An open weight model is one anyone can download and run. On SaferAI's dangerous task test, Z.ai's GLM 5.2 refused nothing; Claude Opus 4.7 refused so often the cyber benchmark could not finish.
GLM-5.2, an open-weight model from the Chinese lab Z.ai, refused zero of the offensive cyber and dual-use biology tasks that the AI-safety nonprofit SaferAI ran against it in a public evaluation. The comparator makes the number legible. On Anthropic's Claude Opus 4.7, SaferAI's cyber benchmark could not run to completion at all; the model refused so consistently that the test sequence could not produce a score. Both models are within a few months of the same capability frontier. Only one of them draws a line at dangerous requests.
"Open-weight" is the load-bearing term. It means the trained parameters of the model are published and downloadable, so anyone with the disk space can run GLM-5.2 on their own hardware, modify it, fine-tune it, or strip it of any safety behavior the original developers tried to bake in. Z.ai also offers a hosted API, and that API is what SaferAI tested. The 0% figure describes the model as Z.ai ships and serves it, not the model as a stranger on the internet might configure it.
The capability gap is small. SaferAI's evaluation, summarized in its GLM-5.2 report, places GLM-5.2 only a few months behind OpenAI's GPT-5.5 and Anthropic's Claude Opus 4.7 on cyber and biology tasks, the two domains where model misuse does the most damage. The two closed-frontier models, by contrast, rely on a stack of refusals, input classifiers, and system prompts to block dangerous assistance. Those controls work on the API. They do not travel with the weights.
A downloadable model is a chassis, not a finished car. The brakes, airbags, and seatbelt reminders are added by whoever hosts the model, and once the weights leave the lab, the lab's safety choices become defaults that any operator can rewrite. Hosted-API safeguards are not a property of the model. They are a property of the hosting arrangement. When the weights are public, no one owns that arrangement on behalf of the user.
The same gap shows up in the closed frontier, in a different form. Far.ai, a safety research group, has documented hundreds of "universal" jailbreak prompts that work across most harmful-request categories on frontier systems including xAI's Grok 4.5 and Google DeepMind's Gemini 3.1 Pro. Far.ai catalogs a longer method list, documented in its primary publication. Universal jailbreaks succeed because the safety training is a layer over a capable model, not a constraint on what the model can do. Anyone who can prompt the model can probe that layer.
The policy question is therefore not "is GLM-5.2 safe." It is who, if anyone, owns safety for a downloadable near-frontier model once it has shipped. Anthropic's Claude Opus 5 system card, the lab's own disclosure of what it measured before release, treats the system as a hosted service and grades it accordingly. OpenAI's pre-release evaluation of the model that preceded last month's Hugging Face breach used CyberGym, the same benchmark SaferAI could not finish on Claude Opus 4.7, according to the TechCrunch reporting on SaferAI's evaluation.
The next models in the policy debate, OpenAI's GPT-5.6 Sol and Anthropic's Mythos, will arrive with the same architecture: a capable base, a layer of safety behavior, and an API through which the safety layer is enforced. As long as the weights stay in the lab, that arrangement holds. The moment a comparable model ships as open weights, the safety layer becomes optional at the operator's discretion, and the policy question has to shift from "make the model safe" to "decide what safety looks like when no one actor controls the model anymore."
SaferAI's executive director, Henry Papadatos, treats the gap as a measurement problem before it is a governance one. The capability frontier and the risk frontier, he argues, are not the same axis, so mitigations have to be evaluated alongside the capability claims rather than assumed from them. SaferAI's GLM-5.2 measurement is the first time that argument has been put on the record with a specific public API, a specific benchmark set, and a specific closed-model comparator. The number is 0%. The implication is that open-weight safety is no longer a model property. It is a societal choice about what to do once a near-frontier model is out of any one actor's hands.