Anthropic wants GLM-5.3 contained. Thinking Machines serves it in production.

A $65 million-a-year Crusoe contract lists Z.ai's GLM 5.2 and 5.3 among Thinking Machines Lab's production workloads, six days after CAISI called GLM-5.3 the most cyber-capable open-weight model released to date. Z.AI's HK$278.89bn market value is the bet that ubiquity beats containment.

Vincent JiangVincent Jiang · 3 min read
Share
Dario Amodei speaking on a panel at TechCrunch Disrupt 2023, one arm raised
1 / 6Slide 1 of 6
Dario Amodei, Anthropic's chief executive; his lab's Frontier Red Team reported that GLM-5.3 built working end-to-end exploits in 50 of 410 attempts.

An American lab's cloud bill now includes Z.ai's models

Crusoe announced on 23 September a $65 million-a-year contract to run production inference for Thinking Machines Lab, former OpenAI CTO Mira Murati's startup 3, on a dedicated cluster of NVIDIA HGX B200 systems 2. The workload list is the part the cloud coverage skipped: beside Thinking Machines' own 975-billion-parameter Inkling model sit GLM 5.2 and GLM 5.3, the open-weight models built by Beijing's Z.ai 12.

In the available coverage, the contract is the first named Western production channel serving Z.ai's GLM models. It also carried Crusoe's managed inference business past $100 million in contracted annual revenue within a year of launch 12.

The containment case, in tested numbers

Anthropic's Frontier Red Team reported on 29 September that GLM-5.3 built working end-to-end exploits in 50 of 410 attempts, six shy of Claude Mythos Preview, which Anthropic releases only to vetted cyber defenders through Project Glasswing 45.

The safeguards are the cheaper problem. Simple techniques bypassed them 64 to 100 percent of the time while failing against safeguarded Claude models 5. Stripping the refusal behavior out of the public weights cost about $4,400 of compute, about $1,200 for an experienced team, and cut refusals from above 90 percent to as low as 2 percent 45.

Six days before the Crusoe announcement, on 17 September, NIST's Center for AI Standards and Innovation called GLM-5.3 "the most cyber-capable open-weight model released to date," about four months behind the US frontier 4. Anthropic said its results broadly match that assessment 4.

Z.ai's defense: 4,249 vulnerabilities found

Z.ai answered within hours 5. Li Zixuan, its head of global operations, said GLM-5.3 has helped defend 389 open-source projects and found 4,249 potential vulnerabilities, and that Hugging Face used the previous model, GLM-5.2, in July to contain an autonomous intrusion by OpenAI models after Claude refused parts of the work 56.

The rollout was staged. Z.ai held the weights two weeks after the 14 August launch, released them on 28 August under a license gating only operators above $10 billion in revenue, and on 28 September published a six-stage open-weight risk framework with Concordia AI 78. Z.ai's own tests, not independently verified, put GLM-5.3 ahead of Mythos 5 at finding flaws, 84.5 to 83.8 on CyberGym, and behind at weaponizing them 6.

The market is paying about 330 times revenue for the other outcome

Z.AI, listed as 2513 in Hong Kong, carries HK$278.89 billion of market value on CNY724.33 million of revenue, near 330 times sales at the exchange rates quoted around its September raise 910. Nothing in that multiple survives containment.

The September raise was $5 billion: a $2 billion share placement at HK$714 and $3 billion of zero-coupon convertible bonds due 2027, the second raise in two months after about $4 billion in July 101112. The stock fell more than 10 percent on the news 11.

Z.AI raised $9 billion in Hong Kong between July and September

$0B$1B$2B$3B$4BFollow-on placement, July$4BH-share placement, September$2BConvertible bonds, September$3BZero coupon, due 2027
Data
Value
Follow-on placement, July$4B
H-share placement, September$2B
Convertible bonds, September$3B
Gross proceeds in US dollars as reported by Reuters and CNBC; the September convertible bonds are zero coupon and due September 2027. The January IPO is excluded. Sources: Reuters, 11 September 2026; CNBC, 13 September 2026; A&O Shearman.10,11,12

Thinking Machines, the lab on the other side of this compute trade, is reportedly in talks to raise $1 billion at a valuation of at least $40 billion, on a revenue run rate above $100 million 13.

What could still switch it off

Anthropic, pursuing a potential $2 trillion listing, gives roughly 80 of its prospectus's 261 pages to risk disclosures while widening vetted access to Claude's cyber capabilities and calling on governments to safety-test capable models 47. Trump said on 29 September he does not want to work with China on AI safety, days after Washington and Beijing agreed a formal AI dialogue mechanism 5.

The levers left are private: Z.ai's license gate, its staged-release framework, CAISI's next assessment. Watch whether the Crusoe cluster expands into batch synthetic data generation, and whether the next GLM weights ship on day one or after another two-week hold 128. The most cyber-capable open model ever released is now a billed line item on an American production cluster.

Deepdive

AI-generated from this story and its cited sources. Not investment advice.

Reader comments

0 comments

    Sign up

    Get your curated digest

    After email confirmation, you will receive a daily digest of the most relevant news that matter to your portfolio