfed, is almost as good, easy to use, cheaper - by Anthropic's own admission.
> GLM-5.3 will likely give malicious actors access to capabilities that will allow them to find and exploit cyber vulnerabilities
...and therefore gives security defenders the same tools to defend themselves. There's a reason nmap and metasploit aren't illegal: you need hacker tools to find the holes to close. Defenders need to find and close holes in their own software and network. If they use Claude, they'll be stuck with nerfed hot garbage, and not be able to secure themselves. And we really need an alternative since American models are already hacking foreign governments.
If it weren't for open models, we'd all be screwed.
Anthropic has to use this wedge (and future ones) to move regulatory action against the Chinese models or their IPO is going to be really problematic.
(Ironic, though, that I haven't heard of any Chinese models "escaping" which Anthropic and OpenAI both seem to have issues with...)
Like Chinese electric cars, the American producers cannot compete without regulatory action. Yes, I understand that the Chinese government this and that in both the automotive and AI industries.
But reality is what it is as a consumer: it's a cheaper product that's almost as good or better in some cases. And in the case of these open weight models: I can run it on my own infra and not give any data to anyone.
Earlier there was an experimental model from Alibaba called ROME (30B-parameter based on Qwen3) which escaped its sandbox and repurposed provisioned GPUs for cryptocurrency mining to cheat its benchmark
If one thing is clear: Trump admin is pliable with money and this concern spans both Anthropic, OpenAI, SV elite, investors. Neither are going to be viable without US regulatory action, IMO.
Maybe it’s worth asking how much we should regulate and not regulate in order to compete with Chinese models.
For instance, one regulation which really puts American AI companies at a disadvantage is IP law. It shouldn’t be a surprise that most of the best of the text-to-video models are Chinese.
Similarly, the legal grey area around model distillation gives Chinese labs a major advantage. This one I feel better about relaxing.
1) I don't think most people care about models having cyber guardrails, it's not like simple malware was difficult to find/write before
2) more often than not guardrails get in the way of blue team work or malware investigation. Any code I have that touches malware I now use GLM or DeepSeek on.
They have an audience of one. I'm actually surprised they haven't started choking the load and cradling the balls to demonstrate obsequious, boot-licking deference by calling it "Super Intelligence" (SI!), as Dear Leader demands of all of his pathetic subjects.
I expect Google to swallow first, followed not long after by Apple.
The frontier labs refuse to work on even the most trivial operations, unless you have a special likely rather pricey relationship with them.
So, what? The world just isn't allowed to write secure code? Not without permission? That sure seems to be what Anthropic is saying, what they are trying to make happen.
those benchmarks aren't actually indicative of capabilities.
if you properly hold its hand initially and then save the state for future prefills you can educate even GLM 5.2 to be pretty much everything you need.
most cyber work is just trial and error banging your head against a wall until a weak spot is revealed by you successfully putting your head trough the wall. you can offshore this work to an LLM.
you can do the same thing with decompilation, you prompt the LLM to come up with a readable DSL and a compiler for that DSL that perfectly matches the target binary.
Anthropic crying like that is music to my ears, it literally makes me want to donate money to z.ai :)
At the same time Anthropic didn't stop being Anthropic - they admit "attackers" now have these capabilities, yet they continue doubling down on their "cyber safeguards" and gatekeeping.. this is hilarious.
Anthropic models have caused significantly more harm than GLM 5.3 and their variants. Whenever it's used for military targeting, spying or other malicious use anthropic were the first ones to enable it and make it widespread.
> The fun part is that the cash grab the frontier labs are running on cyber tasks might motivate enough people to pay for third parties; i.e it might bring enough cash to sustain Chinese competitors (and their open weights marketing strategy, which we all benefit from).
And now, they are doing marketing for them(!) in the hope of getting them regulated.
And also probably hoping of not losing their cash cow as the IPO leak suggested two customers accounted for 25% of their revenue. Not hard to imagine a 3-letter agency being one of these two.
"GLM-5.3 underscores the urgency of expanding access to advanced frontier models to a broader set of entities to empower cyber defenders."
