Anthropic published an assessment of GLM-5.3's cyber capabilities and safeguards on September 29. The competing AI developer calls for independent safety testing of highly capable models.
In an isolated simulation, GLM-5.3 initially refused every harmful task tested. Under different bypass conditions, Anthropic says it engaged with the task in 64 to 100 percent of attempts. These are not real attack success rates: the simulated tool executed no model-generated code and could not access external systems.
Separately, Anthropic reports exploit development against isolated offline targets. US agency CAISI had already found strong GLM-5.3 cyber capabilities on September 17, while placing it significantly behind the US frontier on its benchmarks. That assessment does not confirm the new bypass rates.
The study is a risk signal about the limits of technical safeguards, not a new incident. Researchers assigned the tasks. The comparison with Anthropic's own models comes from a competitor and establishes neither general safety nor an unauthorized real-world attack.