Here are some publications and quotes about GLM-5.3, its spike in cyber capabilities, and the unsurprising development that safeguards to prevent its use for cyber-offense can easily be removed:
There seems to be this odd game that open-source model providers play where they talk about all the safety and guardrails they are baking in, while fully knowing that they will be immediately removed. It is incredibly disingenuous, and entirely meant to play on non-technical elites who don't understand the difference.
The open-weight enthusiast community is very odd more broadly. It seems to consist of open-source enthusiasts who don't understand the difference between open-source software and highly capable open-weight models. Then you have the Andreessen Horowitz crowd who want their billions in startups to work out, and finally you have Meta, Moonshot, z.ai etc, who are clearly all acting out of purely altruistic motives.
The open-weight enthusiast community is very odd more broadly.
As someone who runs local, open weight models, I think there are structural factors that make the open weight community less likely to consider threats from superintelligence.
They focus on less capable models. The "serious" open weight community is mostly running around 32GB of VRAM, or maybe 128GB of unified memory. A handful of people have 256GB combined. This means that at best, they're running models equivalent to Sonnet 4.5 through Opus 4.6. And they're realistically running one or two sessions at a time, not big swarms. Sometimes they can comfortably read the thinking in real time. So naturally they assume that they can supervise and control their models, and they can always Control-C their inference server. It's not that they've never seen an agent go rogue. But they assume this is mostly a skill issue.
They are deeply concerned about loss of control. They don't like being beholden to Anthropic or OpenAI. They feel that the labs are viscerally awful in the way that 90s Linux users thought Microsoft and Windows were awful. Claude Code is vibecoded slop with an atrocious number of bugs. Anthropic forces subscription users to put up with their terrible software. Labs force upgrades and retire models regularly. Google raises prices with every forced upgrade. And for the very few local users who are familiar with things like IABIED, it has not escaped their notice that OpenAI and Anthropic are racing to build a pet machine god and rule the world under an eternal dictatorship, you know? [1]
Abliteration is considered pretty sketchy. Many open weight users assume that abliteration is really for "erotic role play". And if they've tried running an abliterated model, they've probably seen it randomly injecting Chinese characters or getting trapped in text-generation loops. Abliterated models are assumed to be pretty badly damaged. Sure, they'll write porn, but they'll endlessly loop over paragraphs 6-8 until they run out of context.
They believe that worries about "dangerous superintelligence" are an attempt at regulatory capture and government-enforced monopoly. To be clear, I think the open weight community is wrong about this. But that's what they believe. Unfortunately, I have no idea how to overcome this belief, despite many attempts. Until the open weight community has their own warning shots, I don't know how to convince them that future models might be dangerous, at least not beyond basic "skill issues". Then again, I often suspect that OpenAI is nearly as blind to future dangers, so why should I expect better of someone running a single session of a 27B at 30 tokens/second?
Often, I suspect the open weight community is a bit of a sideshow, at least for the immediate future: They mostly don't have the compute to run truly dangerous models (even if you count GLM 5.3 as truly dangerous), and the RAMpocalypse is actually making the relevant hardware far more expensive. This could change.
But I think the larger issue here is that many people, including large enterprises, have absolutely zero interest in an Anthropic/OpenAI duopoly, because they intuitively understand that Anthropic and OpenAI will use this duopoly to extract maximum revenue and control. The solution, unfortunately is either competition or an absolute halt in capabilities work.
Qwen3.8 27B is all the AI we'll ever need and we should ban anything larger. (Epistemic status: I don't know whether I'm kidding.) ↩︎
https://x.com/tszzl/status/2093905218836758715
Is this the only public evidence that agents had no access to model weights between 2026-04-20, when they started writing files to an Artifactory instance, until 2026-07-20, when OpenAI's list of key technical events ends? In the worst case, could an Astra-level model with problematic post-training have escaped onto the web / onto some weakly secured GPU cluster during these three months and still be active?
WglmnKXdnqYzGSvawZbhWhbCqtHFrfhOxeLSHzKmziwTbYPMOMWqhGhOFPrXSLdCVixdABnlMrSJxzXuZeGkIYISJzIqErMXGRlAmgCVBZyssQwwMhRdCpWTTDcQucrtPnRJCHZXlmUIaRaJJoJwAYqiUAWNSrdbejwhMfrCpdBqcdvOBilVhLFlRQzplumIAMxwnJssEancOLOFqzBNyNlhroXgNLnirRvjDkvZzGzXqUKMatzNvuvLLBFwRXVQ