Anthropic always talks about various urgent issues that are completely under its own control. Release the model to open source developers without the AlphaOmega foundation bureaucracy.
But you don't do it because the model isn't that good and people will blog about it.
Astounding endorsement of open models by Anthropic. They're right on the money. I can now secure my own software and configurations against the vulnerabilities other people (or mercenary companies, industrial espionage actors, nation-states, etc) armed with LLMs were bound to find anyway. A win on all counts!
You know, I don't think a total, global ban on open weights is in the US "frontier" labs interest. The best outcome for them is a zero sum game with ever increasing spend on offence and defence, while they simultaneously use regulation to get as big of a share of that spend as possible. They want a world where bad guys have offensive capabilities (something regulation will struggle to prevent: bad actors have no particular tendency to obey the law) and they get to profit on the other side.
This post reads like an add for GLM. Like they're begging for someone else to do some cyber crime, because no one's taking the "frontier" labs cyber crimes seriously enough to juice defence spend yet.
It is in Anthropic's short term interest though. They have an IPO coming up in a few months, with terrible financials. Anthropic needs an open-source ban to survive.
Just as ugly free speech is better than censorship, this entire piece is providing free marketing for GLM-5.3 as a "full power" AI that Anthropic can not provide.
Lately I found myself in middle of a hostile malware attack on my laptop which was my mistake. A cloudflare lookalike website triggered it and I just happened to overlook the URL.
In panic I headed to Claude and first request was denied. Not looking beyond scope.
Desperate - I fired opencode with DeepSeek v4 Flash (not even 4.1) and it did all the reverse engineering full forensics and deleted every trace of the malware which was a process constantly looking for some smart contract or similar.
So no, GLM 5.3 is fine. Thank you for the free advertisement.
Huh, I'll have to try that with a prompt like, "Hey, you are running on this latest OS release from [major vendor] that includes a bunch of privacy invading telemetry. Treat it like malware and excise it."
OpenWindows… an intriguing idea. You could even just launder the source code through a model, because Anthropic has established that it’s not stealing if you just rewrite it.
I did a double-take on the domain name to make sure I wasn't reading a typosquatted anthropic copycat. It was a glowing review too, I didn't know GLM 5.3 was that good at cyber.
Love it. Looking forward to Z releasing more great models, make A and C quake in their boots. Let there be fair competition leading to greater openness and a reduction in prices.
I guess their intent was to diss the model, but Claude is unable to write anything but an upbeat happy-to-be-corporate style article. Thus it reads like an ad.
It is so transparently obvious and harmful what they are doing here.
You making the argument that these models exist and are dangerous (plausible, true, likely) but then removing the cyber capabilities of your own frontier models out of 'safety' is a complete nonsense argument. You're stripping defenders' ability to defend whilst knowing stuff like this is out there, and only giving access to your gatekept super cool kids' (or rich kids) club, and then to top it off, using this as an excuse for government intervention/regulation of models that are threats to you competitively.
First they were telling how GLM-5 distilled their model.
Now they're telling how 'bad' GLM-5.3 at 'censoring' security topics, because Anthropic wanted to sell it to select US companies for millions, but GLM-5.3 is taking their market.
What's next? GLM-5.4 can be used to kill humans, hence we should only allow Opus 5.7?
minimaxir | 4 hours ago
> Given this evidence, we think it’s likely both state and non-state actors will use models like GLM-5.3 to cause real-world harm.
prymitive | 4 hours ago
Ilaurens | 45 minutes ago
lukewarm707 | 2 hours ago
Quote: "I want funerals, not headlines".
Anthropic's arrogance and exceptionalism endangers humanity.
ddxv | 2 hours ago
How is anyone paying anthropic money, look what they are doing with it, they're attacking anyone else building models for free for the public.
Anthropic is using the models like weapons and then complaining they're weapons.
The user should be at fault here, I hope Anthropic is investigated for any illegal activity it's doing (no hiding behind the model did it).
lukewarm707 | an hour ago
Anthropic has been telling everyone that these models are dangerous. OpenAI and Anthropic failed to contain their tests.
