A report from the AI safety nonprofit SaferAI finds that GLM-5.2, the open weight modelOpen-weight modelAn AI model whose trained parameters are published so anyone can download, run and modify it, as opposed to one reachable only through the developer's API. The main policy tension is that open weights spread capability widely and cannot be recalled once released. from the Chinese developer Z.ai, trails OpenAI's GPT-5.5 and Anthropic's Claude Opus 4.7 by only a few months on cyber and biology capabilities, per TechCrunch. In the evaluation, run through Z.ai's public interface, GLM-5.2 declined none of the offensive cyber or dual use biology tasks it was given. Claude Opus 4.7 refused so consistently that SaferAI could not complete CyberGym, a cybersecurity capability benchmark, on it at all. "The frontier of capability is not the frontier of risk, and so we do have to take into account the state of the mitigations as well to assess the risk properly," SaferAI executive director Henry Papadatos said. Safeguards that Z.ai applies at its hosted interface become unenforceable once the weights run on someone else's hardware, where protections can be removed or modified and models fine-tuned.
Read at TechCrunch ↗
The alliance proposed the Shared AI Findings Exchange, or SAFE, a set of guidelines for reporting cybersecurity incidents involving AI agentsAI agentAn AI system that carries out multi-step tasks on its own, such as browsing, writing code or making purchases, rather than answering a single prompt. Agents raise new questions about liability, security and oversight because they act rather than just advise., published as a Linux Foundation request for comments with feedback collected on GitHub, per SiliconANGLE. Nvidia, Cisco Systems, CrowdStrike, Hugging Face and Red Hat led the drafting. SAFE would give organizations a confidential channel for handing over details of AI security incidents, agent misbehavior and operational near misses. The alliance would analyze submissions, notify affected parties and flag recurring control failures. The group launched July 27 with roughly two dozen founding members and now counts more than 120 organizations, including Adobe, Cloudflare and Capital One. Anthropic, OpenAI and Google have not joined.
Read at SiliconANGLE ↗