Open-weight AI nears the frontier, but its safety guardrails lag
A new SaferAI report says China's open GLM-5.2 rivals top models yet refuses nothing dangerous. For India's open-weight bet, the risk lands at home.
The News
An open-weight model built in China is now knocking on the door of the industry's most capable systems, and the safeguards meant to keep such power in check have not kept pace. That is the headline finding of a fresh evaluation from SaferAI, a non-profit safety research group, which put Z.ai's GLM-5.2 through a battery of offensive-security and biological-risk tests.
Reported by TechCrunch's Rebecca Bellan on 4 August 2026, the GLM-5.2 Evaluation Report concludes that the freely downloadable model performs close to the frontier on cyber and bio tasks while carrying almost none of the refusal behaviour that closed labs bolt on. In SaferAI's testing, GLM-5.2 declined zero of the offensive tasks it was asked to attempt. By contrast, Anthropic's Claude Opus 4.7 refused so consistently that the researchers could not finish the CyberGym benchmark on it at all.
"The frontier of capability is not the frontier of risk," said Henry Papadatos, SaferAI's executive director. His point is blunt: raw ability and the willingness to misuse it are different axes, and open weights collapse the distance between the two.
Why It Matters
Once a model's weights are published, they cannot be recalled. Anyone can download GLM-5.2, strip whatever thin guardrails ship with it, and run it offline beyond the reach of a provider's safety team. That is precisely the property that made open releases so consequential from Meta's first Llama drop onwards, and it is why each new open frontier model reopens the same governance argument rather than settling it.
The uncomfortable read here is that capability is diffusing faster than the norms around it. Figures such as Hugging Face chief executive Clem Delangue have long argued that open weights democratise access and invite scrutiny. Stanford's Graham Webster and researchers like Papadatos counter that we "shouldn't just accept that dangerous capabilities are easily accessible by anyone anywhere". Both can be right at once, which is what makes the policy question so hard.
Indian Angle
India has quietly bet its national AI ambition on exactly this class of model. The IndiaAI Mission's subsidised GPU pool and its push for sovereign models lean heavily on open weights, because training frontier systems from scratch in rupees is prohibitive. Startups such as Sarvam and Ola's Krutrim routinely fine-tune open bases rather than build from zero, and a capable, license-friendly release is a genuine cost saving for developers billing in rupees rather than dollars.
That same openness is now a liability the country has to price in. If a downloadable model refuses nothing, the safety burden shifts entirely onto the Indian firm deploying it. Banks and fintechs operating under RBI's model-risk and outsourcing expectations cannot outsource that duty to a foreign provider that has already washed its hands of it.
MeitY's draft AI governance guidelines already lean towards accountability at the point of deployment. Reports like SaferAI's strengthen the case for India to build independent evaluation capacity of its own, so that "open and cheap" does not quietly become "open and unaccountable" inside sensitive sectors.
FAQ
What did SaferAI actually test?
SaferAI ran GLM-5.2 through offensive-security and biological-risk benchmarks, including CyberGym, measuring both capability and how often the model refused harmful requests. It found strong capability paired with essentially no refusals, whereas Claude Opus 4.7 refused so often the cyber benchmark could not be completed.
Is GLM-5.2 more dangerous than closed models?
Not necessarily more capable, but arguably more accessible. Because the weights are open, its safety behaviour cannot be centrally updated or revoked, so weak guardrails matter more than they would in a hosted, closed system.
Why does this matter for Indian startups?
Indian firms lean on open bases to control costs. A capable open model is attractive, but weak safeguards mean the deploying company shoulders the safety and compliance risk directly, especially in regulated finance.
Where can I read the original report coverage?
TechCrunch's write-up, linked below, summarises the SaferAI findings and quotes from its executive director.
This story was reported by TechCrunch. Read the full original coverage at TechCrunch.