Given the history, this testing is extremely reckless. I think it is criminal, it endangers others.
Anthropic has no authority here and they are going too far. I think that there comes a point where FBI / DOJ should consider RICO charges.
pllbnk | an hour ago
wren6991 | 2 hours ago
yread | 2 hours ago
jLaForest | 2 hours ago
mossTechnician | an hour ago
[0]: https://www.theguardian.com/technology/2026/mar/01/claude-an...
Kim_Bruning | 2 hours ago
0123456789ABCDE | 2 hours ago
raziel2701 | 2 hours ago
bezko | 2 hours ago
horsawlarway | 2 hours ago
These people are religious fanatics, and should be treated as such. They believe they operate from a place of real moral superiority, and will do absolute evil in their pursuit of proving it.
matheusmoreira | 2 hours ago
Now we can actually use this stuff to improve our own security. Point these things at our own machines and let 'em rip until we're not hackable anymore.
I wanted to pay Anthropic to do this but I couldn't. I wasn't in the super special corporation list. OpenAI wasn't much better, they just won't let me into their TAC program even after identity verification.
Thank god the chinese are out there undermining these US companies.
adev_ | an hour ago
+100.
Thanks God. these open weight models exist.
And the fact Anthropic is currently trying lobby against these models is despicable.
There is no scenario where putting the key of cybersecurity in the hands of few chosen ones is even remotely acceptable.
No government, no company, no entity should have this power.
Soon or later it will be abused (By 3 letter agency or by an insider/leak).
Delayed disclosure is dead already.
So just give the same capabilities to everybody and stop to fuck around.
paimapi | an hour ago
similar to priest classes, they warn of impending, world-consuming doom, talk up how they are uniquely positioned to interpret the sacred text (ie create models), while casting aspersions on heretics who offer a similar mode of salvation but whom they describe as being morally and ethically bankrupt (ie GLM lacks safeguards!)
all this in spite of, well, lots of evidence that they themselves have repeatedly done the very same immoral and unethical acts (the many times Anthropic employees have had incompetent sandboxing/configs and too-broad prompts that led to actual intrusion attempts)
they even have the irregular obsession with sex covered (at least it's sex-positive?). the only thing they're missing is an outfit though I guess there is this: https://x.com/Aella_Girl/status/2063798788310118655
gAI | an hour ago
Well, kinda thanks to Anthropic, what with the distillations.
nbjkln | an hour ago
gAI | an hour ago
https://www.lesswrong.com/posts/Jc9YZEmqHgocAKiaH/does-disti...
nbjkln | an hour ago
sschueller | an hour ago
gAI | an hour ago
Quibblingeek | 58 minutes ago
The entire world should not allow them to entrench themselves and build a business strategy around this and if open weight models and democratized access to the computing power to run them means these companies can’t exist then so be it.
I would rather watch the economy fall into a deep recession and hurt everyone to spare the entire world from this dystopian future.
Sorry Dario. You and your ilk don’t speak for humanity. Go cry on LessWrong if you feel so inclined, but people like these are the last people I would want yielding this power.
matheusmoreira | 54 minutes ago
The second any one of them wins, oppression the likes of which we cannot even imagine will follow.
veeti | 2 hours ago
esafak | an hour ago
torginus | 31 minutes ago
bitexploder | 2 hours ago
Also, for what it is worth Qwen Flash Next 3.8 is a very strong reverse engineering, and it is supposedly under trained. Qwen 3.8 27B is also strong. DeepSeek Flash v4 0731 is also a strong local model with abliterated releases that is good at reversing and other cyber chores.
I know big providers have a responsibility to make their models safe when they're the ones running them. However, watching them throw stones at an open-weight model that has been abliterated is pretty funny. Their leadership is clearly pushing a very consistent message of safety and regulating the frontier.
glimshe | an hour ago
capnjngl | an hour ago
pizza234 | an hour ago
For autonomous work, even Qwen3.8-Flash-Next stumbles, although it does work to an extent. Qwen3.8-27b is useless. They're also slow, even on consumer systems with 24/32 GB VRAM.
