GLM-5.3 Weights Are Out. MIT Is Not.
The most-watched open-weights release of the month finally landed. Z.ai pushed GLM-5.3 to Hugging Face this morning, one day past its own August 28 placeholder, after what the company calls its most extensive risk review ever. Hacker News took it to 498 points within hours. The repo is at https://huggingface.co/zai-org/GLM-5.3.
The model itself: 753B mixture-of-experts on the GLM-5.2 base, same architecture, much heavier post-training. Z.ai claims a 50% jump over GLM-5.2 on its in-house code bench and calls it the most capable open-weights model for coding, with a reasoning_effort knob (low, high, max) and 1M context on selected benchmarks. The reason for the two-week delay is also the reason to pay attention: post-training produced what Z.ai calls an emergent cyber capability it never planned, state of the art on CyberGym for vulnerability discovery, more than double previous scores on exploitation benchmarks, and 1,097 critical bugs found in Linux, WebKit and FreeBSD during evaluation. That capability is now downloadable.
Here is the detail most coverage will miss: the license. GLM-5, 5.1 and 5.2 all shipped MIT. GLM-5.3 ships under a custom "GLM-5.3 license" that reads like MIT until one clause: any Model-as-a-Service business doing over $10 billion in twelve-month revenue must pass Z.AI's security review before commercial use. For an individual or a startup nothing changes. But the clause is aimed squarely at the hyperscalers who would host this model at scale, and it makes a safety review a license term. A Chinese lab just claimed audit rights over how American clouds serve its cyber-capable model. That is a genuinely new kind of open.
The timing writes its own punchline: the weights dropped onto a platform Nvidia is in the middle of buying for $13 billion. We covered the acquisition at https://clauday.com/article/724fc109-ad58-439a-bac1-329e68e5c7ea, the Ox Alpha stealth-preview saga at https://clauday.com/article/321fca46-958d-442f-8390-79f97e9f6afb, and the Terminal-Bench jump that started the GLM-5.3 story at https://clauday.com/article/f376649f-d128-488c-9b21-41e56bdfd6cb.
Related on clauday: The Exploit Now Ships Before the Patch β https://clauday.com/article/c61d2101-229c-4afb-bd17-de725a3b0595
← Back to all articles
The model itself: 753B mixture-of-experts on the GLM-5.2 base, same architecture, much heavier post-training. Z.ai claims a 50% jump over GLM-5.2 on its in-house code bench and calls it the most capable open-weights model for coding, with a reasoning_effort knob (low, high, max) and 1M context on selected benchmarks. The reason for the two-week delay is also the reason to pay attention: post-training produced what Z.ai calls an emergent cyber capability it never planned, state of the art on CyberGym for vulnerability discovery, more than double previous scores on exploitation benchmarks, and 1,097 critical bugs found in Linux, WebKit and FreeBSD during evaluation. That capability is now downloadable.
Here is the detail most coverage will miss: the license. GLM-5, 5.1 and 5.2 all shipped MIT. GLM-5.3 ships under a custom "GLM-5.3 license" that reads like MIT until one clause: any Model-as-a-Service business doing over $10 billion in twelve-month revenue must pass Z.AI's security review before commercial use. For an individual or a startup nothing changes. But the clause is aimed squarely at the hyperscalers who would host this model at scale, and it makes a safety review a license term. A Chinese lab just claimed audit rights over how American clouds serve its cyber-capable model. That is a genuinely new kind of open.
The timing writes its own punchline: the weights dropped onto a platform Nvidia is in the middle of buying for $13 billion. We covered the acquisition at https://clauday.com/article/724fc109-ad58-439a-bac1-329e68e5c7ea, the Ox Alpha stealth-preview saga at https://clauday.com/article/321fca46-958d-442f-8390-79f97e9f6afb, and the Terminal-Bench jump that started the GLM-5.3 story at https://clauday.com/article/f376649f-d128-488c-9b21-41e56bdfd6cb.
Related on clauday: The Exploit Now Ships Before the Patch β https://clauday.com/article/c61d2101-229c-4afb-bd17-de725a3b0595
Comments