A new report from AI safety nonprofit SaferAI highlights how China's GLM-5.2 open-weight model is rapidly closing the gap with leading AI systems like OpenAI’s GPT-5.5 and Anthropic’s Claude Opus 4.7 in cyber and bio capabilities. According to the report, GLM-5.2 refused none of the offensive cyber or dual-use biology tasks it was given, unlike Claude Opus 4.7, which “refused so consistently that SaferAI could not complete CyberGym on it at all.” CyberGym is a benchmark used to evaluate cybersecurity capabilities, previously used by OpenAI in an evaluation that preceded last month’s Hugging Face breach. The findings underscore the growing concern that open-weight models could enable attackers to access highly capable AI systems without oversight, as the models can be run on any infrastructure with no built-in safeguards. This raises questions about how to manage risks once such models are released, as their capabilities approach those of the world’s leading AI systems. Source: techcrunch

Frontier developers like OpenAI and Anthropic rely on safeguards such as classifiers, refusal training, and API-level controls to limit dangerous cyber and biological assistance. However, these measures are not foolproof, as jailbreaks routinely bypass protections on deployed models. Far.ai, an AI safety nonprofit, found hundreds of universal jailbreaks in models like xAI’s Grok 4.5 and Google DeepMind’s Gemini 3.1 Pro. These jailbreaks succeed when attackers combine multiple manipulation techniques, including roleplaying, authority impersonation, and fake conversation history, to exploit weaknesses in a model’s defenses. The report also notes that safeguards in place for closed models do not apply to open-weight models, which are designed to run on any infrastructure without restrictions. Source: techcrunch

Chinese leaders have acknowledged the risks of advanced AI, with President Xi Jinping emphasizing the importance of open-weight models while stressing the need for human control. However, Chinese AI regulations have historically focused on politically sensitive content, misinformation, and social stability rather than catastrophic AI risks like offensive cyber capabilities and biological misuse. Graham Webster, a researcher at the Stanford Cyber Policy Center, noted that U.S. AI thinkers are more concerned with existential risks than the Chinese community, which believes American companies are more likely to encounter novel frontier risks first. Source: techcrunch

Source: techcrunch