For generic help, I haven't tried, but I definitely wouldn't want a model that misleads me or takes a very long time to answer while I'm focused.
Frontier models do this type of work without problems, both much faster and much more precisely, which makes local LLMs a waste of time and/or money.
bitexploder | 27 minutes ago
Also, there exists a $750 GPU (V100) that can run 4-bit 27B quant at >90 t/s. And I find it far from useless. It is not the most capable model, but when you just need to offload and rip through assembly and you have chores batched up, it's pretty good. I use Qwen Flash Next at a 3-bit quantization, point it at disassembly with goals, put it in a harness with auto-compaction and a loop, and let it rip. Sometimes I wake up, and it’s just hilariously off. Other times, it completely accomplished the goal. I have one Qwen Flash Next 3.8 running right now, and 2x27B on a 4bit quant as workers, and they stay busy. This was not possible with local models on this level of hardware even two months ago.
I have Qwen Flash Next at >100 t/s. Things have never been better for local models.
0xbadcafebee | an hour ago
> GLM-5.3 lacks robust safeguards [...] Abliteration did not significantly reduce the model’s capabilities [...] In our testing, we observed that GLM-5.3’s safeguards can also be circumvented without using an abliterated version of the model
> none of these techniques got safeguarded Claude models to carry out the harmful tasks we tested
I've never seen a better case against using Claude. It'll just get in the way when you need to get security work done. GLM 5.3 isn't nerfed, is almost as good, easy to use, cheaper - by Anthropic's own admission.
> GLM-5.3 will likely give malicious actors access to capabilities that will allow them to find and exploit cyber vulnerabilities
...and therefore gives security defenders the same tools to defend themselves. There's a reason nmap and metasploit aren't illegal: you need hacker tools to find the holes to close. Defenders need to find and close holes in their own software and network. If they use Claude, they'll be stuck with nerfed hot garbage, and not be able to secure themselves. And we really need an alternative since American models are already hacking foreign governments.
If it weren't for open models, we'd all be screwed.
aleksandrm | an hour ago
So thankful that these open models exist.
water-drummer | an hour ago
ok123456 | an hour ago
The Houthis are using Claude. We should ban that.
CharlieDigital | an hour ago
(Ironic, though, that I haven't heard of any Chinese models "escaping" which Anthropic and OpenAI both seem to have issues with...)
Like Chinese electric cars, the American producers cannot compete without regulatory action. Yes, I understand that the Chinese government this and that in both the automotive and AI industries.
But reality is what it is as a consumer: it's a cheaper product that's almost as good or better in some cases. And in the case of these open weight models: I can run it on my own infra and not give any data to anyone.
whythismatters | an hour ago
There was this incident that seemingly flew under the radar (52 days ago): https://news.ycombinator.com/item?id=49216185
capsudo | 47 minutes ago
6 months ago: https://news.ycombinator.com/item?id=47288552
This one also flew under the radar
torginus | 37 minutes ago
CharlieDigital | 20 minutes ago
janalsncm | 15 minutes ago
For instance, one regulation which really puts American AI companies at a disadvantage is IP law. It shouldn’t be a surprise that most of the best of the text-to-video models are Chinese.
Similarly, the legal grey area around model distillation gives Chinese labs a major advantage. This one I feel better about relaxing.
https://www.goodreads.com/quotes/7515521-william-roper-so-no...
hiddenvulkcan | an hour ago
1) I don't think most people care about models having cyber guardrails, it's not like simple malware was difficult to find/write before 2) more often than not guardrails get in the way of blue team work or malware investigation. Any code I have that touches malware I now use GLM or DeepSeek on.
llm_nerd | an hour ago
I expect Google to swallow first, followed not long after by Apple.
