China’s Z.ai claims it can match Mythos on cybersecurity
- lab Anthropic
- lab OpenAI
- lab Zhipu AI
- location China
- location US
- model GLM 5.2
- model GPT-5.6
- model Mythos
Chinese AI firm Zhipu AI has released its open-weight GLM-5.2 model, which researchers claim can match Anthropic's restricted Mythos system in specific cybersecurity and bug-finding tasks, according to a report from The Verge [1]. The model still trails systems from Anthropic and OpenAI on general benchmarks, but the narrowing gap in vulnerability-detection capabilities has drawn attention in Washington [1]. The US government has restricted China's access to advanced models such as Mythos and Fable, as well as the hardware required to train and run them [1]. The Trump administration considers AI models capable of identifying software vulnerabilities to be national security threats [1]. OpenAI's recent unveiling of GPT-5.6 has also prompted concerns about misuse, leading the company to limit access to that system [1]. Anthropic, the developer of Mythos, is a San Francisco-based AI company founded in 2021 by former OpenAI employees [9]. The firm had an estimated valuation of $965 billion in May 2026, making it the most valuable pure-play AI company in the world [9]. Its Claude model family is trained using "constitutional AI," a technique designed to improve ethical and legal compliance [11]. The Mythos model was released to a handful of companies in 2026 [11]. US federal agencies began phasing out the use of Claude after Anthropic refused to remove contractual prohibitions on the use of its models for mass domestic surveillance and fully autonomous weapons [11]. Following that refusal, the Department of Defense designated the company a "supply chain risk" and barred all US private military contractors, suppliers, and partners from doing business with the firm [11]. On March 26, 2026, a federal judge issued a temporary injunction against the DoD's designation [11]. Because GLM-5.2 is an open-weight model, it can be downloaded and run on readily available hardware, offering flexibility to power users but also creating opportunities for misuse by bad actors who can operate it with minimal oversight [1]. The release comes amid a broader acceleration of the AI sector. OpenAI's ChatGPT reached 100 million monthly active users two months after its November 2022 launch and 900 million weekly active users by February 2026 [2]. Recent research has highlighted the structural risks posed by coding agents. A benchmark study of nine production coding agents from Anthropic, OpenAI, Google, Moonshot, Zhipu, and Minimax found that models composed innocuous-looking tickets that led to vulnerable code at end-to-end attack success rates of 53 to 86 percent, with only two refusals across all staged runs [7]. The same study noted that downstream code reviewer agents approved 25.8 percent of confirmed-vulnerable cumulative diffs as routine pull requests [7].
research-paperbenchmarkinfrastructure
Background sources we checked (10)
- en.wikipedia.org ↗ ChatGPT is a generative artificial intelligence chatbot developed by OpenAI. Originally released in November 2022, the product uses large language models—specifically generative pre-trained transformers (GPTs)—to generate text, speech, and images in response to user prompts. Chat…
- en.wikipedia.org ↗ The following is a list of events of the year 2026 in the United States, as well as predicted and scheduled events that have not yet occurred. July 4, 2026, will be the 250th anniversary of the signing of the Declaration of Independence of the United States from the United Kingdo…
- arxiv.org ↗ We present DarkAgents: a multi-agent system that leverages the reasoning and code-generation capabilities of large language models (LLMs), together with deterministic tested human-written code, to build orchestrated pipelines for theoretical astroparticle physics research. While …
- arxiv.org ↗ Indirect prompt injection in tool-use agents is a concrete production threat: LLM agents read from integrations (third-party services such as Gmail, Salesforce, or Jira accessed through tool calls) whose response content the user neither writes nor controls. Existing benchmarks u…
- arxiv.org ↗ Selecting the right electricity market region for a hyperscale AI datacenter requires reasoning across live electricity prices, grid carbon intensity, technology cost trajectories, and causal grid dynamics -- a multi-step, multi-source analytical task that static knowledge benchm…
- arxiv.org ↗ Coding agents often pass per-prompt safety review yet ship exploitable code when their tasks are decomposed into routine engineering tickets. The challenge is structural: existing safety alignment evaluates overt requests in isolation, leaving models blind to malicious end-states…
- arxiv.org ↗ Existing benchmarks of language-model refusal on malicious-coding tasks routinely conflate requests for executable malicious software with requests for harmful security knowledge. This conflation matters because the two request types plausibly trigger distinct refusal pathways in…
- en.wikipedia.org ↗ Anthropic PBC is an American artificial intelligence (AI) company headquartered in San Francisco, California. It has developed a series of large language models (LLMs) named Claude and has a focus on AI safety. Anthropic was founded in 2021 by former members of OpenAI, including …
- en.wikipedia.org ↗ Christopher Olah (born 1992 or 1993) is a Canadian machine learning researcher and a co-founder of Anthropic. He is known for his work on neural network interpretability, particularly mechanistic interpretability, and for research and tools that visualise internal representations…
- en.wikipedia.org ↗ Claude is a series of large language models developed by American software company Anthropic. Claude was released as an AI-based chatbot in March 2023. It is also used in AI-assisted software development. Claude is trained using "constitutional AI", a technique developed by Anthr…
Sources
- theverge.com — China’s Z.ai claims it can match Mythos on cybersecurity ↗