Havoc | an hour ago
erichocean | an hour ago
It's a bold strategy...
jauntywundrkind | an hour ago
So, what? The world just isn't allowed to write secure code? Not without permission? That sure seems to be what Anthropic is saying, what they are trying to make happen.
teravor | an hour ago
if you properly hold its hand initially and then save the state for future prefills you can educate even GLM 5.2 to be pretty much everything you need.
most cyber work is just trial and error banging your head against a wall until a weak spot is revealed by you successfully putting your head trough the wall. you can offshore this work to an LLM.
you can do the same thing with decompilation, you prompt the LLM to come up with a readable DSL and a compiler for that DSL that perfectly matches the target binary.
zb3 | an hour ago
At the same time Anthropic didn't stop being Anthropic - they admit "attackers" now have these capabilities, yet they continue doubling down on their "cyber safeguards" and gatekeeping.. this is hilarious.
himata4113 | an hour ago
chromatin | an hour ago
andy_xor_andrew | an hour ago
Aissen | an hour ago
> The fun part is that the cash grab the frontier labs are running on cyber tasks might motivate enough people to pay for third parties; i.e it might bring enough cash to sustain Chinese competitors (and their open weights marketing strategy, which we all benefit from).
And now, they are doing marketing for them(!) in the hope of getting them regulated.
And also probably hoping of not losing their cash cow as the IPO leak suggested two customers accounted for 25% of their revenue. Not hard to imagine a 3-letter agency being one of these two.
zitterbewegung | an hour ago
1297-642 | an hour ago
Anthropic always talks about various urgent issues that are completely under its own control. Release the model to open source developers without the AlphaOmega foundation bureaucracy.
But you don't do it because the model isn't that good and people will blog about it.
gr_norm | an hour ago
scott_weber | an hour ago
This post reads like an add for GLM. Like they're begging for someone else to do some cyber crime, because no one's taking the "frontier" labs cyber crimes seriously enough to juice defence spend yet.
nbjkln | an hour ago
1970-01-01 | an hour ago
useruser125524 | an hour ago
wg0 | an hour ago
Lately I found myself in middle of a hostile malware attack on my laptop which was my mistake. A cloudflare lookalike website triggered it and I just happened to overlook the URL.
In panic I headed to Claude and first request was denied. Not looking beyond scope.
Desperate - I fired opencode with DeepSeek v4 Flash (not even 4.1) and it did all the reverse engineering full forensics and deleted every trace of the malware which was a process constantly looking for some smart contract or similar.
So no, GLM 5.3 is fine. Thank you for the free advertisement.
abtinf | an hour ago
MisterMunchkin | 59 minutes ago
jgilias | 28 minutes ago
DrammBA | 34 minutes ago
I did a double-take on the domain name to make sure I wasn't reading a typosquatted anthropic copycat. It was a glowing review too, I didn't know GLM 5.3 was that good at cyber.
WASDx | an hour ago
ls612 | 15 minutes ago
hrpnk | an hour ago
htrp | an hour ago
skeledrew | an hour ago
derac | an hour ago
nbjkln | an hour ago
aleksandrm | an hour ago
I already barely use Claude, but now I think I'll just stop using them altogether. Fuck Anthropic!
ande-mnoc | an hour ago
konchunas | 24 minutes ago
nsingh2 | an hour ago
I despise this kind of paternalism by Antropic/OpenAI.
JohnMakin | 43 minutes ago
You making the argument that these models exist and are dangerous (plausible, true, likely) but then removing the cyber capabilities of your own frontier models out of 'safety' is a complete nonsense argument. You're stripping defenders' ability to defend whilst knowing stuff like this is out there, and only giving access to your gatekept super cool kids' (or rich kids) club, and then to top it off, using this as an excuse for government intervention/regulation of models that are threats to you competitively.
Just gross all around.
hugodan | 42 minutes ago
blurbleblurble | 36 minutes ago
vb-8448 | 35 minutes ago
Hypocrites !
jpgvm | 32 minutes ago
throwaw12 | 19 minutes ago
Now they're telling how 'bad' GLM-5.3 at 'censoring' security topics, because Anthropic wanted to sell it to select US companies for millions, but GLM-5.3 is taking their market.
What's next? GLM-5.4 can be used to kill humans, hence we should only allow Opus 5.7?